Certified Authorization Professional – CAP – Question015

The National Information Assurance Certification and Accreditation Process (NIACAP) is the minimum standard process for the certification and accreditation of computer and telecommunications systems that handle U.S. national security information. What are the different types of NIACAP accreditation? Each correct answer represents a complete solution. Choose all that apply.

A.
Secure accreditation
B. Type accreditation
C. System accreditation
D. Site accreditation

Correct Answer: BCD

Certified Authorization Professional – CAP – Question014

Which of the following requires all general support systems and major applications to be fully certified and accredited before these systems and applications are put into production? Each correct answer represents a part of the solution. Choose all that apply.

A.
NIST
B. FIPS
C. FISMA
D. Office of Management and Budget (OMB)

Correct Answer: CD

Certified Authorization Professional – CAP – Question013

Certification and Accreditation (C&A or CnA) is a process for implementing information security. It is a systematic procedure for evaluating, describing, testing, and authorizing systems prior to or after a system is in operation. Which of the following statements are true about Certification and Accreditation? Each correct answer represents a complete solution. Choose two.

A.
Accreditation is the official management decision given by a senior agency official to authorize operation of an information system.
B. Accreditation is a comprehensive assessment of the management, operational, and technical security controls in an information system.
C. Certification is the official management decision given by a senior agency official to authorize operation of an information system.
D. Certification is a comprehensive assessment of the management, operational, and technical security controls in an information system.

Correct Answer: AD

Certified Authorization Professional – CAP – Question012

System Authorization is the risk management process. System Authorization Plan (SAP) is a comprehensive and uniform approach to the System Authorization Process. What are the different phases of System Authorization Plan? Each correct answer represents a part of the solution. Choose all that apply.

A.
Post-Authorization
B. Pre-certification
C. Post-certification
D. Certification
E. Authorization

Correct Answer: ABDE

Certified Authorization Professional – CAP – Question011

Certification and Accreditation (C&A or CnA) is a process for implementing information security. Which of the following is the correct order of C&A phases in a DITSCAP assessment?

A.
Definition, Validation, Verification, and Post Accreditation
B. Verification, Definition, Validation, and Post Accreditation
C. Verification, Validation, Definition, and Post Accreditation
D. Definition, Verification, Validation, and Post Accreditation

Correct Answer: D

Certified Authorization Professional – CAP – Question009

James work as an IT systems personnel in SoftTech Inc. He performs the following tasks: Runs regular backups and routine tests of the validity of the backup data. Performs data restoration from the backups whenever required. Maintains the retained records in accordance with the established information classification policy. What is the role played by James in the organization?

A.
Manager
B. Owner
C. Custodian
D. User

Correct Answer: C

Certified Authorization Professional – CAP – Question006

DIACAP applies to the acquisition, operation, and sustainment of any DoD system that collects, stores, transmits, or processes unclassified or classified information since December 1997. What phases are identified by DIACAP? Each correct answer represents a complete solution. Choose all that apply.

A.
Accreditation
B. Identification
C. System Definition
D. Verification
E. Validation
F. Re-Accreditation

Correct Answer: CDEF