Skip to content

FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks

A bank wants its cyber framework to follow the widely used NIST Cybersecurity Framework functions. After a phishing attack, the team activates its incident response plan, isolates affected servers, and notifies regulators. Which framework function do these actions primarily represent?

These actions fall under the Respond function. Executing the incident response plan, containing affected systems and notifying regulators are all activities taken once an incident is detected, whereas Identify, Protect and Detect concern preparation, safeguards and discovery.

  1. AIdentify
  2. BProtect
  3. CRespondCorrect
  4. DDetect

Explanation

Activating the incident plan, containing the incident by isolating servers and notifying stakeholders are Respond activities. Identify covers asset and risk understanding, Protect covers safeguards, and Detect covers discovering events. Recover would cover restoring services afterward.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.

More Case Study: Cyberthreats and Information Security Risks questions