technical implementation of a a in the nisp
Answers for CDSE's Technical Implementation of A&A in the NISP course. Every answer is verified verbatim against the official CDSE student guide.
Studying for this with your unit? Send it to them.
01What is the purpose of the Technical Implementation of A&A in the NISP course?
The purpose of this course is to provide you with the knowledge needed to assess information systems for authorization under the National Industrial Security Program, or NISP.
VERIFIED AGAINST THE SOURCE
βThe purpose of this course is to provide you with the knowledge needed to assess information systems for authorization under the National Industrial Security Program, or NISP.β
β CDSE β Technical Implementation of A&A in the NISP (CS300.16) Student Guide β02What tools does Monique need to obtain for the self-assessment process?
Monique must obtain a SCAP Compliance Checker and a STIG Viewer.
VERIFIED AGAINST THE SOURCE
βMonique must obtain two tools: a SCAP Compliance Checker and a STIG viewer.β
β CDSE β Technical Implementation of A&A in the NISP (CS300.16) Student Guide β03What is the SCAP Compliance Checker used for?
The SCAP Compliance Checker is an automated vulnerability scanning tool that analyzes and reports on the security configuration of an information system.
VERIFIED AGAINST THE SOURCE
βThe SCAP Compliance Checker is an automated vulnerability scanning tool. It leverages the Defense Information Systems Agency, or DISA, Security Technical Implementation Guides, or STIGs, and Operating System-specific baselines to analyze and report on the security configuration of an information system.β
β CDSE β Technical Implementation of A&A in the NISP (CS300.16) Student Guide β04What administrative requirement is necessary for installing the SCAP Compliance Checker?
Administrative privileges on the machine to be scanned are required to install the SCAP Compliance Checker application and to run scans.
VERIFIED AGAINST THE SOURCE
βIt is important to note that administrative privileges on the machine to be scanned are required to install the SCAP Compliance Checker application and to run scans.β
β CDSE β Technical Implementation of A&A in the NISP (CS300.16) Student Guide β05What is the purpose of the STIG Viewer?
The STIG Viewer is used in conjunction with the SCAP Compliance Checker scan results in order to view the compliance status of the system's security settings.
VERIFIED AGAINST THE SOURCE
βThe STIG Viewer is used in conjunction with the SCAP Compliance Checker scan results in order to view the compliance status of the system's security settings.β
β CDSE β Technical Implementation of A&A in the NISP (CS300.16) Student Guide β06What type of report does the SCAP scan generate?
The SCAP scan generates two types of reports: the All Settings Report and the Non-Compliance Report.
VERIFIED AGAINST THE SOURCE
βOne report is the largest html file, the All Settings Report. The other is the smaller html file, which is the Non-Compliance Report.β
β CDSE β Technical Implementation of A&A in the NISP (CS300.16) Student Guide β07What does the Non-Compliance Report list?
The Non-Compliance Report lists open vulnerabilities.
VERIFIED AGAINST THE SOURCE
βThis is a report that shows only open vulnerabilities.β
β CDSE β Technical Implementation of A&A in the NISP (CS300.16) Student Guide β08What is the role of the ISSM in relation to the POA&M?
The ISSM is responsible for creating the POA&M as part of the Security Authorization Package.
VERIFIED AGAINST THE SOURCE
βAs an ISSM, my role is to create the POA&M as part of the SSP.β
β CDSE β Technical Implementation of A&A in the NISP (CS300.16) Student Guide β09What does the POA&M document?
The POA&M documents unmitigated vulnerabilities and monitors progress in correcting security vulnerabilities.
VERIFIED AGAINST THE SOURCE
βOne of the most important purposes of a POA&M is to monitor the progress of correcting security vulnerabilities.β
β CDSE β Technical Implementation of A&A in the NISP (CS300.16) Student Guide β10What is the significance of the CAT tabs in the STIG Viewer?
The CAT tabs indicate different levels of severity for vulnerabilities, with Level 1 being the most severe.
VERIFIED AGAINST THE SOURCE
βThese are different levels of severity. Level 1 is the most severe and Level 3 is the least severe.β
β CDSE β Technical Implementation of A&A in the NISP (CS300.16) Student Guide β11What is the expected outcome of using the SCAP Compliance Checker and STIG Viewer?
The expected outcome is to identify vulnerabilities and document unmitigated vulnerabilities on a POA&M.
VERIFIED AGAINST THE SOURCE
βThis course provided you with instruction needed to use the SCAP Compliance Checker and STIG Viewer to identify vulnerabilities and document unmitigated vulnerabilities on a POA&M.β
β CDSE β Technical Implementation of A&A in the NISP (CS300.16) Student Guide βKnow questions we're missing?
Submit your own Q&A pairs. AI reviews them for quality, then they go live for everyone.
Study these as flashcards
Load all 11 questions into a free study set β flashcards, a practice test, and spaced repetition. No account.
Works on any PDF, doc or web page too β not just military training.
Veteran? vetaid.ai β free VA benefits help.