Question 36

Which law was superseded by FISMA?
The law required that systems processing federal data be authorized to process by a management official, and failure to do so will constitutes a violation of a federal directive.
Response:
  • Question 37

    Which NIST SP is a Guide for Conducting.
    Response:
  • Question 38

    The risk transference is referred to the transfer of risks to a third party, usually for a fee, it creates a contractual-relationship for the third party to manage the risk on behalf of the performing organization. Which one of the following is NOT an example of the transference risk response?
    Response:
  • Question 39

    You are the project manager for your company and a new change request has been approved for your project. This change request, however, has introduced several new risks to the project. You have communicated these risk events and the project stakeholders understand the possible effects these risks could have on your project.
    You elect to create a mitigation response for the identified risk events. Where will you record the mitigation response?
    Response:
  • Question 40

    The authorization decision is the explicit responsibility of which organizational Official? Response: