P R O F E S S I O N A L P R A C T I C E M AT E R I A L S
FITSP Auditor Exam
Questions & Answers |
Comprehensive
Certification Review
Verified Answers Exam Ready With Rationales
99 QUESTIONS
DOCUMENT OVERVIEW
This document contains 99 verified questions with correct answers related to federal
information security legislation and risk management. It serves as a comprehensive
resource for understanding essential concepts in information security and risk
management. Students can utilize it for effective study, review, and preparation for
certification exams in the field.
CONTENTS
Legislation and Policies Q1–Q18
FISMA and Reporting Q19–Q36
Privacy and Information Security Q37–Q52
Security Controls and Assessments Q53–Q68
System Development Life Cycle Q69–Q83
Page 1
, Risk Management Framework Q84–Q99
E XA M Q U EST I O N S
Q1 QUESTION 1 OF 99
The following legislation requires federal agencies to establish capital planning and
investment control policies and procedures when procuring information technology:
a) E-Government Act of 2002
b) Federal Information Security Management Act (FISMA)
c) Government Information Security Reform Act (GISRA)
d) Clinger-Cohen Act
CORRECT ANSWER
Clinger-Cohen Act
Q2 QUESTION 2 OF 99
The following legislation requires federal agencies to appoint a Chief Information Officer:
a) E-Government Act of 2002
b) Federal Information Security Management Act (FISMA)
c) Government Information Security Reform Act (GISRA)
d) Clinger-Cohen Act
CORRECT ANSWER
Clinger-Cohen Act
Q3 QUESTION 3 OF 99
The following legislation requires federal agencies to develop, document, and implement an
agency-wide information security program:
a) E-Government Act of 2002, Section 208
b) Federal Information Security Management Act (FISMA)
c) Government Information Security Reform Act (GISRA)
d) Clinger-Cohen Act
Page 2
, CORRECT ANSWER
Federal Information Security Management Act (FISMA)
Q4 QUESTION 4 OF 99
The following legislation requires federal agencies to prepare Privacy Impact Assessments
(PIAs) when developing or procuring new information technology:
a) E-Government Act of 2002, Section 208
b) Federal Information Security Management Act (FISMA)
c) Privacy Act, 1974
d) Clinger-Cohen Act
CORRECT ANSWER
E-Government Act of 2002, Section 208
Q5 QUESTION 5 OF 99
The following legislation requires each agency with an Inspector General to conduct an
annual evaluation of agency's information security program, or to appoint an
independent external auditor, to conduct the evaluation on their behalf:
a) E-Government Act of 2002, Title I
b) Federal Information Security Management Act (FISMA)
c) Government Information Security Reform Act (GISRA)
d) Clinger-Cohen Act
CORRECT ANSWER
Federal Information Security Management Act (FISMA)
Q6 QUESTION 6 OF 99
The Federal Information Security Modernization Act of 2014 (FISMA 2014) formally assigns
information security responsibilities to which of the following agencies/departments
(select two):
a) Commerce
b) DHS
c) Justice
d) OMB
Page 3
, CORRECT ANSWER
DHS and OMB
Q7 QUESTION 7 OF 99
Current regulations still require the re-authorization of Federal information systems at least
every three years.
a) True
b) False
CORRECT ANSWER
False
Q8 QUESTION 8 OF 99
Following the loss of 26 million records containing Pll at the Department of Veteran Affairs,
OMB released M-06-16 Protection of Sensitive Agency Information. This memo required all
of the following except:
a) Encryption of all data on mobile computers/devices
b) Permits remote access only with two-factor authentication, for which one factor is
provided by a device separate from the computer gaining access
c) Use a "time-out" function for remote access and mobile devices requiring user
reauthentication after 30 minutes of inactivity
d) Encryption of all server backup tapes
CORRECT ANSWER
Encryption of all server backup tapes
Page 4