← All CAP Flashcard Decks

Mixed Deck — All CAP Topics Flashcards

100 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All CAP Topics flashcards as text
  1. Under the Privacy Act of 1974, what is a 'system of records'?

    Answer: A group of records under agency control from which information is retrieved by personal identifier

    A Privacy Act system of records is a group of records under an agency's control from which information is retrieved by name, SSN, or other personal identifier.

  2. Why is multifactor authentication (MFA) important for access control?

    Answer: It adds an extra layer of authentication

    Multifactor authentication (MFA) is crucial for access control because it significantly enhances security by requiring users to provide two or more distinct verification factors. This means that even if one factor, such as a password, is compromised, an attacker would still need the second factor (e.g., a code from a phone or a fingerprint) to gain access. This additional layer makes it much harder for unauthorized individuals to breach accounts, thereby protecting sensitive information.

  3. During incident response, what is the primary purpose of a chain of custody document?

    Answer: To ensure evidence integrity and admissibility

    Chain of custody documents track who handled evidence and when, ensuring its integrity and legal admissibility.

  4. A system architect needs to protect data that remains sensitive even after the system is decommissioned. Which control addresses this long-term concern?

    Answer: Media sanitization procedures

    Media sanitization (e.g., per NIST SP 800-88) ensures data cannot be recovered after system decommissioning.

  5. In the context of the CAP framework, what does 'defense-in-depth' mean for network security?

    Answer: Layering multiple security controls so no single failure exposes assets

    Defense-in-depth means implementing multiple overlapping security layers so that a failure in one control does not leave systems unprotected.

  6. Which vulnerability scoring system is MOST commonly referenced in threat intelligence to prioritize remediation efforts?

    Answer: CVSS (Common Vulnerability Scoring System)

    CVSS provides standardized numerical scores (0-10) for vulnerability severity, widely used across the industry to prioritize patching and risk treatment.

  7. What is the primary difference between quantitative and qualitative risk analysis methods?

    Answer: Quantitative assigns numeric values to risk; qualitative uses descriptive categories like High/Medium/Low

    Quantitative risk analysis uses numerical values (e.g., dollar amounts, probabilities) while qualitative analysis uses descriptive scales to rank risk levels.

  8. Which security architecture principle ensures that a compromised component cannot affect the security of the entire system?

    Answer: Compartmentalization

    Compartmentalization isolates system components so a breach in one area does not propagate to others.

  9. How does collaboration enhance Cryptography & Encryption in Certified Authorization Professional?

    Answer: It brings diverse perspectives and improves outcomes

    Collaboration brings together different viewpoints and expertise, leading to better decision-making and outcomes.

  10. What is the importance of staying current with trends in Incident Response & Recovery for Certified Authorization Professional?

    Answer: It ensures practices remain effective and relevant

    Staying current with industry trends ensures that professional practices remain effective, relevant, and aligned with evolving standards.

  11. In a zero trust architecture, what is the default access posture for any user or device attempting to connect to a resource?

    Answer: Denied until explicitly verified and authorized

    Zero trust assumes no implicit trust — every access request must be explicitly verified and authorized regardless of network location.

  12. Which process reviews and validates that user access rights remain appropriate and aligned with job responsibilities?

    Answer: Access recertification (access review)

    Access recertification (also called periodic access review) ensures that user permissions are still necessary and appropriate, and removes stale or excess access.

  13. A system security plan (SSP) is required under which regulatory mandate for federal agencies?

    Answer: FISMA

    FISMA requires federal agencies to develop and maintain an SSP that describes the security requirements of the system and the controls in place to meet those requirements.

  14. What is the primary purpose of a Hash-based Message Authentication Code (HMAC)?

    Answer: To provide both data integrity and authentication using a shared secret

    HMAC combines a cryptographic hash function with a secret key to verify both the integrity and authenticity of a message.

  15. Which element must be included in a POA&M entry to satisfy FISMA reporting requirements?

    Answer: Source of the weakness, scheduled completion date, and responsible point of contact

    FISMA-compliant POA&M entries must document the weakness source (e.g., assessment, audit), scheduled remediation date, and the responsible individual or office accountable for closure.

  16. What is a fundamental principle of Security Operations & Monitoring in Certified Authorization Professional practice?

    Answer: Following established standards and best practices

    Following established standards and best practices ensures quality and consistency in Security Operations & Monitoring.

  17. A risk response strategy where the organization implements controls to reduce the likelihood or impact of a threat is called:

    Answer: Risk mitigation (risk reduction)

    Risk mitigation involves implementing security controls or countermeasures to reduce either the probability of a threat occurring or its potential impact.

  18. An organization implements Just-in-Time (JIT) privileged access, where elevated rights are granted only for the duration of an approved task. This practice primarily supports which security principle?

    Answer: Least privilege

    JIT access directly implements least privilege by ensuring elevated rights exist only as long as operationally necessary.

  19. A federal system is categorized as MODERATE impact. Which NIST SP 800-53 security control baseline should be applied as the starting point?

    Answer: The MODERATE baseline.

    NIST SP 800-53 defines three control baselines (LOW, MODERATE, HIGH) aligned to FIPS 199 impact levels. A MODERATE-categorized system uses the MODERATE baseline as its starting point before any tailoring.

  20. A CAP candidate is reviewing a continuous monitoring plan. Which metric best indicates the health of the identity and access management program over time?

    Answer: Percentage of accounts reviewed and recertified within defined timeframes

    Tracking recertification completion rates directly measures how well the organization maintains appropriate access controls over time.