CAP exam study questions with
correct answers
***The Authorizing Official may accept authorization recommendations based on
A. Residual risks of similar system
B. Impact to mission personnel
C. Impact of environmental factors
D. Residual risk of the specific systems** - CORRECT ANSWER-Residual risks of similar system
***The functional description of the control implementation includes
A. The control description, effectiveness, and Plan of Action and Milestones (POA&M)
B. Planned inputs, expected behavior, and expected outputs**
C. A detailed description of the effectiveness of the control
D. The operational parameters of the control - CORRECT ANSWER-The operational parameters of the control
***When making determinations regarding the adequacy of common controls for their respective systems, Information System Owner (ISO) refer
to the Common Control Providers' (CCP)
A. Privacy Impact Assessment (PIA)
B. Business Impact Analysis (BIA)
C. Authorization Packages**
D. Vulnerability Scans - CORRECT ANSWER-Vulnerability Scans
***Which of the following BEST defines the purpose of the security assessment?
A. To determine if the remaining known vulnerability pose an acceptable level of risk
B. To determined the extent to which the security controls are implemented correctly and
operating as intended**
C. To perform oversight and monitor the security controls in the Information System (IS)
D. To perform initial risk estimate and security categorization of the Information System (IS) - CORRECT ANSWER-To determine if the remaining
known vulnerability pose an acceptable level of risk
***Which of the following cannot be delegated by the Authorizing Official (AO)?
A. Certificate resources**
B. Authorization decision
C. Acceptance of Security Plan (SP)
D. Determination of risk to agency operations - CORRECT ANSWER-Authorization Decision
***Which of the following documents is updated when a vulnerability is discovered during continuous monitoring?
A. Plan of Action and Milestones (POA&M)**
B. Business Impact Analysis (BIA)
C. Security Assessment Report (SAR)
D. Incident Response Plan (IRP) - CORRECT ANSWER-Security Assessment Report(SAR)
***Which of the following is the mutual agreement among participating organizations to accept one another's security assessments in order to
reuse system resources or to accept each other's assessed security posture in order to share information?
A. Memorandum of Understanding (MOU)
B. Memorandum of Agreement (MOA)
C. Reciprocity**
D. Reuse - CORRECT ANSWER-Memorandum of Agreement(MOA)
***Which process guides the selection of security controls to ensure adequate security commensurate with the risk of the organization?
A. Risk assessment
B. Security categorization**
C. Vulnerability assessment
D. Privacy Impact Assessment (PIA) - CORRECT ANSWER-Risk assessment
***Which will an Authorizing Official (AO) find implementation details for a control?
A. Plan of Action and Milestones (POA&M)
B. Security and Privacy Plans**
C. Continuous monitoring strategy
D. Risk Assessment Report (RAR) - CORRECT ANSWER-Risk Assessment Report(RAR)
, 114. What is the PRIMARY goal for establishing Information System (IS) boundaries?
A. Identify common security controls
B. Be cost effective
C. Include mitigation for connection to legacy IS
D. Be flexible enough to accommodate major changes without re-authorizing the system - CORRECT ANSWER-Identify common security
controls
A key part of the risk decision process is the recognition that, regardless of the risk response there typically remains a degree of residual risk. On
what basis does an organization determine the acceptable degrees of residual risk?
A. Risk avoidance
B. Risk mitigation
C. Risk tolerance
D. Risk transfer - CORRECT ANSWER-Risk tolerance
A minor application is being added to an existing accredited distributed system.
This application does not require any additional security functionality other than that
provided by the distributed system. Which of the following actions is taken?
A. The owner of the distributed system is responsible for the new application, and adds it to
the existing distributed system Security Plan (SP)
B. The owner of the distributed system needs to create a separate Security Plan (SP) and
reference the distributed system Security Plan (SP)
C. The owner of the new application needs to create an addendum/ application to the
distributed system Security Plan (SP) detailing the necessary additional security
mechanisms for the new application
D. The owner of the new application is responsible for updating the distributed system
Security Plan (SP) with the new application information - CORRECT ANSWER-The owner of the distributed system is responsible for the new
application, and adds it to
the existing distributed system Security Plan (SP)
A Security Control Assessment (SCA) was completed over two years ago, but the surrounding environment has changed. What, if anything,
should the assessment team do with the previous results?
A. Assessment only those controls that have changed
B. Designed since the results are too old
C. Assess all controls for the system
D. Determine changes and impacts - CORRECT ANSWER-Assess all controls for the system
A System Owner (SO) is implementing a new system with their existing organization Information Technology (IT) environment. What objectives
are considered when determining possible impact to risk?
A. Low, Moderate, and High
B. Authentication, Authorization, and Accountability
C. Common, Hybrid, and System-Specific
D. Integrity, Confidentiality, and Availability - CORRECT ANSWER-Integrity ,Confidentiality ,and Availability
All Federal agencies are required by law to conduct which of the following activities?
A. Protect Information Systems (IS) used or operated by a contractor of an agency or other
organization on behalf of an agency
B. Coordinate with the National Institutes of Standards and Technologies (NIST) to develop
binding operational directives
C. Report the effectiveness of information security policies and practices to the Office of
Personnel Management (OPM)
D. Monitor the implementation of information security policies and practices of other
agencies to ensure compliance - CORRECT ANSWER-Protect Information Systems(IS) used or operated by a contractor of an agency or other
organization on behalf of an agency
An effective continuous monitoring strategy includes which of the following?
A. Implementation of the United States Government Configuration Baseline (USGCB)
B. Adherence to the organization's approved enterprise architecture
C. Documenting the functional security baseline configuration
D. Reporting of security and privacy posture to organizational officials - CORRECT ANSWER-Reporting of security and privacy posture to
organizational officials
An Information System (IS) has the following Security Categories (SC) for each information type:
SC public information = (confidentiality, NA), (integrity, HIGH), (availability, LOW) SC investigation information = (confidentiality, MODERATE),
(integrity, HIGH), (availability, MODERATE)SC administrative = (confidentiality, NA), (integrity, LOW), (availability, LOW
What is the overall IS security category for confidentiality
A. LOW
B. MODERATE
C. HIGH
D. N/A - CORRECT ANSWER-MODERATE
An Information System (IS) is registered with appropriate program/management offices in order to
A. Manage and track the system
B. Determine security categorization
C. Set security authorization boundaries
D. Initiate the risk management process - CORRECT ANSWER-Manage and track the system
An organization is developing a risk assessment for a newly installed Information System (IS) to determine the best configuration or a supporting
Information Technology (IT) product. Which of the following specific factors is often overlooked in this analysis?
A. Exposure of interconnections to organizational core mission functions
B. Effectiveness of inherited security controls
C. Cost benefits that can be gained from a broad-based security implementation
D. Implementation of stove-piped activities that enhance security solutions - CORRECT ANSWER-Effectiveness of inherited security controls
An organization should consider which elements when selecting an assessment
team?
A. Expertise and cost
correct answers
***The Authorizing Official may accept authorization recommendations based on
A. Residual risks of similar system
B. Impact to mission personnel
C. Impact of environmental factors
D. Residual risk of the specific systems** - CORRECT ANSWER-Residual risks of similar system
***The functional description of the control implementation includes
A. The control description, effectiveness, and Plan of Action and Milestones (POA&M)
B. Planned inputs, expected behavior, and expected outputs**
C. A detailed description of the effectiveness of the control
D. The operational parameters of the control - CORRECT ANSWER-The operational parameters of the control
***When making determinations regarding the adequacy of common controls for their respective systems, Information System Owner (ISO) refer
to the Common Control Providers' (CCP)
A. Privacy Impact Assessment (PIA)
B. Business Impact Analysis (BIA)
C. Authorization Packages**
D. Vulnerability Scans - CORRECT ANSWER-Vulnerability Scans
***Which of the following BEST defines the purpose of the security assessment?
A. To determine if the remaining known vulnerability pose an acceptable level of risk
B. To determined the extent to which the security controls are implemented correctly and
operating as intended**
C. To perform oversight and monitor the security controls in the Information System (IS)
D. To perform initial risk estimate and security categorization of the Information System (IS) - CORRECT ANSWER-To determine if the remaining
known vulnerability pose an acceptable level of risk
***Which of the following cannot be delegated by the Authorizing Official (AO)?
A. Certificate resources**
B. Authorization decision
C. Acceptance of Security Plan (SP)
D. Determination of risk to agency operations - CORRECT ANSWER-Authorization Decision
***Which of the following documents is updated when a vulnerability is discovered during continuous monitoring?
A. Plan of Action and Milestones (POA&M)**
B. Business Impact Analysis (BIA)
C. Security Assessment Report (SAR)
D. Incident Response Plan (IRP) - CORRECT ANSWER-Security Assessment Report(SAR)
***Which of the following is the mutual agreement among participating organizations to accept one another's security assessments in order to
reuse system resources or to accept each other's assessed security posture in order to share information?
A. Memorandum of Understanding (MOU)
B. Memorandum of Agreement (MOA)
C. Reciprocity**
D. Reuse - CORRECT ANSWER-Memorandum of Agreement(MOA)
***Which process guides the selection of security controls to ensure adequate security commensurate with the risk of the organization?
A. Risk assessment
B. Security categorization**
C. Vulnerability assessment
D. Privacy Impact Assessment (PIA) - CORRECT ANSWER-Risk assessment
***Which will an Authorizing Official (AO) find implementation details for a control?
A. Plan of Action and Milestones (POA&M)
B. Security and Privacy Plans**
C. Continuous monitoring strategy
D. Risk Assessment Report (RAR) - CORRECT ANSWER-Risk Assessment Report(RAR)
, 114. What is the PRIMARY goal for establishing Information System (IS) boundaries?
A. Identify common security controls
B. Be cost effective
C. Include mitigation for connection to legacy IS
D. Be flexible enough to accommodate major changes without re-authorizing the system - CORRECT ANSWER-Identify common security
controls
A key part of the risk decision process is the recognition that, regardless of the risk response there typically remains a degree of residual risk. On
what basis does an organization determine the acceptable degrees of residual risk?
A. Risk avoidance
B. Risk mitigation
C. Risk tolerance
D. Risk transfer - CORRECT ANSWER-Risk tolerance
A minor application is being added to an existing accredited distributed system.
This application does not require any additional security functionality other than that
provided by the distributed system. Which of the following actions is taken?
A. The owner of the distributed system is responsible for the new application, and adds it to
the existing distributed system Security Plan (SP)
B. The owner of the distributed system needs to create a separate Security Plan (SP) and
reference the distributed system Security Plan (SP)
C. The owner of the new application needs to create an addendum/ application to the
distributed system Security Plan (SP) detailing the necessary additional security
mechanisms for the new application
D. The owner of the new application is responsible for updating the distributed system
Security Plan (SP) with the new application information - CORRECT ANSWER-The owner of the distributed system is responsible for the new
application, and adds it to
the existing distributed system Security Plan (SP)
A Security Control Assessment (SCA) was completed over two years ago, but the surrounding environment has changed. What, if anything,
should the assessment team do with the previous results?
A. Assessment only those controls that have changed
B. Designed since the results are too old
C. Assess all controls for the system
D. Determine changes and impacts - CORRECT ANSWER-Assess all controls for the system
A System Owner (SO) is implementing a new system with their existing organization Information Technology (IT) environment. What objectives
are considered when determining possible impact to risk?
A. Low, Moderate, and High
B. Authentication, Authorization, and Accountability
C. Common, Hybrid, and System-Specific
D. Integrity, Confidentiality, and Availability - CORRECT ANSWER-Integrity ,Confidentiality ,and Availability
All Federal agencies are required by law to conduct which of the following activities?
A. Protect Information Systems (IS) used or operated by a contractor of an agency or other
organization on behalf of an agency
B. Coordinate with the National Institutes of Standards and Technologies (NIST) to develop
binding operational directives
C. Report the effectiveness of information security policies and practices to the Office of
Personnel Management (OPM)
D. Monitor the implementation of information security policies and practices of other
agencies to ensure compliance - CORRECT ANSWER-Protect Information Systems(IS) used or operated by a contractor of an agency or other
organization on behalf of an agency
An effective continuous monitoring strategy includes which of the following?
A. Implementation of the United States Government Configuration Baseline (USGCB)
B. Adherence to the organization's approved enterprise architecture
C. Documenting the functional security baseline configuration
D. Reporting of security and privacy posture to organizational officials - CORRECT ANSWER-Reporting of security and privacy posture to
organizational officials
An Information System (IS) has the following Security Categories (SC) for each information type:
SC public information = (confidentiality, NA), (integrity, HIGH), (availability, LOW) SC investigation information = (confidentiality, MODERATE),
(integrity, HIGH), (availability, MODERATE)SC administrative = (confidentiality, NA), (integrity, LOW), (availability, LOW
What is the overall IS security category for confidentiality
A. LOW
B. MODERATE
C. HIGH
D. N/A - CORRECT ANSWER-MODERATE
An Information System (IS) is registered with appropriate program/management offices in order to
A. Manage and track the system
B. Determine security categorization
C. Set security authorization boundaries
D. Initiate the risk management process - CORRECT ANSWER-Manage and track the system
An organization is developing a risk assessment for a newly installed Information System (IS) to determine the best configuration or a supporting
Information Technology (IT) product. Which of the following specific factors is often overlooked in this analysis?
A. Exposure of interconnections to organizational core mission functions
B. Effectiveness of inherited security controls
C. Cost benefits that can be gained from a broad-based security implementation
D. Implementation of stove-piped activities that enhance security solutions - CORRECT ANSWER-Effectiveness of inherited security controls
An organization should consider which elements when selecting an assessment
team?
A. Expertise and cost