Browse all practice questions for the Federal IT Security Professional (FITSP) Operator Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Ace the 2026 Federal IT Security Pro Operator Exam – Dominate Your Future in Cybersecurity! course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • CPE provides nomenclature and dictionary for what?
  • What is a Cold site?
  • RA Step 1 Task 3 involves identifying Assumptions and considerations, including assumptions, constraints, risk tolerances, and priorities/trade-offs.
  • Which standard covers the Keyed-Hash Message Authentication Code (HMAC)?
  • Which area is listed as an area covered when updating the risk assessment?
  • Which memorandum is associated with privacy provisions that include PIA and SORNs and privacy training?
  • Major IT investments reporting for agencies is done via which exhibit?
  • NIST IR 7359 Information Security Guide for Gov Executives provides what kind of guidance?
  • What is EPHI?
  • Which feature is NOT typically listed as a Network Layer Security (IPSEC) capability in the source material?
  • Which document provides guidelines on TT&E design, testing, training, and exercises?
  • Which of the following is a CIO responsibility for government personnel?
  • What does HMAC stand for?
  • What is the primary purpose of symmetric key encryption?
  • How does SSL VPN operate with a browser-based client?
  • Which statement best describes the focus of IR 7316?
  • Which document is known as the Secure Hash Standard?
  • What is a configuration item in a system?
  • Which implementations are allowed for the AES algorithm according to FIPS 197?
  • How many control families exist within SP 800-53 r4 across control types?
  • Which phase describes capturing lessons learned to improve future responses in Malware Incident Response?
  • Which document is titled Automated Password Generator?
  • Which standard defines Security requirements for cryptographic modules?
  • RA Step 1 Task 5 requires identifying what?
  • Which type of detection is the process of comparing signatures against observed events to identify possible incidents?
  • Which requirement is specified by DI-1 Data Quality privacy control?
  • What requires a Radius server?
  • Which of the following is a phase of the Software Development Life Cycle (SDLC)?
  • Which of the following is NOT typically considered part of the CPIC decision process?
  • Which of the following is NOT included in an Authorization Package?
  • Which document is the implementation standard referenced for federal identity and authentication?
  • What is the stated purpose of the Computer Fraud and Abuse Act (CFAA) of 1986?
  • Which NIST IR covers biometrics validation and implementation under FIPS-201 and HSPD-12?
  • What best describes PL-6 Security Related Activity Planning?
  • Which area does User Administration cover?
  • Which protocols secure traffic between a browser and the SSL VPN device?
  • What is the focus of SE-1 Inventory of Personally Identifiable Information?
  • Which memorandum focuses on E-Authentication Guidance for Federal Agencies?
  • In management controls, PL stands for which?
  • What is the first step in the Contingency Planning Process?
  • Which is the initial step in the interconnect process?
  • What are the Risk Assessment Steps? (Risk framing)
  • Which control addresses privacy risk management across the life cycles of all processes that collect or handle PII?
  • What is another name for the Information Technology Management Reform Act of 1996?
  • Which statement best describes Tier 3 risk in relation to Tier 1 and Tier 2 decisions?
  • Which of the following is a technical control family?
  • Compared to TKIP, CCMP is described as what?
  • What is the purpose of Capital Planning and Investment Control (CPIC)?
  • Which requirement is specified by DM-1 Data Minimization privacy control?
  • In a POAM, which field records the organization responsible for correcting a weakness?
  • Which statement best describes ISCM?
  • Which of the following is an area for adjusting system categorization?
  • Which item is listed as a malware category?
  • Which term describes the management of user accounts and access within an organization?
  • In Federal Agency Incident Reporting Categories, which category corresponds to Inappropriate Usage?
  • Which documents support PL-4 Rules of Behavior?
  • Which pairing correctly matches the SP number with its title as described?
  • Which of the following is NOT a control type in SP 800-53 r4?
  • FIPS 180-2 defines which standard?
  • What is the purpore of Open Security Architecture?
  • Which of the following is one of the five Federal Enterprise Architecture models?
  • Which document tracks remediation actions for control implementations?
  • Which NIST Special Publication provides the Guide to Applying the Risk Management Framework to Federal Information Systems?
  • Which SP defines malware categories and types, describes malware prevention techniques, and discusses malware response mechanisms?
  • Under the Clinger-Cohen Act, what does the 'at risk' category indicate?
  • If you need an assessment of an access control system, which IR would you consult?
  • In Federal Agency Incident Reporting Categories, which category corresponds to Denial of Service?
  • What does TIC stand for in the context of M-09-32?
  • What is NIST 800-111 about?
  • In AH, which mode creates a new IP header for each packet?
  • Security reauthorizations are associated with which SDLC lifecycle phase?
  • Which encryption/evaluation level is described as requiring identity-based authentication in the source material?
  • What are the four IDPS technologies listed?
  • Which artifact provides an overview of the agency's entire IT portfolio by listing every IT investment, lifecycle, and budget-year cost information?
  • In the IA Policy and Standard set, which item is designated as the policy reference?
  • Continuous monitoring updates which document?
  • Which description best matches AR-2 Privacy Impact and Risk Assessment?
  • What does 5 CFR 731.106 address?
  • Who approves FIPS?
  • What is the typical order of implementing security controls?
  • Which standard defines the Digital Signature Standard?
  • CCE provides nomenclature and dictionary of what?
  • Which of the following is a security testing and evaluation program?
  • What is the primary focus of NIST SP 800-92?
  • Which of the following is an internal information source?
  • Which Special Publication describes attacker tools such as backdoors?
  • How many layers of Encryption standards are defined by FIPS?
  • Which of the following is NOT a method of assessment?
  • Which of the SP 800-65 CPIC steps involves establishing baseline prioritization?
  • RA Step 3 Task 2 shares risk-related results to support risk responses. What is the primary purpose?
  • What investment life cycle model is used by GAO?
  • SP 800 94 is the Guide to Intrusion Detection and Prevention Systems (IDPS). Which model is described for IDPS?
  • What is the process of comparing definitions of what activity is considered normal against observed events to identify significant deviations called?
  • Which element is contained in the Information Security Program Plan?
  • In management controls, CA stands for which?
  • In which AH mode does not create a new IP header?
  • Tier 2 addresses risk from which perspective?
  • In risk assessment planning, which element is considered primary?
  • ISCP stands for what?
  • Which Act focuses on privacy rights of individuals to access and seek amendment of records held by federal agencies?
  • Which action is a poor practice for long-term log storage?
  • What is WPA-Personal or WPA-PSK designed for?
  • What is the purpose of the US Government Configuration Baseline (USGCB)?
  • Which e-authentication level requires multi-factor authentication using a hard token?
  • Which SP 800 document is the Technical Guide to Information Security Testing and Assessment and works with SP 800-53a for testing and assessment guidance?
  • NIST IR 7564 provides information about security metrics. How are these metrics categorized?
  • How are privacy and security described in Appendix J?
  • Which mandate uses NIST SP-800-53?
  • The AES standard specifies which algorithm?
  • Which statement best describes Common Controls?
  • In identifying threat sources, range of effects is considered for which type of threats?
  • Which standard governs digital certificates used by S/MIME?
  • What does M-03-22 Guidance for Implementing the Privacy Provisions of the E-Gov Act of 2002 cover?
  • RA Step 1 is composed of three tasks. Which statement correctly describes their grouping?
  • Which feature is associated with FIPS 140-2 Level 3 security modules?
  • What defines a low likelihood in risk assessment?
  • NIST 800-45 pertains to which domain?
  • IR 7206 Smart Cards and Mobile Devices Authentication overview describes two novel types of smart cards that?
  • Which SP 800 document provides guidelines for media sanitization, including techniques and disposal?
  • What SP specifies how to run name server software with restricted privileges?
  • What does DM-2 Data Retentions and Disposal support require?
  • Which RMF step involves implementing security controls?
  • Which statement best describes the development life cycle relation to risk assessment?
  • Is reauthentication required every three years?
  • Which of the following is NOT listed as an assessment task?
  • The Health Information Technology for Economic and Clinical Health Act (HITECH) mandates audits of health care providers to investigate HIPAA compliance and is part of which larger recovery act enacted in 2009?
  • Which NIST IR includes the Crypto Module Validation Program and the Crypto Algorithm Validation Program?
  • Which NIST Special Publication defines Security Products?
  • What does CCSS stand for in software security configuration contexts?
  • What is the legal precedence for federal information security policy?
  • PRISM Topic Areas of Coverage provide focus on which aspect of information security program management?
  • Which document focuses on embedded access control mechanisms and their capabilities and limitations?
  • Which is the final step in the interconnect process?
  • Where can vulnerability information be found?
  • Which of the following is listed as a security domain example?
  • In what year was the Federal Information Security Modernization Act (FISMA) enacted?
  • Which basic cryptographic service provides confidentiality?
  • What are the four components of the Risk Management Framework (RMF)?
  • Which NIST Special Publication covers Security Configuration Checklists?
  • FIPS 199 is Standard for Security Categorization of which?
  • When a hard drive from a classified information system is recycled and reused within the organization, which media sanitization method is recommended?
  • Which of the following is not a technical control family?
  • What is the main consideration in determining the scope of protection for an information system?
  • Which act first officially declared what constitutes a National Security System?
  • What is a risk assessment summary?
  • What are the approved digital signature standards?
  • Which publication outlines the units accomplishments during FY 2011?
  • Which GAO life cycle model is described as Select-Control-Evaluate in governance and IT investment planning?
  • Which circular covers Management's Responsibility for Enterprise Risk Management and Internal Control (Revised 07/15/2016)?
  • Which of the following is a storage encryption technology?
  • Following the loss of 26 million records containing PII, M-06-16 requires which of the following?
  • NIST SP 800-114 is associated with which topic according to the source material?
  • Authority and Purpose is the expansion for which privacy control?
  • What measures are provided by 800-55 Performance Measurement Guide for Info Systems?
  • Which statement about SP 800-53 Appendix J is correct?
  • Which references support CA-5 Plan of Action and Milestones?
  • In FIPS 140-2, Level 1 is described as what?
  • FIPS 201 defines personal identity verification of federal employees and contractors. The standard is based on which initiative?
  • What are VPN architectures as listed in the material?
  • Which program is used to verify cryptographic modules?
  • Which sequence correctly lists the steps for handling an incident?
  • The Federal Information Security Management Act (FISMA) is Title III of which act?
  • Which outcome meets the CSRDA requirement?
  • What does NIST 800-55 Security Metric Guide provide?
  • Which approach is an effective method to analyze log data?
  • How is risk assessment typically conducted over time?
  • Which security control is addressed by NIST SP 800-16?
  • Security Functionality is typically defined in terms of what?
  • NIST SP 800-88 covers which topic?
  • Which SP standard covers Protecting PII?
  • What is the first step in handling an incident?
  • The Information Analysis and Infrastructure Protection (IAIP) is part of which department, and what is its primary focus?
  • GISRA 2000 required U.S. government agencies to implement an information security program that includes planning, assessment and protection, and was replaced by which act in 2002?
  • What was the purpose for NIST developing the National Checklist Program (NCP) for IT products?
  • The Economic Espionage Act defines economic espionage as theft or misappropriation of a trade secret with the intent to benefit which entities?
  • FIPS 140-2 pertains to which area?
  • Which approach involves continually balancing protection of agency information and assets with the cost of security controls and mitigation strategies?
  • Which of the following is a stream cipher used for confidentiality among the listed symmetric algorithms?
  • Which directive addresses national policy for protecting critical infrastructure from terrorist attacks?
  • In Federal Agency Incident Reporting Categories, which category corresponds to Investigation?
  • What does NIST 800-56 and 800-57 address?
  • What are the six steps of the RMF in the correct order?
  • Which document provides a standardized approach for review and measurement of an information security program?
  • Which component is primarily used for auditing and monitoring in security controls, as suggested by the material?
  • Malware Incident Response includes which phases in the listed sequence?
  • In the security services life cycle, which phase involves engaging the right source?
  • Which documents support CP-2?
  • CSRDA stands for which act mentioned in relation to the National Checklist Program?
  • Which of the following is a management control family?
  • Which of the following is NOT listed as a security domain?
  • COPPA, the Children's Online Privacy Protection Act, is managed by which federal agency?
  • Which PKI component is used to revoke certificates before expiration?
  • SP 800-137 ISCM guidelines define maintaining ongoing awareness of what?
  • What disposal method is recommended by 800-88 sanitization guidelines for paper-based medical records containing PII?
  • Which statement describes system registration?
  • What is 800-61 focused on?
  • What SP describes Secure Portal VPNs and Secure Tunnel VPN?
  • Which privacy control stands for Individual Participation and Redress?
  • Which VPN model is described as the most often used to provide secure remote access?
  • SP-800-39 superseded which previous NIST Special Publication?
  • What does IR 7316 Assessment of Access Control System provide?
  • Which department issues the Federal Information Security Memorandum (FISM)?
  • Which NIST IR is described as the annual Interagency Report?
  • Which references support PL-5 Privacy Impact Assessment?
  • What is the focus of FIPS 200?
  • What NIST Pub superseded the original SP 800-30 as the primary source for guidance on risk management?
  • Appendix J is based on which principle set?
  • Which statement is true about Tier 3 risk?
  • Which of the following is NOT a resource of the National Vulnerability Database (NVD)?
  • Which allows a user to use a single SSL connection to a Web site to securely access multiple network services?
  • What is used for digital signatures?
  • Which is the final step in the Contingency Planning Process?
  • What does Federal Continuity Directive 2 provide?
  • Which provision did the Computer Security Act of 1987 mandate regarding federal employees who use those systems?
  • Which SP 800 document focuses on the confidentiality of PII and breach response requirements?
  • What is the primary subject of IR 7206?
  • Which data encryption format is used by S/MIME to protect message content?
  • What does M-02-01 cover?
  • Which scenario best describes host-to-host VPN usage?
  • Which detection method involves comparing a predetermined profile of benign protocol activity for each protocol state against observed events to identify deviations?
  • Which IPSEC protocol provides data integrity and authentication of packets?
  • Which of the following is an Information System Manager responsibility?
  • What is the stated purpose of OMB Circular A-11?
  • Which item is included in an Authorization Package?
  • What elements are components of an information system?
  • What does IR 6/7 require?
  • Under the Clinger-Cohen Act, which of the following is a criterion for a system to be considered National Security System?
  • In AES, which parameters are variable according to the standard?
  • Which SP 800 document is the Information Security Handbook - A guide for managers?
  • What is the first step of the ISCM process?
  • Which organization developed the National Checklist Program (NCP) for IT products?
  • RA-3 security control must be partially implemented prior to the implementation of other controls in order to complete the first two steps in the Risk Management Framework: True or False?
  • Which NIST Special Publications cover Security Architecture?
  • Which of the following is NOT a step in the four-step interconnect process?
  • The Clinger-Cohen Act requires alignment of IT investments with what planning process?
  • Which SP includes recommendations for controls to mitigate malware attacks and improve an organization's malware program?
  • ___________ is an aggregate of directives, rules, and practices that prescribe how an organization manages, protects, and distributes information.
  • What does PM-10 Security Auth Process require?
  • Which of the following is a step in the staffing process?
  • Which SP 800 document is the Guide to Computer Security log Management?
  • SP 800-53 r4 control families count statement?
  • Which document presents a program review titled PRISMA for information security management assistance?
  • Which option lists the IPSEC network layer protocol components as described in the source material?
  • Which IR would you consult for key information security terms used in NIST publications?
  • The combination of CPE, CVE, OVAL is associated with which of the following?
  • Which privacy control stands for Transparency?
  • Which SP 800 document covers Information Security Continuous Monitoring for Federal Information System and Org?
  • What does a security assessment report provide?
  • The Interconnection Security Agreement (ISA) primarily details what?
  • In Malware Incident Response, which phase immediately follows Preparation?
  • What does OMB use to assess investments and make funding decisions?
  • 800-39 has replaced 800-30 as the authoritative source of comprehensive risk management guidance.
  • As part of monitoring the security posture of agency desktops, OMB requires federal agencies to use vulnerability scanning tools that leverage the ________ protocol.
  • Which publication discusses two novel smart card types using standard handheld interfaces?
  • Which security control is addressed by NIST SP 800-50?
  • Which option correctly lists the three tiers in Organizational Wide Risk Management?
  • What does the Clinger-Cohen Act of 1996 require?
  • What does M-06-19 PII Reporting require?
  • Which requirement does the Computer Security Act of 1987 mandate for federal computer systems that contain sensitive information?
  • RMF Step 3 - Implement Controls includes which of the following activities?
  • Which VPN architecture option is described as the most common model for secure remote access in the material?
  • FIPS 186-3 defines which digital signature standard?
  • In PKI, which component serves as the database of active digital certificates for a CA?
  • RA Step 2 Task 6 determines risk by combining which two elements?
  • Which of the following is a key establishment algorithm listed as supported by Fortezza cards?
  • Which NIST Special Publication defines CPIC?
  • Which memorandum is associated with e-authentication and federal online service access criteria?
  • NIST 800-92 covers which area?
  • Which item is contained in the Program Management Overview?
  • Which statement best describes AR-6 Privacy Reporting?
  • Which practice aligns with PII handling guidance?
  • What does CVSS measure?
  • What defines a medium likelihood level?
  • What is the final step in the ISCM process?
  • Which items are typically included in a System Registration Declaration?
  • What are the five phases of the SDLC?
  • NIST SP 800-77 is associated with which security technology according to the source material?
  • An MOU/A document primarily documents what?
  • Which of the following is listed as a malware category?
  • Circular A-130 contains policy on the management of what?
  • Which SP 800 document is the Guide for Security Focused Configuration Management of Information Systems?
  • Which Act addresses restrictions on wiretaps and access to electronic communications?
  • In RA Step 2 Task 4, which elements are considered to determine likelihood?
  • RA Step 4 Task 1 Monitor Risk Factors covers which areas?
  • What defines a high likelihood level?
  • Which standard is listed as an integrity standard in the material?
  • RA Step 4 Task 2 Update Risk Assessment specifies which areas and timing?
  • Which of the following is NOT a phase of the SP 800-47 Security Guide for Interconnecting IT Systems?
  • Which IPSEC component is responsible for negotiating security associations and keys?
  • RA Step 1 Task 4 requires that each information source be described with which four elements?
  • Which of the following is NOT listed as a common control candidate?
  • NIST Interagency Reports (NISTIRs) describe research of a technical nature intended for a specialized audience. True or False.
  • ___________ can verify the authenticity of the sender and enforce nonrepudiation to prove that the sender is who she/he claims to be and cannot deny sending it.
  • What does FIPS 199 specify?
  • Which memorandum is designed to force implementation of HSPD-12 Personal Identity Verification criteria along with M05-24, M06-06, M-06-18, M08-01 and M11-11?
  • The Health Information Technology for Economic and Clinical Health Act (HITECH) is part of which act enacted in 2009?
  • Digital signatures provide which assurance?
  • In the security services life cycle, which phase is responsible for specifying the right solution?
  • During what phase of the SDLC should the organization consider the security requirements?
  • Which Bluetooth security mode is non-secure?
  • Data Quality and Integrity is the expansion for which privacy control?
  • RA-3 Risk Assessment is supported by which NIST publication?
  • What triggers updates to the risk assessment?
  • FIPS 197 specifies the algorithm known as which encryption standard?
  • In Federal Agency Incident Reporting Categories, which category corresponds to Unauthorized Access?
  • In what security mode are Bluetooth devices considered promiscuous?
  • Which publication provides a cross-country perspective on validated cryptographic modules and confidence in security assurance?
  • FIPS 191 provides guidelines for the analysis of what?
  • NIST 800-40 is primarily associated with?
  • What is the third step in the staffing process?
  • Which of the following statements about IR 7298 is true?
  • Which category includes Exercise/Network Defense Testing in Federal Agency Incident Reporting Categories?
  • Which security control reiterates the important parts of the security categorization?
  • Which control is associated with Contingency Plan Testing and Exercises in TT&E under NIST 800-84?
  • Tier 3 addresses risk from which perspective?
  • Which NIST IR describes System and Network Security Acronyms and Abbreviations?
  • Which of the following is NOT a step in the Contingency Planning Process?
  • In management controls, RA stands for which?
  • Which NIST document number is associated with IPSEC according to the source material?
  • Which SP 800-65 step focuses on prioritization requirements?
  • What is NIST 800-23?
  • Do the DOD and ODNI follow OMB policy and NIST guidelines for reporting instructions?
  • Which publication provides an overview of information security program concepts to assist senior leadership in overseeing and supporting development and implementation?
  • Which media sanitization step protects confidentiality of data against a laboratory attack?
  • Which action is part of the assessment process?
  • What is the purpose of a POAM schedule?
  • Which IR provides an overview of smart cards and mobile device authentication?
  • Which of the following is a hash algorithm?
  • RA Step 1 Task 3 focuses on which area?
  • What does RPO represent?
  • What topic does NIST SP 800-12 address?
  • Which act superseded the Computer Security Act of 1987?
  • Which SP provides guidance specifically for the DNS deployment?
  • Which is a focus area of the Critical Infrastructure Plan?
  • What does appendix A of 800-34 provide?
  • Which NIST SP document is associated with PIV?
  • Which NIST Special Publication defines Security Services?
  • FIPS 180-3 specifies which cryptographic function?
  • Which pair correctly identifies the data encryption format and digital certificate standard used by S/MIME?
  • Which media sanitization step involves discarding media with no other sanitization consideration?
  • FIPS 198-1 defines which of the following?
  • Who leads the privacy incident response plan according to SE-2 Privacy Incident Response?
  • What is a National Security Letter?
  • NIST SP 800-113 is associated with which security protocol according to the source material?
  • Which organization is NOT listed among the Incident Response (IR) organizations?
  • In the security services life cycle, which phase ensures operational success?
  • What does AR privacy control stand for?
  • The ________ requires agencies to identify sensitive systems, conduct computer security training, and develop computer security plans.
  • Which system is indicated for reporting instructions changes for OMB M11-33/M11-02/M12-02?
  • Which statement about FIPS approval of SSL cipher suites is supported by the material?
  • SP-800 70 Rev2 is associated with which program?
  • Which FIPS 140-2 encryption level enables environmental protections?
  • IR 7298 Glossary of Key Information Security Terms includes terms from which sources?
  • Which statement accurately describes CPIC's overall objective?
  • Under M-06-16, what security measure is required for mobile data when the data resides on mobile devices?
  • In the RMF, which step involves categorizing the information system?
  • In PKI, which component verifies a user's identity before issuing a certificate?
  • Which references support PL-5 Privacy Impact Assessment?
  • What does CPIC stand for?
  • NIST SP 800-63 defines which area of identity and access management?
  • Which input activity involves gathering information directly from on-site stakeholders?
  • What does RMF stand for?
  • Which of the following statements is NOT a core principle of the Federal Enterprise Architecture?
  • Which of the following are uses for IDS and IDPS?
  • RA Step 2 Task 3 focuses on identifying what domains?
  • What is CCMP?
  • Which of the following is an actual Federal Enterprise Architecture model?
  • Which of the following is NOT a SCAP component?
  • Which SP 800 document would you consult for media sanitization guidelines and tools?
  • Which SP 800 document is the Guide to Computer Security log Management?
  • What is Federal Enterprise Architecture?
  • Which entity provides retention schedules for federal records and coordinates with records officers and NARA?
  • Which RMF step provides ongoing oversight after authorization?
  • What does CVE stand for?
  • In the RMF, which step directly follows 'Assess'?
  • What does the E-Government Act of 2002 accomplish?
  • What is a Warm site?
  • What are the approved integrity standards?
  • Which document supports PM-8 Critical Infrastructure Plan?
  • Tier 2 risk decisions are guided by decisions in which tier?
  • RA Step 2 Task 5 determines Impact. Which elements are included?
  • Which document defines minimum security requirements for federal information and information systems?
  • What does OMB M-04-04 E-authentication guidance provide guidance for?
  • SP 800-144 provides guidelines on security and privacy in what context?
  • Which function facilitates sharing of risk information and coordinates with senior leadership?
  • Which item is NOT listed as part of Tier 1 risk coverage?
  • Which VPN model is the least used and typically employed for remote management of servers by system administrators?
  • Which SCAP specification provides a standard naming and dictionary of system configuration issues?
  • In Federal Agency Incident Reporting Categories, which category corresponds to Malicious Code?
  • Which statement best describes the overall concept of risk in this context?
  • What does M-06-15 Safeguarding PII require?
  • FIPS 201 defines which identification standard?
  • Which SP 800 document defines PII and impact levels and provides for confidentiality considerations of USG systems and breach response requirements?
  • Which item is explicitly listed as part of Tier 1 risk coverage?
  • RA Step 2 Task 4 (assessing inputs) is described as selecting the analytic approach and models for the assessment. Which option correctly identifies this task?
  • What does M-03-19 cover?
  • OMB 02-01 provides guidance for what?
  • In IR 7316, which aspects of access control mechanisms are discussed?
  • The National Institute of Standards and Technology (NIST) was formerly known as what name?
  • M-00-13 covers privacy policies and data collection on Federal Web Sites. It requires agencies to do which of the following?
  • Which option is NOT listed as a factor for changes to the Security Control Catalog?
  • Which statement about tampering in FIPS 140-2 is accurate?
  • SP 800-83 is the guide to Malware Incident Prevention and Handling. Which of the following does it define?
  • Which of the following is an operation control family?
  • In RMF-5, which item communicates the decision to accept residual risk?
  • In Bluetooth security, which security mode enforces the link-level security?
  • Which of the following is NOT listed as a type of guidance provided by an OMB Memorandum?
  • Asymmetric key encryption is commonly known as what?
  • What does DI privacy control stand for?
  • Capital Planning and Investment Control entails which of the following?
  • Which of the following is NOT an information input activity for risk assessment?
  • Which publication is focused on outlining the eight topic areas used for strategic information security program management under PRISM?
  • What are the Investment Life Cycle phases?
  • FIPS 186-2 defines which standard?
  • Which item is included in M-07-16 Privacy and Privacy Reporting?
  • FIPS 181 corresponds to which concept?
  • Which control is described as addressing only incidents that relate to PII?
  • Why was the Computer Security Act of 1987 passed?
  • What is the US-CERT incident category name and reporting timeframe for a CAT-3 incident?
  • What control ensures that an organization recognizes the importance of trustworthiness?
  • Which are examples of hash functions?
  • Which of the following describes a key provision of the Clinger-Cohen Act?
  • Which of the following is not an operation control family?
  • Baselines are based upon the IMPACT level as defined in FIPS 199, selected via CNSSI-1253 or FIPS 200, and now implemented through catalog of controls found in SP 800-53. Baselines are based upon the IMPACT level defined in which standard?
  • What does OMB Circular A-127 Revised prescribe?
  • Which of the following is NOT one of the Federal Enterprise Architecture models?
  • In Federal Agency Incident Reporting Categories, which category corresponds to Scans/Probes/Attempted Access?
  • What does IAIP stand for in the IR context?
  • Which action is part of long-term log data storage?
  • Tier 1 risk coverage includes which core area?
  • What does TKIP do?
  • Which legislation requires Federal agencies to develop and implement an agency-wide information security program?
  • Which privacy control stands for Data Minimization and Retention?
  • Which of the following is NOT an Assessment Testing activity?
  • Under the Computer Security Act of 1987, which organization was assigned to develop minimum acceptable practices, with assistance from the NSA?
  • Where is the catalog of controls used to implement baselines located?
  • What does MTD stand for in the context of RTO?
  • Which document is used to document the System Security Plan?
  • Security Reauthorizations are conducted during what phase of the SDLC?
  • What establish the scope of protection for organizational information systems?
  • Under the Clinger-Cohen Act, which of the following describes a National Security System?
  • True or False: Any incident that involves compromised PII must be reported to US-CERT within one hour regardless of the incident category reporting time frame.
  • Which item is included in the Program Management Overview?
  • What is the full title of the USA PATRIOT Act?
  • Which CPIC-related exhibit is explicitly mentioned as part of the process?
  • Why do organizations look for automated solutions for ISCM?
  • What does ICD 704 address?
  • What does OMB Memorandum 10-28 cover?
  • What is SP-800-115?
  • Which of the following is a Responsibility of the Risk Executive function?
  • Which PIV specification addresses technical interoperability requirements for smartcards?
  • What topic does NIST 800-46 address?
  • Which publication is the primary source for risk management guidance in the material?
  • The scope of IR 7206 includes which of the following?
  • Which statement best describes the role of vulnerability scanning tools in government IT security?
  • FIPS 198-1 defines which keyed-hash mechanism?
  • What are resources of National Vulnerability Database (NVD)?
  • The National Checklist Program for IT products was developed as part of CSRDA to facilitate what?
  • What directive establishes a national policy for Federal Departments and agencies to identify and prioritize US critical infrastructure and key resources to protect us from terrorist attacks?
  • Which of the following are examples of information sources?
  • What does SP 800-66 Rev 1 Implementing the HIPAA Security Rules provide?
  • Which of the following is a factor that affects the trustworthiness of an information system?
  • Under CFAA, which definition describes a 'protected computer'?
  • Which sequence correctly lists the four steps of the interconnect process in order?
  • RA Step 1 Task 1 involves identifying the purpose of the assessment, including information the assessment will produce and the decision it will support.
  • Which statement describes the depth and coverage attributes of assessment?
  • Assessment findings are documented in which report?
  • RA Step 2 Task 1 focuses on identifying threat sources of concern, including which attributes?
  • What term is used to evaluate operational information systems against the RMF to determine the security controls in place and the requirements to mitigate risk at an acceptable level?
  • Which references support CA-5 Plan of Action and Milestones?
  • Which NIST Special Publication covers CPIC?
  • Which security testing and evaluation program is used to assess security features and assurances for commercial off-the-shelf products?
  • Tier 2 of the 3-tiered risk management approach addresses risk-related concern at which level?
  • How many novel smart card types are discussed in IR 7206?
  • Which act requires each federal agency to implement an information security program and to report annually to the OMB on the adequacy of the security program, the adequacy of plans and reports relating to annual budgets, and any significant deficiency?
  • Which phase is the first in the Security Services life cycle?
  • Which standard discusses mapping types to categories in security categorization?
  • Which factor does SA-13 primarily address in information security controls?
  • Which reference provides fundamentals for selecting controls?
  • Which item is explicitly listed as a physical access control in the materials?
  • What program employs a network of private sector, accredited testing laboratories to independently evaluate commercial security products in key technology areas?
  • What does Authentication Header (AH) provide in IPsec?
  • Accountability, Audit, and Risk Assessment is the expansion for which privacy control?
  • NIST 800-83 is focused on which security domain?
  • Which item is described as a true-floor-to-true-ceiling barrier in physical access controls?
  • In management controls, SA stands for which?
  • What does RTO define?
  • In FIPS 140-2, which level adds tamper-evident coatings?
  • Which of the following is an Information Sharing and Analysis Center (ISAC)?
  • Which NIST Special Publication defines the System Development Life Cycle (SDLC)?
  • In identifying threat sources, which aspects are examined?
  • What is the first phase of Security-Focused Configuration Management (SecCM)?
  • Which SP 800 document is the Guideline for Media Santitization?
  • NIST SP 800-114 discusses which topic according to the source material?
  • CERT/CC is best described as which type of organization?
  • Why was M-09-32 Trusted Internet Connections initiated?
  • RA Step 1 Task 2 involves identifying Scope, determining what will be considered in the assessment, including organizational applicability, time frame supported, and architectural/technology considerations.
  • In what year did COPPA take effect?
  • What is the second step in the staffing process?
  • RA Step 2 Task 2 focuses on identifying what?
  • Which memorandum includes elements such as PIA and SORNs, Privacy Training, and agency use of web management and customization technologies (cookies)?
  • NIST 800-94 addresses which technology?
  • Which of the following is NOT listed as a phase in the SDLC as described?
  • Which document defines the Digital Signature Standard?
  • Which function takes streams of data and reduces them to a fixed size using a one-way operation?
  • Which media sanitization step is described as the ultimate form of sanitization?
  • Which SP 800 document is the Guide to Intrusion Detection and Prevention Systems (IDPS)?
  • What does AP privacy control stand for?
  • Which of the following is a Common Control Provider responsibility?
  • Which privacy control corresponds to Transparency?
  • What are the two AH modes?
  • RA Step 3 Task 1 focuses on communicating risk assessment results to whom?
  • Which standard validates the Secure Hash Algorithm family?
  • Which document would you reference for a glossary of information security terms?
  • FIPS 190 focuses on guidelines for what?
  • Which action is part of building an effective assurance case?
  • Which publication addresses security and privacy in Public Cloud Computing?
  • Which term defines the boundary around an organization's information systems for protection purposes?
  • Under FISMA, which items are reported to the OMB annually?
  • What does PM-1 Information Security Program Plan document?
  • Which control requires ensuring that the collection of PII is for purposes authorized by law or regulation?
  • Which memorandum includes Breach Notification Policy as part of its privacy provisions?
  • Which SP 800 document is the Information Security Handbook - A guide for managers?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy