D-CSF-SC-01 Sample Questions

D-CSF-SC-01 Sample Questions & Answers

Governance and third-party risk tie with asset management and resilience planning for the top weight, alongside identity and data safeguards, risk-communication integration, incident response and recovery, and analyzing CSF profiles and tiers.

Launch the full D-CSF-SC-01 simulator →

Showing 6 of 12 free samples.

  1. Question 1Advanced

    NIST Framework: GOVERN Function · GOVERN Function and Enterprise Risk Management (ERM)

    GlobalFinTech Solutions is undergoing a major digital transformation, migrating legacy on-premises workloads to a multi-cloud architecture. The Board of Directors has mandated that the new cybersecurity strategy must be fully integrated into the corporate Enterprise Risk Management (ERM) program.

    The Chief Risk Officer (CRO) has decided to use the NIST CSF 2.0 GOVERN Function as the bridge between corporate governance and technical cybersecurity execution.

    Which of the following actions best demonstrates the successful implementation of the GOVERN Function's relationship with ERM in this scenario?

    flowchart TD ERM[Enterprise Risk Management] -->|Dictates Risk Appetite| GV[GOVERN Function] GV -->|Informs| ID[IDENTIFY] GV -->|Informs| PR[PROTECT] GV -->|Informs| DE[DETECT] GV -->|Informs| RS[RESPOND] GV -->|Informs| RC[RECOVER]
    Show answer & explanation

    Correct answer: A

    The GOVERN Function is designed to sit at the center of the framework, taking the organization's overarching Enterprise Risk Management (ERM) directives (like risk appetite and tolerance) and using them to inform and prioritize the activities in the other five Functions. Setting a board-level risk appetite that directly drives IDENTIFY and PROTECT activities perfectly exemplifies this relationship. Options involving SIEM alerts (DETECT), backups (RECOVER), or access controls (PROTECT) are operational activities, not primary GOVERN/ERM integrations.

  2. Question 2Intermediate

    NIST Framework: GOVERN Function · GOVERN Function and Enterprise Risk Management (ERM)

    A multinational manufacturing firm is defining its Risk Management Strategy (GV.RM) under the CSF 2.0 GOVERN Function. The organization operates in multiple regulatory jurisdictions with varying data privacy laws. What is the most critical outcome this strategy must achieve to ensure effective cybersecurity governance?

    Show answer & explanation

    Correct answer: A

    The Risk Management Strategy (GV.RM) category focuses on ensuring that the organization's priorities, constraints, risk tolerance, and risk assumptions are established, communicated, and used to support operational risk decisions. It is not about mandating specific technical controls (like AES-256) or purely focusing on third-party audits, but rather setting the strategic risk parameters.

  3. Question 3Intermediate

    NIST Framework: GOVERN Function · Policies, roles, and supplier/third-party risk

    During an internal audit, it is discovered that while the IT team has implemented strong firewalls and endpoint protection, there is no formal documentation dictating how often access reviews should occur or what acceptable use entails. Which category within the GOVERN Function is currently failing in this organization?

    Show answer & explanation

    Correct answer: B

    The Policy (GV.PO) category ensures that organizational cybersecurity policy is established, communicated, and maintained. The lack of formal documentation dictating rules (like access review frequency or acceptable use) points directly to a failure in establishing and maintaining policy. While roles (GV.RR) are important, the rules themselves belong in GV.PO.

  4. Question 4Intermediate

    NIST Framework: GOVERN Function · Policies, roles, and supplier/third-party risk

    A telecommunications company is restructuring its security department. To comply with the CSF 2.0 GOVERN Function's Roles, Responsibilities, and Authorities (GV.RR) category, the organization must ensure clear lines of accountability. Which of the following best represents a proper implementation of GV.RR?

    Show answer & explanation

    Correct answer: D

    GV.RR requires that cybersecurity roles, responsibilities, and authorities to foster accountability, performance assessment, and continuous improvement are established and communicated. This includes everyone from the board down to general employees and third parties, not just technical IT staff.

  5. Question 5Intermediate

    NIST Framework: GOVERN Function · Policies, roles, and supplier/third-party risk

    An enterprise relies heavily on a dozen SaaS providers and external development agencies. As part of integrating NIST CSF 2.0, the CISO is focusing on Cybersecurity Supply Chain Risk Management (GV.SC). Which approach best fulfills the requirements of this GOVERN subcategory?

    Show answer & explanation

    Correct answer: C

    Cybersecurity Supply Chain Risk Management (GV.SC) involves managing risks associated with suppliers and third parties throughout the relationship lifecycle (onboarding, active management, offboarding) and integrating this into the broader Enterprise Risk Management (ERM) process. Simply demanding indemnification or bringing everything in-house is neither practical nor aligned with the framework's intent of managing risk.

  6. Question 6Beginner

    NIST Framework: GOVERN Function · GOVERN Function and Enterprise Risk Management (ERM)

    Within the NIST CSF 2.0 GOVERN Function, the Oversight (GV.OV) category is designed to ensure that the cybersecurity risk management strategy is achieving its intended outcomes. Which activity is a primary example of Oversight?

    Show answer & explanation

    Correct answer: A

    Oversight (GV.OV) ensures that results of organization-wide cybersecurity risk management activities are used to inform, improve, and adjust the risk management strategy and policies. Reviewing metrics at the executive level to adjust investments is a classic oversight activity.

Ready for the real thing?

The full D-CSF-SC-01 simulator has every exam-style question, timed mode, and instant scoring.