ISC cap practice test

Certified Authorization Professional Exam

Last exam update: Dec 14 ,2024
Page 1 out of 27. Viewing questions 1-15 out of 395

Question 1

Which of the following statements correctly describes DIACAP residual risk?
A. It is the remaining risk to the information system after risk palliation has occurred.
B. It is a process of security authorization.
C. It is the technical implementation of the security design.
D. It is used to validate the information system.

Mark Question:
Answer:

A

Discussions
0 / 1000

Question 2

Which of the following is a standard that sets basic requirements for assessing the effectiveness of
computer security controls built into a computer system?

  • A. TCSEC
  • B. FIPS
  • C. SSAA
  • D. FITSAF
Mark Question:
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 3

A security policy is an overall general statement produced by senior management that dictates what
role security plays within the organization. What are the different types of policies?
Each correct answer represents a complete solution. Choose all that apply.

  • A. Systematic
  • B. Regulatory
  • C. Advisory
  • D. Informative
Mark Question:
Answer:

B,C,D

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 4

Which of the following processes is a structured approach to transitioning individuals, teams, and
organizations from a current state to a desired future state?

  • A. Configuration management
  • B. Procurement management
  • C. Change management
  • D. Risk management
Mark Question:
Answer:

C

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 5

Which of the following is used to indicate that the software has met a defined quality level and is
ready for mass distribution either by electronic means or by physical media?

  • A. DAA
  • B. RTM
  • C. ATM
  • D. CRO
Mark Question:
Answer:

B

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 6

Which of the following statements about Discretionary Access Control List (DACL) is true?

  • A. It is a rule list containing access control entries.
  • B. It specifies whether an audit activity should be performed when an object attempts to access a resource.
  • C. It is a list containing user accounts, groups, and computers that are allowed (or denied) access to the object.
  • D. It is a unique number that identifies a user, group, and computer account
Mark Question:
Answer:

C

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 7

During qualitative risk analysis you want to define the risk urgency assessment. All of the following
are indicators of risk priority except for which one?

  • A. Symptoms
  • B. Cost of the project
  • C. Warning signs
  • D. Risk rating
Mark Question:
Answer:

B

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 8

During which of the following processes, probability and impact matrix is prepared?

  • A. Plan Risk Responses
  • B. Perform Quantitative Risk Analysis
  • C. Perform Qualitative Risk Analysis
  • D. Monitoring and Control Risks
Mark Question:
Answer:

C

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 9

Walter is the project manager of a large construction project. He'll be working with several vendors
on the project. Vendors will be providing materials and labor for several parts of the project. Some of
the works in the project are very dangerous so Walter has implemented safety requirements for all
of the vendors and his own project team. Stakeholders for the project have added new requirements,
which have caused new risks in the project. A vendor has identified a new risk that could affect the
project if it comes into fruition. Walter agrees with the vendor and has updated the risk register and
created potential risk responses to mitigate the risk. What should Walter also update in this scenario
considering the risk event?

  • A. Project contractual relationship with the vendor
  • B. Project communications plan
  • C. Project management plan
  • D. Project scope statement
Mark Question:
Answer:

C

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 10

Which of the following is NOT an objective of the security program?

  • A. Security organization
  • B. Security plan
  • C. Security education
  • D. Information classification
Mark Question:
Answer:

B

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 11

In 2003, NIST developed a new Certification & Accreditation (C&A) guideline known as FIPS 199.
What levels of potential impact are defined by FIPS 199?
Each correct answer represents a complete solution. Choose all that apply.

  • A. Low
  • B. Moderate
  • C. High
  • D. Medium
Mark Question:
Answer:

A,C,D

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 12

An authentication method uses smart cards as well as usernames and passwords for authentication.
Which of the following authentication methods is being referred to?

  • A. Anonymous
  • B. Multi-factor
  • C. Biometrics
  • D. Mutual
Mark Question:
Answer:

B

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 13

You work as a project manager for BlueWell Inc. There has been a delay in your project work that is
adversely affecting the project schedule. You decided, with your stakeholders' approval, to fast track
the project work to get the project done faster. When you fast track the project which of the
following are likely to increase?

  • A. Risks
  • B. Human resource needs
  • C. Quality control concerns
  • D. Costs
Mark Question:
Answer:

A

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 14

Which of the following RMF phases is known as risk analysis?

  • A. Phase 0
  • B. Phase 1
  • C. Phase 2
  • D. Phase 3
Mark Question:
Answer:

C

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000

Question 15

Which one of the following is the only output for the qualitative risk analysis process?

  • A. Enterprise environmental factors
  • B. Project management plan
  • C. Risk register updates
  • D. Organizational process assets
Mark Question:
Answer:

C

User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
vote your answer:
A
B
C
D
0 / 1000
To page 2