← All CAP Flashcard Decks

Risk Management & Security Evaluation Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Management & Security Evaluation flashcards as text
  1. Which NIST publication provides the primary framework for federal information security risk management using the Risk Management Framework (RMF)?

    Answer: NIST SP 800-37

    NIST SP 800-37 defines the RMF and its six steps (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor) for federal systems.

  2. During a security assessment, an assessor discovers that a control is partially implemented. How should this finding be recorded in the Security Assessment Report (SAR)?

    Answer: As 'Other Than Satisfied' with documented weaknesses

    A partially implemented control is recorded as 'Other Than Satisfied' in the SAR, with the specific weaknesses and deficiencies documented.

  3. What is the primary purpose of a Plan of Action and Milestones (POA&M)?

    Answer: To document and track remediation of security weaknesses identified during assessment

    A POA&M documents identified weaknesses, assigns responsibility, and establishes scheduled milestones for corrective action.

  4. Under FISMA, who is ultimately responsible for accepting the residual risk of operating a federal information system?

    Answer: Authorizing Official (AO)

    The Authorizing Official (AO) bears ultimate responsibility for accepting residual risk by signing the Authorization to Operate (ATO).

  5. Which risk response strategy involves transferring potential loss to a third party, such as through cyber insurance?

    Answer: Risk Transference

    Risk transference shifts financial or operational consequences of a risk to another party, such as an insurer or cloud service provider.

  6. What document formally describes the security controls implemented for a federal information system and serves as the primary security planning artifact?

    Answer: System Security Plan (SSP)

    The System Security Plan (SSP) is the primary document describing security requirements and the controls in place or planned for a system.

  7. A system is categorized as HIGH for confidentiality, MODERATE for integrity, and LOW for availability. What is the overall FIPS 199 categorization?

    Answer: HIGH

    FIPS 199 uses the 'high water mark' principle — the overall system categorization equals the highest impact level across all three security objectives.