ISC ISSEP - ISSEP Information Systems Security Engineering Professional Exam

Question #11 (Topic: )
Which of the following guidelines is recommended for engineering, protecting, managing,
processing, and controlling national security and sensitive (although unclassified)
information
A. Federal Information Processing Standard (FIPS) B. Special Publication (SP) C. NISTIRs (Internal Reports) D. DIACAP by the United States Department of Defense (DoD)
Answer: B
Question #12 (Topic: )
Which of the following Security Control Assessment Tasks gathers the documentation and
supporting materials essential for the assessment of the security controls in the information
system
A. Security Control Assessment Task 4 B. Security Control Assessment Task 3 C. Security Control Assessment Task 1 D. Security Control Assessment Task 2
Answer: C
Question #13 (Topic: )
Which of the following professionals plays the role of a monitor and takes part in the
organization's configuration management process
A. Chief Information Officer B. Authorizing Official C. Common Control Provider D. Senior Agency Information Security Officer
Answer: C
Question #14 (Topic: )
Which of the following processes culminates in an agreement between key players that a
system in its current configuration and operation provides adequate protection controls
A. Certification and accreditation (C&A) B. Risk Management C. Information systems security engineering (ISSE) D. Information Assurance (IA)
Answer: A
Question #15 (Topic: )
The Phase 4 of DITSCAP C&A is known as Post Accreditation. This phase starts after the
system has been accredited in Phase 3. What are the process activities of this phase Each
correct answer represents a complete solution. Choose all that apply.
A. Security operations B. Continue to review and refine the SSAA C. Change management D. Compliance validation E. System operations F. Maintenance of the SSAA
Answer: A,C,D,E,F
Download Exam
Page: 3 / 43
Total 213 questions