CAP Security Operations & Monitoring 3 — Questions and Answers
Question 1: What is the role of an Information System Security Officer (ISSO) in ongoing security monitoring?
- Approving system authorization decisions
- Implementing and maintaining day-to-day security controls (Correct answer)
- Conducting independent security assessments
- Establishing organizational security policy
Correct answer: Implementing and maintaining day-to-day security controls
The ISSO is responsible for the day-to-day implementation and maintenance of security controls within the information system.
Question 2: A SIEM system correlates events from multiple sources and generates an alert for an attack pattern. What should the analyst do FIRST?
- Immediately shut down the affected system
- Validate the alert to determine if it is a true positive (Correct answer)
- Notify law enforcement
- Restore the system from backup
Correct answer: Validate the alert to determine if it is a true positive
Alert validation to confirm it is a true positive (not a false positive) is the first step before taking any remediation action.
Question 3: Which of the following BEST describes a 'security baseline' in the context of federal information systems?
- The minimum acceptable risk level for the system
- A pre-defined set of security controls for a given impact level (Correct answer)
- The starting point for incident response procedures
- A summary of known vulnerabilities in the system
Correct answer: A pre-defined set of security controls for a given impact level
A security baseline is a pre-defined set of security controls tailored to a system's FIPS 199 impact level (Low, Moderate, High).
Question 4: Which type of vulnerability scan provides the MOST comprehensive view of security weaknesses on a system?
- Unauthenticated external scan
- Credentialed internal scan (Correct answer)
- Web application proxy scan
- Passive network traffic scan
Correct answer: Credentialed internal scan
Credentialed scans authenticate to the target system and can identify configuration issues, missing patches, and local vulnerabilities that unauthenticated scans miss.
Question 5: Under FISMA, how frequently must federal agencies report security status to OMB?
- Monthly
- Quarterly
- Annually (Correct answer)
- Bi-annually
Correct answer: Annually
FISMA requires federal agencies to report their information security status to OMB on an annual basis.
Question 6: What is the PRIMARY difference between a vulnerability and an exploit?
- A vulnerability is intentional; an exploit is accidental
- A vulnerability is a weakness; an exploit is code or technique that takes advantage of it (Correct answer)
- A vulnerability affects hardware; an exploit affects software
- A vulnerability is discovered; an exploit is remediated
Correct answer: A vulnerability is a weakness; an exploit is code or technique that takes advantage of it
A vulnerability is a weakness in a system, while an exploit is the specific mechanism or code that leverages that weakness to cause harm.
Question 7: Which activity is part of the 'Monitor' step in the NIST Risk Management Framework?
- Selecting initial security controls
- Defining the system authorization boundary
- Assessing security control effectiveness on an ongoing basis (Correct answer)
- Documenting system security plan components
Correct answer: Assessing security control effectiveness on an ongoing basis
The Monitor step includes ongoing assessment of security control effectiveness, reporting security status, and updating system documentation.
What is the role of an Information System Security Officer (ISSO) in ongoing security monitoring?