Free ISSEP Exam Braindumps (page: 15)

Page 14 of 54

You work as a security manager for BlueWell Inc. You are going through the NIST SP 800-37 C&A methodology, which is based on four well defined phases. In which of the following phases of NIST SP 800-37 C&A methodology does the security categorization occur

  1. Continuous Monitoring
  2. Initiation
  3. Security Certification
  4. Security Accreditation

Answer(s): B



You work as a system engineer for BlueWell Inc. You are working on translating system requirements into detailed function criteria. Which of the following diagrams will help you to show all of the function requirements and their groupings in one diagram

  1. Activity diagram
  2. Functional flow block diagram (FFBD)
  3. Functional hierarchy diagram
  4. Timeline analysis diagram

Answer(s): C



Which of the following phases of DITSCAP includes the activities that are necessary for the continuing operation of an accredited IT system in its computing environment and for addressing the changing threats that a system faces throughout its life cycle

  1. Phase 1, Definition
  2. Phase 3, Validation
  3. Phase 4, Post Accreditation Phase
  4. Phase 2, Verification

Answer(s): C



Which of the following Security Control Assessment Tasks evaluates the operational, technical, and the management security controls of the information system using the techniques and measures selected or developed

  1. Security Control Assessment Task 3
  2. Security Control Assessment Task 1
  3. Security Control Assessment Task 4
  4. Security Control Assessment Task 2

Answer(s): A






Post your Comments and Discuss ISC ISSEP exam with other Community members:

ISSEP Discussions & Posts