ISC CAP Exam Practice Questions (P. 3)
- Full Access (395 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #21
Where can a project manager find risk-rating rules?
- ARisk probability and impact matrix
- BOrganizational process assets
- CEnterprise environmental factors
- DRisk management plan
Correct Answer:
B
B
send
light_mode
delete
Question #22
There are five inputs to the quantitative risk analysis process. Which one of the following is NOT an input to the perform quantitative risk analysis process?
- ARisk register
- BCost management plan
- CRisk management plan
- DEnterprise environmental factors
Correct Answer:
D
D
send
light_mode
delete
Question #23
Your project has several risks that may cause serious financial impact should they happen. You have studied the risk events and made some potential risk responses for the risk events but management wants you to do more. They'd like for you to create some type of a chart that identified the risk probability and impact with a financial amount for each risk event. What is the likely outcome of creating this type of chart?
- ARisk response plan
- BQuantitative analysis
- CRisk response
- DContingency reserve
Correct Answer:
D
D
send
light_mode
delete
Question #24
Which of the following professionals is responsible for starting the Certification & Accreditation
(C&A) process?
(C&A) process?
- AAuthorizing Official
- BChief Risk Officer (CRO)
- CChief Information Officer (CIO)
- DInformation system owner
Correct Answer:
D
D
send
light_mode
delete
Question #25
You are working as a project manager in your organization. You are nearing the final stages of project execution and looking towards the final risk monitoring and controlling activities. For your project archives, which one of the following is an output of risk monitoring and control?
- AQuantitative risk analysis
- BQualitative risk analysis
- CRequested changes
- DRisk audits
Correct Answer:
C
C
send
light_mode
delete
Question #26
Which of the following DoD directives is referred to as the Defense Automation Resources Management Manual?
send
light_mode
delete
Question #27
The phase 3 of the Risk Management Framework (RMF) process is known as mitigation planning.
Which of the following processes take place in phase 3?
Each correct answer represents a complete solution. Choose all that apply.
Which of the following processes take place in phase 3?
Each correct answer represents a complete solution. Choose all that apply.
- AIdentify threats, vulnerabilities, and controls that will be evaluated.
- BDocument and implement a mitigation plan.
- CAgree on a strategy to mitigate risks.
- DEvaluate mitigation progress and plan next assessment.
Correct Answer:
BCD
BCD
send
light_mode
delete
Question #28
Gary is the project manager of his organization. He is managing a project that is similar to a project his organization completed recently. Gary has decided that he will use the information from the past project to help him and the project team to identify the risks that may be present in the project. Management agrees that this checklist approach is ideal and will save time in the project. Which of the following statement is most accurate about the limitations of the checklist analysis approach for Gary?
- AThe checklist analysis approach is fast but it is impossible to build and exhaustive checklist.
- BThe checklist analysis approach only uses qualitative analysis.
- CThe checklist analysis approach saves time, but can cost more.
- DThe checklist is also known as top down risk assessment
Correct Answer:
A
A
send
light_mode
delete
Question #29
What are the subordinate tasks of the Initiate and Plan IA C&A phase of the DIACAP process?
Each correct answer represents a complete solution. Choose all that apply.
Each correct answer represents a complete solution. Choose all that apply.
- ADevelop DIACAP strategy.
- BAssign IA controls.
- CAssemble DIACAP team.
- DInitiate IA implementation plan.
- ERegister system with DoD Component IA Program.
- FConduct validation activity.
Correct Answer:
ABCDE
ABCDE
send
light_mode
delete
Question #30
Information risk management (IRM) is the process of identifying and assessing risk, reducing it to an acceptable level, and implementing the right mechanisms to maintain that level. What are the different categories of risk?
Each correct answer represents a complete solution. Choose all that apply.
Each correct answer represents a complete solution. Choose all that apply.
- ASystem interaction
- BHuman interaction
- CEquipment malfunction
- DInside and outside attacks
- ESocial status
- FPhysical damage
Correct Answer:
BCDEF
BCDEF
send
light_mode
delete
All Pages