Browse all practice questions for the Federal IT Security Professional (FITSP) Operator Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Federal IT Security Professional (FITSP) Operator Practice Test course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • Major IT investments reporting for agencies is done via which exhibit?
  • In Federal Agency Incident Reporting Categories, which category corresponds to Investigation?
  • What is the stated purpose of the Computer Fraud and Abuse Act (CFAA) of 1986?
  • In RA Step 2 Task 4, which elements are considered to determine likelihood?
  • Which organization is NOT listed among the Incident Response (IR) organizations?
  • Which of the following describes a key provision of the Clinger-Cohen Act?
  • What is the primary purpose of symmetric key encryption?
  • Which PKI component is used to revoke certificates before expiration?
  • Under the Computer Security Act of 1987, which organization was assigned to develop minimum acceptable practices, with assistance from the NSA?
  • Which memorandum is associated with e-authentication and federal online service access criteria?
  • Which control is described as addressing only incidents that relate to PII?
  • The ________ requires agencies to identify sensitive systems, conduct computer security training, and develop computer security plans.
  • Which statement describes system registration?
  • What is the purpore of Open Security Architecture?
  • NIST SP 800-77 is associated with which security technology according to the source material?
  • What is the US-CERT incident category name and reporting timeframe for a CAT-3 incident?
  • What does M-06-19 PII Reporting require?
  • Which publication is the primary source for risk management guidance in the material?
  • Is reauthentication required every three years?
  • Data Quality and Integrity is the expansion for which privacy control?
  • Which entity provides retention schedules for federal records and coordinates with records officers and NARA?
  • Which feature is NOT typically listed as a Network Layer Security (IPSEC) capability in the source material?
  • The Health Information Technology for Economic and Clinical Health Act (HITECH) mandates audits of health care providers to investigate HIPAA compliance and is part of which larger recovery act enacted in 2009?
  • What is a Cold site?
  • Which SP 800 document is the Guideline for Media Santitization?
  • Which of the following statements about IR 7298 is true?
  • What topic does NIST 800-46 address?
  • Which of the following is NOT one of the Federal Enterprise Architecture models?
  • RA Step 2 Task 3 focuses on identifying what domains?
  • Tier 2 of the 3-tiered risk management approach addresses risk-related concern at which level?
  • FIPS 180-3 specifies which cryptographic function?
  • The Interconnection Security Agreement (ISA) primarily details what?
  • What is the final step in the ISCM process?
  • Which basic cryptographic service provides confidentiality?
  • Compared to TKIP, CCMP is described as what?
  • In AES, which parameters are variable according to the standard?
  • NIST 800-92 covers which area?
  • Which SP 800 document is the Guide to Intrusion Detection and Prevention Systems (IDPS)?
  • Which allows a user to use a single SSL connection to a Web site to securely access multiple network services?
  • What does M-02-01 cover?
  • NIST 800-83 is focused on which security domain?
  • Which of the following is a phase of the Software Development Life Cycle (SDLC)?
  • The AES standard specifies which algorithm?
  • Which of the following is NOT listed as a phase in the SDLC as described?
  • Under the Clinger-Cohen Act, what does the 'at risk' category indicate?
  • What does Federal Continuity Directive 2 provide?
  • Which SP 800 document covers Information Security Continuous Monitoring for Federal Information System and Org?
  • Which memorandum is designed to force implementation of HSPD-12 Personal Identity Verification criteria along with M05-24, M06-06, M-06-18, M08-01 and M11-11?
  • Which document provides guidelines on TT&E design, testing, training, and exercises?
  • What topic does NIST SP 800-12 address?
  • What does CVE stand for?
  • Which SP 800 document is the Guide for Security Focused Configuration Management of Information Systems?
  • Which standard discusses mapping types to categories in security categorization?
  • What establish the scope of protection for organizational information systems?
  • Which program is used to verify cryptographic modules?
  • How does SSL VPN operate with a browser-based client?
  • Which is a focus area of the Critical Infrastructure Plan?
  • Which references support CA-5 Plan of Action and Milestones?
  • Which FIPS 140-2 encryption level enables environmental protections?
  • What are the Investment Life Cycle phases?
  • Security Reauthorizations are conducted during what phase of the SDLC?
  • Who approves FIPS?
  • Why was the Computer Security Act of 1987 passed?
  • COPPA, the Children's Online Privacy Protection Act, is managed by which federal agency?
  • Which provision did the Computer Security Act of 1987 mandate regarding federal employees who use those systems?
  • Which RMF step provides ongoing oversight after authorization?
  • What directive establishes a national policy for Federal Departments and agencies to identify and prioritize US critical infrastructure and key resources to protect us from terrorist attacks?
  • Which statement best describes the development life cycle relation to risk assessment?
  • Which input activity involves gathering information directly from on-site stakeholders?
  • What does AR privacy control stand for?
  • Which of the following is NOT listed as a security domain?
  • Which VPN model is the least used and typically employed for remote management of servers by system administrators?
  • The National Checklist Program for IT products was developed as part of CSRDA to facilitate what?
  • Which SP defines malware categories and types, describes malware prevention techniques, and discusses malware response mechanisms?
  • RMF Step 3 - Implement Controls includes which of the following activities?
  • Which term defines the boundary around an organization's information systems for protection purposes?
  • What is the typical order of implementing security controls?
  • Which of the following is an operation control family?
  • FIPS 186-2 defines which standard?
  • In the security services life cycle, which phase involves engaging the right source?
  • Which IPSEC protocol provides data integrity and authentication of packets?
  • Which IR provides an overview of smart cards and mobile device authentication?
  • Which NIST document number is associated with IPSEC according to the source material?
  • Which of the following is a factor that affects the trustworthiness of an information system?
  • Which of the following is an internal information source?
  • Do the DOD and ODNI follow OMB policy and NIST guidelines for reporting instructions?
  • When a hard drive from a classified information system is recycled and reused within the organization, which media sanitization method is recommended?
  • Which GAO life cycle model is described as Select-Control-Evaluate in governance and IT investment planning?
  • In which AH mode does not create a new IP header?
  • Which standard defines Security requirements for cryptographic modules?
  • Which requirement does the Computer Security Act of 1987 mandate for federal computer systems that contain sensitive information?
  • Which NIST Special Publication covers CPIC?
  • What does IR 7316 Assessment of Access Control System provide?
  • Which statement about FIPS approval of SSL cipher suites is supported by the material?
  • Tier 2 addresses risk from which perspective?
  • CSRDA stands for which act mentioned in relation to the National Checklist Program?
  • Accountability, Audit, and Risk Assessment is the expansion for which privacy control?
  • In Federal Agency Incident Reporting Categories, which category corresponds to Denial of Service?
  • Which of the following are examples of information sources?
  • In Federal Agency Incident Reporting Categories, which category corresponds to Scans/Probes/Attempted Access?
  • FIPS 191 provides guidelines for the analysis of what?
  • RA Step 1 Task 4 requires that each information source be described with which four elements?
  • If you need an assessment of an access control system, which IR would you consult?
  • Which sequence correctly lists the four steps of the interconnect process in order?
  • What does DM-2 Data Retentions and Disposal support require?
  • What is the purpose of the US Government Configuration Baseline (USGCB)?
  • Which standard covers the Keyed-Hash Message Authentication Code (HMAC)?
  • Which are examples of hash functions?
  • In the security services life cycle, which phase is responsible for specifying the right solution?
  • Which SP 800 document provides guidelines for media sanitization, including techniques and disposal?
  • In risk assessment planning, which element is considered primary?
  • Which publication discusses two novel smart card types using standard handheld interfaces?
  • NIST Interagency Reports (NISTIRs) describe research of a technical nature intended for a specialized audience. True or False.
  • What does IAIP stand for in the IR context?
  • Which circular covers Management's Responsibility for Enterprise Risk Management and Internal Control (Revised 07/15/2016)?
  • Which is the final step in the interconnect process?
  • Which implementations are allowed for the AES algorithm according to FIPS 197?
  • What does FIPS 199 specify?
  • Which statement best describes Common Controls?
  • What does CCSS stand for in software security configuration contexts?
  • Which approach is an effective method to analyze log data?
  • RA Step 2 Task 1 focuses on identifying threat sources of concern, including which attributes?
  • NIST SP 800-114 discusses which topic according to the source material?
  • FIPS 140-2 pertains to which area?
  • What is Federal Enterprise Architecture?
  • NIST IR 7564 provides information about security metrics. How are these metrics categorized?
  • Which document defines the Digital Signature Standard?
  • NIST SP 800-114 is associated with which topic according to the source material?
  • Which document defines minimum security requirements for federal information and information systems?
  • Which action is part of building an effective assurance case?
  • What requires a Radius server?
  • What is the process of comparing definitions of what activity is considered normal against observed events to identify significant deviations called?
  • Which NIST Special Publication provides the Guide to Applying the Risk Management Framework to Federal Information Systems?
  • Which component is primarily used for auditing and monitoring in security controls, as suggested by the material?
  • RA Step 2 Task 4 (assessing inputs) is described as selecting the analytic approach and models for the assessment. Which option correctly identifies this task?
  • SP-800-39 superseded which previous NIST Special Publication?
  • Which of the following is listed as a security domain example?
  • In RMF-5, which item communicates the decision to accept residual risk?
  • Which item is contained in the Program Management Overview?
  • In FIPS 140-2, Level 1 is described as what?
  • In the IA Policy and Standard set, which item is designated as the policy reference?
  • Which act requires each federal agency to implement an information security program and to report annually to the OMB on the adequacy of the security program, the adequacy of plans and reports relating to annual budgets, and any significant deficiency?
  • Which media sanitization step involves discarding media with no other sanitization consideration?
  • FIPS 186-3 defines which digital signature standard?
  • SP 800-144 provides guidelines on security and privacy in what context?
  • Which references support PL-5 Privacy Impact Assessment?
  • Which act first officially declared what constitutes a National Security System?
  • What SP specifies how to run name server software with restricted privileges?
  • NIST 800-45 pertains to which domain?
  • Which phase describes capturing lessons learned to improve future responses in Malware Incident Response?
  • Which of the following is an area for adjusting system categorization?
  • Which NIST Special Publication defines the System Development Life Cycle (SDLC)?
  • Which items are typically included in a System Registration Declaration?
  • Which NIST Special Publication defines Security Services?
  • SP 800 94 is the Guide to Intrusion Detection and Prevention Systems (IDPS). Which model is described for IDPS?
  • How are privacy and security described in Appendix J?
  • What is the focus of SE-1 Inventory of Personally Identifiable Information?
  • Which VPN model is described as the most often used to provide secure remote access?
  • Which organization developed the National Checklist Program (NCP) for IT products?
  • What does a security assessment report provide?
  • What is the focus of FIPS 200?
  • What does OMB M-04-04 E-authentication guidance provide guidance for?
  • What does OMB Memorandum 10-28 cover?
  • What is used for digital signatures?
  • Tier 3 addresses risk from which perspective?
  • What does ICD 704 address?
  • What is the first step of the ISCM process?
  • What are VPN architectures as listed in the material?
  • Which of the following are uses for IDS and IDPS?
  • RA Step 1 Task 1 involves identifying the purpose of the assessment, including information the assessment will produce and the decision it will support.
  • Which SP 800 document is the Information Security Handbook - A guide for managers?
  • RA-3 security control must be partially implemented prior to the implementation of other controls in order to complete the first two steps in the Risk Management Framework: True or False?
  • Which statement about SP 800-53 Appendix J is correct?
  • What is 800-61 focused on?
  • Which of the following is a storage encryption technology?
  • Which artifact provides an overview of the agency's entire IT portfolio by listing every IT investment, lifecycle, and budget-year cost information?
  • Which option is NOT listed as a factor for changes to the Security Control Catalog?
  • NIST SP 800-88 covers which topic?
  • The Economic Espionage Act defines economic espionage as theft or misappropriation of a trade secret with the intent to benefit which entities?
  • Which type of detection is the process of comparing signatures against observed events to identify possible incidents?
  • Which directive addresses national policy for protecting critical infrastructure from terrorist attacks?
  • An MOU/A document primarily documents what?
  • Which statement accurately describes CPIC's overall objective?
  • Which system is indicated for reporting instructions changes for OMB M11-33/M11-02/M12-02?
  • Which e-authentication level requires multi-factor authentication using a hard token?
  • Which scenario best describes host-to-host VPN usage?
  • In what security mode are Bluetooth devices considered promiscuous?
  • Which Act addresses restrictions on wiretaps and access to electronic communications?
  • What does the Clinger-Cohen Act of 1996 require?
  • What does OMB use to assess investments and make funding decisions?
  • What does HMAC stand for?
  • Which SP 800 document focuses on the confidentiality of PII and breach response requirements?
  • Assessment findings are documented in which report?
  • Which document provides a standardized approach for review and measurement of an information security program?
  • What does SP 800-66 Rev 1 Implementing the HIPAA Security Rules provide?
  • Why was M-09-32 Trusted Internet Connections initiated?
  • How is risk assessment typically conducted over time?
  • Which of the following is listed as a malware category?
  • Which SP 800 document would you consult for media sanitization guidelines and tools?
  • Which option lists the IPSEC network layer protocol components as described in the source material?
  • What does RPO represent?
  • The Health Information Technology for Economic and Clinical Health Act (HITECH) is part of which act enacted in 2009?
  • Which Bluetooth security mode is non-secure?
  • What term is used to evaluate operational information systems against the RMF to determine the security controls in place and the requirements to mitigate risk at an acceptable level?
  • What does IR 6/7 require?
  • Which option correctly lists the three tiers in Organizational Wide Risk Management?
  • Which SP 800 document is the Information Security Handbook - A guide for managers?
  • PRISM Topic Areas of Coverage provide focus on which aspect of information security program management?
  • Which control addresses privacy risk management across the life cycles of all processes that collect or handle PII?
  • In Federal Agency Incident Reporting Categories, which category corresponds to Inappropriate Usage?
  • Which mandate uses NIST SP-800-53?
  • What is NIST 800-111 about?
  • Which pairing correctly matches the SP number with its title as described?
  • What is the first step in the Contingency Planning Process?
  • What is another name for the Information Technology Management Reform Act of 1996?
  • Which action is part of the assessment process?
  • Why do organizations look for automated solutions for ISCM?
  • Which control is associated with Contingency Plan Testing and Exercises in TT&E under NIST 800-84?
  • Which category includes Exercise/Network Defense Testing in Federal Agency Incident Reporting Categories?
  • Which standard is listed as an integrity standard in the material?
  • Which SP 800 document is the Guide to Computer Security log Management?
  • Who leads the privacy incident response plan according to SE-2 Privacy Incident Response?
  • Which of the following is NOT a step in the Contingency Planning Process?
  • FIPS 181 corresponds to which concept?
  • What is a Warm site?
  • Which of the following is an actual Federal Enterprise Architecture model?
  • Which security testing and evaluation program is used to assess security features and assurances for commercial off-the-shelf products?
  • What are the four components of the Risk Management Framework (RMF)?
  • What does NIST 800-55 Security Metric Guide provide?
  • Which of the following is a key establishment algorithm listed as supported by Fortezza cards?
  • What are the four IDPS technologies listed?
  • Which item is included in an Authorization Package?
  • What does OMB Circular A-127 Revised prescribe?
  • Which function takes streams of data and reduces them to a fixed size using a one-way operation?
  • GISRA 2000 required U.S. government agencies to implement an information security program that includes planning, assessment and protection, and was replaced by which act in 2002?
  • In the RMF, which step directly follows 'Assess'?
  • The Information Analysis and Infrastructure Protection (IAIP) is part of which department, and what is its primary focus?
  • Which act superseded the Computer Security Act of 1987?
  • In management controls, SA stands for which?
  • What measures are provided by 800-55 Performance Measurement Guide for Info Systems?
  • What program employs a network of private sector, accredited testing laboratories to independently evaluate commercial security products in key technology areas?
  • What are the approved integrity standards?
  • Which PIV specification addresses technical interoperability requirements for smartcards?
  • Which item is listed as a malware category?
  • Which is the final step in the Contingency Planning Process?
  • How many layers of Encryption standards are defined by FIPS?
  • What are resources of National Vulnerability Database (NVD)?
  • In Federal Agency Incident Reporting Categories, which category corresponds to Unauthorized Access?
  • Following the loss of 26 million records containing PII, M-06-16 requires which of the following?
  • M-00-13 covers privacy policies and data collection on Federal Web Sites. It requires agencies to do which of the following?
  • Which privacy control corresponds to Transparency?
  • Under CFAA, which definition describes a 'protected computer'?
  • Which publication outlines the units accomplishments during FY 2011?
  • RA Step 1 Task 3 involves identifying Assumptions and considerations, including assumptions, constraints, risk tolerances, and priorities/trade-offs.
  • Which standard validates the Secure Hash Algorithm family?
  • FIPS 198-1 defines which of the following?
  • CERT/CC is best described as which type of organization?
  • What is the stated purpose of OMB Circular A-11?
  • NIST IR 7359 Information Security Guide for Gov Executives provides what kind of guidance?
  • Which of the following is NOT included in an Authorization Package?
  • In PKI, which component serves as the database of active digital certificates for a CA?
  • What does Authentication Header (AH) provide in IPsec?
  • Which SCAP specification provides a standard naming and dictionary of system configuration issues?
  • Which documents support PL-4 Rules of Behavior?
  • Which of the following is NOT listed as a type of guidance provided by an OMB Memorandum?
  • Which of the following is an Information Sharing and Analysis Center (ISAC)?
  • What does 5 CFR 731.106 address?
  • FIPS 197 specifies the algorithm known as which encryption standard?
  • Which of the following is NOT a method of assessment?
  • What is the first phase of Security-Focused Configuration Management (SecCM)?
  • Which practice aligns with PII handling guidance?
  • Which of the following is NOT a SCAP component?
  • Which standard governs digital certificates used by S/MIME?
  • Which of the following is a security testing and evaluation program?
  • Which SP includes recommendations for controls to mitigate malware attacks and improve an organization's malware program?
  • In FIPS 140-2, which level adds tamper-evident coatings?
  • Which document focuses on embedded access control mechanisms and their capabilities and limitations?
  • Which of the following is an Information System Manager responsibility?
  • Which approach involves continually balancing protection of agency information and assets with the cost of security controls and mitigation strategies?
  • What defines a low likelihood in risk assessment?
  • Which of the following is a CIO responsibility for government personnel?
  • Which element is contained in the Information Security Program Plan?
  • What does appendix A of 800-34 provide?
  • Which NIST Special Publication covers Security Configuration Checklists?
  • In Malware Incident Response, which phase immediately follows Preparation?
  • Which statement best describes Tier 3 risk in relation to Tier 1 and Tier 2 decisions?
  • FIPS 201 defines which identification standard?
  • Which encryption/evaluation level is described as requiring identity-based authentication in the source material?
  • In what year was the Federal Information Security Modernization Act (FISMA) enacted?
  • Which document is used to document the System Security Plan?
  • Which statement best describes AR-6 Privacy Reporting?
  • Circular A-130 contains policy on the management of what?
  • Which requirement is specified by DI-1 Data Quality privacy control?
  • What are the approved digital signature standards?
  • Which publication addresses security and privacy in Public Cloud Computing?
  • ___________ is an aggregate of directives, rules, and practices that prescribe how an organization manages, protects, and distributes information.
  • Which of the following statements is NOT a core principle of the Federal Enterprise Architecture?
  • Which memorandum includes Breach Notification Policy as part of its privacy provisions?
  • What is EPHI?
  • Which detection method involves comparing a predetermined profile of benign protocol activity for each protocol state against observed events to identify deviations?
  • Digital signatures provide which assurance?
  • Which document is known as the Secure Hash Standard?
  • Which SP 800-65 step focuses on prioritization requirements?
  • What is CCMP?
  • Tier 2 risk decisions are guided by decisions in which tier?
  • Which privacy control stands for Individual Participation and Redress?
  • Which of the following is one of the five Federal Enterprise Architecture models?
  • Which NIST SP document is associated with PIV?
  • Which IR would you consult for key information security terms used in NIST publications?
  • What is a risk assessment summary?
  • Which factor does SA-13 primarily address in information security controls?
  • What is the primary subject of IR 7206?
  • What is a National Security Letter?
  • ___________ can verify the authenticity of the sender and enforce nonrepudiation to prove that the sender is who she/he claims to be and cannot deny sending it.
  • What does M-03-19 cover?
  • Which item is described as a true-floor-to-true-ceiling barrier in physical access controls?
  • RA Step 1 is composed of three tasks. Which statement correctly describes their grouping?
  • The combination of CPE, CVE, OVAL is associated with which of the following?
  • In Bluetooth security, which security mode enforces the link-level security?
  • SP 800-137 ISCM guidelines define maintaining ongoing awareness of what?
  • Which of the following is a stream cipher used for confidentiality among the listed symmetric algorithms?
  • RA-3 Risk Assessment is supported by which NIST publication?
  • The Federal Information Security Management Act (FISMA) is Title III of which act?
  • Which Act focuses on privacy rights of individuals to access and seek amendment of records held by federal agencies?
  • What is the second step in the staffing process?
  • SP 800-83 is the guide to Malware Incident Prevention and Handling. Which of the following does it define?
  • What are the two AH modes?
  • Which of the following is NOT typically considered part of the CPIC decision process?
  • Which outcome meets the CSRDA requirement?
  • In the security services life cycle, which phase ensures operational success?
  • In identifying threat sources, range of effects is considered for which type of threats?
  • What does CPIC stand for?
  • In identifying threat sources, which aspects are examined?
  • RA Step 2 Task 6 determines risk by combining which two elements?
  • RA Step 1 Task 5 requires identifying what?
  • Which term describes the management of user accounts and access within an organization?
  • What SP describes Secure Portal VPNs and Secure Tunnel VPN?
  • Which statement best describes ISCM?
  • Which of the following is NOT listed as an assessment task?
  • Which references support CA-5 Plan of Action and Milestones?
  • Which area is listed as an area covered when updating the risk assessment?
  • Which SP standard covers Protecting PII?
  • What does NIST 800-56 and 800-57 address?
  • Which sequence correctly lists the steps for handling an incident?
  • Under FISMA, which items are reported to the OMB annually?
  • What was the purpose for NIST developing the National Checklist Program (NCP) for IT products?
  • Which statement best describes the focus of IR 7316?
  • Under M-06-16, what security measure is required for mobile data when the data resides on mobile devices?
  • True or False: Any incident that involves compromised PII must be reported to US-CERT within one hour regardless of the incident category reporting time frame.
  • Which standard defines the Digital Signature Standard?
  • Which memorandum is associated with privacy provisions that include PIA and SORNs and privacy training?
  • Which privacy control stands for Data Minimization and Retention?
  • Which legislation requires Federal agencies to develop and implement an agency-wide information security program?
  • Which of the following is NOT listed as a common control candidate?
  • Which Special Publication describes attacker tools such as backdoors?
  • RA Step 4 Task 2 Update Risk Assessment specifies which areas and timing?
  • Which of the following is NOT a phase of the SP 800-47 Security Guide for Interconnecting IT Systems?
  • Which description best matches AR-2 Privacy Impact and Risk Assessment?
  • Which NIST IR covers biometrics validation and implementation under FIPS-201 and HSPD-12?
  • COPPA protects the privacy of children under what age?
  • What is the third step in the staffing process?
  • Which reference provides fundamentals for selecting controls?
  • Which area does User Administration cover?
  • Which NIST IR describes System and Network Security Acronyms and Abbreviations?
  • What disposal method is recommended by 800-88 sanitization guidelines for paper-based medical records containing PII?
  • Which requirement is specified by DM-1 Data Minimization privacy control?
  • Tier 1 risk coverage includes which core area?
  • What are the Risk Assessment Steps? (Risk framing)
  • Which of the following is NOT an Assessment Testing activity?
  • Which document would you reference for a glossary of information security terms?
  • Which document presents a program review titled PRISMA for information security management assistance?
  • Which publication provides an overview of information security program concepts to assist senior leadership in overseeing and supporting development and implementation?
  • The scope of IR 7206 includes which of the following?
  • Which statement about tampering in FIPS 140-2 is accurate?
  • Which RMF step involves implementing security controls?
  • What control ensures that an organization recognizes the importance of trustworthiness?
  • Which NIST IR is described as the annual Interagency Report?
  • Baselines are based upon the IMPACT level as defined in FIPS 199, selected via CNSSI-1253 or FIPS 200, and now implemented through catalog of controls found in SP 800-53. Baselines are based upon the IMPACT level defined in which standard?
  • What does M-03-22 Guidance for Implementing the Privacy Provisions of the E-Gov Act of 2002 cover?
  • Which of the following is NOT an information input activity for risk assessment?
  • What does RTO define?
  • What does TIC stand for in the context of M-09-32?
  • Which department issues the Federal Information Security Memorandum (FISM)?
  • Which function facilitates sharing of risk information and coordinates with senior leadership?
  • Which protocols secure traffic between a browser and the SSL VPN device?
  • NIST SP 800-113 is associated with which security protocol according to the source material?
  • Which documents support CP-2?
  • In AH, which mode creates a new IP header for each packet?
  • Appendix J is based on which principle set?
  • Which of the following is not an operation control family?
  • Which item is explicitly listed as part of Tier 1 risk coverage?
  • Which of the following is NOT a step in the four-step interconnect process?
  • What does DI privacy control stand for?
  • RA Step 1 Task 2 involves identifying Scope, determining what will be considered in the assessment, including organizational applicability, time frame supported, and architectural/technology considerations.
  • Which NIST Special Publication defines Security Products?
  • What does PM-10 Security Auth Process require?
  • Continuous monitoring updates which document?
  • What is the purpose of a POAM schedule?
  • Which NIST Special Publications cover Security Architecture?
  • What investment life cycle model is used by GAO?
  • What is the legal precedence for federal information security policy?
  • SP 800-53 r4 control families count statement?
  • What does M-06-15 Safeguarding PII require?
  • FIPS 201 defines personal identity verification of federal employees and contractors. The standard is based on which initiative?
  • NIST 800-40 is primarily associated with?
  • What is NIST 800-23?
  • Which of the following is NOT a control type in SP 800-53 r4?
  • What best describes PL-6 Security Related Activity Planning?
  • Which of the following is a technical control family?
  • How many novel smart card types are discussed in IR 7206?
  • SP-800 70 Rev2 is associated with which program?
  • Which pair correctly identifies the data encryption format and digital certificate standard used by S/MIME?
  • Capital Planning and Investment Control entails which of the following?
  • Which statement best describes the overall concept of risk in this context?
  • Where can vulnerability information be found?
  • Which document is titled Automated Password Generator?
  • Which control requires ensuring that the collection of PII is for purposes authorized by law or regulation?
  • Which of the following is a hash algorithm?
  • Which NIST IR includes the Crypto Module Validation Program and the Crypto Algorithm Validation Program?
  • Which action is a poor practice for long-term log storage?
  • Which security control is addressed by NIST SP 800-50?
  • Where is the catalog of controls used to implement baselines located?
  • Which media sanitization step is described as the ultimate form of sanitization?
  • Which SP 800 document defines PII and impact levels and provides for confidentiality considerations of USG systems and breach response requirements?
  • Which of the following is a Responsibility of the Risk Executive function?
  • What does CVSS measure?
  • What does the E-Government Act of 2002 accomplish?
  • FIPS 198-1 defines which keyed-hash mechanism?
  • What is SP-800-115?
  • What is WPA-Personal or WPA-PSK designed for?
  • The Clinger-Cohen Act requires alignment of IT investments with what planning process?
  • What defines a medium likelihood level?
  • RA Step 3 Task 2 shares risk-related results to support risk responses. What is the primary purpose?
  • What does TKIP do?
  • Which statement is true about Tier 3 risk?
  • FIPS 199 is Standard for Security Categorization of which?
  • What elements are components of an information system?
  • Which references support PL-5 Privacy Impact Assessment?
  • What defines a high likelihood level?
  • Authority and Purpose is the expansion for which privacy control?
  • CPE provides nomenclature and dictionary for what?
  • FIPS 180-2 defines which standard?
  • In management controls, PL stands for which?
  • RA Step 2 Task 2 focuses on identifying what?
  • What is the full title of the USA PATRIOT Act?
  • Which item is included in the Program Management Overview?
  • Under the Clinger-Cohen Act, which of the following is a criterion for a system to be considered National Security System?
  • Which privacy control stands for Transparency?
  • Which of the SP 800-65 CPIC steps involves establishing baseline prioritization?
  • Which publication is focused on outlining the eight topic areas used for strategic information security program management under PRISM?
  • Which is the initial step in the interconnect process?
  • Which feature is associated with FIPS 140-2 Level 3 security modules?
  • Security Functionality is typically defined in terms of what?
  • Which document tracks remediation actions for control implementations?
  • IR 7206 Smart Cards and Mobile Devices Authentication overview describes two novel types of smart cards that?
  • In the RMF, which step involves categorizing the information system?
  • Which memorandum focuses on E-Authentication Guidance for Federal Agencies?
  • RA Step 3 Task 1 focuses on communicating risk assessment results to whom?
  • Which document supports PM-8 Critical Infrastructure Plan?
  • NIST SP 800-63 defines which area of identity and access management?
  • CCE provides nomenclature and dictionary of what?
  • What is the primary focus of NIST SP 800-92?
  • In IR 7316, which aspects of access control mechanisms are discussed?
  • Which publication provides a cross-country perspective on validated cryptographic modules and confidence in security assurance?
  • Which security control is addressed by NIST SP 800-16?
  • Which data encryption format is used by S/MIME to protect message content?
  • Which document is the implementation standard referenced for federal identity and authentication?
  • Under the Clinger-Cohen Act, which of the following describes a National Security System?
  • During what phase of the SDLC should the organization consider the security requirements?
  • Which of the following is a Common Control Provider responsibility?
  • In Federal Agency Incident Reporting Categories, which category corresponds to Malicious Code?
  • RA Step 2 Task 5 determines Impact. Which elements are included?
  • Which statement describes the depth and coverage attributes of assessment?
  • Which NIST Special Publication defines CPIC?
  • In PKI, which component verifies a user's identity before issuing a certificate?
  • What does RMF stand for?
  • Asymmetric key encryption is commonly known as what?
  • Which item is NOT listed as part of Tier 1 risk coverage?
  • Which SP 800 document is the Guide to Computer Security log Management?
  • In management controls, CA stands for which?
  • In management controls, RA stands for which?
  • What is the purpose of Capital Planning and Investment Control (CPIC)?
  • What is a configuration item in a system?
  • How many control families exist within SP 800-53 r4 across control types?
  • OMB 02-01 provides guidance for what?
  • What is the first step in handling an incident?
  • Which CPIC-related exhibit is explicitly mentioned as part of the process?
  • What does PM-1 Information Security Program Plan document?
  • Which action is part of long-term log data storage?
  • What NIST Pub superseded the original SP 800-30 as the primary source for guidance on risk management?
  • What are the five phases of the SDLC?
  • Which of the following is not a technical control family?
  • Which IPSEC component is responsible for negotiating security associations and keys?
  • Which phase is the first in the Security Services life cycle?
  • Which SP 800 document is the Technical Guide to Information Security Testing and Assessment and works with SP 800-53a for testing and assessment guidance?
  • Which security control reiterates the important parts of the security categorization?
  • Which item is included in M-07-16 Privacy and Privacy Reporting?
  • Which of the following is a management control family?
  • Which of the following is a step in the staffing process?
  • What does MTD stand for in the context of RTO?
  • In a POAM, which field records the organization responsible for correcting a weakness?
  • RA Step 1 Task 3 focuses on which area?
  • What triggers updates to the risk assessment?
  • FIPS 190 focuses on guidelines for what?
  • What are the six steps of the RMF in the correct order?
  • The National Institute of Standards and Technology (NIST) was formerly known as what name?
  • Malware Incident Response includes which phases in the listed sequence?
  • In what year did COPPA take effect?
  • RA Step 4 Task 1 Monitor Risk Factors covers which areas?
  • Which memorandum includes elements such as PIA and SORNs, Privacy Training, and agency use of web management and customization technologies (cookies)?
  • What does AP privacy control stand for?
  • NIST 800-94 addresses which technology?
  • Security reauthorizations are associated with which SDLC lifecycle phase?
  • IR 7298 Glossary of Key Information Security Terms includes terms from which sources?
  • Which VPN architecture option is described as the most common model for secure remote access in the material?
  • ISCP stands for what?
  • Which SP provides guidance specifically for the DNS deployment?
  • 800-39 has replaced 800-30 as the authoritative source of comprehensive risk management guidance.
  • What is the main consideration in determining the scope of protection for an information system?
  • Which media sanitization step protects confidentiality of data against a laboratory attack?
  • Which statement best describes the role of vulnerability scanning tools in government IT security?
  • As part of monitoring the security posture of agency desktops, OMB requires federal agencies to use vulnerability scanning tools that leverage the ________ protocol.
  • Which item is explicitly listed as a physical access control in the materials?
  • Which of the following is NOT a resource of the National Vulnerability Database (NVD)?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy