Continuous Monitoring and System Lifecycle Flashcards
6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Continuous Monitoring and System Lifecycle flashcards as text
The System Development Life Cycle (SDLC) is important in security because integrating security early follows which principle?
Answer: Shift left / security by design
Integrating security requirements and controls from the earliest SDLC phases (shifting left) is more effective and less costly than retrofitting security later.
During which SDLC phase is the System Security Plan typically first developed?
Answer: Initiation
The SSP is initiated during the Initiation phase when system boundaries, requirements, and preliminary security controls are first identified.
What security activity must be performed before a system is decommissioned during the SDLC Disposal phase?
Answer: Media sanitization and data destruction per NIST SP 800-88
NIST SP 800-88 provides guidelines for media sanitization to ensure sensitive information cannot be recovered after system disposal.
Which continuous monitoring activity involves testing a subset of controls each year rather than all controls simultaneously?
Answer: Rolling assessments
Rolling assessments divide the full control set into groups assessed on a rotating schedule, providing continuous coverage without full annual assessments.
What is the purpose of a hardware and software inventory in continuous monitoring?
Answer: To maintain an accurate record of system components to detect unauthorized assets
Maintaining an accurate inventory is fundamental to continuous monitoring, enabling detection of unauthorized or unknown assets that pose security risks.
Vulnerability scanning in a continuous monitoring program is primarily used to identify what?
Answer: Known software weaknesses, missing patches, and configuration errors
Automated vulnerability scans identify unpatched software, misconfigurations, and known exploitable weaknesses across the system.