โ† All CAP Flashcard Decks

Information Systems & Data Protection Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Information Systems & Data Protection flashcards as text
  1. In the context of federal information systems, what does 'data in use' refer to?

    Answer: Data actively being processed in memory or by an application

    Data in use refers to data actively being accessed, modified, or processed by an application or user, making it vulnerable to memory-based attacks.

  2. Which control baseline under NIST SP 800-53 is appropriate for a system categorized as MODERATE impact?

    Answer: Moderate baseline controls with tailoring as needed

    NIST SP 800-53 provides low, moderate, and high baselines; MODERATE impact systems use the moderate baseline, which can be tailored to organizational needs.

  3. A penetration test reveals that a web application stores session tokens in plaintext cookies. Which security principle is most directly violated?

    Answer: Confidentiality of session data and least privilege for session management

    Plaintext session tokens expose confidential authentication data and violate least privilege by allowing any interceptor to assume a user's session privileges.

  4. Under the Privacy Act of 1974, what is a 'system of records'?

    Answer: A group of records under agency control from which information is retrieved by personal identifier

    A Privacy Act system of records is a group of records under an agency's control from which information is retrieved by name, SSN, or other personal identifier.

  5. What is the key distinction between a Security Assessment Report (SAR) and a Plan of Action and Milestones (POA&M)?

    Answer: The SAR documents assessment findings while the POA&M tracks remediation of weaknesses

    The SAR captures what the assessor found during testing; the POA&M is the system owner's plan for correcting identified weaknesses with scheduled milestones.

  6. Which data protection technique renders data unusable to unauthorized parties if storage media is stolen, but retains full utility for authorized users?

    Answer: Encryption at rest with proper key management

    Encryption at rest with proper key management ensures that stolen media yields only ciphertext, while authorized users with valid keys can access plaintext data normally.

  7. Which federal law mandates that agencies report major information security incidents to US-CERT within one hour of discovery?

    Answer: Federal Information Security Modernization Act (FISMA)

    FISMA requires federal agencies to report major incidents to US-CERT within one hour and includes ongoing incident management requirements.