Certified Authorization Professional (CAP) — Questions and Answers
Question 1: A security control is found to be 'not applicable' during an assessment. What is the CORRECT action?
- Document the rationale for non-applicability and seek AO approval if required (Correct answer)
- Automatically mark the control as failed
- Remove the control from the SSP entirely
- Treat it as a high-risk finding in the POA&M
Correct answer: Document the rationale for non-applicability and seek AO approval if required
Controls that are not applicable must have documented rationale, and the AO may need to formally accept the non-applicability determination.
Question 2: Which NIST SP 800-53 control family is most directly associated with managing access to information and systems?
- Identification and Authentication (IA)
- Access Control (AC) (Correct answer)
- System and Communications Protection (SC)
- Audit and Accountability (AU)
Correct answer: Access Control (AC)
The Access Control (AC) family in NIST SP 800-53 contains controls directly governing who can access information systems and under what conditions.
Question 3: What is the first step in the risk management process for Certified Authorization Professional?
- Transferring risk to insurance
- Identifying potential risks and hazards (Correct answer)
- Implementing controls immediately
- Writing a risk report
Correct answer: Identifying potential risks and hazards
Risk identification is the first step, as you must know what risks exist before you can assess and manage them.
Question 4: Which key component is essential in a security risk management plan?
- Removing all access controls
- Ignoring new threats
- Continuous monitoring of security controls (Correct answer)
- Relying only on annual assessments
Correct answer: Continuous monitoring of security controls
Continuous monitoring is an essential component of a robust security risk management plan because threats and vulnerabilities constantly evolve. It ensures that security controls remain effective over time and that any new risks or changes in the threat landscape are promptly detected and addressed. This ongoing vigilance is critical for maintaining an acceptable security posture.
Question 5: Which document formally describes the security requirements and controls for a specific information system?
- Security Assessment Report (SAR)
- System Security Plan (SSP) (Correct answer)
- Plan of Action and Milestones (POA&M)
- Authorization to Operate (ATO)
Correct answer: System Security Plan (SSP)
The System Security Plan (SSP) formally describes the system boundary, environment, security requirements, and implemented controls.
Question 6: What term describes the minimum set of security controls required for a given impact level (Low, Moderate, High) under NIST SP 800-53?
- Security Control Baseline (Correct answer)
- Compensating Control
- Control Tailoring Guidance
- Security Overlay
Correct answer: Security Control Baseline
A security control baseline is the predefined starting set of controls recommended by NIST for Low, Moderate, or High impact systems before tailoring.
Question 7: What is the purpose of an access control list (ACL)?
- To provide anonymous access
- To allow unrestricted access to all resources
- To disable user authentication
- To define and enforce access permissions (Correct answer)
Correct answer: To define and enforce access permissions
An Access Control List (ACL) is a list of permissions attached to an object, such as a file or directory, that specifies which users or system processes are granted access and what operations they are allowed to perform. ACLs are crucial for defining and enforcing granular access control, ensuring that only authorized entities can interact with specific resources. They act as a gatekeeper, dictating who can read, write, or execute data.
Question 8: An agency is moving a HIGH impact system to a FedRAMP-authorized cloud. Which statement is correct regarding inherited controls?
- The agency must re-assess all inherited controls independently every 90 days
- The agency inherits controls provided by the CSP but retains responsibility for customer-responsible controls (Correct answer)
- FedRAMP authorization eliminates the need for an agency ATO
- All security controls transfer fully to the cloud provider upon migration
Correct answer: The agency inherits controls provided by the CSP but retains responsibility for customer-responsible controls
FedRAMP uses a shared responsibility model where CSP-provided controls are inherited by the agency, but customer-responsible controls remain the agency's obligation.
Question 9: What is the primary security concern when a penetration tester finds that a federal system allows users to upload executable files without restriction?
- Unrestricted File Upload enabling remote code execution (Correct answer)
- Increased bandwidth utilization
- Excessive disk space consumption
- Unauthorized data exfiltration only
Correct answer: Unrestricted File Upload enabling remote code execution
Unrestricted file upload vulnerabilities allow attackers to upload and execute malicious code (webshells) on the server, achieving full remote code execution.
Question 10: Which NIST publication provides guidance specifically on network security for federal information systems?
- NIST SP 800-92
- NIST SP 800-61
- NIST SP 800-34
- NIST SP 800-41 (Correct answer)
Correct answer: NIST SP 800-41
NIST SP 800-41 provides guidelines on firewalls and firewall policy, covering network security for federal information systems.
Question 11: How does collaboration enhance Incident Response & Recovery in Certified Authorization Professional?
- It reduces individual accountability
- It creates unnecessary meetings
- It brings diverse perspectives and improves outcomes (Correct answer)
- It slows down the process
Correct answer: It brings diverse perspectives and improves outcomes
Collaboration brings together different viewpoints and expertise, leading to better decision-making and outcomes.
Question 12: Which of the following BEST describes the concept of 'security control inheritance' in the RMF?
- An AO inherits authorization responsibility from a predecessor AO
- A system copies security controls from a previously authorized system of the same type
- Security controls are applied automatically via configuration management tools
- A system receives security protection from controls implemented by an external provider or shared service (Correct answer)
Correct answer: A system receives security protection from controls implemented by an external provider or shared service
Control inheritance occurs when a system leverages controls implemented and managed by another organizational entity, such as a common control provider or cloud platform.
Question 13: An assessor discovers a control is 'not applicable' for a cloud-hosted system. What is the appropriate next step?
- Apply the control anyway to avoid compliance issues
- Document the rationale for non-applicability and obtain approval through the tailoring process (Correct answer)
- Automatically rate the control as 'not satisfied' in the SAR
- Remove the control from the SSP without documentation
Correct answer: Document the rationale for non-applicability and obtain approval through the tailoring process
Tailoring allows removal of controls that are not applicable, but the rationale must be documented in the SSP and approved by the AO.
Question 14: What does the 'tailoring' process in RMF documentation involve?
- Mapping controls to vendor-specific product capabilities
- Removing all controls that are not technically feasible
- Adjusting baseline security controls to match system-specific conditions, risk tolerance, and mission needs (Correct answer)
- Writing custom code to implement security controls
Correct answer: Adjusting baseline security controls to match system-specific conditions, risk tolerance, and mission needs
Tailoring is the process of customizing a security control baseline by adding, removing, or modifying controls to appropriately address the specific risk environment of the system.
Question 15: Why is assessor independence important in the security control assessment process?
- It ensures the assessor has no financial interest in the organization being assessed.
- It is required so that assessors can hold a Top Secret clearance.
- It ensures the assessment is completed faster by using a dedicated team.
- It prevents conflicts of interest where the assessor might overlook deficiencies in controls they helped implement. (Correct answer)
Correct answer: It prevents conflicts of interest where the assessor might overlook deficiencies in controls they helped implement.
Assessor independence (as described in NIST SP 800-37 and SP 800-53A) is critical because individuals who designed or implemented controls have an inherent conflict of interest when assessing those same controls. Independent assessment provides objective, unbiased results for the AO's decision.
Question 16: What term describes the process of tailoring a security control baseline by adding controls beyond the baseline to address specific threats or operational requirements?
- Scoping (supplementation) (Correct answer)
- Baseline tailoring down
- Common control allocation
- Control inheritance
Correct answer: Scoping (supplementation)
Supplementation (a form of scoping) adds controls above the baseline when the selected baseline is insufficient for specific threat environments or requirements.
Question 17: Which formal verification approach mathematically proves that a security policy is correctly enforced by a system design?
- Formal methods (Correct answer)
- Penetration testing
- Vulnerability scanning
- Code review
Correct answer: Formal methods
Formal methods use mathematical proofs to verify that a system design correctly implements its security policy.
Question 18: A CAP professional is assessing a system where user A can grant other users permissions that exceed user A's own permissions. Which access control weakness does this represent?
- Privilege escalation via DAC misconfiguration (Correct answer)
- Covert channel exploitation
- Insecure direct object reference
- Confused deputy problem
Correct answer: Privilege escalation via DAC misconfiguration
In DAC environments, improper implementation can allow owners to delegate permissions they do not actually possess, enabling privilege escalation.
Question 19: Under FISMA, who is ultimately responsible for accepting the residual risk of operating a federal information system?
- Chief Information Officer (CIO)
- Authorizing Official (AO) (Correct answer)
- Security Control Assessor (SCA)
- Information System Owner (ISO)
Correct answer: Authorizing Official (AO)
The Authorizing Official (AO) bears ultimate responsibility for accepting residual risk by signing the Authorization to Operate (ATO).
Question 20: Which tailoring action allows an organization to remove a security control from the baseline because it is not applicable to the system's operating environment?
- Compensating control substitution
- Scoping (Correct answer)
- Supplementation
- Overlay application
Correct answer: Scoping
Scoping involves applying specific guidance to adjust the baseline — including eliminating controls that are not applicable (e.g., removing mobile device controls from a system that has no mobile interfaces). Supplementation adds controls; overlays are community-wide tailoring guidance; compensating controls substitute when a baseline control cannot be implemented.
Question 21: In the context of CAP, what does 'trustworthiness' of an information system primarily depend on?
- Security functionality and assurance (Correct answer)
- Physical location of servers
- Network bandwidth and latency
- Number of authorized users
Correct answer: Security functionality and assurance
Trustworthiness combines security functionality (what the system does) with assurance (confidence that it does it correctly).
Question 22: Which security architecture principle ensures that a compromised component cannot affect the security of the entire system?
- Defense in depth
- Compartmentalization (Correct answer)
- Least privilege
- Fail-safe defaults
Correct answer: Compartmentalization
Compartmentalization isolates system components so a breach in one area does not propagate to others.
Question 23: In a federal environment, who has the authority to formally accept residual risk and grant an Authorization to Operate (ATO)?
- Authorizing Official (AO) (Correct answer)
- Information System Security Officer (ISSO)
- Security Control Assessor (SCA)
- System Owner (SO)
Correct answer: Authorizing Official (AO)
The Authorizing Official (AO) is the senior official with authority to formally accept residual risk and issue an Authorization to Operate.
Question 24: An organization uses a cloud service provider that holds a FedRAMP authorization. How does this affect the system owner's SSP?
- The system owner must duplicate all FedRAMP controls in their own SSP
- FedRAMP authorization eliminates the need for a system-level SSP
- The system owner must obtain a separate ATO from FedRAMP directly
- The system owner can inherit FedRAMP-authorized controls and document them as inherited in their SSP (Correct answer)
Correct answer: The system owner can inherit FedRAMP-authorized controls and document them as inherited in their SSP
System owners can leverage FedRAMP-authorized cloud services by inheriting assessed controls, which reduces their control implementation burden and is documented as inherited controls in the SSP.
Question 25: A system owner wants to reuse security assessment results from a similar system assessed 14 months ago. What is the primary concern with this approach?
- Reuse is only permitted for systems with the same data classification
- Assessment results cannot legally be reused across different systems
- Security assessors must be the same personnel for reuse to be valid
- The previous SAR may be outside the acceptable reuse window, typically 12 months (Correct answer)
Correct answer: The previous SAR may be outside the acceptable reuse window, typically 12 months
NIST guidance generally limits reuse of assessment evidence to within 12 months, as older results may not reflect the current security posture.
Question 26: A federal system is categorized as MODERATE impact. Which NIST SP 800-53 security control baseline should be applied as the starting point?
- The MODERATE baseline. (Correct answer)
- The HIGH baseline, then scoped down.
- The LOW baseline, then augmented as needed.
- No baseline — controls are selected individually for each system.
Correct answer: The MODERATE baseline.
NIST SP 800-53 defines three control baselines (LOW, MODERATE, HIGH) aligned to FIPS 199 impact levels. A MODERATE-categorized system uses the MODERATE baseline as its starting point before any tailoring.
Question 27: Which NIST publication provides guidelines for categorizing federal information and information systems based on potential impact?
- FIPS 140-2
- NIST SP 800-53
- FIPS 199 (Correct answer)
- NIST SP 800-37
Correct answer: FIPS 199
FIPS 199 establishes security categories for federal information and information systems using potential impact levels of low, moderate, and high.
Question 28: Which NIST publication provides the primary framework for federal information security risk management using the Risk Management Framework (RMF)?
- NIST SP 800-171
- NIST SP 800-30
- NIST SP 800-53
- NIST SP 800-37 (Correct answer)
Correct answer: NIST SP 800-37
NIST SP 800-37 defines the RMF and its six steps (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor) for federal systems.
Question 29: Under NIST SP 800-34, which document establishes the scope, roles, responsibilities, and recovery strategies for an information system?
- Continuity of Operations Plan (COOP)
- Contingency Plan (CP) (Correct answer)
- Business Impact Analysis (BIA)
- Crisis Communications Plan
Correct answer: Contingency Plan (CP)
NIST SP 800-34 defines the Contingency Plan (CP) as the document covering system-level scope, roles, recovery strategies, and procedures for an information system.
Question 30: Which access control model was specifically designed to enforce confidentiality in military and government information systems?
- Clark-Wilson Model
- Brewer-Nash (Chinese Wall) Model
- Bell-LaPadula Model (Correct answer)
- Biba Integrity Model
Correct answer: Bell-LaPadula Model
The Bell-LaPadula model enforces confidentiality by preventing read-up and write-down, making it foundational for classified military and government systems.
Question 31: Which skill is most important for success in Incident Response & Recovery within Certified Authorization Professional?
- Avoiding feedback
- Continuous learning and adaptation (Correct answer)
- Resisting change
- Working without any training
Correct answer: Continuous learning and adaptation
Continuous learning ensures professionals stay current with evolving practices in Incident Response & Recovery.
Question 32: A system that stores Social Security Numbers and health records is being categorized. Which NIST publication maps information types to impact levels to support FIPS 199 categorization?
- NIST SP 800-53
- NIST SP 800-30
- NIST SP 800-60 (Correct answer)
- NIST SP 800-37
Correct answer: NIST SP 800-60
NIST SP 800-60 maps federal information and information system types to security impact levels for use in FIPS 199 categorization.
Question 33: Which document serves as the primary artifact in the NIST RMF that describes the security controls implemented in an information system?
- Authorization to Operate (ATO)
- Plan of Action and Milestones (POA&M)
- Security Assessment Report (SAR)
- System Security Plan (SSP) (Correct answer)
Correct answer: System Security Plan (SSP)
The System Security Plan (SSP) is the primary security documentation artifact that describes how an information system implements required security controls.
Question 34: An access control matrix row represents a subject's permissions. What does each column represent?
- An audit log entry
- A network segment boundary
- Permissions for a specific object or resource (Correct answer)
- A user's role assignment
Correct answer: Permissions for a specific object or resource
In an access control matrix, columns represent objects (resources), and each cell specifies the access rights a subject has to that object.
Question 35: An organization receives an alert that a critical server is communicating with a known malicious IP address. What is the MOST appropriate immediate containment action?
- Reimage the server immediately
- Change all user passwords on the system
- Update antivirus signatures on the server
- Isolate the server from the network while preserving forensic evidence (Correct answer)
Correct answer: Isolate the server from the network while preserving forensic evidence
Network isolation stops ongoing communication with the attacker while preserving evidence needed for forensic investigation.
Question 36: What is the recommended maximum duration for a federal system's Authorization to Operate (ATO) under NIST SP 800-37?
- Authorization has no defined maximum duration
- 1 year
- 5 years
- 3 years (Correct answer)
Correct answer: 3 years
NIST SP 800-37 recommends ATOs be reviewed at least every three years or whenever significant changes occur to the system or its environment.
Question 37: Under the RMF, which role is responsible for developing and maintaining the System Security Plan (SSP)?
- Security Control Assessor (SCA)
- Information System Owner (ISO) (Correct answer)
- Common Control Provider (CCP)
- Authorizing Official (AO)
Correct answer: Information System Owner (ISO)
The Information System Owner (ISO) is responsible for developing, maintaining, and updating the SSP as the primary steward of the system's security documentation.
Question 38: What is the purpose of a Privacy Impact Assessment (PIA) under the E-Government Act of 2002?
- To document all PII fields stored in agency databases for audit purposes
- To evaluate risks to privacy before collecting or processing PII in a federal system (Correct answer)
- To assess the financial impact of privacy breaches on agency budgets
- To verify that privacy notices are displayed on all public-facing websites
Correct answer: To evaluate risks to privacy before collecting or processing PII in a federal system
A PIA analyzes how and why PII is collected, used, shared, and maintained, and identifies risks and mitigation strategies before system deployment.
Question 39: Which skill is most important for success in Network Security Fundamentals within Certified Authorization Professional?
- Resisting change
- Avoiding feedback
- Working without any training
- Continuous learning and adaptation (Correct answer)
Correct answer: Continuous learning and adaptation
Continuous learning ensures professionals stay current with evolving practices in Network Security Fundamentals.
Question 40: In Certified Authorization Professional, what is a risk matrix used for?
- Calculating project budgets
- Evaluating risks based on likelihood and impact (Correct answer)
- Scheduling team meetings
- Tracking employee performance
Correct answer: Evaluating risks based on likelihood and impact
A risk matrix plots risks on a grid of likelihood versus impact, helping prioritize which risks need the most attention.
Question 41: What is the purpose of a risk assessment in cybersecurity?
- To replace incident response procedures
- To ignore security threats
- To avoid implementing security measures
- To evaluate threats and vulnerabilities (Correct answer)
Correct answer: To evaluate threats and vulnerabilities
The purpose of a risk assessment in cybersecurity is to systematically identify and analyze potential threats, such as malware or insider threats, and existing vulnerabilities, like unpatched software or weak configurations. By evaluating these factors, organizations can understand the potential impact and likelihood of security incidents. This understanding informs decisions on how to prioritize and implement security controls.
Question 42: When a user authenticates to a web application and receives a session token, which attack exploits the failure to invalidate that token after the user logs out?
- Session fixation
- Session hijacking via token reuse (Correct answer)
- Cross-site request forgery (CSRF)
- Clickjacking
Correct answer: Session hijacking via token reuse
If session tokens remain valid after logout, an attacker who captured the token can reuse it to impersonate the user.
Question 43: What is a fundamental principle of Cloud Security Architecture in Certified Authorization Professional practice?
- Using outdated methods
- Ignoring industry guidelines
- Working in isolation without guidance
- Following established standards and best practices (Correct answer)
Correct answer: Following established standards and best practices
Following established standards and best practices ensures quality and consistency in Cloud Security Architecture.
Question 44: Which framework is commonly used for risk management in information security?
- NIST Risk Management Framework (RMF) (Correct answer)
- ISO 27001
- HIPAA
- PCI DSS
Correct answer: NIST Risk Management Framework (RMF)
The NIST Risk Management Framework (RMF) is a widely recognized and comprehensive framework developed by the National Institute of Standards and Technology. It provides a structured, seven-step process for managing cybersecurity risks in information systems. The RMF is particularly prevalent in U.S. federal agencies and is often adopted by private sector organizations.
Question 45: What is the role of 'security metrics' in an ISCM program?
- Metrics are used solely for annual budget justification to leadership.
- Metrics are only required for HIGH-impact systems under FISMA.
- Metrics provide quantifiable measures of security control effectiveness and organizational security posture over time. (Correct answer)
- Metrics replace the need for human security analysts in the monitoring process.
Correct answer: Metrics provide quantifiable measures of security control effectiveness and organizational security posture over time.
In ISCM, security metrics are quantifiable measures used to assess the effectiveness of security controls and track the organization's security posture over time. They enable data-driven risk decisions by the AO and support the ongoing authorization model.
Question 46: A penetration tester successfully performs DNS spoofing to redirect users to a malicious site. Which security principle is primarily violated in this attack scenario?
- Integrity (Correct answer)
- Availability
- Non-repudiation
- Confidentiality
Correct answer: Integrity
DNS spoofing violates integrity by corrupting the authentic mapping between domain names and IP addresses, directing users to unauthorized destinations.
Question 47: What is 'key escrow' and why is it controversial in government contexts?
- An approach for revoking compromised keys from a PKI
- A technique for generating stronger keys by iterating a hash function
- A method for distributing public keys via a central directory
- A process where encryption keys are deposited with a trusted third party for recovery, raising concerns about government surveillance (Correct answer)
Correct answer: A process where encryption keys are deposited with a trusted third party for recovery, raising concerns about government surveillance
Key escrow deposits copies of encryption keys with a trusted third party (often government), enabling lawful access but creating controversy over potential misuse and backdoors.
Question 48: Which authorization type allows a system to operate with identified weaknesses while remediation is in progress?
- Full Authorization to Operate (ATO)
- Interim Authorization to Operate (IATO) (Correct answer)
- Provisional Authorization
- Authorization to Test (ATT)
Correct answer: Interim Authorization to Operate (IATO)
An Interim Authorization to Operate (IATO) permits temporary operation of a system with known deficiencies, provided a remediation plan is in place and residual risk is acceptable.
Question 49: A company wants to ensure its SaaS vendor meets baseline security requirements. Which document formalizes these security expectations?
- Security requirements annex or cloud security addendum (Correct answer)
- Memorandum of Understanding (MOU)
- Business Impact Analysis (BIA)
- Service Level Agreement (SLA)
Correct answer: Security requirements annex or cloud security addendum
A security requirements annex or cloud security addendum formally documents and enforces the specific security controls expected from a SaaS vendor.
Question 50: What is the significance of 'continuous monitoring' documentation in the context of maintaining an ATO?
- It provides ongoing evidence that security controls remain effective and risks stay within accepted levels (Correct answer)
- It satisfies FISMA annual training requirements
- It documents physical security inspections only
- It replaces the need for an SSP after initial authorization
Correct answer: It provides ongoing evidence that security controls remain effective and risks stay within accepted levels
Continuous monitoring documentation demonstrates that security controls remain effective over time, supporting ongoing authorization and keeping the ATO valid.
Question 51: What is the role of an Information System Security Officer (ISSO) in ongoing security monitoring?
- Approving system authorization decisions
- Establishing organizational security policy
- Implementing and maintaining day-to-day security controls (Correct answer)
- Conducting independent security assessments
Correct answer: Implementing and maintaining day-to-day security controls
The ISSO is responsible for the day-to-day implementation and maintenance of security controls within the information system.
Question 52: What is a risk register in Certified Authorization Professional practice?
- A financial ledger
- A documented list of identified risks with their analysis and response plans (Correct answer)
- A sign-in sheet for safety meetings
- An employee directory
Correct answer: A documented list of identified risks with their analysis and response plans
A risk register is a document that records all identified risks, their assessment, and planned responses for tracking and management.
Question 53: Which indicator type, according to NIST SP 800-61, is considered the MOST reliable for confirming a security incident?
- Threats
- Vulnerabilities
- Precursors
- Indicators of Compromise (IoCs) (Correct answer)
Correct answer: Indicators of Compromise (IoCs)
Indicators of Compromise (IoCs) are direct evidence that an incident has occurred or is in progress, making them the most reliable confirmation of an actual incident.
Question 54: An organization must report a breach of unsecured PHI to HHS. If the breach affects 500 or more individuals, what is the notification deadline?
- 30 days
- 45 days
- Within 60 days of discovery (Correct answer)
- 60 days
Correct answer: Within 60 days of discovery
HIPAA Breach Notification Rule requires covered entities to notify HHS of breaches affecting 500+ individuals within 60 calendar days of discovering the breach.
Question 55: Which of the following best describes a 'security control overlay' in NIST SP 800-53?
- The process of mapping controls from one framework (e.g., ISO 27001) to NIST SP 800-53.
- An additional layer of encryption applied on top of existing security controls.
- A community-wide tailoring of the security control catalog for a specific technology type, environment, or mission. (Correct answer)
- A custom baseline created by an individual organization for its own internal use.
Correct answer: A community-wide tailoring of the security control catalog for a specific technology type, environment, or mission.
Overlays are tailored baselines developed for specific communities of interest (e.g., cloud systems, healthcare, Industrial Control Systems). They adjust the baseline controls to reflect the unique requirements of that environment and are approved for community-wide use.
Question 56: Which risk response strategy involves transferring potential loss to a third party, such as through cyber insurance?
- Risk Transference (Correct answer)
- Risk Mitigation
- Risk Acceptance
- Risk Avoidance
Correct answer: Risk Transference
Risk transference shifts financial or operational consequences of a risk to another party, such as an insurer or cloud service provider.
Question 57: What is the primary goal of data protection in information systems?
- To allow unrestricted data access
- To delete data frequently
- To prevent data backups
- To secure data from unauthorized access (Correct answer)
Correct answer: To secure data from unauthorized access
The primary goal of data protection in information systems is to secure data from unauthorized access, disclosure, alteration, or destruction. This involves implementing various security measures to ensure data confidentiality, integrity, and availability. Protecting data is crucial for maintaining privacy, complying with regulations, and preserving trust in an organization's systems and services.
Question 58: A system security plan (SSP) is required under which regulatory mandate for federal agencies?
- PCI DSS
- HIPAA Security Rule
- FISMA (Correct answer)
- Sarbanes-Oxley Act
Correct answer: FISMA
FISMA requires federal agencies to develop and maintain an SSP that describes the security requirements of the system and the controls in place to meet those requirements.
Question 59: Which type of penetration test provides the tester with full knowledge of the target system's architecture, source code, and network diagrams?
- Red team testing
- Gray-box testing
- White-box testing (Correct answer)
- Black-box testing
Correct answer: White-box testing
White-box testing gives testers complete knowledge of the target environment, enabling thorough assessment of internal logic and configurations.
Question 60: A user is given temporary elevated access to deploy a change and the access is automatically revoked after 4 hours. This is an example of:
- Discretionary access control
- Role explosion
- Time-based access control / just-in-time access (Correct answer)
- Mandatory access control enforcement
Correct answer: Time-based access control / just-in-time access
Just-in-time (JIT) or time-based access control grants elevated privileges only for the duration needed and automatically removes them afterward.
Question 61: What is a 'salt' in the context of password hashing?
- A cryptographic nonce used only in symmetric encryption
- An encryption key appended to the password before hashing
- A second password used for two-factor authentication
- A random value added to a password before hashing to prevent precomputed attacks (Correct answer)
Correct answer: A random value added to a password before hashing to prevent precomputed attacks
A salt is a unique random value prepended or appended to each password before hashing, ensuring identical passwords produce different hash values and defeating rainbow table attacks.
Question 62: An organization cannot implement a required NIST SP 800-53 control due to a documented technical constraint. What is the correct approach?
- Accept the risk without any alternative measure.
- Implement a compensating control that provides equivalent protection, and document it. (Correct answer)
- Escalate to NIST for a waiver of the control requirement.
- Remove the control from the Security Plan without documentation.
Correct answer: Implement a compensating control that provides equivalent protection, and document it.
When a required control cannot be implemented, organizations should identify and implement a compensating control that provides equivalent or comparable protection. This must be documented in the Security Plan and approved by the Authorizing Official.
Question 63: During a physical penetration test, a tester gains unauthorized access to a server room by tailgating an authorized employee. What type of attack does this represent?
- Eavesdropping
- Dumpster Diving
- Social Engineering - Tailgating/Piggybacking (Correct answer)
- Shoulder Surfing
Correct answer: Social Engineering - Tailgating/Piggybacking
Tailgating (or piggybacking) is a physical social engineering technique where an unauthorized person follows an authorized individual through a secured entry point.
Question 64: Which section of a System Security Plan (SSP) describes how a system processes, stores, and transmits information?
- System Environment
- System Identification
- Security Controls
- Information System Description (Correct answer)
Correct answer: Information System Description
The Information System Description section of an SSP provides an overview of the system's purpose, architecture, and how it handles information throughout its lifecycle.
Question 65: In the context of federal information systems, what does 'data in use' refer to?
- Data transmitted over encrypted network channels
- Data stored on backup tapes in a secure vault
- Data archived in long-term cold storage
- Data actively being processed in memory or by an application (Correct answer)
Correct answer: Data actively being processed in memory or by an application
Data in use refers to data actively being accessed, modified, or processed by an application or user, making it vulnerable to memory-based attacks.
Question 66: Which log source would be MOST useful when investigating potential insider threat activity involving unauthorized data exfiltration?
- Patch management reports
- Data Loss Prevention (DLP) alerts (Correct answer)
- Firewall deny logs
- Antivirus scan results
Correct answer: Data Loss Prevention (DLP) alerts
DLP systems monitor and alert on data movements that violate policy, making them the most direct source for identifying data exfiltration.
Question 67: A security assessor uses penetration testing during a control assessment. Under NIST SP 800-53A, this technique is classified as which assessment method?
- Examine
- Review
- Interview
- Test (Correct answer)
Correct answer: Test
NIST SP 800-53A defines three assessment methods — examine, interview, and test — with penetration testing classified under the 'test' method.
Question 68: In the context of CAP assessments, what document formally captures the results of a security assessment including vulnerability findings and their risk levels?
- System Security Plan (SSP)
- Authorization to Operate (ATO)
- Security Assessment Report (SAR) (Correct answer)
- Plan of Action and Milestones (POA&M)
Correct answer: Security Assessment Report (SAR)
The Security Assessment Report documents all findings from the security assessment, including identified vulnerabilities, their severity, and recommendations.
Question 69: When a federal agency activates its contingency plan and transitions operations to an alternate processing site, which activity should occur first?
- Notifying the Inspector General
- Activating the notification and escalation procedures per the contingency plan (Correct answer)
- Restoring all non-critical systems before mission-critical ones
- Decommissioning the primary site hardware
Correct answer: Activating the notification and escalation procedures per the contingency plan
Contingency plan activation begins with executing the notification and escalation procedures to alert key personnel, leadership, and stakeholders before beginning system recovery activities.
Question 70: Which NIST SP 800-53 control family primarily addresses protecting data in transit and at rest?
- Configuration Management (CM)
- System and Communications Protection (SC) (Correct answer)
- Audit and Accountability (AU)
- Access Control (AC)
Correct answer: System and Communications Protection (SC)
The SC control family includes cryptographic protection, transmission confidentiality/integrity, and network controls that protect data both in transit and at rest.
Question 71: A security analyst receives intelligence indicating that a known APT group is targeting organizations in your sector. At what intelligence level is this information MOST useful?
- Tactical
- Operational
- Technical
- Strategic (Correct answer)
Correct answer: Strategic
Strategic intelligence informs senior leadership about threat actors targeting specific sectors, helping guide risk decisions and resource allocation.
Question 72: What distinguishes a vulnerability scan from a penetration test in the context of federal system assessments?
- Vulnerability scans require written authorization but penetration tests do not
- Penetration tests use only commercial tools while vulnerability scans use open-source tools
- Penetration tests actively attempt to exploit vulnerabilities while scans only identify them (Correct answer)
- Vulnerability scans are always automated while penetration tests are always manual
Correct answer: Penetration tests actively attempt to exploit vulnerabilities while scans only identify them
Penetration tests go beyond identification by actively attempting to exploit vulnerabilities to demonstrate actual impact and risk.
Question 73: What does the concept of 'least functionality' require for federal information systems?
- Implementing only the minimum number of security controls required by the baseline
- Configuring systems to provide only essential capabilities and disabling unused services, ports, and functions (Correct answer)
- Using the minimum number of servers to reduce infrastructure costs
- Limiting system features to those that users most frequently access
Correct answer: Configuring systems to provide only essential capabilities and disabling unused services, ports, and functions
Least functionality (NIST SP 800-53 CM-7) requires disabling all unused services, ports, protocols, and functions to reduce the attack surface.
Question 74: In NIST SP 800-53, security controls are organized into 'families.' Which control family specifically addresses planning for security activities?
- Planning (PL) (Correct answer)
- Program Management (PM)
- System and Services Acquisition (SA)
- Risk Assessment (RA)
Correct answer: Planning (PL)
The Planning (PL) family in NIST SP 800-53 includes controls related to security planning activities, such as developing the System Security Plan (SSP) and Rules of Behavior. The PL family is directly relevant to the authorization documentation process.
Question 75: In public key cryptography, what is used to verify a digital signature?
- A shared HMAC secret
- The signer's private key
- A symmetric session key
- The signer's public key (Correct answer)
Correct answer: The signer's public key
A digital signature is created with the signer's private key and verified by anyone using the corresponding public key.
Question 76: During a penetration test, a tester discovers that a web application reflects user input directly in HTTP responses without encoding. Which vulnerability class does this represent?
- SQL Injection
- Command Injection
- Path Traversal
- Cross-Site Scripting (XSS) (Correct answer)
Correct answer: Cross-Site Scripting (XSS)
Reflected XSS occurs when unsanitized user input is echoed back in HTTP responses, allowing script injection in the victim's browser.
Question 77: A CAP professional is reviewing an Incident Response Plan (IRP). Which element is MOST critical to verify is current and accurate?
- Contact information for the incident response team and escalation paths (Correct answer)
- List of software versions in use
- Historical log of past incidents
- Network diagram from the previous year
Correct answer: Contact information for the incident response team and escalation paths
Outdated contact information and escalation paths are among the most common reasons IRPs fail during actual incidents, making this the most critical element to keep current.
Question 78: A penetration test reveals that a web application stores session tokens in plaintext cookies. Which security principle is most directly violated?
- System availability and redundancy
- Confidentiality of session data and least privilege for session management (Correct answer)
- Non-repudiation of user transactions
- Integrity of audit logs
Correct answer: Confidentiality of session data and least privilege for session management
Plaintext session tokens expose confidential authentication data and violate least privilege by allowing any interceptor to assume a user's session privileges.
Question 79: What does risk mitigation mean in Certified Authorization Professional practice?
- Taking steps to reduce the likelihood or impact of identified risks (Correct answer)
- Ignoring low-level risks
- Eliminating all risks completely
- Accepting all risks without action
Correct answer: Taking steps to reduce the likelihood or impact of identified risks
Risk mitigation involves implementing strategies to reduce either the probability of a risk occurring or its potential impact.
Question 80: Which of the following items is NOT typically included in an authorization package submitted to the Authorizing Official?
- Security Assessment Report (SAR)
- Penetration Test Scope Agreement (Correct answer)
- Plan of Action and Milestones (POA&M)
- System Security Plan (SSP)
Correct answer: Penetration Test Scope Agreement
The standard authorization package per NIST SP 800-37 consists of three core documents: the SSP, the SAR, and the POA&M. A penetration test scope agreement is a pre-engagement document used in contracting, not a formal component of the authorization package.
Question 81: During red team exercises on federal systems, which methodology specifically simulates advanced persistent threat (APT) tactics, techniques, and procedures?
- OSSTMM
- OWASP Testing Guide
- MITRE ATT&CK Framework (Correct answer)
- PTES (Penetration Testing Execution Standard)
Correct answer: MITRE ATT&CK Framework
The MITRE ATT&CK Framework catalogs real-world APT tactics and techniques, making it the primary reference for simulating sophisticated threat actor behavior.
Question 82: In the Biba Integrity Model, what does the 'simple integrity axiom' (no read down) state?
- A subject cannot modify objects at a lower integrity level than its own
- A subject cannot write to objects at a higher integrity level than its own
- A subject cannot read objects at a lower integrity level than its own (Correct answer)
- A subject cannot read objects at a higher integrity level than its own
Correct answer: A subject cannot read objects at a lower integrity level than its own
The simple integrity axiom prevents a subject from reading data at a lower integrity level, protecting the subject from contamination by less-trusted data.
Question 83: Which network security device inspects traffic at the application layer and can make decisions based on the content of packets?
- Network hub
- Next-Generation Firewall (NGFW) (Correct answer)
- Packet-filtering firewall
- Stateful inspection firewall
Correct answer: Next-Generation Firewall (NGFW)
Next-Generation Firewalls operate at layer 7, performing deep packet inspection and making policy decisions based on application identity and content.
Question 84: In the CVSS scoring system, which metric group assesses the characteristics of a vulnerability that cannot be changed over time?
- Base Metrics (Correct answer)
- Temporal Metrics
- Supplemental Metrics
- Environmental Metrics
Correct answer: Base Metrics
CVSS Base Metrics represent the intrinsic characteristics of a vulnerability that are constant across all deployments and time.
Question 85: A system owner wants to minimize data loss in the event of a ransomware attack. Which contingency planning element directly addresses this goal?
- Incident Response Team staffing plan
- System interconnection agreements
- Backup and restoration strategy aligned with a low RPO (Correct answer)
- Business Impact Analysis (BIA)
Correct answer: Backup and restoration strategy aligned with a low RPO
A backup and restoration strategy designed to meet a low Recovery Point Objective (RPO) directly limits how much data can be lost in the event of an attack.
Question 86: Why is a security assessment critical in risk management?
- To reduce the need for security policies
- To eliminate all cybersecurity risks
- To delay compliance audits
- To identify vulnerabilities before exploitation (Correct answer)
Correct answer: To identify vulnerabilities before exploitation
A security assessment is a critical component of risk management because it systematically examines an organization's systems, networks, and applications for weaknesses. By proactively identifying vulnerabilities, organizations can address them before malicious actors can exploit them. This significantly reduces the likelihood of security breaches and data loss.
Question 87: Which federal law mandates that agencies report major information security incidents to US-CERT within one hour of discovery?
- Privacy Act of 1974
- E-Government Act of 2002
- Federal Information Security Modernization Act (FISMA) (Correct answer)
- Computer Fraud and Abuse Act (CFAA)
Correct answer: Federal Information Security Modernization Act (FISMA)
FISMA requires federal agencies to report major incidents to US-CERT within one hour and includes ongoing incident management requirements.
Question 88: Which algorithm is commonly used for key derivation from passwords to slow down brute-force attacks?
- MD5
- PBKDF2 (Correct answer)
- RC4
- SHA-256
Correct answer: PBKDF2
PBKDF2 (Password-Based Key Derivation Function 2) applies a pseudorandom function many times to stretch a password, making brute-force attacks computationally expensive.
Question 89: When conducting a post-incident review, which of the following questions is MOST important for improving the authorization process?
- Was the incident publicly disclosed in a timely manner?
- How many staff hours were spent on the incident?
- Which vendor should be blamed for the vulnerability?
- Were the security controls in the SSP effective, and should the ATO conditions be updated? (Correct answer)
Correct answer: Were the security controls in the SSP effective, and should the ATO conditions be updated?
The CAP professional's primary post-incident concern is whether the security controls and authorization basis remain valid and if the ATO needs to be updated to reflect new risks.
Question 90: What is the purpose of a 'jump bag' in incident response?
- A backup set of authentication credentials
- A portable kit of tools and documentation ready for immediate incident response deployment (Correct answer)
- A secure container for storing encryption keys
- A database of known threat indicators
Correct answer: A portable kit of tools and documentation ready for immediate incident response deployment
A jump bag is a pre-packed collection of hardware, software, and documentation that responders can grab immediately when deploying to handle an incident.
Question 91: An organization's security architect is designing a system with multiple layers of security controls. Which NIST document provides the security control catalog for this effort?
- NIST SP 800-37
- NIST SP 800-53 (Correct answer)
- NIST SP 800-137
- NIST SP 800-30
Correct answer: NIST SP 800-53
NIST SP 800-53 provides the comprehensive catalog of security and privacy controls for federal information systems.
Question 92: A SIEM system correlates events from multiple sources and generates an alert for an attack pattern. What should the analyst do FIRST?
- Restore the system from backup
- Immediately shut down the affected system
- Validate the alert to determine if it is a true positive (Correct answer)
- Notify law enforcement
Correct answer: Validate the alert to determine if it is a true positive
Alert validation to confirm it is a true positive (not a false positive) is the first step before taking any remediation action.
Question 93: Which term describes the documented approval for a system to operate that explicitly acknowledges and accepts residual risk?
- Authority to Connect (ATC)
- Authorization to Operate (ATO) (Correct answer)
- Memorandum of Understanding (MOU)
- Interim Authority to Test (IATT)
Correct answer: Authorization to Operate (ATO)
An ATO is the official management decision by the AO authorizing system operation and explicitly accepting the residual security risk.
Question 94: Which of the following BEST describes a 'compensating control' in the RMF context?
- A backup control activated only during an incident
- A control that compensates for the cost of security investments
- An automated control substituted for a manual one
- An alternative control that provides equivalent protection when the required control cannot be implemented (Correct answer)
Correct answer: An alternative control that provides equivalent protection when the required control cannot be implemented
A compensating control provides equivalent or comparable protection to the required control when the latter is technically or operationally infeasible to implement.
Question 95: NIST SP 800-53A defines three assessment methods. Which set correctly identifies all three?
- Review, Audit, Penetrate
- Examine, Interview, Test (Correct answer)
- Scan, Analyze, Report
- Observe, Document, Verify
Correct answer: Examine, Interview, Test
NIST SP 800-53A defines three assessment methods: Examine (reviewing documentation and artifacts), Interview (discussing controls with personnel), and Test (exercising the control through technical or operational means). These three methods together provide comprehensive coverage of control effectiveness.
Question 96: Under the CAP framework, who is ultimately responsible for authorizing penetration testing activities on a federal information system?
- The Penetration Tester
- The System Owner
- The Information System Security Officer (ISSO)
- The Authorizing Official (AO) (Correct answer)
Correct answer: The Authorizing Official (AO)
The Authorizing Official has the authority and accountability to accept risk, including approving assessment activities like penetration testing.
Question 97: A federal system processes both FOUO (For Official Use Only) and publicly releasable information. What is the most appropriate data handling control?
- Classify all data at the highest sensitivity level present
- Separate the data with access controls and label all FOUO information appropriately (Correct answer)
- Make all data publicly available since some is already public
- Encrypt all data regardless of sensitivity to avoid categorization
Correct answer: Separate the data with access controls and label all FOUO information appropriately
Mixed-sensitivity systems must segregate data, apply appropriate labels, and enforce access controls so that FOUO data is only accessible to authorized users.
Question 98: A security assessor is evaluating a system's resistance to brute-force attacks and finds no account lockout policy. Which NIST SP 800-53 control family is most directly relevant to this finding?
- SC - System and Communications Protection
- IA - Identification and Authentication (Correct answer)
- AU - Audit and Accountability
- AC - Access Control
Correct answer: IA - Identification and Authentication
The IA (Identification and Authentication) control family includes controls like IA-5 that address authenticator management, including account lockout policies.
Question 99: During a penetration test on a federal system, a tester successfully extracts password hashes from a domain controller. Which post-exploitation technique involves using these hashes without cracking them?
- Pass-the-Hash (Correct answer)
- Credential Stuffing
- Rainbow Table Attack
- Privilege Escalation
Correct answer: Pass-the-Hash
Pass-the-Hash allows attackers to authenticate using captured NTLM hashes directly without needing the plaintext password.
Question 100: Under RMF, which artifact serves as the 'living document' that must be updated throughout the system lifecycle, not just at authorization time?
- Authorization Decision Document
- System Security Plan (SSP) (Correct answer)
- Security Categorization memo
- Initial Risk Assessment
Correct answer: System Security Plan (SSP)
The SSP is a living document that must be kept current throughout the system's lifecycle, updated whenever significant changes occur or controls are modified.
Question 101: The NIST Cybersecurity Framework (CSF) core consists of five functions. Which function focuses on detecting cybersecurity events?
- Protect
- Detect (Correct answer)
- Identify
- Respond
Correct answer: Detect
The 'Detect' function of the NIST CSF defines activities to identify the occurrence of a cybersecurity event in a timely manner.
Question 102: What is the purpose of 'supplementation' during security control tailoring?
- To add controls beyond the baseline to address residual risks or organizational policies. (Correct answer)
- To document which controls were inherited from a common control provider.
- To remove inapplicable controls from the baseline.
- To replace all baseline controls with organizational-specific alternatives.
Correct answer: To add controls beyond the baseline to address residual risks or organizational policies.
Supplementation is the tailoring action of adding controls (or control enhancements) to the baseline to address risks not adequately covered by baseline controls, or to meet specific organizational or mission requirements. It is the opposite of scoping, which removes controls.
Question 103: Under CNSSI 1253, which factor primarily drives the selection of security control overlays for national security systems?
- Network topology and bandwidth requirements
- System type, classification level, and operational environment (Correct answer)
- Number of users and geographic distribution
- System age and vendor support status
Correct answer: System type, classification level, and operational environment
CNSSI 1253 overlays are driven by system type (e.g., space, weapons), classification level, and specific operational environments requiring tailored controls.
Question 104: What does 'non-repudiation' provide in information system security architecture?
- Assurance that data has not been altered in an unauthorized manner
- Guarantee that authorized users can access information when required
- Assurance that an entity cannot later deny having performed a specific action or transaction (Correct answer)
- Prevention of unauthorized access to sensitive information resources
Correct answer: Assurance that an entity cannot later deny having performed a specific action or transaction
Non-repudiation provides proof of origin or delivery of data so that neither sender nor receiver can later deny involvement in a transaction, often implemented via digital signatures.
Question 105: Under FISMA, an agency experiences a breach of PII affecting 5,000 individuals. What additional reporting requirement is triggered?
- Immediately shut down all affected systems
- Report to Congress within 7 days
- File a report with GAO within 30 days
- Notify affected individuals and potentially US-CERT within strict timelines (Correct answer)
Correct answer: Notify affected individuals and potentially US-CERT within strict timelines
Breaches of PII trigger mandatory notification to affected individuals and US-CERT reporting under OMB guidelines and agency privacy policies.
Question 106: Which authorization decision type allows a system to operate temporarily while known weaknesses are remediated, typically with strict conditions and a deadline?
- Interim Authority to Test (IATT)
- Denial of Authorization to Operate (DATO)
- Common Control Authorization
- Authorization to Operate with Conditions (ATOC) (Correct answer)
Correct answer: Authorization to Operate with Conditions (ATOC)
An ATOC (or conditional ATO) permits operation despite identified weaknesses, provided the system owner meets specified conditions and remediation timelines.
Question 107: During incident eradication, a technician reimages a compromised server. What critical step must occur BEFORE reimaging to support potential legal action?
- Notify the system users
- Obtain a forensic image of the original disk (Correct answer)
- Reset all user passwords
- Update the system security plan
Correct answer: Obtain a forensic image of the original disk
A forensic image of the original disk must be taken before reimaging to preserve evidence that may be needed for legal proceedings or deeper analysis.
Question 108: Which standard defines the requirements for Payment Card Industry Data Security?
- COBIT 5
- PCI DSS (Correct answer)
- SOC 2 Type II
- ISO 27001
Correct answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) is the global standard mandating security controls for organizations that store, process, or transmit cardholder data.
Question 109: A system is categorized as HIGH for confidentiality, MODERATE for integrity, and LOW for availability. What is the overall FIPS 199 categorization?
- MODERATE
- LOW
- Cannot be determined without further analysis
- HIGH (Correct answer)
Correct answer: HIGH
FIPS 199 uses the 'high water mark' principle — the overall system categorization equals the highest impact level across all three security objectives.
Question 110: Which principle dictates that a user should only be able to access information that is relevant to their current task, even if they are cleared for a higher classification level?
- Least privilege
- Non-repudiation
- Need to know (Correct answer)
- Separation of duties
Correct answer: Need to know
Need to know restricts access to information based on job relevance, regardless of the user's clearance level.
Question 111: What is the primary purpose of a Rules of Engagement (ROE) document in the context of federal penetration testing?
- To outline remediation steps for discovered vulnerabilities
- To define the scope, constraints, and authorized actions for the assessment (Correct answer)
- To establish the reporting format for test results
- To document all vulnerabilities found during testing
Correct answer: To define the scope, constraints, and authorized actions for the assessment
Rules of Engagement define what is in scope, what actions are permitted, and the boundaries testers must operate within during the assessment.
Question 112: Which NIST document provides guidance on security and privacy controls for federal information systems and organizations?
- NIST SP 800-53 (Correct answer)
- NIST SP 800-30
- NIST SP 800-37
- NIST SP 800-137
Correct answer: NIST SP 800-53
NIST SP 800-53 provides a catalog of security and privacy controls for federal information systems and organizations.
Question 113: A security analyst notices anomalous outbound traffic to an unknown IP address. According to NIST SP 800-61, this falls into which incident category?
- Inappropriate Usage
- Unauthorized Access
- Malicious Code (Correct answer)
- Denial of Service
Correct answer: Malicious Code
Anomalous outbound traffic to unknown IPs is typically indicative of malicious code (e.g., malware beaconing to a C2 server).
Question 114: Which step of the NIST RMF involves defining the system boundary, identifying stakeholders, and establishing the authorization strategy?
- Prepare (Correct answer)
- Implement
- Select
- Categorize
Correct answer: Prepare
The Prepare step, added in NIST SP 800-37 Rev. 2, establishes organizational and system-level context before the remaining RMF steps begin.
Question 115: During a security assessment, an assessor discovers that a control is partially implemented. How should this finding be recorded in the Security Assessment Report (SAR)?
- As 'Satisfied' if the intent is met
- As 'Other Than Satisfied' with documented weaknesses (Correct answer)
- As 'Satisfied' with a waiver attached
- As 'Not Applicable' pending remediation
Correct answer: As 'Other Than Satisfied' with documented weaknesses
A partially implemented control is recorded as 'Other Than Satisfied' in the SAR, with the specific weaknesses and deficiencies documented.
Question 116: In secure system architecture, what does 'data-at-rest' protection primarily address?
- Controlling real-time access permissions to live transactional databases
- Securing data held temporarily in volatile memory during processing
- Protection of data packets as they traverse networks between endpoints
- Encryption and access controls for data stored on physical media, databases, or file systems (Correct answer)
Correct answer: Encryption and access controls for data stored on physical media, databases, or file systems
Data-at-rest protection focuses on encrypting and controlling access to stored data — on hard drives, SSDs, tapes, or databases — when data is not actively being transmitted or processed.
Question 117: What is the purpose of maintaining a chain of custody during a penetration test on a federal system?
- To create a timeline of system performance during testing
- To track which tools were used during the assessment
- To document the tester's working hours for billing purposes
- To ensure evidence integrity and accountability for all test artifacts and findings (Correct answer)
Correct answer: To ensure evidence integrity and accountability for all test artifacts and findings
Chain of custody ensures that all evidence and artifacts collected during testing are properly documented, handled, and protected to maintain their integrity and admissibility.
Question 118: What is the primary purpose of defining an 'authorization boundary' in information system architecture?
- To establish the geographic boundary for data storage locations
- To define the physical perimeter of the data center
- To separate classified from unclassified networks at the firewall
- To delineate the scope of the information system for authorization purposes, including all components to be authorized (Correct answer)
Correct answer: To delineate the scope of the information system for authorization purposes, including all components to be authorized
The authorization boundary identifies the system scope — all hardware, software, firmware, and people within that boundary are subject to the same authorization decision.
Question 119: What is the primary goal of data integrity controls in federal information systems?
- Ensuring that authorized users can access data when needed
- Limiting data retention to the minimum legally required period
- Ensuring that data has not been altered or destroyed in an unauthorized or undetected manner (Correct answer)
- Preventing unauthorized users from viewing sensitive information
Correct answer: Ensuring that data has not been altered or destroyed in an unauthorized or undetected manner
Integrity controls protect against unauthorized modification or destruction of data, ensuring its accuracy and completeness throughout its lifecycle.
Question 120: What is the primary purpose of a System Security Plan (SSP) in the RMF process?
- To document the system boundary, environment, and implemented security controls (Correct answer)
- To authorize the system for operation
- To establish the system categorization level
- To document all identified vulnerabilities
Correct answer: To document the system boundary, environment, and implemented security controls
The SSP describes the system boundary, operating environment, security requirements, and the controls implemented to meet those requirements.
Question 121: What is the role of documentation in Network Security Fundamentals for Certified Authorization Professional?
- It provides an accurate record for accountability and reference (Correct answer)
- It should only be done monthly
- It is unnecessary paperwork
- It is only for management review
Correct answer: It provides an accurate record for accountability and reference
Proper documentation in Network Security Fundamentals ensures accountability, traceability, and serves as a reference for future decisions.
Question 122: Which cryptographic primitive is the foundation of blockchain integrity?
- Cryptographic hash chaining (Correct answer)
- Symmetric encryption
- Key encapsulation mechanisms
- Public key certificates
Correct answer: Cryptographic hash chaining
Blockchains maintain integrity by chaining blocks together using cryptographic hashes, making any alteration of a prior block detectable.
Question 123: When a federal system uses SAML 2.0 for single sign-on, the component that makes assertions about user identity to the service provider is called what?
- Identity Provider (IdP) (Correct answer)
- Resource Server
- Relying Party
- Authorization Server
Correct answer: Identity Provider (IdP)
The Identity Provider authenticates the user and issues SAML assertions containing identity and attribute claims to the Service Provider.
Question 124: Which OMB circular establishes the requirement for agencies to develop and maintain an information security program?
- OMB Circular A-76
- OMB Circular A-130 (Correct answer)
- OMB Circular A-11
- OMB Circular A-123
Correct answer: OMB Circular A-130
OMB Circular A-130 establishes policy for the planning, budgeting, governance, acquisition, and management of federal information, including information security programs.
Question 125: In threat intelligence, what does 'pivoting' refer to?
- Redirecting network traffic through a proxy
- Changing the attribution of an attack to a different threat actor
- Switching from offensive to defensive security posture
- Using one indicator to discover related indicators and infrastructure (Correct answer)
Correct answer: Using one indicator to discover related indicators and infrastructure
Pivoting is the analytical technique of using a known IOC (such as a domain or IP) to discover additional related infrastructure and indicators used by the same threat actor.
Question 126: When migrating sensitive workloads to the cloud, what is the recommended approach for assessing residual risk?
- Identify, evaluate, and apply controls to reduce risk to an acceptable level (Correct answer)
- Transfer all risks to the cloud provider via contract
- Avoid migration until all risks are eliminated
- Accept all risks identified during the assessment
Correct answer: Identify, evaluate, and apply controls to reduce risk to an acceptable level
Risk management requires identifying threats, evaluating their impact and likelihood, and applying controls to bring residual risk within the organization's risk appetite.
Certified Authorization Professional (CAP)
The ISC2 CAP (now rebranded as CGRC – Certified in Governance, Risk and Compliance) validates professionals' expertise in authorizing and maintaining information systems using risk management frameworks, security controls, and continuous monitoring within government and enterprise environments.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds