FRAMEWORK (RMF) EXAM
QUESTIONS AND ANSWERS 2026
VERIFIED.
DoD systems are subject to what types of threats? - ANS Confidentiality, integrity, or
availability of information processed, stored, or transmitted by DoD systems.
Define system categorization - ANS System Categorization is the process by which the
Information Owner identifies the potential impact (low, moderate, or high) that would result
from the loss of confidentiality, integrity, and availability should a security breach occur.
What is non-repudiation and the negative impacts of not having non--repudiation? -
ANS Definition: Protection against an individual falsely denying having performed a particular
action. Provides the capability to determine whether a given individual took a particular action
such as creating information, sending a message, approving information, and receiving a
message.
Negative impacts :
1.) Sender could deny message was sent.
2.) Recipient of email could change message and contest that altered message was sent by
sender.
What is confidentiality and the negative impacts of not having confidentiality? -
ANS Definition: Preserving authorized restrictions on information access and disclosure,
including means for protecting personal privacy and proprietary information.
@COPYRIGHT ALL RIGHTS RESERVED PAGE 1 OF 6
, Negative impacts of no confidentiality:
1.) Persons could be granted access to information beyond their need-to-know.
2.) Sensitive or classified information could be disclosed to an unauthorized system
What is CIA in relation to RMF? - ANS Confidentiality: preserving authorized restrictions on
information access and disclosure
Integrity: guarding against unauthorized information modification or destruction
Availability: timely and reliable access to and use of information
What program does RMF replace? - ANS DIACAP
What DoD guidance provides direction for the implementation of RMF? - ANS DoD 8510.01
What does the Risk Management Framework (RMF) provide? - ANS A structured, yet flexible
approach for managing risk resulting from incorporation of information systems into
mission/business processes of organization
What policy partnerships ensure DoD RMF guidance is aligned with pre-existing standards? -
ANS National Institute of Standards and Technology (NIST) and Committee on National
Security Systems (CNSS)
Security controls and safeguards selected by the organization must take what into account? -
ANS Potential mission or business impacts, risk to organizational operations and assets,
individuals, other organizations, the nation.
DoD RMF Guidance Tier 1 - ANS -Office of Secretary of Defense
-Addresses risk management at DoD enterprise level
-Key governance = DoD CIO, Sr IO or SISO
@COPYRIGHT ALL RIGHTS RESERVED PAGE 2 OF 6