Certified Authorization Professional (CAP) — Question 4

In 2003, NIST developed a new Certification & Accreditation (C&A) guideline known as FIPS 199.
What levels of potential impact are defined by FIPS 199?
Each correct answer represents a complete solution. Choose all that apply.

Answer options

Correct answer: A, C, D

Explanation

FIPS 199 defines three levels of potential impact: Low, Moderate, and High. The term 'Medium' is not recognized as a distinct category in FIPS 199; thus, only Low, High, and Medium (D) are correct choices, with D being a mislabeling of Moderate.