In 2003, NIST developed a new Certification & Accreditation (C&A) guideline known as FIPS 199. What levels of potential impact are defined by FIPS 199?
Each correct answer represents a complete solution. Choose all that apply.
In 2003, NIST developed a new Certification & Accreditation (C&A) guideline known as FIPS 199. FIPS 199 is a standard for security
categorization of Federal Information and Information Systems. It defines three levels of potential impact:
Low: It causes a limited adverse effect.
Medium: It causes a serious adverse effect.
High: It causes a severe adverse effect.
How can you calculate the Annualized Loss Expectancy (ALE) that may occur due to a threat?
The Annualized Loss Expectancy (ALE) that occurs due to a threat can be calculated by multiplying the Single Loss Expectancy (SLE) with the
Annualized Rate of Occurrence (ARO).
Annualized Loss Expectancy (ALE) = Single Loss Expectancy (SLE) X Annualized Rate of Occurrence (ARO)
Annualized Rate of Occurrence (ARO) is a number that represents the estimated frequency in which a threat is expected to occur. It is
calculated based upon the probability of the event occurring and the number of employees that could make that event occur.
Single Loss Expectancy (SLE) is the value in dollars that is assigned to a single event. SLE can be calculated by the following formula:
SLE = Asset Value ($) X Exposure Factor (EF)
The Exposure Factor (EF) represents the % of assets loss caused by a threat. The EF is required to calculate Single Loss Expectancy (SLE).
Which of the following are the principle duties performed by the BIOS during POST (power-on-self-test)?
Each correct answer represents a part of the solution. Choose all that apply.
The principle duties performed by the BIOS during POST (power-on-self-test) are as follows:
It verifies the integrity of the BIOS code itself.
It discovers size and verifies system memory.
It discovers, initializes, and catalogs all system hardware.
It delegates control to other BIOS if it is required.
It provides a user interface for system's configuration.
It identifies, organizes, and selects boot devices.
It executes the bootstrap program.
Answer F is incorrect. The BIOS does not interrupt the execution of all running programs.
Which of the following statements about the integrity concept of information security management are true? Each correct answer represents a complete solution. Choose three.
The following statements about the integrity concept of information security management are true:
It ensures that modifications are not made to data by unauthorized personnel or processes.
It ensures that unauthorized modifications are not made to data by authorized personnel or processes.
It ensures that internal information is consistent among all subentities and also consistent with the real-world, external situation.
Answer B is incorrect. Accountability determines the actions and behaviors of an individual within a system, and identifies that particular
individual. Audit trails and logs support accountability.
Frank is the project manager of the NHH Project. He is working with the project team to create a plan to document the procedures to manage risks throughout the project. This document will define how risks will be identified and quantified. It will also define how contingency plans will be implemented by the project team. What document is Frank and the NHH Project team creating in this scenario?
The risk management plan, part of the comprehensive management plan, defines how risks will be identified, analyzed, monitored and
controlled, and even responded to.
A Risk management plan is a document arranged by a project manager to estimate the effectiveness, predict risks, and build response plans
to mitigate them. It also consists of the risk assessment matrix.
Risks are built in with any project, and project managers evaluate risks repeatedly and build plans to address them. The risk management
plan consists of analysis of possible risks with both high and low impacts, and the mitigation strategies to facilitate the project and avoid
being derailed through which the common problems arise. Risk management plans should be timely reviewed by the project team in order to
avoid having the analysis become stale and not reflective of actual potential project risks. Most critically, risk management plans include a risk
strategy for project execution.
Answer C is incorrect. The project management plan is a comprehensive plan that communicates the intent of the project for all project
management knowledge areas.
Answer B is incorrect. The project plan is not an official PMBOK project management plan.
Answer D is incorrect. The resource management plan defines the management of project resources, such as project team members,
facilities, equipment, and contractors.
Michael White
6 days agoPreeti Mishra
27 days agoPaul Lewis
1 month agoKazuki Phan
2 months agoJames Morris
2 months agoSarah Morgan
3 months agoHarold Roberts
4 months agoMelissa Nelson
3 months agoRyan Johnson
4 months agoAmanda Peterson
3 months agoRichard Adams
3 months agoJohn Wright
3 months agoWilda
4 months agoGladys
5 months agoShelba
5 months agoCammy
5 months agoIzetta
5 months agoDalene
6 months agoLouvenia
6 months agoLuisa
6 months agoEdna
7 months agoHannah
7 months agoFelicia
7 months agoCharlene
7 months agoTegan
7 months agoWillow
8 months agoValentine
8 months agoJunita
8 months agoKaycee
8 months agoDelila
9 months agoTegan
9 months agoLeanna
9 months agoTammi
10 months agoLeana
10 months agoMerlyn
10 months agoMoira
10 months agoLachelle
11 months agoRosenda
11 months agoMarilynn
11 months agoRutha
11 months agoArlette
1 year agoCamellia
1 year agoDortha
1 year agoRodrigo
1 year agoGarry
2 years agoRonny
2 years agoParis
2 years agoAja
2 years agoLazaro
2 years agoTawanna
2 years agoCarissa
2 years agoWynell
2 years agoMabelle
2 years agoAshley
2 years agoShenika
2 years agoNicolette
2 years agoTerina
2 years agoDustin
2 years agoMarylin
2 years agoDulce
2 years agoCarmela
2 years agoLeah
2 years agoErinn
2 years agoLarue
2 years agoRochell
2 years agoElli
2 years ago