← All CAP Flashcard Decks

Risk Management & Security Evaluation Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Management & Security Evaluation flashcards as text
  1. Which NIST publication provides guidance on conducting risk assessments and is used to support the RMF Categorize and Assess steps?

    Answer: NIST SP 800-30

    NIST SP 800-30 ('Guide for Conducting Risk Assessments') provides the methodology for identifying, analyzing, and communicating risk to organizational operations.

  2. A security assessor uses penetration testing during a control assessment. Under NIST SP 800-53A, this technique is classified as which assessment method?

    Answer: Test

    NIST SP 800-53A defines three assessment methods — examine, interview, and test — with penetration testing classified under the 'test' method.

  3. Which authorization decision type allows a system to operate temporarily while known weaknesses are remediated, typically with strict conditions and a deadline?

    Answer: Authorization to Operate with Conditions (ATOC)

    An ATOC (or conditional ATO) permits operation despite identified weaknesses, provided the system owner meets specified conditions and remediation timelines.

  4. What is the primary difference between quantitative and qualitative risk analysis methods?

    Answer: Quantitative assigns numeric values to risk; qualitative uses descriptive categories like High/Medium/Low

    Quantitative risk analysis uses numerical values (e.g., dollar amounts, probabilities) while qualitative analysis uses descriptive scales to rank risk levels.

  5. Under FISMA and OMB policy, which type of federal system requires a Privacy Impact Assessment (PIA)?

    Answer: Systems that collect, maintain, or disseminate personally identifiable information (PII)

    OMB Memorandum M-03-22 requires PIAs for federal systems that collect, maintain, or disseminate PII to evaluate privacy risks and protections.

  6. A system that stores Social Security Numbers and health records is being categorized. Which NIST publication maps information types to impact levels to support FIPS 199 categorization?

    Answer: NIST SP 800-60

    NIST SP 800-60 maps federal information and information system types to security impact levels for use in FIPS 199 categorization.

  7. What is the purpose of the 'Deny by Default' principle in the context of least privilege and access control risk management?

    Answer: All access is denied unless explicitly granted, reducing the attack surface

    Deny by default means no access is permitted unless explicitly authorized, ensuring that only necessary permissions are granted and reducing exposure to unauthorized access.