Exam Code: CAP
Exam name: ISC2 CAP Certified Authorization Professional
Certification: ISC2 Certification
Q261. Which of the following refers to a process that is used for implementing information security?

A. Certification and Accreditation(C&A)

B. Information Assurance (IA)

C. Five Pillars model

D. Classic information security model

Answer: A

Q262. Which of the following NIST documents defines impact?

A. NIST SP 800-53

B. NIST SP 800-26

C. NIST SP 800-30

D. NIST SP 800-53A

Answer: C

Q263. You are the project manager of the GGG project. You have completed the risk identification process for the initial phases of your project. As you begin to document the risk events in the risk register what additional information can you associate with the identified risk events?

A. Risk schedule

B. Risk potential responses

C. Risk cost

D. Risk owner

Answer: B

Q264. Which of the following governance bodies directs and coordinates implementations of the information security program?

A. Information Security Steering Committee

B. Senior Management

C. Business Unit Manager

D. Chief Information Security Officer

Answer: D

Q265. For which of the following reporting requirements are continuous monitoring documentation reports used?





Answer: A

Q266. Which of the following is NOT a type of penetration test?

A. Cursory test

B. Partial-knowledge test

C. Zero-knowledge test

D. Full knowledge test

Answer: A

Q267. Which of the following NIST publications defines impact?

A. NIST SP 800-41

B. NIST SP 800-37

C. NIST SP 800-30

D. NIST SP 800-53

Answer: C

Q268. The Project Risk Management knowledge area focuses on which of the following processes?

Each correct answer represents a complete solution. Choose all that apply.

A. Potential Risk Monitoring

B. Risk Management Planning

C. Quantitative Risk Analysis

D. Risk Monitoring and Control

Answer: BCD

Q269. In which of the following phases do the system security plan update and the Plan of Action and Milestones (POAM) update take place?

A. Continuous Monitoring Phase

B. Accreditation Phase

C. Preparation Phase


Answer: A

Q270. Which of the following DoD directives defines DITSCAP as the standard C&A process for the Department of Defense?

A. DoD 8000.1

B. DoD 5200.40

C. DoD 5200.22-M

D. DoD 8910.1

Answer: B

