Cause all that matters here is passing the ISC2 CAP exam. Cause all that you need is a high score of CAP ISC2 CAP Certified Authorization Professional exam. The only one thing you need to do is downloading Exambible CAP exam study guides now. We will not let you down with our money-back guarantee.
ISC2 CAP Free Dumps Questions Online, Read and Test Now.
NEW QUESTION 1
Your project uses a piece of equipment that if the temperature of the machine goes above 450 degree Fahrenheit the machine will overheat and have to be shut down for 48 hours. Should this machine overheat even once it will delay the project's end date. You work with your project to create a response that should the temperature of the machine reach 430, the machine will be paused for at least an hour to cool it down. The temperature of 430 is called what?
- A. Risk identification
- B. Risk response
- C. Risk trigger
- D. Risk event
Answer: C
NEW QUESTION 2
Which of the following DoD directives defines DITSCAP as the standard C&A process for the Department of Defense?
- A. DoD 8000.1
- B. DoD 5200.40
- C. DoD 5200.22-M
- D. DoD 8910.1
Answer: B
NEW QUESTION 3
Which of the following objectives are defined by integrity in the C.I.A triad of information security systems?
Each correct answer represents a part of the solution. Choose three.
- A. It preserves the internal and external consistency of information.
- B. It prevents the unauthorized or unintentional modification of information by the authorized users.
- C. It prevents the intentional or unintentional unauthorized disclosure of a message's contents .
- D. It prevents the modification of information by the unauthorized users.
Answer: ABD
NEW QUESTION 4
Which of the following RMF phases is known as risk analysis?
- A. Phase 2
- B. Phase 1
- C. Phase 0
- D. Phase 3
Answer: A
NEW QUESTION 5
You are preparing to complete the quantitative risk analysis process with your project team and several subject matter experts. You gather the necessary inputs including the project's cost management plan. Why is it necessary to include the project's cost management plan in the preparation for the quantitative risk analysis process?
- A. The project's cost management plan can help you to determine what the total cost of the project is allowed to be.
- B. The project's cost management plan provides direction on how costs may be changed due to identified risks.
- C. The project's cost management plan provides control that may help determine the structure for quantitative analysis of the budget.
- D. The project's cost management plan is not an input to the quantitative risk analysis process .
Answer: C
NEW QUESTION 6
You are the project manager for the NHH project. You are working with your project team to examine the project from four different defined perspectives to increase the breadth of identified risks by including internally generated risks. What risk identification approach are you using in this example?
- A. SWOT analysis
- B. Root cause analysis
- C. Assumptions analysis
- D. Influence diagramming techniques
Answer: A
NEW QUESTION 7
Your organization has a project that is expected to last 20 months but the customer would really like the project completed in 18 months. You have worked on similar projects in the past and believe that you could fast track the project and reach the 18 month deadline. What increases when you fast track a project?
- A. Risks
- B. Costs
- C. Resources
- D. Communication
Answer: A
NEW QUESTION 8
Mark is the project manager of the BFL project for his organization. He and the project team are creating a probability and impact matrix using RAG rating. There is some confusion and disagreement among the project team as to how a certain risk is important and priority for attention should be managed. Where can Mark determine the priority of a risk given its probability and impact?
- A. Risk response plan
- B. Project sponsor
- C. Risk management plan
- D. Look-up table
Answer: D
NEW QUESTION 9
You work as a project manager for BlueWell Inc. You are preparing to plan risk responses for your project with your team. How many risk response types are available for a negative risk event in the project?
- A. Seven
- B. Three
- C. Four
- D. One
Answer: C
NEW QUESTION 10
Gary is the project manager for his organization. He is working with the project stakeholders on the project requirements and how risks may affect their project. One of the stakeholders is confused about what constitutes risks in the project. Which of the following is the most accurate definition of a project risk?
- A. It is an uncertain event that can affect the project costs.
- B. It is an uncertain event or condition within the project execution.
- C. It is an uncertain event that can affect at least one project objective.
- D. It is an unknown event that can affect the project scope.
Answer: C
NEW QUESTION 11
ISO 17799 has two parts. The first part is an implementation guide with guidelines on how to build a comprehensive information security infrastructure and the second part is an auditing guide based on requirements that must be met for an organization to be deemed compliant with ISO 17799. What are the ISO 17799 domains?
Each correct answer represents a complete solution. Choose all that apply.
- A. Information security policy for the organization
- B. Personnel security
- C. Business continuity management
- D. System architecture management
- E. System development and maintenance
Answer: ABCE
NEW QUESTION 12
You work as a project manager for BlueWell Inc. You are working with your team members on the risk responses in the project. Which risk response will likely cause a project to use the procurement processes?
- A. Acceptance
- B. Mitigation
- C. Exploiting
- D. Sharing
Answer: D
NEW QUESTION 13
To help review or design security controls, they can be classified by several criteria. One of these criteria is based on time. According to this criteria, which of the following controls are intended to prevent an incident from occurring?
- A. Adaptive controls
- B. Preventive controls
- C. Detective controls
- D. Corrective controls
Answer: B
NEW QUESTION 14
Which of the following documents were developed by NIST for conducting Certification & Accreditation (C&A)?
Each correct answer represents a complete solution. Choose all that apply.
- A. NIST Special Publication 800-53A
- B. NIST Special Publication 800-37A
- C. NIST Special Publication 800-59
- D. NIST Special Publication 800-53
- E. NIST Special Publication 800-37
- F. NIST Special Publication 800-60
Answer: ACDEF
NEW QUESTION 15
During which of the following processes, probability and impact matrix is prepared?
- A. Plan Risk Responses
- B. Perform Quantitative Risk Analysis
- C. Perform Qualitative Risk Analysis
- D. Monitoring and Control Risks
Answer: C
NEW QUESTION 16
You are the project manager for your organization. You are working with your project team to complete the qualitative risk analysis process. The first tool and technique you are using requires that you assess the probability and what other characteristic of each identified risk in the project?
- A. Risk owner
- B. Risk category
- C. Impact
- D. Cost
Answer: C
NEW QUESTION 17
In which of the following phases do the system security plan update and the Plan of Action and Milestones (POAM) update take place?
- A. Continuous Monitoring Phase
- B. Accreditation Phase
- C. Preparation Phase
- D. DITSCAP Phase
Answer: A
NEW QUESTION 18
......
P.S. Downloadfreepdf.net now are offering 100% pass ensure CAP dumps! All CAP exam questions have been updated with correct answers: https://www.downloadfreepdf.net/CAP-pdf-download.html (395 New Questions)