2027 NEWEST EXAM | ALL QUESTIONS AND CORRECT
ANSWERS WITH EXPLANATIONS | GRADED A+ | VERIFIED
ANSWERS | JUST RELEASED
Selecting controls to be monitored can be best aided by what document?
a. FIPS 199
b. NIST SP 800-37
c. FISMA
d. NIST SP 800-18
FIPS 199
What document provides a standard approach to the assessment of
NIST SP 800-53 security controls?
a. FIPS 199
b. NIST SP 800-53A
c. NIST SP 800-30
d. NIST SP 800-66
NIST SP 800-53A
,Appendix D of NIST SP 800-53A describes what three basic
types of assessment methods?
a. The interview, the examination, and testing
b. The interview, the validation, and testing
c. The interview, the examination, and remediation
d. The interview, the verification, and testing
The interview, the examination, and testing
NIST SP 800-53A defines which of the following three types of
interviews, depending on the level of assessment conducted?
a. Initial, substantial, comprehensive
b. Abbreviated, substantial, comprehensive
c. Abbreviated, moderate, comprehensive
d. Abbreviated, substantial, detailed
Abbreviated, substantial, comprehensive
What NIST SP 800-53A assessment method is used to review,
inspect, and analyze assessment objects such as polices, plans,
requirements, designs,
hardware, firmware, and security activities to determine the effectiveness
of information system security controls?
a. Verification
b. Interview
c. Examination
d. Validation
Examination
, Observing or conducting the operation of physical devices,
hardware, software, and firmware and determining whether they
exhibit the desired and expected behavior describes what type of SP
800-53A assessment method?
a. Examination
b. Testing
c. Validation
d. Remediation
Testing
In continuous monitoring, tracking of proposed or actual changes to the
information system, including operating system patches, hardware,
software, and firmware is called:
a. Systems engineering
b. The system development life cycle (SDLC)
c. Configuration management and controls
d. Security categorization
Configuration management and controls
Determination of the effect of changes to the information system
on the security of the information system is called:
a. Validation analysis
b. Verification
c. Impact analysis
d. Continuous improvement
Impact analysis