Official Bank 0/393

Certified Authorization Professional (CAP) - ISC2 Exam Questions

Last updated on July 22, 2026

97% Exam Compliance
393 Total Questions
1
Question
There are seven risk responses for any project. Which one of the following is a valid risk response for a negative risk event?
Options
A Enhance
B Share
C Acceptance
D Exploit
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
FITSAF stands for Federal Information Technology Security Assessment Framework. It is a methodology for assessing the security of information systems. Which of the following FITSAF levels shows that the procedures and controls have been implemented?
Options
A Level 5
B Level 1
C Level 4
D Level 3
E Level 2
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
In which of the following phases do the system security plan update and the Plan of Action and Milestones (POAM) update take place?
Options
A Continuous Monitoring Phase
B Accreditation Phase
C DITSCAP Phase
D Preparation Phase
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
Which of the following DITSCAP C&A phases takes place between the signing of the initial version of the SSAA and the formal accreditation of the system?
Options
A Phase 3
B Phase 4
C Phase 2
D Phase 1
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
Which of the following individuals informs all C&A participants about life cycle actions, security requirements, and documented user needs?
Options
A User representative
B DAA
C Certification Agent
D IS program manager
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.