Real CAP Dumps - ISC Correct Answers updated on 2021 [Q33-Q56]

Share

Use Real CAP Dumps - ISC Correct Answers updated on 2021

ISC Certification CAP Exam Practice Dumps

NEW QUESTION 33
You work as a project manager for BlueWell Inc. You are currently working with the project stakeholders to identify risks in your project. You understand that the qualitative risk assessment and analysis can reflect the attitude of the project team and other stakeholders to risk. Effective assessment of risk requires management of the risk attitudes of the participants. What should you, the project manager, do with assessment of identified risks in consideration of the attitude and bias of the participants towards the project risk?

  • A. Evaluate the bias towards the risk events and correct the assessment accordingly
  • B. Evaluate and document the bias towards the risk events
  • C. Document the bias for the risk events and communicate the bias with management
  • D. Evaluate the bias through SWOT for true analysis of the risk events

Answer: A

 

NEW QUESTION 34
Thomas is a key stakeholder in your project. Thomas has requested several changes to the
project scope for the project you are managing. Upon review of the proposed changes, you have discovered that these new requirements are laden with risks and you recommend to the change control board that the changes be excluded from the project scope. The change control board agrees with you. What component of the change control system communicates the approval or denial of a proposed change request?

  • A. Change log
  • B. Integrated change control
  • C. Configuration management system
  • D. Scope change control system

Answer: B

 

NEW QUESTION 35
Which of the following individuals is responsible for ensuring the security posture of the organization's information system?

  • A. Chief Information Officer
  • B. Security Control Assessor
  • C. Authorizing Official
  • D. Common Control Provider

Answer: C

 

NEW QUESTION 36
Which of the following professionals plays the role of a monitor and takes part in the organization's configuration management process?

  • A. Senior Agency Information Security Officer
  • B. Common Control Provider
  • C. Authorizing Official
  • D. Chief Information Officer

Answer: B

 

NEW QUESTION 37
You are the program manager for your project. You are working with the project managers regarding the procurement processes for their projects. You have ruled out one particular contract type because it is considered too risky for the program. Which one of the following contract types is usually considered to be the most dangerous for the buyer?

  • A. Time and materials
  • B. Cost plus percentage of costs
  • C. Fixed fee
  • D. Cost plus incentive fee

Answer: B

Explanation:
Section: Volume B

 

NEW QUESTION 38
You are the project manager of the NNQ Project for your company and are working you're your project team to define contingency plans for the risks within your project. Mary, one of your project team members, asks what a contingency plan is. Which of the following statements best defines what a contingency response is?

  • A. Some responses are designed for use only if certain events occur.
  • B. Some responses have a cost and a time factor to consider for each risk event.
  • C. Some responses must counteract pending risk events.
  • D. Quantified risks should always have contingency responses.

Answer: A

Explanation:
Section: Volume C

 

NEW QUESTION 39
You are the project manager of the NKJ Project for your company. The project's success or failure will have a significant impact on your organization's profitability for the coming year. Management has asked you to identify the risk events and communicate the event's probability and impact as early as possible in the project. Management wants to avoid risk events and needs to analyze the cost-benefits of each risk event in this project. What term is assigned to the low-level of stakeholder tolerance in this project?

  • A. Risk-reward mentality
  • B. Risk avoidance
  • C. Mitigation-ready project management
  • D. Risk utility function

Answer: D

 

NEW QUESTION 40
Thomas is a key stakeholder in your project. Thomas has requested several changes to the project scope for the project you are managing. Upon review of the proposed changes, you have discovered that these new requirements are laden with risks and you recommend to the change control board that the changes be excluded from the project scope. The change control board agrees with you. What component of the change control system communicates the approval or denial of a proposed change request?

  • A. Change log
  • B. Integrated change control
  • C. Configuration management system
  • D. Scope change control system

Answer: B

 

NEW QUESTION 41
The Chief Information Officer (CIO), or Information Technology (IT) director, is a job title commonly given to the most senior executive in an enterprise. What are the responsibilities of a Chief Information Officer?
Each correct answer represents a complete solution. Choose all that apply.

  • A. Establishing effective continuous monitoring program for the organization
  • B. Facilitating the sharing of security risk-related information among authorizing officials
  • C. Proposing the information technology needed by an enterprise to achieve its goals and then working within a budget to implement the plan
  • D. Preserving high-level communications and working group relationships in an organization

Answer: A,C,D

Explanation:
Section: Volume C

 

NEW QUESTION 42
You are the project manager for the NHH project. You are working with your project team to examine the project from four different defined perspectives to increase the breadth of identified risks by including internally generated risks. What risk identification approach are you using in this example?

  • A. Root cause analysis
  • B. SWOT analysis
  • C. Assumptions analysis
  • D. Influence diagramming techniques

Answer: B

 

NEW QUESTION 43
Which of the following statements about System Access Control List (SACL) is true?

  • A. It exists for each and every permission entry assigned to any object.
  • B. It contains a list of both users and groups and whatever permissions they have.
  • C. It is a mechanism for reducing the need for globally unique IP addresses.
  • D. It contains a list of any events that are set to audit for that particular object.

Answer: D

Explanation:
Section: Volume C

 

NEW QUESTION 44
Which of the following is an Information Assurance (IA) model that protects and defends information and information systems by ensuring their availability, integrity, authentication, confidentiality, and non-repudiation?

  • A. Parkerian Hexad
  • B. Classic information security model
  • C. Capability Maturity Model (CMM)
  • D. Five Pillars model

Answer: D

 

NEW QUESTION 45
Nancy is the project manager of the NHH project. She and the project team have identified a significant risk in the project during the qualitative risk analysis process. Bob is familiar with the technology that the risk is affecting and proposes to Nancy a solution to the risk event. Nancy tells Bob that she has noted his response, but the risk really needs to pass through the quantitative risk analysis process before creating responses. Bob disagrees and ensures Nancy that his response is most appropriate for the identified risk. Who is correct in this scenario?

  • A. Nancy is correct. All risks of significant probability and impact should pass the quantitative risk analysis process before risk responses are created.
  • B. Bob is correct. Bob is familiar with the technology and the risk event so his response should be implemented.
  • C. Nancy is correct. Because Nancy is the project manager she can determine the correct procedures for risk analysis and risk responses. In addition, she has noted the risk response that Bob recommends.
  • D. Bob is correct. Not all riskevents have to pass the quantitative risk analysis process to develop effective risk responses.

Answer: D

 

NEW QUESTION 46
Which of the following risk responses delineates that the project plan will not be changed to deal with the risk?

  • A. Mitigation
  • B. Exploitation
  • C. Transference
  • D. Acceptance

Answer: D

 

NEW QUESTION 47
In which of the following DIACAP phases is residual risk analyzed?

  • A. Phase 5
  • B. Phase 4
  • C. Phase 3
  • D. Phase 2
  • E. Phase 1

Answer: B

 

NEW QUESTION 48
Your project team has identified a project risk that must be responded to. The risk has been recorded in the risk register and the project team has been discussing potential risk responses for the risk event. The event is not likely to happen for several months but the probability of the event is high. Which one of the following is a valid response to the identified risk event?

  • A. Earned value management
  • B. Technical performance measurement
  • C. Risk audit
  • D. Corrective action

Answer: D

Explanation:
Section: Volume C
Explanation

 

NEW QUESTION 49
You are the project manager for your organization. You have determined that an activity is too dangerous to complete internally so you hire licensed contractor to complete the work. The contractor, however, may not complete the assigned work on time which could cause delays in subsequent work beginning. This is an example of what type of risk event?

  • A. Secondary risk
  • B. Transference
  • C. Internal
  • D. Pure risk

Answer: A

 

NEW QUESTION 50
Which of the following is used to indicate that the software has met a defined quality level and is ready for mass distribution either by electronic means or by physical media?

  • A. CRO
  • B. DAA
  • C. ATM
  • D. RTM

Answer: D

Explanation:
Section: Volume A

 

NEW QUESTION 51
Thomas is the project manager of the NHJ Project for his company. He has identified several positive risk events within his project and he thinks these events can save the project time and money. Positive risk events, such as these within the NHJ Project are also known as what?

  • A. Ancillary constituent components
  • B. Benefits
  • C. Opportunities
  • D. Contingency risks

Answer: C

 

NEW QUESTION 52
Which of the following statements is true about the continuous monitoring process?

  • A. It takes place in the middle of system security accreditation.
  • B. It takes place after the initial system security accreditation.
  • C. It takes place before the initial system security accreditation.
  • D. It takes place before and after system security accreditation.

Answer: B

 

NEW QUESTION 53
Jenny is the project manager for the NBT projects. She is working with the project team and several subject matter experts to perform the quantitative risk analysis process. During this process she and the project team uncover several risks events that were not previously identified.
What should Jenny do with these risk events?

  • A. The events should continue on with quantitative risk analysis.
  • B. The events should be entered into qualitative risk analysis.
  • C. The events should be determined if they need to be accepted or responded to.
  • D. The events should be entered into the risk register.

Answer: D

 

NEW QUESTION 54
ISO 17799 has two parts. The first part is an implementation guide with guidelines on how to build a comprehensive information security infrastructure and the second part is an auditing guide based on requirements that must be met for an organization to be deemed compliant with ISO 17799. What are the ISO
17799 domains?
Each correct answer represents a complete solution. Choose all that apply.

  • A. Business continuity management
  • B. Information security policy for the organization
  • C. System development and maintenance
  • D. System architecture management
  • E. Personnel security

Answer: A,B,C,E

Explanation:
Section: Volume C

 

NEW QUESTION 55
Certification and Accreditation (C&A or CnA) is a process for implementing information security.
Which of the following is the correct order of C&A phases in a DITSCAP assessment?

  • A. Verification, Definition, Validation, and Post Accreditation
  • B. Verification, Validation, Definition, and Post Accreditation
  • C. Definition, Verification, Validation, and Post Accreditation
  • D. Definition, Validation, Verification, and Post Accreditation

Answer: C

 

NEW QUESTION 56
......

Get ready to pass the CAP Exam right now using our ISC Certification  Exam Package: https://www.pass4training.com/CAP-pass-exam-training.html

CAP Premium Files Test pdf - Free Dumps Collection: https://drive.google.com/open?id=13yYvKUpwhyhaK7Wtfac8-_ZFpRX2AHtv