ISC CAP Exam Questions
Certified Authorization Professional (Page 15 )

Updated On: 17-Feb-2026

Which of the following roles is responsible for review and risk analysis of all contracts on a regular basis?

  1. The Supplier Manager
  2. The IT Service Continuity Manager
  3. The Service Catalogue Manager
  4. The Configuration Manager

Answer(s): A



You are the project manager for the NHH project. You are working with your project team to examine the project from four different defined perspectives to increase the breadth of identified risks by including internally generated risks.
What risk identification approach are you using in this example?

  1. SWOT analysis
  2. Root cause analysis
  3. Assumptions analysis
  4. Influence diagramming techniques

Answer(s): A



Which of the following are included in Physical Controls? Each correct answer represents a complete solution. Choose all that apply.

  1. Locking systems and removing unnecessary floppy or CD-ROM drives
  2. Environmental controls
  3. Password and resource management
  4. Identification and authentication methods
  5. Monitoring for intrusion
  6. Controlling individual access into the facilityand different departments

Answer(s): A,B,E,F



Which of the following NIST Special Publication documents provides a guideline on network security testing?

  1. NIST SP 800-60
  2. NIST SP 800-53A
  3. NIST SP 800-37
  4. NIST SP 800-42
  5. NIST SP 800-59
  6. NIST SP 800-53

Answer(s): D



Which one of the following is the only output for the qualitative risk analysis process?

  1. Project management plan
  2. Risk register updates
  3. Enterprise environmental factors
  4. Organizational process assets

Answer(s): B






Post your Comments and Discuss ISC CAP exam dumps with other Community members:

Join the CAP Discussion