Question 121

True or False; After an ATO is granted, ongoing continuous monitoring is performed on all identified security controls as well as physical environment, etc..
Response:
  • Question 122

    The overall length of time an information system's components can be in the recovery phase before negatively impacting the organization's mission or mission/business functions.
    Response:
  • Question 123

    An initial remediation action was taken by the information system owner (ISO) based on findings from the security assessment report (SAR). What is the next appropriate step based on the Risk Management Framework (RMF)?
    Response:
  • Question 124

    The Information system owner should strive to test every control at least every ___ years & most critical controls continuously.
    Response:
  • Question 125

    During the assessment of a new system, the ISO mentioned that if unauthorized modification or destruction of medical information in the system occurred, it could result in potential loss of life because the system hosts essential protected health information. Which of the following is the BEST categorization for the information type? Response: