Ensurepass
2017 July ISC Official New Released CAP Q&As
100% Free Download! 100% Pass Guaranteed!
http://www.ensurepass.com/CAP.html

Certified Authorization Professional

QUESTION 151

Which of the following is NOT an objective of the security program?

 

A.

Security plan

B.

Security education

C.

Security organization

D.

Information classification

 

Correct Answer: A

 

 

QUESTION 152

Which of the following is NOT a responsibility of a data owner?

 

A.

Maintaining and protecting data

B.

Ensuring that the necessary security controls are in place

C.

Delegating responsibility of the day-to-day maintenance of the data protection mechanisms to the data custodian

D.

Approving access requests

 

Correct Answer: A

 

 

QUESTION 153

Walter is the project manager of a large construction project. He’ll be working with several vendors on the project. Vendors will be providing materials and labor for several parts of the project. Some of the works in the project are very dangerous so Walter has implemented safety requirementsfor all of the vendors and his own pro
ject team. Stakeholders for the project have added new requirements, which have caused new risks in the project. A vendor has identified a new risk that could affect the project if it comes into fruition. Walter agreeswith the vendor and has updated the risk register and created potential risk responses to mitigate the risk. What should Walter also update in this scenario considering the risk event?

 

A.

Project communications plan

B.

Project management plan

C.

Projectcontractual relationship with the vendor

D.

Project scope statement

 

Correct Answer: B

 

 

QUESTION 154

Penetration testing (also called pen testing) is the practice of testing a computer system, network, or Web application to find vulnerabilities that an attacker could exploit. Which of the following areas can be exploited in a penetration test? Each correct answer represents a complete solution. Choose all that apply.

 

A.

Race conditions

B.

Social engineering

C.

Information system architectures

D.

Buffer overflows

E.

Kernel flaws

F.

Trojan horses

G.

File and directory permissions

 

Correct Answer: ABDEFG

 

 

QUESTION 155

Harry is the project manager of the MMQ Construction Project. In this project Harry has identified a supplier who can create stained glass windows for 1,000 window units in the construction project. The supplier is an artist who works by himself, but creates windows for several companies throughout the United States. Management reviews the proposal to use this supplier and while they agree that the supplier is talented, they do not think the artist can fulfill the 1,000 window units in time for the project’s deadline. Management asked Harry to find a supplier who will guarantee the completion of the windows by the needed date in the schedule. What risk response has management asked Harry to implement?

 

A.

Mitigation

B.

Acceptance

C.

Transference

D.

Avoidance

 

Correct Answer: A

 

 

QUESTION 156

Which of the following methods of authentication uses finger prints to identify users?

 

A.

PKI

B.

Mutual authentication

C.

Biometrics

D.

Kerberos

 

Correct Answer: C

 

 

QUESTION 157

In which of the following Risk Management Framework (RMF) phases is strategic risk assessment planning performed?

 

A.

Phase 0

B.

Phase 1

C.

Phase 2

D.

Phase 3

 

Correct Answer: A

 

 

QUESTION 158

Which of the following administrative policy controls requires individuals or organizations to be engaged in good business practices relative to the organization’s industry?

 

A.

Segregation of duties

B.

Separation of duties

C.

Need to Know

D.

Due care

 

Correct Answer: D

 

 

QUESTION 159

Which of the following is a security policy implemented by an organization due to compliance, regulation, or other legal requirements?

 

A.

Advisory policy

B.

Informative policy

C.

System Security policy

D.

Regulatory policy

 

Correct Answer: D

 

 

QUESTION 160

Which of the following phases begins with a review of the SSAA in the DITSCAP accreditation?

 

A.

Phase 1

B.

Phase 4

C.

Phase 3

D.

Phase 2

 

Correct Answer: C

100% Free Download!
—Download Free Demo:CAP Demo PDF
100% Pass Guaranteed!
Download 2017 Ensurepass CAP Full Exam PDF and VCE Q&As:395
—Get 10% off your purchase! Copy it:TJDN-947R-9CCD [2017.07.01-2017.07.31]

Ensurepass ExamCollection Testking
Lowest Price Guarantee Yes No No
Up-to-Dated Yes No No
Real Questions Yes No No
Explanation Yes No No
PDF + VCE Yes No No
Free VCE Simulator Yes No No
Instant Download Yes No No

2017 Ensurepass IT Certification PDF and VCE