← Back to CBT Library

technical implementation of a a in the nisp

Answers for CDSE's Technical Implementation of A&A in the NISP course. Every answer is verified verbatim against the official CDSE student guide.

11 questions and answers11 of 11 verified against the official source

Studying for this with your unit? Send it to them.

πŸƒ Flashcards
01What is the purpose of the Technical Implementation of A&A in the NISP course?
A:

The purpose of this course is to provide you with the knowledge needed to assess information systems for authorization under the National Industrial Security Program, or NISP.

VERIFIED AGAINST THE SOURCE

β€œThe purpose of this course is to provide you with the knowledge needed to assess information systems for authorization under the National Industrial Security Program, or NISP.”

β€” CDSE β€” Technical Implementation of A&A in the NISP (CS300.16) Student Guide β†—
02What tools does Monique need to obtain for the self-assessment process?
A:

Monique must obtain a SCAP Compliance Checker and a STIG Viewer.

VERIFIED AGAINST THE SOURCE

β€œMonique must obtain two tools: a SCAP Compliance Checker and a STIG viewer.”

β€” CDSE β€” Technical Implementation of A&A in the NISP (CS300.16) Student Guide β†—
03What is the SCAP Compliance Checker used for?
A:

The SCAP Compliance Checker is an automated vulnerability scanning tool that analyzes and reports on the security configuration of an information system.

VERIFIED AGAINST THE SOURCE

β€œThe SCAP Compliance Checker is an automated vulnerability scanning tool. It leverages the Defense Information Systems Agency, or DISA, Security Technical Implementation Guides, or STIGs, and Operating System-specific baselines to analyze and report on the security configuration of an information system.”

β€” CDSE β€” Technical Implementation of A&A in the NISP (CS300.16) Student Guide β†—
04What administrative requirement is necessary for installing the SCAP Compliance Checker?
A:

Administrative privileges on the machine to be scanned are required to install the SCAP Compliance Checker application and to run scans.

VERIFIED AGAINST THE SOURCE

β€œIt is important to note that administrative privileges on the machine to be scanned are required to install the SCAP Compliance Checker application and to run scans.”

β€” CDSE β€” Technical Implementation of A&A in the NISP (CS300.16) Student Guide β†—
05What is the purpose of the STIG Viewer?
A:

The STIG Viewer is used in conjunction with the SCAP Compliance Checker scan results in order to view the compliance status of the system's security settings.

VERIFIED AGAINST THE SOURCE

β€œThe STIG Viewer is used in conjunction with the SCAP Compliance Checker scan results in order to view the compliance status of the system's security settings.”

β€” CDSE β€” Technical Implementation of A&A in the NISP (CS300.16) Student Guide β†—
06What type of report does the SCAP scan generate?
A:

The SCAP scan generates two types of reports: the All Settings Report and the Non-Compliance Report.

VERIFIED AGAINST THE SOURCE

β€œOne report is the largest html file, the All Settings Report. The other is the smaller html file, which is the Non-Compliance Report.”

β€” CDSE β€” Technical Implementation of A&A in the NISP (CS300.16) Student Guide β†—
07What does the Non-Compliance Report list?
A:

The Non-Compliance Report lists open vulnerabilities.

VERIFIED AGAINST THE SOURCE

β€œThis is a report that shows only open vulnerabilities.”

β€” CDSE β€” Technical Implementation of A&A in the NISP (CS300.16) Student Guide β†—
08What is the role of the ISSM in relation to the POA&M?
A:

The ISSM is responsible for creating the POA&M as part of the Security Authorization Package.

VERIFIED AGAINST THE SOURCE

β€œAs an ISSM, my role is to create the POA&M as part of the SSP.”

β€” CDSE β€” Technical Implementation of A&A in the NISP (CS300.16) Student Guide β†—
09What does the POA&M document?
A:

The POA&M documents unmitigated vulnerabilities and monitors progress in correcting security vulnerabilities.

VERIFIED AGAINST THE SOURCE

β€œOne of the most important purposes of a POA&M is to monitor the progress of correcting security vulnerabilities.”

β€” CDSE β€” Technical Implementation of A&A in the NISP (CS300.16) Student Guide β†—
10What is the significance of the CAT tabs in the STIG Viewer?
A:

The CAT tabs indicate different levels of severity for vulnerabilities, with Level 1 being the most severe.

VERIFIED AGAINST THE SOURCE

β€œThese are different levels of severity. Level 1 is the most severe and Level 3 is the least severe.”

β€” CDSE β€” Technical Implementation of A&A in the NISP (CS300.16) Student Guide β†—
11What is the expected outcome of using the SCAP Compliance Checker and STIG Viewer?
A:

The expected outcome is to identify vulnerabilities and document unmitigated vulnerabilities on a POA&M.

VERIFIED AGAINST THE SOURCE

β€œThis course provided you with instruction needed to use the SCAP Compliance Checker and STIG Viewer to identify vulnerabilities and document unmitigated vulnerabilities on a POA&M.”

β€” CDSE β€” Technical Implementation of A&A in the NISP (CS300.16) Student Guide β†—

Know questions we're missing?

Submit your own Q&A pairs. AI reviews them for quality, then they go live for everyone.

Study these as flashcards

Load all 11 questions into a free study set β€” flashcards, a practice test, and spaced repetition. No account.

Works on any PDF, doc or web page too β€” not just military training.

Veteran? vetaid.ai β€” free VA benefits help.