NEW
Font size
WorksheetsCybersecurity Core Functions
Total questions: 15
Worksheet time: 8mins
RECOVER
Why is a business continuity plan important in cybersecurity recovery?
It ensures that critical operations can continue with minimal disruption after an attack.
It provides a detailed list of all employees' personal information.
It eliminates the need for regular software updates.
It guarantees that no data will be lost during an attack.
What are the key steps in an effective response plan?
Analysis, mitigation, communication, and documentation.
Preparation, execution, evaluation, and reporting.
Identification, assessment, response, and recovery.
Planning, training, implementation, and review.
What is the purpose of forensic analysis in the response process?
To investigate and understand the root cause of an incident for better mitigation and future prevention.
To collect evidence for legal proceedings only.
To provide immediate solutions to ongoing incidents.
To analyze financial data related to the incident.
What is the primary goal of the Detect function in the NIST framework?
To identify cybersecurity events and anomalies in a timely manner.
To prevent unauthorized access to systems and data.
To recover from cybersecurity incidents effectively.
To create awareness about cybersecurity threats.
What are the five core functions of the NIST Cybersecurity Framework?
Identify, Protect, Detect, Respond, Recover
Assess, Mitigate, Monitor, Report, Recover
Identify, Protect, Analyze, Respond, Recover
Detect, Protect, Respond, Train, Recover
PROTECT: What are the key security measures in the Protect function of NIST?
Access control, awareness training, data security, maintenance, and protective technology.
User authentication and password policies.
Network segmentation and firewall configurations.
Incident response and recovery planning.
How does multi-factor authentication (MFA) contribute to the Protect function?
MFA simplifies the login process for users.
MFA adds an extra layer of security, making it harder for unauthorized users to gain access.
MFA eliminates the need for passwords altogether.
MFA is only useful for large organizations.
What are the main activities in the Recover function of NIST?
Recovery planning, improvements, and communication.
Risk assessment and mitigation planning.
Incident detection and response.
Data encryption and access control.
What is the purpose of a risk assessment in the Identify function?
To evaluate threats, vulnerabilities, and impacts to prioritize security measures effectively.
To create a detailed report of all security incidents.
To implement security measures without assessing risks.
To train employees on security protocols.
Why is it important to have a pre-defined communication plan in the Respond function?
To ensure clear, timely, and accurate information is shared with stakeholders during a cybersecurity incident.
To minimize the cost of cybersecurity tools and resources.
To avoid any communication with stakeholders during an incident.
To ensure that only the IT team is informed about the incident.
What type of tools are commonly used in the Detect function?
Intrusion detection systems (IDS), security information and event management (SIEM), and log analysis tools.
Network firewalls and antivirus software.
Data encryption tools and backup solutions.
User authentication systems and access control lists.
PROTECT: What is the role of security awareness training in the Protect function?
It educates employees on recognizing and preventing cyber threats like phishing and social engineering attacks.
It focuses on implementing firewalls and antivirus software.
It ensures compliance with legal regulations regarding data protection.
It provides technical training for IT staff only.
RECOVER
What lessons should be learned from a cybersecurity incident recovery?
Organizations should identify weaknesses, update security policies, and improve response strategies.
Organizations should ignore past incidents to avoid panic.
Organizations should focus solely on technology upgrades.
Organizations should blame external factors for the incident.
Why is continuous monitoring important for cybersecurity?
It helps detect and respond to threats in real time, reducing potential damage.
It allows for periodic audits of security measures.
It eliminates the need for any security protocols.
It focuses solely on data encryption methods.
Why is asset management critical in the Identify function of NIST?
It helps organizations understand what data, hardware, and software they own, allowing for better risk management.
It ensures compliance with all regulatory requirements without exception.
It focuses solely on the financial aspects of asset ownership.
It eliminates the need for regular audits and assessments.
