712-50 · Question #273
The formal certification and accreditation process has four primary steps, what are they?
The correct answer is A. Evaluating, describing, testing and authorizing. Option A is correct because the formal Certification & Accreditation (C&A) process follows these four sequential phases: evaluating the system's security posture, describing (documenting) its configuration and controls, testing those controls to verify they function as…
Question
The formal certification and accreditation process has four primary steps, what are they?
Options
- AEvaluating, describing, testing and authorizing
- BEvaluating, purchasing, testing, authorizing
- CAuditing, documenting, verifying, certifying
- DDiscovery, testing, authorizing, certifying
How the community answered
(24 responses)- A83% (20)
- B4% (1)
- C8% (2)
- D4% (1)
Explanation
Option A is correct because the formal Certification & Accreditation (C&A) process follows these four sequential phases: evaluating the system's security posture, describing (documenting) its configuration and controls, testing those controls to verify they function as intended, and authorizing the system to operate (the Authority to Operate, or ATO). These steps reflect the standard NIST/DIACAP framework for formally approving systems to handle sensitive information.
Why the distractors fail:
- B introduces "purchasing," which is a procurement activity, not a security evaluation step - C&A assesses an existing system, not a buying decision.
- C uses "auditing" and "certifying" - while audit-like activities occur within C&A, "certifying" is the name of the overall process, not one of its internal steps, making this circular and imprecise.
- D includes "discovery," a term from network scanning/reconnaissance, which has no formal role in the C&A framework.
Memory tip: Use the mnemonic "Every Developer Tests Applications" - Evaluating, Describing, Testing, Authorizing - to recall the four steps in order.
Topics
Community Discussion
No community discussion yet for this question.