Systems Security - C845 | 100% Guaranteed Pass
|| Complete A+ Guide
Question 1
Which NIST publication provides the official catalog of
security and privacy controls for federal information
systems?
A) SP 800-30
B) SP 800-53
C) SP 800-34
D) SP 800-171
Correct Answer: B) SP 800-53
Rationale: NIST SP 800-53 is titled "Security and Privacy
Controls for Information Systems and Organizations." SP
800-30 covers risk assessment, SP 800-34 covers
contingency planning, and SP 800-171 covers protecting
controlled unclassified information (CUI).
1
,Question 2
In Task 1 (Risk Assessment), what is the very first step
according to NIST SP 800-30 Revision 1?
A) Identify threats
B) Determine likelihood of occurrence
C) Prepare for the risk assessment
D) Recommend security controls
Correct Answer: C) Prepare for the risk assessment
Rationale: NIST SP 800-30 Rev. 1 specifies a four-step
process: (1) Prepare, (2) Conduct, (3) Communicate, (4)
Maintain. Preparation includes defining scope,
assumptions, constraints, and risk model.
Question 3
Which NIST SP 800-53 control family is dedicated
exclusively to Contingency Planning?
A) IR
2
,B) CP
C) CA
D) AT
Correct Answer: B) CP
Rationale: CP = Contingency Planning. IR = Incident
Response, CA = Security Assessment and Authorization,
AT = Awareness and Training. Each family has a two-
letter identifier.
Question 4
A risk assessment identifies a vulnerability with a high
likelihood of exploitation and severe business impact.
What risk level should be assigned?
A) Low
B) Moderate
C) High
D) Negligible
Correct Answer: C) High
3
, Rationale: Risk level is typically calculated as likelihood ×
impact. High likelihood + severe impact = high risk. High-
risk items require immediate remediation or acceptance
with formal authorization.
Question 5
In Task 2, which NIST SP 800-53 control family addresses
access control mechanisms?
A) AC
B) AU
C) IA
D) PE
Correct Answer: A) AC
Rationale: AC = Access Control (e.g., account
management, least privilege, separation of duties). AU =
Audit and Accountability, IA = Identification and
Authentication, PE = Physical and Environmental
Protection.
4