ISC CISSP-ISSEP - Information Systems Security Engineering Professional - CISSP-ISSEP Exam Practice Test
Which of the following DoD directives defines DITSCAP as the standard C&A process for the Department of Defense?
Correct Answer: A
Diane is the project manager of the HGF Project. A risk that has been identified and analyzed in the project planning processes is now coming into fruition.
What individual should respond to the risk with the preplanned risk response?
What individual should respond to the risk with the preplanned risk response?
Correct Answer: A
Which of the following characteristics are described by the DIAP Information Readiness Assessment function? Each correct answer represents a complete solution. Choose all that apply.
Correct Answer: A,B,D
Which of the following is the application of statistical methods to the monitoring and control of a process to ensure that it operates at its full potential to produce conforming product?
Correct Answer: B
Fill in the blank with an appropriate phrase. _________________ is used to verify and accredit systems by making a standard process, set of activities, general tasks, and management structure.
Correct Answer: A
Which of the following approaches can be used to build a security program? Each correct answer represents a complete solution. Choose all that apply.
Correct Answer: A,C
Which of the following DITSCAPNIACAP model phases is used to show the required evidence to support the DAA in accreditation process and conclude in an Approval To Operate (ATO) ?
Correct Answer: D
Which of the following security controls will you use for the deployment phase of the SDLC to build secure software? Each correct answer represents a complete solution. Choose all that apply.
Correct Answer: A,B,D
Which of the following are the functional analysis and allocation tools? Each correct answer represents a complete solution. Choose all that apply.
Correct Answer: B,C,D
Which of the following individuals reviews and approves project deliverables from a QA perspective?
Correct Answer: B
The phase 3 of the Risk Management Framework (RMF) process is known as mitigation planning. Which of the following processes take place in phase 3? Each correct answer represents a complete solution. Choose all that apply.
Correct Answer: A,B,C
The Information System Security Officer (ISSO) and Information System Security Engineer (ISSE) play the role of a supporter and advisor, respectively. Which of the following statements are true about ISSO and ISSE? Each correct answer represents a complete solution. Choose all that apply.
Correct Answer: B,D,E
Which of the following NIST Special Publication documents provides a guideline on network security testing?
Correct Answer: F
The National Information Assurance Certification and Accreditation Process (NIACAP) is the minimum standard process for the certification and accreditation of computer and telecommunications systems that handle U.S. national security information.
What are the different types of NIACAP accreditation? Each correct answer represents a complete solution. Choose all that apply.
What are the different types of NIACAP accreditation? Each correct answer represents a complete solution. Choose all that apply.
Correct Answer: A,C,D
Fill in the blank with the appropriate phrase.
The ____________ is the risk that remains after the implementation of new or enhanced controls.
The ____________ is the risk that remains after the implementation of new or enhanced controls.
Correct Answer: A