FITSP CORE EXAMS SET 2025/2026 QUESTIONS WITH
ANSWERS RATED A+
✔✔FIPS 197 - ✔✔Advanced Encryption Standard (AES)
• Specifies the Rijndael algorithm
• Block and key size can be changed (variable)
• Cipher key lengths of 128, 192 and 256 bits
• Algorithm may be implemented in software, firmware, hardware or a combination
thereof
✔✔FIPS 198-1 - ✔✔HMAC (Keyed-Hash Message Authentication Code)
✔✔FIPS 199 - ✔✔Security Categorization Based on Impact Levels
✔✔FIPS 200 - ✔✔Minimum Security Requirements for Federal Information and
Information Systems (Baselines)
✔✔FIPS 201-2 - ✔✔Personal Identity Verification PIV (Smart Cards)
✔✔HSPD-1 - ✔✔Organization and Operation of The Homeland Security Council and
Functions
✔✔HSPD-3 - ✔✔Homeland Security Advisory Team
✔✔HSPD-5 - ✔✔Management of Domestic Incidents
✔✔HSPD-7 - ✔✔Critical Infrastructure Identification, Prioritization, and Protection
(replaced with PDD-21)
✔✔HSPD-8 - ✔✔National Preparedness
✔✔HSPD-12 - ✔✔Common Identification Standard for Federal Employees
✔✔HSPD-20/NSPD-51 - ✔✔National Continuity Policy
✔✔HSPD-24 - ✔✔Biometrics for Identification for National Security
✔✔IR 7581 - ✔✔System and Network Security (Acronyms and Abbreviations)
✔✔IR 7564 - ✔✔Directions in Security Metrics Research
✔✔IR 7816-2011 - ✔✔Computer Security Division Annual Report
, ✔✔IR 7359 - ✔✔Information Security Guide for Government Executives
✔✔IR 7536 - ✔✔NIST Computer Security Division (CSD) 2008 Annual Report
✔✔IR 7358 - ✔✔Program Review for Information Security Management Assistance
(PRISMA)
✔✔IR 7316 - ✔✔Assessment of Access Control Systems
✔✔IR 7298 - ✔✔Glossary of Key Information Security Terms
✔✔IR 7206 - ✔✔Smart Cards and Mobile Device Authentication
✔✔CWE - ✔✔Common Weakness Enumeration
✔✔CWSS - ✔✔Common Weakness Scoring System
✔✔CAPEC - ✔✔Common Attack Pattern Enumeration and Classification
✔✔MAEC - ✔✔Malware Attribute Enumeration and Characterization
✔✔IR 7756 - ✔✔CAESARS Framework Extension Reference Model
✔✔SP 800-53 Management Control Families (5) - ✔✔RA - Risk Assessment
SA - System and Services Acquisition
PL - Planning
PM - Project Management
CA - Certification, Accreditation, and Security Assessment and Authorization
✔✔SP 800-53 Technical Control Families (4) - ✔✔AC - Access Control
AU - Audit and Accountability
IA - Identification and Authentication
SC - System and Communications Protection
✔✔SP 800-53 Operational Control Families (9) - ✔✔AT - Awareness and Training
CM - Configuration Management
CP - Contingency Planning
IR - Incident Response
MA - Maintenance
MP - Media Protection
PE - Physical and Environmental Protection
PS - Personnel Security
SI - System and Information Integrity
ANSWERS RATED A+
✔✔FIPS 197 - ✔✔Advanced Encryption Standard (AES)
• Specifies the Rijndael algorithm
• Block and key size can be changed (variable)
• Cipher key lengths of 128, 192 and 256 bits
• Algorithm may be implemented in software, firmware, hardware or a combination
thereof
✔✔FIPS 198-1 - ✔✔HMAC (Keyed-Hash Message Authentication Code)
✔✔FIPS 199 - ✔✔Security Categorization Based on Impact Levels
✔✔FIPS 200 - ✔✔Minimum Security Requirements for Federal Information and
Information Systems (Baselines)
✔✔FIPS 201-2 - ✔✔Personal Identity Verification PIV (Smart Cards)
✔✔HSPD-1 - ✔✔Organization and Operation of The Homeland Security Council and
Functions
✔✔HSPD-3 - ✔✔Homeland Security Advisory Team
✔✔HSPD-5 - ✔✔Management of Domestic Incidents
✔✔HSPD-7 - ✔✔Critical Infrastructure Identification, Prioritization, and Protection
(replaced with PDD-21)
✔✔HSPD-8 - ✔✔National Preparedness
✔✔HSPD-12 - ✔✔Common Identification Standard for Federal Employees
✔✔HSPD-20/NSPD-51 - ✔✔National Continuity Policy
✔✔HSPD-24 - ✔✔Biometrics for Identification for National Security
✔✔IR 7581 - ✔✔System and Network Security (Acronyms and Abbreviations)
✔✔IR 7564 - ✔✔Directions in Security Metrics Research
✔✔IR 7816-2011 - ✔✔Computer Security Division Annual Report
, ✔✔IR 7359 - ✔✔Information Security Guide for Government Executives
✔✔IR 7536 - ✔✔NIST Computer Security Division (CSD) 2008 Annual Report
✔✔IR 7358 - ✔✔Program Review for Information Security Management Assistance
(PRISMA)
✔✔IR 7316 - ✔✔Assessment of Access Control Systems
✔✔IR 7298 - ✔✔Glossary of Key Information Security Terms
✔✔IR 7206 - ✔✔Smart Cards and Mobile Device Authentication
✔✔CWE - ✔✔Common Weakness Enumeration
✔✔CWSS - ✔✔Common Weakness Scoring System
✔✔CAPEC - ✔✔Common Attack Pattern Enumeration and Classification
✔✔MAEC - ✔✔Malware Attribute Enumeration and Characterization
✔✔IR 7756 - ✔✔CAESARS Framework Extension Reference Model
✔✔SP 800-53 Management Control Families (5) - ✔✔RA - Risk Assessment
SA - System and Services Acquisition
PL - Planning
PM - Project Management
CA - Certification, Accreditation, and Security Assessment and Authorization
✔✔SP 800-53 Technical Control Families (4) - ✔✔AC - Access Control
AU - Audit and Accountability
IA - Identification and Authentication
SC - System and Communications Protection
✔✔SP 800-53 Operational Control Families (9) - ✔✔AT - Awareness and Training
CM - Configuration Management
CP - Contingency Planning
IR - Incident Response
MA - Maintenance
MP - Media Protection
PE - Physical and Environmental Protection
PS - Personnel Security
SI - System and Information Integrity