Courseiva
mediumMatchingObjective-mapped

200-201 Practice Question: Match each cybersecurity framework/standard to…

Match each cybersecurity framework/standard to its focus.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Cybersecurity risk management framework

Information security management system standard

Payment card industry data security standard

Knowledge base of adversary tactics and techniques

Prioritized set of security best practices

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

NIST Cybersecurity Framework: Focuses on improving cybersecurity for critical infrastructure.

Correct matches: NIST CSF for critical infrastructure, ISO 27001 for ISMS, PCI DSS for cardholder data, CIS Controls for prioritized security actions. Common confusions include swapping these terms.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • NIST Cybersecurity Framework: Focuses on improving cybersecurity for critical infrastructure.

    Why this is correct

    NIST CSF provides a policy framework for critical infrastructure cybersecurity.

  • ISO/IEC 27001: Focuses on information security management systems (ISMS).

    Why this is correct

    ISO 27001 is an international standard for ISMS.

  • PCI DSS: Focuses on security of cardholder data for organizations handling credit cards.

    Why this is correct

    PCI DSS sets security standards for credit card data protection.

  • CIS Controls: Focuses on a prioritized set of security actions to defend against common cyber threats.

    Why this is correct

    CIS Controls are a prioritized list of security best practices.

  • NIST Cybersecurity Framework: Focuses on a prioritized set of security actions.

    Why it's wrong here

    Incorrect — this describes CIS Controls, not NIST CSF.

  • ISO/IEC 27001: Focuses on protection of cardholder data.

    Why it's wrong here

    Incorrect — this describes PCI DSS, not ISO 27001.

About these practice questions

One of 979 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.