โ† All CAP Flashcard Decks

Security Operations & Monitoring Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Operations & Monitoring flashcards as text
  1. An organization receives an alert that a critical server is communicating with a known malicious IP address. What is the MOST appropriate immediate containment action?

    Answer: Isolate the server from the network while preserving forensic evidence

    Network isolation stops ongoing communication with the attacker while preserving evidence needed for forensic investigation.

  2. What does the concept of 'defense in depth' mean in the context of security operations?

    Answer: Layering multiple security controls so that failure of one does not compromise the system

    Defense in depth uses multiple overlapping security layers so that if one control fails, others continue to protect the system.

  3. Which document formally describes the security requirements and controls for a specific information system?

    Answer: System Security Plan (SSP)

    The System Security Plan (SSP) formally describes the system boundary, environment, security requirements, and implemented controls.

  4. A federal agency wants to prioritize which security vulnerabilities to remediate first. Which approach is MOST aligned with risk management principles?

    Answer: Prioritize based on CVSS score combined with asset criticality and threat context

    Risk-based prioritization considers both the severity of the vulnerability (CVSS) and the criticality of the affected asset and threat likelihood.

  5. What is the purpose of a 'threat intelligence feed' in security monitoring operations?

    Answer: Provide current information on attacker tactics, indicators of compromise, and emerging threats

    Threat intelligence feeds provide timely information about adversary tactics, techniques, procedures (TTPs), and indicators that help detect and respond to threats.

  6. Which NIST publication specifically addresses the implementation of an Information Security Continuous Monitoring (ISCM) program?

    Answer: NIST SP 800-137

    NIST SP 800-137 provides guidance for building and maintaining an Information Security Continuous Monitoring (ISCM) program.

  7. In a federal environment, who has the authority to formally accept residual risk and grant an Authorization to Operate (ATO)?

    Answer: Authorizing Official (AO)

    The Authorizing Official (AO) is the senior official with authority to formally accept residual risk and issue an Authorization to Operate.