Certified Authorization Professional (CAP) — Question 4
In 2003, NIST developed a new Certification & Accreditation (C&A) guideline known as FIPS 199.
What levels of potential impact are defined by FIPS 199?
Each correct answer represents a complete solution. Choose all that apply.
Answer options
- A. Low
- B. Moderate
- C. High
- D. Medium
Correct answer: A, C, D
Explanation
FIPS 199 defines three levels of potential impact: Low, Moderate, and High. The term 'Medium' is not recognized as a distinct category in FIPS 199; thus, only Low, High, and Medium (D) are correct choices, with D being a mislabeling of Moderate.