
EMC NIST Cybersecurity Framework 2023 - D-CSF-SC-23 Exam Questions
QUESTION NO: 1
What must be included in the CMDB?
What must be included in the CMDB?
Correct Answer: D
QUESTION NO: 2
Assume that a DDoS attack has been occurring for 72 minutes.
What determines who talks to external stakeholders?
Assume that a DDoS attack has been occurring for 72 minutes.
What determines who talks to external stakeholders?
Correct Answer: C
QUESTION NO: 3
A new employee is starting work at your company. When should they be informed of the company's security policy?
A new employee is starting work at your company. When should they be informed of the company's security policy?
Correct Answer: B
QUESTION NO: 4
What should an organization use to effectively mitigate against password sharing to prevent unauthorized access to systems?
What should an organization use to effectively mitigate against password sharing to prevent unauthorized access to systems?
Correct Answer: D
QUESTION NO: 5
What is the main goal of a gap analysis in the Identify function?
What is the main goal of a gap analysis in the Identify function?
Correct Answer: B
QUESTION NO: 6
What method identifies the 'delta' in projected time for RTO and actual time to complete?
What method identifies the 'delta' in projected time for RTO and actual time to complete?
Correct Answer: B
QUESTION NO: 7
What is a consideration when performing data collection in Information Security Continuous Monitoring?
What is a consideration when performing data collection in Information Security Continuous Monitoring?
Correct Answer: C




