nerdexam
CompTIA

CAS-001 · Question #463

A security engineer is a new member to a configuration board at the request of management. The company has two new major IT projects starting this year and wants to plan security into the…

The correct answer is A. Establish the security control baseline to be assessed E. Categorize the applications according to use. Under the NIST Risk Management Framework (RMF), the ordered steps are: (1) Categorize, (2) Select controls, (3) Implement, (4) Assess, (5) Authorize, (6) Monitor. If the security engineer is only performing step 4 (Assess), they have skipped step 1 - Categorize the applications…

Enterprise Security

Question

A security engineer is a new member to a configuration board at the request of management. The company has two new major IT projects starting this year and wants to plan security into the application deployment. The board is primarily concerned with the applications' compliance with federal assessment and authorization standards. The security engineer asks for a timeline to determine when a security assessment of both applications should occur and does not attendsubsequent configuration board meetings. If the security engineer is only going to perform a security assessment, which of the following steps in system authorization has the security engineer omitted? (Select TWO).

Options

  • AEstablish the security control baseline to be assessed
  • BBuild the application according to software development security standards
  • CWrite the systems functionality requirements into the security requirements traceability matrix
  • DReview the results of user acceptance testing
  • ECategorize the applications according to use
  • FConsult with the stakeholders to determine which standards can be omitted

How the community answered

(23 responses)
  • A
    65% (15)
  • B
    9% (2)
  • D
    4% (1)
  • F
    22% (5)

Explanation

Under the NIST Risk Management Framework (RMF), the ordered steps are: (1) Categorize, (2) Select controls, (3) Implement, (4) Assess, (5) Authorize, (6) Monitor. If the security engineer is only performing step 4 (Assess), they have skipped step 1 - Categorize the applications according to use (option E) - and step 2 - Establish the security control baseline to be assessed (option A). Categorization determines the system's impact level (low/moderate/high), which drives which control baseline applies. Without a defined baseline, there is nothing to assess against. Options B and D relate to development and testing activities outside the RMF assessment scope. Option C (SRTM) is a documentation artifact, not an RMF step. Option F (omitting standards) is not a legitimate RMF step.

Topics

#security assessment#RMF#security categorization#security control baseline

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice