Page 1 of 131
FITSP – AUDITOR EXAM Q. BANK QUESTIONS
AND ANSWERS | VERIFIED AND WELL
DETAILED ANSWERS |DOWNLOAD AND PASS |
LATEST EXAM UPDATE 2026/2027
The following legislation requires each agency with an
Inspector General to conduct an annual evaluation of
agency's information security program, or to appoint an
independent external auditor, to conduct the evaluation
on their behalf:
a) E-Government Act of 2002, Title I
b) Federal Information Security Management Act (FISMA)
c) Government Information Security Reform Act (GISRA)
d) Clinger-Cohen Act
❖Federal Information Security Management Act
(FISMA)
,Page 2 of 131
How are common controls addressed in the security
authorization package? (Mark all allowable options.)
a) They include the security authorization package for the
common controls in the package being submitted.
b) They do not need to be addressed as they have already
been vetted.
c) The package being submitted can reference the security
authorization package for the common controls.
d) They are already included in the SAR, so no additional
documentation is needed.
❖They include the security authorization package for
the common controls in the package being submitted
and the package being submitted can reference the
security authorization package for the common
controls.
Which of the following would most likely trigger a re-
authorization effort? (Mark all allowable options.)
,Page 3 of 131
a) Upgrading to a new version of the server operating
system
b) Moving the data center to a new facility
c) The Authorizing Official is replaced
d) Three years have passed since the initial ATO was
granted
❖Upgrading to a new version of the server operating
system and moving the data center to a new facility
and possibly three years have passed since the initial
ATO was granted
Security authorization packages are generally submitted
by: (Pick two)
a) Independent Security Control Assessor
b) Common Control Provider
c) External Service Provider
d) Information System Owner
, Page 4 of 131
❖Common Control Provider and Information System
Owner
In the leveraged authorization approach, if the leveraging
organization determines that there is insufficient
information in the owning organization's authorization
package, what is usually done?
a) The leveraging organization negotiates with the owning
organization for more information.
b) The leveraging organization makes the authorization
decision according to the information available.
c) The leveraging organization fills in the gaps by
generating additional information "in house."
d) The Authorizing Official in the leveraging organization
issues a denial of authorization to operate and the
organization must find a different system.
❖The leveraging organization negotiates with the
owning organization for more information.
FITSP – AUDITOR EXAM Q. BANK QUESTIONS
AND ANSWERS | VERIFIED AND WELL
DETAILED ANSWERS |DOWNLOAD AND PASS |
LATEST EXAM UPDATE 2026/2027
The following legislation requires each agency with an
Inspector General to conduct an annual evaluation of
agency's information security program, or to appoint an
independent external auditor, to conduct the evaluation
on their behalf:
a) E-Government Act of 2002, Title I
b) Federal Information Security Management Act (FISMA)
c) Government Information Security Reform Act (GISRA)
d) Clinger-Cohen Act
❖Federal Information Security Management Act
(FISMA)
,Page 2 of 131
How are common controls addressed in the security
authorization package? (Mark all allowable options.)
a) They include the security authorization package for the
common controls in the package being submitted.
b) They do not need to be addressed as they have already
been vetted.
c) The package being submitted can reference the security
authorization package for the common controls.
d) They are already included in the SAR, so no additional
documentation is needed.
❖They include the security authorization package for
the common controls in the package being submitted
and the package being submitted can reference the
security authorization package for the common
controls.
Which of the following would most likely trigger a re-
authorization effort? (Mark all allowable options.)
,Page 3 of 131
a) Upgrading to a new version of the server operating
system
b) Moving the data center to a new facility
c) The Authorizing Official is replaced
d) Three years have passed since the initial ATO was
granted
❖Upgrading to a new version of the server operating
system and moving the data center to a new facility
and possibly three years have passed since the initial
ATO was granted
Security authorization packages are generally submitted
by: (Pick two)
a) Independent Security Control Assessor
b) Common Control Provider
c) External Service Provider
d) Information System Owner
, Page 4 of 131
❖Common Control Provider and Information System
Owner
In the leveraged authorization approach, if the leveraging
organization determines that there is insufficient
information in the owning organization's authorization
package, what is usually done?
a) The leveraging organization negotiates with the owning
organization for more information.
b) The leveraging organization makes the authorization
decision according to the information available.
c) The leveraging organization fills in the gaps by
generating additional information "in house."
d) The Authorizing Official in the leveraging organization
issues a denial of authorization to operate and the
organization must find a different system.
❖The leveraging organization negotiates with the
owning organization for more information.