Free CAP Exam Braindumps (page: 5)

Page 4 of 99

Certification and Accreditation (C&A or CnA) is a process for implementing information security. It is a systematic procedure for evaluating, describing, testing, and authorizing systems prior to or after a system is in operation.
Which of the following statements are true about Certification and Accreditation?
Each correct answer represents a complete solution. Choose two.

  1. Accreditation is the official management decision given by a senior agency official to authorize operation of an information system.
  2. Accreditation is a comprehensive assessment of the management, operational, and technical security controls in an information system.
  3. Certification is the official management decision given by a senior agency official to authorize operation of an information system.
  4. Certification is a comprehensive assessment of the management, operational, and technical security controls in an information system.

Answer(s): A,D



Which of the following requires all general support systems and major applications to be fully certified and accredited before these systems and applications are put into production? Each correct answer represents a part of the solution. Choose all that apply.

  1. NIST
  2. FIPS
  3. FISMA
  4. Office of Management and Budget (OMB)

Answer(s): C,D



The National Information Assurance Certification and Accreditation Process (NIACAP) is the minimum standard process for the certification and accreditation of computer and telecommunications systems that handle U.S. national security information.
What are the different types of NIACAP accreditation?
Each correct answer represents a complete solution. Choose all that apply.

  1. Secure accreditation
  2. Type accreditation
  3. System accreditation
  4. Site accreditation

Answer(s): B,C,D



According to U.S. Department of Defense (DoD) Instruction 8500.2, there are eight Information Assurance (IA) areas, and the controls are referred to as IA controls.
Which of the following are among the eight areas of IA defined by DoD?
Each correct answer represents a complete solution. Choose all that apply.

  1. VI Vulnerability and Incident Management
  2. DC Security Design & Configuration
  3. EC Enclave and Computing Environment
  4. Information systems acquisition, development, and maintenance

Answer(s): A,B,C






Post your Comments and Discuss ISC CAP exam with other Community members:

CAP Discussions & Posts