ISC CAP Exam Practice Questions (P. 1)
- Full Access (395 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
Which of the following professionals plays the role of a monitor and takes part in the organization's configuration management process?
- ASenior Agency Information Security OfficerMost Voted
- BAuthorizing Official
- CCommon Control Provider
- DChief Information Officer
Correct Answer:
C
C
send
light_mode
delete
Question #2
The Chief Information Officer (CIO), or Information Technology (IT) director, is a job title commonly given to the most senior executive in an enterprise. What are the responsibilities of a Chief Information Officer?
Each correct answer represents a complete solution. Choose all that apply.
Each correct answer represents a complete solution. Choose all that apply.
- APreserving high-level communications and working group relationships in an organization
- BFacilitating the sharing of security risk-related information among authorizing officials
- CEstablishing effective continuous monitoring program for the organization
- DProposing the information technology needed by an enterprise to achieve its goals and then working within a budget to implement the plan
Correct Answer:
ACD
ACD
send
light_mode
delete
Question #3
The Information System Security Officer (ISSO) and Information System Security Engineer (ISSE) play the role of a supporter and advisor, respectively. Which of the following statements are true about ISSO and ISSE?
Each correct answer represents a complete solution. Choose all that apply.
Each correct answer represents a complete solution. Choose all that apply.
- AAn ISSE provides advice on the impacts of system changes.
- BAn ISSE manages the security of the information system that is slated for Certification & Accreditation (C&A).
- CAn ISSO manages the security of the information system that is slated for Certification & Accreditation (C&A).
- DAn ISSO takes part in the development activities that are required to implement system changes.
- EAn ISSE provides advice on the continuous monitoring of the information system.
Correct Answer:
ACE
ACE
send
light_mode
delete
Question #4
Which of the following professionals is responsible for starting the Certification & Accreditation (C&A) process?
- AInformation system owner
- BAuthorizing Official
- CChief Risk Officer (CRO)
- DChief Information Officer (CIO)
Correct Answer:
A
A
send
light_mode
delete
Question #5
Which of the following assessment methodologies defines a six-step technical security evaluation?
send
light_mode
delete
Question #6
DIACAP applies to the acquisition, operation, and sustainment of any DoD system that collects, stores, transmits, or processes unclassified or classified information since December 1997. What phases are identified by DIACAP?
Each correct answer represents a complete solution. Choose all that apply.
Each correct answer represents a complete solution. Choose all that apply.
- AAccreditation
- BIdentification
- CSystem Definition
- DVerification
- EValidation
- FRe-Accreditation
Correct Answer:
CDEF
CDEF
send
light_mode
delete
Question #7
Mark works as a Network Administrator for NetTech Inc. He wants users to access only those resources that are required for them. Which of the following access control models will he use?
- AMandatory Access Control
- BRole-Based Access Control
- CDiscretionary Access Control
- DPolicy Access Control
Correct Answer:
B
B
send
light_mode
delete
Question #8
Which of the following refers to an information security document that is used in the United States Department of Defense (DoD) to describe and accredit networks and systems?
send
light_mode
delete
Question #9
James work as an IT systems personnel in SoftTech Inc. He performs the following tasks:
Runs regular backups and routine tests of the validity of the backup data.
Performs data restoration from the backups whenever required.
Maintains the retained records in accordance with the established information classification policy.
What is the role played by James in the organization?
Runs regular backups and routine tests of the validity of the backup data.
Performs data restoration from the backups whenever required.
Maintains the retained records in accordance with the established information classification policy.
What is the role played by James in the organization?
send
light_mode
delete
Question #10
FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for assessing the security of information systems. Which of the following FITSAF levels shows that the procedures and controls have been implemented?
send
light_mode
delete
All Pages