• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 2 out of 14 pages
Exam (elaborations)

FITSP STUDY GUIDE 2025/2026 QUESTIONS WITH ANSWERS RATED A+

Document preview thumbnail
Preview 2 out of 14 pages

FITSP STUDY GUIDE 2025/2026 QUESTIONS WITH ANSWERS RATED A+

Content preview

FITSP STUDY GUIDE 2025/2026 QUESTIONS WITH
ANSWERS RATED A+
✔✔How do you know you can safely purchase a product from a vendor? - ✔✔By
checking the Common Vulnerabilities and Exposures (CVE) and the Cryptographic
Module Validation Program (CMVP) which utilize a common criteria certification process
to provide product validation.

✔✔The National Vulnerability Database (NVD) is - ✔✔The U.S. government repository
of standards based vulnerability management data represented using the Security
Content Automation Protocol (SCAP). This data enables automation of vulnerability
management, security measurement, and compliance. The NVD includes databases of
security checklist references, security-related software flaws, misconfigurations, product
names, and impact metrics.

✔✔M-02-01 - ✔✔Guidance for Preparing and Submitting Security Plans of Action and
Milestones (POAMS)

✔✔M-14-03 Enhancing the Security of Federal Information and Information Systems -
✔✔Established Continuous monitoring (REMOVED 3 year authorization requirement IF
CM is in place)

✔✔M-11-11 - ✔✔Continued Implementation of Homeland Security Presidential Directive
(HSPD) 12- Policy for a Common Identification Standard for Federal Employees and
Contractors

✔✔NIST Risk Management Framework (RMF) - ✔✔Prepare
Categorize
Select
Implement
Assess
Authorize
Monitor

Pretty cool system if anyone asks me

✔✔What are the assessment methods defined by NIST? - ✔✔Test
Interview
Examine

✔✔What are the Five Elements of the NIST Cybersecurity Framework? - ✔✔Identify
Detect
Protect
Respond
Recover

, These core functions aid organizations in their effort to spot, manage and counter
cybersecurity events promptly.

✔✔FIPS 140-2 - ✔✔Cryptographic modules; Superseded by FIPS 140-3
-Establishes the Cryptographic Module Validation Program (CMVP)
-Defines security requirements for Cryptographic Modules:
Level 1: Basic
Level 2: Adds tamper evident coating and role-based authentication
Level 3: Adds identity based authentication, intrusion prevention, and critical access
parameters
Level 4: It requires hardware to be tamper-active. Any tampering of the module to erase
all critical security information

✔✔FIPS-197 - ✔✔AES (Advanced encryption standard)
-The AES algorithm is a symmetric block cipher that can encrypt (encipher) and decrypt
(decipher).

Rijndael algorithm

✔✔What cryptographic keys does the AES algorithm use and what size data blocks can
it encrypt/decrypt? - ✔✔Keys: 128, 192, and 256
Can encrypt/decrypt data blocks of 128 bits

✔✔FIPS-198 - ✔✔Keyed Hash Message Authentication Code (HMAC)
HMACs have two functionally distinct parameters, a message input and a secret key
known only to the message originator and intended receiver(s).

✔✔FIPS-199 - ✔✔Develops standards for categorizing information and information
systems and covers all "official" federal systems.

✔✔SP 800-60 - ✔✔Security Categorization: Guides implementation of FIPS-199

✔✔How does Clinger-Cohen tie into security? - ✔✔1. NIST issues FIPS with which all
agencies must comply
2. Info types are categorized using SP 800-60 (driven by FIPS 199 and 200), which
derive their ratings from their use under the line of business in the Business Reference
Model.
3. This produces the criticality of the system and its info.
4. The above lead to the projection requirements (CIA triad)

✔✔FIPS-200 - ✔✔Establishes minimum security requirements for information systems
(mandates the use of SP800-53 as amended)

✔✔FIPS-201 - ✔✔PIV (common identification and e-auth)

Document information

Uploaded on
May 31, 2025
Number of pages
14
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$12.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
BOARDWALK
3.4
(19)
Sold
157
Followers
7
Items
26503
Last sold
2 weeks ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions