← All CCP Flashcard Decks

NIST CSF & CIS Controls Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 NIST CSF & CIS Controls flashcards as text
  1. An organization wants to prioritize security investments based on potential business impact. Which NIST CSF concept best supports this decision?

    Answer: Framework Tiers

    NIST CSF Tiers (1–4) reflect the degree to which cybersecurity risk management is integrated into business decisions, helping prioritize investments.

  2. CIS Control 5 (Account Management) requires which of the following as a safeguard?

    Answer: Disabling dormant accounts after a defined period

    CIS Control 5 requires disabling or removing dormant accounts to reduce the attack surface from unused credentials.

  3. Which NIST CSF 'Protect' category addresses limiting access to only what is necessary for users to perform their job functions?

    Answer: Identity Management and Access Control

    The 'Identity Management and Access Control' category enforces least privilege and ensures access is limited to what is necessary for job functions.

  4. A security analyst discovers a zero-day vulnerability actively exploited in the wild. Under which NIST CSF function should the organization's immediate response activities fall?

    Answer: Respond

    Active exploitation of a vulnerability triggers the 'Respond' function, which covers executing response plans and mitigating the incident.

  5. CIS Control 8 (Audit Log Management) is most directly aligned with which NIST CSF function?

    Answer: Detect

    Audit Log Management supports the 'Detect' function by ensuring that logs are collected, retained, and reviewed to identify anomalous activity.

  6. Which term describes a NIST CSF document that organizations can use as a starting point, tailored to a specific sector or use case?

    Answer: Community Profile

    A Community Profile is a baseline CSF profile developed collaboratively for a specific sector, technology, or use case that organizations can adapt.

  7. CIS Control 13 (Network Monitoring and Defense) primarily supports which security objective?

    Answer: Detecting and blocking malicious network traffic in real time

    CIS Control 13 focuses on monitoring network traffic to detect and respond to threats, including deploying IDS/IPS and DNS filtering.