CAP Information Systems & Data Protection 2 — Questions and Answers
Question 1: Which NIST publication provides guidelines for categorizing federal information and information systems based on potential impact?
- FIPS 199 (Correct answer)
- NIST SP 800-53
- NIST SP 800-37
- FIPS 140-2
Correct answer: FIPS 199
FIPS 199 establishes security categories for federal information and information systems using potential impact levels of low, moderate, and high.
Question 2: A database containing Social Security Numbers, medical records, and financial data is being categorized. Which security objective drives the overall system categorization to HIGH?
- The highest impact level across all security objectives (Correct answer)
- The average impact level across all data types
- The lowest impact level to ensure usability
- The impact level of the most recently added data element
Correct answer: The highest impact level across all security objectives
Per FIPS 199, the overall information system security category is determined by the high-water mark — the highest impact level across all security objectives (confidentiality, integrity, availability).
Question 3: Under FISMA, which role is responsible for ensuring that information systems under their authority are covered by an approved authorization?
- Authorizing Official (AO) (Correct answer)
- System Owner
- Information System Security Officer (ISSO)
- Chief Information Officer (CIO)
Correct answer: Authorizing Official (AO)
The Authorizing Official is the senior federal official who bears ultimate accountability for accepting risk and ensuring systems have an approved ATO.
Question 4: What is the primary purpose of a System Security Plan (SSP) in the RMF process?
- To document the system boundary, environment, and implemented security controls (Correct answer)
- To authorize the system for operation
- To document all identified vulnerabilities
- To establish the system categorization level
Correct answer: To document the system boundary, environment, and implemented security controls
The SSP describes the system boundary, operating environment, security requirements, and the controls implemented to meet those requirements.
Question 5: Which type of data handling practice violates the principle of data minimization?
- Collecting more PII than is strictly necessary for the stated purpose (Correct answer)
- Encrypting sensitive data at rest
- Purging records after the retention period expires
- Restricting access to PII on a need-to-know basis
Correct answer: Collecting more PII than is strictly necessary for the stated purpose
Data minimization requires collecting only the minimum amount of personal information necessary to fulfill a specific, legitimate purpose.
Question 6: A federal agency discovers that a contractor's system storing agency data lacks an interconnection security agreement (ISA). What is the most immediate concern?
- Unauthorized data flows may exist without documented controls or approvals (Correct answer)
- The contractor cannot bill the agency for services rendered
- The system automatically loses its ATO status
- The agency CIO must personally authorize all data transfers
Correct answer: Unauthorized data flows may exist without documented controls or approvals
Without an ISA, there is no documented agreement on security controls, data handling, and responsibilities governing the interconnection, creating unmanaged risk.
Question 7: Which NIST SP 800-53 control family primarily addresses protecting data in transit and at rest?
- System and Communications Protection (SC) (Correct answer)
- Access Control (AC)
- Audit and Accountability (AU)
- Configuration Management (CM)
Correct answer: System and Communications Protection (SC)
The SC control family includes cryptographic protection, transmission confidentiality/integrity, and network controls that protect data both in transit and at rest.
Which NIST publication provides guidelines for categorizing federal information and information systems based on potential impact?