โ† All CAP Flashcard Decks

Continuous Monitoring and System Lifecycle Flashcards

6 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Continuous Monitoring and System Lifecycle flashcards as text
  1. What is the purpose of a security awareness and training program in the system lifecycle?

    Answer: To ensure users understand their security responsibilities and can recognize threats

    Security awareness and training ensures all personnel understand threats, policies, and their individual responsibilities for protecting information.

  2. What does 'configuration drift' refer to in continuous monitoring?

    Answer: Unauthorized or unintentional changes to system configurations over time that deviate from the approved baseline

    Configuration drift occurs when system settings gradually deviate from the approved secure baseline due to unauthorized changes or system updates.

  3. A continuous monitoring strategy document should define what key elements?

    Answer: Metrics, frequency of monitoring, assessment procedures, and reporting requirements

    The ISCM strategy defines what to monitor, how often, how to collect and analyze data, and how to report findings to decision makers.

  4. In the context of continuous monitoring, what does the term 'security posture' describe?

    Answer: The overall cybersecurity strength and risk level of an organization or system at a given point in time

    Security posture is a holistic assessment of the organization's current state of security, including vulnerabilities, threats, and control effectiveness.

  5. Which NIST document provides guidance specifically on incident handling and response for computer security incidents?

    Answer: NIST SP 800-61

    NIST SP 800-61, the Computer Security Incident Handling Guide, provides guidance on detecting, analyzing, containing, and recovering from incidents.

  6. When a significant system change resets an ongoing authorization, what document must be updated first?

    Answer: The SSP to reflect the new system configuration and updated controls

    The SSP must be updated to reflect the significant change before a new security impact analysis or re-authorization can proceed.