AND CORRECT ANSWERS WITH EXPLANATIONS |
GRADED A+ | VERIFIED ANSWERS | JUST
RELEASED 2026-2027
FITSAF stands for Federal Information Technology Security Assessment
Framework. It is a methodology for assessing the security of information
systems.
Which of the following FITSAF levels shows that the procedures and
controls have been implemented?
a. level 4
b. level 1
c. level 3
d. level 5
e. level 2
level 3
,Certification and Accreditation (C&A or CnA) is a process for implementing
information security. Which of the following is the correct order of C&A
phases in a DITSCAP assessment?
A. Definition, Validation, Verification, and Post Accreditation
B. Verification, Definition, Validation, and Post Accreditation
C. Verification, Validation, Definition, and Post Accreditation
D. Definition, Verification, Validation, and Post Accreditation
Definition, Verification, Validation, and Post Accreditation
System Authorization is the risk management process. System Authorization Plan
(SAP) is a comprehensive and uniform approach to the System Authorization
Process. What are the different phases of System Authorization Plan?
Each correct answer represents a part of the solution. Choose all that apply.
A. Post-Authorization
B. Pre-certification
C. Post-certification
D. Certification
E. Authorization
Post-Authorization
Pre-certification
Certification
Authorization
,Certification and Accreditation (C&A or CnA) is a process for implementing
information security. It is a systematic procedure for evaluating, describing,
testing, and authorizing systems prior to or after a system is in
operation. Which of the following statements are true about
Certification ad Accreditation?
Each correct answer represents a complete solution. Choose two.
A. Accreditation is the official management decision given by a senior
agency official to authorize operation of an information system.
B. Accreditation is a comprehensive assessment of the management,
operational, and technical security controls in an information system.
C. Certification is the official management decision given by a senior
agency official to authorize operation of an information system.
D. Certification is a comprehensive assessment of the management,
operational, and technical security controls in an information system.
Accreditation is the official management decision given by a senior
agency official to authorize operation of an information system.
Certification is a comprehensive assessment of the management,
operational, and technical security controls in an information system.
, Which of the following requires all general support systems and major
applications to be fully certified and accredited before these systems and
applications are put into production?
Each correct answer represents a part of the solution. Choose all that
apply.
a. NIST
B. FIPS
C. FISMA
D. Office of Management and Budget (OMB)
FISMA
OMB
The National Information Assurance Certification and Accreditation
Process
(NIACAP) is the minimum standard process for the certification and
accreditation of computer and telecommunications systems that handle
U.S. national security information. What are the different types of
NIACAP accreditation?
Each correct answer represents a complete solution. Choose all that apply.
A. Secure accreditation
B. Type accreditation
C. System accreditation
D. Site accreditation
B. Type accreditation
C. System accreditation
D. Site accreditation