← All CAP Flashcard Decks

Mixed Deck — All CAP Topics Flashcards

100 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All CAP Topics flashcards as text
  1. During the accreditation process, the CAP is tasked with coordinating between the accrediting body and internal departments. What is the CAP’s key responsibility in this role?

    Answer: Ensure that the accrediting body’s requirements are clearly communicated to all departments

    The CAP's key responsibility in coordinating between the accrediting body and internal departments is to act as a central conduit for information. This involves ensuring that all requirements, updates, and expectations from the accrediting body are clearly and accurately communicated to every relevant department. Effective communication prevents misunderstandings, promotes consistent compliance, and facilitates a smooth accreditation process.

  2. The System Development Life Cycle (SDLC) is important in security because integrating security early follows which principle?

    Answer: Shift left / security by design

    Integrating security requirements and controls from the earliest SDLC phases (shifting left) is more effective and less costly than retrofitting security later.

  3. Which document should the system owner consult when determining information types for categorization?

    Answer: NIST SP 800-60 Volume II

    NIST SP 800-60 Volume II contains the tables that map federal information types to recommended security impact levels.

  4. To ensure staff compliance with accreditation standards, the CAP decides to implement a training program. How should the CAP communicate the purpose and structure of the training to staff?

    Answer: Conduct a kickoff session to explain the program and answer staff questions

    To effectively communicate the purpose and structure of a new training program to staff, a kickoff session is highly beneficial. This interactive approach allows the CAP to directly explain the program's objectives, its relevance to accreditation standards, and logistical details. It also provides a valuable opportunity for staff to ask questions and receive immediate clarification, fostering engagement and ensuring a clear understanding of the training's importance.

  5. What is the significance of documenting implementation status and evidence in the System Security Plan?

    Answer: It provides evidence that assessors and the AO use to evaluate the system's security posture

    Documented implementation evidence gives the security control assessor and Authorizing Official the basis they need to evaluate whether controls are effective and make sound authorization decisions.

  6. What does NIST SP 800-53A provide in direct support of the security control implementation and assessment process?

    Answer: Assessment procedures for determining whether implemented controls are effective

    NIST SP 800-53A provides the assessment procedures used to evaluate whether security controls have been correctly implemented and are operating effectively.

  7. What is the purpose of FIPS 199 in the RMF process?

    Answer: Establishing security categorization standards

    FIPS 199 establishes standards for categorizing federal information and information systems based on potential impact (low, moderate, high).

  8. What information is typically included in the authorization boundary diagram?

    Answer: All hardware, software, and data flows within the system boundary

    The authorization boundary diagram visually represents all system components, interfaces, data flows, and interconnections within scope.

  9. During an internal audit, the CAP identifies a department where documentation practices are inconsistent with accreditation requirements. What should be the CAP’s next step?

    Answer: Collaborate with the department to implement corrective measures

    Upon identifying inconsistent documentation practices during an internal audit, the CAP's role is to facilitate improvement, not just report issues. Collaborating with the affected department empowers them to understand the non-compliance and actively participate in developing and implementing corrective measures. This approach fosters ownership, ensures sustainable change, and aligns with the CAP's responsibility for continuous quality improvement and audit readiness.

  10. Which section of the SSP typically describes how the system processes, stores, or transmits federal information?

    Answer: System Description / Operational Environment

    The system description section explains the system's purpose, data flows, and operational context including what information it handles.

  11. What must the POA&M include for each identified security weakness?

    Answer: Description of the weakness, responsible party, scheduled completion date, and resources needed

    A complete POA&M entry includes what the weakness is, who owns remediation, when it will be fixed, and what resources are required.

  12. What role does the Information System Security Engineer (ISSE) play in security control implementation?

    Answer: Providing technical expertise to ensure controls are properly engineered into the system

    The ISSE applies security engineering expertise to ensure that security controls and requirements are correctly designed and integrated into the system architecture and implementation.

  13. CISA plays which primary role in federal cybersecurity compliance?

    Answer: Coordinates federal civilian cybersecurity defense and leads incident response

    CISA (Cybersecurity and Infrastructure Security Agency) leads the national effort to defend civilian federal networks and coordinate incident response.

  14. Which RMF step involves choosing security controls from NIST SP 800-53?

    Answer: Select

    The Select step involves choosing appropriate security controls tailored to the system's risk profile.

  15. What is typically triggered when a significant change occurs to an authorized information system?

    Answer: A security impact analysis and possible re-authorization are initiated

    Significant changes require a security impact analysis, and if the risk posture changes materially, re-authorization may be required.

  16. To promote continuous improvement, the CAP decides to implement a quality improvement project based on audit findings. What is the CAP’s first step in initiating this project?

    Answer: Select and define a specific area or process that requires improvement

    The first step in initiating any quality improvement project, especially one based on audit findings, is to clearly define its scope. This involves selecting a specific area or process that needs improvement and precisely articulating what the project aims to achieve. A well-defined problem statement ensures that efforts are focused and measurable, setting a solid foundation for the entire improvement initiative.

  17. The authorization decision letter issued by the AO must include which key element?

    Answer: The authorization termination date or conditions

    The authorization decision letter must specify the authorization period or the conditions under which the authorization will be terminated.

  18. Which federal law requires agencies to conduct Privacy Impact Assessments for new information technology systems?

    Answer: E-Government Act of 2002

    Section 208 of the E-Government Act of 2002 mandates PIAs before agencies develop or procure new IT systems that collect PII.

  19. Which FIPS publication establishes the standards for categorizing federal information and information systems?

    Answer: FIPS 199

    FIPS 199 defines the standards for security categorization of federal information and information systems.

  20. Which metric is commonly used to measure the effectiveness of a vulnerability management continuous monitoring process?

    Answer: Mean Time to Remediate (MTTR) critical vulnerabilities

    MTTR measures how quickly identified vulnerabilities are patched, directly reflecting the effectiveness of the vulnerability management process.