โ† All CAP Flashcard Decks

Information Systems & Data Protection Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Information Systems & Data Protection flashcards as text
  1. A system owner wants to share a risk assessment report with a third-party cloud provider. Which concern should be addressed first?

    Answer: Whether the report contains sensitive vulnerability details that could aid attackers if disclosed

    Risk assessment reports often contain sensitive details about system weaknesses; sharing without reviewing for sensitive content could expose exploitable vulnerabilities.

  2. Which approach best supports continuous monitoring of a federal information system's security posture?

    Answer: Automating security control assessments and feeding results into a dashboard with defined metrics and thresholds

    NIST SP 800-137 defines continuous monitoring as an ongoing process using automated tools to maintain situational awareness of control effectiveness in near real time.

  3. Under NIST SP 800-53, which control requires that information systems protect the authenticity of communications sessions?

    Answer: SC-23 (Session Authenticity)

    SC-23 requires systems to protect session authenticity to prevent session hijacking and man-in-the-middle attacks on active communications.

  4. An agency is moving a HIGH impact system to a FedRAMP-authorized cloud. Which statement is correct regarding inherited controls?

    Answer: The agency inherits controls provided by the CSP but retains responsibility for customer-responsible controls

    FedRAMP uses a shared responsibility model where CSP-provided controls are inherited by the agency, but customer-responsible controls remain the agency's obligation.

  5. What is the primary goal of data integrity controls in federal information systems?

    Answer: Ensuring that data has not been altered or destroyed in an unauthorized or undetected manner

    Integrity controls protect against unauthorized modification or destruction of data, ensuring its accuracy and completeness throughout its lifecycle.

  6. Which document formally defines the boundary of an information system for authorization purposes?

    Answer: System Security Plan (SSP) authorization boundary section

    The SSP's authorization boundary section explicitly defines what hardware, software, interfaces, and data are included within the system subject to the ATO.

  7. A risk response strategy where the organization implements controls to reduce the likelihood or impact of a threat is called:

    Answer: Risk mitigation (risk reduction)

    Risk mitigation involves implementing security controls or countermeasures to reduce either the probability of a threat occurring or its potential impact.