Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 27 pages
Exam (elaborations)

CAP exam study questions(Cyber Security Certified Authorization Professional)Answered!!!

Document preview thumbnail
Preview 3 out of 27 pages

CAP exam study questions(Cyber Security Certified Authorization Professional)Answered!!!

Content preview

CAP exam study questions(Cyber Security Certified
Authorization Professional)Answered!!!

,What is included in the Plan of Action and Milestones (POA&M) that is presented in the
Authorizing Official (AO) as part of the initial authorization package?
A. All items identified throughout the Risk Management Framework (RMF) process
B. Only volatile findings that require prioritization in remediation
C. Deficiencies that have not yet been remediate and verified throughout the Risk
Management Framework (RMF) process
D. Only findings that have evaluated as moderate or high - Answer Deficiencies that have not yet
been remediate and verified throughout the Risk
Management Framework (RMF) process

What are the steps of a risk assessment?
A. Prepare, Conduct, Communicate, Maintain
B. Prepare, Conduct, Communicate
C. Prepare, Communicate, Conduct
D. Prepare, Communicate, Maintain, Conduct - Answer
Prepare,Conduct,Communicate,Maintain

***Which of the following cannot be delegated by the Authorizing Official (AO)?
A. Certificate resources**
B. Authorization decision
C. Acceptance of Security Plan (SP)
D. Determination of risk to agency operations - Answer Authorization Decision

Configuring an Information System (IS) to prohibit the use of unused ports and protocols
A. Helps provide least privilege
B. Helps provide least functionality
C. Streamlines the functionality of the system
D. Violates configuration management best practice - Answer Helps provide least functionality

The Authorization boundary of a system undergoing assessment includes
A. The Information System (IS) components to be authorized for operation
B. The Information (IS) components to be authorized for operation and any outside system
it connects to
C. Any components or systems the Information Owner (IO) states should be included in the
assessment
D. Any components found within the given Internet Protocol (IP) range - Answer The
Information System(IS) components to be authorized for operation

Which of the following BEST describes a government-wide standard for security Assessment and
Authorization (A&A) and continuous monitoring for cloud products, which is mandatory for federal
agencies and Cloud Service Providers (CSP)?
A. Federal Risk and Authorization Management Program (FedRAMP)

, B. National Institute of Standards and Technology (NIST)
C. Federal Information Technology Acquisition Reform Act (FITARA)
D. National Cyber Security Program (NCSP) - Answer Federal Risk and
Authorization Management Program(FedRAMP)

All Federal agencies are required by law to conduct which of the following activities?
A. Protect Information Systems (IS) used or operated by a contractor of an agency or other
organization on behalf of an agency
B. Coordinate with the National Institutes of Standards and Technologies (NIST) to develop
binding operational directives
C. Report the effectiveness of information security policies and practices to the Office of
Personnel Management (OPM)
D. Monitor the implementation of information security policies and practices of other agencies
to ensure compliance - Answer Protect Information Systems(IS) used or operated by a contractor
of an agency or other
organization on behalf of an agency

What is the PRIMARY goal of an Information Security Continuous Monitoring (ISCM) strategy?
A. Create expedited assessment process for cost savings
B. Maintain visibility of an organization's high-cost controls
C. Support organization risk management decisions
D. Assess the organizational tiers - Answer Support organization risk management decisions

An organization is developing a risk assessment for a newly installed Information System (IS) to
determine the best configuration or a supporting Information Technology (IT) product. Which of
the following specific factors is often overlooked in this analysis?
A. Exposure of interconnections to organizational core mission functions
B. Effectiveness of inherited security controls
C. Cost benefits that can be gained from a broad-based security implementation
D. Implementation of stove-piped activities that enhance security solutions - Answer
Effectiveness of inherited security controls

If an assessment of a common control determines that it is not effective, what documentation is
required?
A. Letter describing findings sent to system owners using the common control
B. Security Plan (SP) addendum for each system using the common control
C. Plan of Action and Milestones (POA&M)
D. Continuous monitoring plan - Answer Plan of Action and Milestones (POA&M)

Document information

Uploaded on
August 5, 2025
Number of pages
27
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$13.50

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
yvonnekairigo
1.0
(1)
Sold
3
Followers
1
Items
436
Last sold
4 months ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions