SFPC CORE MAIN QUESTIONS AND ANSWERS SET
A+
✔✔At what step of the Risk Management Framework (RMF) would you develop a
system-level continuous monitoring strategy?" **
a. Categorize Information System
b. Select Security Controls
c. Implement Security Controls
d. Assess Security Controls
e. Authorize
f. Monitor Security Controls - ✔✔B
✔✔One responsibility of the Information System Security Manager (ISSM) during Step 6
of the Risk Management Framework (RMF) is:**
a. Review and approve the security plan and system-level continuous monitoring
strategy developed and implemented by the DoD Components.
b. Monitor the system for security relevant events and configuration changes that affect
the security posture negatively.
c. Determine and documents a risk level in the Security Assessment Report (SAR) for
every non-compliant security control in the system baseline.
d. Coordinate the organization of the Information System (IS) and Platform Information
Technology (PIT) systems with the Program Manager (PM)/System Manager (SM),
Information System Owner (ISO), Information Owner (IO), mission owner(s), Action
Officer (AO) or their designated representatives. - ✔✔B
✔✔What family of controls does Security Functionality
Verification belong to?**
a. System and Communications Protection
b. Maintenance
c. System and Information Integrity
d. Audit and Accountability - ✔✔C
✔✔What does "AO" stand for? - ✔✔Authorizing Official
, ✔✔What is a SAR as related to cyber security? - ✔✔System Assessment Report
✔✔What activities occur when authorizing the system? (select all that apply)
a. Implement decommissioning strategy
b. Develop, review, and approve Security Assessment Plan
c. Prepare the Plan of Action and Milestones (POA&M)
d. Submit security authorization package - ✔✔C & D
✔✔What activities occur when assessing security controls? (Select all that apply)
A. prepare the plan of action and milestones (POA&M)
B. conduct final risk determination
C. Develop, plan, and approve Security Assessment Plan
D. Prepare Security Assessment Report - ✔✔C & D
✔✔What activities occur when monitoring security controls? (Select all that apply)
A. Prepare the Plan of Action and Milestones (POA&M)
B. Develop, review, and approve Security Assessment Plan
C. Implement decommissioning strategy
D. Determine impact of changes - ✔✔C & D
✔✔What are the cybersecurity attributes?
Select all that apply.
A Confidentiality
B Integrity
C Availability
D Authentication
E Non-repudiation - ✔✔All of the above
✔✔Why do you need to be aware of cybersecurity?
A To uphold all elements of the National Industrial Security Program Operating Manual
B To appropriately manage risk by mitigating threats and vulnerabilities
C To examine your own actions and activities to uphold personal accountability
D To ensure all appropriate measures are taken to protect a place and ensure only
people with permission enter and leave it - ✔✔B
✔✔What are the cybersecurity drivers?
A NIST 800-30 Rev 1 Guide for Conducting Risk Assessments
B DoD 8530.01 Cybersecurity Activities Support to DoD Information Network
Operations
C DoD 8510.01 Risk Management Framework
D DoD 8500.01
E DoD Security Policy - ✔✔All of the above
✔✔Which skills do security personnel need?
A+
✔✔At what step of the Risk Management Framework (RMF) would you develop a
system-level continuous monitoring strategy?" **
a. Categorize Information System
b. Select Security Controls
c. Implement Security Controls
d. Assess Security Controls
e. Authorize
f. Monitor Security Controls - ✔✔B
✔✔One responsibility of the Information System Security Manager (ISSM) during Step 6
of the Risk Management Framework (RMF) is:**
a. Review and approve the security plan and system-level continuous monitoring
strategy developed and implemented by the DoD Components.
b. Monitor the system for security relevant events and configuration changes that affect
the security posture negatively.
c. Determine and documents a risk level in the Security Assessment Report (SAR) for
every non-compliant security control in the system baseline.
d. Coordinate the organization of the Information System (IS) and Platform Information
Technology (PIT) systems with the Program Manager (PM)/System Manager (SM),
Information System Owner (ISO), Information Owner (IO), mission owner(s), Action
Officer (AO) or their designated representatives. - ✔✔B
✔✔What family of controls does Security Functionality
Verification belong to?**
a. System and Communications Protection
b. Maintenance
c. System and Information Integrity
d. Audit and Accountability - ✔✔C
✔✔What does "AO" stand for? - ✔✔Authorizing Official
, ✔✔What is a SAR as related to cyber security? - ✔✔System Assessment Report
✔✔What activities occur when authorizing the system? (select all that apply)
a. Implement decommissioning strategy
b. Develop, review, and approve Security Assessment Plan
c. Prepare the Plan of Action and Milestones (POA&M)
d. Submit security authorization package - ✔✔C & D
✔✔What activities occur when assessing security controls? (Select all that apply)
A. prepare the plan of action and milestones (POA&M)
B. conduct final risk determination
C. Develop, plan, and approve Security Assessment Plan
D. Prepare Security Assessment Report - ✔✔C & D
✔✔What activities occur when monitoring security controls? (Select all that apply)
A. Prepare the Plan of Action and Milestones (POA&M)
B. Develop, review, and approve Security Assessment Plan
C. Implement decommissioning strategy
D. Determine impact of changes - ✔✔C & D
✔✔What are the cybersecurity attributes?
Select all that apply.
A Confidentiality
B Integrity
C Availability
D Authentication
E Non-repudiation - ✔✔All of the above
✔✔Why do you need to be aware of cybersecurity?
A To uphold all elements of the National Industrial Security Program Operating Manual
B To appropriately manage risk by mitigating threats and vulnerabilities
C To examine your own actions and activities to uphold personal accountability
D To ensure all appropriate measures are taken to protect a place and ensure only
people with permission enter and leave it - ✔✔B
✔✔What are the cybersecurity drivers?
A NIST 800-30 Rev 1 Guide for Conducting Risk Assessments
B DoD 8530.01 Cybersecurity Activities Support to DoD Information Network
Operations
C DoD 8510.01 Risk Management Framework
D DoD 8500.01
E DoD Security Policy - ✔✔All of the above
✔✔Which skills do security personnel need?