Loading course title...
Loading assessment title...
Connecting to LMS...
Progress: in progress
Assessment
1.
What is NIST CSF 2.0 mainly used for?
A. Certifying that an organization has perfect security
B. Replacing all engineering judgment
C. Helping organizations manage and communicate cybersecurity risk
D. Eliminating the need for incident response
2.
What are the main components of CSF 2.0?
A. Core, Organizational Profiles, and Tiers
B. Passwords, firewalls, and antivirus only
C. One mandatory checklist for all organizations
D. A single audit report template
3.
Which list contains the six CSF 2.0 Functions?
A. Plan, Buy, Build, Sell, Audit, Retire
B. Prevent, Block, Patch, Certify, Inspect, Archive
C. Scan, Score, Punish, Certify, Publish, Repeat
D. Govern, Identify, Protect, Detect, Respond, Recover
4.
What does the Govern Function help establish?
A. A guarantee that incidents cannot happen
B. Risk strategy, expectations, policy, roles, and oversight
C. A list of exploit steps
D. A replacement for business ownership
5.
What is an Organizational Profile used for?
A. Hiding cybersecurity gaps
B. Replacing all controls
C. Describing current or target cybersecurity outcomes
D. Proving that no risk exists
6.
What do CSF Tiers help characterize?
A. The brand name of security tools
B. The number of employees in marketing
C. The color of a dashboard
D. The rigor of cybersecurity risk governance and management practices
7.
What is a common mistake when applying CSF 2.0?
A. Treating it as checkbox theater instead of a risk management framework
B. Defining scope and owners
C. Comparing current and target outcomes
D. Communicating risk clearly
8.
Which is the best CSF 2.0 operating routine?
A. Copy another organization's profile and never review it
B. Define scope, assess current outcomes, set target outcomes, prioritize gaps, communicate risk, and improve
C. Ignore governance and only buy tools
D. Claim certification without evidence
Submit Quiz
Previous