Courseiva

(ISC)2 Certified in Governance, Risk and Compliance (CGRC) (CGRC) (CGRC) — Questions 175

199 questions total · 3pages · All types, answers revealed

Page 1 of 3

Page 2
1
Multi-Selecteasy

When structuring a GRC program, which THREE components are critical for compliance management?

Select 3 answers
A.Centralized Policy Management library.
B.Comprehensive Control Library for mapping.
C.A feature to change the font of the system interface.
D.A marketing tool for company social events.
E.Audit and Issue tracking workflows.
AnswersA, B, E

Policies provide the basis for compliance.

Why this answer

Policy management, control libraries, and audit tracking are core components of any compliance framework.

2
MCQeasy

What is the primary risk of having an inaccurately defined authorization boundary?

A.Increased cost of hardware procurement.
B.Violation of the System Development Life Cycle (SDLC).
C.Inability to perform annual performance reviews.
D.Unprotected assets or vulnerabilities left outside the scope of assessment.
AnswerD

This is the core risk of scope drift or poor boundary definition.

Why this answer

An inaccurate boundary leads to 'security gaps' where assets go unmonitored or unprotected.

3
MCQeasy

What is the primary function of an assessor's 'working papers'?

A.To list the audit team members
B.To document evidence and support the findings
C.To submit to the regulator
D.To replace the need for an audit
AnswerB

They provide traceability for audit conclusions.

Why this answer

Working papers document the evidence gathered, testing performed, and observations made, which serve as the foundation for the final assessment report.

4
MCQhard

During a routine audit of a federal system's continuous monitoring program, the auditor finds that the 'Security Control Assessment' results are three years old. What is the non-compliance violation?

A.Failure to perform annual control testing as part of continuous monitoring.
B.The organization failed to report the breach to the US-CERT.
C.The system failed to undergo a full re-accreditation.
D.The System Security Plan (SSP) was not updated in the FISMA database.
AnswerA

Ongoing authorization relies on periodic testing to ensure controls remain effective over time.

Why this answer

NIST SP 800-37 R2 requires that security controls are monitored and assessed frequently enough to maintain an ongoing authorization.

5
MCQhard

During an audit of an IAM system, the auditor notices that inactive accounts are not being disabled. Which control is failing?

A.Audit log retention
B.Account management lifecycle
C.Role-based access control
D.Multi-factor authentication
AnswerB

Lifecycle includes onboarding, maintenance, and offboarding/disabling.

Why this answer

Disabled account management is a critical detective and preventive control to ensure that only authorized, active users have access.

6
MCQmedium

When a system is undergoing a major change, what is the impact on the existing ATO?

A.The ATO is suspended until the next fiscal year
B.The ATO must be re-evaluated
C.The ATO remains valid until the expiration date
D.The ATO is automatically extended
AnswerB

Major changes trigger a re-authorization process.

Why this answer

A major change invalidates the existing ATO because the security posture has fundamentally changed, requiring a re-assessment.

7
MCQhard

To ensure that GRC controls remain effective, the organization requires a 'Control Self-Assessment' (CSA) workflow that triggers automatically based on control criticality. Which setting should be modified?

A.Change the global password policy for GRC users.
B.Adjust the 'Assessment Trigger' logic based on the 'Criticality' score.
C.Require the GRC admin to manually assign tasks to users.
D.Disable the self-assessment feature to force all audits to be external.
AnswerB

This maps the frequency of assessment to the risk profile of the control.

Why this answer

Linking a workflow trigger to a 'Control Criticality' attribute ensures that high-impact controls are assessed more frequently.

8
MCQeasy

You are setting up an IDS/IPS (e.g., Snort). Where should you place the sensor to monitor both internal and external traffic?

A.Directly on the public ISP router
B.Inside the isolated guest Wi-Fi network
C.On a Span Port of the core distribution switch
D.On the WAN interface of the firewall
AnswerC

This allows monitoring of internal and external traffic flows.

Why this answer

Placing the sensor on the span port of the core switch allows visibility into internal traffic flows.

9
MCQhard

You are configuring a 'Risk Appetite Statement'. The requirement is that any risk score exceeding the appetite must automatically trigger a 'Risk Treatment Plan' workflow. What needs to be configured?

A.A manual email notification from the risk owner to the CISO.
B.An automated 'Workflow Trigger' based on a 'Risk Scoring' threshold.
C.A change in the risk rating calculation formula.
D.A daily report showing all risks over the appetite.
AnswerB

This ensures consistent enforcement of risk appetite.

Why this answer

A 'Business Rule' or 'Workflow Trigger' that monitors the 'Residual Risk' field against the 'Appetite' threshold is required.

10
MCQmedium

You are configuring a SIEM (e.g., Splunk) for continuous monitoring. You need to alert when a firewall configuration changes. What is the most important log source for this requirement?

A.Domain controller event logs.
B.Firewall audit/management logs.
C.DHCP server logs.
D.Endpoint antivirus logs.
AnswerB

These logs specifically record who made changes to the security ruleset.

Why this answer

Firewall configuration logs provide the audit trail necessary to detect changes to security policy parameters.

11
MCQeasy

What is the purpose of the Security Assessment Report (SAR)?

A.To provide a snapshot of the control implementation effectiveness
B.To request funding for security improvements
C.To authorize the system for production
D.To list all authorized users
AnswerA

It summarizes the assessment findings.

Why this answer

The SAR documents the results of the control assessment, including findings and recommendations.

12
MCQeasy

Which role is typically responsible for defining the 'Risk Appetite' within a GRC governance framework?

A.The IT Operations Manager.
B.The Executive Steering Committee.
C.The GRC System Administrator.
D.The Internal Audit Manager.
AnswerB

Governance frameworks dictate that senior leadership sets the appetite.

Why this answer

Governance is a top-down function, and the Board or Executive Steering Committee defines risk appetite.

13
MCQeasy

An organization is integrating its GRC platform with an existing Active Directory infrastructure. To enforce the Principle of Least Privilege for internal auditors, which configuration step should be prioritized?

A.Map Active Directory groups to granular GRC Security Profiles.
B.Assign Global Administrator rights to the lead auditor.
C.Enable Single Sign-On (SSO) for all users globally.
D.Configure a shared service account for all audit activities.
AnswerA

This is the correct method to restrict access to specific evidence and assessment data.

Why this answer

Mapping specific Active Directory groups to GRC-defined 'Role-Based Access Control' (RBAC) profiles ensures that auditor access is limited to read-only views of evidence repositories.

14
MCQhard

During a control audit, you find that the organization has documented a 'common control' for password complexity. What does this imply for individual systems?

A.Individual systems must override the common control.
B.Common controls cannot be used for password complexity.
C.Individual systems must report their own password status.
D.Individual systems do not need to address password complexity.
AnswerD

Inheritance means the control is satisfied at the enterprise level.

Why this answer

Common controls are controls provided by the infrastructure or enterprise that individual information systems inherit, reducing the burden on system owners.

15
MCQhard

You are auditing an organization's POA&M process. Which of the following indicates an ineffective process?

A.The POA&M contains vulnerabilities found by automated scans
B.The POA&M lists items with no completion dates
C.The POA&M is stored in a secure repository
D.The POA&M is reviewed by the CISO
AnswerB

This prevents tracking and accountability.

Why this answer

POA&Ms must include completion dates. Without them, there is no accountability for remediation.

16
MCQmedium

You have determined that a system's data is publicly available, but the system is responsible for providing critical government services. If the system goes offline, the loss of availability is catastrophic. How should the FIPS 199 categorization be adjusted?

A.Exclude the system from FIPS 199 requirements.
B.Categorize only based on Confidentiality.
C.Confidentiality=Low, Integrity=Low, Availability=High.
D.Confidentiality=Low, Integrity=Low, Availability=Low.
AnswerC

High impact on availability drives the system to a High categorization.

Why this answer

Categorization must account for the impact on the organization, regardless of data classification (e.g., public vs. sensitive).

17
Multi-Selecthard

Which THREE of the following are necessary to establish a 'Continuous Control Monitoring' (CCM) program?

Select 3 answers
A.Automated notification workflows for failed controls.
B.A physical audit team performing site visits daily.
C.Defined thresholds for 'Pass' or 'Fail' conditions.
D.Automated data extraction from IT assets.
E.A manual spreadsheet that is updated every quarter.
AnswersA, C, D

Notifications ensure timely remediation of failures.

Why this answer

CCM requires automated data feeds, defined thresholds, and notification mechanisms to be effective.

18
MCQeasy

Which type of control is an alarm system installed in a server room?

A.Preventative
B.Detective
C.Corrective
D.Deterrent
AnswerB

Detective controls trigger an alert upon detection of an event.

Why this answer

An alarm system is a detective control designed to alert staff of unauthorized presence.

19
MCQeasy

Which role is responsible for the ongoing monitoring of security controls after an ATO is granted?

A.Authorizing Official
B.Chief Information Security Officer (CISO)
C.Security Control Assessor (SCA)
D.Information System Security Officer (ISSO)
AnswerD

The ISSO performs the continuous monitoring tasks.

Why this answer

The ISSO is responsible for the day-to-day management and monitoring of the security controls.

20
MCQhard

The organization's GRC workflow has a 'Request for Exception' process. The goal is to ensure that temporary risk exceptions are automatically reviewed before they expire. Which mechanism is most appropriate?

A.Configuring a 'Workflow Notification' triggered by a field-based 'Expiration Date'.
B.Requiring the Risk Owner to sign a hard copy document.
C.Disallowing all risk exceptions in the system configuration.
D.Setting a manual reminder on the CISO's calendar.
AnswerA

This leverages system automation to ensure timely oversight of risks.

Why this answer

Automated workflow notifications tied to the 'Expiration Date' field ensure that exceptions do not remain active indefinitely without review.

21
Multi-Selectmedium

Which TWO of the following represent best practices for password management?

Select 2 answers
A.Forcing users to change passwords every 30 days
B.Using a password manager for unique, complex passwords
C.Allowing password sharing among team members
D.Logging passwords in a shared spreadsheet
E.Enforcing a minimum length requirement
AnswersB, E

Password managers facilitate the use of strong, unique credentials.

Why this answer

Complex, unique passwords and the use of a password manager are foundational security practices.

22
MCQhard

Your organization is transitioning to a 'System of Systems' architecture. When defining the boundary for one sub-system, what is the best practice to avoid scope creep?

A.Define the boundary based on the specific services and data flows owned by the sub-system.
B.Include only the database tier.
C.Include the entire enterprise infrastructure to be safe.
D.Include all internal network segments regardless of use.
AnswerA

Focusing on ownership and data flow control keeps the authorization boundary precise.

Why this answer

Clearly defining trust zones and interface points prevents the boundary from expanding unnecessarily.

23
MCQhard

The organization has adopted a 'Defense-in-Depth' strategy. You are tasked with mapping controls to the NIST CSF framework within the GRC tool. What is the most effective way to manage the relationship between framework sub-categories and existing internal controls?

A.Rename all internal controls to match the NIST sub-category names.
B.Create separate GRC instances for every framework adopted.
C.Use 'Control Mapping' functionality to link internal controls to NIST sub-categories.
D.Hard-code the NIST framework into the GRC platform source code.
AnswerC

This provides the necessary traceability for compliance reporting.

Why this answer

The 'Many-to-Many' mapping methodology is the industry standard for reconciling internal controls with external frameworks like NIST CSF.

24
Multi-Selectmedium

Which TWO of the following should be considered when selecting a GRC platform for an enterprise-wide program?

Select 2 answers
A.The vendor's ability to provide free hardware for testing.
B.The physical location of the vendor's headquarters.
C.Scalability of the platform to handle increasing data volumes.
D.Ability to integrate with existing IT and security infrastructure.
E.The complexity of the vendor's logo design.
AnswersC, D

Enterprise programs grow in scope and data load over time.

Why this answer

Integration capabilities and scalability are vital for enterprise deployments.

25
MCQeasy

What document provides the most granular guidance on tailoring security controls for federal systems?

A.FIPS 200.
B.NIST SP 800-37.
C.CNSSI 1253.
D.NIST SP 800-53.
AnswerD

It contains the specific guidance for control selection and tailoring.

Why this answer

NIST SP 800-53, specifically the tailoring guidance section, provides the framework for modifying baselines.

26
MCQhard

An organization is applying NIST SP 800-53 Rev. 5 controls to a cloud-based SaaS application. The authorization official requests that you perform 'supplementing' during the tailoring process. What is the correct action?

A.Replace a control with a vendor-provided security feature.
B.Add additional controls to the baseline to address specific threat vectors.
C.Remove controls from the baseline that are technically infeasible.
D.Adjust the parameters of existing controls to lower operational impact.
AnswerB

Supplementing specifically refers to the addition of controls.

Why this answer

Supplementing is the process of adding controls to a baseline to address specific mission or business requirements that are not covered by the standard baseline.

27
Multi-Selectmedium

Which TWO of the following are critical requirements for implementing an effective patch management program?

Select 2 answers
A.Storing all patch files on a public FTP site
B.Automated patch testing in a staging environment
C.Manual approval for every single update
D.Disabling all automatic updates
E.Defined emergency patch procedures
AnswersB, E

Testing is essential to ensure patches don't break functionality.

Why this answer

Patch management requires testing to prevent outages and a deployment strategy to ensure coverage.

28
Multi-Selecteasy

Which THREE activities are part of the 'Assessment Execution' phase?

Select 3 answers
A.Developing the final risk strategy
B.Purchasing new hardware
C.Reviewing system documentation
D.Testing system configuration
E.Interviewing key personnel
AnswersC, D, E

Method of assessment.

Why this answer

Execution involves interviewing staff, reviewing documentation, and testing technical configuration settings.

29
Multi-Selecteasy

Which TWO of the following are examples of administrative security controls?

Select 2 answers
A.Firewall configuration
B.Data classification policy
C.Security awareness training
D.Biometric locks
E.Intrusion detection systems
AnswersB, C

Policy creation is an administrative task.

Why this answer

Administrative controls are 'soft' controls involving policy and management, whereas technical controls are 'hard' controls.

30
MCQhard

You are assessing a system that utilizes a shared service for identity management. How should this be reflected in the system's authorization boundary?

A.Force the service provider to sign a full system authorization for you.
B.List the identity service as an external provider and inherit the controls.
C.The identity service must be fully assessed as part of your system.
D.Exclude the identity service from the documentation entirely.
AnswerB

Inheritance is the correct mechanism for shared services in RMF.

Why this answer

When using shared services, the system owner documents the inheritance of controls from the shared service provider.

31
Multi-Selectmedium

Which THREE types of findings might appear in an audit report?

Select 3 answers
A.Employee performance pay
B.Operational observations
C.Documentation deficiencies
D.Critical vulnerabilities
E.Office furniture inventory
AnswersB, C, D

Informational findings.

Why this answer

Findings range from critical (immediate risk), to moderate (needs attention), to minor (observational), all of which appear in the report.

32
Multi-Selectmedium

Which TWO factors contribute to the 'scope' of an information security audit?

Select 2 answers
A.External stock prices
B.Competitor market analysis
C.Network boundaries
D.Employee home addresses
E.System components and assets
AnswersC, E

Defines where the audit stops.

Why this answer

The audit scope is driven by the physical and logical boundaries of the system being reviewed.

33
Multi-Selecthard

Which THREE of the following items should be evaluated when performing a security impact analysis for a proposed system change?

Select 3 answers
A.Whether the change negatively impacts existing security controls.
B.The expected cost savings from the change.
C.The color scheme of the new user interface.
D.Whether additional testing or assessment is required.
E.Whether the system's risk rating will increase.
AnswersA, D, E

Assessing the impact on existing controls is the core of the analysis.

Why this answer

The change's impact on security controls, the risk level of the system, and the requirement for re-testing are critical evaluation points.

34
MCQmedium

A cloud environment uses AWS Config to maintain compliance. You need to ensure that all S3 buckets are private. Which AWS Config feature should you configure to automatically remediate non-compliant buckets?

A.AWS Config Remediation Actions.
B.AWS CloudTrail Event Selectors.
C.AWS Config Aggregators.
D.AWS Config Conformance Packs.
AnswerA

Remediation actions allow the execution of Systems Manager documents to fix non-compliant configurations.

Why this answer

AWS Config Rules combined with Systems Manager Automation documents allow for automated remediation of non-compliant resources.

35
Multi-Selecthard

Which THREE of the following are valid methods of verifying that security controls are functioning as intended during continuous monitoring?

Select 3 answers
A.Running automated configuration compliance scans.
B.Interviewing the system users about their productivity.
C.Reviewing system and audit logs.
D.Asking the vendor if the product is secure.
E.Performing physical inspections of the server room.
AnswersA, C, E

Scanning provides objective evidence of the current configuration state.

Why this answer

Validation can occur through automated scans, manual audit/inspection, and the review of system logs.

36
MCQmedium

You are configuring a Linux firewall using 'iptables'. Which chain should you use to filter traffic destined for the local host?

A.OUTPUT
B.INPUT
C.FORWARD
D.PREROUTING
AnswerB

The INPUT chain processes traffic intended for the local socket.

Why this answer

The INPUT chain handles traffic that is addressed to the host machine itself.

37
Multi-Selectmedium

In the context of the RMF, which THREE of the following are considered 'Information System' components that contribute to the authorization boundary? (Select THREE)

Select 3 answers
A.Administrative personnel managing the system.
B.The local library book catalog.
C.Operating systems.
D.Physical security guards at the facility gate.
E.The public social media feed of the organization.
AnswersA, C, D

People, processes, and technology are all part of the information system definition.

Why this answer

An information system is a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.

38
MCQeasy

When establishing a GRC program structure, what is the primary purpose of defining a 'System of Record'?

A.To allow every department to have its own data repository.
B.To minimize the cost of software licenses.
C.To make the GRC platform run faster.
D.To provide a 'Single Source of Truth' for audit and compliance data.
AnswerD

This is the fundamental goal of integrating GRC into one system.

Why this answer

Defining a single 'System of Record' ensures 'Single Source of Truth' for audit and risk reporting.

39
MCQmedium

The GRC program requires that all policies are reviewed annually. What is the most effective way to enforce this within the GRC platform?

A.Block access to the policy after 365 days.
B.Set an 'Expiration Date' and 'Workflow Reminder' on the policy record.
C.Create a recurring meeting for the policy owner.
D.Require the administrator to manually reset the policy status.
AnswerB

System-based reminders ensure adherence to the schedule.

Why this answer

Setting a 'Review Date' field and using 'Workflow Reminders' automates the annual policy lifecycle.

40
MCQmedium

You are auditing a backup solution. Which metric is most critical for the Availability audit?

A.Encryption key rotation
B.Tape rotation schedule
C.Backup storage capacity
D.Recovery Time Objective (RTO)
AnswerD

RTO measures availability requirements.

Why this answer

Recovery Time Objective (RTO) dictates how quickly a system must be available after an outage, which is the primary metric for availability testing.

41
MCQhard

You are assessing an organization's compliance with SOC 2. The auditor requests evidence of 'Trust Services Criteria'. Which evidence is most relevant for the Availability criterion?

A.Privacy policy publication
B.Encryption of data at rest
C.Disaster recovery plan test results
D.User access review logs
AnswerC

DR tests demonstrate that systems can be recovered.

Why this answer

Availability requires that systems be available for operation as agreed. Business continuity and disaster recovery testing provide evidence of this.

42
MCQhard

An organization is transitioning from a siloed risk management approach to an integrated GRC program. During the initial implementation, data inconsistency between the Risk Register and the Compliance Control library is observed. Which action best facilitates 'Common Control Framework' (CCF) mapping?

A.Create manual spreadsheets to reconcile the data outside the GRC platform.
B.Force all business units to use identical risk taxonomy naming conventions.
C.Disable the Regulatory Requirement module to focus only on Risks.
D.Implement a 'Many-to-Many' relationship mapping between Controls and Regulatory Requirements.
AnswerD

This is the standard architectural approach to CCF implementation in GRC systems.

Why this answer

CCF mapping involves linking a single control implementation to multiple regulatory requirements to reduce testing burden.

43
MCQeasy

What is the primary function of a Security Content Automation Protocol (SCAP) tool in a continuous monitoring program?

A.To provide encrypted tunnels for administrative access.
B.To monitor network traffic for anomalous behavior.
C.To automate the assessment of security configurations against benchmarks.
D.To manage the lifecycle of cryptographic keys.
AnswerC

SCAP is designed to enable automated vulnerability and configuration compliance checking.

Why this answer

SCAP provides a standardized way to automate the assessment of system security configurations against established benchmarks.

44
Multi-Selectmedium

Which THREE artifacts are commonly used by the Authorizing Official (AO) to validate the system boundary? (Select THREE)

Select 3 answers
A.The janitorial service contract for the building.
B.Network architecture diagrams.
C.Data flow diagrams illustrating external interfaces.
D.System Security Plan (SSP) boundary description.
E.The organization's holiday schedule.
AnswersB, C, D

Diagrams provide the visual scope of the boundary.

Why this answer

The AO needs visual, written, and logical proof of what they are authorizing.

45
MCQmedium

When conducting an audit, what is 'sampling'?

A.Randomly selecting records without criteria
B.Testing only the most recent data
C.Testing every single record in a database
D.Selecting a representative subset for testing
AnswerD

Sampling makes auditing scalable.

Why this answer

Sampling is the process of selecting a subset of data (e.g., user accounts) to represent the entire population to make an inference about the effectiveness of a control.

46
Multi-Selecthard

Which THREE actions are essential to correctly manage assignments in NIST 800-53 controls?

Select 3 answers
A.Updating all assignment values daily.
B.Ensuring the assignment value is consistent with organizational policy.
C.Consulting with the NIST publication author.
D.Verifying the assignment is addressed by the control implementation.
E.Defining the assignment value in the system security plan.
AnswersB, D, E

Consistency with policy is required for compliance.

Why this answer

Effective management of assignments ensures that controls are tailored and that the organization has a clear record of its security obligations.

47
MCQeasy

Which phase of the RMF includes the 'continuous monitoring' of security controls?

A.Monitor
B.Authorize
C.Select
D.Categorize
AnswerA

This is where continuous monitoring occurs.

Why this answer

The 'Monitor' step is the final phase of the RMF, focused on ongoing compliance.

48
MCQeasy

In the context of configuration management for compliance, what is the primary purpose of a Configuration Baseline?

A.To automate the deployment of new software patches.
B.To document the approved security configuration of a system.
C.To identify all users with administrative privileges.
D.To serve as a temporary backup for system files.
AnswerB

The baseline defines the standard, secure configuration that is periodically verified.

Why this answer

A baseline provides a documented, approved state of a system that serves as a reference point for future changes.

49
MCQhard

Which technique is best to detect 'false negatives' during a security control assessment?

A.Reviewing security log correlation
B.Interviewing developers
C.Checking server physical locks
D.Single tool vulnerability scanning
AnswerA

Cross-log analysis reveals missed threats.

Why this answer

Correlation of logs from multiple sources (e.g., firewall, IPS, host logs) allows an auditor to see if a threat was missed by a single control.

50
MCQhard

The GRC team has determined that 'Residual Risk' is being calculated incorrectly because the 'Control Effectiveness' score is not reflecting the latest audit results. Which architectural fix is required?

A.Update the manual risk assessment survey annually.
B.Configure a 'Dynamic Link' between Audit Testing Results and Risk Rating calculations.
C.Increase the frequency of full organizational risk assessments.
D.Require the CISO to manually approve all risk score changes.
AnswerB

Automating the data flow between audit results and risk scoring is the best practice for accurate residual risk calculation.

Why this answer

The calculation engine must be linked to the latest audit evidence object to dynamically update the risk residual score.

51
MCQeasy

Which administrative control is essential before deploying a new security tool to production?

A.Sharing administrator credentials
B.Disabling internal auditing
C.Immediate deployment to production
D.Change management approval
AnswerD

Change management ensures stability and accountability.

Why this answer

A formal change control process is required to ensure that changes are tested, documented, and approved.

52
Multi-Selectmedium

Which THREE elements are necessary for a compliant continuous monitoring program?

Select 3 answers
A.Configuration management of the system
B.Regular assessment of security controls
C.Full system replacement every year
D.Status reporting to the AO
E.Daily physical site visits
AnswersA, B, D

Ensures changes are tracked.

Why this answer

Continuous monitoring requires regular assessment, tracking of changes, and reporting of the security posture.

53
MCQhard

During an assessment, you identify that an organization is not logging administrative access. What is the most appropriate recommendation in the final report?

A.Increase complexity of passwords
B.Change the audit team
C.Configure audit logging for administrative actions
D.Remove administrative access
AnswerC

This addresses the specific control gap.

Why this answer

A clear, actionable recommendation would be to implement and configure centralized logging (like Syslog or SIEM) for all administrative accounts.

54
MCQmedium

An Authorizing Official grants an 'ATO with Conditions.' What does this mean for the system owner?

A.The system is unauthorized for production use
B.The system is prohibited from processing sensitive data
C.The system must meet specific security requirements to remain authorized
D.The system is permanently compliant
AnswerC

Conditions require timely remediation of identified risks.

Why this answer

An ATO with conditions means the system can operate, but specific security gaps must be closed within a defined timeframe to maintain authorization.

55
Multi-Selectmedium

Which TWO of the following are considered 'common controls'?

Select 2 answers
A.The custom source code of a business logic application.
B.Application-specific encryption keys.
C.Physical building access badges.
D.The specific database schema of a custom app.
E.Network boundary protection (firewall) for the data center.
AnswersC, E

Physical access is typically provided at the facility level.

Why this answer

Common controls are typically provided by centralized entities, such as physical security or network boundary protection.

56
Multi-Selecthard

When aligning GRC with business objectives, which THREE of the following represent effective strategic alignment?

Select 3 answers
A.Mapping risk categories to specific business processes.
B.Focusing exclusively on technical vulnerability patching.
C.Measuring the impact of GRC activities on organizational KPI targets.
D.Involving business owners in the risk assessment process.
E.Allowing IT teams to ignore GRC policies for speed.
AnswersA, C, D

This gives risk context to the business.

Why this answer

Alignment is achieved by mapping risks to objectives, involving stakeholders, and measuring impact.

57
MCQhard

You are deploying a PKI solution using Microsoft AD CS. You need to ensure that compromised certificates can be revoked. What must be configured?

A.OCSP Responder
B.Certificate Revocation List (CRL) Distribution Point
C.Key Archival
D.Trust Anchor
AnswerB

Clients must be able to reach the CDP to verify status.

Why this answer

A Certificate Revocation List (CRL) is essential for clients to verify if a certificate is still valid.

58
Multi-Selectmedium

In a mature GRC program, which TWO of the following activities are typical for the 'Risk Management' domain?

Select 2 answers
A.Designing new corporate office layouts.
B.Writing marketing brochures for the company.
C.Resetting all employee passwords every 30 days.
D.Developing treatment plans for risks exceeding appetite.
E.Identifying risks that could impact business objectives.
AnswersD, E

Treatment is the necessary response to manage risk.

Why this answer

Risk identification and treatment are the primary functions of risk management within GRC.

59
MCQeasy

What is the physical security control used to prevent piggybacking at an entry point?

A.Biometric scanner
B.Mantrap
C.CCTV camera
D.Security guard
AnswerB

A mantrap specifically prevents tailgating/piggybacking.

Why this answer

A mantrap is a physical system that requires one door to be closed before the other opens, preventing unauthorized entry.

60
Multi-Selectmedium

Which TWO of the following characterize the 'Select' step in the RMF?

Select 2 answers
A.Verifying that the controls are operating as expected.
B.Identifying and selecting the security controls to be implemented.
C.Determining the impact categorization of the system.
D.Documenting the controls in the System Security Plan (SSP).
E.Authorizing the system for operation.
AnswersB, D

This is the primary function of the select step.

Why this answer

The select step focuses on choosing the appropriate controls and documenting them in the system security plan.

61
MCQmedium

Your organization has decided to use a 'Control Overlay' for a cloud environment. What is the primary benefit of using an overlay?

A.It provides a standardized set of controls for a specific technology stack.
B.It replaces the need for FIPS 199 categorization.
C.It eliminates the need for manual tailoring.
D.It automatically tests the controls for compliance.
AnswerA

Overlays tailor baselines for specific scenarios like cloud or IoT.

Why this answer

Overlays are pre-defined sets of controls that address specific environments, technologies, or missions, ensuring consistent security posture.

62
MCQmedium

When performing vulnerability management, what is the purpose of a 'credentialed scan'?

A.To perform penetration testing
B.To automate the patching process
C.To bypass the firewall
D.To identify missing patches and misconfigurations
AnswerD

Accessing the OS allows detection of internal vulnerabilities.

Why this answer

Credentialed scans allow the tool to look inside the OS and application configuration, providing more accurate results.

63
Multi-Selecthard

Which THREE of the following are steps required to properly decommission a server containing sensitive data?

Select 3 answers
A.Updating the asset inventory database
B.Cryptographic erase of the storage media
C.Reformatting the drive once
D.Disconnecting from the network and removing physical identity
E.Leaving the server powered on in the rack
AnswersA, B, D

Records must reflect the current state of assets.

Why this answer

Secure data destruction, removing the server from the network, and updating the asset register are standard procedures.

64
Multi-Selecthard

Which THREE factors should an organization consider when applying control overlays?

Select 3 answers
A.The personal preference of the system administrator.
B.The date the system was originally purchased.
C.The mission or business requirements of the system.
D.The impact level of the underlying system.
E.The existing control baseline of the system.
AnswersC, D, E

Business needs drive the need for the specific overlay.

Why this answer

Overlays must be carefully integrated to ensure they maintain compliance while addressing specific environmental factors.

65
MCQhard

You are overseeing the decommissioning of a legacy database server holding PII. Per NIST SP 800-88 guidelines, which method ensures the media is sanitized to a level where the data cannot be recovered even with laboratory techniques?

A.Clear the file system using a standard OS format command.
B.Destroy the hard drive via shredding or incineration.
C.Overwrite the drive once with zeros.
D.Purge the data using a cryptographic erase (CE) method.
AnswerB

Destroy renders the target data recovery infeasible using state-of-the-art laboratory techniques.

Why this answer

According to NIST SP 800-88, destroying the physical media is the only method that prevents recovery from laboratory-grade forensic tools.

66
Multi-Selectmedium

Which TWO methods are commonly used to gather assessment evidence?

Select 2 answers
A.Budget approval
B.Marketing collateral review
C.Interview
D.Observation
E.System retirement
AnswersC, D

Gathering expert input.

Why this answer

Assessment methods commonly include observing processes and interviewing personnel to understand implementation.

67
Multi-Selecteasy

Which TWO types of controls are specifically examined during an audit?

Select 2 answers
A.Physical building aesthetics
B.HR hiring policies
C.Administrative controls
D.Technical controls
E.Marketing controls
AnswersC, D

Verified via documentation review.

Why this answer

Audits assess both technical controls (logical) and administrative controls (policies/procedures).

68
MCQeasy

To ensure compliance with PCI-DSS for a database, you must implement FDE (Full Disk Encryption). Which tool is appropriate for a Linux-based server?

A.BitLocker
B.IPsec
C.dm-crypt/LUKS
D.VeraCrypt
AnswerC

This is the native Linux kernel disk encryption framework.

Why this answer

dm-crypt/LUKS is the industry-standard tool for transparent full disk encryption on Linux.

69
MCQmedium

A federal agency is using FIPS 199 to categorize a system that processes public health data. The confidentiality impact is Low, integrity is Moderate, and availability is Moderate. What is the overall system categorization?

A.Not Categorized
B.Low
C.High
D.Moderate
AnswerD

The highest value among Low, Moderate, and Moderate is Moderate.

Why this answer

FIPS 199 defines the high-water mark based on the highest value among the three security objectives.

70
MCQhard

When a system boundary is complex and spans multiple geographic locations, what should the practitioner focus on to ensure security consistency?

A.Categorizing each site as a separate information system.
B.Excluding remote offices from the authorization boundary.
C.Allowing each site to define its own unique security policy.
D.Implementing consistent security controls across all boundary nodes regardless of location.
AnswerD

Consistent application of controls is essential for multi-site systems.

Why this answer

Centralizing the security management and standardizing controls across locations ensures uniform protection.

71
MCQmedium

You are preparing a security plan for a federal information system categorized as MODERATE impact. According to NIST SP 800-53B, what is the primary objective of the initial control baseline selection process?

A.To remove all controls that do not apply to the local network.
B.To define the continuous monitoring strategy for the system.
C.To provide a standardized starting point based on impact level.
D.To identify all system-specific compensations.
AnswerC

The baseline provides the initial set of controls for the categorization.

Why this answer

NIST SP 800-53B focuses on establishing a starting point of security controls based on the FIPS 199 impact categorization to ensure a minimum security posture.

72
Multi-Selecthard

Which THREE actions are essential for maintaining 'integrity' of audit evidence?

Select 3 answers
A.Publishing evidence to the company website
B.Chain of custody documentation
C.Use of cryptographic hashes for log files
D.Printing all evidence on paper
E.Restricting access to the audit evidence folder
AnswersB, C, E

Proves the evidence hasn't been altered.

Why this answer

Evidence must be protected from unauthorized changes, be verifiable, and be stored securely to maintain its chain of custody.

73
MCQmedium

You are utilizing the NIST SP 800-37 R2 process for an Authorization to Operate (ATO). At what point is the Security Assessment Report (SAR) presented to the Authorizing Official?

A.During the 'Categorize' step
B.After the 'Monitor' step
C.During the 'Prepare' step
D.After the 'Assess' step and before the 'Authorize' step
AnswerD

The SAR is a required input for the authorization decision.

Why this answer

The SAR provides the technical basis for the AO to make the risk-based decision after the assessment is complete.

74
Multi-Selecthard

Which THREE of the following represent common challenges in maintaining an integrated GRC program?

Select 3 answers
A.Ensuring leadership support is sustained over time.
B.Ensuring the GRC platform looks visually identical to the company brand.
C.Limiting the GRC platform to only one department.
D.Breaking down organizational silos of information.
E.Adapting to rapidly changing regulatory environments.
AnswersA, D, E

Sustaining support is difficult as management changes.

Why this answer

Data silos, lack of executive support, and evolving regulations are classic challenges in GRC.

75
MCQhard

You are implementing Windows AppLocker. You want to ensure that only signed binaries from your organization are executed. Which configuration should you choose?

A.Create a Path Rule for C:\Program Files\*
B.Configure the 'Audit only' mode in Group Policy
C.Create a Hash Rule for every existing executable
D.Create a Publisher Rule based on the certificate issuer and product name
AnswerD

This ensures only binaries signed by your organization's CA are permitted.

Why this answer

Publisher rules in AppLocker allow for the most granular control based on digital certificates.

Page 1 of 3

Page 2

All pages