CAP Cheat Sheet 2026

The 30 highest-yield CAP facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

125 questions
180 min time limit
70.00% to pass
  1. Under FISMA, who is ultimately responsible for accepting the residual risk of operating a federal information system? Authorizing Official (AO)
  2. Which of the following helps protect data from loss or corruption? Performing regular data backups
  3. Which access control mechanism allows the owner of a resource to grant access to other users at their own discretion? Discretionary Access Control (DAC)
  4. What is the purpose of an access control list (ACL)? To define and enforce access permissions
  5. A federal system processes both FOUO (For Official Use Only) and publicly releasable information. What is the most appropriate data handling control? Separate the data with access controls and label all FOUO information appropriately
  6. What is the importance of staying current with trends in Network Security Fundamentals for Certified Authorization Professional? It ensures practices remain effective and relevant
  7. Under Executive Order 14028 (Improving the Nation's Cybersecurity, 2021), federal agencies must adopt which security architecture approach? Zero Trust Architecture
  8. Which of the following is a key difference between authentication and authorization? Authentication verifies identity; authorization determines what actions are permitted
  9. What is the importance of staying current with trends in Cryptography & Encryption for Certified Authorization Professional? It ensures practices remain effective and relevant
  10. A web application verifies that an authenticated user can only access their own account records and not those of other users. This check enforces: Horizontal access control
  11. Which cloud security concept ensures that encryption keys are never exposed to the cloud provider in plaintext? Bring Your Own Key (BYOK)
  12. Which cryptographic mode of operation provides both confidentiality and authentication in a single pass? GCM (Galois/Counter Mode)
  13. A system is categorized as HIGH for confidentiality, MODERATE for integrity, and LOW for availability. What is the overall FIPS 199 categorization? HIGH
  14. NIST SP 800-137 defines three tiers for ISCM. Which set correctly identifies these tiers? Organization, Mission/Business Process, Information System
  15. Why is a security assessment critical in risk management? To identify vulnerabilities before exploitation
  16. In the Bell-LaPadula model, the '*-property' (star property) rule states that a subject: Cannot write data to a lower classification level
  17. In asymmetric encryption, which operation is typically performed with the recipient's public key? Encrypting the plaintext
  18. A penetration test reveals that a web application stores session tokens in plaintext cookies. Which security principle is most directly violated? Confidentiality of session data and least privilege for session management
  19. NIST SP 800-18 provides guidance on which RMF artifact? System Security Plan development
  20. NIST SP 800-34 recommends that contingency plans be tested at what minimum frequency? Annually
  21. What is the purpose of maintaining a chain of custody during a penetration test on a federal system? To ensure evidence integrity and accountability for all test artifacts and findings
  22. A federal agency wants to prioritize which security vulnerabilities to remediate first. Which approach is MOST aligned with risk management principles? Prioritize based on CVSS score combined with asset criticality and threat context
  23. Which approach best supports quality outcomes in Network Security Fundamentals for Certified Authorization Professional? Systematic application of evidence-based methods
  24. The Children's Online Privacy Protection Act (COPPA) applies to websites collecting personal information from children under what age? 13
  25. In a shared responsibility model, who is responsible for patching the hypervisor in an IaaS environment? The cloud service provider
  26. Under NIST SP 800-53, which control family directly addresses user provisioning, account types, and least privilege enforcement? AC – Access Control
  27. During red team exercises on federal systems, which methodology specifically simulates advanced persistent threat (APT) tactics, techniques, and procedures? MITRE ATT&CK Framework
  28. In the context of CAP and the RMF, what does the principle of 'least privilege' require? Users receive only the minimum access rights necessary to perform their job functions
  29. What document formally describes the security controls implemented for a federal information system and serves as the primary security planning artifact? System Security Plan (SSP)
  30. Under FISMA, which official has the authority to grant an Authorization to Operate (ATO) for a federal information system? The Authorizing Official (AO), also known as the Designated Accrediting Authority (DAA)
Turn these facts into recall:
Was this helpful?