Winter Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: v4s65

Note! Following CAP Exam is Retired now. Please select the alternative replacement for your Exam Certification.

CAP Exam Dumps - CAP - Certified Authorization Professional

Go to page:
Question # 25

Mark is the project manager of the BFL project for his organization. He and the project team are creating a probability and impact matrix using RAG rating. There is some confusion and disagreement among the project team as to how a certain risk is important and priority for attention should be managed. Where can Mark determine the priority of a risk given its probability and impact?

A.

Risk response plan

B.

Project sponsor

C.

Risk management plan

D.

Look-up table

Full Access
Question # 26

There are seven risk responses for any project. Which one of the following is a valid risk response for a negative risk event?

A.

Enhance

B.

Exploit

C.

Acceptance

D.

Share

Full Access
Question # 27

In 2003, NIST developed a new Certification & Accreditation (C&A) guideline known as FIPS 199.

What levels of potential impact are defined by FIPS 199?

Each correct answer represents a complete solution. Choose all that apply.

A.

Medium

B.

High

C.

Low

D.

Moderate

Full Access
Question # 28

Where can a project manager find risk-rating rules?

A.

Risk probability and impact matrix

B.

Organizational process assets

C.

Enterprise environmental factors

D.

Risk management plan

Full Access
Question # 29

Jeff, a key stakeholder in your project, wants to know how the risk exposure for the risk events is calculated during quantitative risk analysis. He is worried about the risk exposure which is too low for the events surrounding his project requirements. How is the risk exposure calculated?

A.

The probability of a risk event plus the impact of a risk event determines the true risk expo sure.

B.

The risk exposure of a risk event is determined by historical information.

C.

The probability of a risk event times the impact of a risk event determines the true risk exposure.

D.

The probability and impact of a risk event are gauged based on research and in-depth analysis.

Full Access
Question # 30

What are the subordinate tasks of the Initiate and Plan IA C&A phase of the DIACAP process?

Each correct answer represents a complete solution. Choose all that apply.

A.

Develop DIACAP strategy.

B.

Assign IA controls.

C.

Assemble DIACAP team.

D.

Initiate IA implementation plan.

E.

Register system with DoD Component IA Program.

F.

Conduct validation activity.

Full Access
Question # 31

Which of the following DoD directives is referred to as the Defense Automation Resources Management Manual?

A.

DoDD 8000.1

B.

DoD 7950.1-M

C.

DoD 5200.22-M

D.

DoD 8910.1

E.

DoD 5200.1-R

Full Access
Question # 32

Which of the following assessment methodologies defines a six-step technical security evaluation?

A.

OCTAVE

B.

FITSAF

C.

DITSCAP

D.

FIPS 102

Full Access
Go to page: