CRISC Information Technology and Security Practice Question
Which TWO of the following are key benefits of integrating the NIST Cybersecurity Framework with an organization's risk management processes? (Select TWO.)
⚠ Common exam trap
CRISC often tests the difference between a framework's actual benefits (alignment, common language) and overstated claims (prevention, prescriptive controls, replacing governance artifacts), so candidates who pick 'prescriptive controls' or 'replaces risk appetite' misunderstand CSF's voluntary, outcome-based nature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Helps align cybersecurity activities with business objectives
Option B is correct because the NIST Cybersecurity Framework (CSF) is designed to be integrated with enterprise risk management so that cybersecurity investments and activities are prioritized according to business objectives, mission needs, and organizational risk tolerances, rather than treated as a purely technical concern. Option D is correct because the CSF Core's Functions, Categories, and Subcategories (Identify, Protect, Detect, Respond, Recover, and Govern in CSF 2.0) establish a standardized taxonomy that gives technical and business stakeholders a common language for describing, discussing, and communicating cybersecurity risk. Option A is incorrect because no framework can guarantee prevention of all cyber attacks; the CSF is risk-based and assumes some incidents will occur, emphasizing detection, response, and recovery. Option C is incorrect because the CSF is outcome-based and voluntary, not a prescriptive checklist of mandatory controls for every organization. Option E is incorrect because the CSF complements, rather than replaces, an organization's risk appetite statement, which is a governance input used to guide risk-based decisions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ensures all cyber attacks are prevented
Why it's wrong here
The NIST CSF provides a structured approach to identifying, protecting, detecting, responding, and recovering, but no framework prevents attacks. It tempts because adopting the CSF strengthens resilience and reduces likelihood, yet residual risk always remains; prevention of all attacks is unattainable.
- ✓
Helps align cybersecurity activities with business objectives
Why this is correct
Mapping Framework outcomes to enterprise risk processes ties security spending and controls to stated business objectives, letting leadership prioritise investment by impact. This satisfies the integration benefit of aligning cybersecurity activities with what the organisation is trying to achieve.
- ✗
Provides a prescriptive set of controls for all organizations
Why it's wrong here
The NIST CSF is outcome-based and voluntary, offering categories and subcategories that organisations tailor to their own risk profile. It tempts because its five functions look like a control catalogue, yet it prescribes no specific controls; prescriptive control sets come from standards such as ISO 27001 Annex A or NIST SP 800-53.
- ✓
Provides a common language for communicating cybersecurity risk
Why this is correct
The Framework's Functions, Categories and Subcategories give risk, security and business stakeholders one shared taxonomy, so cyber risk can be discussed alongside other enterprise risks. This satisfies the integration benefit of consistent communication across the organisation.
- ✗
Replaces the need for a separate risk appetite statement
Why it's wrong here
The NIST CSF structures and communicates cyber risk; it does not define acceptable risk levels, which remain the organisation's own governance decision. It tempts because the Framework's risk-management language overlaps with appetite discussions, yet a separate risk appetite statement is still required to set tolerance thresholds.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.