CAP: Certified Authorization Professional — Free Practice Questions
10 free sample questions from a bank of 10, with the correct answers and explanations. No signup required — start practising right now.
1Which of the following professionals plays the role of a monitor and takes part in the organization's configuration management process?
Senior Agency Information Security Officer
Authorizing Official
Common Control Provider
Chief Information Officer
Answer: C
2The Chief Information Officer (CIO), or Information Technology (IT) director, is a job title commonly given to the most senior executive in an enterprise. What are
the responsibilities of a Chief Information Officer?
Each correct answer represents a complete solution. Choose all that apply.
Preserving high-level communications and working group relationships in an organization
Facilitating the sharing of security risk-related information among authorizing officials
Establishing effective continuous monitoring program for the organization
Proposing the information technology needed by an enterprise to achieve its goals and then working within a budget to implement the plan
Answer: A, C, D
3The Information System Security Officer (ISSO) and Information System Security Engineer (ISSE) play the role of a supporter and advisor, respectively. Which of
the following statements are true about ISSO and ISSE?
Each correct answer represents a complete solution. Choose all that apply.
An ISSE provides advice on the impacts of system changes.
An ISSE manages the security of the information system that is slated for Certification & Accreditation (C&A).
An ISSO manages the security of the information system that is slated for Certification & Accreditation (C&A).
An ISSO takes part in the development activities that are required to implement system changes.
An ISSE provides advice on the continuous monitoring of the information system.
Answer: A, C, E
4Which of the following professionals is responsible for starting the Certification & Accreditation (C&A) process?
Information system owner
Authorizing Official
Chief Risk Officer (CRO)
Chief Information Officer (CIO)
Answer: A
5Which of the following assessment methodologies defines a six-step technical security evaluation?
FITSAF
FIPS 102
OCTAVE
DITSCAP
Answer: B
6DIACAP applies to the acquisition, operation, and sustainment of any DoD system that collects, stores, transmits, or processes unclassified or classified
information since December 1997. What phases are identified by DIACAP?
Each correct answer represents a complete solution. Choose all that apply.
Accreditation
Identification
System Definition
Verification
Validation
Re-Accreditation
Answer: C, D, E, F
7Mark works as a Network Administrator for NetTech Inc. He wants users to access only those resources that are required for them. Which of the following access
control models will he use?
Mandatory Access Control
Role-Based Access Control
Discretionary Access Control
Policy Access Control
Answer: B
8Which of the following refers to an information security document that is used in the United States Department of Defense (DoD) to describe and accredit networks
and systems?
FITSAF
FIPS
TCSEC
SSAA
Answer: D
9James work as an IT systems personnel in SoftTech Inc. He performs the following tasks:
Runs regular backups and routine tests of the validity of the backup data.
Performs data restoration from the backups whenever required.
Maintains the retained records in accordance with the established information classification policy.
What is the role played by James in the organization?
Manager
Owner
Custodian
User
Answer: C
10FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for assessing the security of information systems. Which
of the following FITSAF levels shows that the procedures and controls have been implemented?