Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 59 pages
Exam (elaborations)

Certified Associate in Project Management (CAPM) Practice Exam 2026 questions and verified answers

Document preview thumbnail
Preview 4 out of 59 pages

Certified Associate in Project Management (CAPM) Practice Exam 2026 questions and verified answers

Content preview

Certified Associate in Project Management (CAPM) Practice Exam 2026
questions and verified answers
Question 1
An organization is conducting a risk assessment for a new financial application.
The risk team assigns numerical monetary values to asset loss and calculates the
exact probability of potential threat occurrences to determine total expected
loss. What type of risk analysis is being performed?
• A. Qualitative Risk Analysis
• B. Quantitative Risk Analysis
• C. Delphi Method
• D. Scenario-Based Threat Modeling
• Correct Answer: B
• Explanation: Quantitative risk analysis involves calculating numerical values
for risks, including Single Loss Expectancy (SLE), Annual Rate of Occurrence
(ARO), and Annualized Loss Expectancy (ALE), using objective financial data.
Question 2
A data protection officer is establishing a data classification policy for corporate
assets. Which of the following factors should be the primary driver when
determining the classification level of corporate data?
• A. The cost of storage media used to hold the data
• B. The sensitivity, criticality, and regulatory value of the data to the
organization
• C. The alphabetical order of file names
• D. The personal preference of the system administrator
• Correct Answer: B
• Explanation: Data classification is driven primarily by data sensitivity,
confidentiality requirements, business criticality, and legal or regulatory
compliance mandates.

,Certified Associate in Project Management (CAPM) Practice Exam 2026
questions and verified answers
Question 3
Within a secure operating system architecture, what core component is
responsible for enforcing access control policies over all subjects
(processes/users) and objects (files/devices), ensuring that the reference
monitor concept is fully implemented?
• A. Trusted Computing Base (TCB) kernel / Security Kernel
• B. Network Interface Card (NIC)
• C. Relational Database Management System (RDBMS)
• D. Hypervisor management console
• Correct Answer: A
• Explanation: The security kernel is the hardware, firmware, and software
elements of a Trusted Computing Base (TCB) that implement and enforce
the reference monitor concept, ensuring mediation of all access requests.
Question 4
A network security engineer is configuring a firewall that evaluates individual
packet headers while also tracking the active state and context of established
TCP/IP connections to filter traffic intelligently. What type of firewall is this?
• A. Packet Filtering Firewall (Static)
• B. Stateful Inspection Firewall
• C. Application-Level Gateway (Proxy)
• D. Circuit-Level Gateway
• Correct Answer: B
• Explanation: Stateful inspection (dynamic packet filtering) firewalls
remember the state of active connections and make decisions based on the
connection context, unlike simple static packet filters.
Question 5

,Certified Associate in Project Management (CAPM) Practice Exam 2026
questions and verified answers
An enterprise wants to allow employees to access multiple external cloud
services using a single set of corporate credentials, leveraging security assertions
formatted in XML and passed between an identity provider and service
providers. What protocol or framework is being used?
• A. OAuth 2.0
• B. Security Assertion Markup Language (SAML)
• C. Simple Network Management Protocol (SNMP)
• D. Internet Protocol Security (IPsec)
• Correct Answer: B
• Explanation: SAML is an open standard for exchanging authentication and
authorization data between parties, specifically between an Identity
Provider (IdP) and a Service Provider (SP) using XML.
Question 6
An external security team is hired to perform an authorized simulated
cyberattack against an organization's network infrastructure and applications to
identify exploitable vulnerabilities before malicious hackers do. What is this
assessment called?
• A. Vulnerability Assessment
• B. Penetration Testing (Pentest)
• C. Static Code Review
• D. Log Auditing
• Correct Answer: B
• Explanation: Penetration testing actively exploits vulnerabilities to evaluate
security defenses, whereas vulnerability scanning merely identifies known
weaknesses without exploitation.
Question 7

, Certified Associate in Project Management (CAPM) Practice Exam 2026
questions and verified answers
During a major security incident, an organization’s incident response team
moves to the phase where they contain the threat, eradicate the root cause,
recover systems to normal operations, and conduct post-incident activities.
According to the NIST incident response framework, what is the final formal
phase?
• A. Detection and Analysis
• B. Containment, Eradication, and Recovery
• C. Post-Incident Activity (Lessons Learned)
• D. Preparation
• Correct Answer: C
• Explanation: The NIST incident response lifecycle consists of four main
phases: Preparation; Detection and Analysis; Containment, Eradication, and
Recovery; and Post-Incident Activity (Lessons Learned).
Question 8
A software development team is performing threat modeling during the design
phase of a web application. They use the STRIDE methodology to analyze threats
of unauthorized elevation of privilege, tampering, and spoofing. Who originally
developed the STRIDE model?
• A. OWASP
• B. Microsoft
• C. National Institute of Standards and Technology (NIST)
• D. International Organization for Standardization (ISO)
• Correct Answer: B
• Explanation: STRIDE is a threat modeling methodology developed by
Microsoft (Spoofing, Tampering, Repudiation, Information Disclosure,
Denial of Service, Elevation of Privilege).

Document information

Uploaded on
July 24, 2026
Number of pages
59
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$19.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
CreativeWrites
3.6
(21)
Sold
88
Followers
3
Items
7900
Last sold
4 days ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions