Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 12 pages
Exam (elaborations)

CAP exam study questions with correct answers

Document preview thumbnail
Preview 2 out of 12 pages

CAP exam study questions with correct answersCAP exam study questions with correct answersCAP exam study questions with correct answers

Content preview

CAP exam study questions with
correct answers



***The Authorizing Official may accept authorization recommendations based on
A. Residual risks of similar system
B. Impact to mission personnel
C. Impact of environmental factors
D. Residual risk of the specific systems** - CORRECT ANSWER-Residual risks of similar system

***The functional description of the control implementation includes
A. The control description, effectiveness, and Plan of Action and Milestones (POA&M)
B. Planned inputs, expected behavior, and expected outputs**
C. A detailed description of the effectiveness of the control
D. The operational parameters of the control - CORRECT ANSWER-The operational parameters of the control

***When making determinations regarding the adequacy of common controls for their respective systems, Information System Owner (ISO) refer
to the Common Control Providers' (CCP)
A. Privacy Impact Assessment (PIA)
B. Business Impact Analysis (BIA)
C. Authorization Packages**
D. Vulnerability Scans - CORRECT ANSWER-Vulnerability Scans

***Which of the following BEST defines the purpose of the security assessment?
A. To determine if the remaining known vulnerability pose an acceptable level of risk
B. To determined the extent to which the security controls are implemented correctly and
operating as intended**
C. To perform oversight and monitor the security controls in the Information System (IS)
D. To perform initial risk estimate and security categorization of the Information System (IS) - CORRECT ANSWER-To determine if the remaining
known vulnerability pose an acceptable level of risk

***Which of the following cannot be delegated by the Authorizing Official (AO)?
A. Certificate resources**
B. Authorization decision
C. Acceptance of Security Plan (SP)
D. Determination of risk to agency operations - CORRECT ANSWER-Authorization Decision

***Which of the following documents is updated when a vulnerability is discovered during continuous monitoring?
A. Plan of Action and Milestones (POA&M)**
B. Business Impact Analysis (BIA)
C. Security Assessment Report (SAR)
D. Incident Response Plan (IRP) - CORRECT ANSWER-Security Assessment Report(SAR)

***Which of the following is the mutual agreement among participating organizations to accept one another's security assessments in order to
reuse system resources or to accept each other's assessed security posture in order to share information?
A. Memorandum of Understanding (MOU)
B. Memorandum of Agreement (MOA)
C. Reciprocity**
D. Reuse - CORRECT ANSWER-Memorandum of Agreement(MOA)

***Which process guides the selection of security controls to ensure adequate security commensurate with the risk of the organization?
A. Risk assessment
B. Security categorization**
C. Vulnerability assessment
D. Privacy Impact Assessment (PIA) - CORRECT ANSWER-Risk assessment

***Which will an Authorizing Official (AO) find implementation details for a control?
A. Plan of Action and Milestones (POA&M)
B. Security and Privacy Plans**
C. Continuous monitoring strategy
D. Risk Assessment Report (RAR) - CORRECT ANSWER-Risk Assessment Report(RAR)

, 114. What is the PRIMARY goal for establishing Information System (IS) boundaries?
A. Identify common security controls
B. Be cost effective
C. Include mitigation for connection to legacy IS
D. Be flexible enough to accommodate major changes without re-authorizing the system - CORRECT ANSWER-Identify common security
controls

A key part of the risk decision process is the recognition that, regardless of the risk response there typically remains a degree of residual risk. On
what basis does an organization determine the acceptable degrees of residual risk?
A. Risk avoidance
B. Risk mitigation
C. Risk tolerance
D. Risk transfer - CORRECT ANSWER-Risk tolerance

A minor application is being added to an existing accredited distributed system.
This application does not require any additional security functionality other than that
provided by the distributed system. Which of the following actions is taken?
A. The owner of the distributed system is responsible for the new application, and adds it to
the existing distributed system Security Plan (SP)
B. The owner of the distributed system needs to create a separate Security Plan (SP) and
reference the distributed system Security Plan (SP)
C. The owner of the new application needs to create an addendum/ application to the
distributed system Security Plan (SP) detailing the necessary additional security
mechanisms for the new application
D. The owner of the new application is responsible for updating the distributed system
Security Plan (SP) with the new application information - CORRECT ANSWER-The owner of the distributed system is responsible for the new
application, and adds it to
the existing distributed system Security Plan (SP)

A Security Control Assessment (SCA) was completed over two years ago, but the surrounding environment has changed. What, if anything,
should the assessment team do with the previous results?
A. Assessment only those controls that have changed
B. Designed since the results are too old
C. Assess all controls for the system
D. Determine changes and impacts - CORRECT ANSWER-Assess all controls for the system

A System Owner (SO) is implementing a new system with their existing organization Information Technology (IT) environment. What objectives
are considered when determining possible impact to risk?
A. Low, Moderate, and High
B. Authentication, Authorization, and Accountability
C. Common, Hybrid, and System-Specific
D. Integrity, Confidentiality, and Availability - CORRECT ANSWER-Integrity ,Confidentiality ,and Availability

All Federal agencies are required by law to conduct which of the following activities?
A. Protect Information Systems (IS) used or operated by a contractor of an agency or other
organization on behalf of an agency
B. Coordinate with the National Institutes of Standards and Technologies (NIST) to develop
binding operational directives
C. Report the effectiveness of information security policies and practices to the Office of
Personnel Management (OPM)
D. Monitor the implementation of information security policies and practices of other
agencies to ensure compliance - CORRECT ANSWER-Protect Information Systems(IS) used or operated by a contractor of an agency or other
organization on behalf of an agency

An effective continuous monitoring strategy includes which of the following?
A. Implementation of the United States Government Configuration Baseline (USGCB)
B. Adherence to the organization's approved enterprise architecture
C. Documenting the functional security baseline configuration
D. Reporting of security and privacy posture to organizational officials - CORRECT ANSWER-Reporting of security and privacy posture to
organizational officials

An Information System (IS) has the following Security Categories (SC) for each information type:
SC public information = (confidentiality, NA), (integrity, HIGH), (availability, LOW) SC investigation information = (confidentiality, MODERATE),
(integrity, HIGH), (availability, MODERATE)SC administrative = (confidentiality, NA), (integrity, LOW), (availability, LOW
What is the overall IS security category for confidentiality
A. LOW
B. MODERATE
C. HIGH
D. N/A - CORRECT ANSWER-MODERATE

An Information System (IS) is registered with appropriate program/management offices in order to
A. Manage and track the system
B. Determine security categorization
C. Set security authorization boundaries
D. Initiate the risk management process - CORRECT ANSWER-Manage and track the system

An organization is developing a risk assessment for a newly installed Information System (IS) to determine the best configuration or a supporting
Information Technology (IT) product. Which of the following specific factors is often overlooked in this analysis?
A. Exposure of interconnections to organizational core mission functions
B. Effectiveness of inherited security controls
C. Cost benefits that can be gained from a broad-based security implementation
D. Implementation of stove-piped activities that enhance security solutions - CORRECT ANSWER-Effectiveness of inherited security controls

An organization should consider which elements when selecting an assessment
team?
A. Expertise and cost

Document information

Uploaded on
November 1, 2024
Number of pages
12
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$10.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
solutionsstudy
4.0
(2)
Sold
23
Followers
2
Items
599
Last sold
2 months ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions