MISY 5325 MIDTERM EXAM REVIEW STUDY
NOTES
◉ The NIST Cybersecurity Framework consists of standards,
guidelines, and practices to protect the promotion of critical
infrastructure.
True
False.
Answer: False
◉ The NIST Cybersecurity Framework __________ is/ are designed to
help organizations to view and understand the characteristics of
their approach to managing cybersecurity risk..
Answer: Tiers
◉ The NIST Cybersecurity Framework Tiers include all of these
categories EXCEPT:.
Answer: a. Internal Participation
◉ In the NIST s Cybersecurity Framework Coordination model, the
executive level communicates the mission priorities, available
resources, and overall risk tolerance to the __________ level..
,Answer: business/process level
◉ __________ point to industry standards, guidelines, and practices
that are beneficial for an organization trying to achieve outcomes..
Answer: Informative references
◉ The NIST Cybersecurity Framework Core consist of these
functions:.
Answer: "identify, protect, detect, respond, recover"
◉ In the NIST s Cybersecurity Framework Coordination model, the
business/process level obtains the executive level inputs into the
risk management process, and then collaborates with the __________
level..
Answer: implementation/operations
◉ The Implementation Tiers in the NIST Cybersecurity Framework
are designed as an overarching measurement of cybersecurity risk
management _________..
Answer: Maturity
◉ ___________ is the process of the subject supplying an identifier to
the object..
Answer: Identification
,◉ The security posture of an organization determines the custom
settings for access controls.
True
False.
Answer: False
◉ The __________ model defines how access rights and permission are
granted..
Answer: Authorization
◉ An identification scheme, an authentication method, and an
authorization model are the three common attributes of all access
controls.
True
False.
Answer: True
◉ In terms of authorization, the three categories of access control
lists (ACLs) include all BUT:.
Answer: Security Controls
, ◉ The three primary authorization models include all EXCEPT:.
Answer: Multilayer authorization
◉ __________ is the process of the subject supplying verifiable
credentials to the object..
Answer: Authentication
◉ The NIST Cybersecurity Framework was created through
collaboration between industry and government.
True
False.
Answer: True
◉ The NIST Cybersecurity Framework Core subcategory outcomes
are meaningful for multiple requirements.
True
False.
Answer: True
NOTES
◉ The NIST Cybersecurity Framework consists of standards,
guidelines, and practices to protect the promotion of critical
infrastructure.
True
False.
Answer: False
◉ The NIST Cybersecurity Framework __________ is/ are designed to
help organizations to view and understand the characteristics of
their approach to managing cybersecurity risk..
Answer: Tiers
◉ The NIST Cybersecurity Framework Tiers include all of these
categories EXCEPT:.
Answer: a. Internal Participation
◉ In the NIST s Cybersecurity Framework Coordination model, the
executive level communicates the mission priorities, available
resources, and overall risk tolerance to the __________ level..
,Answer: business/process level
◉ __________ point to industry standards, guidelines, and practices
that are beneficial for an organization trying to achieve outcomes..
Answer: Informative references
◉ The NIST Cybersecurity Framework Core consist of these
functions:.
Answer: "identify, protect, detect, respond, recover"
◉ In the NIST s Cybersecurity Framework Coordination model, the
business/process level obtains the executive level inputs into the
risk management process, and then collaborates with the __________
level..
Answer: implementation/operations
◉ The Implementation Tiers in the NIST Cybersecurity Framework
are designed as an overarching measurement of cybersecurity risk
management _________..
Answer: Maturity
◉ ___________ is the process of the subject supplying an identifier to
the object..
Answer: Identification
,◉ The security posture of an organization determines the custom
settings for access controls.
True
False.
Answer: False
◉ The __________ model defines how access rights and permission are
granted..
Answer: Authorization
◉ An identification scheme, an authentication method, and an
authorization model are the three common attributes of all access
controls.
True
False.
Answer: True
◉ In terms of authorization, the three categories of access control
lists (ACLs) include all BUT:.
Answer: Security Controls
, ◉ The three primary authorization models include all EXCEPT:.
Answer: Multilayer authorization
◉ __________ is the process of the subject supplying verifiable
credentials to the object..
Answer: Authentication
◉ The NIST Cybersecurity Framework was created through
collaboration between industry and government.
True
False.
Answer: True
◉ The NIST Cybersecurity Framework Core subcategory outcomes
are meaningful for multiple requirements.
True
False.
Answer: True