Courseiva

CCNA Scope OF System Questions

20 questions · Scope OF System · All types, answers revealed

1
MCQeasy

What is the primary risk of having an inaccurately defined authorization boundary?

A.Increased cost of hardware procurement.
B.Violation of the System Development Life Cycle (SDLC).
C.Inability to perform annual performance reviews.
D.Unprotected assets or vulnerabilities left outside the scope of assessment.
AnswerD

This is the core risk of scope drift or poor boundary definition.

Why this answer

An inaccurate boundary leads to 'security gaps' where assets go unmonitored or unprotected.

2
MCQmedium

You have determined that a system's data is publicly available, but the system is responsible for providing critical government services. If the system goes offline, the loss of availability is catastrophic. How should the FIPS 199 categorization be adjusted?

A.Exclude the system from FIPS 199 requirements.
B.Categorize only based on Confidentiality.
C.Confidentiality=Low, Integrity=Low, Availability=High.
D.Confidentiality=Low, Integrity=Low, Availability=Low.
AnswerC

High impact on availability drives the system to a High categorization.

Why this answer

Categorization must account for the impact on the organization, regardless of data classification (e.g., public vs. sensitive).

3
MCQhard

Your organization is transitioning to a 'System of Systems' architecture. When defining the boundary for one sub-system, what is the best practice to avoid scope creep?

A.Define the boundary based on the specific services and data flows owned by the sub-system.
B.Include only the database tier.
C.Include the entire enterprise infrastructure to be safe.
D.Include all internal network segments regardless of use.
AnswerA

Focusing on ownership and data flow control keeps the authorization boundary precise.

Why this answer

Clearly defining trust zones and interface points prevents the boundary from expanding unnecessarily.

4
MCQhard

You are assessing a system that utilizes a shared service for identity management. How should this be reflected in the system's authorization boundary?

A.Force the service provider to sign a full system authorization for you.
B.List the identity service as an external provider and inherit the controls.
C.The identity service must be fully assessed as part of your system.
D.Exclude the identity service from the documentation entirely.
AnswerB

Inheritance is the correct mechanism for shared services in RMF.

Why this answer

When using shared services, the system owner documents the inheritance of controls from the shared service provider.

5
Multi-Selectmedium

In the context of the RMF, which THREE of the following are considered 'Information System' components that contribute to the authorization boundary? (Select THREE)

Select 3 answers
A.Administrative personnel managing the system.
B.The local library book catalog.
C.Operating systems.
D.Physical security guards at the facility gate.
E.The public social media feed of the organization.
AnswersA, C, D

People, processes, and technology are all part of the information system definition.

Why this answer

An information system is a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.

6
Multi-Selectmedium

Which THREE artifacts are commonly used by the Authorizing Official (AO) to validate the system boundary? (Select THREE)

Select 3 answers
A.The janitorial service contract for the building.
B.Network architecture diagrams.
C.Data flow diagrams illustrating external interfaces.
D.System Security Plan (SSP) boundary description.
E.The organization's holiday schedule.
AnswersB, C, D

Diagrams provide the visual scope of the boundary.

Why this answer

The AO needs visual, written, and logical proof of what they are authorizing.

7
MCQmedium

A federal agency is using FIPS 199 to categorize a system that processes public health data. The confidentiality impact is Low, integrity is Moderate, and availability is Moderate. What is the overall system categorization?

A.Not Categorized
B.Low
C.High
D.Moderate
AnswerD

The highest value among Low, Moderate, and Moderate is Moderate.

Why this answer

FIPS 199 defines the high-water mark based on the highest value among the three security objectives.

8
MCQhard

When a system boundary is complex and spans multiple geographic locations, what should the practitioner focus on to ensure security consistency?

A.Categorizing each site as a separate information system.
B.Excluding remote offices from the authorization boundary.
C.Allowing each site to define its own unique security policy.
D.Implementing consistent security controls across all boundary nodes regardless of location.
AnswerD

Consistent application of controls is essential for multi-site systems.

Why this answer

Centralizing the security management and standardizing controls across locations ensures uniform protection.

9
MCQmedium

When classifying an information system under FIPS 199, which stakeholder should typically sign off on the final categorization?

A.The Lead System Administrator.
B.The Information System Owner (ISO).
C.The Chief Information Security Officer (CISO).
D.The Third-Party Auditor.
AnswerB

The ISO is the accountable party for the system categorization.

Why this answer

The Information System Owner (ISO) is responsible for the categorization, which is then approved by the Authorizing Official (AO).

10
MCQhard

You are documenting the system inventory in the Security Assessment Plan (SAP). Which artifact is most effective for demonstrating that all system interconnections have been properly inventoried?

A.The system's latest vulnerability scan report.
B.A comprehensive network topology diagram showing external service endpoints.
C.The organization's enterprise risk register.
D.A listing of all installed software patches.
AnswerB

A topology diagram is the primary artifact for visualizing and validating the system boundary.

Why this answer

A System Interconnection Agreement (SIA) or Data Use Agreement (DUA) provides the formal record of cross-boundary data flows.

11
MCQeasy

Which NIST publication provides the definitive guidance on FIPS 199 security categorization?

A.NIST SP 800-37.
B.NIST SP 800-60.
C.NIST SP 800-53.
D.FIPS 140-3.
AnswerB

SP 800-60 specifically addresses the categorization of information systems.

Why this answer

NIST SP 800-60 is the guide for mapping information types to FIPS 199 security objectives.

12
Multi-Selectmedium

When defining the system boundary, which TWO of the following factors should be considered? (Select TWO)

Select 2 answers
A.The information types processed, stored, or transmitted by the system.
B.The organizational personnel who have access to the system.
C.The fiscal budget allocated for hardware replacement.
D.The interconnections with other internal and external systems.
E.The physical location of the cloud data center.
AnswersA, D

Information types are critical to defining the system's scope and FIPS 199 impact.

Why this answer

Defining the boundary requires understanding the system's operational scope, its connection points, and its data ownership.

13
MCQeasy

When defining the scope of an information system, what is the primary purpose of identifying 'common controls'?

A.To ensure they are manually tested for every individual system.
B.To increase the system's FIPS 199 impact level.
C.To identify controls that are implemented once and applied to multiple systems.
D.To exclude them from the System Security Plan (SSP).
AnswerC

Efficiency in control implementation is a primary goal of common control identification.

Why this answer

Common controls are inherited from the organization or another system, reducing the burden on the individual system owner.

14
Multi-Selecthard

Which THREE of the following are essential components of an effective system inventory for a federal agency? (Select THREE)

Select 3 answers
A.System interconnections and data flow paths.
B.Hardware serial numbers and physical asset tags.
C.The employee performance evaluation score for the system admin.
D.The exact date of the last office coffee machine maintenance.
E.Software versions and patch levels.
AnswersA, B, E

Tracking how the system connects is vital for boundary management.

Why this answer

An inventory must track hardware, software, and operational connections to be useful for risk management.

15
Multi-Selecthard

Which TWO statements regarding FIPS 199 'High Water Mark' are accurate? (Select TWO)

Select 2 answers
A.The overall system categorization is the highest of the three individual security objectives.
B.The high water mark only applies to federal systems with 'High' impact data.
C.Categorization must be performed by averaging the impact scores.
D.The high water mark is only determined by availability.
E.The high water mark must be applied to all security controls within the boundary.
AnswersA, E

This is the definition of the high water mark principle.

Why this answer

The high water mark ensures that the entire system is protected at the level of its most sensitive component.

16
MCQeasy

Which of the following is an example of a 'System Boundary' document that assists with the RMF process?

A.The System Security Plan (SSP) boundary description.
B.The Annual Security Awareness Training log.
C.The Privacy Threshold Analysis (PTA).
D.The System Development Life Cycle (SDLC) policy.
AnswerA

The SSP is the authoritative source for the security boundary.

Why this answer

A boundary diagram or description is required for the System Security Plan to define what is subject to assessment.

17
MCQmedium

An Information System Owner (ISO) is deciding whether to include a legacy database within a new application's authorization boundary. What is the deciding factor?

A.The dependency of the system on the database for operational integrity.
B.Whether the database is hosted in the same physical rack.
C.The age of the hardware.
D.The amount of data stored.
AnswerA

Operational and security dependencies define the boundary.

Why this answer

If the new application relies on the database for security or operational functionality, it must be included.

18
MCQmedium

Which document is mandatory to finalize the system categorization and begin the RMF process?

A.The Incident Response Policy.
B.The Penetration Test Report.
C.The FIPS 199 Security Categorization document.
D.The Contingency Plan.
AnswerC

Categorization is the foundational step in NIST SP 800-60/800-53.

Why this answer

The FIPS 199 Categorization document (or the categorization section of the SSP) is required to select appropriate security controls.

19
Multi-Selecteasy

When applying FIPS 199 to an information system, which TWO security objectives must be evaluated for potential impact? (Select TWO)

Select 2 answers
A.Availability.
B.Authentication.
C.Accountability.
D.Non-repudiation.
E.Confidentiality.
AnswersA, E

Availability is a core FIPS 199 objective.

Why this answer

FIPS 199 defines three objectives: Confidentiality, Integrity, and Availability. You are selecting two from this list.

20
MCQeasy

You are defining the authorization boundary for a cloud-hosted application in the NIST Risk Management Framework. Which component must be explicitly included within the boundary according to NIST SP 800-37?

A.The cloud service provider's physical security controls for the hosting data center.
B.The end-user's local home router configuration.
C.The public internet backbone routing protocols.
D.The organization's global human resources policy.
AnswerA

The authorization boundary encompasses the service environment providing the security controls.

Why this answer

The authorization boundary must include all components for which the authorizing official accepts risk, including third-party cloud services that manage the security controls.

Ready to test yourself?

Try a timed practice session using only Scope OF System questions.