CAP PDF Dumps

How to use our free isc CAP PDF Dumps

Our Free CAP PDF dumps are based on the full CAP mock exams which are available on our Web Site. The isc CAP PDF consists in questions and answers with detailed explanations.
You can use the PDF CAP practice exam as a study material to pass the CAP exam, and don't forget to try also our CAP testing engine Web Simulator.

On-Line Users: {{voteInfo.result.viewUsers}}
Subscribed Users: {{voteInfo.result.subscribedUsers}}
Thank you for your vote {{voteInfo.result.stars}} Your vote has already been submitted ({{voteInfo.result.votingPeople}} votes)

Follow us on SlideShare to see the latest available CAP tests pdf.

										
											Q1.Which of the following professionals plays the role of a monitor and takes part in the organization's
configuration management process?
 - A:   Senior Agency Information Security Officer
 - B:   Authorizing Official
 - C:   Common Control Provider
 - D:   Chief Information Officer

 solution: C



Q2.The Chief Information Officer (CIO), or Information Technology (IT) director, is a job title commonly given to the
most senior executive in an enterprise. What are the responsibilities of a Chief Information Officer?
Each correct answer represents a complete solution. Choose all that apply.
 - A:   Preserving high-level communications and working group relationships in an organization
 - B:   Facilitating the sharing of security risk-related information among authorizing officials
 - C:   Establishing effective continuous monitoring program for the organization
 - D:   Proposing the information technology needed by an enterprise to achieve its goals and then working within

a budget to implement the plan

 solution: A, C, D



Q3.The Information System Security Officer (ISSO) and Information System Security Engineer (ISSE) play the role
of a supporter and advisor, respectively. Which of the following statements are true about ISSO and ISSE?
Each correct answer represents a complete solution. Choose all that apply.
 - A:   An ISSE provides advice on the impacts of system changes.
 - B:   An ISSE manages the security of the information system that is slated for Certification & Accreditation

(C&A).
 - C:   An ISSO manages the security of the information system that is slated for Certification & Accreditation

(C&A).
 - D:   An ISSO takes part in the development activities that are required to implement system changes.
 - E:   An ISSE provides advice on the continuous monitoring of the information system.

 solution: A, C, E



Q4.Which of the following professionals is responsible for starting the Certification & Accreditation (C&A) process?
 - A:   Information system owner
 - B:   Authorizing Official
 - C:   Chief Risk Officer (CRO)
 - D:   Chief Information Officer (CIO)

 solution: A



Q5.Which of the following assessment methodologies defines a six-step technical security evaluation?
 - A:   FITSAF
 - B:   FIPS 102
 - C:   OCTAVE
 - D:   DITSCAP

 solution: B



Q6.DIACAP applies to the acquisition, operation, and sustainment of any DoD system that collects, stores,
transmits, or processes unclassified or classified information since December 1997. What phases are identified
by DIACAP?
Each correct answer represents a complete solution. Choose all that apply.
 - A:   Accreditation
 - B:   Identification
 - C:   System Definition
 - D:   Verification
 - E:   Validation
 - F:   Re-Accreditation

 solution: C, D, E, F



Q7.Mark works as a Network Administrator for NetTech Inc. He wants users to access only those resources that
are required for them. Which of the following access control models will he use?
 - A:   Mandatory Access Control
 - B:   Role-Based Access Control
 - C:   Discretionary Access Control
 - D:   Policy Access Control

 solution: B



Q8.Which of the following refers to an information security document that is used in the United States Department
of Defense (DoD) to describe and accredit networks and systems?
 - A:   FITSAF
 - B:   FIPS
 - C:   TCSEC
 - D:   SSAA

 solution: D



Q9.James work as an IT systems personnel in SoftTech Inc. He performs the following tasks:
Runs regular backups and routine tests of the validity of the backup data.
Performs data restoration from the backups whenever required.
Maintains the retained records in accordance with the established information classification policy.
What is the role played by James in the organization?
 - A:   Manager
 - B:   Owner
 - C:   Custodian
 - D:   User

 solution: C



Q10.FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for
assessing the security of information systems. Which of the following FITSAF levels shows that the procedures
and controls have been implemented?
 - A:   Level 4
 - B:   Level 1
 - C:   Level 3
 - D:   Level 5
 - E:   Level 2

 solution: C