Question.16 According to U.S. Department of Defense (DoD) Instruction 8500.2, there are eight Information Assurance (IA) areas, and the controls are referred to as IA controls. Which of the following are among the eight areas of IA defined by DoD? Each correct answer represents a complete solution. Choose all that apply. (A) VI Vulnerability and Incident Management (B) DC Security Design & Configuration (C) EC Enclave and Computing Environment (D) Information systems acquisition, development, and maintenance |
16. Click here to View Answer
Correct Answer: A , B & C
Question.17 DIACAP applies to the acquisition, operation, and sustainment of any DoD system that collects, stores, transmits, or processes unclassified or classified information since December 1997. What phases are identified by DIACAP? Each correct answer represents a complete solution. Choose all that apply. (A) Validation (B) Re-Accreditation (C) Verification (D) System Definition (E) Identification (F) Accreditation |
17. Click here to View Answer
Correct Answer: A, B, C & D
Question.18 Which of the following is a subset discipline of Corporate Governance focused on information security systems and their performance and risk management? (A) Lanham Act (B) ISG (C) Clinger-Cohen Act (D) Computer Misuse Act |
18. Click here to View Answer
Correct Answer: B
Question.19 Ben is the project manager of the YHT Project for his company. Alice, one of his team members, is confused about when project risks will happen in the project. Which one of the following statements is the most accurate about when project risk happens? A. Project risk can happen at any moment. B. Project risk is uncertain, so no one can predict when the event will happen. C. Project risk happens throughout the project execution. D. Project risk is always in the future. |
19. Click here to View Answer
Correct Answer: D
Question.20 You are the project manager of the NKJ Project for your company. The project’s success or failure will have a significant impact on your organization’s profitability for the coming year. Management has asked you to identify the risk events and communicate the event’s probability and impact as early as possible in the project. Management wants to avoid risk events and needs to analyze the cost-benefits of each risk event in this project. What term is assigned to the low-level of stakeholder tolerance in this project? A. Risk avoidance B. Mitigation-ready project management C. Risk utility function D. Risk-reward mentality |
20. Click here to View Answer
Correct Answer: C