• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 2 out of 8 pages
Exam (elaborations)

Actual Capa Practice Exam Questions And 100% Verified Answers 2026/2027

Document preview thumbnail
Preview 2 out of 8 pages

CAPA practice exam material covering Corrective and Preventive Action, including CAPA principles, root-cause analysis, corrective and preventive actions, investigation, documentation, implementation, and effectiveness verification. The content is designed to support exam preparation with practice questions and verified answers covering essential CAPA concepts and quality-system requirements.

Content preview

ACTUAL CAPA PRACTICE EXAM
QUESTIONS AND 100% VERIFIED
ANSWERS 2026/2027
Which one the following roles is responsible for testing the non‐technical controls in an
information system? - ANSWER-Security Control Assessor

Which reference provides detailed guidance on risk mitigation for the State
Department? - ANSWER-SP 800-53 Security and Privacy Controls for Federal
Information Systems and Organizations

Which of the following roles has the responsibility to ensure that the enterprise
architecture supports the mission and business processes? - ANSWER-a. Information
Security Architect

During which step of the Risk Management Framework (RMF) does the Information
System Owner register the information system? - ANSWER-Categorize Information
System

Who signs the authorization decision letter? - ANSWER-Authorizing Official

Who develops and maintains information security policies, procedures, and control
techniques to address all applicable requirements? - ANSWER-b. Chief Information
Officer

A weakness in an information system, system security procedures, internal controls, or
implementation that could be exploited by a threat source is the definition of which key
term? - ANSWER-Vulnerability

Who procures, develops, integrates, or modifies an information system? - ANSWER-
Information System Owner

Who has the responsibility to prepare the plan of action and milestones based on the
findings and recommendations of the security assessment report? - ANSWER-Common
Control Provider

You have just completed the Risk Assessment defined by NIST SP 800‐30. What
reference identifies the risk management strategy alternatives that can be applied to the
information system? - ANSWER-NIST SP 800-53

In which phase of the NIST SP 800‐30 process does one produce the first full Risk
Assessment Report (RAR)? - ANSWER-Step 2

, Which step of the NIST SP 800‐30 process would most likely identify the CVE database
as a risk assessment information source? - ANSWER-Step 2

Organizations should view assessments as an information gathering activity, not as a
security producing activity. In accordance with NIST SP 800‐53A, security control
assessments create the following benefits: identify potential problems or shortfalls in the
organization's implementation of the NIST Risk Management Framework; support
budgetary decisions and capital investment processes, and: - ANSWER-Support
information system authorization decisions.

The last step in the Risk Assessment process model is called? - ANSWER-Maintain

When using NIST SP 800‐53A, during which SDLC phase are security assessments
used to increase confidence or assurance that the security controls are working
correctly for a system? - ANSWER-Development, Implementation, and Operations and
Maintenance

Which of these is a valid response to address risk? - ANSWER-Accept the risk to the
system

OMB Circular A‐130 states information security must: - ANSWER-Be risk-based, and
cost effective

In accordance with Public Law 107‐347, Executive Agencies must: - ANSWER-
Authorize system processing prior to operation

Adequate Security is: - ANSWER-Commensurate with risk

In the Risk Management Framework as described in NIST SP 800‐37, what is the next
task after "Information System Registration" called? - ANSWER-Common Control
Identification

Which role has PRIMARY responsibility for ongoing remediation actions? - ANSWER-
Information System Owner

Security Control Assessments try to determine if the controls are - ANSWER-Producing
the desired results or outcomes

Which of the following terms are used in NIST SP 800‐60 to describe information that
would have a serious impact on the operation of the organization if confidentiality were
breached? - ANSWER-Moderate because it concerns data sensitivity

What is the minimum frequency periodic testing and evaluation of the effectiveness of
policies should be done? - ANSWER-Annually

Document information

Uploaded on
September 14, 2026
Number of pages
8
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$16.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
ExpertEducators
3.7
(11)
Sold
77
Followers
1
Items
3108
Last sold
1 day ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions