New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 ISSMP Exam - Topic 3 Question 17 Discussion

Actual exam question for ISC2's ISSMP exam
Question #: 17
Topic #: 3
[All ISSMP Questions]

DIACAP applies to the acquisition, operation, and sustainment of any DoD system that collects, stores, transmits, or processes unclassified or classified information since December 1997. What phases are identified by DIACAP?

Each correct answer represents a complete solution. Choose all that apply.

Show Suggested Answer Hide Answer
Suggested Answer: A, C, D, E

The Department of Defense Information Assurance Certification and Accreditation Process (DIACAP) is a process defined by the United States Department of Defense (DoD) for managing risk. DIACAP replaced the former process, known as DITSCAP (Department of Defense Information Technology Security Certification and Accreditation Process), in 2006.

DoD Instruction (DoDI) 8510.01 establishes a standard DoD-wide process with a set of activities, general tasks, and a management structure to certify and accredit an Automated Information System (AIS) that will maintain the Information Assurance (IA) posture of the Defense Information Infrastructure (DII) throughout the system's life cycle.

DIACAP applies to the acquisition, operation, and sustainment of any DoD system that collects, stores, transmits, or processes unclassified or classified information since December 1997. It identifies four phases.

1.System Definition

2.Verification

3.Validation

4.Re-Accreditation


Contribute your Thoughts:

0/2000 characters
Kanisha
4 months ago
Wait, are we sure about all these phases? Sounds complicated.
upvoted 0 times
...
Cletus
4 months ago
System Definition is a must-have phase!
upvoted 0 times
...
Queen
4 months ago
I thought Re-Accreditation was just a repeat of Accreditation?
upvoted 0 times
...
Daniel
4 months ago
Definitely includes Accreditation and Verification.
upvoted 0 times
...
Elizabeth
5 months ago
DIACAP has been around since '97, wow!
upvoted 0 times
...
Keneth
5 months ago
I'm a bit confused about "Identification." I don't recall it being a phase in DIACAP, but I could be mixing it up with another framework.
upvoted 0 times
...
Lisbeth
5 months ago
I practiced a question similar to this, and I believe "Verification" and "Validation" were mentioned as key phases. I hope I got that right!
upvoted 0 times
...
Kristeen
5 months ago
I think "Accreditation" is definitely a phase, and I feel like "Re-Accreditation" might be too. They seem related to the process.
upvoted 0 times
...
Lashandra
5 months ago
I remember studying the DIACAP phases, but I'm not entirely sure if "System Definition" is one of them. It sounds familiar though.
upvoted 0 times
...
Katie
5 months ago
I'm pretty confident the answer is C, the application server. That seems like the most logical connection between those two components.
upvoted 0 times
...
Michal
5 months ago
Okay, let me think this through. I know the Filter transformation is an option, but I'm not sure if the Expression transformation could work as well. I'll need to review the details on each of these.
upvoted 0 times
...
Haley
5 months ago
I'm pretty confident that option D is not mandatory. Mapping the domain name to the bucket is essential only if you want to use a custom domain, right?
upvoted 0 times
...
Tegan
5 months ago
This question reminds me of a practice exam where we discussed setting orphan ports. It seems relevant but I'm a bit confused if that really applies here.
upvoted 0 times
...
Marta
5 months ago
This looks like a tricky question about Cisco UCS manager and security policies. I'll need to carefully review the requirements and options to determine the correct profiles to use.
upvoted 0 times
...

Save Cancel