ISC CAP CAP – Certified Authorization Professional Online Training
ISC CAP Online Training
The questions for CAP were last updated at Apr 27,2025.
- Exam Code: CAP
- Exam Name: CAP – Certified Authorization Professional
- Certification Provider: ISC
- Latest update: Apr 27,2025
You are preparing to start the qualitative risk analysis process for your project. You will be relying on some organizational process assets to influence the process.
Which one of the following is NOT a probable reason for relying on organizational process assets as an input for qualitative risk analysis?
- A . Information on prior, similar projects
- B . Review of vendor contracts to examine risks in past projects
- C . Risk databases that may be available from industry sources
- D . Studies of similar projects by risk specialists
System Authorization is the risk management process. System Authorization Plan (SAP) is a comprehensive and uniform approach to the System Authorization Process.
What are the different phases of System Authorization Plan? Each correct answer represents a part of the solution. Choose all that apply.
- A . Pre-certification
- B . Certification
- C . Post-certification
- D . Authorization
- E . Post-Authorization
A part of a project deals with the hardware work. As a project manager, you have decided to hire a company to deal with all hardware work on the project.
Which type of risk response is this?
- A . Avoidance
- B . Mitigation
- C . Exploit
- D . Transference
Risks with low ratings of probability and impact are included on a ____ for future monitoring.
- A . Watchlist
- B . Risk alarm
- C . Observation list
- D . Risk register
Penetration testing (also called pen testing) is the practice of testing a computer system, network, or Web application to find vulnerabilities that an attacker could exploit.
Which of the following areas can be exploited in a penetration test? Each correct answer represents a complete solution. Choose all that apply.
- A . Social engineering
- B . File and directory permissions
- C . Buffer overflows
- D . Kernel flaws
- E . Race conditions
- F . Information system architectures
- G . Trojan horses
Frank is the project manager of the NHH Project. He is working with the project team to create a plan to document the procedures to manage risks throughout the project. This document will define how risks will be identified and quantified. It will also define how contingency plans will be implemented by the project team.
What document is Frank and the NHH Project team creating in this scenario?
- A . Project management plan
- B . Resource management plan
- C . Risk management plan
- D . Project plan
In which of the following testing methodologies do assessors use all available documentation and work under no constraints, and attempt to circumvent the security features of an information system?
- A . Full operational test
- B . Walk-through test
- C . Penetration test
- D . Paper test
Which of the following DITSCAP phases validates that the preceding work has produced an IS that operates in a specified computing environment?
- A . Phase 4
- B . Phase 3
- C . Phase 2
- D . Phase 1
Which of the following techniques are used after a security breach and are intended to limit the extent of any damage caused by the incident?
- A . Safeguards
- B . Preventive controls
- C . Detective controls
- D . Corrective controls
Which of the following roles is also known as the accreditor?
- A . Chief Risk Officer
- B . Data owner
- C . Designated Approving Authority
- D . Chief Information Officer