CAP Dumps

CAP Free Practice Test

ISC2 CAP: ISC2 CAP Certified Authorization Professional

QUESTION 11

ISO 17799 has two parts. The first part is an implementation guide with guidelines on how to build a comprehensive information security infrastructure and the second part is an auditing guide based on requirements that must be met for an organization to be deemed compliant with ISO 17799. What are the ISO 17799 domains?
Each correct answer represents a complete solution. Choose all that apply.

Correct Answer: ABCE

QUESTION 12

Shoulder surfing is a type of in-person attack in which the attacker gathers information about the premises of an organization. This attack is often performed by looking surreptitiously at the keyboard of an employee's computer while he is typing in his password at any access point such as a terminal/Web site. Which of the following is violated in a shoulder surfing attack?

Correct Answer: B

QUESTION 13

Which of the following guidance documents is useful in determining the impact level of a particular threat on agency systems?

Correct Answer: C

QUESTION 14

Which one of the following is the only output for the qualitative risk analysis process?

Correct Answer: C

QUESTION 15

You are the project manager for your organization. You have identified a risk event you??re your organization could manage internally or externally. If you manage the event internally it will cost your project $578,000 and an additional $12,000 per month the solution is in use. A vendor can manage the risk event for you. The vendor will charge $550,000 and $14,500 per month that the solution is in use. How many months will you need to use the solution to pay for the internal solution in comparison to the vendor's solution?

Correct Answer: B