SFPC EXAM WITH QUESTIONS AND WELL-
VERIFIED ANSWERS|| ALREADY GRADED A+ |
GUARANTEED PASS | BEST VERSION
To provide access to Social Media sites, the DoD agency must provide all of the
following, EXCEPT:
- Protection against malware and advance threats.
- Blocked access to prohibited sites and content.
- Individual compliance with Joint Ethics Regulations and guidelines.
- Constant monitoring to deter inappropriate site access. - ANSWER-D
Whose responsibility is it during the categorized steps to identify a potential impact (low, moderate, or high) due to loss of confidentiality, integrity, and availability if a security breach occurs? **
- Information System Owner (ISO)
- Information Owner (IO)
- Information System Security Manager (ISSM)
- Authorizing Official (AO) - ANSWER-B
Please determine which of the following is an example of reportable foreign intelligence contacts, activities, indicators, and behaviors.
- Authorizing others to acquire unauthorized access to classified or sensitive
- Unauthorized downloads or uploads of sensitive data. 1 / 4
information systems.
- Network spillage incidents or information compromise.
- Use of DoD account credentials by unauthorized parties. - ANSWER-A
Limiting nonsecure computer e-mail messages to nonmilitary activities and not providing operational information in nonsecure e-mail messages are functions of which OPSEC measure?
- Operational and Logistic Measures
- Technical Measures
- Administrative Measures
- Operations Security and Military Deception - ANSWER-B
Which of the following is NOT a category of Information Technology (IT)? **?
- Platform Information Technology (PIT)
- Information Technology Services
- Information Technology Products
- Information Technology Applications - ANSWER-D
What step within the Risk Management Framework (RMF) does system categorization occur? **
- Categorize Information System
- Select Security Controls
- Implement Security Controls
- Assess Security Controls
- Authorize
- Monitor Security Controls - ANSWER-A
- / 4
At what step of the Risk Management Framework (RMF) would you develop a system-level continuous monitoring strategy?" **
- Categorize Information System
- Select Security Controls
- Implement Security Controls
- Assess Security Controls
- Authorize
- Monitor Security Controls - ANSWER-B
One responsibility of the Information System Security Manager (ISSM) during
Step 6 of the Risk Management Framework (RMF) is:**
- Review and approve the security plan and system-level continuous monitoring
- Monitor the system for security relevant events and configuration changes that
- Determine and documents a risk level in the Security Assessment Report (SAR)
- Coordinate the organization of the Information System (IS) and Platform
strategy developed and implemented by the DoD Components.
affect the security posture negatively.
for every non-compliant security control in the system baseline.
Information Technology (PIT) systems with the Program Manager (PM)/System Manager (SM), Information System Owner (ISO), Information Owner (IO), mission owner(s), Action Officer (AO) or their designated representatives. -
ANSWER-B
What is the role of the government contracting activity (GCA), or cleared prime contractor, when a contractor that does not have a Facility Clearance (FCL) wants to bid on a Request?for Proposal (RFP) that requires access to classified information? a. The GCA must issue a formal letter rejecting the contractor's bid since the contractor does not have the requisite FCL. 3 / 4
- The contractor must submit a sponsorship request to DSS, who will decide
- The GCA must sponsor the contractor for a facility security clearance by
- The GCA must ensure that the all owners and senior management of the
whether to allow the contractor to bid on the contract.
submitting a sponsorship request to DSS, which initiates the facility clearance process.
uncleared contractor are U.S. citizens and are eligible to be processed for a personnel security clearance. - ANSWER-C
What is the purpose of the Federal Acquisition Regulations (FAR)?
- To codify and publish uniform policies and procedures for acquisition by all
- To manage DoD funds and prioritize the development of vital research and
- To provide small businesses and minority owned companies an opportunity to
- To promote uniform standards and best practices of technology acquisition
executive agencies.
technology.
compete in the government acquisition process.
across U.S. industry. - ANSWER-A
What is the role of the security professional during the "Award Contract" step of the contracting process?
- To ensure the appropriate classification level for the bid, and to define unique
- To interface with the Cognizant Security Organization (CSO) to ensure
- To ensure that the contractor follows proper safeguarding and disposition
- To review and define the specific security requirements with the contracting
- / 4
security requirements associated with the product.
oversight is performed and review results of and previous assessments on behalf of component.
guidance.
officer - specifically, block 13 of DD Form 254. - ANSWER-D