FITSP Manager-Part 2 Exam Questions and Answers
FITSP Manager-Part 2 Exam Questions and Answers HIDS/HIPS - Answer ️️ -- Host-Based, - monitors the characteristics of a single host and the events occurring within that host for suspicious activity and most commonly deployed on critical hosts such as publicly accessible servers and servers containing sensitive information - network traffic (only for that host), system logs, running processes, application activity, file access and modification, and system and application configuration changes. NIST SP 800-60, Rev 1 - Answer ️️ -Security Categorization NIST SP 800-122 - Answer ️️ -Categorizing PII FIPS-199 - Answer ️️ -Security Categorization FIPS-200 - Answer ️️ -Minimum Security Requirements NIST SP 800-18, Rev 1 - Answer ️️ -System Security Plan NIST SP 800-30, Rev 1 - Answer ️️ -Risk Assessment Please note that original version has been replaced by 800-39, which is Risk Management Risk Impact - Answer ️️ -Risk associated with the operation and use of information systems that support the missions and business functions of their organizations NIST SP 800-34 - Answer ️️ -Contingency Planning for IT Systems NIST SP 800-37, Rev 2 - Answer ️️ -RMF/Roles and Process FIPS 180-2 - Answer ️️ -- Secure Hash Standard - Federal agencies must use the Secure Hash Standard if we use hashing - Provides Integrity - SHA (Secure Hash Algorithm) there are 4 hash algorithms (SHA-1, SHA-256, SHA-384, SHA- 512) - Secure because a change to a message results in a different message digest. - Other non-standard hash algorithms (MD2, MD5, CRC, HAVAL) FIPS 186-2 - Answer ️️ -- Digital Signature Standard - Provides integrity (message digest) and nonrepudiation (only I have my private key) - Algorithms - Digital Signature Algorithm (DSA) - RSA digital signature algorithm, specified in American National Standard (ANS) X9.31 and Public - Key Cryptography Standard (PKCS) - Elliptic Curve Digital Signature Algorithm (ECDSA), specified in ANS X9.62. FIPS 186-3 approves the use of ECDSA FIPS 197 - Answer ️️ -- specifies AES, Advanced Encryption Standard - uses Rijndael Algorithm - Encrypting is best way to provide confidentiality - Symmetric encryption - faster than asymmetric encryption - Cipher Key lengths -128, 192, 256 - three "flavors" FIPS 198-1 - Answer ️️ -- Keyed Hash Message Authentication Code (HMAC) - Purpose of a MAC is to authenticate both the source of the message and its integrity. - HMACs have 2 parameters: 1) Message input and 2) secret key known only to originator and intended receiver. - HMAC is used by the message sender to produce a value (the MAC) that is formed by hashing the secret key and the message input. FIPS 140-2 - Answer ️️ -- Security Requirements for Cryptographic Modules - Level 1: Basic Security. Atleast one approved algorithm or approved security function shall be used - Level 2: Adds tamper evident coatings, adds role-based authentication Tamper evidence Role based, e.g. AD security groups, user account inherit rights of the group - Level 3: Adds identity based authentication, intrusion prevention, and critical access parameters - Level 4: requires any tampering of the module to erase all critical security information/self- destruction e.g., Bitlocker Environmental protection - FIPS 140-2 establishes with Cryptographic Module Validation Program FIPS 201-2 - Answer ️️ -- PIV - HSPD 12 HSPD 12 - Answer ️️ -- policy for a Common Identification Standard for Federal Employees and Contractor - FIPS 201-1 NIST SP 800-37, Rev 2 - Answer ️️ -RMF/Roles and Process NIST SP 800-39 - Answer ️️ -Managing Risk NIST SP 800-45 r2 - Answer ️️ -Guidelines on email security NIST SP 800-47 - Answer ️️ -Interconnecting IT systems NIST SP 800-53, Rev 4 - Answer ️️ -Baseline Controls NIST SP 800-53A, Rev 4 - Answer ️️ -Testing Controls NIST SP 800-55 - Answer ️️ -Performance Measurement Guide for Information Systems NIST SP 800-60, Rev 1 - Answer ️️ -- Security Categorization - Based on OMB's Business Reference Model - FIPS 199 NIST SP 800-65 - Answer ️️ -Integration of IT Security and Capital Planning NIST SP 800-70 - Answer ️️ -National Checklist Program NIST SP 800-88 - Answer ️️ -Media Sanitization NIST SP 800-122 - Answer ️️ -Guide to protecting the confidentiality of Categorizing PII Defines PII and impact levels Breach response requirements - 1 hour to US CERT per FISMA NIST SP 800-137 - Answer ️️ -Continuous Monitoring Also M-14-03 M 10-28 - Answer ️️ -- Clarifying Cyber responsibilities & activities - OMB as the REPORTING agency vs. - DHS as the GATHERING agency and AUTHORITY for cybersecurity data and events M-02-01 - Answer ️️ -- POA
Información del documento
- Subido en
- 19 de enero de 2024
- Número de páginas
- 47
- Escrito en
- 2023/2024
- Tipo
- Examen
- Contiene
- Preguntas y respuestas