Download ISC.CAP.Prep4Sure.2018-12-01.243q.vcex

Download Exam

File Info

Exam Certified Authorization Professional
Number CAP
File Name ISC.CAP.Prep4Sure.2018-12-01.243q.vcex
Size 177 KB
Posted Dec 01, 2018
Download ISC.CAP.Prep4Sure.2018-12-01.243q.vcex

How to open VCEX & EXAM Files?

Files with VCEX & EXAM extensions can be opened by ProfExam Simulator.

Purchase

Coupon: MASTEREXAM
With discount: 20%






Demo Questions

Question 1

Where can a project manager find risk-rating rules? 


  1. Risk probability and impact matrix
  2. Organizational process assets
  3. Enterprise environmental factors
  4. Risk management plan
Correct answer: B



Question 2

There are five inputs to the quantitative risk analysis process. Which one of the following is NOT an input to the perform quantitative risk analysis process?


  1. Risk register
  2. Cost management plan
  3. Risk management plan
  4. Enterprise environmental factors
Correct answer: D



Question 3

Your project has several risks that may cause serious financial impact should they happen. You have studied the risk events and made some potential risk responses for the risk events but management wants you to do more. They'd like for you to create some type of a chart that identified the risk probability and impact with a financial amount for each risk event. What is the likely outcome of creating this type of chart?


  1. Risk response plan
  2. Quantitative analysis
  3. Risk response
  4. Contingency reserve
Correct answer: D



Question 4

Which of the following professionals is responsible for starting the Certification & Accreditation (C&A) process?


  1. Authorizing Official
  2. Chief Risk Officer (CRO)
  3. Chief Information Officer (CIO)
  4. Information system owner
Correct answer: D



Question 5

You are working as a project manager in your organization. You are nearing the final stages of project execution and looking towards the final risk monitoring and controlling activities. For your project archives, which one of the following is an output of risk monitoring and control?


  1. Quantitative risk analysis
  2. Qualitative risk analysis
  3. Requested changes 
  4. Risk audits
Correct answer: C



Question 6

Which of the following DoD directives is referred to as the Defense Automation Resources Management Manual?


  1. DoDD 8000.1
  2. DoD 7950.1-M
  3. DoD 5200.22-M
  4. DoD 8910.1
  5. DoD 5200.1-R
Correct answer: B



Question 7

The phase 3 of the Risk Management Framework (RMF) process is known as mitigation planning. 
Which of the following processes take place in phase 3? 
Each correct answer represents a complete solution. Choose all that apply.


  1. Identify threats, vulnerabilities, and controls that will be evaluated.
  2. Document and implement a mitigation plan.
  3. Agree on a strategy to mitigate risks.
  4. Evaluate mitigation progress and plan next assessment.
Correct answer: BCD
Explanation:



Question 8

What are the subordinate tasks of the Initiate and Plan IA C&A phase of the DIACAP process? 
Each correct answer represents a complete solution. Choose all that apply.


  1. Develop DIACAP strategy.
  2. Assign IA controls.
  3. Assemble DIACAP team.
  4. Initiate IA implementation plan.
  5. Register system with DoD Component IA Program.
  6. Conduct validation activity.
Correct answer: ABCDE



Question 9

Information risk management (IRM) is the process of identifying and assessing risk, reducing it to an acceptable level, and implementing the right mechanisms to maintain that level. What are the different categories of risk? 
Each correct answer represents a complete solution. Choose all that apply.


  1. System interaction
  2. Human interaction
  3. Equipment malfunction
  4. Inside and outside attacks
  5. Social status
  6. Physical damage
Correct answer: BCDEF
Explanation:



Question 10

Neil works as a project manager for SoftTech Inc. He is working with Tom, the COO of his company, on several risks within the project. Tom understands that through qualitative analysis Neil has identified many risks in the project. Tom's concern, however, is that the priority list of these risk events are sorted in "high-risk," "moderate-risk," and "low-risk" as conditions apply within the project. Tom wants to know that is there any other objective on which Neil can make the priority list for project risks. What will be Neil's reply to Tom?


  1. Risk may be listed by the responses in the near-term
  2. Risks may be listed by categories
  3. Risks may be listed by the additional analysis and response
  4. Risks may be listed by priority separately for schedule, cost, and performance
Correct answer: D









CONNECT US

Facebook

Twitter

PROFEXAM WITH A 20% DISCOUNT

You can buy ProfExam with a 20% discount!



HOW TO OPEN VCEX FILES

Use ProfExam Simulator to open VCEX files