ISC CISSP-ISSEP - Information Systems Security Engineering Professional Exam
Page: 3 / 43
Total 214 questions
Question #11 (Topic: Topic 1)
Which of the following guidelines is recommended for engineering, protecting, managing, processing, and controlling national security and sensitive (although
unclassified) information
unclassified) information
A. Federal Information Processing Standard (FIPS)
B. Special Publication (SP)
C. NISTIRs (Internal Reports)
D. DIACAP by the United States Department of Defense (DoD)
Answer: B
Question #12 (Topic: Topic 1)
Which of the following Security Control Assessment Tasks gathers the documentation and supporting materials essential for the assessment of the security
controls in the information system
controls in the information system
A. Security Control Assessment Task 4
B. Security Control Assessment Task 3
C. Security Control Assessment Task 1
D. Security Control Assessment Task 2
Answer: C
Question #13 (Topic: Topic 1)
Which of the following professionals plays the role of a monitor and takes part in the organization's configuration management process
A. Chief Information Officer
B. Authorizing Official
C. Common Control Provider
D. Senior Agency Information Security Officer
Answer: C
Question #14 (Topic: Topic 1)
Which of the following processes culminates in an agreement between key players that a system in its current configuration and operation provides adequate
protection controls
protection controls
A. Certification and accreditation (C&A)
B. Risk Management
C. Information systems security engineering (ISSE)
D. Information Assurance (IA)
Answer: A
Question #15 (Topic: Topic 1)
The Phase 4 of DITSCAP C&A is known as Post Accreditation. This phase starts after the system has been accredited in Phase 3. What are the process activities
of this phase Each correct answer represents a complete solution. Choose all that apply.
of this phase Each correct answer represents a complete solution. Choose all that apply.
A. Security operations
B. Continue to review and refine the SSAA
C. Change management
D. Compliance validation
E. System operations
F. Maintenance of the SSAA
Answer: EAFCD