MISY 5325 EXAM 2 QUESTIONS & ANSWERS | 2026
In the NIST s Cybersecurity Framework Coordination model, the
implementation/operations level is where the stakeholders are in charge of
implementing the framework and communicating the implementation progress to the
__________ level.
audit/accounting
implementation/operations
business/process
Executive - Answers - business/process
NIST's Cybersecurity Framework provides a common language to communicate
requirements with all the stakeholders within or outside your organization that are
responsible for the delivery of essential critical infrastructure services.
True
False - Answers - True
NIST Cybersecurity Framework is built from standards, guidelines, and practices to
provide a common __________ for organizations.
standard
guidance
framework
practice - Answers - guidance
__________ are a list of specific outcomes of technical and/or management activities.
Categories
Subcategories
Informative references
Guidelines - Answers - Subcategories
In the NIST's Cybersecurity Framework Coordination model, the business/process level
obtains the executive level inputs into the risk management process and then
collaborates with the __________ level.
business/process
implementation/operations
audit/accounting
marketing/sales - Answers - implementation/operations
The NIST Cybersecurity Framework Core consist of these functions:
,"identify, prevent, detect, respond, recover"
"identify, protect, defect, respond, recover"
"identify, protect, detect, respond, recover"
"identify, protect, detect, respond, receive" - Answers - "identify, protect, detect,
respond, recover"
Correct answer
The work product of cybersecurity requirements management using the NIST
Cybersecurity Framework is referred to as a(n) __________.
profile
indentity
tier
level - Answers - profile
The NIST Cybersecurity Framework Core functions are broken down in to all of these
EXCEPT:
Categories
Subcategories
Informative references
Guidelines - Answers - Guidelines
NIST s Cybersecurity Framework is divided into three parts including all EXCEPT:
core
profiles
standards
implementation tiers - Answers - standards
The NIST Cybersecurity Framework consists of standards, guidelines, and practices to
protect the promotion of critical infrastructure.
True
False - Answers - False
The NIST Cybersecurity Framework __________ is/ are designed to help organizations
to view and understand the characteristics of their approach to managing cybersecurity
risk. - Answers - Tiers
The NIST Cybersecurity Framework Tiers include all of these categories EXCEPT: -
Answers - a. Internal Participation
, In the NIST s Cybersecurity Framework Coordination model, the executive level
communicates the mission priorities, available resources, and overall risk tolerance to
the __________ level. - Answers - business/process level
__________ point to industry standards, guidelines, and practices that are beneficial for
an organization trying to achieve outcomes. - Answers - Informative references
The NIST Cybersecurity Framework Core consist of these functions: - Answers -
"identify, protect, detect, respond, recover"
In the NIST s Cybersecurity Framework Coordination model, the business/process level
obtains the executive level inputs into the risk management process, and then
collaborates with the __________ level. - Answers - implementation/operations
The Implementation Tiers in the NIST Cybersecurity Framework are designed as an
overarching measurement of cybersecurity risk management _________. - Answers -
Maturity
___________ is the process of the subject supplying an identifier to the object. -
Answers - Identification
The security posture of an organization determines the custom settings for access
controls.
True
False - Answers - False
The __________ model defines how access rights and permission are granted. -
Answers - Authorization
An identification scheme, an authentication method, and an authorization model are the
three common attributes of all access controls.
True
False - Answers - True
In terms of authorization, the three categories of access control lists (ACLs) include all
BUT: - Answers - Security Controls
The three primary authorization models include all EXCEPT: - Answers - Multilayer
authorization
__________ is the process of the subject supplying verifiable credentials to the object. -
Answers - Authentication
In the NIST s Cybersecurity Framework Coordination model, the
implementation/operations level is where the stakeholders are in charge of
implementing the framework and communicating the implementation progress to the
__________ level.
audit/accounting
implementation/operations
business/process
Executive - Answers - business/process
NIST's Cybersecurity Framework provides a common language to communicate
requirements with all the stakeholders within or outside your organization that are
responsible for the delivery of essential critical infrastructure services.
True
False - Answers - True
NIST Cybersecurity Framework is built from standards, guidelines, and practices to
provide a common __________ for organizations.
standard
guidance
framework
practice - Answers - guidance
__________ are a list of specific outcomes of technical and/or management activities.
Categories
Subcategories
Informative references
Guidelines - Answers - Subcategories
In the NIST's Cybersecurity Framework Coordination model, the business/process level
obtains the executive level inputs into the risk management process and then
collaborates with the __________ level.
business/process
implementation/operations
audit/accounting
marketing/sales - Answers - implementation/operations
The NIST Cybersecurity Framework Core consist of these functions:
,"identify, prevent, detect, respond, recover"
"identify, protect, defect, respond, recover"
"identify, protect, detect, respond, recover"
"identify, protect, detect, respond, receive" - Answers - "identify, protect, detect,
respond, recover"
Correct answer
The work product of cybersecurity requirements management using the NIST
Cybersecurity Framework is referred to as a(n) __________.
profile
indentity
tier
level - Answers - profile
The NIST Cybersecurity Framework Core functions are broken down in to all of these
EXCEPT:
Categories
Subcategories
Informative references
Guidelines - Answers - Guidelines
NIST s Cybersecurity Framework is divided into three parts including all EXCEPT:
core
profiles
standards
implementation tiers - Answers - standards
The NIST Cybersecurity Framework consists of standards, guidelines, and practices to
protect the promotion of critical infrastructure.
True
False - Answers - False
The NIST Cybersecurity Framework __________ is/ are designed to help organizations
to view and understand the characteristics of their approach to managing cybersecurity
risk. - Answers - Tiers
The NIST Cybersecurity Framework Tiers include all of these categories EXCEPT: -
Answers - a. Internal Participation
, In the NIST s Cybersecurity Framework Coordination model, the executive level
communicates the mission priorities, available resources, and overall risk tolerance to
the __________ level. - Answers - business/process level
__________ point to industry standards, guidelines, and practices that are beneficial for
an organization trying to achieve outcomes. - Answers - Informative references
The NIST Cybersecurity Framework Core consist of these functions: - Answers -
"identify, protect, detect, respond, recover"
In the NIST s Cybersecurity Framework Coordination model, the business/process level
obtains the executive level inputs into the risk management process, and then
collaborates with the __________ level. - Answers - implementation/operations
The Implementation Tiers in the NIST Cybersecurity Framework are designed as an
overarching measurement of cybersecurity risk management _________. - Answers -
Maturity
___________ is the process of the subject supplying an identifier to the object. -
Answers - Identification
The security posture of an organization determines the custom settings for access
controls.
True
False - Answers - False
The __________ model defines how access rights and permission are granted. -
Answers - Authorization
An identification scheme, an authentication method, and an authorization model are the
three common attributes of all access controls.
True
False - Answers - True
In terms of authorization, the three categories of access control lists (ACLs) include all
BUT: - Answers - Security Controls
The three primary authorization models include all EXCEPT: - Answers - Multilayer
authorization
__________ is the process of the subject supplying verifiable credentials to the object. -
Answers - Authentication