01. FISMA requires a determination of whether a system should be deemed a national security system. Which NIST publication supports that determination?
a) NIST SP 800-70
b) NIST SP 800-69
c) NIST SP 800-60
d) NIST SP 800-59
02. The architecture description used as a Risk Management Framework starting point identifies information system boundaries. What does a system boundary establish?
a) All other systems within the organization
b) The system overseen by the information system owner
c) The system owned by the authorizing official
d) The systems that are immediately adjacent to the intended system
03. As identified in NIST SP 800-30, a risk analysis approach can be threat-oriented, vulnerability-oriented, or which of the following?
a) Likelihood-oriented
b) Impact-oriented
c) Asset/impact-oriented
d) Mitigation-oriented
04. Which key risk term is defined as any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image or reputation), organizational assets, individuals, other organizations or the Nation through an information system via unauthorized access, destruction, disclosure or modification of information, or denial of service?
a) Threat
b) Vulnerability
c) Risk determination
d) Impact
05. In NIST SP 800-39, risk framing requires that organizations identify which of the following?
a) Risk assumption, risk constraints and risk tolerance
b) Risk planning, risk methodology and risk tolerance
c) Risk planning, risk methodology, risk tolerance and risk management
d) Risk assumption, risk constraints, risk tolerance, and priorities and trade-offs.
06. There are many prospective risks, categories of risk and ways in which risk is evaluated. Federal law requires that risk be considered in terms of mission, assets, other organizations and which of the following?
a) None of the above
b) Individuals
c) Financial
d) Policy
07. One NIST-defined role is primarily responsible for ensuring that:
1. security risk-related considerations for individual information systems, including the authorization decisions for those systems, are viewed with an organization-wide perspective against the overall strategic goals and objectives of the organization in carrying out its mission and business functions; and
2. managing risk from individual information systems is consistent across the organization, reflects organizational risk tolerance, and is weighed alongside the other organizational risks affecting mission and business success.
Which role is this?
a) Chief information officer
b) Chief information security officer
c) Risk executive
d) Head of the agency
08. Which three properties are the security objectives against which information and information systems are categorized?
a) Confidentiality, integrity and availability
b) Risk management, risk mitigation and risk monitoring
c) Confidentiality, integrity and authenticity
d) Confidentiality, sensitivity and availability
09. A condition that exists within an organization, a mission or business process, an enterprise architecture, an information system, or an environment of operation, and that increases or decreases the likelihood that a threat event will result in adverse impact, is known as which of the following?
a) An impact
b) A risk
c) A consequence
d) A predisposing condition
10. One term is defined as determining:
1. the types of risk management decisions that are reserved for specific senior leadership roles;
2. the types of risk management decisions that are deemed to be organization-wide, as against those delegated to subordinate organizations; and
3. how risk management decisions will be communicated.
Which term is being defined?
a) Risk program
b) Governance
c) Management
d) Oversight