ISC2 Certified Authorization Professional (CAP) — Questions and Answers
Question 1: What is the purpose of a vendor risk assessment in ICT supply chain risk management?
- To verify that a vendor's products are FedRAMP authorized
- To negotiate better pricing on hardware procurement
- To evaluate a third-party vendor's security practices, financial stability, and ability to protect government data (Correct answer)
- To determine which country manufactured the product components
Correct answer: To evaluate a third-party vendor's security practices, financial stability, and ability to protect government data
Vendor risk assessments evaluate whether suppliers have adequate security controls, business continuity plans, and integrity measures to be trusted partners.
Question 2: What does an agency's contingency plan document describe?
- Vendor escalation procedures
- How to handle data breaches only
- Procedures to recover information system operations after a disruption or disaster (Correct answer)
- Network configuration backups
Correct answer: Procedures to recover information system operations after a disruption or disaster
A contingency plan defines the procedures for maintaining or restoring operations of an information system following a disruption.
Question 3: When a significant system change resets an ongoing authorization, what document must be updated first?
- The Rules of Behavior
- The POA&M
- The SSP to reflect the new system configuration and updated controls (Correct answer)
- The contingency plan
Correct answer: The SSP to reflect the new system configuration and updated controls
The SSP must be updated to reflect the significant change before a new security impact analysis or re-authorization can proceed.
Question 4: What NIST publication provides the primary guidance for the Risk Management Framework (RMF)?
- NIST SP 800-53
- NIST SP 800-30
- NIST SP 800-171
- NIST SP 800-37 (Correct answer)
Correct answer: NIST SP 800-37
NIST SP 800-37 provides the guide for applying the Risk Management Framework to federal information systems.
Question 5: Executive Order 14028, issued in May 2021, directed federal agencies to take which key action?
- Transfer all systems to on-premises data centers
- Improve the nation's cybersecurity through software supply chain security, zero trust, and enhanced incident reporting (Correct answer)
- Reduce IT budgets by 10%
- Eliminate use of commercial cloud services
Correct answer: Improve the nation's cybersecurity through software supply chain security, zero trust, and enhanced incident reporting
EO 14028 required federal agencies to modernize cybersecurity by adopting zero trust, improving software supply chain security, and enhancing incident logging.
Question 6: What is the purpose of security control overlays in the implementation process?
- To eliminate inherited controls from the SSP
- To replace the need for security categorization
- To tailor baseline controls for specific technologies, environments, or communities of interest (Correct answer)
- To reduce the number of required security assessors
Correct answer: To tailor baseline controls for specific technologies, environments, or communities of interest
Overlays provide tailoring guidance that customizes security control baselines for specific technologies, deployment environments, or sector-specific requirements.
Question 7: Under FISMA, what annual requirement must federal agencies fulfill regarding their information security programs?
- Conduct a full system re-authorization
- Publish a public cybersecurity report
- Submit an annual report to OMB and Congress on their security program status (Correct answer)
- Replace all security tools
Correct answer: Submit an annual report to OMB and Congress on their security program status
FISMA requires federal agencies to report annually to OMB and Congress on the effectiveness of their information security programs.
Question 8: A CAP is responsible for monitoring ongoing compliance within an organization. What is the most effective tool for tracking compliance metrics over time?
- A paper-based log for each department
- A centralized database for compliance tracking and reporting (Correct answer)
- Regular emails requesting updates from department heads
- A manual checklist completed monthly
Correct answer: A centralized database for compliance tracking and reporting
For monitoring ongoing compliance effectively over time, a centralized database is the most effective tool. It allows for systematic collection, storage, and analysis of compliance metrics, providing a comprehensive and up-to-date overview of the organization's status. Unlike manual or fragmented methods, a centralized system facilitates efficient reporting, trend analysis, and proactive identification of potential issues.
Question 9: Which federal law established the modern framework for federal information security and was significantly updated in 2014?
- Clinger-Cohen Act of 1996
- Federal Information Security Modernization Act (FISMA) (Correct answer)
- Sarbanes-Oxley Act
- Privacy Act of 1974
Correct answer: Federal Information Security Modernization Act (FISMA)
FISMA 2014 updated the original 2002 law to strengthen DHS's role, require automated monitoring, and improve incident reporting.
Question 10: In preparing for an accreditation audit, a CAP realizes that employees lack awareness of a new regulatory standard. What is the CAP's best course of action?
- Place the new standard document in the break room
- Ignore the issue, as it may not impact the audit results
- Send an email with a copy of the standard to all employees
- Schedule a training session focused on the new standard (Correct answer)
Correct answer: Schedule a training session focused on the new standard
When employees lack awareness of a new regulatory standard, a comprehensive training session is the most effective course of action. This allows for direct instruction, clarification of complex details, and opportunities for questions, ensuring a shared understanding across the workforce. Simply sending an email or placing a document is passive and less likely to achieve widespread comprehension and compliance, which is critical for accreditation.
Question 11: Which tool is commonly used in US federal agencies to automate continuous monitoring data collection?
- FedRAMP Portal
- OMB MAX Portal
- Continuous Diagnostics and Mitigation (CDM) Dashboard (Correct answer)
- NIST Cybersecurity Framework Tool
Correct answer: Continuous Diagnostics and Mitigation (CDM) Dashboard
CISA's CDM program provides federal agencies with tools, integration services, and a dashboard to automate continuous monitoring.
Question 12: How does FedRAMP use continuous monitoring for cloud service providers?
- FedRAMP requires quarterly AO reviews instead of continuous monitoring
- CSPs only need an annual assessment to maintain FedRAMP authorization
- CSPs must provide monthly vulnerability scans, annual penetration tests, and ongoing POA&M updates to maintain their FedRAMP authorization (Correct answer)
- CSPs submit continuous monitoring data only when requested by agencies
Correct answer: CSPs must provide monthly vulnerability scans, annual penetration tests, and ongoing POA&M updates to maintain their FedRAMP authorization
FedRAMP's continuous monitoring requirements include monthly vulnerability scanning, annual penetration testing, and regular POA&M tracking to maintain authorization.
Question 13: Which federal agency is responsible for issuing FIPS publications that federal agencies must comply with?
- OMB
- NIST (Correct answer)
- NSA
- CISA
Correct answer: NIST
The National Institute of Standards and Technology (NIST) issues Federal Information Processing Standards (FIPS) publications.
Question 14: Which CAP-related document captures the results of security testing and evaluation activities?
- Contingency Plan
- Rules of Behavior
- System Security Plan
- Security Assessment Report (Correct answer)
Correct answer: Security Assessment Report
The Security Assessment Report (SAR) documents the findings, deficiencies, and recommendations from testing and evaluating security controls.
Question 15: What is typically triggered when a significant change occurs to an authorized information system?
- The SSP is deleted and recreated
- The ATO is immediately revoked
- A security impact analysis and possible re-authorization are initiated (Correct answer)
- The ISSO must resign
Correct answer: A security impact analysis and possible re-authorization are initiated
Significant changes require a security impact analysis, and if the risk posture changes materially, re-authorization may be required.
Question 16: Which document records all security-relevant events and changes affecting an information system over time?
- Configuration Management Log (Correct answer)
- System Security Plan
- Security Authorization Package History
- Security Assessment Report
Correct answer: Configuration Management Log
The configuration management log tracks changes to system components, supporting the ongoing integrity of the system's documented baseline.
Question 17: Which document within the RMF authorization package identifies weaknesses and plans to remediate them?
- Plan of Action and Milestones (POA&M) (Correct answer)
- Security Assessment Report (SAR)
- Authorization Decision Document
- System Security Plan (SSP)
Correct answer: Plan of Action and Milestones (POA&M)
The POA&M tracks identified security weaknesses and documents the corrective actions and timelines for remediation.
Question 18: What are the three potential impact levels defined by FIPS 199?
- Level 1, Level 2, Level 3
- Critical, Important, Minor
- Green, Yellow, Red
- Low, Moderate, High (Correct answer)
Correct answer: Low, Moderate, High
FIPS 199 defines Low, Moderate, and High as the three potential impact levels for each security objective.
Question 19: Which OMB memorandum introduced the 'Assume Breach' mentality and required agencies to adopt zero trust architecture?
- OMB M-21-31
- OMB M-22-09 (Correct answer)
- OMB A-130
- OMB M-17-12
Correct answer: OMB M-22-09
OMB M-22-09 established a federal zero trust architecture strategy requiring agencies to meet specific zero trust security goals.
Question 20: OMB Circular A-130 provides federal policy guidance on which broad area?
- Congressional budget procedures
- Federal procurement rules
- Federal hiring standards
- Managing federal information resources, including IT security and privacy (Correct answer)
Correct answer: Managing federal information resources, including IT security and privacy
OMB Circular A-130 establishes federal policy for managing information resources, including requirements for information security and privacy.
Question 21: What does the term 'Controlled Unclassified Information' (CUI) refer to?
- Top Secret/SCI data
- Publicly releasable federal records
- Information the government requires safeguarding per law, regulation, or policy, but is not classified (Correct answer)
- Classified defense information
Correct answer: Information the government requires safeguarding per law, regulation, or policy, but is not classified
CUI is sensitive government information that requires protection but does not meet the threshold for national security classification.
Question 22: What is the difference between an Authorization to Operate (ATO) and an Interim Authorization to Operate (IATO)?
- An ATO requires FISMA compliance; an IATO does not
- An ATO is for classified systems; an IATO is for unclassified systems
- An ATO is a full authorization; an IATO is a time-limited authorization granted while residual risks are being mitigated (Correct answer)
- An ATO is issued by the ISSO; an IATO is issued by the AO
Correct answer: An ATO is a full authorization; an IATO is a time-limited authorization granted while residual risks are being mitigated
An IATO allows a system to operate temporarily with known risks under conditions that must be remediated within a specified timeframe.
Question 23: Which executive order significantly elevated the importance of software supply chain security for federal agencies?
- Executive Order 13636 (Improving Critical Infrastructure Cybersecurity)
- Executive Order 14028 (Improving the Nation's Cybersecurity) (Correct answer)
- Executive Order 13800 (Strengthening Federal Networks)
- Executive Order 12333 (United States Intelligence Activities)
Correct answer: Executive Order 14028 (Improving the Nation's Cybersecurity)
EO 14028, issued in May 2021, directed federal agencies to improve supply chain security, requiring SBOMs and secure software development practices.
Question 24: According to NIST SP 800-53, which control baseline applies to an information system with a FIPS 199 overall impact level of Moderate?
- Moderate baseline (Correct answer)
- Minimum security baseline
- High baseline
- Low baseline
Correct answer: Moderate baseline
NIST SP 800-53 directly maps baseline selection to impact level, so a Moderate-impact system uses the Moderate security control baseline.
Question 25: Which NIST publication provides guidance on preparing the authorization package and submitting it to the AO?
- NIST SP 800-37 (Correct answer)
- NIST SP 800-53A
- NIST SP 800-60
- NIST SP 800-30
Correct answer: NIST SP 800-37
NIST SP 800-37 describes the RMF process including the preparation and submission of the authorization package to the Authorizing Official.
Question 26: Which of the following best describes the primary purpose of conducting an internal audit as part of the CAP’s responsibilities?
- To fulfill a mandatory requirement by the accrediting body
- To identify compliance gaps before the official audit (Correct answer)
- To create a summary report for marketing purposes
- To test staff knowledge of accreditation standards
Correct answer: To identify compliance gaps before the official audit
The primary purpose of conducting an internal audit, as part of a CAP's responsibilities, is to proactively assess the organization's adherence to accreditation standards. By performing these internal checks, the CAP can identify any compliance gaps or areas of non-conformance before the official external audit. This allows the organization to implement necessary corrective actions, thereby improving readiness and increasing the chances of successful accreditation.
Question 27: Under FedRAMP, what authorization path allows agencies to reuse an existing cloud ATO?
- Security Impact Analysis
- Agency ATO
- Reciprocity Agreement
- Joint Authorization Board (JAB) Provisional ATO (Correct answer)
Correct answer: Joint Authorization Board (JAB) Provisional ATO
A JAB Provisional ATO (P-ATO) issued by FedRAMP's Joint Authorization Board can be leveraged by multiple agencies through reciprocity.
Question 28: What is the difference between configuration management and continuous monitoring?
- Configuration management is only for hardware; continuous monitoring covers software
- Continuous monitoring replaces the need for configuration management
- Configuration management establishes and maintains secure baselines; continuous monitoring verifies those baselines are maintained over time (Correct answer)
- They are synonymous terms used interchangeably
Correct answer: Configuration management establishes and maintains secure baselines; continuous monitoring verifies those baselines are maintained over time
Configuration management defines the desired security state, while continuous monitoring checks that the system continues to operate in that desired state.
Question 29: Which federal privacy law gives US citizens the right to access and correct records held by federal agencies?
- HIPAA
- COPPA
- FERPA
- Privacy Act of 1974 (Correct answer)
Correct answer: Privacy Act of 1974
The Privacy Act of 1974 governs federal agency collection, maintenance, use, and dissemination of personally identifiable information.
Question 30: A data flow diagram (DFD) in an SSP is used to illustrate what?
- Security control gaps
- How data moves through the system, including inputs, outputs, and storage (Correct answer)
- User access permissions
- Network topology only
Correct answer: How data moves through the system, including inputs, outputs, and storage
A DFD maps how data enters, travels through, is processed, and exits the information system, supporting privacy and security analysis.
Question 31: What is a Memorandum of Understanding (MOU) used for in the context of information system authorization?
- Granting temporary access to contractors
- Documenting agreed-upon responsibilities between two or more organizations sharing a system or service (Correct answer)
- Replacing the SSP for low-impact systems
- Replacing the POA&M
Correct answer: Documenting agreed-upon responsibilities between two or more organizations sharing a system or service
An MOU documents the responsibilities and agreements between organizations regarding shared systems, services, or data.
Question 32: Which process ensures that security controls remain correctly configured as a system evolves and changes are introduced?
- Incident response
- Business impact analysis
- Configuration management (Correct answer)
- Risk assessment
Correct answer: Configuration management
Configuration management controls changes to system components and ensures that security controls remain properly implemented as the system evolves.
Question 33: What is the purpose of a System of Records Notice (SORN)?
- To grant database access permissions
- To list authorized system users
- To publicly notify citizens about federal systems that collect and use their personal data (Correct answer)
- To document system vulnerabilities
Correct answer: To publicly notify citizens about federal systems that collect and use their personal data
A SORN is published in the Federal Register to inform the public about systems that maintain personally identifiable information about individuals.
Question 34: Which document in the authorization package describes known vulnerabilities and the schedule to fix them?
- Authorization Decision Letter
- System Security Plan
- Plan of Action and Milestones (Correct answer)
- Security Assessment Report
Correct answer: Plan of Action and Milestones
The Plan of Action and Milestones (POA&M) tracks identified weaknesses, responsible parties, resources needed, and target completion dates.
Question 35: What document serves as the primary guide for implementing security controls in an information system?
- Privacy Impact Assessment (PIA)
- System Security Plan (SSP) (Correct answer)
- Security Assessment Report (SAR)
- Plan of Action and Milestones (POA&M)
Correct answer: System Security Plan (SSP)
The System Security Plan documents how security controls are planned and implemented, serving as the authoritative reference for control implementation.
Question 36: Which FIPS standard defines the three security objectives: confidentiality, integrity, and availability?
- FIPS 201
- FIPS 199 (Correct answer)
- FIPS 200
- FIPS 140-2
Correct answer: FIPS 199
FIPS 199 establishes the standards for categorizing federal information and information systems using C, I, and A.
Question 37: Which NIST publication provides the comprehensive catalog of security and privacy controls for federal information systems?
- NIST SP 800-60
- FIPS 199
- NIST SP 800-53 (Correct answer)
- NIST SP 800-37
Correct answer: NIST SP 800-53
NIST SP 800-53 provides the catalog of security and privacy controls that organizations select from when building their control baseline.
Question 38: Which NIST SP 800-137 activity involves reviewing and revising the continuous monitoring program based on lessons learned?
- Respond
- Analyze/Report
- Review/Update (Correct answer)
- Implement
Correct answer: Review/Update
The Review/Update step ensures the continuous monitoring program evolves based on changing threats, technology, and lessons learned from findings.
Question 39: What is the purpose of FIPS 199 in the RMF process?
- Guiding incident response
- Establishing security categorization standards (Correct answer)
- Defining encryption standards
- Outlining audit requirements
Correct answer: Establishing security categorization standards
FIPS 199 establishes standards for categorizing federal information and information systems based on potential impact (low, moderate, high).
Question 40: The CAP needs to communicate non-compliance findings from a recent internal audit to the leadership team. What is the best communication strategy?
- Present a summary report highlighting key findings and recommended actions (Correct answer)
- Forward the raw audit data and let leadership interpret the results
- Schedule a meeting but provide no prior documentation for review
- Only report findings related to high-priority issues
Correct answer: Present a summary report highlighting key findings and recommended actions
When communicating non-compliance findings to leadership, the most effective strategy is to provide a concise summary report. This report should clearly highlight the key findings, explain their significance, and, crucially, propose recommended actions or a corrective action plan. Leadership needs actionable insights, not raw data, to make informed decisions and support necessary improvements.
Question 41: What is a Security Information and Event Management (SIEM) system's primary role in continuous monitoring?
- To aggregate, correlate, and analyze security event logs from across the enterprise in near real-time (Correct answer)
- To serve as the primary vulnerability scanner
- To replace firewalls with AI-driven packet inspection
- To generate the System Security Plan automatically
Correct answer: To aggregate, correlate, and analyze security event logs from across the enterprise in near real-time
A SIEM collects logs from multiple sources, correlates events, and generates alerts to enable rapid detection of security incidents.
Question 42: What is the purpose of an authorization boundary in the context of system documentation?
- To define the scope of components, data, and services subject to assessment and authorization (Correct answer)
- To list all users authorized to access the system
- To identify funding boundaries for IT projects
- To establish the physical perimeter of a data center
Correct answer: To define the scope of components, data, and services subject to assessment and authorization
The authorization boundary defines exactly what is included in the assessment and authorization, preventing scope creep during reviews.
Question 43: Which mission-based information type from NIST SP 800-60 typically receives a High Confidentiality categorization?
- Facilities management information
- Public outreach and communications data
- Intelligence data and law enforcement sensitive information (Correct answer)
- Training and education records for public programs
Correct answer: Intelligence data and law enforcement sensitive information
Information types like intelligence and law enforcement sensitive data typically warrant High confidentiality due to the severe harm from unauthorized disclosure.
Question 44: Which RMF step results in the formal decision to authorize a system to operate?
- Authorize (Correct answer)
- Monitor
- Select
- Assess
Correct answer: Authorize
The Authorize step is where the Authorizing Official reviews the risk and formally grants an Authorization to Operate (ATO).
Question 45: Adjusting audit findings to meet the accreditation requirements
- Withholding audit details from certain stakeholders
- Adjusting audit findings to meet the accreditation requirements
- Ensuring transparency and accuracy in audit reporting (Correct answer)
- Avoiding documentation of minor issues to streamline the process
Correct answer: Ensuring transparency and accuracy in audit reporting
The phrase 'Adjusting audit findings to meet the accreditation requirements' describes an unethical practice that compromises the integrity of the audit process. The correct professional responsibility is ensuring transparency and accuracy in audit reporting. This means presenting findings truthfully, without manipulation, to accurately reflect the organization's compliance status and foster genuine improvement.
Question 46: What does NIST SP 800-53A provide in direct support of the security control implementation and assessment process?
- A catalog of new security controls not in SP 800-53
- Templates for completing authorization packages
- Assessment procedures for determining whether implemented controls are effective (Correct answer)
- Guidance on information system impact categorization
Correct answer: Assessment procedures for determining whether implemented controls are effective
NIST SP 800-53A provides the assessment procedures used to evaluate whether security controls have been correctly implemented and are operating effectively.
Question 47: What is the primary goal of continuous monitoring in the context of the RMF?
- To eliminate the need for periodic security assessments
- To automate the granting of ATOs without AO review
- To replace annual FISMA reporting with automated tools
- To maintain ongoing situational awareness of the security state of information systems and detect changes that affect risk (Correct answer)
Correct answer: To maintain ongoing situational awareness of the security state of information systems and detect changes that affect risk
Continuous monitoring provides real-time or near real-time visibility into the security posture of systems so that risk can be managed dynamically.
Question 48: What is the purpose of an Interconnection Security Agreement (ISA)?
- To define incident response procedures
- To authorize user access to classified data
- To document the security requirements for a connection between two systems (Correct answer)
- To grant an ATO to a new system
Correct answer: To document the security requirements for a connection between two systems
An ISA establishes the security interface requirements and responsibilities when two systems are interconnected.
Question 49: What does FISMA stand for and what does it mandate?
- Federal Information Systems Management Act; mandates annual security audits
- Federal Information Security Modernization Act; mandates federal agencies implement RMF-based security programs (Correct answer)
- Federal Information Security Management Act; mandates encryption of all federal data
- Federal IT Security Modernization Act; mandates cloud-first adoption
Correct answer: Federal Information Security Modernization Act; mandates federal agencies implement RMF-based security programs
FISMA requires federal agencies to develop, document, and implement information security programs aligned with the RMF.
Question 50: What is the primary goal of tailoring baseline security controls in the RMF?
- To adjust controls to the specific conditions, threat environment, and risk tolerance of the system (Correct answer)
- To replace government controls with industry standards
- To reduce the number of controls to the minimum possible
- To align controls with vendor recommendations
Correct answer: To adjust controls to the specific conditions, threat environment, and risk tolerance of the system
Tailoring allows organizations to customize baseline controls to fit their specific operational environment, threat landscape, and risk posture.
Question 51: Which control overlay in NIST SP 800-53 provides additional guidance for classified national security systems?
- FedRAMP overlay
- CNSS Instruction 1253 overlay (Correct answer)
- Intelligence overlay
- Privacy overlay
Correct answer: CNSS Instruction 1253 overlay
CNSSI 1253 provides the security categorization and control selection guidance for national security systems.
Question 52: Which NIST SP 800-53 control family covers configuration management?
- CP
- CA
- CM (Correct answer)
- AC
Correct answer: CM
The CM (Configuration Management) family includes controls for baseline configurations, change control, and software usage restrictions.
Question 53: Which FIPS publication establishes the standards for categorizing federal information and information systems?
- FIPS 199 (Correct answer)
- FIPS 200
- FIPS 201
- FIPS 140-2
Correct answer: FIPS 199
FIPS 199 defines the standards for security categorization of federal information and information systems.
Question 54: Which continuous monitoring activity involves testing a subset of controls each year rather than all controls simultaneously?
- Rolling assessments (Correct answer)
- Baseline reconfiguration
- Risk acceptance
- Penetration testing
Correct answer: Rolling assessments
Rolling assessments divide the full control set into groups assessed on a rotating schedule, providing continuous coverage without full annual assessments.
Question 55: What are the six steps of the ISCM process defined in NIST SP 800-137?
- Prepare, Categorize, Select, Implement, Assess, Authorize
- Identify, Protect, Detect, Respond, Recover, Adapt
- Plan, Do, Check, Act, Monitor, Report
- Define, Establish, Implement, Analyze/Report, Respond, Review/Update (Correct answer)
Correct answer: Define, Establish, Implement, Analyze/Report, Respond, Review/Update
NIST SP 800-137 defines the ISCM process as: Define strategy, Establish program, Implement program, Analyze/Report findings, Respond to findings, and Review/Update the program.
Question 56: In the context of continuous monitoring, what does the term 'security posture' describe?
- The number of security staff employed
- The overall cybersecurity strength and risk level of an organization or system at a given point in time (Correct answer)
- The encryption algorithms in use
- Physical security of a data center
Correct answer: The overall cybersecurity strength and risk level of an organization or system at a given point in time
Security posture is a holistic assessment of the organization's current state of security, including vulnerabilities, threats, and control effectiveness.
Question 57: What is the CAP’s role in ensuring ongoing compliance with accreditation standards?
- Regularly reviewing processes and implementing improvements as needed (Correct answer)
- Conducting random audits without prior notice to staff
- Waiting for the accrediting body to point out areas of non-compliance
- Overseeing external audits and delegating all internal monitoring tasks
Correct answer: Regularly reviewing processes and implementing improvements as needed
A CAP's role in ensuring ongoing compliance is proactive and continuous. This involves regularly reviewing existing processes, procedures, and practices against current accreditation standards to identify any deviations or opportunities for enhancement. Implementing improvements as needed ensures that the organization not only meets but consistently maintains and often exceeds compliance requirements, fostering a culture of sustained quality.
Question 58: Control tailoring in NIST SP 800-53 allows organizations to do which of the following?
- Remove all baseline controls
- Add only compensating controls
- Adjust baseline controls to meet specific operational needs (Correct answer)
- Ignore privacy controls
Correct answer: Adjust baseline controls to meet specific operational needs
Tailoring lets organizations add, remove, or modify baseline controls to fit their unique environment and risk tolerance.
Question 59: A Plan of Action and Milestones (POA&M) is used to track what?
- Approved system features
- System backup schedules
- Employee training records
- Weaknesses and remediation plans for security controls (Correct answer)
Correct answer: Weaknesses and remediation plans for security controls
The POA&M documents identified security weaknesses, responsible parties, and scheduled remediation milestones.
Question 60: Which federal law requires agencies to conduct Privacy Impact Assessments for new information technology systems?
- Federal Records Act
- FISMA
- Privacy Act of 1974
- E-Government Act of 2002 (Correct answer)
Correct answer: E-Government Act of 2002
Section 208 of the E-Government Act of 2002 mandates PIAs before agencies develop or procure new IT systems that collect PII.
Question 61: Which document formally describes the security controls applied to a system and how they are implemented?
- Security Assessment Report
- System Security Plan (Correct answer)
- Memorandum of Understanding
- Plan of Action and Milestones
Correct answer: System Security Plan
The System Security Plan (SSP) comprehensively describes all security controls and their implementation details for the information system.
Question 62: Executive Order 13800 directed federal agencies to take what primary action regarding cybersecurity risk?
- Use the NIST Cybersecurity Framework to manage institutional risk (Correct answer)
- Adopt zero-trust architecture immediately
- Eliminate all legacy systems within one year
- Transfer all systems to commercial cloud
Correct answer: Use the NIST Cybersecurity Framework to manage institutional risk
EO 13800 required agency heads to use the NIST Cybersecurity Framework to manage cybersecurity risk as part of enterprise risk management.
Question 63: What does 'risk tolerance' mean in the context of defining a continuous monitoring strategy?
- The degree of risk the organization is willing to accept while still achieving its mission objectives (Correct answer)
- The amount of budget allocated to security monitoring tools
- The maximum number of vulnerabilities allowed before an ATO is revoked
- The minimum uptime percentage required for critical systems
Correct answer: The degree of risk the organization is willing to accept while still achieving its mission objectives
Risk tolerance defines how much residual risk leadership is willing to accept, which informs what to monitor, how frequently, and what triggers escalation.
Question 64: Which term describes the maximum acceptable downtime for a system as defined in a Business Impact Analysis?
- Maximum Tolerable Downtime (MTD) (Correct answer)
- Recovery Time Objective (RTO)
- Recovery Point Objective (RPO)
- Mean Time to Repair (MTTR)
Correct answer: Maximum Tolerable Downtime (MTD)
MTD is the longest period an organization can survive without a critical system before business operations are permanently impaired.
Question 65: Which NIST document provides guidance specifically on incident handling and response for computer security incidents?
- NIST SP 800-53
- NIST SP 800-61 (Correct answer)
- NIST SP 800-30
- NIST SP 800-37
Correct answer: NIST SP 800-61
NIST SP 800-61, the Computer Security Incident Handling Guide, provides guidance on detecting, analyzing, containing, and recovering from incidents.
Question 66: What is the relationship between a Privacy Threshold Analysis (PTA) and security categorization?
- A PTA determines if PII is present in the system, which can affect the categorization of confidentiality (Correct answer)
- A PTA only applies to systems with a High categorization
- A PTA is completed after the ATO is granted
- A PTA replaces the FIPS 199 categorization for civilian agencies
Correct answer: A PTA determines if PII is present in the system, which can affect the categorization of confidentiality
A PTA identifies whether a system contains PII, and the presence of PII may elevate the Confidentiality impact level during categorization.
Question 67: What is the purpose of a Plan of Action and Milestones (POA&M) update in the continuous monitoring process?
- To terminate the ATO when a vulnerability is found
- To document newly identified weaknesses and track remediation progress over time (Correct answer)
- To request additional budget for security tools
- To replace the SAR after the initial assessment
Correct answer: To document newly identified weaknesses and track remediation progress over time
Regular POA&M updates during continuous monitoring ensure that newly found weaknesses are documented and remediation activities are tracked and reported.
Question 68: What are the three security control baselines defined in NIST SP 800-53B?
- Minimal, Standard, Enhanced
- Basic, Intermediate, Advanced
- Tier 1, Tier 2, Tier 3
- Low, Moderate, High (Correct answer)
Correct answer: Low, Moderate, High
NIST SP 800-53B defines Low, Moderate, and High baselines corresponding to the FIPS 199 impact categories.
Question 69: How does continuous monitoring support the 'Monitor' step of the RMF?
- By replacing the need for the security assessment report
- By providing ongoing assessment of controls, documenting changes, and reporting security status to the AO (Correct answer)
- By automating POA&M remediation without human involvement
- By generating the initial SSP before authorization
Correct answer: By providing ongoing assessment of controls, documenting changes, and reporting security status to the AO
The Monitor step of the RMF is implemented through a continuous monitoring program that tracks control effectiveness and reports status to decision-makers.
Question 70: In the context of continuous monitoring, what is a 'security metric'?
- A financial cost associated with a security breach
- A user access log entry
- A vulnerability severity score
- A quantifiable measure used to assess the effectiveness of security controls over time (Correct answer)
Correct answer: A quantifiable measure used to assess the effectiveness of security controls over time
Security metrics provide measurable data on control effectiveness, enabling organizations to track trends and make informed risk decisions.
Question 71: What does an Authorization Denial (DATO) indicate?
- The AO has determined the risk is unacceptable and the system must not operate (Correct answer)
- The system has minor findings that need remediation
- The system passed all security controls but lacks documentation
- The ATO has expired and requires renewal
Correct answer: The AO has determined the risk is unacceptable and the system must not operate
A DATO means the Authorizing Official found the risk too high to accept and prohibits the system from operating.
Question 72: What is the security categorization format specified in FIPS 199?
- Category = (High/Moderate/Low)
- SC = {(confidentiality, impact), (integrity, impact), (availability, impact)} (Correct answer)
- Risk = Threat Ă— Vulnerability Ă— Impact
- SC = [C+I+A] / 3
Correct answer: SC = {(confidentiality, impact), (integrity, impact), (availability, impact)}
FIPS 199 specifies the format as SC information type = {(confidentiality, impact level), (integrity, impact level), (availability, impact level)}.
Question 73: Which of the following steps is critical when conducting a risk assessment as part of monitoring?
- Delegating risk identification entirely to department heads
- Prioritizing risks based on their likelihood and potential impact (Correct answer)
- Focusing only on risks identified in the previous external audit
- Addressing all potential risks equally, regardless of their severity
Correct answer: Prioritizing risks based on their likelihood and potential impact
A critical step in conducting a risk assessment is prioritizing identified risks. This involves evaluating each risk based on two key factors: its likelihood of occurring and its potential impact if it does occur. Prioritization allows the CAP to allocate resources effectively, focusing on mitigating the most significant threats first, rather than treating all risks equally.
Question 74: The CAP notices an upward trend in patient safety incidents during routine monitoring in a healthcare organization. What should the CAP do first?
- Investigate the root cause of the safety incidents (Correct answer)
- Schedule a follow-up audit to confirm the trend
- Inform senior management about the trend and recommend penalties
- Develop a corrective action plan to address the trend
Correct answer: Investigate the root cause of the safety incidents
When an upward trend in patient safety incidents is observed, the CAP's immediate and most critical first step is to investigate the root cause. Understanding why these incidents are occurring is essential for developing effective and sustainable corrective actions. Without identifying the underlying causes, any attempts to address the trend would be superficial and unlikely to prevent future occurrences.
Question 75: What is the purpose of defining monitoring frequencies in a continuous monitoring strategy?
- To establish how often each control is assessed based on its volatility, importance, and available resources (Correct answer)
- To comply with mandatory daily scanning requirements
- To define the schedule for penetration tests only
- To set how many times per year the AO must review the system
Correct answer: To establish how often each control is assessed based on its volatility, importance, and available resources
Monitoring frequencies are tailored to each control based on how often it changes, its criticality, and the resources available to monitor it.
Question 76: What is a 'security status report' in the context of continuous monitoring?
- A daily automated scan report from a SIEM tool
- The official document granting an ATO
- The final output of a penetration test engagement
- A periodic report provided to the AO summarizing the current security posture, monitoring results, and risk levels (Correct answer)
Correct answer: A periodic report provided to the AO summarizing the current security posture, monitoring results, and risk levels
Security status reports keep the AO informed of the system's ongoing security posture between formal reauthorization events.
Question 77: Which regulation governs the security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems?
- FIPS 199
- NIST SP 800-171 (Correct answer)
- NIST SP 800-53
- OMB M-17-12
Correct answer: NIST SP 800-171
NIST SP 800-171 establishes requirements for protecting CUI in nonfederal systems and organizations, particularly for DoD contractors.
Question 78: What federal initiative provides automated continuous monitoring capabilities and dashboards to federal civilian agencies?
- HSPD-12
- FedRAMP
- Continuous Diagnostics and Mitigation (CDM) (Correct answer)
- Einstein Program
Correct answer: Continuous Diagnostics and Mitigation (CDM)
The CDM program, managed by CISA, provides tools and dashboards to automate continuous monitoring across federal civilian agencies.
Question 79: During the accreditation process, the CAP is tasked with coordinating between the accrediting body and internal departments. What is the CAP’s key responsibility in this role?
- Limit communication to only critical updates from the accrediting body
- Ensure that the accrediting body’s requirements are clearly communicated to all departments (Correct answer)
- Delegate all communication tasks to department leads
- Act as a mediator to resolve disputes between the accrediting body and staff
Correct answer: Ensure that the accrediting body’s requirements are clearly communicated to all departments
The CAP's key responsibility in coordinating between the accrediting body and internal departments is to act as a central conduit for information. This involves ensuring that all requirements, updates, and expectations from the accrediting body are clearly and accurately communicated to every relevant department. Effective communication prevents misunderstandings, promotes consistent compliance, and facilitates a smooth accreditation process.
Question 80: What document serves as the primary contract between the system owner and the Authorizing Official during RMF?
- System Security Plan (Correct answer)
- Plan of Action and Milestones
- Authorization Decision Document
- Security Assessment Report
Correct answer: System Security Plan
The System Security Plan (SSP) describes how security requirements are met and forms the basis for the authorization decision.
Question 81: Which artifact documents interconnections between an information system and external systems?
- Authorization Decision Document
- System Security Plan body only
- Interconnection Security Agreement (ISA) / Memorandum of Understanding (MOU) (Correct answer)
- POA&M
Correct answer: Interconnection Security Agreement (ISA) / Memorandum of Understanding (MOU)
ISAs (often paired with MOUs) formally document the terms, security requirements, and authorizations for system interconnections.
Question 82: What document formally records the selected security controls for an information system during the RMF?
- Authorization to Operate (ATO)
- Security Assessment Report (SAR)
- System Security Plan (SSP) (Correct answer)
- Plan of Action and Milestones (POA&M)
Correct answer: System Security Plan (SSP)
The System Security Plan documents the security controls selected and implemented for the system.
Question 83: A Privacy Impact Assessment (PIA) is required under which federal law before collecting or using personally identifiable information?
- E-Government Act of 2002 (Correct answer)
- FISMA
- Privacy Act of 1974
- HIPAA
Correct answer: E-Government Act of 2002
The E-Government Act of 2002 requires federal agencies to conduct PIAs before developing or procuring IT systems that collect PII.
Question 84: How frequently must federal agencies review and update their System Security Plans per NIST guidance?
- Quarterly regardless of system changes
- Every five years during reauthorization
- Only when a security incident occurs
- At least annually or whenever significant changes occur (Correct answer)
Correct answer: At least annually or whenever significant changes occur
NIST recommends reviewing and updating the SSP at least annually and whenever significant changes to the system occur.
Question 85: Which three security objectives are used in FIPS 199 to categorize information and systems?
- Identification, Protection, Recovery
- Authentication, Authorization, Accounting
- Prevention, Detection, Response
- Confidentiality, Integrity, Availability (Correct answer)
Correct answer: Confidentiality, Integrity, Availability
FIPS 199 uses potential impacts to confidentiality, integrity, and availability (the CIA triad) to assign security categories.
Question 86: The Federal Risk and Authorization Management Program (FedRAMP) standardizes security authorizations for which type of systems?
- Classified national security systems
- Cloud computing products and services used by federal agencies (Correct answer)
- Mobile device management platforms
- On-premises legacy systems
Correct answer: Cloud computing products and services used by federal agencies
FedRAMP provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud services used by the federal government.
Question 87: What does it mean to 'adjust' a recommended information type impact level from NIST SP 800-60?
- To reduce controls to save cost
- To raise or lower the recommended level based on the specific operational context and risk environment (Correct answer)
- To override FIPS 199 completely with agency-defined categories
- To apply a classification label above Secret
Correct answer: To raise or lower the recommended level based on the specific operational context and risk environment
Agencies may adjust recommended impact levels up or down when local factors, mission context, or threat environment justify a different level than the default.
Question 88: Which security control family in NIST SP 800-53 addresses access control?
- CM
- CA
- AC (Correct answer)
- AU
Correct answer: AC
The AC (Access Control) family contains controls governing who can access systems, data, and functions.
Question 89: What should happen when continuous monitoring detects a significant security change to a system?
- The POA&M is automatically closed
- The ATO period resets to three years automatically
- The ISSO must notify the AO and update the SSP and risk assessment to reflect the new security posture (Correct answer)
- The system must be immediately shut down
Correct answer: The ISSO must notify the AO and update the SSP and risk assessment to reflect the new security posture
Significant changes detected during monitoring must be reported to the AO, and associated documentation must be updated to reflect the current risk posture.
Question 90: Which body conducts independent audits of federal agency information security programs and reports findings to Congress?
- GAO (Government Accountability Office) (Correct answer)
- OMB
- CISA
- NSA
Correct answer: GAO (Government Accountability Office)
The GAO conducts independent audits and evaluations of federal programs, including information security, and reports to Congress.
Question 91: A continuous monitoring strategy document should define what key elements?
- Employee salary ranges
- Vendor procurement timelines
- Annual training schedules only
- Metrics, frequency of monitoring, assessment procedures, and reporting requirements (Correct answer)
Correct answer: Metrics, frequency of monitoring, assessment procedures, and reporting requirements
The ISCM strategy defines what to monitor, how often, how to collect and analyze data, and how to report findings to decision makers.
Question 92: Which privacy-related requirement was integrated into NIST SP 800-53 Revision 5?
- Privacy controls were removed and placed in a separate publication
- Privacy controls were integrated alongside security controls in the same catalog (Correct answer)
- Privacy controls replaced audit controls in Rev. 5
- Privacy only applies to systems handling classified data
Correct answer: Privacy controls were integrated alongside security controls in the same catalog
NIST SP 800-53 Rev. 5 fully integrated privacy controls into the same catalog as security controls, reflecting a unified approach.
Question 93: NIST SP 800-137 provides guidance on which topic?
- Penetration testing methodology
- Incident response
- Security categorization
- Information Security Continuous Monitoring (ISCM) for federal systems (Correct answer)
Correct answer: Information Security Continuous Monitoring (ISCM) for federal systems
NIST SP 800-137 provides guidance for developing an ISCM strategy and program for federal information systems and organizations.
Question 94: Which NIST publication provides guidance on security and privacy controls for federal information systems?
- NIST SP 800-60
- NIST SP 800-30
- NIST SP 800-37
- NIST SP 800-53 (Correct answer)
Correct answer: NIST SP 800-53
NIST SP 800-53 provides the catalog of security and privacy controls used during the RMF Select step.
Question 95: What is a compensating security control?
- A control mandated by FISMA
- An alternative control providing equivalent protection when the primary control cannot be implemented (Correct answer)
- A control that replaces all other controls
- A control applied only to high-impact systems
Correct answer: An alternative control providing equivalent protection when the primary control cannot be implemented
A compensating control provides an equivalent level of protection when the baseline control is not feasible to implement as specified.
Question 96: What is an 'ongoing authorization' in the context of continuous monitoring?
- An ATO that never expires and requires no review
- An automated system that grants ATOs without human review
- A contract with an MSSP for 24/7 monitoring
- A risk management approach where the AO makes ongoing authorization decisions based on real-time monitoring data rather than periodic reassessments (Correct answer)
Correct answer: A risk management approach where the AO makes ongoing authorization decisions based on real-time monitoring data rather than periodic reassessments
Ongoing authorization shifts from periodic reauthorization to a continuous risk-informed process where the AO monitors security posture in real time.
Question 97: What is the role of automated scanning tools in a continuous monitoring program?
- To replace the need for human security analysts
- To efficiently collect security state data such as patch levels, configuration compliance, and vulnerabilities at scale (Correct answer)
- To conduct penetration testing on a daily basis
- To generate ATOs automatically based on scan results
Correct answer: To efficiently collect security state data such as patch levels, configuration compliance, and vulnerabilities at scale
Automated tools enable continuous data collection across large environments, making it feasible to assess many controls frequently without manual effort.
Question 98: To promote continuous improvement, the CAP decides to implement a quality improvement project based on audit findings. What is the CAP’s first step in initiating this project?
- Schedule a follow-up audit to ensure the project’s effectiveness
- Select and define a specific area or process that requires improvement (Correct answer)
- Gather feedback from the accrediting body on potential improvement areas
- Delegate the project to department heads without further involvement
Correct answer: Select and define a specific area or process that requires improvement
The first step in initiating any quality improvement project, especially one based on audit findings, is to clearly define its scope. This involves selecting a specific area or process that needs improvement and precisely articulating what the project aims to achieve. A well-defined problem statement ensures that efforts are focused and measurable, setting a solid foundation for the entire improvement initiative.
Question 99: How should organizations manage the risk of 'end-of-life' (EOL) software and hardware components in the supply chain?
- By tracking EOL dates, planning replacements before support ends, and implementing compensating controls if immediate replacement is not possible (Correct answer)
- By requiring vendors to provide indefinite support via contractual clauses
- By continuing to use EOL components as long as no active exploits are known
- By isolating EOL systems from all networks permanently
Correct answer: By tracking EOL dates, planning replacements before support ends, and implementing compensating controls if immediate replacement is not possible
EOL components no longer receive security patches, so proactive replacement planning and compensating controls are essential to manage the associated risk.
Question 100: What is the purpose of including supply chain security requirements in contracts with third-party service providers?
- To transfer all liability for security incidents to the vendor
- To eliminate the need for the agency to conduct its own risk assessments
- To legally obligate vendors to implement specified security controls and flow down those requirements to their subcontractors (Correct answer)
- To ensure vendors provide the lowest possible price
Correct answer: To legally obligate vendors to implement specified security controls and flow down those requirements to their subcontractors
Contractual security requirements ensure vendors are legally bound to maintain security standards and pass those requirements through their own supply chains.
Question 101: What must the POA&M include for each identified security weakness?
- The name of the penetration tester who found it
- Description of the weakness, responsible party, scheduled completion date, and resources needed (Correct answer)
- Only the vulnerability CVE number
- A sign-off from the system owner
Correct answer: Description of the weakness, responsible party, scheduled completion date, and resources needed
A complete POA&M entry includes what the weakness is, who owns remediation, when it will be fixed, and what resources are required.
Question 102: What is an 'inherited control' in the context of continuous monitoring for a leveraged system?
- A security control implemented by a common control provider whose monitoring responsibilities are inherited rather than duplicated by the leveraging system (Correct answer)
- A control that is monitored by an external auditor
- A control that no longer needs monitoring because it is fully automated
- A control that has been assessed and passed during the last ATO cycle
Correct answer: A security control implemented by a common control provider whose monitoring responsibilities are inherited rather than duplicated by the leveraging system
When a system inherits a common control, the monitoring responsibility for that control lies with the common control provider, not the system owner.
Question 103: Under FISMA, which office provides policy guidance and oversight for federal information security programs?
- NSA
- OMB (Correct answer)
- CISA
- GAO
Correct answer: OMB
The Office of Management and Budget (OMB) issues policy guidance and oversees federal agency compliance with FISMA requirements.
Question 104: What NIST publication provides guidance on organizational risk management as the overarching context for the RMF?
- NIST SP 800-30
- NIST SP 800-53
- NIST SP 800-39 (Correct answer)
- NIST SP 800-37
Correct answer: NIST SP 800-39
NIST SP 800-39 addresses managing information security risk at the organization, mission/business, and information system tiers.
Question 105: Which federal policy requires agencies to report major cybersecurity incidents to CISA and Congress within a specific timeframe?
- FedRAMP authorization rules
- NIST SP 800-61 only
- FISMA 2014 and OMB reporting requirements (Correct answer)
- FIPS 200 requirements
Correct answer: FISMA 2014 and OMB reporting requirements
FISMA 2014 and related OMB memoranda require agencies to report major incidents to CISA and notify Congress within prescribed timeframes.
Question 106: The National Cybersecurity Strategy released in 2023 by the Biden administration emphasized shifting cybersecurity responsibility to whom?
- Technology providers and organizations best positioned to reduce risk (Correct answer)
- Individual end users
- State and local governments
- Small businesses only
Correct answer: Technology providers and organizations best positioned to reduce risk
The 2023 National Cybersecurity Strategy called for shifting the cybersecurity burden from individuals to technology vendors and large organizations.
Question 107: The authorization decision letter issued by the AO must include which key element?
- The names of all system users
- The system's IP addresses
- A full list of all security controls
- The authorization termination date or conditions (Correct answer)
Correct answer: The authorization termination date or conditions
The authorization decision letter must specify the authorization period or the conditions under which the authorization will be terminated.
Question 108: What information is typically included in the authorization boundary diagram?
- Only external connections
- Vendor contracts and SLAs
- Employee organizational chart
- All hardware, software, and data flows within the system boundary (Correct answer)
Correct answer: All hardware, software, and data flows within the system boundary
The authorization boundary diagram visually represents all system components, interfaces, data flows, and interconnections within scope.
Question 109: The RMF Monitor step is primarily intended to provide what type of assurance?
- Control selection validation
- Ongoing situational awareness (Correct answer)
- Initial risk acceptance
- One-time certification
Correct answer: Ongoing situational awareness
The Monitor step ensures continuous situational awareness of the security posture through ongoing assessments and reporting.
Question 110: Which step of the RMF involves selecting the appropriate security controls for an information system?
- Categorize
- Implement
- Select (Correct answer)
- Assess
Correct answer: Select
The Select step of the RMF involves choosing baseline security controls tailored to the system's categorization.
Question 111: What information must a System Security Plan include about the system boundary?
- A list of all user account names
- A description of the authorization boundary defining which components are within scope (Correct answer)
- Only the IP addresses of networked devices
- The physical location of all servers
Correct answer: A description of the authorization boundary defining which components are within scope
The SSP must clearly define the authorization boundary to establish what hardware, software, and services are in scope for the assessment.
Question 112: Which concept BEST describes implementing multiple overlapping layers of security controls to protect information system resources?
- Least privilege
- Separation of duties
- Need to know
- Defense in depth (Correct answer)
Correct answer: Defense in depth
Defense in depth involves layering multiple security controls so that if one control fails, additional controls remain in place to protect the system.
Question 113: CISA plays which primary role in federal cybersecurity compliance?
- Issues FIPS publications
- Audits agency compliance with FISMA
- Approves agency ATOs
- Coordinates federal civilian cybersecurity defense and leads incident response (Correct answer)
Correct answer: Coordinates federal civilian cybersecurity defense and leads incident response
CISA (Cybersecurity and Infrastructure Security Agency) leads the national effort to defend civilian federal networks and coordinate incident response.
Question 114: When a security control is determined to be 'not applicable' to an information system, what must the system owner do?
- Escalate the decision directly to the Authorizing Official for formal approval
- Automatically replace it with a compensating control
- Document the rationale for non-applicability in the SSP (Correct answer)
- Remove it from the SSP entirely without any notation
Correct answer: Document the rationale for non-applicability in the SSP
Non-applicability determinations must be documented with a clear rationale in the SSP so assessors and the AO can evaluate whether the decision is justified.
Question 115: What is the primary purpose of a security impact analysis?
- To categorize a new system
- To document the results of a penetration test
- To evaluate the effect of proposed changes on a system's security posture (Correct answer)
- To assign an impact level to data
Correct answer: To evaluate the effect of proposed changes on a system's security posture
A security impact analysis assesses how a proposed change could affect the confidentiality, integrity, or availability of an information system.
Question 116: A healthcare system processes patient records and payment data. Which security objective is most likely to have the highest impact level?
- Integrity
- Confidentiality (Correct answer)
- All three are equal
- Availability
Correct answer: Confidentiality
Patient and payment records are highly sensitive, making unauthorized disclosure the greatest concern and driving a High Confidentiality impact.
Question 117: Which NIST publication provides guidance specifically on supply chain risk management for federal systems?
- NIST SP 800-161 (Correct answer)
- NIST SP 800-53
- NIST SP 800-37
- NIST SP 800-171
Correct answer: NIST SP 800-161
NIST SP 800-161 provides guidance on identifying and mitigating supply chain risks for federal information systems and organizations.
Question 118: What does NIST SP 800-60 help federal agencies determine?
- How to encrypt data at rest
- Which information types and systems belong in which FIPS 199 impact categories (Correct answer)
- How to configure firewalls
- How to respond to security incidents
Correct answer: Which information types and systems belong in which FIPS 199 impact categories
NIST SP 800-60 maps information types to security impact levels, guiding agencies in applying FIPS 199 categorization consistently.
Question 119: What is a 'trusted supplier' program in the context of federal ICT procurement?
- A program that gives preferred pricing to domestic IT vendors
- A list of vendors banned from federal procurement
- A vetting process to identify and use vendors who meet security standards and have demonstrated trustworthiness (Correct answer)
- A certification program for cloud service providers only
Correct answer: A vetting process to identify and use vendors who meet security standards and have demonstrated trustworthiness
Trusted supplier programs establish criteria for vetting vendors' security practices, integrity, and supply chain controls before purchasing their products.
Question 120: What is Information and Communications Technology Supply Chain Risk Management (ICT SCRM)?
- Auditing the source code of all purchased applications
- The process of identifying, assessing, and mitigating risks associated with the global supply chain for IT products and services (Correct answer)
- Verifying that all hardware is manufactured domestically
- Managing vendor contracts for software licenses only
Correct answer: The process of identifying, assessing, and mitigating risks associated with the global supply chain for IT products and services
ICT SCRM addresses risks arising from the complex global supply chain, including malicious tampering, counterfeits, and vendor vulnerabilities.
Question 121: When a required security control cannot be implemented as specified in the baseline, what alternative mechanism may be used with appropriate documentation?
- Compensating control (Correct answer)
- Residual risk acceptance
- Security overlay
- Control inheritance
Correct answer: Compensating control
Compensating controls are alternative management, operational, or technical safeguards employed when standard control implementation is not feasible.
Question 122: What distinguishes a system-specific control from a hybrid control in NIST SP 800-53?
- System-specific controls are mandatory; hybrid controls are optional
- System-specific controls are implemented only for the local system; hybrid controls are shared and locally customized (Correct answer)
- Hybrid controls require AO approval; system-specific controls do not
- System-specific controls apply only to cloud systems
Correct answer: System-specific controls are implemented only for the local system; hybrid controls are shared and locally customized
Hybrid controls have portions implemented by a common control provider and portions implemented locally by the system owner.
Question 123: Which section of the SSP typically describes how the system processes, stores, or transmits federal information?
- Authorization Decision
- System Description / Operational Environment (Correct answer)
- Control Implementation Summary
- POA&M Appendix
Correct answer: System Description / Operational Environment
The system description section explains the system's purpose, data flows, and operational context including what information it handles.
Question 124: During an internal audit, the CAP identifies a department where documentation practices are inconsistent with accreditation requirements. What should be the CAP’s next step?
- Ignore it, as it may not affect the overall accreditation status
- Rewrite the documentation to meet standards without informing the department
- Report the issue directly to the external auditors
- Collaborate with the department to implement corrective measures (Correct answer)
Correct answer: Collaborate with the department to implement corrective measures
Upon identifying inconsistent documentation practices during an internal audit, the CAP's role is to facilitate improvement, not just report issues. Collaborating with the affected department empowers them to understand the non-compliance and actively participate in developing and implementing corrective measures. This approach fosters ownership, ensures sustainable change, and aligns with the CAP's responsibility for continuous quality improvement and audit readiness.
Question 125: What does a High categorization for Availability mean for a federal system?
- The system is accessible to all federal employees
- The system is classified at the Top Secret level
- The system requires 99.999% uptime by law
- Loss of availability would have a severe or catastrophic adverse effect on operations, assets, or individuals (Correct answer)
Correct answer: Loss of availability would have a severe or catastrophic adverse effect on operations, assets, or individuals
A High Availability impact means system downtime could cause severe harm to the organization's mission, finances, or national security.
Question 126: Under an ongoing authorization approach, how often must a full re-authorization be conducted?
- Every six months
- When risk exceeds defined thresholds rather than on a fixed schedule (Correct answer)
- Every five years regardless of risk
- Every year
Correct answer: When risk exceeds defined thresholds rather than on a fixed schedule
Ongoing authorization uses continuous monitoring to maintain a current security posture, triggering re-authorization based on risk events rather than time.
ISC2 Certified Authorization Professional (CAP)
The CAP (now rebranded as CGRC) certification validates expertise in authorizing and maintaining information systems using the Risk Management Framework (RMF), covering governance, risk, and compliance for cybersecurity professionals.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds