ACTUAL QUESTIONS WITH VERIFIED
ANSWERS.
What are the components of the Risk Management System?
(Select all that apply)
A Revision
B Analysis
C Evaluation
D Assessment
E Mitigation - correct answer-C, D & E
What are the steps in the Risk Management Framework
(RMF)? (Select all that apply)
A Monitor Security Controls
B Categorize System
C Authorize System
D Assess Security Controls
E Select Security Controls
F Implement Security Controls - correct answer-All of the above
,What threat environments should you consider? (Select all that
apply)
A Adversarial
B Environmental
C Structural
D Accidental - correct answer-All of the above
What should you look for when assessing vulnerabilities?
(Select all that apply)
A Residual risk
B Ease
C Likelihood
D Related threats
D Rewards - correct answer-All of the above
Which steps of the RMF are designed to mitigate risk? (Select
all that apply)
A Assess Security Controls
B Monitor Security Controls
C Select Security Controls
D Authorize System
E Implement Security Controls
F Categorize System - correct answer-C & E
,Which of the following are the activities that occur when
performing RMF Step 2, Select Security Controls? (Select all
that apply)
A Common Control Identification
B Monitoring Strategy
C Security Baseline and Overlay Selection
D Security Plan and Review Approval - correct answer-All of
the above
What activities occur during implementation of security
controls? (Select all that apply)
A Communicate updates to appropriate audiences
B Seek approvals from CIO
C Create appropriate training and communication plans
D Ensure consistency with DoD architectures
E Document security control implementation in the security plan
F Identify security controls available for inheritance - correct
answer-D, E & F
Which steps of the RMF are designed to evaluate risk? (Select
all that apply)
, A Select Security Controls
B Assess Security Controls
C Monitor Security Controls
D Authorize System
E Categorize System
F Implement Security Controls - correct answer-B, C & D
What activities occur when assessing security controls? (Select
all that apply)
A Prepare the Plan of Action and Milestones (POA&M)
B Conduct final risk determination
C Develop, plan, and approve Security Assessment Plan
D Prepare Security Assessment Report (SAR) - correct answer-
C&D
Select ALL of the correct responses. What activities occur
during implementation of security
controls?
A Ensure consistency with DoD architectures
B Document security control implementation in the security plan
C Seek approvals from CIO
D Identify security controls available for inheritance
E Communicate updates to appropriate audiences