โ† All CAP Flashcard Decks

Security Operations & Monitoring Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Operations & Monitoring flashcards as text
  1. What is the MAIN purpose of network traffic baselining in a security monitoring program?

    Answer: To establish normal traffic patterns so anomalies can be detected

    Baselining normal network traffic patterns allows security teams to identify deviations that may indicate malicious activity.

  2. A security control is found to be 'not applicable' during an assessment. What is the CORRECT action?

    Answer: Document the rationale for non-applicability and seek AO approval if required

    Controls that are not applicable must have documented rationale, and the AO may need to formally accept the non-applicability determination.

  3. Which type of security assessment methodology involves testing without prior knowledge of the system's internal architecture?

    Answer: Black-box testing

    Black-box testing simulates an external attacker who has no prior knowledge of the system's internal structure or configurations.

  4. Which security principle ensures that users only have access to information and systems necessary to perform their job functions?

    Answer: Least privilege

    The principle of least privilege limits user access rights to the minimum necessary to perform assigned job functions.

  5. An Authorizing Official reviews a system and determines that residual risks are too high to grant an ATO. What authorization decision can the AO make instead?

    Answer: Denial of Authorization to Operate (DATO)

    When residual risks are unacceptable, the AO issues a Denial of Authorization to Operate (DATO), preventing the system from processing federal information.

  6. What does 'mean time to respond' (MTTR) measure in a security operations context?

    Answer: Average time from incident detection to containment or resolution

    MTTR measures the average elapsed time from when a security incident is detected to when it is contained or resolved.

  7. Which of the following is an example of a DETECTIVE security control in an operational environment?

    Answer: Intrusion Detection System (IDS)

    An IDS is a detective control because it identifies and alerts on potential malicious activity rather than preventing or correcting it.