Courseiva

CCNA Control Selection Questions

27 questions · Control Selection · All types, answers revealed

1
MCQhard

During a control audit, you find that the organization has documented a 'common control' for password complexity. What does this imply for individual systems?

A.Individual systems must override the common control.
B.Common controls cannot be used for password complexity.
C.Individual systems must report their own password status.
D.Individual systems do not need to address password complexity.
AnswerD

Inheritance means the control is satisfied at the enterprise level.

Why this answer

Common controls are controls provided by the infrastructure or enterprise that individual information systems inherit, reducing the burden on system owners.

2
MCQeasy

What document provides the most granular guidance on tailoring security controls for federal systems?

A.FIPS 200.
B.NIST SP 800-37.
C.CNSSI 1253.
D.NIST SP 800-53.
AnswerD

It contains the specific guidance for control selection and tailoring.

Why this answer

NIST SP 800-53, specifically the tailoring guidance section, provides the framework for modifying baselines.

3
MCQhard

An organization is applying NIST SP 800-53 Rev. 5 controls to a cloud-based SaaS application. The authorization official requests that you perform 'supplementing' during the tailoring process. What is the correct action?

A.Replace a control with a vendor-provided security feature.
B.Add additional controls to the baseline to address specific threat vectors.
C.Remove controls from the baseline that are technically infeasible.
D.Adjust the parameters of existing controls to lower operational impact.
AnswerB

Supplementing specifically refers to the addition of controls.

Why this answer

Supplementing is the process of adding controls to a baseline to address specific mission or business requirements that are not covered by the standard baseline.

4
Multi-Selecthard

Which THREE actions are essential to correctly manage assignments in NIST 800-53 controls?

Select 3 answers
A.Updating all assignment values daily.
B.Ensuring the assignment value is consistent with organizational policy.
C.Consulting with the NIST publication author.
D.Verifying the assignment is addressed by the control implementation.
E.Defining the assignment value in the system security plan.
AnswersB, D, E

Consistency with policy is required for compliance.

Why this answer

Effective management of assignments ensures that controls are tailored and that the organization has a clear record of its security obligations.

5
Multi-Selectmedium

Which TWO of the following are considered 'common controls'?

Select 2 answers
A.The custom source code of a business logic application.
B.Application-specific encryption keys.
C.Physical building access badges.
D.The specific database schema of a custom app.
E.Network boundary protection (firewall) for the data center.
AnswersC, E

Physical access is typically provided at the facility level.

Why this answer

Common controls are typically provided by centralized entities, such as physical security or network boundary protection.

6
Multi-Selectmedium

Which TWO of the following characterize the 'Select' step in the RMF?

Select 2 answers
A.Verifying that the controls are operating as expected.
B.Identifying and selecting the security controls to be implemented.
C.Determining the impact categorization of the system.
D.Documenting the controls in the System Security Plan (SSP).
E.Authorizing the system for operation.
AnswersB, D

This is the primary function of the select step.

Why this answer

The select step focuses on choosing the appropriate controls and documenting them in the system security plan.

7
MCQmedium

Your organization has decided to use a 'Control Overlay' for a cloud environment. What is the primary benefit of using an overlay?

A.It provides a standardized set of controls for a specific technology stack.
B.It replaces the need for FIPS 199 categorization.
C.It eliminates the need for manual tailoring.
D.It automatically tests the controls for compliance.
AnswerA

Overlays tailor baselines for specific scenarios like cloud or IoT.

Why this answer

Overlays are pre-defined sets of controls that address specific environments, technologies, or missions, ensuring consistent security posture.

8
Multi-Selecthard

Which THREE factors should an organization consider when applying control overlays?

Select 3 answers
A.The personal preference of the system administrator.
B.The date the system was originally purchased.
C.The mission or business requirements of the system.
D.The impact level of the underlying system.
E.The existing control baseline of the system.
AnswersC, D, E

Business needs drive the need for the specific overlay.

Why this answer

Overlays must be carefully integrated to ensure they maintain compliance while addressing specific environmental factors.

9
MCQmedium

You are preparing a security plan for a federal information system categorized as MODERATE impact. According to NIST SP 800-53B, what is the primary objective of the initial control baseline selection process?

A.To remove all controls that do not apply to the local network.
B.To define the continuous monitoring strategy for the system.
C.To provide a standardized starting point based on impact level.
D.To identify all system-specific compensations.
AnswerC

The baseline provides the initial set of controls for the categorization.

Why this answer

NIST SP 800-53B focuses on establishing a starting point of security controls based on the FIPS 199 impact categorization to ensure a minimum security posture.

10
MCQmedium

What is the primary role of the authorization official (AO) during the Control Selection phase?

A.To approve the tailoring decisions.
B.To configure the security appliances.
C.To write the security policy.
D.To perform the technical assessment.
AnswerA

The AO signs off on the risk represented by the selected controls.

Why this answer

The AO reviews and approves the selected control set to ensure it meets the risk appetite of the organization.

11
MCQmedium

When selecting controls for a system that uses mobile devices, you apply an overlay. What is the correct relationship between the baseline and the overlay?

A.The overlay supplements the baseline.
B.The overlay is used only if the system is High impact.
C.The baseline is discarded if an overlay is used.
D.The overlay replaces the entire baseline.
AnswerA

The overlay adds or modifies controls for the specific technology.

Why this answer

Overlays are used to augment the base control set; they don't replace the baseline but tailor it for a specific context.

12
Multi-Selecthard

Which THREE of the following are benefits of using the NIST 800-53 control framework?

Select 3 answers
A.It supports a consistent approach to security across the organization.
B.It eliminates the need for any technical expertise.
C.It facilitates risk-based decision-making.
D.It automates all manual security processes.
E.It provides a common language for security controls.
AnswersA, C, E

Consistent application is a primary benefit.

Why this answer

The framework provides a common language and structured approach to security that helps organizations manage risk effectively.

13
MCQeasy

When utilizing the NIST 800-53 control catalog, which field identifies the specific family to which a control belongs?

A.Control priority tag.
B.The assignment statement.
C.Control ID prefix.
D.The control parameter list.
AnswerC

The prefix denotes the family, such as AC for Access Control.

Why this answer

Control identifiers in NIST 800-53 follow a format such as AC-2, where 'AC' refers to the Access Control family.

14
Multi-Selecthard

Which THREE of the following are components that must be included when documenting a compensating control?

Select 3 answers
A.The identity of the person who approved the control.
B.A detailed explanation of how the compensating control mitigates the risk.
C.A description of the risk the control is intended to mitigate.
D.A list of every user affected by the control.
E.The reason why the original control could not be implemented.
AnswersB, C, E

The mechanism of mitigation must be proven.

Why this answer

Compensating controls require rigorous documentation to ensure the auditor can verify that the risk is mitigated effectively.

15
Multi-Selectmedium

Which TWO of the following statements regarding the 'Tailoring' process are accurate?

Select 2 answers
A.Tailoring is performed during the Assess step.
B.Tailoring actions must be documented to justify the risk management decisions.
C.Tailoring is only permitted for High impact systems.
D.Tailoring is used to modify the baseline based on system-specific factors.
E.Tailoring is optional and not required by RMF.
AnswersB, D

Documentation is mandatory for transparency and auditability.

Why this answer

Tailoring allows for the modification of the baseline, but those modifications must be documented and justified.

16
MCQeasy

If a control is determined to be 'system-specific', what does that mean?

A.It is a hybrid control.
B.It is implemented by the system owner for that system only.
C.It must be implemented by the vendor.
D.It is inherited from the enterprise.
AnswerB

System-specific means the system is responsible for the implementation.

Why this answer

A system-specific control is one that is implemented solely by the information system and is not inherited from an enterprise service.

17
MCQmedium

During tailoring, what is the 'Refinement' process?

A.Changing the impact level of the system.
B.Removing controls that are too expensive.
C.Adjusting the control statement to make it more precise.
D.Adding new controls to the baseline.
AnswerC

Refinement makes the control more applicable.

Why this answer

Refinement is the process of adjusting the implementation of a control to be more specific to the technology or mission.

18
MCQhard

You are assessing a system. You find a control that is marked as 'Inherited'. What is the most critical item to verify?

A.That the control is listed in the system's own configuration guide.
B.That the system owner has full administrative control.
C.That the common control provider provides evidence of compliance.
D.That the control is manually tested by the system team.
AnswerC

Validation of the provider is essential.

Why this answer

For inherited controls, the system owner must verify the 'Inheritance Agreement' or the 'Common Control Provider' documentation to ensure the control is actually in place and operating correctly.

19
MCQmedium

You are tailoring controls for a system that does not process PII. Which action should you take regarding the Privacy (PRIV) family controls in the NIST 800-53 catalog?

A.Replace the family with general security controls.
B.Keep the controls but set them to 'manual' mode.
C.Document the removal of the family with a justification.
D.Implement the controls as high-priority items.
AnswerC

Tailoring allows for the removal of non-applicable controls with justification.

Why this answer

If a control or family is not applicable to the system's function, it should be scoped out or documented as not applicable during the tailoring process.

20
MCQeasy

Which document defines the security control baselines (Low, Moderate, High) for federal information systems?

A.NIST SP 800-53B.
B.NIST SP 800-53A.
C.FIPS 199.
D.NIST SP 800-37.
AnswerA

This document specifies the actual control baselines.

Why this answer

NIST SP 800-53B provides the control baselines for the various impact levels.

21
MCQmedium

A control in the NIST 800-53 catalog has a parameter that reads: '[Assignment: organization-defined frequency]'. What is your responsibility as the system owner?

A.Use the default value provided in the appendix.
B.Remove the control since it is not fully defined.
C.Leave the assignment blank.
D.Define the frequency based on organizational policy.
AnswerD

The organization is responsible for filling in the assignment.

Why this answer

Organizations must define the value for the assignment within the bracket to make the control actionable.

22
MCQhard

You are tailoring a baseline and encounter a control marked as 'Not Applicable'. What is the correct documentation approach?

A.Mark the control as 'Implemented' and leave the field blank.
B.Document the removal and the justification in the SSP.
C.Request a waiver from the CISO.
D.Just delete the control from the system security plan (SSP).
AnswerB

Justification is required for all tailoring actions.

Why this answer

When controls are removed from the baseline during tailoring, the justification must be recorded to support auditability.

23
Multi-Selectmedium

Which TWO of the following are valid reasons for tailoring a NIST 800-53 control baseline?

Select 2 answers
A.The control is not applicable to the system's technology.
B.The system environment requires a specific, more rigorous implementation.
C.The control has a high cost of implementation.
D.The control is too difficult to monitor.
E.The system owner disagrees with the FIPS 199 classification.
AnswersA, B

If the control does not apply, it should be removed.

Why this answer

Tailoring is performed to align the baseline with the specific mission and technical needs of the information system.

24
MCQhard

A system owner determines that a specific NIST 800-53 control cannot be implemented due to legacy hardware constraints. They choose to implement a different control to mitigate the same risk. This is an example of what?

A.Risk Acceptance.
B.Baseline Tailoring.
C.Control Supplementation.
D.Compensating Control.
AnswerD

This is the definition of a compensating control.

Why this answer

A compensating control is an alternate measure used to satisfy the requirement of a security control that cannot be implemented as stated.

25
MCQhard

Your organization is applying NIST SP 800-53 controls to a hybrid cloud infrastructure. What is the main purpose of utilizing the 'Control Catalog'?

A.To automate the scanning process.
B.To serve as a comprehensive list of all possible security controls.
C.To mandate the order of implementation.
D.To identify which vendors are compliant.
AnswerB

The catalog provides the full set from which baselines are derived.

Why this answer

The catalog serves as the central repository from which organizations select appropriate controls based on their system-specific security needs.

26
MCQmedium

When selecting controls, you notice that a specific NIST 800-53 control includes 'assignment' statements. What is the purpose of these statements?

A.To define specific parameters for control implementation.
B.To categorize the control by its priority level.
C.To link the control to a regulatory requirement.
D.To assign the control to a specific system administrator.
AnswerA

Assignments allow organizations to define values like 'every 30 days' or 'authorized personnel'.

Why this answer

Assignment statements provide a mechanism to tailor the control by specifying organization-defined values or frequencies.

27
MCQeasy

Which of the following describes a 'Hybrid' control?

A.A control that covers both physical and logical security.
B.A control with shared responsibility between the organization and the system.
C.A control that is always automated.
D.A control that is used in both cloud and on-premise environments.
AnswerB

This defines a hybrid control.

Why this answer

A hybrid control is a control where both the organization (or provider) and the information system share responsibility for implementation.

Ready to test yourself?

Try a timed practice session using only Control Selection questions.