ISC CGRC Actual Free Exam Questions & Community Discussion
Testing must include an assessment of the _____________ as described in the system security plan, as recorded in the risk assessment, and reflected in the accreditation boundary; all should be the same.
Response:
Response:
Correct Answer: D
Vote an answer
A written plan for recovering one or more information systems at an alternate facility in response to a major hardware or software failure or destruction of facilities.
Response:
Response:
Correct Answer: B
Vote an answer
Who has the responsibility to review and ensure that only substantive items are incorporated in the plan of action and milestones?
Response:
Response:
Correct Answer: A
Vote an answer
According to RMF which role has a primary responsibility to report the security status of the information system to the AO & other appropriate organizational officials on an ongoing basis IAW monitoring strategy (ISSO, CCP, ISSM, AO)?
Response:
Response:
Correct Answer: C
Vote an answer
Once the System Owner selects the controls he wants to Continuously Monitor, he should coordinate with AO, AODR, and ___________.
Response:
Response:
Correct Answer: D
Vote an answer
Guarding against improper information modification or destruction, and includes ensuring information non- repudiation and authenticity.
Response:
Response:
Correct Answer: A
Vote an answer
DIACAP applies to the acquisition, operation, and sustainment of any DoD system that collects, stores, transmits, or processes unclassified or classified information since December 1997.
What phases are identified by DIACAP?
Each correct answer represents a complete solution. Choose all that apply.
Response:
What phases are identified by DIACAP?
Each correct answer represents a complete solution. Choose all that apply.
Response:
Correct Answer: A,C,E,F
Vote an answer
Amy is the project manager for her company. In her current project the organization has a very low tolerance for risk events that will affect the project schedule. Management has asked Amy to consider the affect of all the risks on the project schedule.
What approach can Amy take to create a bias against risks that will affect the schedule of the project? Response:
What approach can Amy take to create a bias against risks that will affect the schedule of the project? Response:
Correct Answer: C
Vote an answer
Tailoring refers to the process by which a security control baseline is modified based on all but one of the following:
Response:
Response:
Correct Answer: B
Vote an answer
Normally the requirements documented in the __________ ________ document will formulate the scope of SCA testing.
Response:
Response:
Correct Answer: B
Vote an answer
FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for assessing the security of information systems. Which of the following FITSAF levels shows that the procedures and controls have been implemented?
Response:
Response:
Correct Answer: A
Vote an answer
Why is the early selection of assessors important to organizations implementing a systems security engineering approach?
Response:
Response:
Correct Answer: D
Vote an answer
0
0
0
10
