• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 2 fuera de 8 páginas
Examen

Actual Capa Practice Exam Questions And 100% Verified Answers 2026/2027

Document preview thumbnail
Vista previa 2 fuera de 8 páginas

CAPA practice exam material covering Corrective and Preventive Action, including CAPA principles, root-cause analysis, corrective and preventive actions, investigation, documentation, implementation, and effectiveness verification. The content is designed to support exam preparation with practice questions and verified answers covering essential CAPA concepts and quality-system requirements.

Vista previa del contenido

ACTUAL CAPA PRACTICE EXAM
QUESTIONS AND 100% VERIFIED
ANSWERS 2026/2027
Which one the following roles is responsible for testing the non‐technical controls in an
information system? - ANSWER-Security Control Assessor

Which reference provides detailed guidance on risk mitigation for the State
Department? - ANSWER-SP 800-53 Security and Privacy Controls for Federal
Information Systems and Organizations

Which of the following roles has the responsibility to ensure that the enterprise
architecture supports the mission and business processes? - ANSWER-a. Information
Security Architect

During which step of the Risk Management Framework (RMF) does the Information
System Owner register the information system? - ANSWER-Categorize Information
System

Who signs the authorization decision letter? - ANSWER-Authorizing Official

Who develops and maintains information security policies, procedures, and control
techniques to address all applicable requirements? - ANSWER-b. Chief Information
Officer

A weakness in an information system, system security procedures, internal controls, or
implementation that could be exploited by a threat source is the definition of which key
term? - ANSWER-Vulnerability

Who procures, develops, integrates, or modifies an information system? - ANSWER-
Information System Owner

Who has the responsibility to prepare the plan of action and milestones based on the
findings and recommendations of the security assessment report? - ANSWER-Common
Control Provider

You have just completed the Risk Assessment defined by NIST SP 800‐30. What
reference identifies the risk management strategy alternatives that can be applied to the
information system? - ANSWER-NIST SP 800-53

In which phase of the NIST SP 800‐30 process does one produce the first full Risk
Assessment Report (RAR)? - ANSWER-Step 2

, Which step of the NIST SP 800‐30 process would most likely identify the CVE database
as a risk assessment information source? - ANSWER-Step 2

Organizations should view assessments as an information gathering activity, not as a
security producing activity. In accordance with NIST SP 800‐53A, security control
assessments create the following benefits: identify potential problems or shortfalls in the
organization's implementation of the NIST Risk Management Framework; support
budgetary decisions and capital investment processes, and: - ANSWER-Support
information system authorization decisions.

The last step in the Risk Assessment process model is called? - ANSWER-Maintain

When using NIST SP 800‐53A, during which SDLC phase are security assessments
used to increase confidence or assurance that the security controls are working
correctly for a system? - ANSWER-Development, Implementation, and Operations and
Maintenance

Which of these is a valid response to address risk? - ANSWER-Accept the risk to the
system

OMB Circular A‐130 states information security must: - ANSWER-Be risk-based, and
cost effective

In accordance with Public Law 107‐347, Executive Agencies must: - ANSWER-
Authorize system processing prior to operation

Adequate Security is: - ANSWER-Commensurate with risk

In the Risk Management Framework as described in NIST SP 800‐37, what is the next
task after "Information System Registration" called? - ANSWER-Common Control
Identification

Which role has PRIMARY responsibility for ongoing remediation actions? - ANSWER-
Information System Owner

Security Control Assessments try to determine if the controls are - ANSWER-Producing
the desired results or outcomes

Which of the following terms are used in NIST SP 800‐60 to describe information that
would have a serious impact on the operation of the organization if confidentiality were
breached? - ANSWER-Moderate because it concerns data sensitivity

What is the minimum frequency periodic testing and evaluation of the effectiveness of
policies should be done? - ANSWER-Annually

Información del documento

Subido en
14 de septiembre de 2026
Número de páginas
8
Escrito en
2026/2027
Tipo
Examen
Contiene
Preguntas y respuestas
$16.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
ExpertEducators
3.7
(11)
Vendido
77
Seguidores
1
Artículos
3108
Última venta
1 día hace




Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes