MISY 5325 UPDATED STUDY QUESTIONS AND
ANSWERS SET A+
✔✔The NIST Cybersecurity Framework __________ is/ are designed to help
organizations to view and understand the characteristics of their approach to managing
cybersecurity risk. - ✔✔Tiers
✔✔The NIST Cybersecurity Framework Tiers include all of these categories EXCEPT: -
✔✔a. Internal Participation
✔✔In the NIST s Cybersecurity Framework Coordination model, the executive level
communicates the mission priorities, available resources, and overall risk tolerance to
the __________ level. - ✔✔business/process level
✔✔__________ point to industry standards, guidelines, and practices that are beneficial
for an organization trying to achieve outcomes. - ✔✔Informative references
✔✔The NIST Cybersecurity Framework Core consist of these functions: - ✔✔"identify,
protect, detect, respond, recover"
✔✔In the NIST s Cybersecurity Framework Coordination model, the business/process
level obtains the executive level inputs into the risk management process, and then
collaborates with the __________ level. - ✔✔implementation/operations
✔✔The Implementation Tiers in the NIST Cybersecurity Framework are designed as an
overarching measurement of cybersecurity risk management _________. - ✔✔Maturity
✔✔___________ is the process of the subject supplying an identifier to the object. -
✔✔Identification
✔✔The security posture of an organization determines the custom settings for access
controls.
,True
False - ✔✔False
✔✔The __________ model defines how access rights and permission are granted. -
✔✔Authorization
✔✔An identification scheme, an authentication method, and an authorization model are
the three common attributes of all access controls.
True
False - ✔✔True
✔✔In terms of authorization, the three categories of access control lists (ACLs) include
all BUT: - ✔✔Security Controls
✔✔The three primary authorization models include all EXCEPT: - ✔✔Multilayer
authorization
✔✔__________ is the process of the subject supplying verifiable credentials to the
object. - ✔✔Authentication
✔✔The NIST Cybersecurity Framework was created through collaboration between
industry and government.
True
False - ✔✔True
✔✔The NIST Cybersecurity Framework Core subcategory outcomes are meaningful for
multiple requirements.
True
False - ✔✔True
✔✔The Implementation Tiers in the NIST Cybersecurity Framework are not prescriptive
like you may find in other maturity models.
True
False - ✔✔True
✔✔NIST Cybersecurity Framework is built from standards, guidelines, and practices to
provide a common __________ for organizations. - ✔✔Guidance
, ✔✔In the NIST Cybersecurity Framework Cyber Supply Chain Relationship, companies
have communication with all EXCEPT: - ✔✔Operational process (OP) partners
✔✔NIST s Cybersecurity Framework provides a common language to communicate
requirements with all the stakeholders within or outside your organization that are
responsible for the delivery of essential critical infrastructure services.
True
False - ✔✔True
✔✔NIST defines three levels within an organization that should be engaged to
coordinate the framework implementation and a common flow of information including
all of these EXCEPT: - ✔✔IT Department
✔✔The NIST Cybersecurity Framework __________ is/are a collection of cybersecurity
activities, outcomes, and informative references that are common across critical
infrastructure sectors. - ✔✔Core
✔✔The NIST Cybersecurity Framework is never used by organizations of differing
sizes.
True
False. - ✔✔False
✔✔Using specially crafted phone calls during a corporate account takeover, criminals
capture a business's online banking credentials or compromise the workstation used for
online banking. This is a form of Malware.
True
False. - ✔✔False
✔✔The NIST Cybersecurity Framework __________ is/are designed to help the
underlying organization align its cybersecurity undertakings with business requirements,
risk tolerances, and resources. - ✔✔Profiles
✔✔__________ group the elements of a function into collections of cybersecurity
outcomes. - ✔✔Categories
✔✔NIST is very clear that their framework is aimed to replace existing risk management
processes and cybersecurity programs of your organization
True
False - ✔✔False
ANSWERS SET A+
✔✔The NIST Cybersecurity Framework __________ is/ are designed to help
organizations to view and understand the characteristics of their approach to managing
cybersecurity risk. - ✔✔Tiers
✔✔The NIST Cybersecurity Framework Tiers include all of these categories EXCEPT: -
✔✔a. Internal Participation
✔✔In the NIST s Cybersecurity Framework Coordination model, the executive level
communicates the mission priorities, available resources, and overall risk tolerance to
the __________ level. - ✔✔business/process level
✔✔__________ point to industry standards, guidelines, and practices that are beneficial
for an organization trying to achieve outcomes. - ✔✔Informative references
✔✔The NIST Cybersecurity Framework Core consist of these functions: - ✔✔"identify,
protect, detect, respond, recover"
✔✔In the NIST s Cybersecurity Framework Coordination model, the business/process
level obtains the executive level inputs into the risk management process, and then
collaborates with the __________ level. - ✔✔implementation/operations
✔✔The Implementation Tiers in the NIST Cybersecurity Framework are designed as an
overarching measurement of cybersecurity risk management _________. - ✔✔Maturity
✔✔___________ is the process of the subject supplying an identifier to the object. -
✔✔Identification
✔✔The security posture of an organization determines the custom settings for access
controls.
,True
False - ✔✔False
✔✔The __________ model defines how access rights and permission are granted. -
✔✔Authorization
✔✔An identification scheme, an authentication method, and an authorization model are
the three common attributes of all access controls.
True
False - ✔✔True
✔✔In terms of authorization, the three categories of access control lists (ACLs) include
all BUT: - ✔✔Security Controls
✔✔The three primary authorization models include all EXCEPT: - ✔✔Multilayer
authorization
✔✔__________ is the process of the subject supplying verifiable credentials to the
object. - ✔✔Authentication
✔✔The NIST Cybersecurity Framework was created through collaboration between
industry and government.
True
False - ✔✔True
✔✔The NIST Cybersecurity Framework Core subcategory outcomes are meaningful for
multiple requirements.
True
False - ✔✔True
✔✔The Implementation Tiers in the NIST Cybersecurity Framework are not prescriptive
like you may find in other maturity models.
True
False - ✔✔True
✔✔NIST Cybersecurity Framework is built from standards, guidelines, and practices to
provide a common __________ for organizations. - ✔✔Guidance
, ✔✔In the NIST Cybersecurity Framework Cyber Supply Chain Relationship, companies
have communication with all EXCEPT: - ✔✔Operational process (OP) partners
✔✔NIST s Cybersecurity Framework provides a common language to communicate
requirements with all the stakeholders within or outside your organization that are
responsible for the delivery of essential critical infrastructure services.
True
False - ✔✔True
✔✔NIST defines three levels within an organization that should be engaged to
coordinate the framework implementation and a common flow of information including
all of these EXCEPT: - ✔✔IT Department
✔✔The NIST Cybersecurity Framework __________ is/are a collection of cybersecurity
activities, outcomes, and informative references that are common across critical
infrastructure sectors. - ✔✔Core
✔✔The NIST Cybersecurity Framework is never used by organizations of differing
sizes.
True
False. - ✔✔False
✔✔Using specially crafted phone calls during a corporate account takeover, criminals
capture a business's online banking credentials or compromise the workstation used for
online banking. This is a form of Malware.
True
False. - ✔✔False
✔✔The NIST Cybersecurity Framework __________ is/are designed to help the
underlying organization align its cybersecurity undertakings with business requirements,
risk tolerances, and resources. - ✔✔Profiles
✔✔__________ group the elements of a function into collections of cybersecurity
outcomes. - ✔✔Categories
✔✔NIST is very clear that their framework is aimed to replace existing risk management
processes and cybersecurity programs of your organization
True
False - ✔✔False