FITSP-A Module 5 Exam Questions and Answers
FITSP-A Module 5 Exam Questions and Answers 1. An assessment object for each security control, which identifies the specific control items being assessed and testing techniques, can be found in which document? a) NIST Special Publication 800-37 Revision 1, Guide for Applying the Risk Management Framework to Federal Information Systems b) NIST Special Publication 800-53 Revision 4, Recommended Security Controls for Federal Information Systems and Organizations c) NIST Special Publication 800-53A Revision 4, Guide for Assessing the Security Controls in Federal Information Systems and Organizations d) All of the above - Answer ️️ -Correct answer: c) NIST Special Publication 800-53A Revision 4 NIST SP 800-53Ar4 states: "An assessment procedure consists of a set of assessment objectives, each with an associated set of potential assessment methods and assessment objects/' It then provides the assessment procedures with the objects for each control in SP 800-53r4. Incorrect answers: a) is the RMF Guide; c) provides the controls, but not assessment objects; d) is incorrect - only c) contains the assessment objects. 2. Examples of control activities that are specific protection-related pursuits or actions that involve people are all of the following except? a) Exercising a contingency plan b) Locking user accounts after failed logins c) Reviewing audit logs d) Moving backups to an offsite location - Answer ️️ -Correct answer: b) Locking user accounts after failed logins NIST SP 800-53Ar4, p. F-31 includes this activity in control AC-7. It is performed automatically by the system without human intervention. Incorrect answers: All other choices require people to perform at least part of the activity. Which of the following is not one of the phases of the SDLC? (System Development Life Cycle) a) Implementation b) Innovation c) Disposition (Disposal) d) Development/Acquisition - Answer ️️ -Correct answer: b) Innovation NIST SP 800-64r2, paragraph 2.1.1 states: "A typical SDLC includes five phases: initiation, development/acquisition, implementation/assessment, operations/maintenance, and disposal. Incorrect answers: a), c), and d) are all phases of SDLC per the citation above. 4. Which of the following is a valid assessment method? a) Test b) Examine c) Interview d) All of the above - Answer ️️ -Correct answer: d) All of the above NIST SP 800-53Ar4, Paragraph 2.4 states: "Assessment methods define the nature of the assessor actions and include examine, interview, and test." Incorrect answers: All three are valid methods; any single choice is incorrect. 5. Which of the following statements about system security assessments is false? a) System assessments are typically conducted by information systems developers, systems integrators, information system owners, common control providers, assessors, auditors, Inspectors General, and the infor
Document information
- Uploaded on
- January 19, 2024
- Number of pages
- 10
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers