ExamGecko
Home / ISC / CAP / List of questions
Ask Question

ISC CAP Practice Test - Questions Answers, Page 21

Add to Whishlist

List of questions

Question 201

Report Export Collapse

You are the project manager of the CUL project in your organization. You and the project team are assessing the risk events and creating a probability and impact matrix for the identified risks.

Which one of the following statements best describes the requirements for the data type used in qualitative risk analysis?

A qualitative risk analysis requires fast and simple data to complete the analysis.
A qualitative risk analysis requires fast and simple data to complete the analysis.
A qualitative risk analysis requires accurate and unbiased data if it is to be credible.
A qualitative risk analysis requires accurate and unbiased data if it is to be credible.
A qualitative risk analysis required unbiased stakeholders with biased risk tolerances.
A qualitative risk analysis required unbiased stakeholders with biased risk tolerances.
A qualitative risk analysis encourages biased data to reveal risk tolerances.
A qualitative risk analysis encourages biased data to reveal risk tolerances.
Suggested answer: B
asked 18/09/2024
Josh Rose
45 questions

Question 202

Report Export Collapse

You are the project manager of a large construction project. Part of the project involves the wiring of the electricity in the building your project is creating. You and the project team determine the electrical work is too dangerous to perform yourself so you hire an electrician to perform the work for the project. This is an example of what type of risk response?

Transference
Transference
Mitigation
Mitigation
Avoidance
Avoidance
Acceptance
Acceptance
Suggested answer: A
asked 18/09/2024
Tiro malope
44 questions

Question 203

Report Export Collapse

You are the project manager of the GHY project for your organization. You are about to start the qualitative risk analysis process for the project and you need to determine the roles and responsibilities for conducting risk management. Where can you find this information?

Risk management plan
Risk management plan
Enterprise environmental factors
Enterprise environmental factors
Staffing management plan
Staffing management plan
Risk register
Risk register
Suggested answer: A
asked 18/09/2024
Fednol Presume
39 questions

Question 204

Report Export Collapse

The Phase 1 of DITSCAP C&A is known as Definition Phase. The goal of this phase is to define the C&A level of effort, identify the main C&A roles and responsibilities, and create an agreement on the method for implementing the security requirements. What are the process activities of this phase? Each correct answer represents a complete solution. Choose all that apply.

Registration
Registration
Document mission need
Document mission need
Negotiation
Negotiation
Initial Certification Analysis
Initial Certification Analysis
Suggested answer: A, B, C
asked 18/09/2024
Sergiu Anton
39 questions

Question 205

Report Export Collapse

You are the project manager of the GGH Project in your company. Your company is structured as a functional organization and you report to the functional manager that you are ready to move onto the quantitative risk analysis process. What things will you need as inputs for the quantitative risk analysis of the project in this scenario?

You will need the risk register, risk management plan, permission from the functional manager, and any relevant organizational process assets.
You will need the risk register, risk management plan, permission from the functional manager, and any relevant organizational process assets.
You will need the risk register, risk management plan, outputs of qualitative risk analysis, and any relevant organizational process assets.
You will need the risk register, risk management plan, outputs of qualitative risk analysis, and any relevant organizational process assets.
You will need the risk register, risk management plan, cost management plan, schedule management plan, and any relevant organizational process assets.
You will need the risk register, risk management plan, cost management plan, schedule management plan, and any relevant organizational process assets.
Quantitative risk analysis does not happen through the project manager in a functional stru cture.
Quantitative risk analysis does not happen through the project manager in a functional stru cture.
Suggested answer: C
asked 18/09/2024
Do Hien
52 questions

Question 206

Report Export Collapse

Which of the following professionals plays the role of a monitor and takes part in the organization's configuration management process?

Senior Agency Information Security Officer
Senior Agency Information Security Officer
Authorizing Official
Authorizing Official
Chief Information Officer
Chief Information Officer
Common Control Provider
Common Control Provider
Suggested answer: D
asked 18/09/2024
rita whitfield
51 questions

Question 207

Report Export Collapse

In which of the following DIACAP phases is residual risk analyzed?

Phase 2
Phase 2
Phase 4
Phase 4
Phase 5
Phase 5
Phase 3
Phase 3
Phase 1
Phase 1
Suggested answer: B
asked 18/09/2024
BRIAN SCULLION
38 questions

Question 208

Report Export Collapse

You are responsible for network and information security at a metropolitan police station. The most important concern is that unauthorized parties are not able to access data. What is this called?

Confidentiality
Confidentiality
Encryption
Encryption
Integrity
Integrity
Availability
Availability
Suggested answer: A
asked 18/09/2024
Michael Amann
43 questions

Question 209

Report Export Collapse

Mark is the project manager of the BFL project for his organization. He and the project team are creating a probability and impact matrix using RAG rating. There is some confusion and disagreement among the project team as to how a certain risk is important and priority for attention should be managed. Where can Mark determine the priority of a risk given its probability and impact?

Risk response plan
Risk response plan
Project sponsor
Project sponsor
Risk management plan
Risk management plan
Look-up table
Look-up table
Suggested answer: D
asked 18/09/2024
Chris Carter
39 questions

Question 210

Report Export Collapse

Which of the following statements are true about security risks?

Each correct answer represents a complete solution. Choose three.

They can be removed completely by taking proper actions.
They can be removed completely by taking proper actions.
They can be analyzed and measured by the risk analysis process.
They can be analyzed and measured by the risk analysis process.
They can be mitigated by reviewing and taking responsible actions based on possible risks.
They can be mitigated by reviewing and taking responsible actions based on possible risks.
They are considered an indicator of threats coupled with vulnerability.
They are considered an indicator of threats coupled with vulnerability.
Suggested answer: B, C, D
asked 18/09/2024
Miroslav Burzinskij
41 questions
Total 395 questions
Go to page: of 40
Search

Related questions