• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 47 pages
Exam (elaborations)

Ato Level Ii Complete Questions And Answers Graded A+

Document preview thumbnail
Preview 4 out of 47 pages

ATO LEVEL II COMPLETE QUESTIONS AND ANSWERS GRADED A+

Content preview

ATO LEVEL II COMPLETE QUESTIONS
AND ANSWERS GRADED A+


◉ Which of the following are security-focused configuration
management (SecCM) roles in risk management?
Answer: A.) Ensuring that adjustments to the system
configuration do not adversely affect the security of the
information system B.) Establishing configuration baselines and
tracking, controlling, and managing aspects of business
development C.) Ensuring that adjustments to the system
configuration do not adversely affect the organizations operations


◉ This security Configuration Management (CM) control includes
physical and logical access controls and prevents the installation
of software and firmware unless verified with an approved
certificate.
Answer: Access Restrictions for Change


◉ This security Configuration Management (CM) control ensures
that software use complies with contract agreements and
copyright laws, tracks usage, and is not used for unauthorized
distribution, display, performance, or reproduction.
Answer: Software Usage Restrictions

,◉ This security Configuration Management (CM) control involves
the systematic proposal, justification, implementation, testing,
review, and disposition of changes to the systems, including
system upgrades and modifications.
Answer: Configuration Change Control


◉ This security Configuration Management (CM) control applies
to the parameters that can be changed in hardware, software, or
firmware components that affect the security posture and/or
funtionality of the system, including registry settings,
account/directory permission setting, and settings for functions,
ports and protocols.
Answer: Configuration Settings


◉ Which of the following describes the role of the National
Industrial Security Program (NISP) in continuous monitoring?
Answer: The NISP ensures that monitoring requirements,
restrictions, and safeguards that industry must follow are in place
before any classified work may begin.


◉ Which of the following describes the relationship between
configuration management controls and continuous monitoring?
Answer: Implementing information system changes almost always
results in some adjustment to the system configuration that
requires continuous monitoring of security controls.

,◉ Which of the following is a role of risk management in
continuous monitoring?
Answer: Risk management in continuous monitoring ensures that
information security solutions are broad-based, consensus-
driven, and address the ongoing needs of and risks to the
government and industry.


◉ Select ALL the correct responses. Which of the following
describe continuous monitoring capabilities for detecting threats
and mitigating vulnerabilities?
Answer: A.) Conducting frequent audits B.) Not relying on
firewalls to protect against all attacks


◉ Which of the following describes how the Information System
Continuous Monitoring (ISCM) strategy supports the Tier 2
MISSION/BUSINESS PROCESSES approach to risk management?
Answer: Tier 2 ISCM strategies focus on the controls that address
the establishment and management of the organization's
information security program, including establishing the
minimum frequency with which each security control or metric is
to be assessed or monitored.


◉ Which of the following is an example of how
counterintelligence and cybersecurity personnel support
continuous monitoring?
Answer: Through aggregation and analysis of Suspicious Network
Activity via cyber intrusion, viruses, malware, backdoor attacks,
acquisition of user names and passwords, and similar targeting,

, the DSS CI Directorate produces and disseminates reports on
trends in cyberattacks and espionage.


◉ Which of the following describes how audit logs support
continuous monitoring?
Answer: Security auditing is a fundamental activity in continuous
monitoring in order to determine what activities occurred and
which user or process was responsible for them on an
information system.


◉ Which of the following identifies how the Risk Management
Framework (RMF) supports risk management?
Answer: The RMF process emphasizes continuous monitoring and
timely correction of deficiencies.


◉ Select ALL the correct responses. Which of the following are
key information provided in a security audit trail analysis?
Answer: A.) Unsuccessful accesses to security-relevant objects
and directories B.) Successful and unsuccessful logons/logoffs C.)
Denial of access for excessive logon attempts


◉ Which of the following fundamental concepts does continuous
monitoring support that means DoD information technology is
managed to minimize shared risk by ensuring the security
posture of one system is not undermined by vulnerabilities of
interconnected systems?
Answer: Interoperability and operational reciprocity

Document information

Uploaded on
September 28, 2026
Number of pages
47
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$17.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
TopGradeInsider
4.2
(13)
Sold
187
Followers
2
Items
60879
Last sold
5 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions