CAP Risk Management & Security Evaluation 2 — Questions and Answers
Question 1: Which NIST publication provides the primary framework for federal information security risk management using the Risk Management Framework (RMF)?
- NIST SP 800-37 (Correct answer)
- NIST SP 800-53
- NIST SP 800-30
- NIST SP 800-171
Correct answer: NIST SP 800-37
NIST SP 800-37 defines the RMF and its six steps (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor) for federal systems.
Question 2: During a security assessment, an assessor discovers that a control is partially implemented. How should this finding be recorded in the Security Assessment Report (SAR)?
- As 'Other Than Satisfied' with documented weaknesses (Correct answer)
- As 'Satisfied' if the intent is met
- As 'Not Applicable' pending remediation
- As 'Satisfied' with a waiver attached
Correct answer: As 'Other Than Satisfied' with documented weaknesses
A partially implemented control is recorded as 'Other Than Satisfied' in the SAR, with the specific weaknesses and deficiencies documented.
Question 3: What is the primary purpose of a Plan of Action and Milestones (POA&M)?
- To document and track remediation of security weaknesses identified during assessment (Correct answer)
- To authorize system operation at an acceptable risk level
- To define security control baselines for a system
- To record the system boundary and interconnections
Correct answer: To document and track remediation of security weaknesses identified during assessment
A POA&M documents identified weaknesses, assigns responsibility, and establishes scheduled milestones for corrective action.
Question 4: Under FISMA, who is ultimately responsible for accepting the residual risk of operating a federal information system?
- Authorizing Official (AO) (Correct answer)
- Information System Owner (ISO)
- Security Control Assessor (SCA)
- Chief Information Officer (CIO)
Correct answer: Authorizing Official (AO)
The Authorizing Official (AO) bears ultimate responsibility for accepting residual risk by signing the Authorization to Operate (ATO).
Question 5: Which risk response strategy involves transferring potential loss to a third party, such as through cyber insurance?
- Risk Transference (Correct answer)
- Risk Avoidance
- Risk Mitigation
- Risk Acceptance
Correct answer: Risk Transference
Risk transference shifts financial or operational consequences of a risk to another party, such as an insurer or cloud service provider.
Question 6: What document formally describes the security controls implemented for a federal information system and serves as the primary security planning artifact?
- System Security Plan (SSP) (Correct answer)
- Security Assessment Report (SAR)
- Authorization Package
- Privacy Impact Assessment (PIA)
Correct answer: System Security Plan (SSP)
The System Security Plan (SSP) is the primary document describing security requirements and the controls in place or planned for a system.
Question 7: A system is categorized as HIGH for confidentiality, MODERATE for integrity, and LOW for availability. What is the overall FIPS 199 categorization?
- HIGH (Correct answer)
- MODERATE
- LOW
- Cannot be determined without further analysis
Correct answer: HIGH
FIPS 199 uses the 'high water mark' principle — the overall system categorization equals the highest impact level across all three security objectives.
Which NIST publication provides the primary framework for federal information security risk management using the Risk Management Framework (RMF)?