FITSP EVALUATION EXAMS 2025/2026 QUESTIONS WITH
ANSWERS RATED A+
✔✔Clinger-Cohen Act (CCA) _. - ✔✔legislation requires federal agencies to develop,
document and implement agency-wide security programs
✔✔E-Government Act of 2002 - ✔✔legislation requires each agency with an Inspector
General to conduct annual evaluations of information security programs or to appoint an
independent external auditor
✔✔OMB Circular A-130, Appendix III Security of Federal Automated Information
Resources - ✔✔OMB guidance - requires federal agencies to review security controls in
each system when significant modifications are made, or at least every three years
✔✔DHS and OMB - ✔✔FISMA 2014 assign information security to these agencies
✔✔FISM - ✔✔Memorandums done by DHS
✔✔What are the two FISMs put out by DHS? - ✔✔FISM 11-01 TIC reference
architecture 2.0
FISM 12-02 Reporting Instructions for FISMA and Agency Privacy Management
✔✔SP800-82 Rev 2 - ✔✔Continuous Monitoring
✔✔How are the OMB memorandums organized? - ✔✔By Year
✔✔Four Areas of CIO responsibilities: - ✔✔Governance, Commodity IT, Program
Management and Information Security
✔✔SCAP - ✔✔Security Content Automation Protocol. A method with automated
vulnerability management, measurement, and policy compliance evaluation tools
✔✔OMB M-06-16 - ✔✔Protection of Sensitive Agency Information -requires
- encryption of all data on mobile computers/devices
- permits remote access only with two-factor authentication, where one factor is
provided by a device separate from the computer gaining access
-use a time-out function for remote access and mobile devices requiring user re-
authentication after 30 min of inactivity
✔✔risk management approach - ✔✔continually balances the protection of information
and assets with the cost of security controls and mitigation strategies
✔✔What are the six steps of RMF process? - ✔✔categorize, select, implement, assess,
authorize, monitor
, ✔✔what phase of sdlc should the organization consider security requirements? -
✔✔initiation phase/development/acquisition
✔✔security authorization are conducted during which SDLC phase? -
✔✔operations/maintenance
✔✔NIST publication superseded SP800-30 - ✔✔SP800-39
✔✔gap analysis - ✔✔First three steps of the RMF to the legacy system to determine if
the necessary and sufficient security controls have been appropriately selected and
allocated.
✔✔What are the three tiers of the Risk Management Approach - ✔✔Organization
Mission/Business Process
Information System
✔✔Information System Continuous Monitoring updates - ✔✔System Security Plan
(SSP), System Access Report (SAR) and Plan of Action Milestones (POAM)
✔✔Security status reporting - ✔✔time and event driven
✔✔Final step of ISCM - ✔✔review and update the monitoring program
✔✔SCAP specification provide standard naming and dictionary of system configuration
- ✔✔CPE (common platform enumeration)
✔✔What are the resources of national vulnerability database (NVB) - ✔✔CPE, CVE and
OVAL
✔✔What are the categories of controls in NIST Handbook? - ✔✔Management,
Operational, and Technical
✔✔Computer Security Act of 1987 - ✔✔Requires federal agencies
to identify and protect computer systems that contain sensitive information.
conduct computer security training
develop computer security plans.
✔✔Three assessments methods by NIST SP - ✔✔Examine, Interview and Test
✔✔SP800-113 - Guide to SSL VPN - ✔✔Secure Portal VPNs and Secure Tunnel VPNs
✔✔SP800-81 - ✔✔Run name server software with restricted priviledges
ANSWERS RATED A+
✔✔Clinger-Cohen Act (CCA) _. - ✔✔legislation requires federal agencies to develop,
document and implement agency-wide security programs
✔✔E-Government Act of 2002 - ✔✔legislation requires each agency with an Inspector
General to conduct annual evaluations of information security programs or to appoint an
independent external auditor
✔✔OMB Circular A-130, Appendix III Security of Federal Automated Information
Resources - ✔✔OMB guidance - requires federal agencies to review security controls in
each system when significant modifications are made, or at least every three years
✔✔DHS and OMB - ✔✔FISMA 2014 assign information security to these agencies
✔✔FISM - ✔✔Memorandums done by DHS
✔✔What are the two FISMs put out by DHS? - ✔✔FISM 11-01 TIC reference
architecture 2.0
FISM 12-02 Reporting Instructions for FISMA and Agency Privacy Management
✔✔SP800-82 Rev 2 - ✔✔Continuous Monitoring
✔✔How are the OMB memorandums organized? - ✔✔By Year
✔✔Four Areas of CIO responsibilities: - ✔✔Governance, Commodity IT, Program
Management and Information Security
✔✔SCAP - ✔✔Security Content Automation Protocol. A method with automated
vulnerability management, measurement, and policy compliance evaluation tools
✔✔OMB M-06-16 - ✔✔Protection of Sensitive Agency Information -requires
- encryption of all data on mobile computers/devices
- permits remote access only with two-factor authentication, where one factor is
provided by a device separate from the computer gaining access
-use a time-out function for remote access and mobile devices requiring user re-
authentication after 30 min of inactivity
✔✔risk management approach - ✔✔continually balances the protection of information
and assets with the cost of security controls and mitigation strategies
✔✔What are the six steps of RMF process? - ✔✔categorize, select, implement, assess,
authorize, monitor
, ✔✔what phase of sdlc should the organization consider security requirements? -
✔✔initiation phase/development/acquisition
✔✔security authorization are conducted during which SDLC phase? -
✔✔operations/maintenance
✔✔NIST publication superseded SP800-30 - ✔✔SP800-39
✔✔gap analysis - ✔✔First three steps of the RMF to the legacy system to determine if
the necessary and sufficient security controls have been appropriately selected and
allocated.
✔✔What are the three tiers of the Risk Management Approach - ✔✔Organization
Mission/Business Process
Information System
✔✔Information System Continuous Monitoring updates - ✔✔System Security Plan
(SSP), System Access Report (SAR) and Plan of Action Milestones (POAM)
✔✔Security status reporting - ✔✔time and event driven
✔✔Final step of ISCM - ✔✔review and update the monitoring program
✔✔SCAP specification provide standard naming and dictionary of system configuration
- ✔✔CPE (common platform enumeration)
✔✔What are the resources of national vulnerability database (NVB) - ✔✔CPE, CVE and
OVAL
✔✔What are the categories of controls in NIST Handbook? - ✔✔Management,
Operational, and Technical
✔✔Computer Security Act of 1987 - ✔✔Requires federal agencies
to identify and protect computer systems that contain sensitive information.
conduct computer security training
develop computer security plans.
✔✔Three assessments methods by NIST SP - ✔✔Examine, Interview and Test
✔✔SP800-113 - Guide to SSL VPN - ✔✔Secure Portal VPNs and Secure Tunnel VPNs
✔✔SP800-81 - ✔✔Run name server software with restricted priviledges