Join the discussion
Question 85/209
Which of the following DITSCAP phases validates that the preceding work has produced an IS that operates in a specified computing environment?
Correct Answer: D
Explanation/Reference:
Explanation: The Phase 3 of DITSCAP C&A is known as Validation. The goal of Phase 3 is to validate that the preceding work has produced an IS that operates in a specified computing environment. AnswerC is incorrect. The goal of this phase is to define the C&A level of effort, identify the main C&A roles and responsibilities, and create an agreement on the method for implementing the security requirements.
AnswerA is incorrect. The goal of this phase is to obtain a fully integrated system for certification testing
and accreditation. AnswerB is incorrect. This phase ensures that it will maintain an acceptable level of residual risk.
Explanation: The Phase 3 of DITSCAP C&A is known as Validation. The goal of Phase 3 is to validate that the preceding work has produced an IS that operates in a specified computing environment. AnswerC is incorrect. The goal of this phase is to define the C&A level of effort, identify the main C&A roles and responsibilities, and create an agreement on the method for implementing the security requirements.
AnswerA is incorrect. The goal of this phase is to obtain a fully integrated system for certification testing
and accreditation. AnswerB is incorrect. This phase ensures that it will maintain an acceptable level of residual risk.
Add Comments
- Other Question (209q)
- Q1. Shoulder surfing is a type of in-person attack in which the attacker gathers information a...
- Q2. You work as a CSO (Chief Security Officer) for Tech Perfect Inc. You want to perform the f...
- Q3. Which of the following are Service Level Agreement (SLA) structures as defined by ITIL? Ea...
- Q4. Which of the following acts is used to recognize the importance of information security to...
- Q5. Which of the following governance bodies provides management, operational and technical co...
- Q6. According to the NIST SAMATE, dynamic analysis tools operate by generating runtime vulnera...
- Q7. What are the security advantages of virtualization, as described in the NIST Information S...
- Q8. Which of the following tiers addresses risks from an information system perspective?...
- Q9. In which of the following cryptographic attacking techniques does an attacker obtain encry...
- Q10. John works as a professional Ethical Hacker. He has been assigned the project of testing t...
- Q11. Which of the following DoD directives defines DITSCAP as the standard C&A process for ...
- Q12. You work as a Security Manager for Tech Perfect Inc. The company has a Windows based netwo...
- Q13. The mission and business process level is the Tier 2. What are the various Tier 2 activiti...
- Q14. Who amongst the following makes the final accreditation decision?...
- Q15. Which of the following are the primary functions of configuration management? Each correct...
- Q16. You work as a systems engineer for BlueWell Inc. Which of the following tools will you use...
- Q17. Which of the following are the levels of public or commercial data classification system? ...
- Q18. The National Information Assurance Certification and Accreditation Process (NIACAP) is the...
- Q19. Which of the following testing methods verifies the interfaces between components against ...
- Q20. To help review or design security controls, they can be classified by several criteria. On...
- Q21. What are the subordinate tasks of the Initiate and Plan IA C&A phase of the DIACAP pro...
- Q22. Which of the following elements of the BCP process emphasizes on creating the scope and th...
- Q23. Which of the following are the types of intellectual property? Each correct answer represe...
- Q24. DoD 8500.2 establishes IA controls for information systems according to the Mission Assura...
- Q25. Which of the following terms ensures that no intentional or unintentional unauthorized mod...
- Q26. An organization monitors the hard disks of its employees' computers from time to time. Whi...
- Q27. Which of the following can be used to accomplish authentication? Each correct answer repre...
- Q28. You are advising a school district on disaster recovery plans. In case a disaster affects ...
- Q29. You work as a Security Manager for Tech Perfect Inc. The company has a Windows based netwo...
- Q30. Mark is the project manager of the NHQ project in StarTech Inc. The project has an asset v...
- Q31. Which of the following plans is designed to protect critical business processes from natur...
- Q32. Henry is the project manager of the QBG Project for his company. This project has a budget...
- Q33. FITSAF stands for Federal Information Technology Security Assessment Framework. It is a me...
- Q34. The rights of an author or a corporation to make profit from the creation of their product...
- Q35. Which of the following techniques is used to identify attacks originating from a botnet?...
- Q36. Which of the following ensures that a party to a dispute cannot deny the authenticity of t...
- Q37. Which of the following governance bodies directs and coordinates implementations of the in...
- Q38. Which of the following is a set of exclusive rights granted by a state to an inventor or h...
- Q39. Which of the following statements about the availability concept of Information security m...
- Q40. The mission and business process level is the Tier 2. What are the various Tier 2 activiti...
- Q41. Which of the following areas of information system, as separated by Information Assurance ...
- Q42. Which of the following security architectures defines how to integrate widely disparate ap...
- Q43. Which of the following characteristics are described by the DIAP Information Readiness Ass...
- Q44. Martha works as a Project Leader for BlueWell Inc. She and her team have developed account...
- Q45. In which of the following DIACAP phases is residual risk analyzed?...
- Q46. DIACAP applies to the acquisition, operation, and sustainment of any DoD system that colle...
- Q47. Which of the following security models dictates that subjects can only access objects thro...
- Q48. Bill is the project manager of the JKH Project. He and the project team have identified a ...
- Q49. Certification and Accreditation (C&A or CnA) is a process for implementing information...
- Q50. Which of the following processes culminates in an agreement between key players that a sys...
- Q51. The service-oriented modeling framework (SOMF) introduces five major life cycle modeling a...
- Q52. Companies use some special marks to distinguish their products from those of other compani...
- Q53. Which of the following individuals inspects whether the security policies, standards, guid...
- Q54. An asset with a value of $600,000 is subject to a successful malicious attack threat twice...
- Q55. The organization level is the Tier 1 and it addresses risks from an organizational perspec...
- Q56. What are the differences between managed and unmanaged code technologies? Each correct ans...
- Q57. Who amongst the following makes the final accreditation decision?...
- Q58. Which of the following are examples of passive attacks? Each correct answer represents a c...
- Q59. You are the project manager for GHY Project and are working to create a risk response for ...
- Q60. Certification and Accreditation (C&A or CnA) is a process for implementing information...
- Q61. Stella works as a system engineer for BlueWell Inc. She wants to identify the performance ...
- Q62. Which of the following are examples of the application programming interface (API)? Each c...
- Q63. Which of the following organizations assists the President in overseeing the preparation o...
- Q64. Which of the following is a malicious exploit of a website, whereby unauthorized commands ...
- Q65. Which of the following security controls works as the totality of protection mechanisms wi...
- Q66. Software Development Life Cycle (SDLC) is a logical process used by programmers to develop...
- Q67. The LeGrand Vulnerability-Oriented Risk Management method is based on vulnerability analys...
- Q68. Which of the following is the duration of time and a service level within which a business...
- Q69. Adam works as a Computer Hacking Forensic Investigator for a garment company in the United...
- Q70. Harry is the project manager of the MMQ Construction Project. In this project, Harry has i...
- Q71. Which of the following are the initial steps required to perform a risk analysis process? ...
- Q72. Software Development Life Cycle (SDLC) is a logical process used by programmers to develop...
- Q73. What are the various benefits of a software interface according to the "Enhancing the Deve...
- Q74. You are responsible for network and information security at a metropolitan police station....
- Q75. Which of the following are the important areas addressed by a software system's security p...
- Q76. Which of the following governance bodies provides management, operational and technical co...
- Q77. The Systems Development Life Cycle (SDLC) is the process of creating or altering the syste...
- Q78. Which of the following are the common roles with regard to data in an information classifi...
- Q79. Which of the following disaster recovery tests includes the operations that shut down at t...
- Q80. Which of the following phases of the DITSCAP C&A process is used to define the C&A...
- Q81. The NIST Information Security and Privacy Advisory Board (ISPAB) paper "Perspectives on Cl...
- Q82. Which of the following ISO standards is entitled as "Information technology - Security tec...
- Q83. Which of the following policies can explain how the company interacts with partners, the c...
- Q84. Which of the following statements describe the main purposes of a Regulatory policy? Each ...
- Q85. Which of the following DITSCAP phases validates that the preceding work has produced an IS...
- Q86. Which of the following activities are performed by the 'Do' cycle component of PDCA (plan-...
- Q87. You are the project manager of the NNN project for your company. You and the project team ...
- Q88. Which of the following are the goals of risk management? Each correct answer represents a ...
- Q89. What project management plan is most likely to direct the quantitative risk analysis proce...
- Q90. Which of the following NIST Special Publication documents provides a guideline on question...
- Q91. Which of the following types of attacks occurs when an attacker successfully inserts an in...
- Q92. To help review or design security controls, they can be classified by several criteria . O...
- Q93. A security policy is an overall general statement produced by senior management that dicta...
- Q94. The Data and Analysis Center for Software (DACS) specifies three general principles for so...
- Q95. Which of the following types of obfuscation transformation increases the difficulty for a ...
- Q96. Which of the following types of redundancy prevents attacks in which an attacker can get p...
- Q97. Which of the following methods does the Java Servlet Specification v2.4 define in the Http...
- Q98. You and your project team have identified the project risks and now are analyzing the prob...
- Q99. Which of the following phases of the DITSCAP C&A process is used to define the C&A...
- Q100. Which of the following are the basic characteristics of declarative security? Each correct...
- Q101. Which of the following approaches can be used to build a security program? Each correct an...
- Q102. The NIST ITL Cloud Research Team defines some primary and secondary technologies as the fu...
- Q103. Which of the following processes identifies the threats that can impact the business conti...
- Q104. Samantha works as an Ethical Hacker for we-are-secure Inc. She wants to test the security ...
- Q105. Which of the following elements of the BCP process emphasizes on creating the scope and th...
- Q106. You are responsible for network and information security at a large hospital. It is a sign...
- Q107. Which of the following statements about the integrity concept of information security mana...
- Q108. Which of the following are the types of access controls? Each correct answer represents a ...
- Q109. In digital rights management, the level of robustness depends on the various types of tool...
- Q110. Elizabeth is a project manager for her organization and she finds risk management to be ve...
- Q111. Which of the following statements best describes the difference between the role of a data...
- Q112. You work as a CSO (Chief Security Officer) for Tech Perfect Inc. You want to perform the f...
- Q113. What are the subordinate tasks of the Implement and Validate Assigned IA Control phase in ...
- Q114. In which of the following alternative processing sites is the backup facility maintained i...
- Q115. Which of the following types of signatures is used in an Intrusion Detection System to tri...
- Q116. Which of the following is an open source network intrusion detection system?...
- Q117. There are seven risks responses that a project manager can choose from. Which risk respons...
- Q118. Which of the following are the responsibilities of a custodian with regard to data in an i...
- Q119. John works as a systems engineer for BlueWell Inc. He has modified the software, and wants...
- Q120. Which of the following are the scanning methods used in penetration testing? Each correct ...
- Q121. DRAG DROP Auditing is used to track user accounts for file and object access, logon attemp...
- Q122. Maria has been recently appointed as a Network Administrator in Gentech Inc. She has been ...
- Q123. Which of the following methods does the Java Servlet Specification v2.4 define in the Http...
- Q124. The Phase 2 of DITSCAP C&A is known as Verification. The goal of this phase is to obta...
- Q125. In which of the following cryptographic attacking techniques does an attacker obtain encry...
- Q126. Which of the following models uses a directed graph to specify the rights that a subject c...
- Q127. Which of the following security design patterns provides an alternative by requiring that ...
- Q128. Which of the following policies can explain how the company interacts with partners, the c...
- Q129. Which of the following is a standard that sets basic requirements for assessing the effect...
- Q130. Which of the following describes a residual risk as the risk remaining after a risk mitiga...
- Q131. Which of the following is a name, symbol, or slogan with which a product is identified?...
- Q132. Numerous information security standards promote good security practices and define framewo...
- Q133. You have a storage media with some data and you make efforts to remove this data. After pe...
- Q134. SIMULATION Fill in the blank with an appropriate phrase. is used to provide security mecha...
- Q135. In which of the following IDS evasion attacks does an attacker send a data packet such tha...
- Q136. Which of the following refers to the ability to ensure that the data is not modified or ta...
- Q137. Which of the following plans is a comprehensive statement of consistent actions to be take...
- Q138. In which of the following phases of the DITSCAP process does Security Test and Evaluation ...
- Q139. Which of the following refers to a process that is used for implementing information secur...
- Q140. Henry is the project manager of the QBG Project for his company. This project has a budget...
- Q141. Which of the following US Acts emphasized a "risk-based policy for cost-effective security...
- Q142. You work as a system engineer for BlueWell Inc. You want to verify that the build meets it...
- Q143. The DARPA paper defines various procedural patterns to perform secure system development p...
- Q144. Which of the following activities are performed by the 'Do' cycle component of PDCA (plan-...
- Q145. The Systems Development Life Cycle (SDLC) is the process of creating or altering the syste...
- Q146. Which of the following access control models uses a predefined set of access privileges fo...
- Q147. DRAG DROP Drag and drop the appropriate principle documents in front of their respective f...
- Q148. Which of the following SDLC phases consists of the given security controls: Misuse Case Mo...
- Q149. You are the project manager for your organization. You are preparing for the quantitative ...
- Q150. Part of your change management plan details what should happen in the change control syste...
- Q151. The Phase 1 of DITSCAP C&A is known as Definition Phase. The goal of this phase is to ...
- Q152. Which of the following is a set of exclusive rights granted by a state to an inventor or h...
- Q153. Which of the following provides an easy way to programmers for writing lower-risk applicat...
- Q154. Which of the following terms refers to the protection of data against unauthorized access?...
- Q155. Which of the following is a patch management utility that scans one or more computers on a...
- Q156. In which of the following phases of the SDLC does the software and other components of the...
- Q157. Which of the following is generally used in packages in order to determine the package or ...
- Q158. Which of the following models uses a directed graph to specify the rights that a subject c...
- Q159. A service provider guarantees for end-to-end network traffic performance to a customer. Wh...
- Q160. Which of the following is designed to detect unwanted attempts at accessing, manipulating,...
- Q161. The Phase 4 of DITSCAP C&A is known as Post Accreditation. This phase starts after the...
- Q162. Which of the following are the tasks performed by the owner in the information classificat...
- Q163. Numerous information security standards promote good security practices and define framewo...
- Q164. What component of the change management system is responsible for evaluating, testing, and...
- Q165. Numerous information security standards promote good security practices and define framewo...
- Q166. You work as a project manager for a company. The company has started a new security softwa...
- Q167. The build environment of secure coding consists of some tools that actively support secure...
- Q168. Which of the following is a patch management utility that scans one or more computers on a...
- Q169. According to U.S. Department of Defense (DoD) Instruction 8500.2, there are eight Informat...
- Q170. In which of the following processes are experienced personnel and software tools used to i...
- Q171. According to the NIST SAMATE, dynamic analysis tools operate by generating runtime vulnera...
- Q172. "Enhancing the Development Life Cycle to Produce Secure Software" summarizes the tools and...
- Q173. Which of the following are examples of the application programming interface (API)? Each c...
- Q174. According to U.S. Department of Defense (DoD) Instruction 8500.2, there are eight Informat...
- Q175. You work as a project manager for BlueWell Inc. You are working on a project and the manag...
- Q176. Which of the following processes will you involve to perform the active analysis of the sy...
- Q177. Which of the following plans is a comprehensive statement of consistent actions to be take...
- Q178. You work as the senior project manager in SoftTech Inc. You are working on a software proj...
- Q179. Which of the following components of configuration management involves periodic checks to ...
- Q180. The DoD 8500 policy series represents the Department's information assurance strategy. Whi...
- Q181. You work as a project manager for BlueWell Inc. You are preparing to plan risk responses f...
- Q182. Which of the following rated systems of the Orange book has mandatory protection of the TC...
- Q183. In which of the following SDLC phases is the system's security features configured and ena...
- Q184. You work as a Security Manager for Tech Perfect Inc. In the organization, Syslog is used f...
- Q185. Which of the following is an attack with IP fragments that cannot be reassembled?...
- Q186. Which of the following agencies is responsible for funding the development of many technol...
- Q187. An assistant from the HR Department calls you to ask the Service Hours & Maintenance S...
- Q188. Which of the following types of activities can be audited for security? Each correct answe...
- Q189. Which of the following classification levels defines the information that, if disclosed to...
- Q190. The LeGrand Vulnerability-Oriented Risk Management method is based on vulnerability analys...
- Q191. Which of the following processes describes the elements such as quantity, quality, coverag...
- Q192. Which of the following allows multiple operating systems (guests) to run concurrently on a...
- Q193. You work as a security engineer for BlueWell Inc. You want to use some techniques and proc...
- Q194. Della work as a project manager for BlueWell Inc. A threat with a dollar value of $250,000...
- Q195. Which of the following is a name, symbol, or slogan with which a product is identified?...
- Q196. Which of the following life cycle modeling activities establishes service relationships an...
- Q197. What are the subordinate tasks of the Initiate and Plan IA C&A phase of the DIACAP pro...
- Q198. Which of the following processes does the decomposition and definition sequence of the Vee...
- Q199. You work as a Security Manager for Tech Perfect Inc. You want to save all the data from th...
- Q200. In which of the following testing methods is the test engineer equipped with the knowledge...
- Q201. Which of the following attacks causes software to fail and prevents the intended users fro...
- Q202. Which of the following techniques is used to identify attacks originating from a botnet?...
- Q203. Information Security management is a process of defining the security controls in order to...
- Q204. Which of the following secure coding principles and practices defines the appearance of co...
- Q205. Which of the following security related areas are used to protect the confidentiality, int...
- Q206. Security controls are safeguards or countermeasures to avoid, counteract, or minimize secu...
- Q207. Which of the following actions does the Data Loss Prevention (DLP) technology take when an...
- Q208. Which of the following is a signature-based intrusion detection system (IDS) ?...
- Q209. The Phase 1 of DITSCAP C&A is known as Definition Phase. The goal of this phase is to ...
