FITSP MANAGER 2025/2026 QUESTIONS WITH ANSWERS
RATED A+
✔✔What are the Investment Life Cycles phases? - ✔✔Select, Control, Evaluate
✔✔What are the 7 steps in SP 800-65 Intergrating information security into the CPIC
process? - ✔✔Identify the baseline
Identify prioritization requirements
Conduct enterprise-level prioritization
Conduct system-level prioritization
Develop supporting materials
Implement Investment Review Board and Portfolio management
Submit Exhibit 300s, Exhibit 53, and Conduct Program Management.
✔✔NIST 800-55 - ✔✔Security Metric Guide for information technology systems
provides guidance on how an org by using metrics, identifies the adequacy of in-place
security controls, policies and procedures
✔✔What is Federal Enterprise Architecture? - ✔✔This consist of a set of interrelated
"reference models" designed to facilitate cross agency analysis and the identification of
duplicative investments, gaps, and opportunities for collaboration within and across
agencies.
✔✔What are the 5 Federal Enterprise Architecture models? - ✔✔Performance
Reference
Business Reference
Service Component Reference
Technical Reference
Data Reference
✔✔What are the core principle of the FEA? - ✔✔Business-driven
Proactive and collaborative throughout the Federal goverment
Architecture improves the effectiveness and efficiency of goverment information
✔✔What support RA-3 Risk Assessment - ✔✔800-37
✔✔RA-3 security control must be partially implemented prior to the implementation of
other controls in order to completed the first two steps in the Risk Management
Framework? True or False - ✔✔True
✔✔What meet the requirement of the Cyber Security Research and Development Act of
2002 (Public law 107-305) CSRDA? - ✔✔To faciliated development the security
chechlist, NIST developed the National Checklist Program for IT products.
,✔✔800-39 has replaced 800-30 as the authoritative source of comprehensive risk
management guidance. True or False - ✔✔True
✔✔What are the Risk Assessment Steps? (Risk framing) - ✔✔Prepare for assessment
Conduct the assessment
Report and Communicate the assessment
Maintain the assessment
✔✔What happens in RA Step 1 - Task 1 - ✔✔Prepare for assessment
Task: Identify purpose of assessment -
Information that the assessment is intended to produce
Decision the assessment is intended to support
✔✔What happens in RA Step 1 - Task 2 - ✔✔Prepare for assessment
Task: Identify Scope - determines what will be considered in the assessment
Org applicability
Time frame supported
Architectural/technology considerations
✔✔What happens in RA Step 1 - Task 3 - ✔✔Prepare for assessment
Task: Indentiy Assumptions and considerations
-Assumption
-constraints
-risk tolerances
-priorities/trade-offs
✔✔What are some assumptions and constraints regarding risk assessment? -
✔✔Threat source
Threat event
Vulnerabilities and predisposing conditions
Potential impacts
Assessment and analysis approaches
Which missions/business functions are primary
✔✔What happens in RA Step 1 - Task 4 - ✔✔Prepare for assessment
Task: Indentify information sources
-descriptions
-threat
-vulnerability
-impact
✔✔What are example of Information Sources? - ✔✔Internal
-logs
-reports
-trouble tickets
, External
-cross-community org (ie CERT, ISAC, etc.)
-research orgs
✔✔What are some information input activities for risk assessment? - ✔✔document
reviews
questionaires and surveys
on-site interviews
automated tools
✔✔What happens in RA Step 1 - Task 5 - ✔✔Prepare for assessment
Task: Identify risk model and analytic approach
-one or more risk models for use in conducting risk assessment
-identify which model is to be used for risk assessment
✔✔What happens in RA Step 2 - Task 1 - ✔✔Task: Identify Threat Sources'
-Identify and characterize threat source of concern
-capability, intent, and targeting
-range of effects for non-adversarial threats
✔✔What happens in RA Step 2 - Task 2 - ✔✔Task: Identify threat events
-potential threat events
-relevance of the events
-threat sources that could initate the events
✔✔What happens in RA Step 2 - Task 3 - ✔✔Task: Identify Vulnerbilities and
predisposing conditions
-org
-mission/business processes
-information system
✔✔What is the definition of a lilkelihood level that's high? - ✔✔The threat source is
highly motivated and sufficiently capable, and controls to prevent the vulnerbility from
being exercised are ineffective.
✔✔What is the definition of a lilkelihood level that's medium? - ✔✔The threat source is
motivated and capable, but controls are in place that may impede successful exercise of
the vulnerablity.
✔✔What is the definition of a lilkelihood level that's low? - ✔✔The threat source lacks
motivation or capability, or controls are in place to prevent, or at least significantly
impede, the vulnerability from being exercised.
✔✔What happens in RA Step 2 - Task 4 - ✔✔Task: Determine likelihood
- the characteristics of the threat sources
RATED A+
✔✔What are the Investment Life Cycles phases? - ✔✔Select, Control, Evaluate
✔✔What are the 7 steps in SP 800-65 Intergrating information security into the CPIC
process? - ✔✔Identify the baseline
Identify prioritization requirements
Conduct enterprise-level prioritization
Conduct system-level prioritization
Develop supporting materials
Implement Investment Review Board and Portfolio management
Submit Exhibit 300s, Exhibit 53, and Conduct Program Management.
✔✔NIST 800-55 - ✔✔Security Metric Guide for information technology systems
provides guidance on how an org by using metrics, identifies the adequacy of in-place
security controls, policies and procedures
✔✔What is Federal Enterprise Architecture? - ✔✔This consist of a set of interrelated
"reference models" designed to facilitate cross agency analysis and the identification of
duplicative investments, gaps, and opportunities for collaboration within and across
agencies.
✔✔What are the 5 Federal Enterprise Architecture models? - ✔✔Performance
Reference
Business Reference
Service Component Reference
Technical Reference
Data Reference
✔✔What are the core principle of the FEA? - ✔✔Business-driven
Proactive and collaborative throughout the Federal goverment
Architecture improves the effectiveness and efficiency of goverment information
✔✔What support RA-3 Risk Assessment - ✔✔800-37
✔✔RA-3 security control must be partially implemented prior to the implementation of
other controls in order to completed the first two steps in the Risk Management
Framework? True or False - ✔✔True
✔✔What meet the requirement of the Cyber Security Research and Development Act of
2002 (Public law 107-305) CSRDA? - ✔✔To faciliated development the security
chechlist, NIST developed the National Checklist Program for IT products.
,✔✔800-39 has replaced 800-30 as the authoritative source of comprehensive risk
management guidance. True or False - ✔✔True
✔✔What are the Risk Assessment Steps? (Risk framing) - ✔✔Prepare for assessment
Conduct the assessment
Report and Communicate the assessment
Maintain the assessment
✔✔What happens in RA Step 1 - Task 1 - ✔✔Prepare for assessment
Task: Identify purpose of assessment -
Information that the assessment is intended to produce
Decision the assessment is intended to support
✔✔What happens in RA Step 1 - Task 2 - ✔✔Prepare for assessment
Task: Identify Scope - determines what will be considered in the assessment
Org applicability
Time frame supported
Architectural/technology considerations
✔✔What happens in RA Step 1 - Task 3 - ✔✔Prepare for assessment
Task: Indentiy Assumptions and considerations
-Assumption
-constraints
-risk tolerances
-priorities/trade-offs
✔✔What are some assumptions and constraints regarding risk assessment? -
✔✔Threat source
Threat event
Vulnerabilities and predisposing conditions
Potential impacts
Assessment and analysis approaches
Which missions/business functions are primary
✔✔What happens in RA Step 1 - Task 4 - ✔✔Prepare for assessment
Task: Indentify information sources
-descriptions
-threat
-vulnerability
-impact
✔✔What are example of Information Sources? - ✔✔Internal
-logs
-reports
-trouble tickets
, External
-cross-community org (ie CERT, ISAC, etc.)
-research orgs
✔✔What are some information input activities for risk assessment? - ✔✔document
reviews
questionaires and surveys
on-site interviews
automated tools
✔✔What happens in RA Step 1 - Task 5 - ✔✔Prepare for assessment
Task: Identify risk model and analytic approach
-one or more risk models for use in conducting risk assessment
-identify which model is to be used for risk assessment
✔✔What happens in RA Step 2 - Task 1 - ✔✔Task: Identify Threat Sources'
-Identify and characterize threat source of concern
-capability, intent, and targeting
-range of effects for non-adversarial threats
✔✔What happens in RA Step 2 - Task 2 - ✔✔Task: Identify threat events
-potential threat events
-relevance of the events
-threat sources that could initate the events
✔✔What happens in RA Step 2 - Task 3 - ✔✔Task: Identify Vulnerbilities and
predisposing conditions
-org
-mission/business processes
-information system
✔✔What is the definition of a lilkelihood level that's high? - ✔✔The threat source is
highly motivated and sufficiently capable, and controls to prevent the vulnerbility from
being exercised are ineffective.
✔✔What is the definition of a lilkelihood level that's medium? - ✔✔The threat source is
motivated and capable, but controls are in place that may impede successful exercise of
the vulnerablity.
✔✔What is the definition of a lilkelihood level that's low? - ✔✔The threat source lacks
motivation or capability, or controls are in place to prevent, or at least significantly
impede, the vulnerability from being exercised.
✔✔What happens in RA Step 2 - Task 4 - ✔✔Task: Determine likelihood
- the characteristics of the threat sources