exam questions

Exam SY0-601 All Questions

View all questions & answers for the SY0-601 exam

Exam SY0-601 topic 1 question 856 discussion

Actual exam question from CompTIA's SY0-601
Question #: 856
Topic #: 1
[All SY0-601 Questions]

Which of the following provides guidelines for the management and reduction of information security risk?

  • A. CIS
  • B. NIST CSF
  • C. ISO
  • D. PCI DSS
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
CircaG
Highly Voted 1 year, 3 months ago
Selected Answer: B
B. The National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) provides guidelines, standards, and best practices for organizations to manage and reduce cybersecurity risk. It offers a flexible and customizable framework that helps organizations align their cybersecurity activities with business objectives, risk tolerance, and available resources.
upvoted 5 times
...
chizzuck
Most Recent 11 months, 3 weeks ago
Selected Answer: B
B. NIST CSF • National Institute of Standards and Technology – Cybersecurity Framework (CSF) – A voluntary commercial framework • Framework Core – Identify, Protect, Detect, Respond, and Recover • Framework Implementation Tiers – An organization’s view of cybersecurity risk and processes to manage the risk • Framework Profile - The alignment of standards, guidelines, and practices to the Framework Core
upvoted 1 times
...
AspiringNerd
1 year, 1 month ago
Selected Answer: B
NIST CSF is a guideline. ISO are standards.
upvoted 2 times
...
MortG7
1 year, 2 months ago
The NIST Cybersecurity Framework (CSF) 2.0 provides guidance to industry, government agencies, and other organizations to manage cybersecurity risks. It offers a taxonomy of high-level cybersecurity outcomes that can be used by any organization — regardless of its size, sector, or maturity — to better understand, assess, prioritize, and communicate its cybersecurity efforts.
upvoted 1 times
...
RamnathKM
1 year, 2 months ago
Selected Answer: C
ISO 27001 https://www.iso.org/standard/27001
upvoted 1 times
...
paCer66
1 year, 3 months ago
B. The NIST CSF is designed as a guide, whereas ISO 27001 is designed as a standard. The difference here is that NIST CSF serves as an instruction manual and ISO 27001 is more of a test that requires certain measures to pass. In the NIST CSF, there is no certification or audit process.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...