QUESTIONS AND 100% VERIFIED
ANSWERS 2026/2027
Which one the following roles is responsible for testing the non‐technical controls in an
information system? - ANSWER-Security Control Assessor
Which reference provides detailed guidance on risk mitigation for the State
Department? - ANSWER-SP 800-53 Security and Privacy Controls for Federal
Information Systems and Organizations
Which of the following roles has the responsibility to ensure that the enterprise
architecture supports the mission and business processes? - ANSWER-a. Information
Security Architect
During which step of the Risk Management Framework (RMF) does the Information
System Owner register the information system? - ANSWER-Categorize Information
System
Who signs the authorization decision letter? - ANSWER-Authorizing Official
Who develops and maintains information security policies, procedures, and control
techniques to address all applicable requirements? - ANSWER-b. Chief Information
Officer
A weakness in an information system, system security procedures, internal controls, or
implementation that could be exploited by a threat source is the definition of which key
term? - ANSWER-Vulnerability
Who procures, develops, integrates, or modifies an information system? - ANSWER-
Information System Owner
Who has the responsibility to prepare the plan of action and milestones based on the
findings and recommendations of the security assessment report? - ANSWER-Common
Control Provider
You have just completed the Risk Assessment defined by NIST SP 800‐30. What
reference identifies the risk management strategy alternatives that can be applied to the
information system? - ANSWER-NIST SP 800-53
In which phase of the NIST SP 800‐30 process does one produce the first full Risk
Assessment Report (RAR)? - ANSWER-Step 2
, Which step of the NIST SP 800‐30 process would most likely identify the CVE database
as a risk assessment information source? - ANSWER-Step 2
Organizations should view assessments as an information gathering activity, not as a
security producing activity. In accordance with NIST SP 800‐53A, security control
assessments create the following benefits: identify potential problems or shortfalls in the
organization's implementation of the NIST Risk Management Framework; support
budgetary decisions and capital investment processes, and: - ANSWER-Support
information system authorization decisions.
The last step in the Risk Assessment process model is called? - ANSWER-Maintain
When using NIST SP 800‐53A, during which SDLC phase are security assessments
used to increase confidence or assurance that the security controls are working
correctly for a system? - ANSWER-Development, Implementation, and Operations and
Maintenance
Which of these is a valid response to address risk? - ANSWER-Accept the risk to the
system
OMB Circular A‐130 states information security must: - ANSWER-Be risk-based, and
cost effective
In accordance with Public Law 107‐347, Executive Agencies must: - ANSWER-
Authorize system processing prior to operation
Adequate Security is: - ANSWER-Commensurate with risk
In the Risk Management Framework as described in NIST SP 800‐37, what is the next
task after "Information System Registration" called? - ANSWER-Common Control
Identification
Which role has PRIMARY responsibility for ongoing remediation actions? - ANSWER-
Information System Owner
Security Control Assessments try to determine if the controls are - ANSWER-Producing
the desired results or outcomes
Which of the following terms are used in NIST SP 800‐60 to describe information that
would have a serious impact on the operation of the organization if confidentiality were
breached? - ANSWER-Moderate because it concerns data sensitivity
What is the minimum frequency periodic testing and evaluation of the effectiveness of
policies should be done? - ANSWER-Annually