Risk Management & Security Evaluation Flashcards
7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Management & Security Evaluation flashcards as text
Which step of the NIST RMF involves defining the system boundary, identifying stakeholders, and establishing the authorization strategy?
Answer: Prepare
The Prepare step, added in NIST SP 800-37 Rev. 2, establishes organizational and system-level context before the remaining RMF steps begin.
What is the key distinction between a vulnerability and a threat in the context of CAP risk management?
Answer: A vulnerability is a weakness; a threat is a potential cause of harm that exploits it
A vulnerability is a flaw or weakness in a system, while a threat is any circumstance or event with the potential to exploit that vulnerability.
Under CNSSI 1253, which factor primarily drives the selection of security control overlays for national security systems?
Answer: System type, classification level, and operational environment
CNSSI 1253 overlays are driven by system type (e.g., space, weapons), classification level, and specific operational environments requiring tailored controls.
An organization conducts ongoing security monitoring and discovers a new critical vulnerability in a production system. What is the FIRST action the ISSO should take?
Answer: Assess the vulnerability's impact and report it to the AO
The ISSO must first assess impact and report to the AO so that an informed risk decision can be made before any remediation action.
What term describes the process of tailoring a security control baseline by adding controls beyond the baseline to address specific threats or operational requirements?
Answer: Scoping (supplementation)
Supplementation (a form of scoping) adds controls above the baseline when the selected baseline is insufficient for specific threat environments or requirements.
Which of the following BEST describes the concept of 'security control inheritance' in the RMF?
Answer: A system receives security protection from controls implemented by an external provider or shared service
Control inheritance occurs when a system leverages controls implemented and managed by another organizational entity, such as a common control provider or cloud platform.
What is the recommended maximum duration for a federal system's Authorization to Operate (ATO) under NIST SP 800-37?
Answer: 3 years
NIST SP 800-37 recommends ATOs be reviewed at least every three years or whenever significant changes occur to the system or its environment.