nerdexam
(ISC)2

CAP · Question #32

Which of the following DITSCAP phases validates that the preceding work has produced an IS that operates in a specified computing environment?

The correct answer is B. Phase 3. DITSCAP (DoD Information Technology Security Certification and Accreditation Process) has four phases: Phase 1 (Definition) establishes the system security requirements; Phase 2 (Verification) verifies the system is designed to meet the SSAA; Phase 3 (Validation) validates that…

Assessment/Audit of Security and Privacy Controls

Question

Which of the following DITSCAP phases validates that the preceding work has produced an IS that operates in a specified computing environment?

Options

  • APhase 4
  • BPhase 3
  • CPhase 2
  • DPhase 1

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    94% (30)
  • D
    3% (1)

Explanation

DITSCAP (DoD Information Technology Security Certification and Accreditation Process) has four phases: Phase 1 (Definition) establishes the system security requirements; Phase 2 (Verification) verifies the system is designed to meet the SSAA; Phase 3 (Validation) validates that the completed system actually operates correctly in its intended environment-this is where Security Test and Evaluation (ST&E) occurs to confirm the system meets all requirements; Phase 4 (Post Accreditation) covers ongoing operations and maintenance. Phase 3 is the correct answer because 'validation' confirms the real-world system matches what was planned.

Topics

#DITSCAP#Certification and Accreditation#Security Validation#System Assessment

Community Discussion

No community discussion yet for this question.

Full CAP Practice