Skip to content
Oluma Cyber Security Awareness
NIST Cybersecurity Framework Fundamentals — Practice Exam | Oluma Digital
Cert Zone · NIST Fundamentals

NIST Cybersecurity Framework Fundamentals

NIST

Oluma Digital Practice: NIST CSF 2.0 Fundamentals

The NIST Fundamentals practice page helps learners understand the NIST Cybersecurity Framework 2.0, including the Govern, Identify, Protect, Detect, Respond, and Recover functions, plus profiles, tiers, risk management, and practical framework use.

Managed by
NIST / Oluma Digital Practice
Exam code
NIST
Level
Fundamentals
Delivery
Provider dependent
Duration
Practice assessment
Passing score
Study score only
Audience
GRC and security learners
Questions here
100 practice items
Format
Multiple choice
Reference / official page → NIST

What this practice exam covers

The questions are grouped into study-friendly domains for framework, ISMS, implementation, and audit readiness.

01

CSF 2.0 structure

Govern, Identify, Protect, Detect, Respond, Recover, categories, subcategories, outcomes, and informative references.

02

Risk management basics

Assets, threats, vulnerabilities, likelihood, impact, risk tolerance, target profile, and current profile.

03

Governance and program management

Policy, accountability, strategy, supply chain risk, roles, communication, and oversight.

04

Implementation and improvement

Gap analysis, prioritization, roadmap, measurement, communication, continuous improvement, and alignment to other control frameworks.

Provider-specific NIST and ISO 27001 certificate exams can vary. Always verify the current provider syllabus before scheduling an exam.

Practice questions

Number of questions:

Pick a length, then choose an answer for instant feedback. Your score tracks below and counts only the questions you can see.

CSF 2.0 structure

Which option best describes Govern function?

✓ Access granted.  Govern function is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: Govern function. Govern function is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing Identify function. What should Identify function be associated with?

✓ Access granted.  The scenario points to Identify function, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving Identify function. The scenario points to Identify function, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is Protect function the BEST answer?

✓ Access granted.  Choose Protect function when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Protect function. Choose Protect function when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to Detect function?

✓ Access granted.  Detect function is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Detect function. Detect function is the relevant term; the other choices are unrelated distractors.
CSF 2.0 structure

Which option best describes Respond function?

✓ Access granted.  Respond function is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: Respond function. Respond function is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing Recover function. What should Recover function be associated with?

✓ Access granted.  The scenario points to Recover function, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving Recover function. The scenario points to Recover function, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is CSF Core the BEST answer?

✓ Access granted.  Choose CSF Core when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about CSF Core. Choose CSF Core when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to CSF Profile?

✓ Access granted.  CSF Profile is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: CSF Profile. CSF Profile is the relevant term; the other choices are unrelated distractors.
CSF 2.0 structure

Which option best describes Current Profile?

✓ Access granted.  Current Profile is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: Current Profile. Current Profile is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing Target Profile. What should Target Profile be associated with?

✓ Access granted.  The scenario points to Target Profile, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving Target Profile. The scenario points to Target Profile, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is CSF Tier the BEST answer?

✓ Access granted.  Choose CSF Tier when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about CSF Tier. Choose CSF Tier when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to Informative reference?

✓ Access granted.  Informative reference is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Informative reference. Informative reference is the relevant term; the other choices are unrelated distractors.
CSF 2.0 structure

Which option best describes Implementation example?

✓ Access granted.  Implementation example is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: Implementation example. Implementation example is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing Cybersecurity outcome. What should Cybersecurity outcome be associated with?

✓ Access granted.  The scenario points to Cybersecurity outcome, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving Cybersecurity outcome. The scenario points to Cybersecurity outcome, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is Risk tolerance the BEST answer?

✓ Access granted.  Choose Risk tolerance when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Risk tolerance. Choose Risk tolerance when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to Risk appetite?

✓ Access granted.  Risk appetite is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Risk appetite. Risk appetite is the relevant term; the other choices are unrelated distractors.
CSF 2.0 structure

Which option best describes Asset inventory?

✓ Access granted.  Asset inventory is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: Asset inventory. Asset inventory is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing Business environment. What should Business environment be associated with?

✓ Access granted.  The scenario points to Business environment, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving Business environment. The scenario points to Business environment, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is Governance policy the BEST answer?

✓ Access granted.  Choose Governance policy when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Governance policy. Choose Governance policy when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to Risk assessment?

✓ Access granted.  Risk assessment is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Risk assessment. Risk assessment is the relevant term; the other choices are unrelated distractors.
CSF 2.0 structure

Which option best describes Supply chain risk management?

✓ Access granted.  Supply chain risk management is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: Supply chain risk management. Supply chain risk management is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing Access control. What should Access control be associated with?

✓ Access granted.  The scenario points to Access control, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving Access control. The scenario points to Access control, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is Awareness training the BEST answer?

✓ Access granted.  Choose Awareness training when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Awareness training. Choose Awareness training when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to Data security?

✓ Access granted.  Data security is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Data security. Data security is the relevant term; the other choices are unrelated distractors.
CSF 2.0 structure

Which option best describes Protective technology?

✓ Access granted.  Protective technology is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: Protective technology. Protective technology is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing Anomalies and events. What should Anomalies and events be associated with?

✓ Access granted.  The scenario points to Anomalies and events, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving Anomalies and events. The scenario points to Anomalies and events, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is Continuous monitoring the BEST answer?

✓ Access granted.  Choose Continuous monitoring when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Continuous monitoring. Choose Continuous monitoring when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to Detection process?

✓ Access granted.  Detection process is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Detection process. Detection process is the relevant term; the other choices are unrelated distractors.
CSF 2.0 structure

Which option best describes Response planning?

✓ Access granted.  Response planning is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: Response planning. Response planning is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing Communications. What should Communications be associated with?

✓ Access granted.  The scenario points to Communications, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving Communications. The scenario points to Communications, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is Analysis the BEST answer?

✓ Access granted.  Choose Analysis when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Analysis. Choose Analysis when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to Mitigation?

✓ Access granted.  Mitigation is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Mitigation. Mitigation is the relevant term; the other choices are unrelated distractors.
CSF 2.0 structure

Which option best describes Improvements?

✓ Access granted.  Improvements is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: Improvements. Improvements is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing Recovery planning. What should Recovery planning be associated with?

✓ Access granted.  The scenario points to Recovery planning, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving Recovery planning. The scenario points to Recovery planning, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is Resilience the BEST answer?

✓ Access granted.  Choose Resilience when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Resilience. Choose Resilience when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to Lessons learned?

✓ Access granted.  Lessons learned is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Lessons learned. Lessons learned is the relevant term; the other choices are unrelated distractors.
CSF 2.0 structure

Which option best describes Enterprise risk management?

✓ Access granted.  Enterprise risk management is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: Enterprise risk management. Enterprise risk management is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing Gap assessment. What should Gap assessment be associated with?

✓ Access granted.  The scenario points to Gap assessment, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving Gap assessment. The scenario points to Gap assessment, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is Prioritization the BEST answer?

✓ Access granted.  Choose Prioritization when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Prioritization. Choose Prioritization when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to Roadmap?

✓ Access granted.  Roadmap is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Roadmap. Roadmap is the relevant term; the other choices are unrelated distractors.
CSF 2.0 structure

Which option best describes Control mapping?

✓ Access granted.  Control mapping is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: Control mapping. Control mapping is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing NIST SP 800-53. What should NIST SP 800-53 be associated with?

✓ Access granted.  The scenario points to NIST SP 800-53, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving NIST SP 800-53. The scenario points to NIST SP 800-53, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is NIST SP 800-171 the BEST answer?

✓ Access granted.  Choose NIST SP 800-171 when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about NIST SP 800-171. Choose NIST SP 800-171 when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to Framework adoption?

✓ Access granted.  Framework adoption is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Framework adoption. Framework adoption is the relevant term; the other choices are unrelated distractors.
CSF 2.0 structure

Which option best describes Executive reporting?

✓ Access granted.  Executive reporting is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: Executive reporting. Executive reporting is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing Cybersecurity metrics. What should Cybersecurity metrics be associated with?

✓ Access granted.  The scenario points to Cybersecurity metrics, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving Cybersecurity metrics. The scenario points to Cybersecurity metrics, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is Third-party risk the BEST answer?

✓ Access granted.  Choose Third-party risk when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Third-party risk. Choose Third-party risk when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to Incident lifecycle?

✓ Access granted.  Incident lifecycle is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Incident lifecycle. Incident lifecycle is the relevant term; the other choices are unrelated distractors.
CSF 2.0 structure

Which option best describes Continuous improvement?

✓ Access granted.  Continuous improvement is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: Continuous improvement. Continuous improvement is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing Risk register. What should Risk register be associated with?

✓ Access granted.  The scenario points to Risk register, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving Risk register. The scenario points to Risk register, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is Govern function the BEST answer?

✓ Access granted.  Choose Govern function when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Govern function. Choose Govern function when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to Identify function?

✓ Access granted.  Identify function is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Identify function. Identify function is the relevant term; the other choices are unrelated distractors.
CSF 2.0 structure

Which option best describes Protect function?

✓ Access granted.  Protect function is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: Protect function. Protect function is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing Detect function. What should Detect function be associated with?

✓ Access granted.  The scenario points to Detect function, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving Detect function. The scenario points to Detect function, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is Respond function the BEST answer?

✓ Access granted.  Choose Respond function when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Respond function. Choose Respond function when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to Recover function?

✓ Access granted.  Recover function is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Recover function. Recover function is the relevant term; the other choices are unrelated distractors.
CSF 2.0 structure

Which option best describes CSF Core?

✓ Access granted.  CSF Core is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: CSF Core. CSF Core is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing CSF Profile. What should CSF Profile be associated with?

✓ Access granted.  The scenario points to CSF Profile, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving CSF Profile. The scenario points to CSF Profile, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is Current Profile the BEST answer?

✓ Access granted.  Choose Current Profile when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Current Profile. Choose Current Profile when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to Target Profile?

✓ Access granted.  Target Profile is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Target Profile. Target Profile is the relevant term; the other choices are unrelated distractors.
CSF 2.0 structure

Which option best describes CSF Tier?

✓ Access granted.  CSF Tier is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: CSF Tier. CSF Tier is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing Informative reference. What should Informative reference be associated with?

✓ Access granted.  The scenario points to Informative reference, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving Informative reference. The scenario points to Informative reference, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is Implementation example the BEST answer?

✓ Access granted.  Choose Implementation example when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Implementation example. Choose Implementation example when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to Cybersecurity outcome?

✓ Access granted.  Cybersecurity outcome is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Cybersecurity outcome. Cybersecurity outcome is the relevant term; the other choices are unrelated distractors.
CSF 2.0 structure

Which option best describes Risk tolerance?

✓ Access granted.  Risk tolerance is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: Risk tolerance. Risk tolerance is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing Risk appetite. What should Risk appetite be associated with?

✓ Access granted.  The scenario points to Risk appetite, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving Risk appetite. The scenario points to Risk appetite, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is Asset inventory the BEST answer?

✓ Access granted.  Choose Asset inventory when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Asset inventory. Choose Asset inventory when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to Business environment?

✓ Access granted.  Business environment is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Business environment. Business environment is the relevant term; the other choices are unrelated distractors.
CSF 2.0 structure

Which option best describes Governance policy?

✓ Access granted.  Governance policy is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: Governance policy. Governance policy is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing Risk assessment. What should Risk assessment be associated with?

✓ Access granted.  The scenario points to Risk assessment, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving Risk assessment. The scenario points to Risk assessment, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is Supply chain risk management the BEST answer?

✓ Access granted.  Choose Supply chain risk management when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Supply chain risk management. Choose Supply chain risk management when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to Access control?

✓ Access granted.  Access control is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Access control. Access control is the relevant term; the other choices are unrelated distractors.
CSF 2.0 structure

Which option best describes Awareness training?

✓ Access granted.  Awareness training is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: Awareness training. Awareness training is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing Data security. What should Data security be associated with?

✓ Access granted.  The scenario points to Data security, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving Data security. The scenario points to Data security, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is Protective technology the BEST answer?

✓ Access granted.  Choose Protective technology when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Protective technology. Choose Protective technology when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to Anomalies and events?

✓ Access granted.  Anomalies and events is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Anomalies and events. Anomalies and events is the relevant term; the other choices are unrelated distractors.
CSF 2.0 structure

Which option best describes Continuous monitoring?

✓ Access granted.  Continuous monitoring is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: Continuous monitoring. Continuous monitoring is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing Detection process. What should Detection process be associated with?

✓ Access granted.  The scenario points to Detection process, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving Detection process. The scenario points to Detection process, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is Response planning the BEST answer?

✓ Access granted.  Choose Response planning when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Response planning. Choose Response planning when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to Communications?

✓ Access granted.  Communications is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Communications. Communications is the relevant term; the other choices are unrelated distractors.
CSF 2.0 structure

Which option best describes Analysis?

✓ Access granted.  Analysis is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: Analysis. Analysis is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing Mitigation. What should Mitigation be associated with?

✓ Access granted.  The scenario points to Mitigation, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving Mitigation. The scenario points to Mitigation, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is Improvements the BEST answer?

✓ Access granted.  Choose Improvements when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Improvements. Choose Improvements when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to Recovery planning?

✓ Access granted.  Recovery planning is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Recovery planning. Recovery planning is the relevant term; the other choices are unrelated distractors.
CSF 2.0 structure

Which option best describes Resilience?

✓ Access granted.  Resilience is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: Resilience. Resilience is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing Lessons learned. What should Lessons learned be associated with?

✓ Access granted.  The scenario points to Lessons learned, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving Lessons learned. The scenario points to Lessons learned, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is Enterprise risk management the BEST answer?

✓ Access granted.  Choose Enterprise risk management when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Enterprise risk management. Choose Enterprise risk management when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to Gap assessment?

✓ Access granted.  Gap assessment is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Gap assessment. Gap assessment is the relevant term; the other choices are unrelated distractors.
CSF 2.0 structure

Which option best describes Prioritization?

✓ Access granted.  Prioritization is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: Prioritization. Prioritization is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing Roadmap. What should Roadmap be associated with?

✓ Access granted.  The scenario points to Roadmap, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving Roadmap. The scenario points to Roadmap, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is Control mapping the BEST answer?

✓ Access granted.  Choose Control mapping when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Control mapping. Choose Control mapping when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to NIST SP 800-53?

✓ Access granted.  NIST SP 800-53 is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: NIST SP 800-53. NIST SP 800-53 is the relevant term; the other choices are unrelated distractors.
CSF 2.0 structure

Which option best describes NIST SP 800-171?

✓ Access granted.  NIST SP 800-171 is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: NIST SP 800-171. NIST SP 800-171 is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing Framework adoption. What should Framework adoption be associated with?

✓ Access granted.  The scenario points to Framework adoption, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving Framework adoption. The scenario points to Framework adoption, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is Executive reporting the BEST answer?

✓ Access granted.  Choose Executive reporting when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Executive reporting. Choose Executive reporting when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to Cybersecurity metrics?

✓ Access granted.  Cybersecurity metrics is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Cybersecurity metrics. Cybersecurity metrics is the relevant term; the other choices are unrelated distractors.
CSF 2.0 structure

Which option best describes Third-party risk?

✓ Access granted.  Third-party risk is the concept or activity most directly connected to this exam objective.
✗ Access denied.  Correct answer: Third-party risk. Third-party risk is the concept or activity most directly connected to this exam objective.
Risk management basics

A practitioner is reviewing Incident lifecycle. What should Incident lifecycle be associated with?

✓ Access granted.  The scenario points to Incident lifecycle, which is part of practical security framework and ISMS work.
✗ Access denied.  Correct answer: A governance, risk, audit, or security management activity involving Incident lifecycle. The scenario points to Incident lifecycle, which is part of practical security framework and ISMS work.
Governance and program management

In an exam scenario, when is Continuous improvement the BEST answer?

✓ Access granted.  Choose Continuous improvement when the scenario asks for that control, process, audit element, or management system concept.
✗ Access denied.  Correct answer: When the requirement specifically asks about Continuous improvement. Choose Continuous improvement when the scenario asks for that control, process, audit element, or management system concept.
Implementation and improvement

Which item is MOST relevant to Risk register?

✓ Access granted.  Risk register is the relevant term; the other choices are unrelated distractors.
✗ Access denied.  Correct answer: Risk register. Risk register is the relevant term; the other choices are unrelated distractors.

Ready to keep building your GRC skills?

Use this practice page to review the terminology, processes, and exam-style decision points before moving into provider-specific study materials.

Unofficial practice questions created by Oluma Digital for study purposes. Not affiliated with or endorsed by NIST, ISO, IEC, PECB, CertiProf, or any certification body. Always verify current objectives with the official provider.

0Correct0Answered25Visible