โ† All CAP Flashcard Decks

Information Systems & Data Protection Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Information Systems & Data Protection flashcards as text
  1. A federal system processes both FOUO (For Official Use Only) and publicly releasable information. What is the most appropriate data handling control?

    Answer: Separate the data with access controls and label all FOUO information appropriately

    Mixed-sensitivity systems must segregate data, apply appropriate labels, and enforce access controls so that FOUO data is only accessible to authorized users.

  2. What does the concept of 'least functionality' require for federal information systems?

    Answer: Configuring systems to provide only essential capabilities and disabling unused services, ports, and functions

    Least functionality (NIST SP 800-53 CM-7) requires disabling all unused services, ports, protocols, and functions to reduce the attack surface.

  3. Which RMF step involves selecting security controls based on system categorization?

    Answer: Step 2: Select

    RMF Step 2 (Select) involves choosing the appropriate security controls from NIST SP 800-53 based on the system's FIPS 199 categorization.

  4. An assessor discovers a control is 'not applicable' for a cloud-hosted system. What is the appropriate next step?

    Answer: Document the rationale for non-applicability and obtain approval through the tailoring process

    Tailoring allows removal of controls that are not applicable, but the rationale must be documented in the SSP and approved by the AO.

  5. Which data protection control prevents a malicious insider from exfiltrating sensitive data via email or removable media?

    Answer: Data Loss Prevention (DLP) tools and media access controls

    DLP tools inspect content leaving the organization via email, web, or removable media, and media access controls restrict USB and other removable storage usage.

  6. What is the purpose of a Privacy Impact Assessment (PIA) under the E-Government Act of 2002?

    Answer: To evaluate risks to privacy before collecting or processing PII in a federal system

    A PIA analyzes how and why PII is collected, used, shared, and maintained, and identifies risks and mitigation strategies before system deployment.

  7. Which term describes the documented approval for a system to operate that explicitly acknowledges and accepts residual risk?

    Answer: Authorization to Operate (ATO)

    An ATO is the official management decision by the AO authorizing system operation and explicitly accepting the residual security risk.