CAP Risk Management & Security Evaluation 3 — Questions and Answers
Question 1: Which step of the NIST RMF involves defining the system boundary, identifying stakeholders, and establishing the authorization strategy?
- Prepare (Correct answer)
- Categorize
- Select
- Implement
Correct answer: Prepare
The Prepare step, added in NIST SP 800-37 Rev. 2, establishes organizational and system-level context before the remaining RMF steps begin.
Question 2: What is the key distinction between a vulnerability and a threat in the context of CAP risk management?
- A vulnerability is a weakness; a threat is a potential cause of harm that exploits it (Correct answer)
- A vulnerability is external; a threat is internal
- A vulnerability requires patching; a threat requires insurance
- A vulnerability is documented in CVE; a threat is documented in STRIDE
Correct answer: A vulnerability is a weakness; a threat is a potential cause of harm that exploits it
A vulnerability is a flaw or weakness in a system, while a threat is any circumstance or event with the potential to exploit that vulnerability.
Question 3: Under CNSSI 1253, which factor primarily drives the selection of security control overlays for national security systems?
- System type, classification level, and operational environment (Correct answer)
- System age and vendor support status
- Network topology and bandwidth requirements
- Number of users and geographic distribution
Correct answer: System type, classification level, and operational environment
CNSSI 1253 overlays are driven by system type (e.g., space, weapons), classification level, and specific operational environments requiring tailored controls.
Question 4: An organization conducts ongoing security monitoring and discovers a new critical vulnerability in a production system. What is the FIRST action the ISSO should take?
- Assess the vulnerability's impact and report it to the AO (Correct answer)
- Immediately shut down the system
- Issue an emergency change request to patch the system
- Update the POA&M without notifying the AO
Correct answer: Assess the vulnerability's impact and report it to the AO
The ISSO must first assess impact and report to the AO so that an informed risk decision can be made before any remediation action.
Question 5: What term describes the process of tailoring a security control baseline by adding controls beyond the baseline to address specific threats or operational requirements?
- Scoping (supplementation) (Correct answer)
- Control inheritance
- Common control allocation
- Baseline tailoring down
Correct answer: Scoping (supplementation)
Supplementation (a form of scoping) adds controls above the baseline when the selected baseline is insufficient for specific threat environments or requirements.
Question 6: Which of the following BEST describes the concept of 'security control inheritance' in the RMF?
- A system receives security protection from controls implemented by an external provider or shared service (Correct answer)
- A system copies security controls from a previously authorized system of the same type
- An AO inherits authorization responsibility from a predecessor AO
- Security controls are applied automatically via configuration management tools
Correct answer: A system receives security protection from controls implemented by an external provider or shared service
Control inheritance occurs when a system leverages controls implemented and managed by another organizational entity, such as a common control provider or cloud platform.
Question 7: What is the recommended maximum duration for a federal system's Authorization to Operate (ATO) under NIST SP 800-37?
- 3 years (Correct answer)
- 1 year
- 5 years
- Authorization has no defined maximum duration
Correct answer: 3 years
NIST SP 800-37 recommends ATOs be reviewed at least every three years or whenever significant changes occur to the system or its environment.
Which step of the NIST RMF involves defining the system boundary, identifying stakeholders, and establishing the authorization strategy?