40%off
CSSLP Premium Bundle
Latest CSSLP Exam Premium Dumps provide by TrainingDump.com to help you Passing CSSLP Exam! TrainingDump.com offers the updated CSSLP exam dumps, the TrainingDump.com CSSLP exam questions has been updated to correct Answer. Get the latest TrainingDump.com CSSLP pdf dumps with Exam Engine here:
(349 Q&As Dumps, 40%OFF Special Discount: DumpsFiles)
Join the discussion
Question 138/209
In which of the following phases of the DITSCAP process does Security Test and Evaluation (ST&E) occur?
Correct Answer: C
Security Test and Evaluation (ST&E) occurs in Phase 3 of the DITSCAP C&A process. Answer D is incorrect. The Phase 1 of DITSCAP C&A is known as Definition Phase. The goal of this phase is to define the C&A level of effort, identify the main C&A roles and responsibilities, and create an agreement on the method for implementing the security requirements. The Phase 1 starts with the input of the mission need. This phase comprises three process activities: Document mission need Registration Negotiation Answer A is incorrect. The Phase 2 of DITSCAP C&A is known as Verification. The goal of this phase is to obtain a fully integrated system for certification testing and accreditation. This phase takes place between the signing of the initial version of the SSAA and the formal accreditation of the system. This phase verifies security requirements during system development. The process activities of this phase are as follows: Configuring refinement of the SSAA System development Certification analysis Assessment of the Analysis Results Answer B is incorrect. The Phase 4 of DITSCAP C&A is known as Post Accreditation. This phase starts after the system has been accredited in the Phase
3. The goal of this phase is to continue to operate and manage the system and to ensure that it will maintain an acceptable level of residual risk. The process activities of this phase are as follows: System operations Security operations Maintenance of the SSAA Change management Compliance validation
3. The goal of this phase is to continue to operate and manage the system and to ensure that it will maintain an acceptable level of residual risk. The process activities of this phase are as follows: System operations Security operations Maintenance of the SSAA Change management Compliance validation
Add Comments
- Other Question (209q)
- Q1. Shoulder surfing is a type of in-person attack in which the attacker gathers information a...
- Q2. You work as a CSO (Chief Security Officer) for Tech Perfect Inc. You want to perform the f...
- Q3. Which of the following are Service Level Agreement (SLA) structures as defined by ITIL? Ea...
- Q4. Which of the following acts is used to recognize the importance of information security to...
- Q5. Which of the following governance bodies provides management, operational and technical co...
- Q6. According to the NIST SAMATE, dynamic analysis tools operate by generating runtime vulnera...
- Q7. What are the security advantages of virtualization, as described in the NIST Information S...
- Q8. Which of the following tiers addresses risks from an information system perspective?...
- Q9. In which of the following cryptographic attacking techniques does an attacker obtain encry...
- Q10. John works as a professional Ethical Hacker. He has been assigned the project of testing t...
- Q11. Which of the following DoD directives defines DITSCAP as the standard C&A process for ...
- Q12. You work as a Security Manager for Tech Perfect Inc. The company has a Windows based netwo...
- Q13. The mission and business process level is the Tier 2. What are the various Tier 2 activiti...
- Q14. Who amongst the following makes the final accreditation decision?...
- Q15. Which of the following are the primary functions of configuration management? Each correct...
- Q16. You work as a systems engineer for BlueWell Inc. Which of the following tools will you use...
- Q17. Which of the following are the levels of public or commercial data classification system? ...
- Q18. The National Information Assurance Certification and Accreditation Process (NIACAP) is the...
- Q19. Which of the following testing methods verifies the interfaces between components against ...
- Q20. To help review or design security controls, they can be classified by several criteria. On...
- Q21. What are the subordinate tasks of the Initiate and Plan IA C&A phase of the DIACAP pro...
- Q22. Which of the following elements of the BCP process emphasizes on creating the scope and th...
- Q23. Which of the following are the types of intellectual property? Each correct answer represe...
- Q24. DoD 8500.2 establishes IA controls for information systems according to the Mission Assura...
- Q25. Which of the following terms ensures that no intentional or unintentional unauthorized mod...
- Q26. An organization monitors the hard disks of its employees' computers from time to time. Whi...
- Q27. Which of the following can be used to accomplish authentication? Each correct answer repre...
- Q28. You are advising a school district on disaster recovery plans. In case a disaster affects ...
- Q29. You work as a Security Manager for Tech Perfect Inc. The company has a Windows based netwo...
- Q30. Mark is the project manager of the NHQ project in StarTech Inc. The project has an asset v...
- Q31. Which of the following plans is designed to protect critical business processes from natur...
- Q32. Henry is the project manager of the QBG Project for his company. This project has a budget...
- Q33. FITSAF stands for Federal Information Technology Security Assessment Framework. It is a me...
- Q34. The rights of an author or a corporation to make profit from the creation of their product...
- Q35. Which of the following techniques is used to identify attacks originating from a botnet?...
- Q36. Which of the following ensures that a party to a dispute cannot deny the authenticity of t...
- Q37. Which of the following governance bodies directs and coordinates implementations of the in...
- Q38. Which of the following is a set of exclusive rights granted by a state to an inventor or h...
- Q39. Which of the following statements about the availability concept of Information security m...
- Q40. The mission and business process level is the Tier 2. What are the various Tier 2 activiti...
- Q41. Which of the following areas of information system, as separated by Information Assurance ...
- Q42. Which of the following security architectures defines how to integrate widely disparate ap...
- Q43. Which of the following characteristics are described by the DIAP Information Readiness Ass...
- Q44. Martha works as a Project Leader for BlueWell Inc. She and her team have developed account...
- Q45. In which of the following DIACAP phases is residual risk analyzed?...
- Q46. DIACAP applies to the acquisition, operation, and sustainment of any DoD system that colle...
- Q47. Which of the following security models dictates that subjects can only access objects thro...
- Q48. Bill is the project manager of the JKH Project. He and the project team have identified a ...
- Q49. Certification and Accreditation (C&A or CnA) is a process for implementing information...
- Q50. Which of the following processes culminates in an agreement between key players that a sys...
- Q51. The service-oriented modeling framework (SOMF) introduces five major life cycle modeling a...
- Q52. Companies use some special marks to distinguish their products from those of other compani...
- Q53. Which of the following individuals inspects whether the security policies, standards, guid...
- Q54. An asset with a value of $600,000 is subject to a successful malicious attack threat twice...
- Q55. The organization level is the Tier 1 and it addresses risks from an organizational perspec...
- Q56. What are the differences between managed and unmanaged code technologies? Each correct ans...
- Q57. Who amongst the following makes the final accreditation decision?...
- Q58. Which of the following are examples of passive attacks? Each correct answer represents a c...
- Q59. You are the project manager for GHY Project and are working to create a risk response for ...
- Q60. Certification and Accreditation (C&A or CnA) is a process for implementing information...
- Q61. Stella works as a system engineer for BlueWell Inc. She wants to identify the performance ...
- Q62. Which of the following are examples of the application programming interface (API)? Each c...
- Q63. Which of the following organizations assists the President in overseeing the preparation o...
- Q64. Which of the following is a malicious exploit of a website, whereby unauthorized commands ...
- Q65. Which of the following security controls works as the totality of protection mechanisms wi...
- Q66. Software Development Life Cycle (SDLC) is a logical process used by programmers to develop...
- Q67. The LeGrand Vulnerability-Oriented Risk Management method is based on vulnerability analys...
- Q68. Which of the following is the duration of time and a service level within which a business...
- Q69. Adam works as a Computer Hacking Forensic Investigator for a garment company in the United...
- Q70. Harry is the project manager of the MMQ Construction Project. In this project, Harry has i...
- Q71. Which of the following are the initial steps required to perform a risk analysis process? ...
- Q72. Software Development Life Cycle (SDLC) is a logical process used by programmers to develop...
- Q73. What are the various benefits of a software interface according to the "Enhancing the Deve...
- Q74. You are responsible for network and information security at a metropolitan police station....
- Q75. Which of the following are the important areas addressed by a software system's security p...
- Q76. Which of the following governance bodies provides management, operational and technical co...
- Q77. The Systems Development Life Cycle (SDLC) is the process of creating or altering the syste...
- Q78. Which of the following are the common roles with regard to data in an information classifi...
- Q79. Which of the following disaster recovery tests includes the operations that shut down at t...
- Q80. Which of the following phases of the DITSCAP C&A process is used to define the C&A...
- Q81. The NIST Information Security and Privacy Advisory Board (ISPAB) paper "Perspectives on Cl...
- Q82. Which of the following ISO standards is entitled as "Information technology - Security tec...
- Q83. Which of the following policies can explain how the company interacts with partners, the c...
- Q84. Which of the following statements describe the main purposes of a Regulatory policy? Each ...
- Q85. Which of the following DITSCAP phases validates that the preceding work has produced an IS...
- Q86. Which of the following activities are performed by the 'Do' cycle component of PDCA (plan-...
- Q87. You are the project manager of the NNN project for your company. You and the project team ...
- Q88. Which of the following are the goals of risk management? Each correct answer represents a ...
- Q89. What project management plan is most likely to direct the quantitative risk analysis proce...
- Q90. Which of the following NIST Special Publication documents provides a guideline on question...
- Q91. Which of the following types of attacks occurs when an attacker successfully inserts an in...
- Q92. To help review or design security controls, they can be classified by several criteria . O...
- Q93. A security policy is an overall general statement produced by senior management that dicta...
- Q94. The Data and Analysis Center for Software (DACS) specifies three general principles for so...
- Q95. Which of the following types of obfuscation transformation increases the difficulty for a ...
- Q96. Which of the following types of redundancy prevents attacks in which an attacker can get p...
- Q97. Which of the following methods does the Java Servlet Specification v2.4 define in the Http...
- Q98. You and your project team have identified the project risks and now are analyzing the prob...
- Q99. Which of the following phases of the DITSCAP C&A process is used to define the C&A...
- Q100. Which of the following are the basic characteristics of declarative security? Each correct...
- Q101. Which of the following approaches can be used to build a security program? Each correct an...
- Q102. The NIST ITL Cloud Research Team defines some primary and secondary technologies as the fu...
- Q103. Which of the following processes identifies the threats that can impact the business conti...
- Q104. Samantha works as an Ethical Hacker for we-are-secure Inc. She wants to test the security ...
- Q105. Which of the following elements of the BCP process emphasizes on creating the scope and th...
- Q106. You are responsible for network and information security at a large hospital. It is a sign...
- Q107. Which of the following statements about the integrity concept of information security mana...
- Q108. Which of the following are the types of access controls? Each correct answer represents a ...
- Q109. In digital rights management, the level of robustness depends on the various types of tool...
- Q110. Elizabeth is a project manager for her organization and she finds risk management to be ve...
- Q111. Which of the following statements best describes the difference between the role of a data...
- Q112. You work as a CSO (Chief Security Officer) for Tech Perfect Inc. You want to perform the f...
- Q113. What are the subordinate tasks of the Implement and Validate Assigned IA Control phase in ...
- Q114. In which of the following alternative processing sites is the backup facility maintained i...
- Q115. Which of the following types of signatures is used in an Intrusion Detection System to tri...
- Q116. Which of the following is an open source network intrusion detection system?...
- Q117. There are seven risks responses that a project manager can choose from. Which risk respons...
- Q118. Which of the following are the responsibilities of a custodian with regard to data in an i...
- Q119. John works as a systems engineer for BlueWell Inc. He has modified the software, and wants...
- Q120. Which of the following are the scanning methods used in penetration testing? Each correct ...
- Q121. DRAG DROP Auditing is used to track user accounts for file and object access, logon attemp...
- Q122. Maria has been recently appointed as a Network Administrator in Gentech Inc. She has been ...
- Q123. Which of the following methods does the Java Servlet Specification v2.4 define in the Http...
- Q124. The Phase 2 of DITSCAP C&A is known as Verification. The goal of this phase is to obta...
- Q125. In which of the following cryptographic attacking techniques does an attacker obtain encry...
- Q126. Which of the following models uses a directed graph to specify the rights that a subject c...
- Q127. Which of the following security design patterns provides an alternative by requiring that ...
- Q128. Which of the following policies can explain how the company interacts with partners, the c...
- Q129. Which of the following is a standard that sets basic requirements for assessing the effect...
- Q130. Which of the following describes a residual risk as the risk remaining after a risk mitiga...
- Q131. Which of the following is a name, symbol, or slogan with which a product is identified?...
- Q132. Numerous information security standards promote good security practices and define framewo...
- Q133. You have a storage media with some data and you make efforts to remove this data. After pe...
- Q134. SIMULATION Fill in the blank with an appropriate phrase. is used to provide security mecha...
- Q135. In which of the following IDS evasion attacks does an attacker send a data packet such tha...
- Q136. Which of the following refers to the ability to ensure that the data is not modified or ta...
- Q137. Which of the following plans is a comprehensive statement of consistent actions to be take...
- Q138. In which of the following phases of the DITSCAP process does Security Test and Evaluation ...
- Q139. Which of the following refers to a process that is used for implementing information secur...
- Q140. Henry is the project manager of the QBG Project for his company. This project has a budget...
- Q141. Which of the following US Acts emphasized a "risk-based policy for cost-effective security...
- Q142. You work as a system engineer for BlueWell Inc. You want to verify that the build meets it...
- Q143. The DARPA paper defines various procedural patterns to perform secure system development p...
- Q144. Which of the following activities are performed by the 'Do' cycle component of PDCA (plan-...
- Q145. The Systems Development Life Cycle (SDLC) is the process of creating or altering the syste...
- Q146. Which of the following access control models uses a predefined set of access privileges fo...
- Q147. DRAG DROP Drag and drop the appropriate principle documents in front of their respective f...
- Q148. Which of the following SDLC phases consists of the given security controls: Misuse Case Mo...
- Q149. You are the project manager for your organization. You are preparing for the quantitative ...
- Q150. Part of your change management plan details what should happen in the change control syste...
- Q151. The Phase 1 of DITSCAP C&A is known as Definition Phase. The goal of this phase is to ...
- Q152. Which of the following is a set of exclusive rights granted by a state to an inventor or h...
- Q153. Which of the following provides an easy way to programmers for writing lower-risk applicat...
- Q154. Which of the following terms refers to the protection of data against unauthorized access?...
- Q155. Which of the following is a patch management utility that scans one or more computers on a...
- Q156. In which of the following phases of the SDLC does the software and other components of the...
- Q157. Which of the following is generally used in packages in order to determine the package or ...
- Q158. Which of the following models uses a directed graph to specify the rights that a subject c...
- Q159. A service provider guarantees for end-to-end network traffic performance to a customer. Wh...
- Q160. Which of the following is designed to detect unwanted attempts at accessing, manipulating,...
- Q161. The Phase 4 of DITSCAP C&A is known as Post Accreditation. This phase starts after the...
- Q162. Which of the following are the tasks performed by the owner in the information classificat...
- Q163. Numerous information security standards promote good security practices and define framewo...
- Q164. What component of the change management system is responsible for evaluating, testing, and...
- Q165. Numerous information security standards promote good security practices and define framewo...
- Q166. You work as a project manager for a company. The company has started a new security softwa...
- Q167. The build environment of secure coding consists of some tools that actively support secure...
- Q168. Which of the following is a patch management utility that scans one or more computers on a...
- Q169. According to U.S. Department of Defense (DoD) Instruction 8500.2, there are eight Informat...
- Q170. In which of the following processes are experienced personnel and software tools used to i...
- Q171. According to the NIST SAMATE, dynamic analysis tools operate by generating runtime vulnera...
- Q172. "Enhancing the Development Life Cycle to Produce Secure Software" summarizes the tools and...
- Q173. Which of the following are examples of the application programming interface (API)? Each c...
- Q174. According to U.S. Department of Defense (DoD) Instruction 8500.2, there are eight Informat...
- Q175. You work as a project manager for BlueWell Inc. You are working on a project and the manag...
- Q176. Which of the following processes will you involve to perform the active analysis of the sy...
- Q177. Which of the following plans is a comprehensive statement of consistent actions to be take...
- Q178. You work as the senior project manager in SoftTech Inc. You are working on a software proj...
- Q179. Which of the following components of configuration management involves periodic checks to ...
- Q180. The DoD 8500 policy series represents the Department's information assurance strategy. Whi...
- Q181. You work as a project manager for BlueWell Inc. You are preparing to plan risk responses f...
- Q182. Which of the following rated systems of the Orange book has mandatory protection of the TC...
- Q183. In which of the following SDLC phases is the system's security features configured and ena...
- Q184. You work as a Security Manager for Tech Perfect Inc. In the organization, Syslog is used f...
- Q185. Which of the following is an attack with IP fragments that cannot be reassembled?...
- Q186. Which of the following agencies is responsible for funding the development of many technol...
- Q187. An assistant from the HR Department calls you to ask the Service Hours & Maintenance S...
- Q188. Which of the following types of activities can be audited for security? Each correct answe...
- Q189. Which of the following classification levels defines the information that, if disclosed to...
- Q190. The LeGrand Vulnerability-Oriented Risk Management method is based on vulnerability analys...
- Q191. Which of the following processes describes the elements such as quantity, quality, coverag...
- Q192. Which of the following allows multiple operating systems (guests) to run concurrently on a...
- Q193. You work as a security engineer for BlueWell Inc. You want to use some techniques and proc...
- Q194. Della work as a project manager for BlueWell Inc. A threat with a dollar value of $250,000...
- Q195. Which of the following is a name, symbol, or slogan with which a product is identified?...
- Q196. Which of the following life cycle modeling activities establishes service relationships an...
- Q197. What are the subordinate tasks of the Initiate and Plan IA C&A phase of the DIACAP pro...
- Q198. Which of the following processes does the decomposition and definition sequence of the Vee...
- Q199. You work as a Security Manager for Tech Perfect Inc. You want to save all the data from th...
- Q200. In which of the following testing methods is the test engineer equipped with the knowledge...
- Q201. Which of the following attacks causes software to fail and prevents the intended users fro...
- Q202. Which of the following techniques is used to identify attacks originating from a botnet?...
- Q203. Information Security management is a process of defining the security controls in order to...
- Q204. Which of the following secure coding principles and practices defines the appearance of co...
- Q205. Which of the following security related areas are used to protect the confidentiality, int...
- Q206. Security controls are safeguards or countermeasures to avoid, counteract, or minimize secu...
- Q207. Which of the following actions does the Data Loss Prevention (DLP) technology take when an...
- Q208. Which of the following is a signature-based intrusion detection system (IDS) ?...
- Q209. The Phase 1 of DITSCAP C&A is known as Definition Phase. The goal of this phase is to ...
