IT CertificationsAnswer Key

Rmf Security Assessment Plan

11 community-sourced questions and answers. Free — no login.

Community-sourced. Answers may be wrong or out of date. Always verify with your official training portal before submitting. Not affiliated with any branch, agency, or vendor. Details.
QUESTION 1

Who must ensure that the security assessment plan is consistent with the security objectives of the organization and is cost-effective with regard to the resources allocated for the assessment?

ANSWER

Security Control Assessor

QUESTION 2

If you use eMASS to document security control assessment you should stop doing so.

ANSWER

False

QUESTION 3

Dodi 8510.01 dated March 2014 is the?

ANSWER

High level document that sets forth the policy stating RMF is to be used by DoD

QUESTION 4

Assessment procedure?

ANSWER

Are maintained by the RMF Techincal Advisory Group

QUESTION 5

The information system owner relies on the technical expertise and judgement of assessors to assess the security controls employed within or inherited by the information systems using assessment procedures specified in the security assessment plan.

ANSWER

True

QUESTION 6

Who has primary responsibility for all four tasks that comprise step 4 of the RMF?

ANSWER

Security Control Assessor

QUESTION 7

Security control assessments determine the extent to which the controls are implemented correctly, operate as intended, and produce the desired outcome with respect to meeting the security requirements for the information system.

ANSWER

True

QUESTION 8

When assessing security control compliance status

ANSWER

If vulnerabilities are found the control is recorded as compliant in the Security Assessment Report

QUESTION 9

Preparing for a security control assessment includes all of the following key activities, EXCEPT:

ANSWER

Identifying security controls that end users agree to support

QUESTION 10

Who approves the security assessment plan?

ANSWER

Security Control Assessor

QUESTION 11

The fourth step in the RMF process is to:

ANSWER

Assess Security Controls

Looking for a different version?

CBTs get updated every year. Search for the exact version you're taking (e.g. "cyber awareness 2025").

Search all study materials