PECB NIS 2 Directive Lead Implementer - PECB Certified NIS 2 Directive Lead Implementer Exam

Question #11 (Topic: Exam A)
Scenario 2:
MHospital, founded in 2005 in Metropolis, has become a healthcare industry leader with over 2,000 dedicated employees known for its commitment to qualitative medical services and patient care innovation. With the rise of cyberattacks targeting healthcare institutions, MHospital acknowledged the need for a comprehensive cyber strategy to mitigate risks effectively and ensure patient safety and data security. Hence, it decided to implement the NIS 2 Directive requirements. To avoid creating additional processes that do not fit the company’s context and culture, MHospital decided to integrate the Directive’s requirements into its existing processes. To initiate the implementation of the Directive, the company decided to conduct a gap analysis to assess the current state of the cybersecurity measures against the requirements outlined in the NIS 2 Directive and then identify opportunities for closing the gap.
Recognizing the indispensable role of a computer security incident response team (CSIRT) in maintaining a secure network environment, MHospital empowers its CSIRT to conduct thorough penetration testing on the company’s networks. This rigorous testing helps identify vulnerabilities with a potentially significant impact and enables the implementation of robust security measures. The CSIRT monitors threats and vulnerabilities at the national level and assists MHospital regarding real-time monitoring of their network and information systems. MHospital also conducts cooperative evaluations of security risks within essential supply chains for critical ICT services and systems. Collaborating with interested parties, it engages in the assessment of security risks, contributing to a collective effort to enhance the resilience of the healthcare sector against cyber threats.
To ensure compliance with the NIS 2 Directive’s reporting requirements, MHospital has streamlined its incident reporting process. In the event of a security incident, the company is committed to issuing an official notification within four days of identifying the incident to ensure that prompt actions are taken to mitigate the impact of incidents and maintain the integrity of patient data and healthcare operations. MHospital’s dedication to implementing the NIS 2 Directive extends to cyber strategy and governance. The company has established robust cyber risk management and compliance protocols, aligning its cybersecurity initiatives with its overarching business objectives.
Based on the scenario above, answer the following question:
Is the role of the MHospital’s CSIRT regarding vulnerability assessment in alignment with the requirements of Article 11 of the NIS 2 Directive?
A. No, according to Article 11, the CSIRT should not conduct scanning of the network and information systems of the entity as this should be done during the coordinated vulnerability disclosure B. No, the CSIRT should not be involved in vulnerability management, as defined in Article 11 C. Yes, the role of the CSIRT is consistent with vulnerability assessment requirements specified in Article 11
Answer: C
Question #12 (Topic: Exam A)
Based on scenario 2, are the cooperative evaluations of security risks carried out in alignment with Article 22 of the NIS 2 Directive?
A. Yes, cooperative evaluations are carried out in accordance with Article 22 B. No, cooperative evaluations should be done by the Cooperation Group, Commission, and ENISA C. No, cooperative evaluations should be done by direct suppliers and service providers
Answer: A
Question #13 (Topic: Exam A)
According to scenario 2, MHospital is committed to issuing an official notification within four days of identifying an incident. Is this in compliance with the NIS 2 Directive requirements?
A. No, the official notification should be issued within 48 hours of identifying the incident B. No, the official notification should be issued within 72 hours of identifying the incident C. Yes, the official notification should be issued within 96 hours of identifying the incident
Answer: C
Question #14 (Topic: Exam A)
According to scenario 2, as a first step toward the NIS 2 Directive implementation, MHospital decided to conduct a gap analysis to assess its current state of the cybersecurity measures against the requirements outlined in the NIS 2 Directive. Is this in alignment with best practices?
A. Yes, a gap analysis should be initially conducted before taking any further actions to implement the Directive B. No, the initial step should have been a risk assessment to identify potential cybersecurity vulnerabilities C. No, the initial step should have been a scop assessment to determine the scope of the company’s compliance
Answer: A
Question #15 (Topic: Exam A)
Based on scenario 2, in order to avoid creating additional processes that do not fit with the company’s context and culture, MHospital decided to integrate the Directive’s requirements into its existing processes. Is this in accordance with best practices?
A. Yes, organizations should incorporate the NIS 2 Directive into their existing processes B. No, organizations should create other processes in addition to the existing processes to ensure full compliance with the NIS 2 Directive C. No, organizations should disregard existing processes completely and create new ones to ensure full compliance with the NIS 2 Directive
Answer: A
Download Exam
Page: 3 / 16
Total 80 questions