New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 ISSEP Exam - Topic 3 Question 18 Discussion

Actual exam question for ISC2's ISSEP exam
Question #: 18
Topic #: 3
[All ISSEP Questions]

Which of the following individuals informs all C&A participants about life cycle actions, security

requirements, and documented user needs?

Show Suggested Answer Hide Answer
Suggested Answer: D

The IS program manager is the primary authorization advocate. He is responsible for the Information

Systems (IS) throughout the life cycle of

system development. He also ensures that the security requirements are integrated in a way that

will result in an acceptable level of risk. He

also informs all C&A participants about life cycle actions, security requirements, and documented

user needs. The program manager is also

responsible for system acquisition, life cycle schedules, funding, system operation, system

performance, and maintenance.

Answer option C is incorrect. The Certification Agent is also referred to as the certifier. He provides

the technical expertise to conduct the

certification throughout the system life cycle. The certifier determines the existing level of residual

risk. He also makes an accreditation

recommendation to the DAA. He determines whether a system is ready for certification and

conducts the certification process.

Answer option A is incorrect. A user representative is one who focuses on system availability, access,

integrity, functionality, performance, and

confidentiality in a Certification and Accreditation (C&A) process. He is responsible for the

identification of operational requirements and for the

secure operation of a certified and accredited IS. He represents the user community and assists in

the C&A process. He also defines the

system's operations and functional requirements.

Answer option B is incorrect. The Designated Approving Authority (DAA), in the United States

Department of Defense, is the official with the

authority to formally assume responsibility for operating a system at an acceptable level of risk. The

DAA is responsible for implementing

system security. The DAA can grant the accreditation and can determine that the system's risks are

not at an acceptable level and the system

is not ready to be operational.


Contribute your Thoughts:

0/2000 characters
Chandra
4 months ago
Not sure about this one, seems a bit unclear.
upvoted 0 times
...
Royce
4 months ago
Definitely the IS program manager, no doubt about it!
upvoted 0 times
...
Candida
4 months ago
Wait, is the Certification Agent really involved in this?
upvoted 0 times
...
Carey
4 months ago
I disagree, I think it's the DAA.
upvoted 0 times
...
Viva
5 months ago
I'm pretty sure it's the User representative.
upvoted 0 times
...
Lachelle
5 months ago
I thought the User representative was the one who communicates user needs, but I also remember the DAA having a role in security. This is tricky!
upvoted 0 times
...
Valene
5 months ago
I'm kind of torn between the Certification Agent and the IS program manager. I know both roles deal with documentation, but I can't recall which one specifically informs all participants.
upvoted 0 times
...
Noel
5 months ago
I feel like I've seen a similar question before, and I think the DAA might be the right answer. They usually handle security requirements, right?
upvoted 0 times
...
Erin
5 months ago
I think it might be the User representative, but I'm not entirely sure. I remember something about them being the main point of contact for user needs.
upvoted 0 times
...
Keshia
5 months ago
Based on the information provided, I think the server interface and the user's computer would be the two most appropriate locations to gather packets. That way, I can see what's happening on both ends of the connection.
upvoted 0 times
...
Ming
5 months ago
Okay, I think I've got this. The web server needs to be HTTP compliant so it can generate VoiceXML, which is key for a GVP solution.
upvoted 0 times
...
Johnson
5 months ago
Okay, I've got this. The manual payment method is about recording a payment made outside of Payables, so I'll select option D.
upvoted 0 times
...
Jeanice
5 months ago
Hmm, I'm not too familiar with the specifics of RSVP-TE configuration on this particular platform. I'll need to think through the options carefully to determine the correct default settings.
upvoted 0 times
...

Save Cancel