FITSP MANAGER FINAL PAPER 2025/2026 QUESTIONS
WITH ANSWERS RATED A+
✔✔Which approach involves continually balancing the protection of agency information
and assets with the cost of security controls and mitigation strategies? - ✔✔Risk
Management Approach
✔✔What establish the scope of protection for organizational information systems? -
✔✔System Boundaries
✔✔During what phase of the SDLC should the org consider the security requirments? -
✔✔Initiation Phase/ Development /Acquisition Phase
✔✔Security Reauthorizations are conducted during what phase of the SDLC? -
✔✔Operations/Maintenance
✔✔What NIST Pub superseded the original SP 800-30 as the primary source for
guidance on risk management? - ✔✔SP 800-39
✔✔Tier 2 of the 3-tiered risk management approach addresses risk-related concern at
which level? - ✔✔Mission/Business Process
✔✔What is the final step in the ISCM process? - ✔✔Review and update the monitoring
program.
✔✔What SCAP specification provide a standard naming and dictionary of system
configuration issues? - ✔✔CPE
✔✔What are resources of National Vulnerbility Database (NVD)? - ✔✔CPE, CVE,
OVAL
✔✔What are examples of security domains? - ✔✔Vulnerbility and Patch Management
Event and Incident Management
Malware Detection
✔✔Why do organization look for automated solutions for ISCM? - ✔✔Lower costs,
ehancce efficiency, improve reliablity
✔✔What the first step of the ISCM process? - ✔✔Define an ISCM Strategy
✔✔What mandate uses NIST SP-800 53? - ✔✔FIPS 200
,✔✔The _________ requires agencies to identify sensitive systems, conduct computer
security training, and develop computer security plans. - ✔✔Computer Security Act of
1987
✔✔What SP describes Secure Portal VPNs and Secure Tunnel VPN? - ✔✔800-113
Guide to SSL VPN
✔✔What SP specifies how to run name server software with restricted privileges? -
✔✔800-81 Secure Domain Name System (DNS) Deployment Guide.
✔✔What SP describes attacker tools such as Backdoors? - ✔✔800-83 - Guide to
Malware Incident Prevention and Handling includes recommendations for controls to
mitigate malware attacks and improving an organization malware program.
✔✔_________________ is typically defined in terms of the security features, functions,
mechanisms, services, procedures, and architectures implemented within organizational
information systems or the enviroments in which those systems operate. - ✔✔Security
Functionality
✔✔Who approves FIPS? - ✔✔Secretary of Commerce
✔✔How many layers of Encrytion standards are defined by FIPS? - ✔✔Four
✔✔What are approved intergrity standard? - ✔✔Digital Signature, Secure Hash, HMAC
✔✔What are the five phases of SDLC? - ✔✔Initiation,
Acquisition/Development,
Implementation,
Operations/Maintenance
Disposition
✔✔What does SP 800-66 Rev 1 Implementing the health and insurance portiability and
accountablilty act (HIPPA) Security rules provides? - ✔✔Provide the NIST 800-53
correlations to the hippa technical,administrative, and physical security safeguards rules
Provide NIST guidance on organizational policy, procedural, and documentation
requirments.
✔✔What is EPHI? - ✔✔Electronic Protection health information.
✔✔SP-800 70 REV2 - ✔✔National Checklist Program
✔✔SP 800-83 - ✔✔Guide to Malware Incident Prevention and Handling
-defines malware categories and types
-decribes malware prevention techniques
, -discuss malware response mechnisms
✔✔SP 800 88 Rev 1 - ✔✔Guideline for Media Santitization
-defines needs ant techniques for media sanitization
-describes various sanitization techniques and tools
-show the benefits and difficulties of media sanitization,disposal, and destruction
✔✔SP 800 92 - ✔✔Guide to Computer Security log Management
✔✔SP 800 94 - ✔✔Guide to Intrusion Detection and Prevention Systems (IDPS)
✔✔What is IDPS process model - ✔✔Information Sources, Analysis, Response
✔✔What are the 4 types of IDPS technology - ✔✔Network Based, Wireless, Network
Behavior Analysis, Host-based.
✔✔SP 800 -100 - ✔✔Infomation Security Handbook - A guide for managers
✔✔SP 800-115 - ✔✔Technical Guide to Information Security Testing and Assessment
-works with 800-53a at testing and assessment guidance
✔✔SP 800-122 - ✔✔Guide to Protecting the Confidentiality of PII
-defines PII and Impace levels
-provides for confidentiality consideration of USG systems
-dicussess breach response requiements
✔✔SP 800 128 - ✔✔Guide for Secuity Forcused Configuration Management of
Information Systems
✔✔SP 800-137 - ✔✔Information Security Continuous Monitoring for Federal Information
System and Org
✔✔SP 800 144 - ✔✔Guidelines on Security and Privacy in Public Cloud Computing
✔✔What are FITSP-M objectives - FIPS - ✔✔Oversee requirements for secure
applications
Manage a contingency plan
Establish and enforce secure configuration settings
Supervise controls to facilitate confidentiality
Manage safeguards that facilitate integrity
Oversee, direct, and manage user identification and authentication to allow access
✔✔FIPS 140-2 - ✔✔Security requirements for cryptographic modules
WITH ANSWERS RATED A+
✔✔Which approach involves continually balancing the protection of agency information
and assets with the cost of security controls and mitigation strategies? - ✔✔Risk
Management Approach
✔✔What establish the scope of protection for organizational information systems? -
✔✔System Boundaries
✔✔During what phase of the SDLC should the org consider the security requirments? -
✔✔Initiation Phase/ Development /Acquisition Phase
✔✔Security Reauthorizations are conducted during what phase of the SDLC? -
✔✔Operations/Maintenance
✔✔What NIST Pub superseded the original SP 800-30 as the primary source for
guidance on risk management? - ✔✔SP 800-39
✔✔Tier 2 of the 3-tiered risk management approach addresses risk-related concern at
which level? - ✔✔Mission/Business Process
✔✔What is the final step in the ISCM process? - ✔✔Review and update the monitoring
program.
✔✔What SCAP specification provide a standard naming and dictionary of system
configuration issues? - ✔✔CPE
✔✔What are resources of National Vulnerbility Database (NVD)? - ✔✔CPE, CVE,
OVAL
✔✔What are examples of security domains? - ✔✔Vulnerbility and Patch Management
Event and Incident Management
Malware Detection
✔✔Why do organization look for automated solutions for ISCM? - ✔✔Lower costs,
ehancce efficiency, improve reliablity
✔✔What the first step of the ISCM process? - ✔✔Define an ISCM Strategy
✔✔What mandate uses NIST SP-800 53? - ✔✔FIPS 200
,✔✔The _________ requires agencies to identify sensitive systems, conduct computer
security training, and develop computer security plans. - ✔✔Computer Security Act of
1987
✔✔What SP describes Secure Portal VPNs and Secure Tunnel VPN? - ✔✔800-113
Guide to SSL VPN
✔✔What SP specifies how to run name server software with restricted privileges? -
✔✔800-81 Secure Domain Name System (DNS) Deployment Guide.
✔✔What SP describes attacker tools such as Backdoors? - ✔✔800-83 - Guide to
Malware Incident Prevention and Handling includes recommendations for controls to
mitigate malware attacks and improving an organization malware program.
✔✔_________________ is typically defined in terms of the security features, functions,
mechanisms, services, procedures, and architectures implemented within organizational
information systems or the enviroments in which those systems operate. - ✔✔Security
Functionality
✔✔Who approves FIPS? - ✔✔Secretary of Commerce
✔✔How many layers of Encrytion standards are defined by FIPS? - ✔✔Four
✔✔What are approved intergrity standard? - ✔✔Digital Signature, Secure Hash, HMAC
✔✔What are the five phases of SDLC? - ✔✔Initiation,
Acquisition/Development,
Implementation,
Operations/Maintenance
Disposition
✔✔What does SP 800-66 Rev 1 Implementing the health and insurance portiability and
accountablilty act (HIPPA) Security rules provides? - ✔✔Provide the NIST 800-53
correlations to the hippa technical,administrative, and physical security safeguards rules
Provide NIST guidance on organizational policy, procedural, and documentation
requirments.
✔✔What is EPHI? - ✔✔Electronic Protection health information.
✔✔SP-800 70 REV2 - ✔✔National Checklist Program
✔✔SP 800-83 - ✔✔Guide to Malware Incident Prevention and Handling
-defines malware categories and types
-decribes malware prevention techniques
, -discuss malware response mechnisms
✔✔SP 800 88 Rev 1 - ✔✔Guideline for Media Santitization
-defines needs ant techniques for media sanitization
-describes various sanitization techniques and tools
-show the benefits and difficulties of media sanitization,disposal, and destruction
✔✔SP 800 92 - ✔✔Guide to Computer Security log Management
✔✔SP 800 94 - ✔✔Guide to Intrusion Detection and Prevention Systems (IDPS)
✔✔What is IDPS process model - ✔✔Information Sources, Analysis, Response
✔✔What are the 4 types of IDPS technology - ✔✔Network Based, Wireless, Network
Behavior Analysis, Host-based.
✔✔SP 800 -100 - ✔✔Infomation Security Handbook - A guide for managers
✔✔SP 800-115 - ✔✔Technical Guide to Information Security Testing and Assessment
-works with 800-53a at testing and assessment guidance
✔✔SP 800-122 - ✔✔Guide to Protecting the Confidentiality of PII
-defines PII and Impace levels
-provides for confidentiality consideration of USG systems
-dicussess breach response requiements
✔✔SP 800 128 - ✔✔Guide for Secuity Forcused Configuration Management of
Information Systems
✔✔SP 800-137 - ✔✔Information Security Continuous Monitoring for Federal Information
System and Org
✔✔SP 800 144 - ✔✔Guidelines on Security and Privacy in Public Cloud Computing
✔✔What are FITSP-M objectives - FIPS - ✔✔Oversee requirements for secure
applications
Manage a contingency plan
Establish and enforce secure configuration settings
Supervise controls to facilitate confidentiality
Manage safeguards that facilitate integrity
Oversee, direct, and manage user identification and authentication to allow access
✔✔FIPS 140-2 - ✔✔Security requirements for cryptographic modules