CAP Security Operations & Monitoring 2 — Questions and Answers
Question 1: Which NIST document provides guidance on security and privacy controls for federal information systems and organizations?
- NIST SP 800-37
- NIST SP 800-53 (Correct answer)
- NIST SP 800-137
- NIST SP 800-30
Correct answer: NIST SP 800-53
NIST SP 800-53 provides a catalog of security and privacy controls for federal information systems and organizations.
Question 2: A security analyst notices repeated failed login attempts followed by a successful login from an unusual geographic location. This pattern most likely indicates:
- A misconfigured authentication policy
- A credential stuffing or brute-force attack succeeded (Correct answer)
- Normal user behavior during travel
- An expired certificate causing authentication failures
Correct answer: A credential stuffing or brute-force attack succeeded
Repeated failed attempts followed by success from an unusual location is a hallmark indicator of a credential-based attack that succeeded.
Question 3: Under the RMF, which step involves assessing whether the security controls selected are implemented correctly and operating as intended?
- Categorize
- Select
- Assess (Correct answer)
- Authorize
Correct answer: Assess
The Assess step involves evaluating whether controls are implemented correctly, operating as intended, and producing the desired outcome.
Question 4: What is the primary purpose of a Plan of Action and Milestones (POA&M)?
- Document the system authorization boundary
- Track remediation of identified security weaknesses (Correct answer)
- Establish the system categorization level
- Define personnel roles and responsibilities
Correct answer: Track remediation of identified security weaknesses
A POA&M documents identified security weaknesses and tracks the planned remediation actions and target completion dates.
Question 5: Which log source would be MOST useful when investigating potential insider threat activity involving unauthorized data exfiltration?
- Firewall deny logs
- Data Loss Prevention (DLP) alerts (Correct answer)
- Antivirus scan results
- Patch management reports
Correct answer: Data Loss Prevention (DLP) alerts
DLP systems monitor and alert on data movements that violate policy, making them the most direct source for identifying data exfiltration.
Question 6: In continuous monitoring, what does the term 'ongoing authorization' replace in the traditional RMF approach?
- The security categorization step
- The periodic reauthorization cycle (Correct answer)
- The initial control selection process
- The system boundary definition
Correct answer: The periodic reauthorization cycle
Ongoing authorization replaces the traditional fixed three-year reauthorization cycle with real-time risk management through continuous monitoring.
Question 7: Which metric is MOST important for measuring the effectiveness of a security monitoring program?
- Number of security tools deployed
- Mean Time to Detect (MTTD) security incidents (Correct answer)
- Total volume of log data collected
- Number of security personnel on staff
Correct answer: Mean Time to Detect (MTTD) security incidents
Mean Time to Detect measures how quickly threats are identified, directly reflecting the effectiveness of monitoring capabilities.
Which NIST document provides guidance on security and privacy controls for federal information systems and organizations?