Browse all practice questions for the Federal IT Security Professional (FITSP) Auditor Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Federal IT Security Professional (FITSP) Auditor Practice Exam 2026 - Free IT Security Practice Questions and Study Guide course image
All questions

These questions are part of the practice quiz. Start practicing

  • Which automated system must agencies use to submit required FISMA reports?
  • Which element is considered critical in the assessment of IT security processes in agencies?
  • The AES algorithm may be used with three different key lengths; which of the following is not a recognized AES flavor?
  • In relation to security categorization, which document is crucial for understanding the impact levels?
  • Who is primarily responsible for the implementation of security controls in an organization?
  • What additional approval is required according to OMB Memorandum M-14-04 before issuing an authorization to operate?
  • What is the correct order of the Risk Management Framework process?
  • What protocol, used by IPsec, manages connection settings and authenticates endpoints?
  • What is the primary goal of the risk management process?
  • What is the primary goal of the RMF?
  • Which NIST publication focuses heavily on the Risk Management Framework?
  • Which of the following is NOT part of the incident handling process?
  • What is the most significant change regarding security control selection in the revision of the SP 800-37?
  • Which publication provides guidance for interconnecting information technology systems?
  • What program uses a "do once, use many times" framework to streamline agency security assessments?
  • Who has the primary responsibility for implementing security controls?
  • Is teleworking from an employee's residence included under the Alternate Work Site security control?
  • What occurs if an Authorizing Official denies authorization to operate?
  • The Risk Management Framework (RMF) places heavy emphasis on which aspect?
  • What are the possible outcomes of the Authorization Decision?
  • Which of the following is NOT an example of actions noted in contingency plans?
  • Which vulnerability scanning tool is widely used for security assessments?
  • What are the data encryption format and digital certificate standard used by S/MIME?
  • What is the best course of action for media containing classified material that is no longer in use?
  • What type of maintenance is conducted by individuals communicating through a network, as identified by the control identifier MA-4?
  • Which of the following is a reason for adjusting a system's provisional impact level?
  • What is the supporting guideline for PE-17 Alternate Work Site?
  • Which FIPS 140-2 encryption level provides environmental protections?
  • What is the main role of the Internet Key Exchange (IKE) in network security?
  • Which agency conducts audits of private organizations using electronic health systems?
  • In which document would you find guidance for applying the Risk Management Framework to federal information systems?
  • Which of the following is NOT considered a security testing technique?
  • Which statement about system security assessments is false?
  • Which agency is responsible for publishing FISMA Reporting Metrics annually?
  • What kind of security control is a management, operational, or technical control employed by an organization in lieu of a recommended security control?
  • What is created to correlate the information system with critical mission/business processes?
  • Which type of control is typically the last resort when it comes to mitigating risks?
  • Under FISMA 2014, which agencies are formally assigned information security responsibilities?
  • Which approach focuses on balancing the protection of agency information with the cost of security controls?
  • In the context of security controls, what does "System-Specific" refer to?
  • In which Bluetooth mode are devices considered "promiscuous"?
  • What OMB memo requires agencies to safeguard against breaches of personally identifiable information?
  • Which law directed the Secretary of Health and Human Services to develop electronic health information protection standards?
  • During which SDLC phase is the training for security personnel conducted?
  • Which type of assessment reviews the potential impact of a failure in a system?
  • Are Federal information systems required to be re-authorized at least every three years?
  • Which two protocols refer to the same underlying protocol in different terms?
  • During which phase of the SDLC should the organization consider security requirements?
  • Which VPN technologies are authorized for use by federal agencies?
  • What policy and standard overlap physical security controls with identification and authentication?
  • How are compensating controls most effectively utilized?
  • What are the four components of the new Risk Management Model?
  • Applying the first three steps in the RMF to legacy systems can be viewed as a ______ to determine if the necessary and sufficient security controls have been appropriately selected and allocated.
  • Which NIST document lists information types and their associated provisional impact level?
  • What are some of the threats that an information system faces?
  • In cryptography, which term specifically refers to the protection of information from unauthorized access?
  • Which of the following represents a factor in adjusting provisional impact levels?
  • What is the basis for defining information types?
  • What are the six steps of the RMF process?
  • Which protocol is required by the OMB for Federal agencies to use in vulnerability scanning tools?
  • What is the automated reporting tool that agencies must use to report data, per DHS direction?
  • What does FedRAMP provide a standardized approach for?
  • Which directive establishes a national policy for the protection of US critical infrastructure?
  • What does the RMF Step 2 emphasize?
  • Which control activity does not involve direct protection-related actions?
  • Which document should detail the weaknesses or deficiencies identified in security controls?
  • Name the AES-based, wireless encryption mechanism used in the 802.11i wireless technical specification.
  • What are the components of an information system?
  • Which security role is responsible for authorizing the information system's operation?
  • What are the main components of security categories used in risk assessment?
  • Which NIST document lists information types and their associated provisional impact level?
  • What is defined as an identifiable part of a system that is a discrete target of configuration control processes?
  • What type of cybersecurity training is necessary to ensure staff understands their roles during an incident?
  • Are privacy security requirements adequately addressed by the standard catalog of security controls?
  • What is the primary purpose of the Business Impact Analysis (BIA)?
  • Which department was assigned by FISMA to prescribe standards for federal information systems?
  • What does the acronym POAM stand for in the context of security assessments?
  • What does AU-10 Non-Repudiation primarily address in information security?
  • Which OMB memo announced the implementation of accepted security configurations for Windows operating systems?
  • Which is a common method for assessing the risk associated with sensitive data?
  • What does the acronym PII stand for in data protection?
  • Which control relates to the essential processes of assessing and managing risks to information systems?
  • Which of the following DOES NOT cite IT performance measurement as a requirement?
  • Which of the following is NOT a requirement under the OMB memo M-06-16?
  • Which statements are linked to the security control's content to ensure assessment results trace back to control requirements?
  • Which legislation requires Privacy Impact Assessments when developing new IT?
  • Which framework is used to evaluate security controls and how they impact risk management?
  • What is the term that represents the total time the system owner is willing to accept a mission/business process outage or disruption?
  • Which legislation requires an annual evaluation of an agency's information security program by its Inspector General or an external auditor?
  • Because AH transport mode cannot alter the original IP header, it is generally used in which VPN architecture?
  • Which type of controls can be inherited by one or more organizational information systems?
  • In which phase of the SDLC are the PIA, BIA, and Security Categorization conducted?
  • Which of the following is NOT a key document used for risk-based authorization decisions?
  • What must be conducted to support a security authorization package?
  • What is the objective of the Continuous Monitoring process?
  • Which directive was established to enhance the security of identities used by Federal agencies?
  • Which act assigned responsibilities to NIST for developing standards related to securing Federal Information Systems?
  • Which SCAP specifications provide a standard naming convention for operating systems, hardware, and applications?
  • Which publication recommends using the independence standards for an agency's FISMA audit?
  • What does the acronym CPIC stand for in the context of information security resource management?
  • Is it true that more than one method may be required to assess the proper operation of a single security control?
  • How many business areas are described in the BRM?
  • What is the correct order of the four components of risk management?
  • Which IPSec protocol can be configured to provide compression for IPSec traffic?
  • What is the primary goal of the Risk Management Framework (RMF)?
  • Which NIST Special Publication is NOT related to risk management and risk assessment?
  • In terms of IT security, what is the main purpose of establishing a security configuration baseline?
  • Personnel meet in a classroom to discuss their roles during an emergency. What type of exercise is this?
  • During which SDLC phase are Security Reauthorizations conducted?
  • What are some of the threats that an information system faces?
  • Which category falls under the responsibilities of federal agencies as defined by OMB?
  • What are security controls that are inheritable by organizational information systems?
  • Which type of testing involves simulating an attack on a system to identify vulnerabilities?
  • Which NIST Special Publication provides guidance for protecting PII?
  • What is a well-defined, documented, and approved specification that describes the approved configuration of an information system?
  • What is a key focus of the FedRAMP program?
  • What e-authentication level requires multifactor authentication and the use of a hard token?
  • During which phase of the SDLC are Security Reauthorizations conducted?
  • Where are security controls documented?
  • What does the Federal Information Security Management Act (FISMA) primarily aim to improve?
  • Which Federal mandate requires agencies to report incidents to US-CERT?
  • What is the correct order of the four components of risk management?
  • What are the possible outcomes of the Authorization Decision?
  • What drives the level of effort for the selection and implementation of security controls?
  • What significant change was made regarding security control selection in the revision of SP 800-37?
  • What is the first step to assigning impact levels for security categorization?
  • Can the Authorizing Official delegate the decision to authorize?
  • What is the name of the testing that determines if a change caused issues in unchanged parts of the system?
  • Which NIST special publication helps facilitate security control assessments in a risk management framework?
  • Which practice can help reduce the effort required to assess controls?
  • What is the reporting timeframe for a CAT-3 incident categorized under US-CERT?
  • What is the primary purpose of HSPD-12?
  • Which two NIST Special Publications are essential for information security planning?
  • Which FIPS encryption level requires identity based authentication?
  • What is the Homeland Security Presidential Directive that establishes a government-wide identification standard?
  • What mechanism is used to authenticate information transmitted between two parties sharing a secret key?
  • During which phase of the SDLC should an organization consider the security requirements?
  • Which Bluetooth security mode allows devices to connect without restrictions?
  • Which roles must be assigned only to government personnel?
  • Which of the following is NOT a phase of the SDLC?
  • Which NIST special publication provides guidance on the privacy and legal issues with VOIP?
  • What is the policy established for a Common Identification Standard for Federal Employees and Contractors?
  • What establishes the scope of protection for organizational information systems?
  • What does the NIST SP 800-60 Volume 2 specifically address?
  • Tier 2 of the three-tiered risk management approach addresses risk-related concerns at which level?
  • What control emphasizes the significance of the security categorization process?
  • Which GSA program provides a cost-effective approach for adopting cloud services?
  • The Information Security Program Plan documents which TWO components?
  • Which of the following is NOT a part of the FISCAM control hierarchy?
  • What is the required frequency for FISMA reporting feeds for CFO Act agencies?
  • What VPN model is most commonly used for traveling employees to access organizational services?
  • Which special publication provides guidelines on designing, developing, conducting, and evaluating test, training, and exercise events?
  • Which phase of the SDLC includes the implementation of security controls?
  • ISCM aims to improve security by replacing the "every three years" reauthorization requirement with what type of process?
  • What are the IETF specifications for securing DNS queries to second-level .gov domain servers?
  • Which of the following is NOT a component of an information system?
  • Which federal act emphasizes the importance of securing federal automated information systems?
  • Which contingency planning variable defines the maximum time a resource can be unavailable before it impacts operations?
  • What is the primary focus of continuous monitoring in security control revisions?
  • What is the main purpose of a Tabletop exercise in emergency management?
  • What does the abbreviation PII stand for in the context of NIST guidance?
  • At what point in the SDLC are security controls implemented?
  • What is the primary function of the System Security Plan?
  • What legislation requires federal agencies to develop an agency-wide information security program?
  • In which NIST special publication can you find guidance regarding mobile computers using FIPS 140-2 validated cryptographic modules?
  • What law granted OMB the authority to define policies for US Government Agencies?
  • What technique is commonly used in security to ensure the authenticity of a message?
  • FIPS 200 provides guidance for security control selection based on what?
  • Which document provides the results of assessing the implementation of security controls to determine their operational effectiveness?
  • Which of the following acts is primarily focused on the cyber defense of critical infrastructure?
  • According to OMB M-14-04, which two individuals must sign the ATO for a new information system to operate?
  • Which factors influence the level of effort expended when implementing the RMF tasks?
  • During which phase of the SDLC should security requirements be defined?
  • What security control ensures that an individual cannot deny having performed a particular action?
  • Software assurance is addressed by which family of security controls from SP 800-53?
  • What is the FIPS publication that specifies the Rijndael algorithm?
  • What are the three levels of potential impact from a security breach?
  • Which two NIST special publications provide the management overview and risk assessment guidance on risk management?
  • Which document provides a policy framework for information resources management across the Federal government?
  • In which phase of contingency planning are recovery activities completed and normal operations resumed?
  • Name the contingency planning variable that defines the maximum amount of time that a system resource can remain unavailable before there is an unacceptable impact.
  • What is the specific type of authorization allowing a system to operate with live data for testing purposes?
  • Which of the following is NOT a feature of Security Mode 1 in Bluetooth technology?
  • After security categorization, which publication specifies the minimum security requirements?
  • Which role is responsible for ensuring that security requirements are integrated into the systems development lifecycle?
  • What is the method of reviewing or analyzing one or more assessment objects called?
  • Who is responsible for ensuring that information security requirements are addressed in enterprise architecture?
  • In which phase of the SDLC are the PIA, BIA, and Security Categorization performed?
  • Security Controls are allocated into which three designations?
  • What is defined as a body of evidence organized into an argument to assure claims about an information system?
  • FIPS 199 standards apply to which types of systems?
  • Which legislation requires federal agencies to establish capital planning and investment control policies for IT procurement?
  • How many families are security controls organized into?
  • What type of security control is used in place of a recommended security control?
  • Which method of encryption involves both a public and private key for secure data transmission?
  • Which of the following were purposes in introducing overlays in SP 800-53r4?
  • Which of the following are the security objectives under FISMA?
  • Which security framework emphasizes a risk management approach to information security?
  • Which document outlines the procedures for responding to cybersecurity incidents?
  • What are the two most important factors when selecting a security control assessor?
  • What are the two types of authorization decisions that can be made by authorizing officials?
  • Which US Law mandates all agencies to report security incidents to a Federal incident response center?
  • Which aspect is primarily evaluated in security assessments?
  • What does SAR stand for in security documentation?
  • Which two encryption mechanisms are approved for use by US Federal agencies?
  • Which security mechanism is specifically designed to ensure that a message is not altered in transit?
  • What is one of the requirements of the Clinger-Cohen Act for federal agencies?
  • What form of cryptographic service is used to establish non-repudiation?
  • What type of authentication must be used for remote access according to the memo released after the Veterans Affairs incident?
  • Blocking outside traffic that claims to be from within the organization is managed by which security control?
  • When would you use a gap analysis in the RMF process?
  • What framework was introduced for automated assessment of security controls?
  • Which NIST Special Publication superseded the original Special Publication 800-30 for risk management guidance?
  • What program does the OMB use to help agencies identify business processes?
  • What initiative aims to create security configuration baselines for IT products deployed federally?
  • What is the recommended disposal method for paper-based medical records containing sensitive PII?
  • Early integration of security in the SDLC allows agencies to maximize ROI in their security programs through:
  • Which of the following is NOT a cryptographic security service?
  • In response to the loss of records at the Department of Veteran Affairs, which requirement is NOT mandated by OMB memo M-06-16?
  • Which OMB guidance requires federal agencies to review security controls for each system at least every three years?
  • Which standard governs the Keyed-Hash Message Authentication Code (HMAC)?
  • The risk management processes at the information system level link to organizational level processes through which newly defined role in the RMF?
  • Which task is NOT part of the RMF implementation process?
  • Which NIST Special Publication provides guidance for implementing ISCM?
  • In which case can a POAM be utilized effectively?
  • Name the three tasks of the RMF Categorization step.
  • Where can one find the list of privacy controls required for Federal information systems?
  • What is the purpose of common controls in an organization?
  • What is the primary focus of the incident containment phase?
  • Which RMF role ensures risk-related considerations are viewed from an organization-wide perspective?
  • What is the correct order of the four tasks of the assessment step of the RMF?
  • Which of the following is NOT a type of security control?
  • Which SCAP specification provides a standard naming convention for operating systems, hardware, and applications?
  • Which of the following is an example of Tier 1 risk?
  • What is the basis for the identification of information types?
  • IDPS use this type of detection to identify significant deviations. What is this method called?
  • Which document or report outlines the necessary procedures for the protection of sensitive agency information?
  • How often are CFO Agencies required to submit data through CyberScope?
  • What are the factors that drive the level of effort for the selection and implementation of security controls?
  • What establishes the scope of protection for organizational information systems?
  • What abbreviation represents the effort to provide adequate resources for information security?
  • What is a valid assessment method for security controls?
  • Which security control is designed to protect against an individual falsely denying an action?
  • Which roles must be assigned only to government personnel?
  • Which document outlines the risk assessment process for data systems?
  • What term refers to the techniques that are used to protect the confidentiality, integrity, and availability of information?
  • What type of contingency alternate site has all the resources required to assume full processing in case of the loss of the primary site but might result in a short delay before becoming fully operational?
  • Which NIST Special Publication details assessment objects for security controls?
  • What are the two key components affecting the trustworthiness of information systems?
  • Which legislation mandates the appointment of a Chief Information Officer in federal agencies?
  • IPSEC protects the integrity of data in transit using which protocol?
  • Which type of authorization is not valid according to OMB, despite being used by some agencies?
  • What is the NIST Special Publication that provides guidance for protecting PII?
  • What would be the appropriate backup strategy and alternate site combination for a system with a FIPS 199 Availability Impact of MODERATE?
  • Which role is responsible for ensuring that security policies are enforced within an organization?
  • Which NIST Special Publication applies to information systems in employee's residences for telecommuting?
  • Which act outlines guidelines specifically for agency-wide security programs in federal agencies?
  • In the sanitization guidelines of NIST SP 800-88, what is the recommended disposal method for paper-based medical records containing sensitive PII?
  • What is defined as a simulation of an emergency to validate an Information System Contingency Plan (ISCP)?
  • Which framework does the Federal Government adhere to for privacy controls?
  • In the context of information security, what is a primary function of the System Security Plan?
  • What is the overarching goal of the Federal Information Security Management Act (FISMA)?
  • What is the US-CERT incident category name and reporting timeframe for a CAT-2 incident?
  • What does SSP refer to after a risk assessment?
  • What is the main goal of the ISCP?
  • What is the first step to assigning impact levels for security categorization?
  • What documents compose a Security Authorization Package?
  • Which of the following SCAP specifications provides a standard naming and dictionary of system configuration issues?
  • What is the purpose of using Message Authentication Codes between parties?
  • What defines the three levels of baseline controls for an information system?
  • What type of analysis is performed during the Initiation phase of the SDLC?
  • This Standard defines a MAC that employs a cryptographic hash function with a secret key.
  • What type of control is applied to protect against unauthorized access?
  • A hard drive pulled from an unclassified information system containing high confidentiality information will be reused. What is the recommended course of media sanitization?
  • What are the six steps of the RMF process?
  • What main policy does the Department of Homeland Security encompass regarding information systems?
  • Which security designation describes controls applicable to more than one information system?
  • In the context of cybersecurity, what does the term 'replay attack' refer to?
  • Which approach involves continually balancing the protection of agency information and assets with cost considerations?
  • Which key management practice is critical when using public key infrastructure (PKI)?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy