FITSP COMPREHENSIVE EXAMS 2025/2026 QUESTIONS
WITH ANSWERS RATED A+
✔✔What are the three levels of potential impact from a security breach? - ✔✔Low,
Moderate, High
✔✔Privacy security requirements are adequately addressed by the standard catalog of
security controls? - ✔✔TRUE
✔✔Which Are the types of security controls - ✔✔System Specific, Hybrid, Common
✔✔When would you use a gap analysis in the RMF process? - ✔✔When applying
security to a legacy system
✔✔Who has the primary responsibility for implementing the security controls specified
in the system security plan? - ✔✔Information System Owner
✔✔what is the first Step to assigning Impact levels for security categorization -
✔✔Identify Information Type
✔✔What are security controls that are inheritable by one or more organizational
information systems - ✔✔Common Controls
✔✔What kind of security control is a management, operational, or technical control
employed by an organization in lieu of a recommended security control? -
✔✔Compensating Control
✔✔What is the most significant change, regarding security control selection, in the
revision of the SP 800-37? - ✔✔RMF Step 2 Monitoring Strategy
✔✔What is the basis for the identification of information types? - ✔✔Business
Reference Model
✔✔what are the factors that drive the level of effort for the selection and implementation
of security controls? - ✔✔System Importance & Criticality
✔✔Which of the following were purposes in introducing overlays in SP 800-53.4? -
✔✔Allow pre-tailoring of security baselines for specific situations and Reduce the
requirement for ad hoc tailoring
✔✔which NIST document lists information types, and their associated provisional
impact level? - ✔✔SP 800-60
,✔✔Which NIST Special Publication provides guidance for protecting Pll - ✔✔SP 800-
122
✔✔Name the 3 tasks of the RMF Categorization step -
✔✔Categorize/Describe/Register
✔✔An assessment object for each security control, which identifies the specific control
items being assessed and testing techniques, can be found in which document -
✔✔NIST Special Publication 800-53A Revision 4
✔✔Examples of control activities that are specific protection-related pursuits or actions
that involve people are all of the following except? - ✔✔Locking user accounts after
failed logins
✔✔Which of the following is not one of the phases of the SDLC? - ✔✔Innovation
✔✔What are the valid assessment methods? - ✔✔Test, Examine and Interview
✔✔What does NIST SP 800 53r4 say about the authority of the security Assessor? -
✔✔Paragraph 2.3 contains the following statements: "Assessors obtain the required
evidence during the assessment process to allow the appropriate organizational officials
to make objective determinations.However, assessors do not authorize risk acceptance
as that as part of the authorization decision.
✔✔What project was instituted to improve automated assessment of security controls? -
✔✔SCAP
✔✔List the four tasks of the assessment step of the RMF in the proper order. -
✔✔Prepare, Assess Controls, Report, Remediate
✔✔System testing to determine if a change caused a bug in unchanged portions of the
SVStem is called - ✔✔Regression Testing
✔✔What does NIST SP 800 53r4 say about which method should be used to assess
the proper operation of a single security control? - ✔✔Paragraph 3.2.3 states: "It is
recognized that organizations can specify, document, and configure their information
systems in a variety of ways, and that the content and applicability of existing
assessment evidence will vary. This may result in the need to apply variety of
assessment methods to various assessment objects to generate the assessment
evidence needed to determine whether the security or privacy controls are effective in
their application/'
, ✔✔Which of the following practices can reduce the effort required to assess controls? -
✔✔Maximize the use of common controls in the system
✔✔Which NIST special publication is written to facilitate security control assessments
conducted within an effective risk management framework - ✔✔SP800-53a
✔✔List the security testing techniques - ✔✔Examine, Test, Interview
✔✔What is defined as body of evidence organized into an argument demonstrating that
some claim about an information system is assured - ✔✔Assurance Case
✔✔Which statements are linked to the content of the security control (i.e., the security
control functionality) to ensure traceability of assessment results back to the
fundamental control requirements - ✔✔Determination Statement
✔✔Which assessment method is the process of reviewing, inspecting, observing,
studying, or analyzing one or more assessment objects (i.e., specifications,
mechanisms, or activities)? - ✔✔Examine
✔✔What are the two most important factors in choosing a security control assessor? -
✔✔Independence and Expertise
✔✔Which phase of the System Development Life Cycle is least likely to require
assessment of controls - ✔✔Initiation
✔✔The rigor and scope of the assessment are determined by the level
______________ level desired - ✔✔Assurance
✔✔Which of the following have primary responsibility in the remediation task in the
assessment process? - ✔✔Security Control Assessor and Information System Owner
✔✔Open Checklist Interactive Language (OCIL) is used to: - ✔✔Express determination
statements in the assessment procedures
✔✔What are the different types of Authorization approaches - ✔✔Single, Joint and
Leveraged
✔✔What are the mandatory elements of the authorization decision document -
✔✔Authorization Decision/Terms & Conditions/Termination Date
✔✔Which document will provide the results of assessing the implementation of the
security controls identified in the security plan to determine the extent to which the
WITH ANSWERS RATED A+
✔✔What are the three levels of potential impact from a security breach? - ✔✔Low,
Moderate, High
✔✔Privacy security requirements are adequately addressed by the standard catalog of
security controls? - ✔✔TRUE
✔✔Which Are the types of security controls - ✔✔System Specific, Hybrid, Common
✔✔When would you use a gap analysis in the RMF process? - ✔✔When applying
security to a legacy system
✔✔Who has the primary responsibility for implementing the security controls specified
in the system security plan? - ✔✔Information System Owner
✔✔what is the first Step to assigning Impact levels for security categorization -
✔✔Identify Information Type
✔✔What are security controls that are inheritable by one or more organizational
information systems - ✔✔Common Controls
✔✔What kind of security control is a management, operational, or technical control
employed by an organization in lieu of a recommended security control? -
✔✔Compensating Control
✔✔What is the most significant change, regarding security control selection, in the
revision of the SP 800-37? - ✔✔RMF Step 2 Monitoring Strategy
✔✔What is the basis for the identification of information types? - ✔✔Business
Reference Model
✔✔what are the factors that drive the level of effort for the selection and implementation
of security controls? - ✔✔System Importance & Criticality
✔✔Which of the following were purposes in introducing overlays in SP 800-53.4? -
✔✔Allow pre-tailoring of security baselines for specific situations and Reduce the
requirement for ad hoc tailoring
✔✔which NIST document lists information types, and their associated provisional
impact level? - ✔✔SP 800-60
,✔✔Which NIST Special Publication provides guidance for protecting Pll - ✔✔SP 800-
122
✔✔Name the 3 tasks of the RMF Categorization step -
✔✔Categorize/Describe/Register
✔✔An assessment object for each security control, which identifies the specific control
items being assessed and testing techniques, can be found in which document -
✔✔NIST Special Publication 800-53A Revision 4
✔✔Examples of control activities that are specific protection-related pursuits or actions
that involve people are all of the following except? - ✔✔Locking user accounts after
failed logins
✔✔Which of the following is not one of the phases of the SDLC? - ✔✔Innovation
✔✔What are the valid assessment methods? - ✔✔Test, Examine and Interview
✔✔What does NIST SP 800 53r4 say about the authority of the security Assessor? -
✔✔Paragraph 2.3 contains the following statements: "Assessors obtain the required
evidence during the assessment process to allow the appropriate organizational officials
to make objective determinations.However, assessors do not authorize risk acceptance
as that as part of the authorization decision.
✔✔What project was instituted to improve automated assessment of security controls? -
✔✔SCAP
✔✔List the four tasks of the assessment step of the RMF in the proper order. -
✔✔Prepare, Assess Controls, Report, Remediate
✔✔System testing to determine if a change caused a bug in unchanged portions of the
SVStem is called - ✔✔Regression Testing
✔✔What does NIST SP 800 53r4 say about which method should be used to assess
the proper operation of a single security control? - ✔✔Paragraph 3.2.3 states: "It is
recognized that organizations can specify, document, and configure their information
systems in a variety of ways, and that the content and applicability of existing
assessment evidence will vary. This may result in the need to apply variety of
assessment methods to various assessment objects to generate the assessment
evidence needed to determine whether the security or privacy controls are effective in
their application/'
, ✔✔Which of the following practices can reduce the effort required to assess controls? -
✔✔Maximize the use of common controls in the system
✔✔Which NIST special publication is written to facilitate security control assessments
conducted within an effective risk management framework - ✔✔SP800-53a
✔✔List the security testing techniques - ✔✔Examine, Test, Interview
✔✔What is defined as body of evidence organized into an argument demonstrating that
some claim about an information system is assured - ✔✔Assurance Case
✔✔Which statements are linked to the content of the security control (i.e., the security
control functionality) to ensure traceability of assessment results back to the
fundamental control requirements - ✔✔Determination Statement
✔✔Which assessment method is the process of reviewing, inspecting, observing,
studying, or analyzing one or more assessment objects (i.e., specifications,
mechanisms, or activities)? - ✔✔Examine
✔✔What are the two most important factors in choosing a security control assessor? -
✔✔Independence and Expertise
✔✔Which phase of the System Development Life Cycle is least likely to require
assessment of controls - ✔✔Initiation
✔✔The rigor and scope of the assessment are determined by the level
______________ level desired - ✔✔Assurance
✔✔Which of the following have primary responsibility in the remediation task in the
assessment process? - ✔✔Security Control Assessor and Information System Owner
✔✔Open Checklist Interactive Language (OCIL) is used to: - ✔✔Express determination
statements in the assessment procedures
✔✔What are the different types of Authorization approaches - ✔✔Single, Joint and
Leveraged
✔✔What are the mandatory elements of the authorization decision document -
✔✔Authorization Decision/Terms & Conditions/Termination Date
✔✔Which document will provide the results of assessing the implementation of the
security controls identified in the security plan to determine the extent to which the