QUESTION 1Certification and Accreditation (CandA or CNA) is a process for implementing information security. Which of the
following is the correct order of CandA phases in a DITSCAP assessment
QUESTION 2Which of the following is a type of security management for computers and networks in order to identify security
QUESTION 3DoD 8500.2 establishes IA controls for information systems according to the Mission Assurance Categories (MAC) and
confidentiality levels. Which of the following MAC levels requires basic integrity and availability
QUESTION 4What are the responsibilities of a system owner Each correct answer represents a complete solution? Choose all that apply. (Choose three)
QUESTION 5Which of the following protocols is built in the Web server and browser to encrypt data traveling over the Internet
QUESTION 6Which of the following are the functional analysis and allocation tools Each correct answer represents a complete solution. Choose all that apply. (Choose three)
QUESTION 7Registration Task 5 identifies the system security requirements. Which of the following elements of Registration Task 5 defines the type of data processed by the system
QUESTION 8Fill in the blank with an appropriate section name. _________________ is a section of the SEMP template, which
specifies the methods and reasoning planned to build the requisite trade-offs between functionality, performance, cost,
and risk. Correct Answer: System Analysis
QUESTION 9Which of the following Registration Tasks sets up the business or operational functional description and system identification
QUESTION 10Which of the following individuals is an upper-level manager who has the power and capability to evaluate the mission, business case, and budgetary needs of the system while also considering the security risks
QUESTION 11Which of the following tools demands involvement by upper executives, in order to integrate quality into the business system and avoid delegation of quality functions to junior administrators
QUESTION 12The Phase 2 of DITSCAP CandA is known as Verification. The goal of this phase is to obtain a fully integrated system
for certification testing and accreditation. What are the process activities of this phase Each correct answer represents a
complete solution? Choose all that apply. (Choose four)
QUESTION 13In which of the following phases of the interconnection life cycle as defined by NIST SP 800-47, do the organizations
build and execute a plan for establishing the interconnection, including executing or configuring appropriate security

