• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 4 fuera de 53 páginas
Examen

FITSP AUDITOR QUESTIONS AND ANSWERS

Document preview thumbnail
Vista previa 4 fuera de 53 páginas

FITSP AUDITOR QUESTIONS AND ANSWERS The following legislation requires federal agencies to establish capital planning and investment control policies and procedures when procuring information technology: a) E-Government Act of 2002 b) Federal Information Security Management Act (FISMA) c) Government Information Security Reform Act (GISRA) d) Clinger-Cohen Act - CORRECT ANSWERClinger-Cohen Act

Vista previa del contenido

FITSP AUDITOR QUESTIONS AND ANSWERS
The following legislation requires federal agencies to establish capital planning and investment control
policies and procedures when procuring information technology:

a) E-Government Act of 2002

b) Federal Information Security Management Act (FISMA)

c) Government Information Security Reform Act (GISRA)

d) Clinger-Cohen Act - CORRECT ANSWER✅✅Clinger-Cohen Act



The following legislation requires federal agencies to appoint a Chief Information Officer:

a) E-Government Act of 2002

b) Federal Information Security Management Act (FISMA)

c) Government Information Security Reform Act (GISRA)

d) Clinger-Cohen Act - CORRECT ANSWER✅✅Clinger-Cohen Act



The following legislation requires federal agencies to develop, document, and implement an agency-
wide information security program:

a) E-Government Act of 2002, Section 208

b) Federal Information Security Management Act (FISMA)

c) Government Information Security Reform Act (GISRA)

d) Clinger-Cohen Act - CORRECT ANSWER✅✅Federal Information Security Management Act (FISMA)



The following legislation requires federal agencies to prepare Privacy Impact Assessments (PIAs) when
developing or procuring new information technology:

a) E-Government Act of 2002, Section 208

b) Federal Information Security Management Act (FISMA)

c) Privacy Act, 1974

d) Clinger-Cohen Act - CORRECT ANSWER✅✅E-Government Act of 2002, Section 208



The following legislation requires each agency with an Inspector General to conduct an annual
evaluation of agency's information security program, or to appoint an

,independent external auditor, to conduct the evaluation on their behalf:

a) E-Government Act of 2002, Title I

b) Federal Information Security Management Act (FISMA)

c) Government Information Security Reform Act (GISRA)

d) Clinger-Cohen Act - CORRECT ANSWER✅✅Federal Information Security Management Act (FISMA)



The Secretary of what department or agency was delegated the responsibility by FISMA to prescribe
standards and guidelines pertaining to federal information systems

to improve the efficiency of operation or security of Federal information systems:

a) Department of Homeland Security (DHS)

b) Defense Department

c) Commerce Department

d) National Security Agency - CORRECT ANSWER✅✅



The following OMB guidance established the requirement for federal agencies to review the security
controls in each system when significant modifications are made to

the system, or at least every three years. This guidance also requires federal agencies to re-authorize
information systems every three years.

a) OMB Circular No. A-123- Management Accountability and Control

b) OMB Circular No. A-130, Appendix III, Security of Federal Automated Information Resources

c) OMB Circular No. A-127, Financial Management Systems

d) OMB Circular No. A-136, Financial Management Reporting Requirements - CORRECT
ANSWER✅✅OMB Circular No. A-130, Appendix III, Security of Federal Automated Information
Resources



The Federal Information Security Modernization Act of 2014 (FISMA 2014) formally assigns information
security responsibilities to which of the following agencies/departments (select two):

a) Commerce

b) DHS

c) Justice

d) OMB - CORRECT ANSWER✅✅DHS and OMB

,What is the required frequency of FISMA reporting feeds for CFO Act agencies?

a) Monthly

b) Quarterly

c) Semi-annually

d) Annually - CORRECT ANSWER✅✅Monthly



Which law directed the Secretary of Health and Human Services to develop standards for protecting
electronic health information?

a) AARA

b) HITECH

c) HIPAA

d) ePHI - CORRECT ANSWER✅✅HIPAA



Current regulations still require the re-authorization of Federal information systems at least every three
years.

a) True

b) False - CORRECT ANSWER✅✅False



As part of monitoring the security posture of agency desktops, OMB requires Federal agencies to

use vulnerability scanning tools that leverage the protocol.

a) SNMP

b) SMTP

c) SCAP

d) LDAP - CORRECT ANSWER✅✅SCAP



Following the loss of 26 million records containing Pll at the Department of Veteran Affairs, OMB
released M-06-16 Protection of Sensitive Agency Information. This memo required all of the following
except:

a) Encryption of all data on mobile computers/devices

, b) Permits remote access only with two-factor authentication, for which one factor is provided by a
device separate from the computer gaining access

c) Use a "time-out" function for remote access and mobile devices requiring user reauthentication after
30 minutes of inactivity

d) Encryption of all server backup tapes - CORRECT ANSWER✅✅Encryption of all server backup tapes



This Homeland Security Presidential Directive requires all Federal agencies to adopt a standard,

government-wide card to reduce identity fraud, protect personal privacy, and provide for

authentication. This directive is called:

a) Real-ID Act

b) HSPD-12 - Common Identification Standard

c) Critical Infrastructure Protection Act

d) HSPD 24 - Biometrics to Enhance National Security Act - CORRECT ANSWER✅✅HSPD-12 - Common
Identification Standard



FISMA Reporting Metrics are now published annually by what agency/department?

a) OMB

b) Commerce

c) Justice

d) DHS - CORRECT ANSWER✅✅DHS



Agencies are now required to submit required FISMA reports using which of the following automated
systems?

a) CyberStat

b) FISMARpt

c) CyberScope

d) CyberProtect - CORRECT ANSWER✅✅CyberScope



Where can you find the list of recently publish privacy controls required for Federal information systems
containing Pll?

Información del documento

Subido en
27 de octubre de 2025
Número de páginas
53
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas
$13.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
STANGRADES
3.4
(14)
Vendido
96
Seguidores
2
Artículos
12022
Última venta
1 semana hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes