Exam Code : D-CSF-SC-23
Exam Name : NIST Cybersecurity Framework 2023 Certification
Vendor Name :
"DELL-EMC"
D-CSF-SC-23 Dumps
D-CSF-SC-23 Braindumps
D-CSF-SC-23 Real Questions D-CSF-SC-23 Practice Test
D-CSF-SC-23 Actual Questions
killexams.com
NIST Cybersecurity Framework 2023 Certification
https://killexams.com/pass4sure/exam-detail/D-CSF-SC-23
What could be considered a set of cybersecurity activities, desired outcomes, and applicable references that are common across critical infrastructure sectors and align to five concurrent and continuous functions?
Baseline
Core
Profile
Governance
Your organizationâs security team has been working with various business units to understand their business requirements, risk tolerance, and resources used to create a Framework Profile. Based on the Profile provided, what entries correspond to labels A, B, and C?
Option A
Option B
Option C
Answer: A
Question: 3
What term refers to a partially equipped, environmentally conditioned work space used to relocate operations in the event of a significant disruption?
Hot site
Warm site
Mirror site
Secondary site
What common process conducted by organizations when protecting digital assets is outside the scope of the NIST Cybersecurity Framework?
Recover
Identify
Protect
Investigate
What are the main components of the NIST Cybersecurity Framework?
Core, Categories, and Tiers
Functions, Profiles, and Tiers
Categories, Tiers, and Profiles
Core, Tiers, and Profiles
The Disaster Recovery Plan must document what effort in order to address unrecoverable assets?
RTO savings
Recovery priority
Recovery resources
Recovery resources
To generate an accurate risk assessment, organizations need to gather information in what areas?
Assets, Threats, Vulnerabilities, and Impact
Assets, Vulnerabilities, Security, and Response
Inventory, Security, Response, and Impact
Inventory, Threats, Security, and Impact
You need to review your current security baseline policy for your company and determine which security controls need to be applied to the baseline and what changes have occurred since the last update.
Which category addresses this need?
I
AM
P
IP
P
MA
I
SC
What specifically addresses cyber-attacks against an organization's IT systems?
Continuity of Support Plan
Business Continuity Plan
Continuity of Operations Plan
Incident Response Plan
The CSF recommends that the Communication Plan for an IRP include audience, method of communication, frequency, and what other element?
Incident category
Message criteria
Incident severity
Templates to use
You have completed a review of your current security baseline policy. In order to minimize financial, legal, and reputational damage, the baseline configuration requires that infrastructure be categorized for the BIA.
Which categorizations are necessary for the BIA?
Mission critical and business critical only
Mission critical, safety critical, and business critical
Security critical, safety critical, and business critical
Mission critical and safety critical only
In accordance with PR.MA, an organization has just truncated all log files that are more than 12 months old. This has freed up 25 TB per logging server.
What must be updated once the transaction is verified?
SDLC
IRP
Baseline
ISCM
What activity informs situational awareness of the security status of an organization's systems?
IDP
RMF
ISCM
DPI
What is the effect of changing the Baseline defined in the NIST Cybersecurity Framework?
Negative impact on recovery
Does not result in changes to the BIA
Positive impact on detection
Review of previously generated alerts
The network security team in your company has discovered a threat that leaked partial data on a compromised file server that handles sensitive information. Containment must be initiated and addresses by the CSIRT. Service
disruption is not a concern because this server is used only to store files and does not hold any critical workload. Your company security policy required that all forensic information must be preserved.
Which actions should you take to stop data leakage and comply with requirements of the company security policy?
Disconnect the file server from the network to stop data leakage and keep it powered on for further analysis.
Shut down the server to stop the data leakage and power it up only for further forensic analysis.
Restart the server to purge all malicious connections and keep it powered on for further analysis.
Create a firewall rule to block all external connections for this file server and keep it powered on for further analysis.
Which category addresses the detection of unauthorized code in software?
P
DS
D
DP
P
AT
D
CM
Which phase in the SDLC is most concerned with maintaining proper authentication of users and processes to ensure an appropriate access control policy is defined?
Implementation
Operation / Maintenance
Initiation
Development / Acquisition
A company failed to detect a breach of their production system. The breach originated from a legacy system that was originally thought to be decommissioned. It turned out that system was still operating and occasionally connected to the production system for reporting purposes.
Which part of the process failed?
D
CM
I
BE
I
AM
P
DS
A company implemented an intrusion detection system. They notice the system generates a very large number of false alarms.
What steps should the company take to rectify this situation?
Re-evaluate the Baseline and make necessary adjustments to the detection rules
Replace the intrusion detection system with an intrusion protection system
Define how to identify and disregard the false alarms
Consider evaluating a system from another vendor
What are the five categories that make up the Response function?
Response Planning, Data Security, Communications, Analysis, and Mitigation
Response Planning, Communications, Analysis, Mitigation, and Improvements
Mitigation, Improvements, Maintenance, Response Planning, and Governance
Awareness and Training, Improvements, Communications, Analysis, and Governance
What is the purpose of the Asset Management category?
Prevent unauthorized access, damage, and interference to business premises and information
Support asset management strategy and information infrastructure security policies
Avoid breaches of any criminal or civil law, statutory, regulatory, or contractual obligations
Inventory physical devices and systems, software platform and applications, and communication flows
What is a consideration when performing data collection in Information Security Continuous Monitoring?
Data collection efficiency is increased through automation.
The more data collected, the better chances to catch an anomaly.
Collection is used only for compliance requirements.
Data is best captured as it traverses the network.
What database is used to record and manage assets?
Configuration Management Database
Asset Inventory Management Database
High Availability Mirrored Database
Patch Management Inventory Database
What is used to ensure an organization understands the security risk to operations, assets, and individuals?
Risk Management Strategy
Risk Assessment
Operational Assessment
Risk Profile
What is the purpose of separation of duties?
Internal control to prevent fraud
Enhance exposure to functional areas
Encourage collaboration
Mitigate collusion and prevent theft
A bank has been alerted to a breach of its reconciliation systems. The notification came from the cybercriminals claiming responsibility in an email to the CEO. The CEO has alerted the company CSIRT.
What does the Communication Plan for the IRP specifically guide against?
Transfer of chain of custody
Accelerated turn over
Rushed disclosure
Initiating kill chain
An organization has a policy to respond âASAPâ to security incidents. The security team is having a difficult time
prioritizing events because they are responding to all of them, in order of receipt. Which part of the IRP does the team need to implement or update?
Scheduling of incident responses
âPost mortemâ documentation
Classification of incidents
Containment of incidents
What determines the technical controls used to restrict access to USB devices and help prevent their use within a company?
Block use of the USB devices for all employees
Written security policy prohibiting the use of the USB devices
Acceptable use policy in the employee HR on-boarding training
Detect use of the USB devices and report users
What helps an organization compare an "as-is, to-be" document and identify opportunities for improving cybersecurity posture useful for capturing organizational baselines of today and their desired state of tomorrow so that a gap analysis can be conducted?
Framework
Core
Assessment
Profile
The CSIRT team is following the existing recovery plans on non-production systems in a PRE-BREACH scenario. This action is being executed in which function?
Protect
Recover
Identify
Respond
What is the purpose of a baseline assessment?
Enhance data integrity
Determine costs
Reduce deployment time
Determine risk
What is the main goal of a gap analysis in the Identify function?
Determine security controls to improve security measures
Determine actions required to get from the current profile state to the target profile state
Identify gaps between Cybersecurity Framework and Cyber Resilient Lifecycle pertaining to that function
Identify business process gaps to improve business efficiency
What is concerned with availability, reliability, and recoverability of business processes and functions?
Business Impact Analysis
Business Continuity Plan
Recovery Strategy
Disaster Recovery Plan
Concerning a risk management strategy, what should the executive level be responsible for communicating?
Risk mitigation
Risk profile
Risk tolerance
Asset risk
What type of item appears in the second column of the table?
Subcategory
Informative Reference
Function
Tier
At what cyber kill chain stage do attackers use malware to exploit specific software or hardware vulnerabilities on the target, based on the information retrieved at the reconnaissance stage?
Installation
Reconnaissance
Weaponization
Delivery
During what activity does an organization identify and prioritize technical, organizational, procedural, administrative, and physical security weaknesses?
Table top exercise
Penetration testing
Vulnerability assessment
White box testing
Your organization was breached. You informed the CSIRT and they contained the breach and eradicated the threat.
What is the next step required to ensure that you have an effective CSRL and a more robust cybersecurity posture in the future?
Determine change agent
Update the BIA
Conduct a gap analysis
Update the BCP
The information security manager for a major web based retailer has determined that the product catalog database is corrupt. The business can still accept orders online but the products cannot be updated. Expected downtime to rebuild is roughly four hours.
What type of asset should the product catalog database be categorized as?
Mission critical
Safety critical
Non-critical
Business critical
What should an organization use to effectively mitigate against password sharing to prevent unauthorized access to systems?
Access through a ticketing system
Frequent password resets
Strong password requirements
Two factor authentication