Practice CGRC Scope OF System questions with full explanations on every answer.
Start practicing
Scope OF System — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
Which of the following is an example of a 'System Boundary' document that assists with the RMF process?
2A federal agency is using FIPS 199 to categorize a system that processes public health data. The confidentiality impact is Low, integrity is Moderate, and availability is Moderate. What is the overall system categorization?
3When classifying an information system under FIPS 199, which stakeholder should typically sign off on the final categorization?
4When defining the scope of an information system, what is the primary purpose of identifying 'common controls'?
5Your organization is transitioning to a 'System of Systems' architecture. When defining the boundary for one sub-system, what is the best practice to avoid scope creep?
6You are defining the authorization boundary for a cloud-hosted application in the NIST Risk Management Framework. Which component must be explicitly included within the boundary according to NIST SP 800-37?
7You are documenting the system inventory in the Security Assessment Plan (SAP). Which artifact is most effective for demonstrating that all system interconnections have been properly inventoried?
8You have determined that a system's data is publicly available, but the system is responsible for providing critical government services. If the system goes offline, the loss of availability is catastrophic. How should the FIPS 199 categorization be adjusted?
9What is the primary risk of having an inaccurately defined authorization boundary?
10Which NIST publication provides the definitive guidance on FIPS 199 security categorization?
11You are assessing a system that utilizes a shared service for identity management. How should this be reflected in the system's authorization boundary?
12When a system boundary is complex and spans multiple geographic locations, what should the practitioner focus on to ensure security consistency?
13Which document is mandatory to finalize the system categorization and begin the RMF process?
14An Information System Owner (ISO) is deciding whether to include a legacy database within a new application's authorization boundary. What is the deciding factor?
15When defining the system boundary, which TWO of the following factors should be considered? (Select TWO)
16Which THREE of the following are essential components of an effective system inventory for a federal agency? (Select THREE)
17When applying FIPS 199 to an information system, which TWO security objectives must be evaluated for potential impact? (Select TWO)
18Which THREE artifacts are commonly used by the Authorizing Official (AO) to validate the system boundary? (Select THREE)
19Which TWO statements regarding FIPS 199 'High Water Mark' are accurate? (Select TWO)
20In the context of the RMF, which THREE of the following are considered 'Information System' components that contribute to the authorization boundary? (Select THREE)
The Scope OF System domain covers the key concepts tested in this area of the CGRC exam blueprint published by (ISC)². Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all CGRC domains — no account required.
The Courseiva CGRC question bank contains 20 questions in the Scope OF System domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Scope OF System domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included