All questions

Federal IT Security Professional (FITSP) Operator Practice Test

Browse all practice questions for the Federal IT Security Professional (FITSP) Operator Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Federal IT Security Professional (FITSP) Operator Practice Test course image
All questions

These questions are part of the practice quiz. Start practicing

  • RA Step 1 Task 5 requires identifying what?
  • Which publication outlines the units accomplishments during FY 2011?
  • Which category includes Exercise/Network Defense Testing in Federal Agency Incident Reporting Categories?
  • RA Step 1 Task 3 focuses on which area?
  • Which outcome meets the CSRDA requirement?
  • The Information Analysis and Infrastructure Protection (IAIP) is part of which department, and what is its primary focus?
  • What does M-03-19 cover?
  • In Malware Incident Response, which phase immediately follows Preparation?
  • In RMF-5, which item communicates the decision to accept residual risk?
  • The National Checklist Program for IT products was developed as part of CSRDA to facilitate what?
  • Which of the following is NOT a resource of the National Vulnerability Database (NVD)?
  • NIST SP 800-77 is associated with which security technology according to the source material?
  • RA Step 3 Task 1 focuses on communicating risk assessment results to whom?
  • Which is the initial step in the interconnect process?
  • SP 800 94 is the Guide to Intrusion Detection and Prevention Systems (IDPS). Which model is described for IDPS?
  • Which of the following is a phase of the Software Development Life Cycle (SDLC)?
  • RA Step 2 Task 6 determines risk by combining which two elements?
  • Malware Incident Response includes which phases in the listed sequence?
  • Who leads the privacy incident response plan according to SE-2 Privacy Incident Response?
  • Which memorandum includes Breach Notification Policy as part of its privacy provisions?
  • NIST 800-94 addresses which technology?
  • Which NIST Special Publication defines Security Services?
  • CERT/CC is best described as which type of organization?
  • Which item is listed as a malware category?
  • Which statement best describes Tier 3 risk in relation to Tier 1 and Tier 2 decisions?
  • If you need an assessment of an access control system, which IR would you consult?
  • What directive establishes a national policy for Federal Departments and agencies to identify and prioritize US critical infrastructure and key resources to protect us from terrorist attacks?
  • COPPA protects the privacy of children under what age?
  • What is a configuration item in a system?
  • In the RMF, which step directly follows 'Assess'?
  • Which document tracks remediation actions for control implementations?
  • Which input activity involves gathering information directly from on-site stakeholders?
  • Which document presents a program review titled PRISMA for information security management assistance?
  • Which of the following is an Information Sharing and Analysis Center (ISAC)?
  • What does 5 CFR 731.106 address?
  • Which SP 800 document is the Guideline for Media Santitization?
  • What are the four IDPS technologies listed?
  • How is risk assessment typically conducted over time?
  • In management controls, PL stands for which?
  • NIST SP 800-113 is associated with which security protocol according to the source material?
  • Which item is included in the Program Management Overview?
  • Which program is used to verify cryptographic modules?
  • What does FIPS 199 specify?
  • Which document defines minimum security requirements for federal information and information systems?
  • What is the main consideration in determining the scope of protection for an information system?
  • What does HMAC stand for?
  • Which references support PL-5 Privacy Impact Assessment?
  • An MOU/A document primarily documents what?
  • What does OMB Circular A-127 Revised prescribe?
  • Which control is associated with Contingency Plan Testing and Exercises in TT&E under NIST 800-84?
  • FIPS 140-2 pertains to which area?
  • What does TIC stand for in the context of M-09-32?
  • Which pairing correctly matches the SP number with its title as described?
  • FIPS 201 defines which identification standard?
  • In the security services life cycle, which phase ensures operational success?
  • Which standard governs digital certificates used by S/MIME?
  • GISRA 2000 required U.S. government agencies to implement an information security program that includes planning, assessment and protection, and was replaced by which act in 2002?
  • Tier 2 addresses risk from which perspective?
  • RA Step 3 Task 2 shares risk-related results to support risk responses. What is the primary purpose?
  • What does M-06-15 Safeguarding PII require?
  • Which act superseded the Computer Security Act of 1987?
  • What is a risk assessment summary?
  • Which SP 800 document focuses on the confidentiality of PII and breach response requirements?
  • Which publication provides an overview of information security program concepts to assist senior leadership in overseeing and supporting development and implementation?
  • What does TKIP do?
  • What does DM-2 Data Retentions and Disposal support require?
  • Which statement best describes Common Controls?
  • Which of the following is one of the five Federal Enterprise Architecture models?
  • What does RPO represent?
  • Which of the following is an operation control family?
  • Which statement about SP 800-53 Appendix J is correct?
  • SP 800-53 r4 control families count statement?
  • Which privacy control stands for Individual Participation and Redress?
  • What is the purpose of a POAM schedule?
  • What does PM-1 Information Security Program Plan document?
  • What does CCSS stand for in software security configuration contexts?
  • Which element is contained in the Information Security Program Plan?
  • Which IR would you consult for key information security terms used in NIST publications?
  • Which SP 800 document is the Guide for Security Focused Configuration Management of Information Systems?
  • What is the legal precedence for federal information security policy?
  • RA Step 1 Task 1 involves identifying the purpose of the assessment, including information the assessment will produce and the decision it will support.
  • Under the Clinger-Cohen Act, which of the following describes a National Security System?
  • COPPA, the Children's Online Privacy Protection Act, is managed by which federal agency?
  • Which of the following is listed as a malware category?
  • What is SP-800-115?
  • What is the primary purpose of symmetric key encryption?
  • Which of the following is a management control family?
  • What defines a low likelihood in risk assessment?
  • NIST Interagency Reports (NISTIRs) describe research of a technical nature intended for a specialized audience. True or False.
  • Which IR provides an overview of smart cards and mobile device authentication?
  • FIPS 198-1 defines which of the following?
  • Which references support CA-5 Plan of Action and Milestones?
  • What is the first phase of Security-Focused Configuration Management (SecCM)?
  • Which document is the implementation standard referenced for federal identity and authentication?
  • Which of the following is a stream cipher used for confidentiality among the listed symmetric algorithms?
  • Which of the following is NOT included in an Authorization Package?
  • What was the purpose for NIST developing the National Checklist Program (NCP) for IT products?
  • Which SP 800-65 step focuses on prioritization requirements?
  • What are the Investment Life Cycle phases?
  • The AES standard specifies which algorithm?
  • Asymmetric key encryption is commonly known as what?
  • Which standard discusses mapping types to categories in security categorization?
  • Which NIST IR covers biometrics validation and implementation under FIPS-201 and HSPD-12?
  • SP 800-137 ISCM guidelines define maintaining ongoing awareness of what?
  • Which of the following is NOT an information input activity for risk assessment?
  • NIST 800-83 is focused on which security domain?
  • Which statement best describes the focus of IR 7316?
  • Which type of detection is the process of comparing signatures against observed events to identify possible incidents?
  • What is the first step in the Contingency Planning Process?
  • What defines a high likelihood level?
  • In which AH mode does not create a new IP header?
  • In management controls, CA stands for which?
  • Which approach is an effective method to analyze log data?
  • RA-3 Risk Assessment is supported by which NIST publication?
  • In the security services life cycle, which phase is responsible for specifying the right solution?
  • Compared to TKIP, CCMP is described as what?
  • What does a security assessment report provide?
  • The Health Information Technology for Economic and Clinical Health Act (HITECH) is part of which act enacted in 2009?
  • Which of the following is NOT a SCAP component?
  • What does NIST 800-55 Security Metric Guide provide?
  • In identifying threat sources, which aspects are examined?
  • Major IT investments reporting for agencies is done via which exhibit?
  • In Federal Agency Incident Reporting Categories, which category corresponds to Denial of Service?
  • The ________ requires agencies to identify sensitive systems, conduct computer security training, and develop computer security plans.
  • Which security control is addressed by NIST SP 800-50?
  • Which document is known as the Secure Hash Standard?
  • Which area does User Administration cover?
  • What control ensures that an organization recognizes the importance of trustworthiness?
  • RA Step 2 Task 1 focuses on identifying threat sources of concern, including which attributes?
  • Which encryption/evaluation level is described as requiring identity-based authentication in the source material?
  • What does PM-10 Security Auth Process require?
  • Under FISMA, which items are reported to the OMB annually?
  • Which SP 800 document defines PII and impact levels and provides for confidentiality considerations of USG systems and breach response requirements?
  • Which requirement does the Computer Security Act of 1987 mandate for federal computer systems that contain sensitive information?
  • Which of the SP 800-65 CPIC steps involves establishing baseline prioritization?
  • What does IAIP stand for in the IR context?
  • What requires a Radius server?
  • Which PKI component is used to revoke certificates before expiration?
  • Which media sanitization step protects confidentiality of data against a laboratory attack?
  • Which of the following is NOT a control type in SP 800-53 r4?
  • In the security services life cycle, which phase involves engaging the right source?
  • Assessment findings are documented in which report?
  • Which of the following is NOT listed as a security domain?
  • How many control families exist within SP 800-53 r4 across control types?
  • Which action is part of the assessment process?
  • In PKI, which component serves as the database of active digital certificates for a CA?
  • Under CFAA, which definition describes a 'protected computer'?
  • Which of the following are uses for IDS and IDPS?
  • What is NIST 800-111 about?
  • What does M-03-22 Guidance for Implementing the Privacy Provisions of the E-Gov Act of 2002 cover?
  • The combination of CPE, CVE, OVAL is associated with which of the following?
  • RA Step 1 is composed of three tasks. Which statement correctly describes their grouping?
  • Which of the following is NOT listed as a type of guidance provided by an OMB Memorandum?
  • What does DI privacy control stand for?
  • Which references support CA-5 Plan of Action and Milestones?
  • In the RMF, which step involves categorizing the information system?
  • Which practice aligns with PII handling guidance?
  • What topic does NIST SP 800-12 address?
  • SP-800-39 superseded which previous NIST Special Publication?
  • Which e-authentication level requires multi-factor authentication using a hard token?
  • Which requirement is specified by DI-1 Data Quality privacy control?
  • Which media sanitization step is described as the ultimate form of sanitization?
  • In AH, which mode creates a new IP header for each packet?
  • Which of the following is a Common Control Provider responsibility?
  • Which of the following describes a key provision of the Clinger-Cohen Act?
  • Which memorandum is associated with privacy provisions that include PIA and SORNs and privacy training?
  • Which allows a user to use a single SSL connection to a Web site to securely access multiple network services?
  • Which NIST Special Publication defines CPIC?
  • Which of the following is NOT listed as a phase in the SDLC as described?
  • Security Functionality is typically defined in terms of what?
  • Which NIST Special Publication covers Security Configuration Checklists?
  • Which publication is focused on outlining the eight topic areas used for strategic information security program management under PRISM?
  • Which privacy control stands for Data Minimization and Retention?
  • Which SP 800 document is the Guide to Computer Security log Management?
  • FIPS 191 provides guidelines for the analysis of what?
  • Which directive addresses national policy for protecting critical infrastructure from terrorist attacks?
  • NIST 800-40 is primarily associated with?
  • Which item is included in an Authorization Package?
  • What is another name for the Information Technology Management Reform Act of 1996?
  • Which statement best describes the development life cycle relation to risk assessment?
  • Which statement describes the depth and coverage attributes of assessment?
  • ___________ is an aggregate of directives, rules, and practices that prescribe how an organization manages, protects, and distributes information.
  • FIPS 201 defines personal identity verification of federal employees and contractors. The standard is based on which initiative?
  • True or False: Any incident that involves compromised PII must be reported to US-CERT within one hour regardless of the incident category reporting time frame.
  • RA Step 2 Task 4 (assessing inputs) is described as selecting the analytic approach and models for the assessment. Which option correctly identifies this task?
  • Which SP 800 document is the Information Security Handbook - A guide for managers?
  • What defines a medium likelihood level?
  • Which Bluetooth security mode is non-secure?
  • What are the Risk Assessment Steps? (Risk framing)
  • Which standard is listed as an integrity standard in the material?
  • What does OMB M-04-04 E-authentication guidance provide guidance for?
  • Which action is a poor practice for long-term log storage?
  • Which sequence correctly lists the steps for handling an incident?
  • FIPS 197 specifies the algorithm known as which encryption standard?
  • What is the purpose of Capital Planning and Investment Control (CPIC)?
  • Which component is primarily used for auditing and monitoring in security controls, as suggested by the material?
  • What is the purpore of Open Security Architecture?
  • Which implementations are allowed for the AES algorithm according to FIPS 197?
  • Which SP defines malware categories and types, describes malware prevention techniques, and discusses malware response mechanisms?
  • Under the Computer Security Act of 1987, which organization was assigned to develop minimum acceptable practices, with assistance from the NSA?
  • What is Federal Enterprise Architecture?
  • Which control is described as addressing only incidents that relate to PII?
  • Tier 2 of the 3-tiered risk management approach addresses risk-related concern at which level?
  • NIST 800-92 covers which area?
  • Appendix J is based on which principle set?
  • Which statement is true about Tier 3 risk?
  • Which function takes streams of data and reduces them to a fixed size using a one-way operation?
  • Is reauthentication required every three years?
  • Which of the following is NOT a step in the four-step interconnect process?
  • In Federal Agency Incident Reporting Categories, which category corresponds to Inappropriate Usage?
  • Which statement about FIPS approval of SSL cipher suites is supported by the material?
  • IR 7298 Glossary of Key Information Security Terms includes terms from which sources?
  • Which of the following is NOT listed as an assessment task?
  • Which basic cryptographic service provides confidentiality?
  • Which statement best describes ISCM?
  • Which references support PL-5 Privacy Impact Assessment?
  • Which document is titled Automated Password Generator?
  • Which area is listed as an area covered when updating the risk assessment?
  • Which RMF step provides ongoing oversight after authorization?
  • RA-3 security control must be partially implemented prior to the implementation of other controls in order to complete the first two steps in the Risk Management Framework: True or False?
  • What does OMB use to assess investments and make funding decisions?
  • Which security control reiterates the important parts of the security categorization?
  • In Bluetooth security, which security mode enforces the link-level security?
  • What are the approved digital signature standards?
  • Which of the following is not a technical control family?
  • RA Step 4 Task 2 Update Risk Assessment specifies which areas and timing?
  • Tier 2 risk decisions are guided by decisions in which tier?
  • In the security services life cycle, which phase ensures successful closure?
  • Which system is indicated for reporting instructions changes for OMB M11-33/M11-02/M12-02?
  • What are resources of National Vulnerability Database (NVD)?
  • Which item is described as a true-floor-to-true-ceiling barrier in physical access controls?
  • FIPS 186-2 defines which standard?
  • Data Quality and Integrity is the expansion for which privacy control?
  • Which FIPS 140-2 encryption level enables environmental protections?
  • What investment life cycle model is used by GAO?
  • Which reference provides fundamentals for selecting controls?
  • Which act first officially declared what constitutes a National Security System?
  • Which document focuses on embedded access control mechanisms and their capabilities and limitations?
  • Which action is part of long-term log data storage?
  • Which SP 800 document covers Information Security Continuous Monitoring for Federal Information System and Org?
  • The Federal Information Security Management Act (FISMA) is Title III of which act?
  • Which SP 800 document is the Information Security Handbook - A guide for managers?
  • Which publication discusses two novel smart card types using standard handheld interfaces?
  • Which of the following statements is NOT a core principle of the Federal Enterprise Architecture?
  • NIST SP 800-63 defines which area of identity and access management?
  • Which publication addresses security and privacy in Public Cloud Computing?
  • Which GAO life cycle model is described as Select-Control-Evaluate in governance and IT investment planning?
  • Security Reauthorizations are conducted during what phase of the SDLC?
  • What does MTD stand for in the context of RTO?
  • FIPS 181 corresponds to which concept?
  • FIPS 180-3 specifies which cryptographic function?
  • Where can vulnerability information be found?
  • What are VPN architectures as listed in the material?
  • 800-39 has replaced 800-30 as the authoritative source of comprehensive risk management guidance.
  • OMB 02-01 provides guidance for what?
  • NIST IR 7359 Information Security Guide for Gov Executives provides what kind of guidance?
  • What is the first step in handling an incident?
  • What does M-02-01 cover?
  • In RA Step 2 Task 4, which elements are considered to determine likelihood?
  • Which of the following is a technical control family?
  • When a hard drive from a classified information system is recycled and reused within the organization, which media sanitization method is recommended?
  • Circular A-130 contains policy on the management of what?
  • The National Institute of Standards and Technology (NIST) was formerly known as what name?
  • Which document provides guidelines on TT&E design, testing, training, and exercises?
  • Which of the following is a storage encryption technology?
  • Which of the following is NOT a method of assessment?
  • What does ICD 704 address?
  • In the IA Policy and Standard set, which item is designated as the policy reference?
  • Authority and Purpose is the expansion for which privacy control?
  • Which Act addresses restrictions on wiretaps and access to electronic communications?
  • What does M-06-19 PII Reporting require?
  • Under the Clinger-Cohen Act, which of the following is a criterion for a system to be considered National Security System?
  • Which statement describes system registration?
  • Which option correctly lists the three tiers in Organizational Wide Risk Management?
  • Which of the following is NOT a phase of the SP 800-47 Security Guide for Interconnecting IT Systems?
  • Which of the following is NOT one of the Federal Enterprise Architecture models?
  • Which of the following is a step in the staffing process?
  • Which detection method involves comparing a predetermined profile of benign protocol activity for each protocol state against observed events to identify deviations?
  • Which item is NOT listed as part of Tier 1 risk coverage?
  • Which statement accurately describes CPIC's overall objective?
  • What is a Cold site?
  • Which NIST Special Publication covers CPIC?
  • What is the primary focus of NIST SP 800-92?
  • During what phase of the SDLC should the organization consider the security requirements?
  • Which VPN model is the least used and typically employed for remote management of servers by system administrators?
  • RA Step 1 Task 3 involves identifying Assumptions and considerations, including assumptions, constraints, risk tolerances, and priorities/trade-offs.
  • Which SCAP specification provides a standard naming and dictionary of system configuration issues?
  • Which protocols secure traffic between a browser and the SSL VPN device?
  • What does AP privacy control stand for?
  • Which CPIC-related exhibit is explicitly mentioned as part of the process?
  • ISCP stands for what?
  • What is the primary subject of IR 7206?
  • What does IR 7316 Assessment of Access Control System provide?
  • Which item is contained in the Program Management Overview?
  • In identifying threat sources, range of effects is considered for which type of threats?
  • What is the typical order of implementing security controls?
  • Which act requires each federal agency to implement an information security program and to report annually to the OMB on the adequacy of the security program, the adequacy of plans and reports relating to annual budgets, and any significant deficiency?
  • ___________ can verify the authenticity of the sender and enforce nonrepudiation to prove that the sender is who she/he claims to be and cannot deny sending it.
  • What does the Clinger-Cohen Act of 1996 require?
  • RA Step 2 Task 2 focuses on identifying what?
  • Which of the following are examples of information sources?
  • In FIPS 140-2, which level adds tamper-evident coatings?
  • Which option is NOT listed as a factor for changes to the Security Control Catalog?
  • What does CPIC stand for?
  • In what security mode are Bluetooth devices considered promiscuous?
  • What is the process of comparing definitions of what activity is considered normal against observed events to identify significant deviations called?
  • Which of the following is NOT an Assessment Testing activity?
  • Baselines are based upon the IMPACT level as defined in FIPS 199, selected via CNSSI-1253 or FIPS 200, and now implemented through catalog of controls found in SP 800-53. Baselines are based upon the IMPACT level defined in which standard?
  • Which term defines the boundary around an organization's information systems for protection purposes?
  • Which option lists the IPSEC network layer protocol components as described in the source material?
  • NIST 800-45 pertains to which domain?
  • Which requirement is specified by DM-1 Data Minimization privacy control?
  • What is the stated purpose of OMB Circular A-11?
  • Where is the catalog of controls used to implement baselines located?
  • Which phase describes capturing lessons learned to improve future responses in Malware Incident Response?
  • The Interconnection Security Agreement (ISA) primarily details what?
  • PRISM Topic Areas of Coverage provide focus on which aspect of information security program management?
  • What is EPHI?
  • Which department issues the Federal Information Security Memorandum (FISM)?
  • FIPS 190 focuses on guidelines for what?
  • CCE provides nomenclature and dictionary of what?
  • Which IPSEC component is responsible for negotiating security associations and keys?
  • RA Step 1 Task 2 involves identifying Scope, determining what will be considered in the assessment, including organizational applicability, time frame supported, and architectural/technology considerations.
  • Which of the following is a factor that affects the trustworthiness of an information system?
  • Which is the final step in the interconnect process?
  • In risk assessment planning, which element is considered primary?
  • Which of the following is not an operation control family?
  • Which NIST Special Publication defines Security Products?
  • Which phase is the first in the Security Services life cycle?
  • Which data encryption format is used by S/MIME to protect message content?
  • Why was the Computer Security Act of 1987 passed?
  • Which SP provides guidance specifically for the DNS deployment?
  • Which of the following is an actual Federal Enterprise Architecture model?
  • Which of the following is a Responsibility of the Risk Executive function?
  • What SP specifies how to run name server software with restricted privileges?
  • Which PIV specification addresses technical interoperability requirements for smartcards?
  • Which function facilitates sharing of risk information and coordinates with senior leadership?
  • Which mandate uses NIST SP-800-53?
  • Which circular covers Management's Responsibility for Enterprise Risk Management and Internal Control (Revised 07/15/2016)?
  • What SP describes Secure Portal VPNs and Secure Tunnel VPN?
  • What is the focus of FIPS 200?
  • RA Step 4 Task 1 Monitor Risk Factors covers which areas?
  • Which NIST document number is associated with IPSEC according to the source material?
  • Which SP 800 document is the Guide to Computer Security log Management?
  • Who approves FIPS?
  • Why do organizations look for automated solutions for ISCM?
  • In management controls, SA stands for which?
  • What is the first step of the ISCM process?
  • What are the two AH modes?
  • RA Step 1 Task 4 requires that each information source be described with which four elements?
  • What is the focus of SE-1 Inventory of Personally Identifiable Information?
  • What triggers updates to the risk assessment?
  • What is the US-CERT incident category name and reporting timeframe for a CAT-3 incident?
  • Which term describes the management of user accounts and access within an organization?
  • Continuous monitoring updates which document?
  • What is a National Security Letter?
  • What is used for digital signatures?
  • Which item is explicitly listed as part of Tier 1 risk coverage?
  • Which standard validates the Secure Hash Algorithm family?
  • SP 800-144 provides guidelines on security and privacy in what context?
  • Which media sanitization step involves discarding media with no other sanitization consideration?
  • The Economic Espionage Act defines economic espionage as theft or misappropriation of a trade secret with the intent to benefit which entities?
  • Which control addresses privacy risk management across the life cycles of all processes that collect or handle PII?
  • Which VPN architecture option is described as the most common model for secure remote access in the material?
  • The Clinger-Cohen Act requires alignment of IT investments with what planning process?
  • In Federal Agency Incident Reporting Categories, which category corresponds to Unauthorized Access?
  • Which privacy control corresponds to Transparency?
  • What measures are provided by 800-55 Performance Measurement Guide for Info Systems?
  • What does NIST 800-56 and 800-57 address?
  • Which of the following is an area for adjusting system categorization?
  • What best describes PL-6 Security Related Activity Planning?
  • Which VPN model is described as the most often used to provide secure remote access?
  • Which RMF step involves implementing security controls?
  • What is CCMP?
  • Under the Clinger-Cohen Act, what does the 'at risk' category indicate?
  • M-00-13 covers privacy policies and data collection on Federal Web Sites. It requires agencies to do which of the following?
  • Which organization developed the National Checklist Program (NCP) for IT products?
  • Which scenario best describes host-to-host VPN usage?
  • RMF Step 3 - Implement Controls includes which of the following activities?
  • Which items are typically included in a System Registration Declaration?
  • Which standard defines the Digital Signature Standard?
  • Which SP includes recommendations for controls to mitigate malware attacks and improve an organization's malware program?
  • What is the stated purpose of the Computer Fraud and Abuse Act (CFAA) of 1986?
  • Which document provides a standardized approach for review and measurement of an information security program?
  • Which NIST Special Publications cover Security Architecture?
  • Digital signatures provide which assurance?
  • In Federal Agency Incident Reporting Categories, which category corresponds to Scans/Probes/Attempted Access?
  • What does appendix A of 800-34 provide?
  • Which of the following is a key establishment algorithm listed as supported by Fortezza cards?
  • Which SP 800 document is the Technical Guide to Information Security Testing and Assessment and works with SP 800-53a for testing and assessment guidance?
  • Which of the following is an Information System Manager responsibility?
  • Which IPSEC protocol provides data integrity and authentication of packets?
  • NIST IR 7564 provides information about security metrics. How are these metrics categorized?
  • What does RMF stand for?
  • Which approach involves continually balancing protection of agency information and assets with the cost of security controls and mitigation strategies?
  • Which memorandum is associated with e-authentication and federal online service access criteria?
  • Which statement best describes the overall concept of risk in this context?
  • Which standard covers the Keyed-Hash Message Authentication Code (HMAC)?
  • Which documents support PL-4 Rules of Behavior?
  • RA Step 2 Task 5 determines Impact. Which elements are included?
  • RA Step 2 Task 3 focuses on identifying what domains?
  • What is the full title of the USA PATRIOT Act?
  • Which of the following is listed as a security domain example?
  • What does SP 800-66 Rev 1 Implementing the HIPAA Security Rules provide?
  • IR 7206 Smart Cards and Mobile Devices Authentication overview describes two novel types of smart cards that?
  • In Federal Agency Incident Reporting Categories, which category corresponds to Malicious Code?
  • Which of the following is an internal information source?
  • How are privacy and security described in Appendix J?
  • Which of the following is NOT a step in the Contingency Planning Process?
  • Which statement best describes the role of vulnerability scanning tools in government IT security?
  • Which of the following is a hash algorithm?
  • In Federal Agency Incident Reporting Categories, which category corresponds to Investigation?
  • Under M-06-16, what security measure is required for mobile data when the data resides on mobile devices?
  • Which of the following is NOT listed as a common control candidate?
  • Security reauthorizations are associated with which SDLC lifecycle phase?
  • Which publication is the primary source for risk management guidance in the material?
  • What is the second step in the staffing process?
  • Which privacy control stands for Transparency?
  • What is the purpose of the US Government Configuration Baseline (USGCB)?
  • Which memorandum includes elements such as PIA and SORNs, Privacy Training, and agency use of web management and customization technologies (cookies)?
  • What does RTO define?
  • What does CVE stand for?
  • Which NIST Special Publication defines the System Development Life Cycle (SDLC)?
  • Which Special Publication describes attacker tools such as backdoors?
  • Accountability, Audit, and Risk Assessment is the expansion for which privacy control?
  • Which item is explicitly listed as a physical access control in the materials?
  • Which factor does SA-13 primarily address in information security controls?
  • Which NIST SP document is associated with PIV?
  • FIPS 180-2 defines which standard?
  • Which sequence correctly lists the four steps of the interconnect process in order?
  • What is a Warm site?
  • In management controls, RA stands for which?
  • What term is used to evaluate operational information systems against the RMF to determine the security controls in place and the requirements to mitigate risk at an acceptable level?
  • What are the six steps of the RMF in the correct order?
  • What NIST Pub superseded the original SP 800-30 as the primary source for guidance on risk management?
  • In what year was the Federal Information Security Modernization Act (FISMA) enacted?
  • What is 800-61 focused on?
  • CPE provides nomenclature and dictionary for what?
  • Which of the following statements about IR 7298 is true?
  • Which memorandum focuses on E-Authentication Guidance for Federal Agencies?
  • NIST SP 800-88 covers which topic?
  • Tier 3 addresses risk from which perspective?
  • How many layers of Encryption standards are defined by FIPS?
  • Which security testing and evaluation program is used to assess security features and assurances for commercial off-the-shelf products?
  • FIPS 186-3 defines which digital signature standard?
  • Which is a focus area of the Critical Infrastructure Plan?
  • NIST SP 800-114 is associated with which topic according to the source material?
  • Which are examples of hash functions?
  • Which control requires ensuring that the collection of PII is for purposes authorized by law or regulation?
  • Which feature is associated with FIPS 140-2 Level 3 security modules?
  • What does AR privacy control stand for?
  • In AES, which parameters are variable according to the standard?
  • What are the four components of the Risk Management Framework (RMF)?
  • Which artifact provides an overview of the agency's entire IT portfolio by listing every IT investment, lifecycle, and budget-year cost information?
  • Which statement about tampering in FIPS 140-2 is accurate?
  • Which of the following is a CIO responsibility for government personnel?
  • Which document defines the Digital Signature Standard?
  • Which NIST IR describes System and Network Security Acronyms and Abbreviations?
  • What elements are components of an information system?
  • Which standard defines Security requirements for cryptographic modules?
  • Which SP standard covers Protecting PII?
  • Which memorandum is designed to force implementation of HSPD-12 Personal Identity Verification criteria along with M05-24, M06-06, M-06-18, M08-01 and M11-11?
  • What does Federal Continuity Directive 2 provide?
  • Which organization is NOT listed among the Incident Response (IR) organizations?
  • What are the five phases of the SDLC?
  • NIST SP 800-114 discusses which topic according to the source material?
  • In what year did COPPA take effect?
  • What does the E-Government Act of 2002 accomplish?
  • Capital Planning and Investment Control entails which of the following?
  • In a POAM, which field records the organization responsible for correcting a weakness?
  • In FIPS 140-2, Level 1 is described as what?
  • Which document is used to document the System Security Plan?
  • Which documents support CP-2?
  • What is NIST 800-23?
  • What is the final step in the ISCM process?
  • Which SP 800 document is the Guide to Intrusion Detection and Prevention Systems (IDPS)?
  • Which provision did the Computer Security Act of 1987 mandate regarding federal employees who use those systems?
  • Which of the following is NOT typically considered part of the CPIC decision process?
  • SP 800-83 is the guide to Malware Incident Prevention and Handling. Which of the following does it define?
  • In IR 7316, which aspects of access control mechanisms are discussed?
  • What does Authentication Header (AH) provide in IPsec?
  • Which entity provides retention schedules for federal records and coordinates with records officers and NARA?
  • As part of monitoring the security posture of agency desktops, OMB requires federal agencies to use vulnerability scanning tools that leverage the ________ protocol.
  • Which SP 800 document provides guidelines for media sanitization, including techniques and disposal?
  • Which NIST IR includes the Crypto Module Validation Program and the Crypto Algorithm Validation Program?
  • Which action is part of building an effective assurance case?
  • Following the loss of 26 million records containing PII, M-06-16 requires which of the following?
  • CSRDA stands for which act mentioned in relation to the National Checklist Program?
  • What establish the scope of protection for organizational information systems?
  • Which SP 800 document would you consult for media sanitization guidelines and tools?
  • Which NIST Special Publication provides the Guide to Applying the Risk Management Framework to Federal Information Systems?
  • Which document would you reference for a glossary of information security terms?
  • Which is the final step in the Contingency Planning Process?
  • Do the DOD and ODNI follow OMB policy and NIST guidelines for reporting instructions?
  • Which legislation requires Federal agencies to develop and implement an agency-wide information security program?
  • How does SSL VPN operate with a browser-based client?
  • FIPS 198-1 defines which keyed-hash mechanism?
  • Which NIST IR is described as the annual Interagency Report?
  • What is WPA-Personal or WPA-PSK designed for?
  • How many novel smart card types are discussed in IR 7206?
  • Which pair correctly identifies the data encryption format and digital certificate standard used by S/MIME?
  • In PKI, which component verifies a user's identity before issuing a certificate?
  • Which document supports PM-8 Critical Infrastructure Plan?
  • Which item is included in M-07-16 Privacy and Privacy Reporting?
  • What disposal method is recommended by 800-88 sanitization guidelines for paper-based medical records containing PII?
  • The Health Information Technology for Economic and Clinical Health Act (HITECH) mandates audits of health care providers to investigate HIPAA compliance and is part of which larger recovery act enacted in 2009?
  • The scope of IR 7206 includes which of the following?
  • Why was M-09-32 Trusted Internet Connections initiated?
  • Tier 1 risk coverage includes which core area?
  • What does OMB Memorandum 10-28 cover?
  • Which feature is NOT typically listed as a Network Layer Security (IPSEC) capability in the source material?
  • Which Act focuses on privacy rights of individuals to access and seek amendment of records held by federal agencies?
  • Which description best matches AR-2 Privacy Impact and Risk Assessment?
  • What does IR 6/7 require?
  • Which of the following is a security testing and evaluation program?
  • What does CVSS measure?
  • Which publication provides a cross-country perspective on validated cryptographic modules and confidence in security assurance?
  • Which statement best describes AR-6 Privacy Reporting?
  • Which security control is addressed by NIST SP 800-16?
  • FIPS 199 is Standard for Security Categorization of which?
  • What are the approved integrity standards?
  • SP-800 70 Rev2 is associated with which program?
  • What program employs a network of private sector, accredited testing laboratories to independently evaluate commercial security products in key technology areas?
  • What topic does NIST 800-46 address?
  • What is the third step in the staffing process?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy