CAP Practice Exam Question and Answers
Which one the following roles is responsible for testing the non‐technical controls in an
information system? - -Correct Answer-Security Control Assessor
Which reference provides detailed guidance on risk mitigation for the State Department?
- -Correct Answer-SP 800-53 Security and Privacy Controls for Federal Information
Systems and Organizations
Which of the following roles has the responsibility to ensure that the enterprise
architecture supports the mission and business processes? - -Correct Answer-a.
Information Security Architect
During which step of the Risk Management Framework (RMF) does the Information
System Owner register the information system? - -Correct Answer-Categorize
Information System
Who signs the authorization decision letter? - -Correct Answer-Authorizing Official
Who develops and maintains information security policies, procedures, and control
techniques to address all applicable requirements? - -Correct Answer-b. Chief
Information Officer
A weakness in an information system, system security procedures, internal controls, or
implementation that could be exploited by a threat source is the definition of which key
term? - -Correct Answer-Vulnerability
Who procures, develops, integrates, or modifies an information system? - -Correct
Answer-Information System Owner
1
, 2
Who has the responsibility to prepare the plan of action and milestones based on the
findings and recommendations of the security assessment report? - -Correct Answer-
Common Control Provider
You have just completed the Risk Assessment defined by NIST SP 800‐30. What
reference identifies the risk management strategy alternatives that can be applied to the
information system? - -Correct Answer-NIST SP 800-53
In which phase of the NIST SP 800‐30 process does one produce the first full Risk
Assessment Report (RAR)? - -Correct Answer-Step 2
Which step of the NIST SP 800‐30 process would most likely identify the CVE database
as a risk assessment information source? - -Correct Answer-Step 2
Organizations should view assessments as an information gathering activity, not as a
security producing activity. In accordance with NIST SP 800‐53A, security control
assessments create the following benefits: identify potential problems or shortfalls in the
organization's implementation of the NIST Risk Management Framework; support
budgetary decisions and capital investment processes, and: - -Correct Answer-Support
information system authorization decisions.
The last step in the Risk Assessment process model is called? - -Correct Answer-
Maintain
When using NIST SP 800‐53A, during which SDLC phase are security assessments
used to increase confidence or assurance that the security controls are working correctly
for a system? - -Correct Answer-Development, Implementation, and Operations and
Maintenance
2