CAP Security Controls and Authorization 1 — Questions and Answers
Question 1: What are the three security control baselines defined in NIST SP 800-53B?
- Basic, Intermediate, Advanced
- Low, Moderate, High (Correct answer)
- Tier 1, Tier 2, Tier 3
- Minimal, Standard, Enhanced
Correct answer: Low, Moderate, High
NIST SP 800-53B defines Low, Moderate, and High baselines corresponding to the FIPS 199 impact categories.
Question 2: Which security control family in NIST SP 800-53 addresses access control?
- AC (Correct answer)
- AU
- CA
- CM
Correct answer: AC
The AC (Access Control) family contains controls governing who can access systems, data, and functions.
Question 3: Control tailoring in NIST SP 800-53 allows organizations to do which of the following?
- Remove all baseline controls
- Adjust baseline controls to meet specific operational needs (Correct answer)
- Add only compensating controls
- Ignore privacy controls
Correct answer: Adjust baseline controls to meet specific operational needs
Tailoring lets organizations add, remove, or modify baseline controls to fit their unique environment and risk tolerance.
Question 4: Which NIST SP 800-53 control family specifically addresses audit and accountability?
- AT
- AU (Correct answer)
- CA
- IR
Correct answer: AU
The AU (Audit and Accountability) family includes controls for logging, audit record retention, and review of audit logs.
Question 5: What is a compensating security control?
- A control that replaces all other controls
- An alternative control providing equivalent protection when the primary control cannot be implemented (Correct answer)
- A control applied only to high-impact systems
- A control mandated by FISMA
Correct answer: An alternative control providing equivalent protection when the primary control cannot be implemented
A compensating control provides an equivalent level of protection when the baseline control is not feasible to implement as specified.
Question 6: In the context of authorization, what does 'security control inheritance' mean?
- A child system adopts the risk decisions of a parent system
- A system leverages controls already implemented by a common control provider (Correct answer)
- An AO delegates authority to a subordinate
- Security policies are copied from another agency
Correct answer: A system leverages controls already implemented by a common control provider
Inheritance means the system benefits from controls already in place at a higher organizational level without implementing them independently.
What are the three security control baselines defined in NIST SP 800-53B?