NIST Cybersecurity Framework Fundamentals — Practice Exam | Oluma DigitalCert Zone · NIST FundamentalsNIST Cybersecurity Framework FundamentalsNISTOluma Digital Practice: NIST CSF 2.0 FundamentalsThe NIST Fundamentals practice page helps learners understand the NIST Cybersecurity Framework 2.0, including the Govern, Identify, Protect, Detect, Respond, and Recover functions, plus profiles, tiers, risk management, and practical framework use.Managed byNIST / Oluma Digital PracticeExam codeNISTLevelFundamentalsDeliveryProvider dependentDurationPractice assessmentPassing scoreStudy score onlyAudienceGRC and security learnersQuestions here100 practice itemsFormatMultiple choiceReference / official page → NISTWhat this practice exam coversThe questions are grouped into study-friendly domains for framework, ISMS, implementation, and audit readiness.01CSF 2.0 structureGovern, Identify, Protect, Detect, Respond, Recover, categories, subcategories, outcomes, and informative references.02Risk management basicsAssets, threats, vulnerabilities, likelihood, impact, risk tolerance, target profile, and current profile.03Governance and program managementPolicy, accountability, strategy, supply chain risk, roles, communication, and oversight.04Implementation and improvementGap analysis, prioritization, roadmap, measurement, communication, continuous improvement, and alignment to other control frameworks.Provider-specific NIST and ISO 27001 certificate exams can vary. Always verify the current provider syllabus before scheduling an exam.Practice questionsNumber of questions:102550All 100Pick a length, then choose an answer for instant feedback. Your score tracks below and counts only the questions you can see.CSF 2.0 structureWhich option best describes Govern function?AGovern functionBA generic file nameCA printer tray settingDA marketing campaign✓ Access granted. Govern function is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: Govern function. Govern function is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing Identify function. What should Identify function be associated with?AA video transitionBA marketing campaignCA browser bookmark onlyDA governance, risk, audit, or security management activity involving Identify function✓ Access granted. The scenario points to Identify function, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving Identify function. The scenario points to Identify function, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is Protect function the BEST answer?AA social media postBA payroll processCWhen the requirement specifically asks about Protect functionDAn email signature template✓ Access granted. Choose Protect function when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about Protect function. Choose Protect function when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to Detect function?AA browser bookmark onlyBDetect functionCA video transitionDA generic file name✓ Access granted. Detect function is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: Detect function. Detect function is the relevant term; the other choices are unrelated distractors.CSF 2.0 structureWhich option best describes Respond function?ARespond functionBA generic file nameCA social media postDA furniture layout✓ Access granted. Respond function is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: Respond function. Respond function is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing Recover function. What should Recover function be associated with?AA personal calendar reminderBA browser bookmark onlyCA printer tray settingDA governance, risk, audit, or security management activity involving Recover function✓ Access granted. The scenario points to Recover function, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving Recover function. The scenario points to Recover function, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is CSF Core the BEST answer?AA video transitionBA conference badge colorCWhen the requirement specifically asks about CSF CoreDA browser bookmark only✓ Access granted. Choose CSF Core when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about CSF Core. Choose CSF Core when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to CSF Profile?AA furniture layoutBCSF ProfileCA generic file nameDA social media post✓ Access granted. CSF Profile is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: CSF Profile. CSF Profile is the relevant term; the other choices are unrelated distractors.CSF 2.0 structureWhich option best describes Current Profile?ACurrent ProfileBA payroll processCA personal calendar reminderDA video transition✓ Access granted. Current Profile is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: Current Profile. Current Profile is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing Target Profile. What should Target Profile be associated with?AA marketing campaignBA browser bookmark onlyCA generic file nameDA governance, risk, audit, or security management activity involving Target Profile✓ Access granted. The scenario points to Target Profile, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving Target Profile. The scenario points to Target Profile, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is CSF Tier the BEST answer?AA marketing campaignBA video transitionCWhen the requirement specifically asks about CSF TierDA personal calendar reminder✓ Access granted. Choose CSF Tier when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about CSF Tier. Choose CSF Tier when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to Informative reference?AA printer tray settingBInformative referenceCA browser bookmark onlyDAn email signature template✓ Access granted. Informative reference is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: Informative reference. Informative reference is the relevant term; the other choices are unrelated distractors.CSF 2.0 structureWhich option best describes Implementation example?AImplementation exampleBA browser bookmark onlyCA graphic design effectDA marketing campaign✓ Access granted. Implementation example is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: Implementation example. Implementation example is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing Cybersecurity outcome. What should Cybersecurity outcome be associated with?AA payroll processBA generic file nameCA conference badge colorDA governance, risk, audit, or security management activity involving Cybersecurity outcome✓ Access granted. The scenario points to Cybersecurity outcome, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving Cybersecurity outcome. The scenario points to Cybersecurity outcome, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is Risk tolerance the BEST answer?AA printer tray settingBA graphic design effectCWhen the requirement specifically asks about Risk toleranceDA personal calendar reminder✓ Access granted. Choose Risk tolerance when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about Risk tolerance. Choose Risk tolerance when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to Risk appetite?AAn email signature templateBRisk appetiteCA printer tray settingDA graphic design effect✓ Access granted. Risk appetite is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: Risk appetite. Risk appetite is the relevant term; the other choices are unrelated distractors.CSF 2.0 structureWhich option best describes Asset inventory?AAsset inventoryBA browser bookmark onlyCA graphic design effectDA video transition✓ Access granted. Asset inventory is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: Asset inventory. Asset inventory is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing Business environment. What should Business environment be associated with?AA browser bookmark onlyBA marketing campaignCA personal calendar reminderDA governance, risk, audit, or security management activity involving Business environment✓ Access granted. The scenario points to Business environment, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving Business environment. The scenario points to Business environment, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is Governance policy the BEST answer?AA video transitionBA marketing campaignCWhen the requirement specifically asks about Governance policyDA generic file name✓ Access granted. Choose Governance policy when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about Governance policy. Choose Governance policy when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to Risk assessment?AA personal calendar reminderBRisk assessmentCA generic file nameDA furniture layout✓ Access granted. Risk assessment is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: Risk assessment. Risk assessment is the relevant term; the other choices are unrelated distractors.CSF 2.0 structureWhich option best describes Supply chain risk management?ASupply chain risk managementBA browser bookmark onlyCA furniture layoutDAn email signature template✓ Access granted. Supply chain risk management is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: Supply chain risk management. Supply chain risk management is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing Access control. What should Access control be associated with?AA payroll processBA personal calendar reminderCA printer tray settingDA governance, risk, audit, or security management activity involving Access control✓ Access granted. The scenario points to Access control, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving Access control. The scenario points to Access control, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is Awareness training the BEST answer?AA social media postBAn email signature templateCWhen the requirement specifically asks about Awareness trainingDA personal calendar reminder✓ Access granted. Choose Awareness training when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about Awareness training. Choose Awareness training when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to Data security?AA personal calendar reminderBData securityCA browser bookmark onlyDA printer tray setting✓ Access granted. Data security is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: Data security. Data security is the relevant term; the other choices are unrelated distractors.CSF 2.0 structureWhich option best describes Protective technology?AProtective technologyBA video transitionCA conference badge colorDA personal calendar reminder✓ Access granted. Protective technology is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: Protective technology. Protective technology is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing Anomalies and events. What should Anomalies and events be associated with?AA browser bookmark onlyBAn email signature templateCA marketing campaignDA governance, risk, audit, or security management activity involving Anomalies and events✓ Access granted. The scenario points to Anomalies and events, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving Anomalies and events. The scenario points to Anomalies and events, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is Continuous monitoring the BEST answer?AA marketing campaignBA video transitionCWhen the requirement specifically asks about Continuous monitoringDA graphic design effect✓ Access granted. Choose Continuous monitoring when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about Continuous monitoring. Choose Continuous monitoring when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to Detection process?AA printer tray settingBDetection processCA payroll processDA furniture layout✓ Access granted. Detection process is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: Detection process. Detection process is the relevant term; the other choices are unrelated distractors.CSF 2.0 structureWhich option best describes Response planning?AResponse planningBA graphic design effectCAn email signature templateDA personal calendar reminder✓ Access granted. Response planning is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: Response planning. Response planning is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing Communications. What should Communications be associated with?AA conference badge colorBA browser bookmark onlyCA generic file nameDA governance, risk, audit, or security management activity involving Communications✓ Access granted. The scenario points to Communications, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving Communications. The scenario points to Communications, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is Analysis the BEST answer?AAn email signature templateBA furniture layoutCWhen the requirement specifically asks about AnalysisDA conference badge color✓ Access granted. Choose Analysis when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about Analysis. Choose Analysis when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to Mitigation?AAn email signature templateBMitigationCA printer tray settingDA social media post✓ Access granted. Mitigation is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: Mitigation. Mitigation is the relevant term; the other choices are unrelated distractors.CSF 2.0 structureWhich option best describes Improvements?AImprovementsBA printer tray settingCA graphic design effectDA marketing campaign✓ Access granted. Improvements is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: Improvements. Improvements is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing Recovery planning. What should Recovery planning be associated with?AA printer tray settingBA furniture layoutCA social media postDA governance, risk, audit, or security management activity involving Recovery planning✓ Access granted. The scenario points to Recovery planning, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving Recovery planning. The scenario points to Recovery planning, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is Resilience the BEST answer?AA browser bookmark onlyBA printer tray settingCWhen the requirement specifically asks about ResilienceDA generic file name✓ Access granted. Choose Resilience when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about Resilience. Choose Resilience when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to Lessons learned?AA generic file nameBLessons learnedCA furniture layoutDA graphic design effect✓ Access granted. Lessons learned is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: Lessons learned. Lessons learned is the relevant term; the other choices are unrelated distractors.CSF 2.0 structureWhich option best describes Enterprise risk management?AEnterprise risk managementBA payroll processCA conference badge colorDA furniture layout✓ Access granted. Enterprise risk management is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: Enterprise risk management. Enterprise risk management is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing Gap assessment. What should Gap assessment be associated with?AA furniture layoutBA printer tray settingCA social media postDA governance, risk, audit, or security management activity involving Gap assessment✓ Access granted. The scenario points to Gap assessment, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving Gap assessment. The scenario points to Gap assessment, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is Prioritization the BEST answer?AA printer tray settingBA browser bookmark onlyCWhen the requirement specifically asks about PrioritizationDAn email signature template✓ Access granted. Choose Prioritization when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about Prioritization. Choose Prioritization when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to Roadmap?AA marketing campaignBRoadmapCA printer tray settingDA video transition✓ Access granted. Roadmap is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: Roadmap. Roadmap is the relevant term; the other choices are unrelated distractors.CSF 2.0 structureWhich option best describes Control mapping?AControl mappingBA conference badge colorCA marketing campaignDA printer tray setting✓ Access granted. Control mapping is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: Control mapping. Control mapping is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing NIST SP 800-53. What should NIST SP 800-53 be associated with?AA graphic design effectBA personal calendar reminderCA payroll processDA governance, risk, audit, or security management activity involving NIST SP 800-53✓ Access granted. The scenario points to NIST SP 800-53, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving NIST SP 800-53. The scenario points to NIST SP 800-53, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is NIST SP 800-171 the BEST answer?AA video transitionBA personal calendar reminderCWhen the requirement specifically asks about NIST SP 800-171DA printer tray setting✓ Access granted. Choose NIST SP 800-171 when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about NIST SP 800-171. Choose NIST SP 800-171 when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to Framework adoption?AA generic file nameBFramework adoptionCA video transitionDA payroll process✓ Access granted. Framework adoption is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: Framework adoption. Framework adoption is the relevant term; the other choices are unrelated distractors.CSF 2.0 structureWhich option best describes Executive reporting?AExecutive reportingBA furniture layoutCA printer tray settingDA graphic design effect✓ Access granted. Executive reporting is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: Executive reporting. Executive reporting is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing Cybersecurity metrics. What should Cybersecurity metrics be associated with?AA graphic design effectBA generic file nameCA browser bookmark onlyDA governance, risk, audit, or security management activity involving Cybersecurity metrics✓ Access granted. The scenario points to Cybersecurity metrics, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving Cybersecurity metrics. The scenario points to Cybersecurity metrics, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is Third-party risk the BEST answer?AA generic file nameBA payroll processCWhen the requirement specifically asks about Third-party riskDA personal calendar reminder✓ Access granted. Choose Third-party risk when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about Third-party risk. Choose Third-party risk when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to Incident lifecycle?AA personal calendar reminderBIncident lifecycleCA social media postDA conference badge color✓ Access granted. Incident lifecycle is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: Incident lifecycle. Incident lifecycle is the relevant term; the other choices are unrelated distractors.CSF 2.0 structureWhich option best describes Continuous improvement?AContinuous improvementBA social media postCA furniture layoutDA marketing campaign✓ Access granted. Continuous improvement is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: Continuous improvement. Continuous improvement is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing Risk register. What should Risk register be associated with?AAn email signature templateBA marketing campaignCA furniture layoutDA governance, risk, audit, or security management activity involving Risk register✓ Access granted. The scenario points to Risk register, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving Risk register. The scenario points to Risk register, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is Govern function the BEST answer?AA graphic design effectBA conference badge colorCWhen the requirement specifically asks about Govern functionDA video transition✓ Access granted. Choose Govern function when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about Govern function. Choose Govern function when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to Identify function?AAn email signature templateBIdentify functionCA social media postDA payroll process✓ Access granted. Identify function is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: Identify function. Identify function is the relevant term; the other choices are unrelated distractors.CSF 2.0 structureWhich option best describes Protect function?AProtect functionBA social media postCA generic file nameDA marketing campaign✓ Access granted. Protect function is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: Protect function. Protect function is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing Detect function. What should Detect function be associated with?AA video transitionBA browser bookmark onlyCA marketing campaignDA governance, risk, audit, or security management activity involving Detect function✓ Access granted. The scenario points to Detect function, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving Detect function. The scenario points to Detect function, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is Respond function the BEST answer?AA graphic design effectBA social media postCWhen the requirement specifically asks about Respond functionDA printer tray setting✓ Access granted. Choose Respond function when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about Respond function. Choose Respond function when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to Recover function?AA furniture layoutBRecover functionCA graphic design effectDA marketing campaign✓ Access granted. Recover function is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: Recover function. Recover function is the relevant term; the other choices are unrelated distractors.CSF 2.0 structureWhich option best describes CSF Core?ACSF CoreBA generic file nameCA social media postDA furniture layout✓ Access granted. CSF Core is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: CSF Core. CSF Core is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing CSF Profile. What should CSF Profile be associated with?AA furniture layoutBA social media postCA browser bookmark onlyDA governance, risk, audit, or security management activity involving CSF Profile✓ Access granted. The scenario points to CSF Profile, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving CSF Profile. The scenario points to CSF Profile, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is Current Profile the BEST answer?AA furniture layoutBAn email signature templateCWhen the requirement specifically asks about Current ProfileDA graphic design effect✓ Access granted. Choose Current Profile when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about Current Profile. Choose Current Profile when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to Target Profile?AA social media postBTarget ProfileCA marketing campaignDA video transition✓ Access granted. Target Profile is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: Target Profile. Target Profile is the relevant term; the other choices are unrelated distractors.CSF 2.0 structureWhich option best describes CSF Tier?ACSF TierBA video transitionCA printer tray settingDA browser bookmark only✓ Access granted. CSF Tier is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: CSF Tier. CSF Tier is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing Informative reference. What should Informative reference be associated with?AA printer tray settingBA graphic design effectCA social media postDA governance, risk, audit, or security management activity involving Informative reference✓ Access granted. The scenario points to Informative reference, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving Informative reference. The scenario points to Informative reference, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is Implementation example the BEST answer?AA payroll processBA generic file nameCWhen the requirement specifically asks about Implementation exampleDA printer tray setting✓ Access granted. Choose Implementation example when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about Implementation example. Choose Implementation example when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to Cybersecurity outcome?AA video transitionBCybersecurity outcomeCA printer tray settingDA payroll process✓ Access granted. Cybersecurity outcome is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: Cybersecurity outcome. Cybersecurity outcome is the relevant term; the other choices are unrelated distractors.CSF 2.0 structureWhich option best describes Risk tolerance?ARisk toleranceBA personal calendar reminderCA conference badge colorDA video transition✓ Access granted. Risk tolerance is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: Risk tolerance. Risk tolerance is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing Risk appetite. What should Risk appetite be associated with?AA graphic design effectBA video transitionCA social media postDA governance, risk, audit, or security management activity involving Risk appetite✓ Access granted. The scenario points to Risk appetite, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving Risk appetite. The scenario points to Risk appetite, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is Asset inventory the BEST answer?AA social media postBA conference badge colorCWhen the requirement specifically asks about Asset inventoryDA browser bookmark only✓ Access granted. Choose Asset inventory when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about Asset inventory. Choose Asset inventory when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to Business environment?AA furniture layoutBBusiness environmentCA social media postDA video transition✓ Access granted. Business environment is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: Business environment. Business environment is the relevant term; the other choices are unrelated distractors.CSF 2.0 structureWhich option best describes Governance policy?AGovernance policyBA video transitionCAn email signature templateDA furniture layout✓ Access granted. Governance policy is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: Governance policy. Governance policy is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing Risk assessment. What should Risk assessment be associated with?AA printer tray settingBA marketing campaignCAn email signature templateDA governance, risk, audit, or security management activity involving Risk assessment✓ Access granted. The scenario points to Risk assessment, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving Risk assessment. The scenario points to Risk assessment, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is Supply chain risk management the BEST answer?AA graphic design effectBAn email signature templateCWhen the requirement specifically asks about Supply chain risk managementDA marketing campaign✓ Access granted. Choose Supply chain risk management when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about Supply chain risk management. Choose Supply chain risk management when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to Access control?AA conference badge colorBAccess controlCA generic file nameDA graphic design effect✓ Access granted. Access control is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: Access control. Access control is the relevant term; the other choices are unrelated distractors.CSF 2.0 structureWhich option best describes Awareness training?AAwareness trainingBA browser bookmark onlyCA social media postDA graphic design effect✓ Access granted. Awareness training is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: Awareness training. Awareness training is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing Data security. What should Data security be associated with?AA video transitionBA payroll processCA browser bookmark onlyDA governance, risk, audit, or security management activity involving Data security✓ Access granted. The scenario points to Data security, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving Data security. The scenario points to Data security, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is Protective technology the BEST answer?AA browser bookmark onlyBA social media postCWhen the requirement specifically asks about Protective technologyDAn email signature template✓ Access granted. Choose Protective technology when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about Protective technology. Choose Protective technology when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to Anomalies and events?AA conference badge colorBAnomalies and eventsCA video transitionDA marketing campaign✓ Access granted. Anomalies and events is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: Anomalies and events. Anomalies and events is the relevant term; the other choices are unrelated distractors.CSF 2.0 structureWhich option best describes Continuous monitoring?AContinuous monitoringBA browser bookmark onlyCA payroll processDA conference badge color✓ Access granted. Continuous monitoring is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: Continuous monitoring. Continuous monitoring is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing Detection process. What should Detection process be associated with?AA furniture layoutBA social media postCA printer tray settingDA governance, risk, audit, or security management activity involving Detection process✓ Access granted. The scenario points to Detection process, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving Detection process. The scenario points to Detection process, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is Response planning the BEST answer?AA furniture layoutBA generic file nameCWhen the requirement specifically asks about Response planningDA social media post✓ Access granted. Choose Response planning when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about Response planning. Choose Response planning when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to Communications?AAn email signature templateBCommunicationsCA marketing campaignDA graphic design effect✓ Access granted. Communications is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: Communications. Communications is the relevant term; the other choices are unrelated distractors.CSF 2.0 structureWhich option best describes Analysis?AAnalysisBA generic file nameCA social media postDA conference badge color✓ Access granted. Analysis is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: Analysis. Analysis is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing Mitigation. What should Mitigation be associated with?AA browser bookmark onlyBA social media postCA video transitionDA governance, risk, audit, or security management activity involving Mitigation✓ Access granted. The scenario points to Mitigation, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving Mitigation. The scenario points to Mitigation, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is Improvements the BEST answer?AA conference badge colorBA graphic design effectCWhen the requirement specifically asks about ImprovementsDA social media post✓ Access granted. Choose Improvements when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about Improvements. Choose Improvements when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to Recovery planning?AA video transitionBRecovery planningCA browser bookmark onlyDA marketing campaign✓ Access granted. Recovery planning is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: Recovery planning. Recovery planning is the relevant term; the other choices are unrelated distractors.CSF 2.0 structureWhich option best describes Resilience?AResilienceBA printer tray settingCA graphic design effectDA furniture layout✓ Access granted. Resilience is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: Resilience. Resilience is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing Lessons learned. What should Lessons learned be associated with?AAn email signature templateBA personal calendar reminderCA graphic design effectDA governance, risk, audit, or security management activity involving Lessons learned✓ Access granted. The scenario points to Lessons learned, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving Lessons learned. The scenario points to Lessons learned, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is Enterprise risk management the BEST answer?AA payroll processBAn email signature templateCWhen the requirement specifically asks about Enterprise risk managementDA printer tray setting✓ Access granted. Choose Enterprise risk management when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about Enterprise risk management. Choose Enterprise risk management when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to Gap assessment?AA personal calendar reminderBGap assessmentCA furniture layoutDA printer tray setting✓ Access granted. Gap assessment is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: Gap assessment. Gap assessment is the relevant term; the other choices are unrelated distractors.CSF 2.0 structureWhich option best describes Prioritization?APrioritizationBA marketing campaignCAn email signature templateDA personal calendar reminder✓ Access granted. Prioritization is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: Prioritization. Prioritization is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing Roadmap. What should Roadmap be associated with?AA social media postBA personal calendar reminderCA furniture layoutDA governance, risk, audit, or security management activity involving Roadmap✓ Access granted. The scenario points to Roadmap, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving Roadmap. The scenario points to Roadmap, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is Control mapping the BEST answer?AA printer tray settingBA video transitionCWhen the requirement specifically asks about Control mappingDA generic file name✓ Access granted. Choose Control mapping when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about Control mapping. Choose Control mapping when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to NIST SP 800-53?AA furniture layoutBNIST SP 800-53CAn email signature templateDA browser bookmark only✓ Access granted. NIST SP 800-53 is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: NIST SP 800-53. NIST SP 800-53 is the relevant term; the other choices are unrelated distractors.CSF 2.0 structureWhich option best describes NIST SP 800-171?ANIST SP 800-171BA payroll processCA video transitionDA printer tray setting✓ Access granted. NIST SP 800-171 is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: NIST SP 800-171. NIST SP 800-171 is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing Framework adoption. What should Framework adoption be associated with?AA marketing campaignBA printer tray settingCA conference badge colorDA governance, risk, audit, or security management activity involving Framework adoption✓ Access granted. The scenario points to Framework adoption, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving Framework adoption. The scenario points to Framework adoption, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is Executive reporting the BEST answer?AA conference badge colorBA marketing campaignCWhen the requirement specifically asks about Executive reportingDA video transition✓ Access granted. Choose Executive reporting when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about Executive reporting. Choose Executive reporting when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to Cybersecurity metrics?AA social media postBCybersecurity metricsCA printer tray settingDA conference badge color✓ Access granted. Cybersecurity metrics is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: Cybersecurity metrics. Cybersecurity metrics is the relevant term; the other choices are unrelated distractors.CSF 2.0 structureWhich option best describes Third-party risk?AThird-party riskBA furniture layoutCA graphic design effectDA video transition✓ Access granted. Third-party risk is the concept or activity most directly connected to this exam objective.✗ Access denied. Correct answer: Third-party risk. Third-party risk is the concept or activity most directly connected to this exam objective.Risk management basicsA practitioner is reviewing Incident lifecycle. What should Incident lifecycle be associated with?AA video transitionBA printer tray settingCA conference badge colorDA governance, risk, audit, or security management activity involving Incident lifecycle✓ Access granted. The scenario points to Incident lifecycle, which is part of practical security framework and ISMS work.✗ Access denied. Correct answer: A governance, risk, audit, or security management activity involving Incident lifecycle. The scenario points to Incident lifecycle, which is part of practical security framework and ISMS work.Governance and program managementIn an exam scenario, when is Continuous improvement the BEST answer?AA printer tray settingBA payroll processCWhen the requirement specifically asks about Continuous improvementDA conference badge color✓ Access granted. Choose Continuous improvement when the scenario asks for that control, process, audit element, or management system concept.✗ Access denied. Correct answer: When the requirement specifically asks about Continuous improvement. Choose Continuous improvement when the scenario asks for that control, process, audit element, or management system concept.Implementation and improvementWhich item is MOST relevant to Risk register?AA browser bookmark onlyBRisk registerCA video transitionDA graphic design effect✓ Access granted. Risk register is the relevant term; the other choices are unrelated distractors.✗ Access denied. Correct answer: Risk register. Risk register is the relevant term; the other choices are unrelated distractors.Ready to keep building your GRC skills?Use this practice page to review the terminology, processes, and exam-style decision points before moving into provider-specific study materials.Reference pageBack to Cert ZoneUnofficial practice questions created by Oluma Digital for study purposes. Not affiliated with or endorsed by NIST, ISO, IEC, PECB, CertiProf, or any certification body. Always verify current objectives with the official provider.0Correct0Answered25VisibleRestart