Study the NIST Cybersecurity Framework (NIST CSF) standard published by NIST with free practice questions on CyberCertPrep. Our NIST CSF knowledge check is 80 questions in 2 hours with a 70% target score. There is no single NIST CSF exam for us to mirror, so those three figures are ours, not a vendor blueprint.
Choose from Practice mode, Knowledge Check, Weak Areas review, and Daily Challenge. Track your progress with detailed analytics and study with flashcards.
NIST Cybersecurity Framework (NIST CSF) Exam Domain
Focus your study on this domain with targeted practice questions. This domain accounts for 10% of your NIST CSF exam score.
The Govern domain is one of 6 exam domains on the NIST Cybersecurity Framework (NIST CSF) certification exam by NIST. At 10% of the total exam, this domain is important but should be balanced with higher-weighted domains in your study plan.
The NIST CSF exam consists of 80 questions with a time limit of 2 hours and a passing score of 70%. That means approximately 8 questions on your exam will come from the Govern domain.
AES (Advanced Encryption Standard)
A symmetric block cipher algorithm adopted by the U.S. government as the standard for encrypting electronic data, replac...
Compliance
The act of conforming to established guidelines, specifications, regulations, or legislation related to information secu...
GDPR
The General Data Protection Regulation, an EU regulation enacted in 2018 that governs data protection and privacy for al...
IAM (Identity and Access Management)
A framework of policies, processes, and technologies for managing digital identities and controlling user access to crit...
Identity and Access Management (IAM)
A framework of policies and technologies that ensures the right individuals have appropriate access to resources at the ...
SOX (Sarbanes-Oxley Act)
U.S. federal law enacted in 2002 to enhance corporate financial reporting accuracy and prevent accounting fraud followin...
Prompt Injection
An attack against large language model (LLM) applications in which crafted input manipulates the model into ignoring its...
Model Inversion Attack
A privacy attack that reconstructs sensitive training data, or attributes of it, by repeatedly querying a model and anal...
These certifications also cover topics related to Govern:
Governance, Risk & Compliance, 20% of exam
Information Security Governance, 17% of exam
Governance and Management of IT, 18% of exam
Governance, 26% of exam
Privacy Governance, 20% of exam
Security and Privacy Governance, Risk Management, and Compliance Program, 16% of exam