โ† All CCP Flashcard Decks

NIST CSF & CIS Controls Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 NIST CSF & CIS Controls flashcards as text
  1. An organization uses the NIST CSF to communicate its cybersecurity posture to the board of directors. Which CSF artifact is most useful for this purpose?

    Answer: A Target Profile gap analysis summary

    A Target Profile gap analysis provides a business-aligned view of desired outcomes versus current state, making it suitable for board-level communication.

  2. CIS Control 7 (Continuous Vulnerability Management) recommends that organizations perform authenticated vulnerability scanning. Why is authentication important in this context?

    Answer: It allows the scanner to identify more vulnerabilities by accessing system internals

    Authenticated scanning logs into systems to check installed software, configurations, and patches, revealing vulnerabilities invisible to unauthenticated network scans.

  3. Which NIST CSF 'Detect' category focuses on understanding the expected behavior of users, networks, and systems to identify deviations?

    Answer: Continuous Monitoring

    The 'Continuous Monitoring' category ensures that information systems and assets are monitored at discrete intervals to identify anomalies.

  4. CIS Control 17 (Incident Response Management) requires organizations to do which of the following?

    Answer: Designate personnel to manage incidents and test the plan annually

    CIS Control 17 requires designating incident response personnel, establishing a documented plan, and testing it through exercises at least annually.

  5. A financial services firm must align its security program with NIST CSF while also meeting regulatory requirements. What CSF feature enables this alignment?

    Answer: Informative References mapped to regulatory controls

    Informative References cross-walk CSF subcategories to regulatory frameworks (e.g., FFIEC, PCI DSS), allowing organizations to map compliance requirements to CSF outcomes.

  6. Which CIS Control focuses on limiting the use and installation of software to only authorized applications, reducing the attack surface?

    Answer: CIS Control 2 (Inventory and Control of Software Assets)

    CIS Control 2 ensures only authorized and supported software is installed, directly reducing exposure from unauthorized or malicious applications.

  7. Under NIST CSF 2.0's 'Govern' function, which category addresses establishing policies for managing cybersecurity supply chain risks?

    Answer: GV.SC (Cybersecurity Supply Chain Risk Management)

    GV.SC under the Govern function establishes policies and processes for managing cybersecurity risks arising from the supply chain, including third-party dependencies.