• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 39 pages
Exam (elaborations)

CASP 003 UPDATED ACTUAL Exam Questions and CORRECT Answers

Document preview thumbnail
Preview 4 out of 39 pages

CASP 003 UPDATED ACTUAL Exam Questions and CORRECT Answers Risk Management Process - CORRECT ANSWER analyzation 5. mitigation - 1. identification 2. assessment 4. NIST SP 800-39 RMF six unique stages - CORRECT ANSWER - 1. categorize the info systems and data 2. select security controls 3. implement controls 4. assess the effectiveness of the controls 5. authorize the info system 6. monitor the controls (CSIAAM) ISO/IEC 27000 - CORRECT ANSWER - The ISO/IEC 27000-series (also known as the 'ISMS Family of Standards' or 'ISO27K' for short) comprises information security standards published jointly by the International Organization for Standardization (ISO) and the

Content preview

CASP 003 UPDATED ACTUAL Exam
Questions and CORRECT Answers
Risk Management Process - CORRECT ANSWER - 1. identification 2. assessment 4.
analyzation 5. mitigation


NIST SP 800-39 RMF six unique stages - CORRECT ANSWER - 1. categorize the info
systems and data 2. select security controls 3. implement controls 4. assess the effectiveness of
the controls 5. authorize the info system 6. monitor the controls (CSIAAM)


ISO/IEC 27000 - CORRECT ANSWER - The ISO/IEC 27000-series (also known as the
'ISMS Family of Standards' or 'ISO27K' for short) comprises information security standards
published jointly by the International Organization for Standardization (ISO) and the
International Electrotechnical Commission (IEC).[1]
The series provides best practice recommendations on information security management—the
management of information risks through information security controls—within the context of
an overall Information security management system (ISMS), similar in design to management
systems for quality assurance (the ISO 9000 series), environmental protection (the ISO 14000
series) and other management systems


Gramm-Leach-Bliley Act - CORRECT ANSWER - requires financial institutions to
ensure the security and confidentiality of customer data (PII)


Sarbanes-Oxley Act of 2002 - CORRECT ANSWER - established requirements for proper
financial record keeping for public companies and penalties of as much as 25 years in prison for
noncompliance


FISMA - CORRECT ANSWER - federal info security management act - US law requires
federal agencies to create, document and implement security program


PCI DSS - CORRECT ANSWER - payment card industry data security standard - security
standards for credit card companies to protect transactions and data. It is a contractual
requirement although some states treat it as law.

,EU Directive 2002/58/EC and 2009/136/EC - CORRECT ANSWER - 2002 directive -
aimed at privacy and electronic communications service providers to provide security with
services. 2009 directive - amended to require user consent before cookies are installed (the
cookie law)


GDPR (General Data Protection Regulation) - CORRECT ANSWER - New European
Union law on data protection and privacy for individuals for all EU citizens


Cloud Act - CORRECT ANSWER - bill the U.S. created in 2018 that empowers the gov to
issue warrants that compel Americans businesses to pull data from their servers stored locally
and internationally


COBIT (Control Objectives for Information and related Technology) - CORRECT
ANSWER - Framework set of best practices for IT management created by ISACA and
the ITGI, assists orgs in maximizing the benefits from the use of information technology


HITECH - CORRECT ANSWER - Health Information Technology for Economic and
Clinical Health Act - widens the scope of privacy and security protections available under
HIPAA, imposes data breach notification requirements, increases legal liability for
noncompliance, and extends to software vendors of electronic medical records.


Deperimeterization - CORRECT ANSWER - occurs when an organization moves
employees outside its firewall, a growing movement to change the way corporations address
technology security


BYOD - CORRECT ANSWER - makes it possible for users to be free to use their
personal devices to access a corporate or a campus network


COPE (Corporate Owned, Personally Enabled) - CORRECT ANSWER - Bridges the gap
by providing corporate owned resources that employees can use for personal tasks.

,CYOD (Choose Your Own Device) - CORRECT ANSWER - Enables employees to
choose from a list of company approved choices.


MDM (mobile device management) - CORRECT ANSWER - An effort to add controls to
a enterprise environment
Can push security policies & applications while also monitoring devices


NIST 800-53 - CORRECT ANSWER - Framework that recommends security controls for
federal info systems and organizations except those designed for national security.


FIPS 199 - CORRECT ANSWER - Standards for Security Categorization of Federal
Information and Information Systems. Categorizes info systems based on low, moderate, or high
relative to CIA. the highest score for each category is the overall category for that system.


Risk Analysis Goals - CORRECT ANSWER - 1. identify assets and their value 2. identify
vulnerabilities and threats 3. calculate threat probability and impact 4. balance threat impact with
cost of control


SLE (Single Loss Expectancy) - CORRECT ANSWER - SLE is the total of hardware,
labor costs and downtime costs for one incident. SLE is equal to asset value times exposure
factor. SLE = AVxEF


ALE (Annual Loss Expectancy) - CORRECT ANSWER - a monetary measure of how
much loss you could expect in a year, equal to SLE times the rate of occurance. ALE=SLE x
ARO


NIST 800-30 Guide for conducting risk assessments (6 steps) - CORRECT ANSWER - 1.
identify assets and their value 2. identify threats. 3. identify vulnerabilities. 4. determine
likelihood 5. identify impact 6. determine risk of likelihood and impact


NIST 800-34 contingency planning guide (7 steps) - CORRECT ANSWER - 1. develop a
policy for contingency planning 2. conduct a BIA 3. identify preventative controls 4. create
recovery strategies 5. develop the BCP 6. test, train and exercise the BCP 7. maintain the BCP

, Security Policy Categories - CORRECT ANSWER - regulatory - mandated. advisory -
recommendations. information - gentle reminders.


SABSA (Sherwood Applied Business Security Architecture) Framework - CORRECT
ANSWER - framework and methodology for enterprise security architecture and service
management


TCA (third party connection agreement) - CORRECT ANSWER - dictates security
controls that should be taken to protect the data being exchanged between partners


ISA (Interconnection Security Agreement) - CORRECT ANSWER - An agreement
between parties that operate connected IT systems intended to minimize security risks for data
transmitted across a network.


Computer Fraud and Abuse Act of 1986 - CORRECT ANSWER - defines hacking of
protected computers, prohibits access without authorization


PIPEDA (Personal Information Protection and Electronic Documents Act) - CORRECT
ANSWER - Canadian law that governs how private organizations collect, use, and disclose
personal information


Economic Espionage Act (1996) - CORRECT ANSWER - a law that makes the theft of
trade secrets by foreign entities a federal crime in the United States


USA Patriot Act - CORRECT ANSWER - Antiterrorism law that allowed the government
certain rights and tools to investigate terrorism


BIA 4 steps - CORRECT ANSWER - 1. identify critical assets 2. identify impact and est.
downtime 3. identify resource requirements 4. identify priorities for recovery

Document information

Uploaded on
June 24, 2025
Number of pages
39
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$14.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
STANFORDGRADESS
4.0
(240)
Sold
1653
Followers
108
Items
119940
Last sold
2 hours ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions