Questions and Answers (Grade
A+)
The authorization decision document conveys the final security authorization decision from
the authorizing official to the information system owner. The authorization decision
document contains all of the following information except?
A. Authorization decision
B. Terms and conditions for the authorization
C. Approving revisions to the SSAA
D. Authorization termination date—ANSWER--C. Approving revisions to the SSAA
Security categorization of an National Security System must consider the security categories
of all information types resident on it.
A. True
,B. False—ANSWER--A. True
NIST SP 800 53A defines three types of interview depending on the level of assessment
conducted. Which of the following NIST SP 800 53A interviews consists of informal and ad
hoc interviews?
A. Substantial
B. Abbreviated
C. Comprehensive
D. Significant—ANSWER--B. Abbreviated
How many steps are defined in the RMF process?
A. Three
B. Four
C. Six
D. Five—ANSWER--C. Six
© 2026 Copyright. All Rights Reserved. This document is
protected by copyright law, Copyrighted By Brittie Donald
, In which type of access control do user ID and password system come under?
A. Physical
B. Administrative
C. Power
D. Technical—ANSWER--D. Technical
Why would the authorization decision issue a determination of Not Authorized?
A. If the system is not authorized (NA) to process classified information.
B. If it is deemed that the agency level risk is unacceptably high.
C. If the system is mission critical and requires an interim authority to operate.
D. The information system is always accredited without any restrictions or limitations on its
operation.—ANSWER--B. If it is deemed that the agency level risk is unacceptably high.