Information Systems & Data Protection Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Information Systems & Data Protection flashcards as text
Which NIST publication provides guidelines for categorizing federal information and information systems based on potential impact?
Answer: FIPS 199
FIPS 199 establishes security categories for federal information and information systems using potential impact levels of low, moderate, and high.
A database containing Social Security Numbers, medical records, and financial data is being categorized. Which security objective drives the overall system categorization to HIGH?
Answer: The highest impact level across all security objectives
Per FIPS 199, the overall information system security category is determined by the high-water mark โ the highest impact level across all security objectives (confidentiality, integrity, availability).
Under FISMA, which role is responsible for ensuring that information systems under their authority are covered by an approved authorization?
Answer: Authorizing Official (AO)
The Authorizing Official is the senior federal official who bears ultimate accountability for accepting risk and ensuring systems have an approved ATO.
What is the primary purpose of a System Security Plan (SSP) in the RMF process?
Answer: To document the system boundary, environment, and implemented security controls
The SSP describes the system boundary, operating environment, security requirements, and the controls implemented to meet those requirements.
Which type of data handling practice violates the principle of data minimization?
Answer: Collecting more PII than is strictly necessary for the stated purpose
Data minimization requires collecting only the minimum amount of personal information necessary to fulfill a specific, legitimate purpose.
A federal agency discovers that a contractor's system storing agency data lacks an interconnection security agreement (ISA). What is the most immediate concern?
Answer: Unauthorized data flows may exist without documented controls or approvals
Without an ISA, there is no documented agreement on security controls, data handling, and responsibilities governing the interconnection, creating unmanaged risk.
Which NIST SP 800-53 control family primarily addresses protecting data in transit and at rest?
Answer: System and Communications Protection (SC)
The SC control family includes cryptographic protection, transmission confidentiality/integrity, and network controls that protect data both in transit and at rest.