CCP NIST CSF & CIS Controls 3 — Questions and Answers
Question 1: An organization wants to prioritize security investments based on potential business impact. Which NIST CSF concept best supports this decision?
- Framework Tiers (Correct answer)
- Implementation Groups
- Subcategory mapping
- Risk Register
Correct answer: Framework Tiers
NIST CSF Tiers (1–4) reflect the degree to which cybersecurity risk management is integrated into business decisions, helping prioritize investments.
Question 2: CIS Control 5 (Account Management) requires which of the following as a safeguard?
- Encrypting all data at rest
- Disabling dormant accounts after a defined period (Correct answer)
- Deploying endpoint detection on all systems
- Implementing multi-factor authentication only for admins
Correct answer: Disabling dormant accounts after a defined period
CIS Control 5 requires disabling or removing dormant accounts to reduce the attack surface from unused credentials.
Question 3: Which NIST CSF 'Protect' category addresses limiting access to only what is necessary for users to perform their job functions?
- Awareness and Training
- Identity Management and Access Control (Correct answer)
- Data Security
- Platform Security
Correct answer: Identity Management and Access Control
The 'Identity Management and Access Control' category enforces least privilege and ensures access is limited to what is necessary for job functions.
Question 4: A security analyst discovers a zero-day vulnerability actively exploited in the wild. Under which NIST CSF function should the organization's immediate response activities fall?
- Identify
- Protect
- Detect
- Respond (Correct answer)
Correct answer: Respond
Active exploitation of a vulnerability triggers the 'Respond' function, which covers executing response plans and mitigating the incident.
Question 5: CIS Control 8 (Audit Log Management) is most directly aligned with which NIST CSF function?
- Identify
- Protect
- Detect (Correct answer)
- Recover
Correct answer: Detect
Audit Log Management supports the 'Detect' function by ensuring that logs are collected, retained, and reviewed to identify anomalous activity.
Question 6: Which term describes a NIST CSF document that organizations can use as a starting point, tailored to a specific sector or use case?
- Framework Core
- Community Profile (Correct answer)
- Implementation Tier
- Informative Reference
Correct answer: Community Profile
A Community Profile is a baseline CSF profile developed collaboratively for a specific sector, technology, or use case that organizations can adapt.
Question 7: CIS Control 13 (Network Monitoring and Defense) primarily supports which security objective?
- Ensuring secure configuration of all network devices
- Detecting and blocking malicious network traffic in real time (Correct answer)
- Managing authorized and unauthorized software
- Encrypting all network communications
Correct answer: Detecting and blocking malicious network traffic in real time
CIS Control 13 focuses on monitoring network traffic to detect and respond to threats, including deploying IDS/IPS and DNS filtering.
An organization wants to prioritize security investments based on potential business impact.
Which NIST CSF concept best supports this decision?