ISC CAP Exam Questions
Certified Authorization Professional (Page 3 )

Updated On: 16-Feb-2026

DIACAP applies to the acquisition, operation, and sustainment of any DoD system that collects, stores, transmits, or processes unclassified or classified information since December 1997.
What phases are identified by DIACAP?
Each correct answer represents a complete solution. Choose all that apply.

  1. Accreditation
  2. Identification
  3. System Definition
  4. Verification
  5. Validation
  6. Re-Accreditation

Answer(s): C,D,E,F



Mark works as a Network Administrator for NetTech Inc. He wants users to access only those resources that are required for them.
Which of the following access control models will he use?

  1. Mandatory Access Control
  2. Role-Based Access Control
  3. Discretionary Access Control
  4. Policy Access Control

Answer(s): B



Which of the following refers to an information security document that is used in the United States Department of Defense (DoD) to describe and accredit networks and systems?

  1. FITSAF
  2. FIPS
  3. TCSEC
  4. SSAA

Answer(s): D



James work as an IT systems personnel in SoftTech Inc. He performs the following tasks:
Runs regular backups and routine tests of the validity of the backup data. Performs data restoration from the backups whenever required. Maintains the retained records in accordance with the established information classification policy.
What is the role played by James in the organization?

  1. Manager
  2. Owner
  3. Custodian
  4. User

Answer(s): C



FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for assessing the security of information systems.
Which of the following FITSAF levels shows that the procedures and controls have been implemented?

  1. Level 4
  2. Level 1
  3. Level 3
  4. Level 5
  5. Level 2

Answer(s): C






Post your Comments and Discuss ISC CAP exam dumps with other Community members:

Join the CAP Discussion