• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 2 fuera de 5 páginas
Examen

FITSP EVALUATION EXAMS 2025/2026 QUESTIONS WITH ANSWERS RATED A+

Document preview thumbnail
Vista previa 2 fuera de 5 páginas

FITSP EVALUATION EXAMS 2025/2026 QUESTIONS WITH ANSWERS RATED A+

Vista previa del contenido

FITSP EVALUATION EXAMS 2025/2026 QUESTIONS WITH
ANSWERS RATED A+
✔✔Clinger-Cohen Act (CCA) _. - ✔✔legislation requires federal agencies to develop,
document and implement agency-wide security programs

✔✔E-Government Act of 2002 - ✔✔legislation requires each agency with an Inspector
General to conduct annual evaluations of information security programs or to appoint an
independent external auditor

✔✔OMB Circular A-130, Appendix III Security of Federal Automated Information
Resources - ✔✔OMB guidance - requires federal agencies to review security controls in
each system when significant modifications are made, or at least every three years

✔✔DHS and OMB - ✔✔FISMA 2014 assign information security to these agencies

✔✔FISM - ✔✔Memorandums done by DHS

✔✔What are the two FISMs put out by DHS? - ✔✔FISM 11-01 TIC reference
architecture 2.0
FISM 12-02 Reporting Instructions for FISMA and Agency Privacy Management

✔✔SP800-82 Rev 2 - ✔✔Continuous Monitoring

✔✔How are the OMB memorandums organized? - ✔✔By Year

✔✔Four Areas of CIO responsibilities: - ✔✔Governance, Commodity IT, Program
Management and Information Security

✔✔SCAP - ✔✔Security Content Automation Protocol. A method with automated
vulnerability management, measurement, and policy compliance evaluation tools

✔✔OMB M-06-16 - ✔✔Protection of Sensitive Agency Information -requires
- encryption of all data on mobile computers/devices
- permits remote access only with two-factor authentication, where one factor is
provided by a device separate from the computer gaining access
-use a time-out function for remote access and mobile devices requiring user re-
authentication after 30 min of inactivity

✔✔risk management approach - ✔✔continually balances the protection of information
and assets with the cost of security controls and mitigation strategies

✔✔What are the six steps of RMF process? - ✔✔categorize, select, implement, assess,
authorize, monitor

, ✔✔what phase of sdlc should the organization consider security requirements? -
✔✔initiation phase/development/acquisition

✔✔security authorization are conducted during which SDLC phase? -
✔✔operations/maintenance

✔✔NIST publication superseded SP800-30 - ✔✔SP800-39

✔✔gap analysis - ✔✔First three steps of the RMF to the legacy system to determine if
the necessary and sufficient security controls have been appropriately selected and
allocated.

✔✔What are the three tiers of the Risk Management Approach - ✔✔Organization
Mission/Business Process
Information System

✔✔Information System Continuous Monitoring updates - ✔✔System Security Plan
(SSP), System Access Report (SAR) and Plan of Action Milestones (POAM)

✔✔Security status reporting - ✔✔time and event driven

✔✔Final step of ISCM - ✔✔review and update the monitoring program

✔✔SCAP specification provide standard naming and dictionary of system configuration
- ✔✔CPE (common platform enumeration)

✔✔What are the resources of national vulnerability database (NVB) - ✔✔CPE, CVE and
OVAL

✔✔What are the categories of controls in NIST Handbook? - ✔✔Management,
Operational, and Technical

✔✔Computer Security Act of 1987 - ✔✔Requires federal agencies
to identify and protect computer systems that contain sensitive information.
conduct computer security training
develop computer security plans.

✔✔Three assessments methods by NIST SP - ✔✔Examine, Interview and Test

✔✔SP800-113 - Guide to SSL VPN - ✔✔Secure Portal VPNs and Secure Tunnel VPNs

✔✔SP800-81 - ✔✔Run name server software with restricted priviledges

Información del documento

Subido en
31 de mayo de 2025
Número de páginas
5
Escrito en
2024/2025
Tipo
Examen
Contiene
Preguntas y respuestas
$12.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
BOARDWALK
3.4
(19)
Vendido
157
Seguidores
7
Artículos
26503
Última venta
2 semanas hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes