nerdexam
(ISC)2

CISSP-ISSEP · Question #207

DoD 8500.2 establishes IA controls for information systems according to the Mission Assurance Categories (MAC) and confidentiality levels. Which of the following MAC levels requires basic integrity…

The correct answer is D. MAC III. MAC III is the correct answer because it represents the lowest mission assurance tier under DoD 8500.2, covering systems that support administrative or routine business functions where only basic integrity and availability are required - disruption would cause minimal impact to…

Security Planning and Design

Question

DoD 8500.2 establishes IA controls for information systems according to the Mission Assurance Categories (MAC) and confidentiality levels. Which of the following MAC levels requires basic integrity and availability?

Options

  • AMAC I
  • BMAC II
  • CMAC IV
  • DMAC III

How the community answered

(14 responses)
  • A
    7% (1)
  • B
    7% (1)
  • D
    86% (12)

Explanation

MAC III is the correct answer because it represents the lowest mission assurance tier under DoD 8500.2, covering systems that support administrative or routine business functions where only basic integrity and availability are required - disruption would cause minimal impact to DoD operations.

Why the distractors are wrong:

  • MAC I (A) is the highest tier, requiring high integrity and high availability - these are mission-critical systems where failure could cause loss of life or mission failure.
  • MAC II (B) sits in the middle, requiring medium integrity and availability - systems important to mission support but not immediately life-critical.
  • MAC IV (C) does not exist in DoD 8500.2 - the framework only defines MAC I, II, and III.

Memory tip: Think of MAC levels as an inverse scale - higher MAC number = lower criticality. MAC III = "Three's the floor" (basic/minimal requirements), while MAC I = "One is top" (maximum requirements). The fake MAC IV option is a common trick; always remember the framework stops at III.

Topics

#DoD 8500.2#MAC levels#IA controls#Integrity/Availability

Community Discussion

No community discussion yet for this question.

Full CISSP-ISSEP Practice