CRISC Information Technology and Security Practice Question
An organization is considering adopting the NIST Cybersecurity Framework to manage cybersecurity risk. Which of the following are core functions of the framework? (Choose TWO.)
⚠ Common exam trap
CRISC often tests the exact five functions of the NIST CSF, and candidates may confuse them with other risk management terms like 'Prevent' or 'Mitigate' which are not part of the core functions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Protect
The NIST Cybersecurity Framework defines five core functions: Identify, Protect, Detect, Respond, and Recover. Option E (Identify) is correct because it covers understanding the organization's assets, risks, and governance to prioritize cybersecurity efforts. Option C (Protect) is correct because it encompasses safeguards such as access control, awareness training, and data security to limit or contain the impact of a potential cybersecurity event. Options A (Prevent), B (Mitigate), and D (Analyze) are not among the five core functions, even though they describe related risk-management concepts; the framework uses Detect, Respond, and Recover instead of those terms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Prevent
Why it's wrong here
Prevent is not a CSF core function; preventive controls fall under the Protect function. It is tempting because prevention is a familiar security objective and many frameworks name it explicitly, but the CSF deliberately separates Protect (safeguards) from Detect, Respond and Recover.
- ✗
Mitigate
Why it's wrong here
Mitigate is not a CSF core function; risk mitigation is achieved through the Protect, Respond and Recover functions. It is tempting because mitigation is standard risk terminology, but the framework's five functions are Identify, Protect, Detect, Respond and Recover, with mitigation expressed as outcomes within them.
- ✓
Protect
Why this is correct
Protect is a NIST CSF core function, encompassing access control, awareness training, data security and protective technology. It satisfies the framework's structure by delivering the safeguards that limit or contain the impact of a potential cybersecurity event.
- ✗
Analyze
Why it's wrong here
Analyze is not one of the five NIST CSF core functions (Identify, Protect, Detect, Respond, Recover); it is a step within risk assessment processes such as those in NIST SP 800-30. It tempts because analysis underpins risk management, but the framework names functions, not activities.
- ✓
Identify
Why this is correct
Identify is one of the five NIST CSF core functions, covering asset management, risk assessment and governance to build organisational understanding of cybersecurity risk. It satisfies the framework's requirement by establishing the context needed before protective controls can be selected or prioritised.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.