
Latest Jul-2022 CAP Dumps PDF And Certification Training
Check your preparation for ISC CAP On-Demand Exam
ISC CAP Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
NEW QUESTION 26
Which of the following assessment methods is used to review, inspect, and analyze assessment objects?
- A. Testing
- B. Debugging
- C. Interview
- D. Examination
Answer: D
NEW QUESTION 27
You are the project manager of the NNN project for your company. You and the project team are working together to plan the risk responses for the project. You feel that the team has successfully completed the risk response planning and now you must initiate what risk process it is. Which of the following risk processes is repeated after the plan risk responses to determine if the overall project risk has been satisfactorily decreased?
- A. Risk response implementation
- B. Qualitative risk analysis
- C. Risk identification
- D. Quantitative risk analysis
Answer: D
NEW QUESTION 28
Which of the following individuals makes the final accreditation decision?
- A. CRO
- B. DAA
- C. ISSO
- D. ISSE
Answer: B
Explanation:
Section: Volume C
NEW QUESTION 29
Which of the following terms related to risk management represents the estimated frequency at which a threat is expected to occur?
- A. Annualized Rate of Occurrence (ARO)
- B. Safeguard
- C. Exposure Factor (EF)
- D. Single Loss Expectancy (SLE)
Answer: A
Explanation:
Section: Volume C
NEW QUESTION 30
Which of the following refers to an information security document that is used in the United States Department of Defense (DoD) to describe and accredit networks and systems?
- A. FIPS
- B. TCSEC
- C. FITSAF
- D. SSAA
Answer: D
NEW QUESTION 31
Which of the following phases begins with a review of the SSAA in the DITSCAP accreditation?
- A. Phase 3
- B. Phase 4
- C. Phase 1
- D. Phase 2
Answer: A
Explanation:
Section: Volume B
NEW QUESTION 32
Your project is an agricultural-based project that deals with plant irrigation systems. You have discovered a byproduct in your project that your organization could use to make a profityou're your organization seizes this opportunity it would be an example of what risk response?
- A. Positive
- B. Exploiting
- C. Enhancing
- D. Opportunistic
Answer: B
NEW QUESTION 33
Certification and Accreditation (C&A or CnA) is a process for implementing information security. It is a systematic procedure for evaluating, describing, testing, and authorizing systems prior to or after a system is in operation. Which of the following statements are true about Certification and Accreditation?
Each correct answer represents a complete solution. Choose two.
- A. Certification is a comprehensive assessment of the management, operational, and technical security controls in an information system.
- B. Accreditation is a comprehensive assessment of the management, operational, and technical security controls in an information system.
- C. Accreditation is the official management decision given by a senior agency official to authorize operation of an information system.
- D. Certification is the official management decision given by a senior agency official to authorize operation of an information system.
Answer: A,C
Explanation:
Section: Volume A
NEW QUESTION 34
In which of the following DIACAP phases is residual risk analyzed?
- A. Phase 3
- B. Phase 1
- C. Phase 4
- D. Phase 2
- E. Phase 5
Answer: C
NEW QUESTION 35
A Web-based credit card company had collected financial and personal details of Mark before issuing him a credit card. The company has now provided Mark's financial and personal details to another company. Which of the following Internet laws has the credit card issuing company violated?
- A. Trademark law
- B. Privacy law
- C. Security law
- D. Copyright law
Answer: B
Explanation:
Section: Volume A
NEW QUESTION 36
Fred is the project manager of the PKL project. He is working with his project team to complete the quantitative risk analysis process as a part of risk management planning. Fred understands that once the quantitative risk analysis process is complete, the process will need to be completed again in at least two other times in the project. When will the quantitative risk analysis process need to be repeated?
- A. Quantitative risk analysis process will be completed again after the cost managementplanning and as a part of monitoring and controlling.
- B. Quantitativerisk analysis process will be completed again after new risks are identified and as part of monitoring and controlling.
- C. Quantitative risk analysisprocess will be completed again after the plan risk response planning and as part of procurement.
- D. Quantitative risk analysis process will be completed again after the risk response planning and as a part of monitoring and controlling.
Answer: D
NEW QUESTION 37
Your organization has named you the project manager of the JKN Project. This project has a BAC of
$1,500,000 and it is expected to last 18 months. Management has agreed that if the schedule baseline has a variance of more than five percent then you will need to crash the project. What happens when the project manager crashes a project?
- A. Project costs will increase.
- B. The project will take longer to complete, but risks will diminish.
- C. Project risks will increase.
- D. The amount of hours a resource can be used will diminish.
Answer: A
NEW QUESTION 38
Which of the following individuals is responsible for preparing and submitting security status reports to the organizations?
- A. Common Control Provider
- B. Senior Agency Information Security Officer
- C. Chief Information Officer
- D. Authorizing Official
Answer: A
NEW QUESTION 39
Which of the following access control models uses a predefined set of access privileges for an object of a system?
- A. Policy Access Control
- B. Mandatory Access Control
- C. Role-Based Access Control
- D. Discretionary Access Control
Answer: B
NEW QUESTION 40
Which of the following documents is used to provide a standard approach to the assessment of NIST SP 800-53 security controls?
- A. NIST SP 800-37
- B. NIST SP 800-66
- C. NIST SP 800-53A
- D. NIST SP 800-41
Answer: C
NEW QUESTION 41
Which of the following processes is described in the statement below?
"It is the process of implementing risk response plans, tracking identified risks, monitoring residual risk, identifying new risks, and evaluating risk process effectiveness throughout the project."
- A. Monitor and Control Risks
- B. Perform Quantitative Risk Analysis
- C. Identify Risks
- D. Perform Qualitative Risk Analysis
Answer: A
Explanation:
Section: Volume C
NEW QUESTION 42
Certification and Accreditation (C&A or CnA) is a process for implementing information security. It is a systematic procedure for evaluating, describing, testing, and authorizing systems prior to or after a system is in operation. Which of the following statements are true about Certification and Accreditation?
Each correct answer represents a complete solution. Choose two.
- A. Certification is a comprehensive assessment of the management, operational, and technical security controls in an information system.
- B. Accreditation is a comprehensive assessment of the management, operational, and technical security controls in an information system.
- C. Accreditation is the official management decision given by a senior agency official to authorize operation of an information system.
- D. Certification is the official management decision given by a senior agency official to authorize operation of an information system.
Answer: A,C
Explanation:
Section: Volume B
NEW QUESTION 43
Which of the following parts of BS 7799 covers risk analysis and management?
- A. Part 4
- B. Part 2
- C. Part 3
- D. Part 1
Answer: C
Explanation:
Section: Volume D
NEW QUESTION 44
Your project uses a piece of equipment that if the temperature of the machine goes above 450 degree Fahrenheit the machine will overheat and have to be shut down for 48 hours. Should this machine overheat even once it will delay the project's end date. You work with your project to create a response that should the temperature of the machine reach 430, the machine will be paused for at least an hour to cool it down. The temperature of 430 is called what?
- A. Risk response
- B. Risk identification
- C. Risk event
- D. Risk trigger
Answer: D
NEW QUESTION 45
BS 7799 is an internationally recognized ISM standard that provides high level, conceptual recommendations on enterprise security. BS 7799 is basically divided into three parts. Which of the following statements are true about BS 7799?
Each correct answer represents a complete solution. Choose all that apply.
- A. BS 7799 Part 1 was a standard originally published as BS 7799 by the British Standards Institute (BSI) in
1995. - B. BS 7799 Part 3 was published in 2005, covering risk analysis and management.
- C. BS 7799 Part 1 was adopted by ISO as ISO/IEC 27001 in November 2005.
- D. BS 7799 Part 2 was adopted by ISO as ISO/IEC 27001 in November 2005.
Answer: A,B,D
Explanation:
Section: Volume C
NEW QUESTION 46
Which of the following statements is true about the continuous monitoring process?
- A. It takes place in the middle of system security accreditation.
- B. It takes place before the initial system security accreditation.
- C. It takes place before and after system security accreditation.
- D. It takes place after the initial system security accreditation.
Answer: D
Explanation:
Section: Volume D
NEW QUESTION 47
Which of the following refers to an information security document that is used in the United States Department of Defense (DoD) to describe and accredit networks and systems?
- A. FIPS
- B. TCSEC
- C. FITSAF
- D. SSAA
Answer: D
Explanation:
Section: Volume B
Explanation/Reference:
NEW QUESTION 48
During qualitative risk analysis you want to define the risk urgency assessment. All of the
following are indicators of risk priority except for which one?
- A. Warning signs
- B. Symptoms
- C. Cost of the project
- D. Risk rating
Answer: C
NEW QUESTION 49
......
Implementation of Security Controls (16%):
- Security Control Implementation Documentation – You need competence in capturing planned inputs, expected outputs, and expected behavior of security controls as well as validating documented details aligned with the purpose, impact, and scope of the information system. It is important to be able to acquire implementation information from the relevant organization entities.
- Implement the Chosen Security Control – This requires competence in coordinating inherited control implementation with the use of the common control providers and authenticating that security controls are constant with the enterprise architect. The interested individuals should also have the skills in determining the mandatory configuration settings and authenticating implementation as well as determining the compensating security controls;
Target Audience and Prerequisites
The CAP certification is intended for the information security, information technology, and information assurance professionals looking to validate their knowledge of RMF. These are the specialists seeking to demonstrate their advanced knowledge as well as technical abilities to formalize the processes required for assessing risk and establishing security documentation.
The potential candidates must possess at least two years of cumulative work experience in a minimum of one of the seven domains of the Certified Authorized Professional Common Book of Knowledge. Those who do not have the prerequisite experience can pass the CAP exam and become an Associate of (ISC)2 to gain some work experience.
Valid CAP Dumps for Helping Passing ISC Exam: https://www.examcollectionpass.com/ISC/CAP-practice-exam-dumps.html
Practice Exam CAP Realistic Dumps Verified Questions: https://drive.google.com/open?id=1qFFC-uVPAEoRHCvprs_BjgHMpZF_St-N