CAP Cheat Sheet 2026
The 30 highest-yield CAP facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
125 questions
180 min time limit
70.00% to pass
- Under FISMA, who is ultimately responsible for accepting the residual risk of operating a federal information system? → Authorizing Official (AO)
- Which of the following helps protect data from loss or corruption? → Performing regular data backups
- Which access control mechanism allows the owner of a resource to grant access to other users at their own discretion? → Discretionary Access Control (DAC)
- What is the purpose of an access control list (ACL)? → To define and enforce access permissions
- A federal system processes both FOUO (For Official Use Only) and publicly releasable information. What is the most appropriate data handling control? → Separate the data with access controls and label all FOUO information appropriately
- What is the importance of staying current with trends in Network Security Fundamentals for Certified Authorization Professional? → It ensures practices remain effective and relevant
- Under Executive Order 14028 (Improving the Nation's Cybersecurity, 2021), federal agencies must adopt which security architecture approach? → Zero Trust Architecture
- Which of the following is a key difference between authentication and authorization? → Authentication verifies identity; authorization determines what actions are permitted
- What is the importance of staying current with trends in Cryptography & Encryption for Certified Authorization Professional? → It ensures practices remain effective and relevant
- A web application verifies that an authenticated user can only access their own account records and not those of other users. This check enforces: → Horizontal access control
- Which cloud security concept ensures that encryption keys are never exposed to the cloud provider in plaintext? → Bring Your Own Key (BYOK)
- Which cryptographic mode of operation provides both confidentiality and authentication in a single pass? → GCM (Galois/Counter Mode)
- A system is categorized as HIGH for confidentiality, MODERATE for integrity, and LOW for availability. What is the overall FIPS 199 categorization? → HIGH
- NIST SP 800-137 defines three tiers for ISCM. Which set correctly identifies these tiers? → Organization, Mission/Business Process, Information System
- Why is a security assessment critical in risk management? → To identify vulnerabilities before exploitation
- In the Bell-LaPadula model, the '*-property' (star property) rule states that a subject: → Cannot write data to a lower classification level
- In asymmetric encryption, which operation is typically performed with the recipient's public key? → Encrypting the plaintext
- A penetration test reveals that a web application stores session tokens in plaintext cookies. Which security principle is most directly violated? → Confidentiality of session data and least privilege for session management
- NIST SP 800-18 provides guidance on which RMF artifact? → System Security Plan development
- NIST SP 800-34 recommends that contingency plans be tested at what minimum frequency? → Annually
- What is the purpose of maintaining a chain of custody during a penetration test on a federal system? → To ensure evidence integrity and accountability for all test artifacts and findings
- A federal agency wants to prioritize which security vulnerabilities to remediate first. Which approach is MOST aligned with risk management principles? → Prioritize based on CVSS score combined with asset criticality and threat context
- Which approach best supports quality outcomes in Network Security Fundamentals for Certified Authorization Professional? → Systematic application of evidence-based methods
- The Children's Online Privacy Protection Act (COPPA) applies to websites collecting personal information from children under what age? → 13
- In a shared responsibility model, who is responsible for patching the hypervisor in an IaaS environment? → The cloud service provider
- Under NIST SP 800-53, which control family directly addresses user provisioning, account types, and least privilege enforcement? → AC – Access Control
- During red team exercises on federal systems, which methodology specifically simulates advanced persistent threat (APT) tactics, techniques, and procedures? → MITRE ATT&CK Framework
- In the context of CAP and the RMF, what does the principle of 'least privilege' require? → Users receive only the minimum access rights necessary to perform their job functions
- What document formally describes the security controls implemented for a federal information system and serves as the primary security planning artifact? → System Security Plan (SSP)
- Under FISMA, which official has the authority to grant an Authorization to Operate (ATO) for a federal information system? → The Authorizing Official (AO), also known as the Designated Accrediting Authority (DAA)
Turn these facts into recall:
Was this helpful?