Free CAP Exam Braindumps (page: 31)

Page 30 of 99

Which of the following phases of the DITSCAP C&A process is used to define the C&A level of effort, to identify the main C&A roles and responsibilities, and to create an agreement on the method for implementing the security requirements?

  1. Phase 3
  2. Phase 2
  3. Phase 4
  4. Phase 1

Answer(s): D



A security policy is an overall general statement produced by senior management that dictates what role security plays within the organization.
Which of the following are required to be addressed in a well designed policy?
Each correct answer represents a part of the solution. Choose all that apply.

  1. Who is expected to exploit the vulnerability?
  2. What is being secured?
  3. Where is the vulnerability, threat, or risk?
  4. Who is expected to comply with the policy?

Answer(s): B,C,D



The Project Risk Management knowledge area focuses on which of the following processes? Each correct answer represents a complete solution. Choose all that apply.

  1. Potential Risk Monitoring
  2. Risk Management Planning
  3. Quantitative Risk Analysis
  4. Risk Monitoring and Control

Answer(s): B,C,D



Which of the following objectives are defined by integrity in the C.I.A triad of information security systems? Each correct answer represents a part of the solution. Choose three.

  1. It preserves the internal and external consistency of information.
  2. It prevents the unauthorized or unintentional modification of information by the authorized users.
  3. It prevents the intentional or unintentional unauthorized disclosure of a message's contents .
  4. It prevents the modification of information by the unauthorized users.

Answer(s): A,B,D






Post your Comments and Discuss ISC CAP exam with other Community members:

CAP Exam Discussions & Posts