D-CSF-SC-23 Sample Questions

D-CSF-SC-23 Sample Questions & Answers

Baseline configuration and business-continuity planning under the Protect function carry the top weight, alongside asset management, the framework's overall architecture, disaster recovery, incident containment, and breach detection with ongoing monitoring.

Launch the full D-CSF-SC-23 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    NIST Framework: Recover Function · Disaster Recovery Planning

    A cloud-native startup relies entirely on a single public cloud provider for all its operations. After a major regional outage caused by the provider, the startup's leadership decides to formalize its recovery strategy. They need a plan that specifically details the technical procedures to restore their services, either in the same region or a different one. Which document is most appropriate for this purpose?

    Show answer & explanation

    Correct answer: C

    A Disaster Recovery Plan (DRP) is a technical, documented process focused on restoring IT systems and infrastructure after a disaster. It contains the specific procedures for recovery, such as failing over to a secondary region or restoring from backups. This is distinct from a Business Continuity Plan (BCP), which is broader and focuses on keeping business functions running during a disruption.

  2. Question 2Intermediate

    NIST Framework Overview · NIST Framework Architecture and Purpose

    True or False: The NIST Cybersecurity Framework Implementation Tiers are maturity levels that an organization must progress through sequentially from Tier 1 to Tier 4 to be considered compliant.

    Show answer & explanation

    Correct answer: B

    This statement is false. The NIST CSF Implementation Tiers (1-Partial, 2-Risk Informed, 3-Repeatable, 4-Adaptive) are not maturity levels. They describe the rigor of an organization's risk management practices. An organization selects a target Tier based on its business needs, risk tolerance, and threat environment; there is no requirement to progress sequentially, and a higher Tier is not always better or necessary.

  3. Question 3Beginner

    NIST Framework: Identify Function · Discovery and Inventory Planning Integration

    A government agency is conducting a Business Impact Analysis (BIA) as part of the Identify function (ID.BE). The goal is to determine the criticality of various IT systems. The BIA team needs to define the maximum acceptable amount of data loss from a system following a disruptive event. Which metric should they establish for this purpose?

    Show answer & explanation

    Correct answer: B

    The Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss, measured in time (e.g., 15 minutes of data, 4 hours of data). It dictates the required frequency of backups or replication. In contrast, the Recovery Time Objective (RTO) defines how quickly a system must be restored after an outage.

  4. Question 4Intermediate

    NIST Framework: Protect Function · Protection Subcategory Controls

    A financial institution is implementing controls for the Protect function. To comply with subcategory PR.DS-5: Protections against data leaks are implemented, the security team is evaluating several technologies. Which technology is specifically designed to identify, monitor, and prevent the unauthorized exfiltration of sensitive data from the network?

    Show answer & explanation

    Correct answer: C

    Data Loss Prevention (DLP) solutions are specifically designed to enforce policies that prevent sensitive data from leaving an organization's control. They work by inspecting data in use, in motion, and at rest for content that matches predefined patterns (e.g., credit card numbers, social security numbers) and blocking or alerting on unauthorized transfer attempts.

  5. Question 5Intermediate

    NIST Framework: Detect Function · Continuous Monitoring and Analysis

    A security operations team is struggling with a high volume of alerts from various security tools, leading to analyst fatigue and missed incidents. To improve their detection capabilities (DE.AE), they decide to implement a system that will aggregate logs, normalize data, and use correlation rules to identify high-fidelity threats. Which type of system are they implementing?

    Show answer & explanation

    Correct answer: C

    A Security Information and Event Management (SIEM) system is the core technology for addressing this problem. Its primary functions are to collect (aggregate) log and event data from diverse sources, normalize it into a common format, and apply correlation rules to identify patterns indicative of a security threat. This reduces alert fatigue by consolidating many low-level events into a single, actionable incident.

  6. Question 6Intermediate

    NIST Framework: Respond Function · Incident Response Planning

    Following a major security incident, a company's leadership team requests an After Action Review. The goal is to identify systemic weaknesses and improve the overall security posture. According to the NIST CSF Respond (RS) function, which of the following is the most critical activity during this review process?

    Show answer & explanation

    Correct answer: C

    The primary purpose of an After Action Review, as outlined in RS.IM-2 (Response processes are improved), is to learn from the incident to prevent recurrence. This is achieved by conducting a thorough root cause analysis to determine not just what happened, but why it was possible. The output should be a set of tracked, actionable recommendations to improve policies, procedures, and technologies.

  7. Question 7Intermediate

    NIST Framework: Recover Function · Business Continuity and Recovery Operations

    A retail company's primary e-commerce platform experienced a catastrophic failure, resulting in 12 hours of downtime. The Business Continuity Plan (BCP) was activated, but stakeholders noted significant confusion during the event. To address this, the BCP needs to be updated. Which component of the BCP is most directly related to ensuring clear, timely, and appropriate stakeholder updates during a crisis?

    Show answer & explanation

    Correct answer: C

    The Communications Plan is a critical component of both the BCP and IRP. It outlines the procedures for communicating with all relevant stakeholders (internal and external) during and after an incident. This includes who to contact, what information to share, when to share it, and the methods of communication, thereby preventing confusion and misinformation.

  8. Question 8Beginner

    NIST Framework Overview · NIST Framework Architecture and Purpose

    The NIST Cybersecurity Framework is composed of three main parts: the Framework Core, Implementation Tiers, and Profiles. Which part provides a set of specific cybersecurity activities, outcomes, and informative references organized into Functions, Categories, and Subcategories?

    Show answer & explanation

    Correct answer: A

    The Framework Core is the central part of the NIST CSF that provides the catalog of cybersecurity outcomes and activities. It is structured hierarchically with Functions (Identify, Protect, etc.) at the top, followed by Categories, Subcategories, and Informative References to other standards like ISO 27001 and COBIT.

  9. Question 9Advanced

    NIST Framework: Identify Function · Asset Management and Protection

    A risk analyst is tasked with prioritizing vulnerabilities for remediation based on the NIST CSF Identify function (ID.RA). The analyst has a list of vulnerabilities, their CVSS scores, and a complete asset inventory with criticality ratings. What is the most effective next step to prioritize remediation efforts in alignment with the Framework?

    Show answer & explanation

    Correct answer: B

    The NIST CSF emphasizes a risk-based approach. Simply using the CVSS score is insufficient as a critical vulnerability on a non-critical asset may be a lower priority than a medium vulnerability on a mission-critical system. The most effective approach is to combine vulnerability data (threat/likelihood) with asset data (criticality/impact) to understand the actual business risk and prioritize remediation accordingly.

  10. Question 10IntermediateSelect 3

    NIST Framework: Protect Function · Protection Subcategory Controls

    A university is developing a security awareness program to meet the requirements of PR.AT-1: All users are informed and trained. The program must be effective for a diverse audience including students, faculty, and administrative staff. Which of the following elements are essential for a successful security awareness program? (Select THREE)

    Show answer & explanation

    Correct answers: A, C, E

    A one-size-fits-all approach is ineffective. Role-based training ensures content is relevant. For example, developers need training on secure coding, while finance staff need training on business email compromise.

    Phishing simulations provide practical, hands-on experience in identifying malicious emails. They are a highly effective tool for measuring program effectiveness and improving user resilience against a common attack vector.

    To justify the program and demonstrate improvement, it's essential to track metrics. These can include training completion rates, quiz scores, and, most importantly, behavioral metrics like phishing simulation click rates and user reporting rates.

Ready for the real thing?

The full D-CSF-SC-23 simulator has every exam-style question, timed mode, and instant scoring.