NIST CSF Practice Question: How does asset classification support cybersecurity risk management? | CyberCertPrep
NISTNIST CSFIdentify FunctionEASYFree question
How does asset classification support cybersecurity risk management?
A.It helps alphabetize the asset list
B.Classifying assets based on their criticality and sensitivity enables prioritized protection, ensuring the most important assets receive appropriate levels of cybersecurity investment
C.Classification is only used for insurance purposes
D.It determines which assets can be discarded
Why B is correct
Asset classification assigns importance levels based on business impact, enabling organizations to allocate limited cybersecurity resources to protect the most critical and sensitive assets first.
Know someone studying for NIST CSF? Send them this one.
Where this fits in the NIST CSF exam
Identify Function
Asset management, business environment, governance, risk assessment, risk management strategy, and supply chain risk management
This question belongs to the "Identify" domain, which makes up about 20% of the NIST CSF exam.
CyberCertPrep gives you 20 free NIST CSF questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
NIST CSF and NIST are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by NIST or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
Why does the Identify function include Supply Chain Risk Management (ID.SC)?