CySA+ Test Compliance Frameworks 3 — Questions and Answers
Question 1: Which framework uses a maturity model with five levels (Initial, Managed, Defined, Quantitatively Managed, Optimizing) to assess cybersecurity processes?
- ISO 27001
- NIST CSF
- CMMI (Correct answer)
- COBIT 5
Correct answer: CMMI
CMMI (Capability Maturity Model Integration) defines five maturity levels used to benchmark and improve organizational processes including security.
Question 2: Under the FedRAMP authorization process, which impact level applies to federal systems where breach could cause serious adverse effects?
- Low
- Moderate
- High (Correct answer)
- Critical
Correct answer: High
FedRAMP High impact level applies to systems where unauthorized disclosure could cause severe or catastrophic adverse effects on federal operations or national security.
Question 3: A company performing a gap analysis against ISO 27001 identifies missing controls. What document defines the scope of controls selected for implementation?
- Statement of Applicability (SoA) (Correct answer)
- Risk Treatment Plan
- Information Security Policy
- Asset Register
Correct answer: Statement of Applicability (SoA)
The Statement of Applicability (SoA) lists all ISO 27001 Annex A controls, indicating which are applicable, implemented, or excluded with justification.
Question 4: Which CIS Control focuses on continuous vulnerability management through scanning and remediation?
- CIS Control 1 — Inventory of Enterprise Assets
- CIS Control 5 — Account Management
- CIS Control 7 — Continuous Vulnerability Management (Correct answer)
- CIS Control 13 — Network Monitoring and Defense
Correct answer: CIS Control 7 — Continuous Vulnerability Management
CIS Control 7 specifically addresses continuous vulnerability management, requiring organizations to regularly scan for and remediate vulnerabilities.
Question 5: FISMA requires federal agencies to categorize information systems using which standard?
- FIPS 140-2
- FIPS 199 (Correct answer)
- NIST SP 800-37
- NIST SP 800-53
Correct answer: FIPS 199
FIPS 199 provides the standards for security categorization of federal information and information systems based on potential impact.
Question 6: Which HIPAA rule establishes national standards for the protection of electronically protected health information (ePHI)?
- HIPAA Privacy Rule
- HIPAA Security Rule (Correct answer)
- HIPAA Breach Notification Rule
- HIPAA Enforcement Rule
Correct answer: HIPAA Security Rule
The HIPAA Security Rule specifically addresses the protection of ePHI through administrative, physical, and technical safeguards.
Question 7: An analyst discovers that the organization's cloud provider holds a shared responsibility for compliance. Under PCI DSS, who is ultimately accountable for cardholder data protection?
- The cloud provider, as the infrastructure owner
- Both the merchant and cloud provider equally
- The merchant (covered entity) (Correct answer)
- The card brands (Visa, Mastercard)
Correct answer: The merchant (covered entity)
Under PCI DSS, the merchant (covered entity) retains ultimate accountability for cardholder data protection regardless of what a cloud provider manages.
Which framework uses a maturity model with five levels (Initial, Managed, Defined, Quantitatively Managed, Optimizing) to assess cybersecurity processes?