Certified Authorization Professional (CAP)
Questions And Correct Answers (Verified
Answers) Plus Rationales 2026 Q&A | Instant
Download Pdf
1. Which framework does the CAP primarily use for risk
management and information system authorization?
A. ISO 27001
B. COBIT
C. NIST RMF
D. ITIL
The NIST Risk Management Framework (RMF) provides
structured processes for categorizing, assessing, and authorizing
information systems, forming the foundation for CAP practices.
2. What is the primary objective of an Authorization to Operate
(ATO)?
A. To implement security controls
B. To formally accept the risk associated with operating a system
C. To develop security policies
, D. To classify data
An ATO is issued by a senior official to formally accept residual
risks after controls are implemented, authorizing system
operation.
3. During which step of the RMF is the system categorized?
A. Implement security controls
B. Assess security controls
C. Categorize the information system
D. Monitor security controls
Categorization occurs first in the RMF to identify the system’s
impact level and tailor security controls accordingly.
4. Which role is primarily responsible for ensuring compliance with
security policies and procedures?
A. Authorizing Official
B. Information System Security Officer (ISSO)
C. System Owner
D. Security Control Assessor
The ISSO manages the system’s compliance, oversees control
implementation, and ensures policies are followed.
5. What is the main purpose of continuous monitoring?
A. To create the system security plan
, B. To implement controls
C. To authorize a system
D. To track security control effectiveness over time
Continuous monitoring identifies changes or vulnerabilities that
may affect risk posture, ensuring controls remain effective.
6. Which document provides a detailed description of security
controls for a system?
A. Risk Assessment Report
B. Security Assessment Plan
C. System Security Plan (SSP)
D. Contingency Plan
The SSP outlines system boundaries, control selection, and
implementation details, forming a central document in RMF.
7. Which type of risk is considered residual risk?
A. Risk before controls are applied
B. Risk remaining after controls are implemented
C. Inherent risk
D. Threat risk
Residual risk represents the risk that remains despite the
implementation of security controls.
, 8. Who has the authority to accept residual risk for an information
system?
A. System Administrator
B. Authorizing Official (AO)
C. Security Control Assessor
D. Chief Information Security Officer (CISO)
The AO is responsible for formally accepting residual risk and
granting system authorization.
9. Which of the following best defines control inheritance?
A. Using inherited data for risk assessments
B. Leveraging security controls from another system or
environment
C. Copying user accounts from another system
D. Using inherited threat intelligence
Control inheritance reduces redundancy by reusing existing,
implemented controls from shared infrastructure or other
systems.
10. The CAP exam emphasizes knowledge in which of the
following domains?
A. Cryptography algorithms
B. Risk management, authorization, and security control
Questions And Correct Answers (Verified
Answers) Plus Rationales 2026 Q&A | Instant
Download Pdf
1. Which framework does the CAP primarily use for risk
management and information system authorization?
A. ISO 27001
B. COBIT
C. NIST RMF
D. ITIL
The NIST Risk Management Framework (RMF) provides
structured processes for categorizing, assessing, and authorizing
information systems, forming the foundation for CAP practices.
2. What is the primary objective of an Authorization to Operate
(ATO)?
A. To implement security controls
B. To formally accept the risk associated with operating a system
C. To develop security policies
, D. To classify data
An ATO is issued by a senior official to formally accept residual
risks after controls are implemented, authorizing system
operation.
3. During which step of the RMF is the system categorized?
A. Implement security controls
B. Assess security controls
C. Categorize the information system
D. Monitor security controls
Categorization occurs first in the RMF to identify the system’s
impact level and tailor security controls accordingly.
4. Which role is primarily responsible for ensuring compliance with
security policies and procedures?
A. Authorizing Official
B. Information System Security Officer (ISSO)
C. System Owner
D. Security Control Assessor
The ISSO manages the system’s compliance, oversees control
implementation, and ensures policies are followed.
5. What is the main purpose of continuous monitoring?
A. To create the system security plan
, B. To implement controls
C. To authorize a system
D. To track security control effectiveness over time
Continuous monitoring identifies changes or vulnerabilities that
may affect risk posture, ensuring controls remain effective.
6. Which document provides a detailed description of security
controls for a system?
A. Risk Assessment Report
B. Security Assessment Plan
C. System Security Plan (SSP)
D. Contingency Plan
The SSP outlines system boundaries, control selection, and
implementation details, forming a central document in RMF.
7. Which type of risk is considered residual risk?
A. Risk before controls are applied
B. Risk remaining after controls are implemented
C. Inherent risk
D. Threat risk
Residual risk represents the risk that remains despite the
implementation of security controls.
, 8. Who has the authority to accept residual risk for an information
system?
A. System Administrator
B. Authorizing Official (AO)
C. Security Control Assessor
D. Chief Information Security Officer (CISO)
The AO is responsible for formally accepting residual risk and
granting system authorization.
9. Which of the following best defines control inheritance?
A. Using inherited data for risk assessments
B. Leveraging security controls from another system or
environment
C. Copying user accounts from another system
D. Using inherited threat intelligence
Control inheritance reduces redundancy by reusing existing,
implemented controls from shared infrastructure or other
systems.
10. The CAP exam emphasizes knowledge in which of the
following domains?
A. Cryptography algorithms
B. Risk management, authorization, and security control