Courseiva

CRISC Information Technology and Security Practice Question

Which TWO of the following are key benefits of integrating the NIST Cybersecurity Framework with an organization's risk management processes? (Select TWO.)

⚠ Common exam trap

CRISC often tests the difference between a framework's actual benefits (alignment, common language) and overstated claims (prevention, prescriptive controls, replacing governance artifacts), so candidates who pick 'prescriptive controls' or 'replaces risk appetite' misunderstand CSF's voluntary, outcome-based nature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Helps align cybersecurity activities with business objectives

Option B is correct because the NIST Cybersecurity Framework (CSF) is designed to be integrated with enterprise risk management so that cybersecurity investments and activities are prioritized according to business objectives, mission needs, and organizational risk tolerances, rather than treated as a purely technical concern. Option D is correct because the CSF Core's Functions, Categories, and Subcategories (Identify, Protect, Detect, Respond, Recover, and Govern in CSF 2.0) establish a standardized taxonomy that gives technical and business stakeholders a common language for describing, discussing, and communicating cybersecurity risk. Option A is incorrect because no framework can guarantee prevention of all cyber attacks; the CSF is risk-based and assumes some incidents will occur, emphasizing detection, response, and recovery. Option C is incorrect because the CSF is outcome-based and voluntary, not a prescriptive checklist of mandatory controls for every organization. Option E is incorrect because the CSF complements, rather than replaces, an organization's risk appetite statement, which is a governance input used to guide risk-based decisions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ensures all cyber attacks are prevented

    Why it's wrong here

    The NIST CSF provides a structured approach to identifying, protecting, detecting, responding, and recovering, but no framework prevents attacks. It tempts because adopting the CSF strengthens resilience and reduces likelihood, yet residual risk always remains; prevention of all attacks is unattainable.

  • ✓

    Helps align cybersecurity activities with business objectives

    Why this is correct

    Mapping Framework outcomes to enterprise risk processes ties security spending and controls to stated business objectives, letting leadership prioritise investment by impact. This satisfies the integration benefit of aligning cybersecurity activities with what the organisation is trying to achieve.

  • ✗

    Provides a prescriptive set of controls for all organizations

    Why it's wrong here

    The NIST CSF is outcome-based and voluntary, offering categories and subcategories that organisations tailor to their own risk profile. It tempts because its five functions look like a control catalogue, yet it prescribes no specific controls; prescriptive control sets come from standards such as ISO 27001 Annex A or NIST SP 800-53.

  • ✓

    Provides a common language for communicating cybersecurity risk

    Why this is correct

    The Framework's Functions, Categories and Subcategories give risk, security and business stakeholders one shared taxonomy, so cyber risk can be discussed alongside other enterprise risks. This satisfies the integration benefit of consistent communication across the organisation.

  • ✗

    Replaces the need for a separate risk appetite statement

    Why it's wrong here

    The NIST CSF structures and communicates cyber risk; it does not define acceptable risk levels, which remain the organisation's own governance decision. It tempts because the Framework's risk-management language overlaps with appetite discussions, yet a separate risk appetite statement is still required to set tolerance thresholds.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.