CCP NIST CSF & CIS Controls 2 — Questions and Answers
Question 1: Which NIST CSF 2.0 function was added as a new core function compared to the original 2014 version?
- Detect
- Govern (Correct answer)
- Protect
- Recover
Correct answer: Govern
NIST CSF 2.0 added the 'Govern' function to emphasize cybersecurity governance and risk management strategy.
Question 2: CIS Control 1 (Inventory and Control of Enterprise Assets) is primarily designed to address which risk?
- Unmanaged or unknown assets that can be exploited (Correct answer)
- Weak password policies on known devices
- Misconfigured firewall rules
- Insufficient logging on servers
Correct answer: Unmanaged or unknown assets that can be exploited
CIS Control 1 addresses the risk that unmanaged or unknown assets cannot be protected, making them prime targets for attackers.
Question 3: In the NIST CSF, which category under the 'Identify' function addresses understanding the organization's mission, objectives, and stakeholders?
- Asset Management
- Risk Assessment
- Organizational Context (Correct answer)
- Supply Chain Risk Management
Correct answer: Organizational Context
The 'Organizational Context' category under Identify helps organizations understand their mission, stakeholders, dependencies, and legal requirements.
Question 4: CIS Controls are organized into three Implementation Groups (IGs). Which IG is appropriate for large enterprises with dedicated security staff?
- IG1
- IG2
- IG3 (Correct answer)
- IG4
Correct answer: IG3
IG3 targets large enterprises with significant cybersecurity resources and addresses sophisticated, targeted attacks.
Question 5: A company maps its existing security controls to the NIST CSF to identify gaps. This activity is best described as:
- Threat modeling
- Current Profile creation (Correct answer)
- Target Profile creation
- Risk quantification
Correct answer: Current Profile creation
A Current Profile documents the cybersecurity outcomes an organization currently achieves, enabling gap analysis against a Target Profile.
Question 6: Which CIS Control specifically addresses the use of application software security practices such as input validation and secure coding?
- CIS Control 14 (Security Awareness)
- CIS Control 16 (Application Software Security) (Correct answer)
- CIS Control 12 (Network Infrastructure Management)
- CIS Control 18 (Penetration Testing)
Correct answer: CIS Control 16 (Application Software Security)
CIS Control 16 focuses on application software security, including secure coding practices, code review, and vulnerability management for applications.
Question 7: Under NIST CSF's 'Respond' function, which category focuses on executing a response plan and coordinating with stakeholders during an incident?
- Incident Management
- Response Planning
- Communications (Correct answer)
- Analysis
Correct answer: Communications
The 'Communications' category ensures that response activities are coordinated with internal and external stakeholders, including law enforcement and media as appropriate.
Which NIST CSF 2.0 function was added as a new core function compared to the original 2014 version?