All questions

Federal IT Security Professional (FITSP) Auditor Practice Exam

Browse all practice questions for the Federal IT Security Professional (FITSP) Auditor Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Federal IT Security Auditor Practice Exam 2026 – Complete Study Guide course image
All questions

These questions are part of the practice quiz. Start practicing

  • Which NIST Special Publication provides guidance for protecting PII?
  • What type of analysis is performed during the Initiation phase of the SDLC?
  • What is the correct order of the four components of risk management?
  • Which vulnerability scanning tool is widely used for security assessments?
  • What is the required frequency for FISMA reporting feeds for CFO Act agencies?
  • Which aspect is primarily evaluated in security assessments?
  • What does the NIST SP 800-60 Volume 2 specifically address?
  • Which OMB memo announced the implementation of accepted security configurations for Windows operating systems?
  • What is the primary focus of continuous monitoring in security control revisions?
  • What is the NIST Special Publication that provides guidance for protecting PII?
  • Name the three tasks of the RMF Categorization step.
  • Which GSA program provides a cost-effective approach for adopting cloud services?
  • What is the specific type of authorization allowing a system to operate with live data for testing purposes?
  • Which security mechanism is specifically designed to ensure that a message is not altered in transit?
  • What is the correct order of the Risk Management Framework process?
  • Which of the following is NOT a feature of Security Mode 1 in Bluetooth technology?
  • What additional approval is required according to OMB Memorandum M-14-04 before issuing an authorization to operate?
  • What is the basis for defining information types?
  • What type of contingency alternate site has all the resources required to assume full processing in case of the loss of the primary site but might result in a short delay before becoming fully operational?
  • What is the purpose of common controls in an organization?
  • Which type of testing involves simulating an attack on a system to identify vulnerabilities?
  • Which NIST Special Publication is NOT related to risk management and risk assessment?
  • Which act assigned responsibilities to NIST for developing standards related to securing Federal Information Systems?
  • What does FedRAMP provide a standardized approach for?
  • IPSEC protects the integrity of data in transit using which protocol?
  • Which special publication provides guidelines on designing, developing, conducting, and evaluating test, training, and exercise events?
  • In which phase of the SDLC are the PIA, BIA, and Security Categorization conducted?
  • Which of the following is an example of Tier 1 risk?
  • Which of the following is NOT a phase of the SDLC?
  • In the context of information security, what is a primary function of the System Security Plan?
  • Which OMB guidance requires federal agencies to review security controls for each system at least every three years?
  • Software assurance is addressed by which family of security controls from SP 800-53?
  • Which approach focuses on balancing the protection of agency information with the cost of security controls?
  • What is the first step to assigning impact levels for security categorization?
  • Which of the following acts is primarily focused on the cyber defense of critical infrastructure?
  • What is a key focus of the FedRAMP program?
  • Is teleworking from an employee's residence included under the Alternate Work Site security control?
  • Which law directed the Secretary of Health and Human Services to develop electronic health information protection standards?
  • Where are security controls documented?
  • Which VPN technologies are authorized for use by federal agencies?
  • Which publication provides guidance for interconnecting information technology systems?
  • Which Bluetooth security mode allows devices to connect without restrictions?
  • What legislation requires federal agencies to develop an agency-wide information security program?
  • Who is responsible for ensuring that information security requirements are addressed in enterprise architecture?
  • In cryptography, which term specifically refers to the protection of information from unauthorized access?
  • What is the correct order of the four tasks of the assessment step of the RMF?
  • What is the basis for the identification of information types?
  • Which security framework emphasizes a risk management approach to information security?
  • What security control ensures that an individual cannot deny having performed a particular action?
  • Which act outlines guidelines specifically for agency-wide security programs in federal agencies?
  • Which protocol is required by the OMB for Federal agencies to use in vulnerability scanning tools?
  • During which phase of the SDLC should the organization consider security requirements?
  • What are the main components of security categories used in risk assessment?
  • Which directive was established to enhance the security of identities used by Federal agencies?
  • What does SAR stand for in security documentation?
  • During which SDLC phase is the training for security personnel conducted?
  • What are the six steps of the RMF process?
  • What would be the appropriate backup strategy and alternate site combination for a system with a FIPS 199 Availability Impact of MODERATE?
  • In which phase of contingency planning are recovery activities completed and normal operations resumed?
  • Which legislation requires Privacy Impact Assessments when developing new IT?
  • What main policy does the Department of Homeland Security encompass regarding information systems?
  • Which NIST publication focuses heavily on the Risk Management Framework?
  • Which department was assigned by FISMA to prescribe standards for federal information systems?
  • Which statement about system security assessments is false?
  • What kind of security control is a management, operational, or technical control employed by an organization in lieu of a recommended security control?
  • The Risk Management Framework (RMF) places heavy emphasis on which aspect?
  • Which NIST Special Publication details assessment objects for security controls?
  • What program uses a "do once, use many times" framework to streamline agency security assessments?
  • This Standard defines a MAC that employs a cryptographic hash function with a secret key.
  • Which security role is responsible for authorizing the information system's operation?
  • Which of the following is NOT a type of security control?
  • Which element is considered critical in the assessment of IT security processes in agencies?
  • Which of the following is NOT a component of an information system?
  • What are the factors that drive the level of effort for the selection and implementation of security controls?
  • Name the contingency planning variable that defines the maximum amount of time that a system resource can remain unavailable before there is an unacceptable impact.
  • What term refers to the techniques that are used to protect the confidentiality, integrity, and availability of information?
  • What defines the three levels of baseline controls for an information system?
  • Early integration of security in the SDLC allows agencies to maximize ROI in their security programs through:
  • Which of the following is a reason for adjusting a system's provisional impact level?
  • Which of the following were purposes in introducing overlays in SP 800-53r4?
  • What program does the OMB use to help agencies identify business processes?
  • When would you use a gap analysis in the RMF process?
  • Which phase of the SDLC includes the implementation of security controls?
  • Which federal act emphasizes the importance of securing federal automated information systems?
  • ISCM aims to improve security by replacing the "every three years" reauthorization requirement with what type of process?
  • Blocking outside traffic that claims to be from within the organization is managed by which security control?
  • What is the primary purpose of the Business Impact Analysis (BIA)?
  • What occurs if an Authorizing Official denies authorization to operate?
  • What establishes the scope of protection for organizational information systems?
  • What form of cryptographic service is used to establish non-repudiation?
  • What is defined as a body of evidence organized into an argument to assure claims about an information system?
  • What mechanism is used to authenticate information transmitted between two parties sharing a secret key?
  • Which method of encryption involves both a public and private key for secure data transmission?
  • Under FISMA 2014, which agencies are formally assigned information security responsibilities?
  • Which approach involves continually balancing the protection of agency information and assets with cost considerations?
  • Tier 2 of the three-tiered risk management approach addresses risk-related concerns at which level?
  • What type of maintenance is conducted by individuals communicating through a network, as identified by the control identifier MA-4?
  • What are the components of an information system?
  • What is the primary goal of the risk management process?
  • What is the main goal of the ISCP?
  • The risk management processes at the information system level link to organizational level processes through which newly defined role in the RMF?
  • Which of the following DOES NOT cite IT performance measurement as a requirement?
  • The Information Security Program Plan documents which TWO components?
  • Which is a common method for assessing the risk associated with sensitive data?
  • In response to the loss of records at the Department of Veteran Affairs, which requirement is NOT mandated by OMB memo M-06-16?
  • What is the primary goal of the Risk Management Framework (RMF)?
  • What does the abbreviation PII stand for in the context of NIST guidance?
  • Which legislation mandates the appointment of a Chief Information Officer in federal agencies?
  • Applying the first three steps in the RMF to legacy systems can be viewed as a ______ to determine if the necessary and sufficient security controls have been appropriately selected and allocated.
  • What is the primary focus of the incident containment phase?
  • What OMB memo requires agencies to safeguard against breaches of personally identifiable information?
  • Which factors influence the level of effort expended when implementing the RMF tasks?
  • What is the Homeland Security Presidential Directive that establishes a government-wide identification standard?
  • Which publication recommends using the independence standards for an agency's FISMA audit?
  • Which SCAP specifications provide a standard naming convention for operating systems, hardware, and applications?
  • During which SDLC phase are Security Reauthorizations conducted?
  • Which IPSec protocol can be configured to provide compression for IPSec traffic?
  • Which NIST Special Publication superseded the original Special Publication 800-30 for risk management guidance?
  • What documents compose a Security Authorization Package?
  • In which NIST special publication can you find guidance regarding mobile computers using FIPS 140-2 validated cryptographic modules?
  • What type of cybersecurity training is necessary to ensure staff understands their roles during an incident?
  • What is the recommended disposal method for paper-based medical records containing sensitive PII?
  • Which type of assessment reviews the potential impact of a failure in a system?
  • Who has the primary responsibility for implementing security controls?
  • What technique is commonly used in security to ensure the authenticity of a message?
  • Which roles must be assigned only to government personnel?
  • What e-authentication level requires multifactor authentication and the use of a hard token?
  • What is the purpose of using Message Authentication Codes between parties?
  • What protocol, used by IPsec, manages connection settings and authenticates endpoints?
  • What are security controls that are inheritable by organizational information systems?
  • Which task is NOT part of the RMF implementation process?
  • Which two NIST Special Publications are essential for information security planning?
  • What control emphasizes the significance of the security categorization process?
  • Are privacy security requirements adequately addressed by the standard catalog of security controls?
  • What abbreviation represents the effort to provide adequate resources for information security?
  • What are the IETF specifications for securing DNS queries to second-level .gov domain servers?
  • Which directive establishes a national policy for the protection of US critical infrastructure?
  • Which agency is responsible for publishing FISMA Reporting Metrics annually?
  • Which NIST special publication provides guidance on the privacy and legal issues with VOIP?
  • What does the acronym POAM stand for in the context of security assessments?
  • What type of authentication must be used for remote access according to the memo released after the Veterans Affairs incident?
  • What is the reporting timeframe for a CAT-3 incident categorized under US-CERT?
  • What is the method of reviewing or analyzing one or more assessment objects called?
  • What are the four components of the new Risk Management Model?
  • Which document provides the results of assessing the implementation of security controls to determine their operational effectiveness?
  • What is the objective of the Continuous Monitoring process?
  • What is the overarching goal of the Federal Information Security Management Act (FISMA)?
  • What is one of the requirements of the Clinger-Cohen Act for federal agencies?
  • Which category falls under the responsibilities of federal agencies as defined by OMB?
  • What establishes the scope of protection for organizational information systems?
  • At what point in the SDLC are security controls implemented?
  • What VPN model is most commonly used for traveling employees to access organizational services?
  • Where can one find the list of privacy controls required for Federal information systems?
  • How many families are security controls organized into?
  • FIPS 199 standards apply to which types of systems?
  • What is the correct order of the four components of risk management?
  • What is created to correlate the information system with critical mission/business processes?
  • What does SSP refer to after a risk assessment?
  • Which legislation requires federal agencies to establish capital planning and investment control policies for IT procurement?
  • Which Federal mandate requires agencies to report incidents to US-CERT?
  • FIPS 200 provides guidance for security control selection based on what?
  • Which legislation requires an annual evaluation of an agency's information security program by its Inspector General or an external auditor?
  • Which type of controls can be inherited by one or more organizational information systems?
  • Is it true that more than one method may be required to assess the proper operation of a single security control?
  • What is the automated reporting tool that agencies must use to report data, per DHS direction?
  • Which practice can help reduce the effort required to assess controls?
  • Which FIPS encryption level requires identity based authentication?
  • In relation to security categorization, which document is crucial for understanding the impact levels?
  • Which role is responsible for ensuring that security policies are enforced within an organization?
  • Which NIST Special Publication applies to information systems in employee's residences for telecommuting?
  • Which document outlines the risk assessment process for data systems?
  • What does AU-10 Non-Repudiation primarily address in information security?
  • Which document or report outlines the necessary procedures for the protection of sensitive agency information?
  • Which document outlines the procedures for responding to cybersecurity incidents?
  • Which of the following SCAP specifications provides a standard naming and dictionary of system configuration issues?
  • What is the primary function of the System Security Plan?
  • What is the term that represents the total time the system owner is willing to accept a mission/business process outage or disruption?
  • What are the data encryption format and digital certificate standard used by S/MIME?
  • What is the policy established for a Common Identification Standard for Federal Employees and Contractors?
  • What is the most significant change regarding security control selection in the revision of the SP 800-37?
  • Which standard governs the Keyed-Hash Message Authentication Code (HMAC)?
  • What is a valid assessment method for security controls?
  • Which control relates to the essential processes of assessing and managing risks to information systems?
  • Which of the following is NOT a requirement under the OMB memo M-06-16?
  • Which NIST document lists information types and their associated provisional impact level?
  • Which control activity does not involve direct protection-related actions?
  • Which NIST Special Publication provides guidance for implementing ISCM?
  • What framework was introduced for automated assessment of security controls?
  • What is the primary purpose of HSPD-12?
  • Are Federal information systems required to be re-authorized at least every three years?
  • What is the FIPS publication that specifies the Rijndael algorithm?
  • What drives the level of effort for the selection and implementation of security controls?
  • Which FIPS 140-2 encryption level provides environmental protections?
  • What type of security control is used in place of a recommended security control?
  • What are some of the threats that an information system faces?
  • Which of the following is NOT a cryptographic security service?
  • After security categorization, which publication specifies the minimum security requirements?
  • Which of the following represents a factor in adjusting provisional impact levels?
  • Which of the following is NOT considered a security testing technique?
  • Which two encryption mechanisms are approved for use by US Federal agencies?
  • Which contingency planning variable defines the maximum time a resource can be unavailable before it impacts operations?
  • What type of control is applied to protect against unauthorized access?
  • Which US Law mandates all agencies to report security incidents to a Federal incident response center?
  • Which framework is used to evaluate security controls and how they impact risk management?
  • What significant change was made regarding security control selection in the revision of SP 800-37?
  • What does the RMF Step 2 emphasize?
  • What is the first step to assigning impact levels for security categorization?
  • What are the two most important factors when selecting a security control assessor?
  • What is the supporting guideline for PE-17 Alternate Work Site?
  • Which security designation describes controls applicable to more than one information system?
  • What are some of the threats that an information system faces?
  • According to OMB M-14-04, which two individuals must sign the ATO for a new information system to operate?
  • The AES algorithm may be used with three different key lengths; which of the following is not a recognized AES flavor?
  • Which agency conducts audits of private organizations using electronic health systems?
  • In which case can a POAM be utilized effectively?
  • Which security control is designed to protect against an individual falsely denying an action?
  • In the context of cybersecurity, what does the term 'replay attack' refer to?
  • What does the acronym PII stand for in data protection?
  • Which SCAP specification provides a standard naming convention for operating systems, hardware, and applications?
  • What must be conducted to support a security authorization package?
  • Which NIST document lists information types and their associated provisional impact level?
  • Which of the following is NOT an example of actions noted in contingency plans?
  • What are the six steps of the RMF process?
  • Because AH transport mode cannot alter the original IP header, it is generally used in which VPN architecture?
  • What are the two types of authorization decisions that can be made by authorizing officials?
  • Which of the following is NOT a key document used for risk-based authorization decisions?
  • What policy and standard overlap physical security controls with identification and authentication?
  • What is the main purpose of a Tabletop exercise in emergency management?
  • In terms of IT security, what is the main purpose of establishing a security configuration baseline?
  • Which NIST special publication helps facilitate security control assessments in a risk management framework?
  • IDPS use this type of detection to identify significant deviations. What is this method called?
  • What initiative aims to create security configuration baselines for IT products deployed federally?
  • What is defined as a simulation of an emergency to validate an Information System Contingency Plan (ISCP)?
  • What does the acronym CPIC stand for in the context of information security resource management?
  • Which two protocols refer to the same underlying protocol in different terms?
  • Security Controls are allocated into which three designations?
  • Which statements are linked to the security control's content to ensure assessment results trace back to control requirements?
  • Which of the following are the security objectives under FISMA?
  • Which document should detail the weaknesses or deficiencies identified in security controls?
  • Which automated system must agencies use to submit required FISMA reports?
  • Personnel meet in a classroom to discuss their roles during an emergency. What type of exercise is this?
  • What is the primary goal of the RMF?
  • In which Bluetooth mode are devices considered "promiscuous"?
  • During which phase of the SDLC are Security Reauthorizations conducted?
  • What is defined as an identifiable part of a system that is a discrete target of configuration control processes?
  • How often are CFO Agencies required to submit data through CyberScope?
  • Who is primarily responsible for the implementation of security controls in an organization?
  • What law granted OMB the authority to define policies for US Government Agencies?
  • In the context of security controls, what does "System-Specific" refer to?
  • In which document would you find guidance for applying the Risk Management Framework to federal information systems?
  • What are the possible outcomes of the Authorization Decision?
  • Which document provides a policy framework for information resources management across the Federal government?
  • In which phase of the SDLC are the PIA, BIA, and Security Categorization performed?
  • Which of the following is NOT a part of the FISCAM control hierarchy?
  • Which of the following is NOT part of the incident handling process?
  • What are the two key components affecting the trustworthiness of information systems?
  • Which type of control is typically the last resort when it comes to mitigating risks?
  • Which two NIST special publications provide the management overview and risk assessment guidance on risk management?
  • Which type of authorization is not valid according to OMB, despite being used by some agencies?
  • What is the main role of the Internet Key Exchange (IKE) in network security?
  • What are the three levels of potential impact from a security breach?
  • What are the possible outcomes of the Authorization Decision?
  • Which framework does the Federal Government adhere to for privacy controls?
  • What is the US-CERT incident category name and reporting timeframe for a CAT-2 incident?
  • In the sanitization guidelines of NIST SP 800-88, what is the recommended disposal method for paper-based medical records containing sensitive PII?
  • What is the name of the testing that determines if a change caused issues in unchanged parts of the system?
  • Which RMF role ensures risk-related considerations are viewed from an organization-wide perspective?
  • A hard drive pulled from an unclassified information system containing high confidentiality information will be reused. What is the recommended course of media sanitization?
  • Which role is responsible for ensuring that security requirements are integrated into the systems development lifecycle?
  • Which roles must be assigned only to government personnel?
  • What is a well-defined, documented, and approved specification that describes the approved configuration of an information system?
  • What is the best course of action for media containing classified material that is no longer in use?
  • During which phase of the SDLC should an organization consider the security requirements?
  • Can the Authorizing Official delegate the decision to authorize?
  • Which key management practice is critical when using public key infrastructure (PKI)?
  • How are compensating controls most effectively utilized?
  • During which phase of the SDLC should security requirements be defined?
  • How many business areas are described in the BRM?
  • Name the AES-based, wireless encryption mechanism used in the 802.11i wireless technical specification.
  • What does the Federal Information Security Management Act (FISMA) primarily aim to improve?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy