• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 2 fuera de 14 páginas
Examen

FITSP STUDY GUIDE 2025/2026 QUESTIONS WITH ANSWERS RATED A+

Document preview thumbnail
Vista previa 2 fuera de 14 páginas

FITSP STUDY GUIDE 2025/2026 QUESTIONS WITH ANSWERS RATED A+

Vista previa del contenido

FITSP STUDY GUIDE 2025/2026 QUESTIONS WITH
ANSWERS RATED A+
✔✔How do you know you can safely purchase a product from a vendor? - ✔✔By
checking the Common Vulnerabilities and Exposures (CVE) and the Cryptographic
Module Validation Program (CMVP) which utilize a common criteria certification process
to provide product validation.

✔✔The National Vulnerability Database (NVD) is - ✔✔The U.S. government repository
of standards based vulnerability management data represented using the Security
Content Automation Protocol (SCAP). This data enables automation of vulnerability
management, security measurement, and compliance. The NVD includes databases of
security checklist references, security-related software flaws, misconfigurations, product
names, and impact metrics.

✔✔M-02-01 - ✔✔Guidance for Preparing and Submitting Security Plans of Action and
Milestones (POAMS)

✔✔M-14-03 Enhancing the Security of Federal Information and Information Systems -
✔✔Established Continuous monitoring (REMOVED 3 year authorization requirement IF
CM is in place)

✔✔M-11-11 - ✔✔Continued Implementation of Homeland Security Presidential Directive
(HSPD) 12- Policy for a Common Identification Standard for Federal Employees and
Contractors

✔✔NIST Risk Management Framework (RMF) - ✔✔Prepare
Categorize
Select
Implement
Assess
Authorize
Monitor

Pretty cool system if anyone asks me

✔✔What are the assessment methods defined by NIST? - ✔✔Test
Interview
Examine

✔✔What are the Five Elements of the NIST Cybersecurity Framework? - ✔✔Identify
Detect
Protect
Respond
Recover

, These core functions aid organizations in their effort to spot, manage and counter
cybersecurity events promptly.

✔✔FIPS 140-2 - ✔✔Cryptographic modules; Superseded by FIPS 140-3
-Establishes the Cryptographic Module Validation Program (CMVP)
-Defines security requirements for Cryptographic Modules:
Level 1: Basic
Level 2: Adds tamper evident coating and role-based authentication
Level 3: Adds identity based authentication, intrusion prevention, and critical access
parameters
Level 4: It requires hardware to be tamper-active. Any tampering of the module to erase
all critical security information

✔✔FIPS-197 - ✔✔AES (Advanced encryption standard)
-The AES algorithm is a symmetric block cipher that can encrypt (encipher) and decrypt
(decipher).

Rijndael algorithm

✔✔What cryptographic keys does the AES algorithm use and what size data blocks can
it encrypt/decrypt? - ✔✔Keys: 128, 192, and 256
Can encrypt/decrypt data blocks of 128 bits

✔✔FIPS-198 - ✔✔Keyed Hash Message Authentication Code (HMAC)
HMACs have two functionally distinct parameters, a message input and a secret key
known only to the message originator and intended receiver(s).

✔✔FIPS-199 - ✔✔Develops standards for categorizing information and information
systems and covers all "official" federal systems.

✔✔SP 800-60 - ✔✔Security Categorization: Guides implementation of FIPS-199

✔✔How does Clinger-Cohen tie into security? - ✔✔1. NIST issues FIPS with which all
agencies must comply
2. Info types are categorized using SP 800-60 (driven by FIPS 199 and 200), which
derive their ratings from their use under the line of business in the Business Reference
Model.
3. This produces the criticality of the system and its info.
4. The above lead to the projection requirements (CIA triad)

✔✔FIPS-200 - ✔✔Establishes minimum security requirements for information systems
(mandates the use of SP800-53 as amended)

✔✔FIPS-201 - ✔✔PIV (common identification and e-auth)

Información del documento

Subido en
31 de mayo de 2025
Número de páginas
14
Escrito en
2024/2025
Tipo
Examen
Contiene
Preguntas y respuestas
$12.49

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
BOARDWALK
3.4
(19)
Vendido
157
Seguidores
7
Artículos
26503
Última venta
2 semanas hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes