โ† All CAP Flashcard Decks

Security Operations & Monitoring Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Operations & Monitoring flashcards as text
  1. What is the role of an Information System Security Officer (ISSO) in ongoing security monitoring?

    Answer: Implementing and maintaining day-to-day security controls

    The ISSO is responsible for the day-to-day implementation and maintenance of security controls within the information system.

  2. A SIEM system correlates events from multiple sources and generates an alert for an attack pattern. What should the analyst do FIRST?

    Answer: Validate the alert to determine if it is a true positive

    Alert validation to confirm it is a true positive (not a false positive) is the first step before taking any remediation action.

  3. Which of the following BEST describes a 'security baseline' in the context of federal information systems?

    Answer: A pre-defined set of security controls for a given impact level

    A security baseline is a pre-defined set of security controls tailored to a system's FIPS 199 impact level (Low, Moderate, High).

  4. Which type of vulnerability scan provides the MOST comprehensive view of security weaknesses on a system?

    Answer: Credentialed internal scan

    Credentialed scans authenticate to the target system and can identify configuration issues, missing patches, and local vulnerabilities that unauthenticated scans miss.

  5. Under FISMA, how frequently must federal agencies report security status to OMB?

    Answer: Annually

    FISMA requires federal agencies to report their information security status to OMB on an annual basis.

  6. What is the PRIMARY difference between a vulnerability and an exploit?

    Answer: A vulnerability is a weakness; an exploit is code or technique that takes advantage of it

    A vulnerability is a weakness in a system, while an exploit is the specific mechanism or code that leverages that weakness to cause harm.

  7. Which activity is part of the 'Monitor' step in the NIST Risk Management Framework?

    Answer: Assessing security control effectiveness on an ongoing basis

    The Monitor step includes ongoing assessment of security control effectiveness, reporting security status, and updating system documentation.