What are the subordinate tasks of the Implement and Validate Assigned IA Control phase in the DIACAP process Each correct answer represents a complete solution. Choose all that apply.
Reveal answer details Close answer details
Correct answersB, C, D
ISC · CISSP-ISSEP
Preview real exam questions, verified answers and available explanations before choosing a study plan.
|
Multiple choice
What are the subordinate tasks of the Implement and Validate Assigned IA Control phase in the DIACAP process Each correct answer represents a complete solution. Choose all that apply. Reveal answer details Close answer detailsCorrect answersB, C, D
Single choice
Which of the following security controls works as the totality of protection mechanisms within a computer system, including hardware, firmware, and software, the combination of which is responsible for enforcing a security policy Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following documents is defined as a source document, which is most useful for the ISSE when classifying the needed security functionality Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following certification levels requires the completion of the minimum security checklist and more in-depth, independent analysis Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following federal agencies coordinates, directs, and performs highly specialized activities to protect U.S. information systems and produces foreign intelligence information Reveal answer details Close answer detailsCorrect answerB
Single choice
In which of the following phases of the interconnection life cycle as defined by NIST SP 800-47 does the participating organizations perform the following tasks Perform preliminary activities. Examine all relevant technical, security and administrative issues. Form an agreement governing the management, operation, and use of the interconnection. Reveal answer details Close answer detailsCorrect answerC
Single choice
Which of the following individuals is an upper-level manager who has the power and capability to evaluate the mission, business case, and budgetary needs of the system while also considering the security risks Reveal answer details Close answer detailsCorrect answerD
Single choice
The risk transference is referred to the transfer of risks to a third party, usually for a fee, it creates a contractual-relationship for the third party to manage the risk on behalf of the performing organization. Reveal answer details Close answer detailsCorrect answerD
Single choice
Which of the following acts is used to recognize the importance of information security to the economic and national security interests of the United States Reveal answer details Close answer detailsCorrect answerB
Single choice
FIPS 199 defines the three levels of potential impact on organizations. Which of the following potential impact levels shows limited adverse effects on organizational operations, organizational assets, or individuals Reveal answer details Close answer detailsCorrect answerD
Multiple choice
Which of the following principles are defined by the IATF model Each correct answer represents a complete solution. Choose all that apply. Reveal answer details Close answer detailsCorrect answersB, C, D
Single choice
Which of the following federal laws establishes roles and responsibilities for information security, risk management, testing, and training, and authorizes NIST and NSA to provide guidance for security planning and implementation Reveal answer details Close answer detailsCorrect answerB
Single choice
Which of the following individuals is responsible for monitoring the information system environment for factors that can negatively impact the security of the system and its accreditation Reveal answer details Close answer detailsCorrect answerD
Single choice
Which of the following is a standard that sets basic requirements for assessing the effectiveness of computer security controls built into a computer system Reveal answer details Close answer detailsCorrect answerB
Single choice
Which of the of following departments protects and supports DoD information, information systems, and information networks that are critical to the department and the armed forces during the day-to-day operations, and in the time of crisis Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following phases of DITSCAP includes the activities that are necessary for the continuing operation of an accredited IT system in its computing environment and for addressing the changing threats that a system faces throughout its life cycle Reveal answer details Close answer detailsCorrect answerC
Single choice
Which of the following organizations assists the President in overseeing the preparation of the federal budget and to supervise its administration in Executive Branch agencies Reveal answer details Close answer detailsCorrect answerB
Single choice
Which of the following Registration Tasks notifies the DAA, Certifier, and User Representative that the system requires C&A Support Reveal answer details Close answer detailsCorrect answerD
Single choice
Which of the following federal agencies has the objective to develop and promote measurement, standards, and technology to enhance productivity, facilitate trade, and improve the quality of life Reveal answer details Close answer detailsCorrect answerA
Single choice
You work as a systems engineer for BlueWell Inc. You are working on translating system requirements into detailed function criteria. Which of the following diagrams will help you to show all of the function requirements and their groupings in one diagram Reveal answer details Close answer detailsCorrect answerC
Single choice
Which of the following laws is the first to implement penalties for the creator of viruses, worms, and other types of malicious code that causes harm to the computer systems Reveal answer details Close answer detailsCorrect answerA
Multiple choice
According to U.S. Department of Defense (DoD) Instruction 8500.2, there are eight Information Assurance (IA) areas, and the controls are referred to as IA controls. Which of the following are among the eight areas of IA defined by DoD Each correct answer represents a complete solution. Choose all that apply. Reveal answer details Close answer detailsCorrect answersA, B, C
Single choice
Stella works as a system engineer for BlueWell Inc. She wants to identify the performance thresholds of each build. Which of the following tests will help Stella to achieve her task Reveal answer details Close answer detailsCorrect answerD
Single choice
Part of your change management plan details what should happen in the change control system for your project. Theresa, a junior project manager, asks what the configuration management activities are for scope changes. You tell her that all of the following are valid configuration management activities except for which one Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following refers to an information security document that is used in the United States Department of Defense (DoD) to describe and accredit networks and systems Reveal answer details Close answer detailsCorrect answerA
Single choice
Your project has several risks that may cause serious financial impact should they happen. You have studied the risk events and made some potential risk responses for the risk events but management wants you to do more. They'd like for you to create some type of a chart that identified the risk probability and impact with a financial amount for each risk event. What is the likely outcome of creating this type of chart Reveal answer details Close answer detailsCorrect answerD
Single choice
Which of the following types of firewalls increases the security of data packets by remembering the state of connection at the network and the session layers as they pass through the filter Reveal answer details Close answer detailsCorrect answerC
Single choice
You are working as a project manager in your organization. You are nearing the final stages of project execution and looking towards the final risk monitoring and controlling activities. For your project archives, which one of the following is an output of risk monitoring and control Reveal answer details Close answer detailsCorrect answerC
Single choice
Which of the following types of CNSS issuances establishes criteria, and assigns responsibilities Reveal answer details Close answer detailsCorrect answerD
Single choice
You work as a security engineer for BlueWell Inc. Which of the following documents will you use as a guide for the security certification and accreditation of Federal Information Systems Reveal answer details Close answer detailsCorrect answerB
Multiple choice
A security policy is an overall general statement produced by senior management that dictates what role security plays within the organization. Which of the following are required to be addressed in a well designed policy Each correct answer represents a part of the solution. Choose all that apply. Reveal answer details Close answer detailsCorrect answersA, B, C
Single choice
Which of the following elements of Registration task 4 defines the operating system, database management system, and software applications, and how they will be used Reveal answer details Close answer detailsCorrect answerC |