Courseiva

(ISC)2 Certified in Governance, Risk and Compliance (CGRC) (CGRC) (CGRC) — Questions 76150

199 questions total · 3pages · All types, answers revealed

Page 1

Page 2 of 3

Page 3
76
Multi-Selectmedium

Which TWO factors should an ISSO consider when determining if a system change requires a re-authorization?

Select 2 answers
A.The color of the server casing
B.The impact on the security control baseline
C.The scope of the changes made to the system
D.The number of administrative staff
E.The age of the hardware
AnswersB, C

If controls are weakened, it requires re-evaluation.

Why this answer

The magnitude of the change and the impact on the security controls are the two key triggers for re-authorization.

77
MCQhard

A system has received an Authority to Operate (ATO) with conditions. As the GRC officer, how do you handle these conditions in the continuous monitoring phase?

A.Document them in the System Security Plan (SSP) as 'accepted risks'.
B.Ignore them until the next major system upgrade.
C.Incorporate them into the POA&M and track remediation progress.
D.Submit a request to the AO to remove the conditions without changes.
AnswerC

The POA&M is the formal mechanism for tracking the resolution of security deficiencies associated with an ATO.

Why this answer

Conditions attached to an ATO represent known risks that must be tracked and mitigated through the POA&M to transition to full, unconditioned authorization.

78
MCQhard

When implementing an 802.1X environment, what is the role of the RADIUS server?

A.Encapsulating EAP frames
B.Providing the EAP method to the client
C.Enforcing the physical port state
D.Authenticating the supplicant
AnswerD

The RADIUS server makes the final decision on access based on the credentials.

Why this answer

The RADIUS server acts as the Authentication Server, validating the credentials provided by the supplicant via the authenticator.

79
Multi-Selecthard

Which THREE items are critical when verifying an organization's Compliance with NIST SP 800-53?

Select 3 answers
A.System Security Plan (SSP)
B.Annual report of stock performance
C.Security Assessment Report (SAR)
D.Internal marketing strategy
E.POA&M
AnswersA, C, E

Baseline requirement.

Why this answer

NIST compliance requires a review of the SSP, the assessment of the controls, and the documentation of any deficiencies in a POA&M.

80
Multi-Selectmedium

Which TWO actions should an ISSO take when a critical security control is found to be ineffective during assessment?

Select 2 answers
A.Delete the control from the SSP
B.Change the system password
C.Document the finding in the SAR
D.Create a POA&M entry to track remediation
E.Immediately disconnect the system
AnswersC, D

Findings must be reported.

Why this answer

The ISSO must document the finding in the SAR and work with the system owner to document the mitigation in a POA&M.

81
Multi-Selecthard

Which THREE actions are required when preparing to decommission a system that stored 'Classified' information?

Select 3 answers
A.Move the system to a secure storage area for indefinite holding.
B.Create a certificate of destruction for audit purposes.
C.Physically destroy the storage media.
D.Reformat the drive for reuse in a non-sensitive project.
E.Remove the system from the active asset inventory.
AnswersB, C, E

A certificate provides formal evidence that the sanitization/destruction occurred.

Why this answer

Sanitizing the media, updating the inventory, and documenting the destruction process are all critical steps for classified systems.

82
MCQmedium

A contractor provides a service for your organization. How do you ensure the contractor's system is compliant?

A.Grant them access to your internal ATO database
B.Include security requirements in the contract language
C.Perform an audit of the contractor's office
D.Trust the contractor's internal IT department
AnswerB

Contractual requirements are the primary mechanism for third-party compliance.

Why this answer

Incorporating security requirements into the contract (like FAR/DFARS clauses) ensures the contractor is legally bound to meet security standards.

83
MCQmedium

When classifying an information system under FIPS 199, which stakeholder should typically sign off on the final categorization?

A.The Lead System Administrator.
B.The Information System Owner (ISO).
C.The Chief Information Security Officer (CISO).
D.The Third-Party Auditor.
AnswerB

The ISO is the accountable party for the system categorization.

Why this answer

The Information System Owner (ISO) is responsible for the categorization, which is then approved by the Authorizing Official (AO).

84
MCQeasy

An Authorizing Official (AO) is reviewing a Plan of Action and Milestones (POA&M) for a high-impact system. What is the AO's primary responsibility regarding this document?

A.Drafting the mitigation tasks
B.Conducting the security controls assessment
C.Implementing the technical patches
D.Accepting the residual risk associated with the POA&M
AnswerD

The AO signs off on the risk acceptance.

Why this answer

The AO is accountable for the risk the system poses to the organization and must approve the mitigation strategy outlined in the POA&M.

85
MCQeasy

A security auditor needs to verify that the principle of least privilege is applied to a Linux server. Which audit activity is most appropriate?

A.Running a Nessus vulnerability scan
B.Verifying user account permissions and group assignments
C.Checking for physical server room access
D.Reviewing system logs for failed login attempts
AnswerB

This directly maps access to roles.

Why this answer

Reviewing /etc/passwd and /etc/group files and comparing user permissions against assigned roles is a direct method to verify least privilege.

86
MCQmedium

What is the primary role of the authorization official (AO) during the Control Selection phase?

A.To approve the tailoring decisions.
B.To configure the security appliances.
C.To write the security policy.
D.To perform the technical assessment.
AnswerA

The AO signs off on the risk represented by the selected controls.

Why this answer

The AO reviews and approves the selected control set to ensure it meets the risk appetite of the organization.

87
MCQmedium

If a security control is deemed 'Not Applicable' (NA) in the System Security Plan (SSP), what must the system owner provide?

A.A waiver request to the CISO
B.A copy of the vendor's warranty
C.A technical justification for the N/A status
D.The procurement contract
AnswerC

Justification is required to ensure the control was not mistakenly omitted.

Why this answer

For a control to be N/A, there must be a valid justification based on the system's architecture or operational environment.

88
Multi-Selectmedium

Which TWO of the following are common challenges when implementing continuous monitoring in a legacy environment?

Select 2 answers
A.The system is too new for security researchers to find bugs.
B.High risk of system instability during patch deployment.
C.Lack of modern API support for automated monitoring tools.
D.The system automatically updates its own firmware daily.
E.Too much disk space available for logging.
AnswersB, C

Legacy systems are often brittle, making automated patching risky.

Why this answer

Legacy systems often lack support for modern automation tools and are difficult to patch without downtime.

89
Multi-Selectmedium

Which THREE roles are typically involved in a security assessment?

Select 3 answers
A.Customer support agents
B.External public relations firm
C.Assessor / Auditor
D.Chief Information Security Officer (CISO)
E.System Owner
AnswersC, D, E

Performs the evaluation.

Why this answer

The assessor (auditor), the system owner (responsible party), and the security officer (compliance expert) are key participants.

90
MCQeasy

Which document is primarily used to track and manage changes to security controls under the continuous monitoring strategy?

A.Plan of Action and Milestones (POA&M).
B.System Security Plan (SSP).
C.Risk Assessment Report (RAR).
D.Authority to Operate (ATO).
AnswerA

The POA&M is used to track the progress of remediating identified security weaknesses.

Why this answer

The Plan of Action and Milestones (POA&M) is the standard document used to track the remediation of security control deficiencies.

91
Multi-Selecthard

Which TWO elements are required to be included in a Plan of Action and Milestones (POA&M)?

Select 2 answers
A.Target completion date
B.Personnel salary data
C.Historical audit logs
D.Description of the vulnerability
E.Software licensing keys
AnswersA, D

The 'Milestones' part of POA&M.

Why this answer

A POA&M must define the vulnerability/weakness and the specific milestone/date for remediation.

92
MCQmedium

When selecting controls for a system that uses mobile devices, you apply an overlay. What is the correct relationship between the baseline and the overlay?

A.The overlay supplements the baseline.
B.The overlay is used only if the system is High impact.
C.The baseline is discarded if an overlay is used.
D.The overlay replaces the entire baseline.
AnswerA

The overlay adds or modifies controls for the specific technology.

Why this answer

Overlays are used to augment the base control set; they don't replace the baseline but tailor it for a specific context.

93
Multi-Selecthard

Which THREE of the following are benefits of using the NIST 800-53 control framework?

Select 3 answers
A.It supports a consistent approach to security across the organization.
B.It eliminates the need for any technical expertise.
C.It facilitates risk-based decision-making.
D.It automates all manual security processes.
E.It provides a common language for security controls.
AnswersA, C, E

Consistent application is a primary benefit.

Why this answer

The framework provides a common language and structured approach to security that helps organizations manage risk effectively.

94
Multi-Selecteasy

Which TWO of the following are considered 'technical' security controls?

Select 2 answers
A.Annual risk assessment
B.Security policies
C.Encryption of data in transit
D.Access Control Lists (ACLs)
E.Fencing around the data center
AnswersC, D

Encryption is a technical control.

Why this answer

Technical controls (also called logical controls) use technology to enforce security.

95
MCQhard

When assessing a cloud service provider (CSP) using a FedRAMP-authorized solution, what is the primary benefit to your organization?

A.It guarantees the system will never be breached
B.It reduces the level of effort for the security assessment
C.It eliminates the need for any internal security oversight
D.It allows the organization to bypass the RMF
AnswerB

The 'do once, use many' principle applies here.

Why this answer

Using a pre-authorized CSP means the government has already assessed the security controls, reducing the need for redundant assessments.

96
MCQhard

You are documenting the system inventory in the Security Assessment Plan (SAP). Which artifact is most effective for demonstrating that all system interconnections have been properly inventoried?

A.The system's latest vulnerability scan report.
B.A comprehensive network topology diagram showing external service endpoints.
C.The organization's enterprise risk register.
D.A listing of all installed software patches.
AnswerB

A topology diagram is the primary artifact for visualizing and validating the system boundary.

Why this answer

A System Interconnection Agreement (SIA) or Data Use Agreement (DUA) provides the formal record of cross-boundary data flows.

97
Multi-Selectmedium

Which TWO of the following documents should be updated during the continuous monitoring phase when a system configuration is changed?

Select 2 answers
A.The vendor's hardware sales catalog.
B.System Security Plan (SSP).
C.Employee Handbook.
D.Configuration Baseline document.
E.Corporate financial statements.
AnswersB, D

The SSP must always reflect the current state of the system.

Why this answer

The System Security Plan and the associated configuration baselines must be kept current to reflect the system's actual state.

98
MCQeasy

Which NIST publication provides the definitive guidance on FIPS 199 security categorization?

A.NIST SP 800-37.
B.NIST SP 800-60.
C.NIST SP 800-53.
D.FIPS 140-3.
AnswerB

SP 800-60 specifically addresses the categorization of information systems.

Why this answer

NIST SP 800-60 is the guide for mapping information types to FIPS 199 security objectives.

99
MCQeasy

When utilizing the NIST 800-53 control catalog, which field identifies the specific family to which a control belongs?

A.Control priority tag.
B.The assignment statement.
C.Control ID prefix.
D.The control parameter list.
AnswerC

The prefix denotes the family, such as AC for Access Control.

Why this answer

Control identifiers in NIST 800-53 follow a format such as AC-2, where 'AC' refers to the Access Control family.

100
Multi-Selectmedium

When setting up a new GRC program, which TWO of the following are essential for ensuring successful adoption across the business?

Select 2 answers
A.Hiring only external consultants to manage the GRC tool.
B.Obtaining formal executive sponsorship for the initiative.
C.Disabling all audit logs to improve system performance.
D.Defining clear roles and responsibilities for all users.
E.Purchasing the most expensive GRC module available.
AnswersB, D

Support from leadership is essential for resource allocation.

Why this answer

Executive sponsorship and clear ownership are foundational for any governance program.

101
Multi-Selecthard

Which THREE of the following are components that must be included when documenting a compensating control?

Select 3 answers
A.The identity of the person who approved the control.
B.A detailed explanation of how the compensating control mitigates the risk.
C.A description of the risk the control is intended to mitigate.
D.A list of every user affected by the control.
E.The reason why the original control could not be implemented.
AnswersB, C, E

The mechanism of mitigation must be proven.

Why this answer

Compensating controls require rigorous documentation to ensure the auditor can verify that the risk is mitigated effectively.

102
Multi-Selectmedium

When defining the system boundary, which TWO of the following factors should be considered? (Select TWO)

Select 2 answers
A.The information types processed, stored, or transmitted by the system.
B.The organizational personnel who have access to the system.
C.The fiscal budget allocated for hardware replacement.
D.The interconnections with other internal and external systems.
E.The physical location of the cloud data center.
AnswersA, D

Information types are critical to defining the system's scope and FIPS 199 impact.

Why this answer

Defining the boundary requires understanding the system's operational scope, its connection points, and its data ownership.

103
Multi-Selecthard

Which THREE of the following are valid components of an Authorization Package?

Select 3 answers
A.Vendor invoices
B.Security Assessment Report (SAR)
C.User training records
D.System Security Plan (SSP)
E.Plan of Action and Milestones (POA&M)
AnswersB, D, E

Core component.

Why this answer

The Authorization Package consists of the SSP, SAR, and POA&M as the core elements for the AO.

104
Multi-Selecthard

Which THREE of the following are components of a secure server hardening process?

Select 3 answers
A.Installing all available third-party software
B.Applying security patches
C.Configuring the OS with a minimal footprint
D.Running the web server as the root user
E.Disabling unused services and ports
AnswersB, C, E

Patching is critical for vulnerability remediation.

Why this answer

Disabling unnecessary services, updating software, and using minimal feature sets are key to reducing the attack surface.

105
MCQmedium

You are performing a gap analysis. What is the correct order of operations for a professional assessment?

A.Current state, Target state, Gap identification
B.Gap identification, Target state, Current state
C.Current state, Gap identification, Target state
D.Target state, Current state, Gap identification
AnswerD

The target must be established before measuring the current state.

Why this answer

You must define the target (what good looks like), determine the current state (as-is), and then identify the delta (gap).

106
MCQmedium

Your organization uses Tenable.io for continuous monitoring of vulnerability status. You notice that several high-severity vulnerabilities remain 'open' despite being marked as 'patched' in your configuration management database. What is the most likely cause?

A.The Nessus scanner plugin needs an update to recognize the patch.
B.The scan policy is set to 'Discovery' instead of 'Audit'.
C.The scan agent was decommissioned prematurely.
D.The vulnerability scan was not performed after the patch was applied.
AnswerD

Continuous monitoring requires validation scans to confirm patch effectiveness before updating the compliance status.

Why this answer

This discrepancy indicates a failure in the synchronization between the patch management process and the vulnerability management detection phase.

107
MCQeasy

When defining the scope of an information system, what is the primary purpose of identifying 'common controls'?

A.To ensure they are manually tested for every individual system.
B.To increase the system's FIPS 199 impact level.
C.To identify controls that are implemented once and applied to multiple systems.
D.To exclude them from the System Security Plan (SSP).
AnswerC

Efficiency in control implementation is a primary goal of common control identification.

Why this answer

Common controls are inherited from the organization or another system, reducing the burden on the individual system owner.

108
MCQeasy

When aligning GRC objectives with business goals, which metric best demonstrates the value of an integrated GRC program to a Board of Directors?

A.The number of tickets opened in the GRC helpdesk.
B.The total storage space consumed by evidence files.
C.The number of users logged into the GRC platform daily.
D.The percentage reduction in repeat audit findings.
AnswerD

This is a key performance indicator (KPI) demonstrating effective risk remediation.

Why this answer

'Reduction in audit findings' directly correlates to lower operational risk and better compliance posture, which resonates with stakeholders.

109
Multi-Selecthard

Which THREE of the following are essential components of an effective system inventory for a federal agency? (Select THREE)

Select 3 answers
A.System interconnections and data flow paths.
B.Hardware serial numbers and physical asset tags.
C.The employee performance evaluation score for the system admin.
D.The exact date of the last office coffee machine maintenance.
E.Software versions and patch levels.
AnswersA, B, E

Tracking how the system connects is vital for boundary management.

Why this answer

An inventory must track hardware, software, and operational connections to be useful for risk management.

110
MCQhard

You are implementing 'decommissioning' procedures for a virtual machine (VM) in a cloud environment. What is the final step you must take to ensure compliance with data privacy regulations after the data has been deleted?

A.Delete the VM snapshot from the management console.
B.Revoke the access rights of the VM administrator.
C.Shut down the VM and wait for the provider to recycle the hardware.
D.Perform a cryptographic erase by deleting the associated encryption keys.
AnswerD

Cryptographic erase is a standard, compliant way to sanitize data in cloud environments where physical destruction is not possible.

Why this answer

Deleting the VM is not enough; you must verify that the underlying storage blocks have been properly sanitized or that the keys used to encrypt the data have been destroyed.

111
Multi-Selecthard

Which TWO statements regarding FIPS 199 'High Water Mark' are accurate? (Select TWO)

Select 2 answers
A.The overall system categorization is the highest of the three individual security objectives.
B.The high water mark only applies to federal systems with 'High' impact data.
C.Categorization must be performed by averaging the impact scores.
D.The high water mark is only determined by availability.
E.The high water mark must be applied to all security controls within the boundary.
AnswersA, E

This is the definition of the high water mark principle.

Why this answer

The high water mark ensures that the entire system is protected at the level of its most sensitive component.

112
MCQmedium

You are configuring a GRC workflow to address 'High' severity findings. The requirement is that any finding classified as 'High' must be approved by the CISO before moving to the 'Remediated' state. Which mechanism should you configure?

A.Set up a Workflow Transition Condition triggered by the 'Severity' field.
B.Configure a global Business Rule to auto-close all findings.
C.Change the default notification email template for findings.
D.Modify the User Permission set for the CISO account.
AnswerA

Workflow transitions allow for conditional routing based on specific metadata values.

Why this answer

Workflow automation engines in GRC platforms use conditional logic transitions to route tasks based on field values like 'Severity'.

113
MCQeasy

Which of the following is an example of a 'System Boundary' document that assists with the RMF process?

A.The System Security Plan (SSP) boundary description.
B.The Annual Security Awareness Training log.
C.The Privacy Threshold Analysis (PTA).
D.The System Development Life Cycle (SDLC) policy.
AnswerA

The SSP is the authoritative source for the security boundary.

Why this answer

A boundary diagram or description is required for the System Security Plan to define what is subject to assessment.

114
Multi-Selecthard

Which THREE categories of controls are identified in NIST SP 800-53?

Select 3 answers
A.Financial
B.Operational
C.Management
D.Environmental
E.Technical
AnswersB, C, E

A valid control category.

Why this answer

NIST categorizes controls into Technical, Management, and Operational families.

115
MCQmedium

You are preparing a NIST SP 800-53A security control assessment. Which methodology step is performed immediately after the 'Prepare for Assessment' phase?

A.Analyze Security Assessment Results
B.Develop the Plan of Action and Milestones (POA&M)
C.Assess Security Controls
D.Authorize the Information System
AnswerC

The assessment phase follows preparation.

Why this answer

According to NIST SP 800-53A, the assessment process is a linear flow where the 'Prepare for Assessment' phase leads directly into the 'Assess Security Controls' phase to execute the test procedures.

116
MCQmedium

You are managing access to a file server. You want to ensure that users can read files but not delete them. What is this an example of?

A.Modify permission
B.Full Control
C.Read-Only permission
D.Write permission
AnswerC

Read-Only allows access to content but prevents modification or deletion.

Why this answer

This is the principle of Least Privilege, specifically using NTFS permissions to restrict write/delete access.

117
Multi-Selectmedium

Which TWO of the following statements regarding the 'Tailoring' process are accurate?

Select 2 answers
A.Tailoring is performed during the Assess step.
B.Tailoring actions must be documented to justify the risk management decisions.
C.Tailoring is only permitted for High impact systems.
D.Tailoring is used to modify the baseline based on system-specific factors.
E.Tailoring is optional and not required by RMF.
AnswersB, D

Documentation is mandatory for transparency and auditability.

Why this answer

Tailoring allows for the modification of the baseline, but those modifications must be documented and justified.

118
MCQeasy

If a control is determined to be 'system-specific', what does that mean?

A.It is a hybrid control.
B.It is implemented by the system owner for that system only.
C.It must be implemented by the vendor.
D.It is inherited from the enterprise.
AnswerB

System-specific means the system is responsible for the implementation.

Why this answer

A system-specific control is one that is implemented solely by the information system and is not inherited from an enterprise service.

119
MCQmedium

You are configuring a SIEM (e.g., Splunk) to monitor failed login attempts. What is the most efficient way to reduce noise while maintaining audit integrity?

A.Apply filters on the Universal Forwarder
B.Disable logging on the domain controller
C.Delete logs after ingestion
D.Increase log rotation frequency
AnswerA

Filtering at the source (forwarder) prevents ingestion of noise.

Why this answer

Filtering at the forwarder level prevents unnecessary ingestion of logs, saving storage and improving performance.

120
MCQmedium

A vulnerability scan identifies a 'missing patch' on a server. You discover that the patch cannot be applied due to compatibility issues with a critical legacy application. What is the correct compliance management action?

A.Request an exemption from the CISO without providing documentation.
B.Ignore the vulnerability as it cannot be fixed.
C.Implement and document compensating controls.
D.Disconnect the server from the network permanently.
AnswerC

Compensating controls are required when the primary control (patching) is not feasible.

Why this answer

When a patch cannot be applied, compensating controls must be implemented and documented to mitigate the risk.

121
MCQmedium

During tailoring, what is the 'Refinement' process?

A.Changing the impact level of the system.
B.Removing controls that are too expensive.
C.Adjusting the control statement to make it more precise.
D.Adding new controls to the baseline.
AnswerC

Refinement makes the control more applicable.

Why this answer

Refinement is the process of adjusting the implementation of a control to be more specific to the technology or mission.

122
MCQmedium

An Information System Owner (ISO) is deciding whether to include a legacy database within a new application's authorization boundary. What is the deciding factor?

A.The dependency of the system on the database for operational integrity.
B.Whether the database is hosted in the same physical rack.
C.The age of the hardware.
D.The amount of data stored.
AnswerA

Operational and security dependencies define the boundary.

Why this answer

If the new application relies on the database for security or operational functionality, it must be included.

123
MCQhard

You are hardening a web server. You need to ensure that only secure ciphers are used for TLS connections. Where is this typically configured?

A.The server's TLS configuration file
B.The server's BIOS settings
C.The web application's root directory
D.The firewall access control list
AnswerA

This file controls how the server handles cryptographic handshakes.

Why this answer

The web server's SSL/TLS configuration file (e.g., httpd.conf or nginx.conf) defines the supported cipher suites.

124
MCQhard

You are assessing a system. You find a control that is marked as 'Inherited'. What is the most critical item to verify?

A.That the control is listed in the system's own configuration guide.
B.That the system owner has full administrative control.
C.That the common control provider provides evidence of compliance.
D.That the control is manually tested by the system team.
AnswerC

Validation of the provider is essential.

Why this answer

For inherited controls, the system owner must verify the 'Inheritance Agreement' or the 'Common Control Provider' documentation to ensure the control is actually in place and operating correctly.

125
MCQmedium

You are performing a configuration audit on a Linux server. Which file would you examine to ensure that the SSH daemon is not allowing root login?

A./etc/hosts.allow
B./etc/shadow
C./etc/passwd
D./etc/ssh/sshd_config
AnswerD

The sshd_config file is the standard configuration file for the SSH daemon.

Why this answer

The sshd_config file contains the 'PermitRootLogin' directive which must be set to 'no' for compliance.

126
Multi-Selecteasy

Which TWO of the following are responsibilities of the Authorizing Official?

Select 2 answers
A.Conducting the scan
B.Signing the authorization decision
C.Accepting the residual risk
D.Writing the user manual
E.Updating the firewall rules
AnswersB, C

AO responsibility.

Why this answer

The AO is the final risk decision maker and is accountable for the system's security status.

127
MCQhard

An organization is moving to a cloud-native infrastructure. What is the most significant change in the assessment of 'inherited' controls?

A.POA&M is prohibited for cloud providers
B.Greater reliance on third-party audit reports
C.Physical security is no longer assessed
D.Manual testing is mandated for all controls
AnswerB

The assessor relies on the provider's third-party attestations.

Why this answer

In a cloud environment, the provider manages the physical and infrastructure controls (inherited), meaning the assessor focuses on verifying the provider's attestations (like SOC 2 reports).

128
MCQmedium

You are configuring an AWS Security Group for a web server. To allow incoming HTTPS traffic from the internet while restricting all other traffic, which rule should you apply?

A.Inbound Rule: Type HTTPS, Port 443, Source 0.0.0.0/0
B.Outbound Rule: Type HTTPS, Port 443, Destination 0.0.0.0/0
C.Inbound Rule: Type All Traffic, Port All, Source 0.0.0.0/0
D.Inbound Rule: Type HTTPS, Port 443, Source 127.0.0.1/32
AnswerA

This correctly allows HTTPS traffic from any source.

Why this answer

Security groups are stateful; allowing inbound traffic automatically allows the return traffic, and the default is to deny all other traffic.

129
Multi-Selecteasy

Which TWO of the following are effective ways to secure endpoints against malware?

Select 2 answers
A.Implementing a patch management policy
B.Allowing users to install any software
C.Turning off all logging
D.Disabling the OS firewall
E.Deploying EDR software
AnswersA, E

Patching prevents exploitation of software vulnerabilities.

Why this answer

Antivirus/EDR and regular patching are the primary technical controls for endpoint malware protection.

130
MCQhard

When configuring Cisco ASA firewall rules, you notice that traffic is being dropped despite an 'allow' access-list. What is the most likely cause?

A.The interface is not assigned to a security zone
B.The traffic is encrypted by VPN
C.Missing 'permit ip any any' at the top
D.The rule is placed after a 'deny ip any any' rule in the same list
AnswerD

ASA access lists are processed sequentially; the first match wins.

Why this answer

The Cisco ASA uses an 'implicit deny' at the end of every access-list, and the order of rules matters.

131
MCQmedium

Which document is mandatory to finalize the system categorization and begin the RMF process?

A.The Incident Response Policy.
B.The Penetration Test Report.
C.The FIPS 199 Security Categorization document.
D.The Contingency Plan.
AnswerC

Categorization is the foundational step in NIST SP 800-60/800-53.

Why this answer

The FIPS 199 Categorization document (or the categorization section of the SSP) is required to select appropriate security controls.

132
MCQmedium

You are managing an AWS S3 bucket that stores sensitive PII. Which control is the primary mechanism to prevent public access?

A.Encryption at Rest
B.Bucket ACLs
C.S3 Block Public Access
D.IAM User Permissions
AnswerC

This is the definitive control to prevent public access regardless of object settings.

Why this answer

S3 Block Public Access settings provide a centralized, account-wide or bucket-level override to prevent accidental exposure.

133
Multi-Selecthard

Which THREE of the following represent 'compensating controls' that might be used when a specific security control cannot be implemented exactly as required?

Select 3 answers
A.Segmenting the system into a separate, isolated network zone.
B.Providing the system administrator with a larger office.
C.Implementing enhanced logging and monitoring of the affected component.
D.Installing a new air conditioning unit in the server room.
E.Requiring multi-factor authentication for all administrative access.
AnswersA, C, E

Isolation limits the blast radius of a vulnerability.

Why this answer

Compensating controls provide an alternative way to achieve the security objective; examples include increased monitoring, network isolation, or enhanced access auditing.

134
MCQeasy

Which document defines the specific security controls that an organization must implement based on its risk assessment?

A.Incident Response Plan
B.Risk Management Plan
C.Security Assessment Report (SAR)
D.System Security Plan (SSP)
AnswerD

The SSP identifies applied controls.

Why this answer

The System Security Plan (SSP) describes the system and the controls that have been selected (tailored) to meet security requirements.

135
MCQeasy

What is the purpose of a 'pre-assessment' meeting?

A.To set expectations and coordinate logistics
B.To conduct penetration testing
C.To finalize the POA&M
D.To perform hardware inventory
AnswerA

Logistics are vital for assessment success.

Why this answer

A pre-assessment or kickoff meeting ensures alignment on scope, timeline, logistics, and points of contact between the auditor and the client.

136
MCQeasy

Which type of audit is performed by an internal department to assess the effectiveness of security controls without external pressure?

A.Third-party assessment
B.Penetration test
C.Self-assessment
D.Regulatory inspection
AnswerC

Self-assessments are internal exercises.

Why this answer

Internal audits are conducted by the organization's own staff to improve internal processes and compliance before formal external audits occur.

137
MCQeasy

Which document provides the formal authority to operate a system?

A.System Security Plan
B.Risk Assessment Report
C.Security Control Assessment
D.Authorization Decision Document
AnswerD

This document conveys the AO's decision.

Why this answer

The Authorization Decision Document (ADD) or ATO letter is the formal record of the AO's decision.

138
Multi-Selectmedium

Which TWO documents are essential for an Authorizing Official to make an informed risk-based decision?

Select 2 answers
A.System Security Plan (SSP)
B.Hardware inventory list
C.Plan of Action and Milestones (POA&M)
D.Security Assessment Report (SAR)
E.Network diagram
AnswersC, D

Essential for knowing the remediation plan for weaknesses.

Why this answer

The SAR provides the technical assessment, and the POA&M identifies how identified weaknesses will be addressed.

139
MCQeasy

Which GRC component is used to document the organizational structure, such as business units and departments, to which risks are assigned?

A.The 'Report' generator.
B.The 'Policy' library.
C.The 'Incident' tracking module.
D.The 'Entity' or 'Organization' Manager module.
AnswerD

This defines the business taxonomy and hierarchy.

Why this answer

The 'Organization Hierarchy' or 'Entity Manager' module defines the business structure within the GRC platform.

140
MCQeasy

Which GRC platform component is most critical for ensuring that executive leadership receives accurate, real-time risk posture data?

A.The Executive Dashboard and Reporting module.
B.The system audit log.
C.The User Provisioning interface.
D.The API integration module.
AnswerA

Dashboards provide the visualization layer for GRC data.

Why this answer

Dashboards and reporting widgets are designed to aggregate data from underlying assessment records for executive consumption.

141
MCQmedium

You are tailoring controls for a system that does not process PII. Which action should you take regarding the Privacy (PRIV) family controls in the NIST 800-53 catalog?

A.Replace the family with general security controls.
B.Keep the controls but set them to 'manual' mode.
C.Document the removal of the family with a justification.
D.Implement the controls as high-priority items.
AnswerC

Tailoring allows for the removal of non-applicable controls with justification.

Why this answer

If a control or family is not applicable to the system's function, it should be scoped out or documented as not applicable during the tailoring process.

142
MCQmedium

What is the relationship between the System Security Plan (SSP) and the Security Assessment Report (SAR)?

A.The SAR evaluates the effectiveness of the controls described in the SSP
B.The SSP is a summary of the SAR
C.They are independent documents with no relationship
D.The SAR provides the controls to be documented in the SSP
AnswerA

The SAR is the validation of the SSP.

Why this answer

The SSP describes the controls that *should* be in place, and the SAR reports on whether those controls are actually effective.

143
Multi-Selecthard

To ensure the integrity of the GRC 'System of Record', which THREE controls must be enforced?

Select 3 answers
A.Automated data validation rules for input fields.
B.Allowing all users to edit any data at any time.
C.Strict access control and user authorization policies.
D.Disabling the backup of the GRC database.
E.Comprehensive audit logs of all user actions.
AnswersA, C, E

Input validation ensures data quality.

Why this answer

Integrity is managed via audit trails, access controls, and data validation rules.

144
MCQhard

You are implementing Disk Encryption using BitLocker. You want to ensure that the recovery key is stored securely. Where should it be stored?

A.On a local USB drive
B.In Active Directory
C.Printed on the side of the PC
D.In a text file on the desktop
AnswerB

AD DS provides a secure, centralized location for recovery keys.

Why this answer

Storing recovery keys in Active Directory Domain Services (AD DS) ensures central management and recovery capability for IT staff.

145
Multi-Selecthard

Which THREE types of information should be included in a risk acceptance memo?

Select 3 answers
A.The name of the software vendor
B.The technical specifications of the server
C.Description of the identified risk
D.The impact on the organizational mission
E.Justification for accepting the risk
AnswersC, D, E

Must define what is being accepted.

Why this answer

Risk acceptance must document the specific risk, the impact, and the duration or justification for accepting it.

146
MCQeasy

Which document serves as the primary agreement between an assessor and the target organization outlining the scope of an audit?

A.Interconnection Security Agreement
B.Rules of Engagement
C.Security Assessment Plan
D.Risk Assessment Report
E.System Security Plan
AnswerB

ROE serves as the governance agreement.

Why this answer

The Rules of Engagement (ROE) define the boundaries, scope, and procedures for an assessment, ensuring both parties understand the limitations.

147
MCQhard

An organization is integrating 'Third-Party Risk Management' (TPRM) into their GRC framework. They need to ensure that vendors with 'Critical' status undergo annual due diligence. Which configuration is required?

A.Email all vendors every January to ask if they are ready.
B.Configure an 'Automated Workflow Trigger' based on 'Vendor Tier' and 'Date'.
C.Hire a full-time employee to manage vendor emails.
D.Require vendors to login to the GRC platform daily.
AnswerB

This automates the compliance cycle for third parties.

Why this answer

A 'Scheduled Assessment' or 'Workflow Trigger' based on 'Vendor Criticality' ensures compliance with due diligence timelines.

148
MCQmedium

A company is implementing a 'Continuous Monitoring' program in their GRC tool. They need to ingest data from a Cloud Security Posture Management (CSPM) tool. What is the most efficient configuration approach?

A.Build a custom script to write directly to the GRC database tables.
B.Manually export and import CSV files every hour.
C.Use an established 'Data Connector' or 'API Integration' module.
D.Have the CSPM tool email screenshots of security alerts to the GRC team.
AnswerC

API connectors provide the most secure and scalable data ingestion.

Why this answer

Using pre-built API connectors or 'Data Integrators' provided by the GRC platform is the standard way to ingest external security data.

149
Multi-Selectmedium

Which TWO of the following entities are typically responsible for maintaining compliance in a cloud environment under a shared responsibility model?

Select 2 answers
A.The hardware manufacturer.
B.The local internet service provider.
C.The end-user of the application.
D.The cloud service provider (CSP).
E.The cloud customer.
AnswersD, E

The CSP is responsible for security of the cloud (infrastructure).

Why this answer

Security in the cloud is a shared endeavor where the provider covers the infrastructure and the customer covers the configuration and data.

150
MCQeasy

Which document defines the security control baselines (Low, Moderate, High) for federal information systems?

A.NIST SP 800-53B.
B.NIST SP 800-53A.
C.FIPS 199.
D.NIST SP 800-37.
AnswerA

This document specifies the actual control baselines.

Why this answer

NIST SP 800-53B provides the control baselines for the various impact levels.

Page 1

Page 2 of 3

Page 3

All pages