Fitsp - Auditor Questions With Correct Answer
The cfollowing clegislation crequires cfederal cagencies cto cestablish ccapital cplanning cand cinvestmen
cprocedures cwhen cprocuring cinformation ctechnology:
a) cE-Government cAct cof c2002
b) cFederal cInformation cSecurity cManagement cAct c(FISMA)
c) cGovernment cInformation cSecurity cReform cAct c(GISRA)
d) cClinger-Cohen cAct c- cCORRECT cANS✔✔Clinger-Cohen cAct
The cfollowing clegislation crequires cfederal cagencies cto cappoint ca cChief cInformation cOfficer:
a) cE-Government cAct cof c2002
b) cFederal cInformation cSecurity cManagement cAct c(FISMA)
c) cGovernment cInformation cSecurity cReform cAct c(GISRA)
d) cClinger-Cohen cAct c- cCORRECT cANS✔✔Clinger-Cohen cAct
The cfollowing clegislation crequires cfederal cagencies cto cdevelop, cdocument, cand cimplement can c
csecurity cprogram:
a) cE-Government cAct cof c2002, cSection c208
b) cFederal cInformation cSecurity cManagement cAct c(FISMA)
c) cGovernment cInformation cSecurity cReform cAct c(GISRA)
d) cClinger-Cohen cAct c- cCORRECT cANS✔✔Federal cInformation cSecurity cManagement cAct c(FIS
The cfollowing clegislation crequires cfederal cagencies cto cprepare cPrivacy cImpact cAssessments c(P
cprocuring cnew cinformation ctechnology:
a) cE-Government cAct cof c2002, cSection c208
b) cFederal cInformation cSecurity cManagement cAct c(FISMA)
c) cPrivacy cAct, c1974
d) cClinger-Cohen cAct c- cCORRECT cANS✔✔E-Government cAct cof c2002, cSection c208
The cfollowing clegislation crequires ceach cagency cwith can cInspector cGeneral cto cconduct can cannu
cinformation csecurity cprogram, cor cto cappoint can
independent cexternal cauditor, cto cconduct cthe cevaluation con ctheir cbehalf:
,d) cOMB cCircular cNo. cA-136, cFinancial cManagement cReporting cRequirements c- cCORRECT cAN
cAppendix cIII, cSecurity cof cFederal cAutomated cInformation cResources
The cFederal cInformation cSecurity cModernization cAct cof c2014 c(FISMA c2014) cformally cassigns c
cresponsibilities cto cwhich cof cthe cfollowing cagencies/departments c(select ctwo):
a) cCommerce
b) cDHS
c) cJustice
d) cOMB c- cCORRECT cANS✔✔DHS cand cOMB
What cis cthe crequired cfrequency cof cFISMA creporting cfeeds cfor cCFO cAct cagencies?
a) cMonthly
b) cQuarterly
c) cSemi-annually
d) cAnnually c- cCORRECT cANS✔✔Monthly
Which claw cdirected cthe cSecretary cof cHealth cand cHuman cServices cto cdevelop cstandards cfor cp
cinformation?
a) cAARA
b) cHITECH
c) cHIPAA
d) cePHI c- cCORRECT cANS✔✔HIPAA
Current cregulations cstill crequire cthe cre-authorization cof cFederal cinformation csystems cat cleast ce
a) cTrue
b) cFalse c- cCORRECT cANS✔✔False
As cpart cof cmonitoring cthe csecurity cposture cof cagency cdesktops, cOMB crequires cFederal cagenc
use cvulnerability cscanning ctools cthat cleverage cthe cprotocol.
a) cSNMP
b) cSMTP
c) cSCAP
d) cLDAP c- cCORRECT cANS✔✔SCAP
Following cthe closs cof c26 cmillion crecords ccontaining cPll cat cthe cDepartment cof cVeteran cAffairs, c
cProtection cof cSensitive cAgency cInformation. cThis cmemo crequired call cof cthe cfollowing cexcept:
a) cEncryption cof call cdata con cmobile ccomputers/devices
b) cPermits cremote caccess conly cwith ctwo-factor cauthentication, cfor cwhich cone cfactor cis cprovide
cthe ccomputer cgaining caccess
c) cUse ca c"time-out" cfunction cfor cremote caccess cand cmobile cdevices crequiring cuser creauthentic
cinactivity
d) cEncryption cof call cserver cbackup ctapes c- cCORRECT cANS✔✔Encryption cof call cserver cbacku
This cHomeland cSecurity cPresidential cDirective crequires call cFederal cagencies cto cadopt ca cstand
government-wide ccard cto creduce cidentity cfraud, cprotect cpersonal cprivacy, cand cprovide cfor
authentication. cThis cdirective cis ccalled:
a) cReal-ID cAct
b) cHSPD-12 c- cCommon cIdentification cStandard
c) cCritical cInfrastructure cProtection cAct
d) cHSPD c24 c- cBiometrics cto cEnhance cNational cSecurity cAct c- cCORRECT cANS✔✔HSPD-12 c-
cStandard
FISMA cReporting cMetrics care cnow cpublished cannually cby cwhat cagency/department?
a) cOMB
b) cCommerce
, The cfollowing cOMB cmemo cannounced cimplementation cof ccommonly caccepted csecurity cconfigu
csystems.
a) cM-07-18
b) cM-09-32
c) cM-10-28
d) cM-07-11 c- cCORRECT cANS✔✔M-07-11
With cthe cpublication cof cOMB cM-14-04, cFiscal cYear c2013 cReporting cInstructions cfor cFISMA can
cManagement, cthe csignatures cof cthe cfollowing ctwo
individuals con cthe cATO care crequired cto cauthorize ca cnew cinformation csystem cto coperate
(select ctwo):
a) cCISO
b) cCIO
c) cAO
d) cSAOP c- cCORRECT cANS✔✔AO cand cSAOP
The cFISCAM ccontrol chierarchy cconsists cof call cof cthe cfollowing cEXCEPT:
a) cControl cactivities
b) cControl cobjectives
c) cCritical celements
d) cControl ccategories c- cCORRECT cANS✔✔Control cobjectives
FISCAM crecommends cusing cthe cindependence cstandards cin cthe cdetermine cthe cauditor's cindep
caudit/evaluation.
a) cWhite cBook
b) cOrange cBook
c) cYellow cBook
d) cGreen cBook c- cCORRECT cANS✔✔Yellow cBook
Which claw cgave cOMB cthe cauthority cto cdefine cpolicies cfor cUS cGovernment cAgencies? c- cCORR
cReduction cAct c(PRA) c- cGranted cOMB cthe cresponsibility cto cdevelop
Government-wide cpolicies cto chelp cother cfederal cagencies ccomply cwith cthe ccongressional
mandates.
Which claw cassigned cresponsibilities cto cNIST cfor ccreating cstandards cand cguidelines crelating cto
Federal cInformation cSystems? c- cCORRECT cANS✔✔Computer cSecurity cAct c(CSA) c& cFederal c
cManagement cAct(FISMA) c- cDelegated cresponsibility cto cNIST cand cthe cNSA cto ccreate cstandard
help cfederal cagencies ccomply cwith ccongressional cmandates.
Which cOMB cprogram cprovides ca cstructure cfor cAgencies cto cidentify cbusiness cprocesses? c- cCO
cEnterprise cArchitecture cBusiness cReference cModel c(FEA cBRM) cprovides ca cstructure cfor cAgen
cprocesses.
Which cdocument cprovides ca cpolicy cframework cfor cinformation cresources cmanagement cacross c
cCORRECT cANS✔✔OMB cCircular cA-130
Which cOMB cmemo crequires cthat cagencies csafeguard cagainst cand crespond cto cbreaches cof cpe
cinformation? c- cCORRECT cANS✔✔OMB cM-07-16
Name can cinitiative cto ccreate csecurity cconfiguration cbaselines cfor cInformation cTechnology cprodu
cthe cfederal cagencies. c- cCORRECT cANS✔✔U.S. cGovernment cConfiguration cBaseline c(USGCB
Agencies care crequired cto cadhere cto cDHS' cdirection cto creport cdata cthrough cthis cautomated crep
crequired cfrequency cof cthese cdata cfeeds? c- cCORRECT cANS✔✔CyberScope; cMonthly cfor cCFO
The cfollowing clegislation crequires cfederal cagencies cto cestablish ccapital cplanning cand cinvestmen
cprocedures cwhen cprocuring cinformation ctechnology:
a) cE-Government cAct cof c2002
b) cFederal cInformation cSecurity cManagement cAct c(FISMA)
c) cGovernment cInformation cSecurity cReform cAct c(GISRA)
d) cClinger-Cohen cAct c- cCORRECT cANS✔✔Clinger-Cohen cAct
The cfollowing clegislation crequires cfederal cagencies cto cappoint ca cChief cInformation cOfficer:
a) cE-Government cAct cof c2002
b) cFederal cInformation cSecurity cManagement cAct c(FISMA)
c) cGovernment cInformation cSecurity cReform cAct c(GISRA)
d) cClinger-Cohen cAct c- cCORRECT cANS✔✔Clinger-Cohen cAct
The cfollowing clegislation crequires cfederal cagencies cto cdevelop, cdocument, cand cimplement can c
csecurity cprogram:
a) cE-Government cAct cof c2002, cSection c208
b) cFederal cInformation cSecurity cManagement cAct c(FISMA)
c) cGovernment cInformation cSecurity cReform cAct c(GISRA)
d) cClinger-Cohen cAct c- cCORRECT cANS✔✔Federal cInformation cSecurity cManagement cAct c(FIS
The cfollowing clegislation crequires cfederal cagencies cto cprepare cPrivacy cImpact cAssessments c(P
cprocuring cnew cinformation ctechnology:
a) cE-Government cAct cof c2002, cSection c208
b) cFederal cInformation cSecurity cManagement cAct c(FISMA)
c) cPrivacy cAct, c1974
d) cClinger-Cohen cAct c- cCORRECT cANS✔✔E-Government cAct cof c2002, cSection c208
The cfollowing clegislation crequires ceach cagency cwith can cInspector cGeneral cto cconduct can cannu
cinformation csecurity cprogram, cor cto cappoint can
independent cexternal cauditor, cto cconduct cthe cevaluation con ctheir cbehalf:
,d) cOMB cCircular cNo. cA-136, cFinancial cManagement cReporting cRequirements c- cCORRECT cAN
cAppendix cIII, cSecurity cof cFederal cAutomated cInformation cResources
The cFederal cInformation cSecurity cModernization cAct cof c2014 c(FISMA c2014) cformally cassigns c
cresponsibilities cto cwhich cof cthe cfollowing cagencies/departments c(select ctwo):
a) cCommerce
b) cDHS
c) cJustice
d) cOMB c- cCORRECT cANS✔✔DHS cand cOMB
What cis cthe crequired cfrequency cof cFISMA creporting cfeeds cfor cCFO cAct cagencies?
a) cMonthly
b) cQuarterly
c) cSemi-annually
d) cAnnually c- cCORRECT cANS✔✔Monthly
Which claw cdirected cthe cSecretary cof cHealth cand cHuman cServices cto cdevelop cstandards cfor cp
cinformation?
a) cAARA
b) cHITECH
c) cHIPAA
d) cePHI c- cCORRECT cANS✔✔HIPAA
Current cregulations cstill crequire cthe cre-authorization cof cFederal cinformation csystems cat cleast ce
a) cTrue
b) cFalse c- cCORRECT cANS✔✔False
As cpart cof cmonitoring cthe csecurity cposture cof cagency cdesktops, cOMB crequires cFederal cagenc
use cvulnerability cscanning ctools cthat cleverage cthe cprotocol.
a) cSNMP
b) cSMTP
c) cSCAP
d) cLDAP c- cCORRECT cANS✔✔SCAP
Following cthe closs cof c26 cmillion crecords ccontaining cPll cat cthe cDepartment cof cVeteran cAffairs, c
cProtection cof cSensitive cAgency cInformation. cThis cmemo crequired call cof cthe cfollowing cexcept:
a) cEncryption cof call cdata con cmobile ccomputers/devices
b) cPermits cremote caccess conly cwith ctwo-factor cauthentication, cfor cwhich cone cfactor cis cprovide
cthe ccomputer cgaining caccess
c) cUse ca c"time-out" cfunction cfor cremote caccess cand cmobile cdevices crequiring cuser creauthentic
cinactivity
d) cEncryption cof call cserver cbackup ctapes c- cCORRECT cANS✔✔Encryption cof call cserver cbacku
This cHomeland cSecurity cPresidential cDirective crequires call cFederal cagencies cto cadopt ca cstand
government-wide ccard cto creduce cidentity cfraud, cprotect cpersonal cprivacy, cand cprovide cfor
authentication. cThis cdirective cis ccalled:
a) cReal-ID cAct
b) cHSPD-12 c- cCommon cIdentification cStandard
c) cCritical cInfrastructure cProtection cAct
d) cHSPD c24 c- cBiometrics cto cEnhance cNational cSecurity cAct c- cCORRECT cANS✔✔HSPD-12 c-
cStandard
FISMA cReporting cMetrics care cnow cpublished cannually cby cwhat cagency/department?
a) cOMB
b) cCommerce
, The cfollowing cOMB cmemo cannounced cimplementation cof ccommonly caccepted csecurity cconfigu
csystems.
a) cM-07-18
b) cM-09-32
c) cM-10-28
d) cM-07-11 c- cCORRECT cANS✔✔M-07-11
With cthe cpublication cof cOMB cM-14-04, cFiscal cYear c2013 cReporting cInstructions cfor cFISMA can
cManagement, cthe csignatures cof cthe cfollowing ctwo
individuals con cthe cATO care crequired cto cauthorize ca cnew cinformation csystem cto coperate
(select ctwo):
a) cCISO
b) cCIO
c) cAO
d) cSAOP c- cCORRECT cANS✔✔AO cand cSAOP
The cFISCAM ccontrol chierarchy cconsists cof call cof cthe cfollowing cEXCEPT:
a) cControl cactivities
b) cControl cobjectives
c) cCritical celements
d) cControl ccategories c- cCORRECT cANS✔✔Control cobjectives
FISCAM crecommends cusing cthe cindependence cstandards cin cthe cdetermine cthe cauditor's cindep
caudit/evaluation.
a) cWhite cBook
b) cOrange cBook
c) cYellow cBook
d) cGreen cBook c- cCORRECT cANS✔✔Yellow cBook
Which claw cgave cOMB cthe cauthority cto cdefine cpolicies cfor cUS cGovernment cAgencies? c- cCORR
cReduction cAct c(PRA) c- cGranted cOMB cthe cresponsibility cto cdevelop
Government-wide cpolicies cto chelp cother cfederal cagencies ccomply cwith cthe ccongressional
mandates.
Which claw cassigned cresponsibilities cto cNIST cfor ccreating cstandards cand cguidelines crelating cto
Federal cInformation cSystems? c- cCORRECT cANS✔✔Computer cSecurity cAct c(CSA) c& cFederal c
cManagement cAct(FISMA) c- cDelegated cresponsibility cto cNIST cand cthe cNSA cto ccreate cstandard
help cfederal cagencies ccomply cwith ccongressional cmandates.
Which cOMB cprogram cprovides ca cstructure cfor cAgencies cto cidentify cbusiness cprocesses? c- cCO
cEnterprise cArchitecture cBusiness cReference cModel c(FEA cBRM) cprovides ca cstructure cfor cAgen
cprocesses.
Which cdocument cprovides ca cpolicy cframework cfor cinformation cresources cmanagement cacross c
cCORRECT cANS✔✔OMB cCircular cA-130
Which cOMB cmemo crequires cthat cagencies csafeguard cagainst cand crespond cto cbreaches cof cpe
cinformation? c- cCORRECT cANS✔✔OMB cM-07-16
Name can cinitiative cto ccreate csecurity cconfiguration cbaselines cfor cInformation cTechnology cprodu
cthe cfederal cagencies. c- cCORRECT cANS✔✔U.S. cGovernment cConfiguration cBaseline c(USGCB
Agencies care crequired cto cadhere cto cDHS' cdirection cto creport cdata cthrough cthis cautomated crep
crequired cfrequency cof cthese cdata cfeeds? c- cCORRECT cANS✔✔CyberScope; cMonthly cfor cCFO