• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 39 pages
Exam (elaborations)

Certified Authorization Professional (CAP) Questions And Correct Answers (Verified Answers) Plus Rationales 2026 Q&A | Instant Download Pdf

Document preview thumbnail
Preview 4 out of 39 pages

Certified Authorization Professional (CAP) Questions And Correct Answers (Verified Answers) Plus Rationales 2026 Q&A | Instant Download Pdf

Content preview

Certified Authorization Professional (CAP)
Questions And Correct Answers (Verified
Answers) Plus Rationales 2026 Q&A | Instant
Download Pdf


1. Which framework does the CAP primarily use for risk
management and information system authorization?
A. ISO 27001
B. COBIT
C. NIST RMF
D. ITIL
The NIST Risk Management Framework (RMF) provides
structured processes for categorizing, assessing, and authorizing
information systems, forming the foundation for CAP practices.

2. What is the primary objective of an Authorization to Operate
(ATO)?
A. To implement security controls
B. To formally accept the risk associated with operating a system
C. To develop security policies

, D. To classify data
An ATO is issued by a senior official to formally accept residual
risks after controls are implemented, authorizing system
operation.

3. During which step of the RMF is the system categorized?
A. Implement security controls
B. Assess security controls
C. Categorize the information system
D. Monitor security controls
Categorization occurs first in the RMF to identify the system’s
impact level and tailor security controls accordingly.

4. Which role is primarily responsible for ensuring compliance with
security policies and procedures?
A. Authorizing Official
B. Information System Security Officer (ISSO)
C. System Owner
D. Security Control Assessor
The ISSO manages the system’s compliance, oversees control
implementation, and ensures policies are followed.

5. What is the main purpose of continuous monitoring?
A. To create the system security plan

, B. To implement controls
C. To authorize a system
D. To track security control effectiveness over time
Continuous monitoring identifies changes or vulnerabilities that
may affect risk posture, ensuring controls remain effective.

6. Which document provides a detailed description of security
controls for a system?
A. Risk Assessment Report
B. Security Assessment Plan
C. System Security Plan (SSP)
D. Contingency Plan
The SSP outlines system boundaries, control selection, and
implementation details, forming a central document in RMF.

7. Which type of risk is considered residual risk?
A. Risk before controls are applied
B. Risk remaining after controls are implemented
C. Inherent risk
D. Threat risk
Residual risk represents the risk that remains despite the
implementation of security controls.

, 8. Who has the authority to accept residual risk for an information
system?
A. System Administrator
B. Authorizing Official (AO)
C. Security Control Assessor
D. Chief Information Security Officer (CISO)
The AO is responsible for formally accepting residual risk and
granting system authorization.

9. Which of the following best defines control inheritance?
A. Using inherited data for risk assessments
B. Leveraging security controls from another system or
environment
C. Copying user accounts from another system
D. Using inherited threat intelligence
Control inheritance reduces redundancy by reusing existing,
implemented controls from shared infrastructure or other
systems.

10. The CAP exam emphasizes knowledge in which of the
following domains?
A. Cryptography algorithms
B. Risk management, authorization, and security control

Document information

Uploaded on
March 23, 2026
Number of pages
39
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$23.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
LectRizz
3.6
(34)
Sold
129
Followers
2
Items
4327
Last sold
2 weeks ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions