CGRC · domain
Scope OF System
Practise CGRC DHCP questions covering DORA flow, scopes, excluded addresses, default gateway options, helper addresses, and troubleshooting clients that receive APIPA or cannot get an IP address.
Focused practice
Practice Scope OF System questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Scope OF System
DHCP questions usually test address assignment, scopes, relay agents, excluded addresses and why a client cannot obtain an IP address.
DHCP discovery, offer, request and acknowledgement flow.
DHCP scopes, excluded addresses and default gateway options.
DHCP relay using helper addresses.
Troubleshooting clients that receive APIPA or no address.
Why learners struggle
Why Scope OF System questions are commonly missed
DHCP questions are missed when learners overlook the relay agent requirement for cross-subnet assignments, or assume that because a DHCP server exists, a client will always get an address. Routing, relay, scope, and exclusion details all affect the outcome.
- ·DHCP relay required — clients on a different subnet cannot broadcast to a remote DHCP server without a helper address
- ·Excluded addresses — addresses in an excluded range are never offered, even if they are in the scope
- ·Default gateway option — must match the client subnet, not the server's subnet
- ·APIPA address (169.254.x.x) — indicates DHCP discovery failed, not a server response
- ·DORA flow — Discovery, Offer, Request, Acknowledgement; missing any step breaks assignment
- ·Scope exhaustion — a full scope returns no addresses even when the server is reachable
Watch out for
Common Scope OF System exam traps
- ▸A DHCP server on another subnet usually requires a relay/helper address.
- ▸Excluded addresses are not offered to clients.
- ▸The default gateway option must match the client subnet.
- ▸A client can fail even when the server exists if routing or relay is wrong.
Question index
All Scope OF System questions (20)
Click any question to see the full explanation, or start a practice session above.
What is the primary risk of having an inaccurately defined authorization boundary?
Easy2You have determined that a system's data is publicly available, but the system is responsible for providing critical government services. If the system goes offline, the loss of availability is catastrophic. How should the FIPS 199 categorization be adjusted?
Medium3Your organization is transitioning to a 'System of Systems' architecture. When defining the boundary for one sub-system, what is the best practice to avoid scope creep?
Hard4You are assessing a system that utilizes a shared service for identity management. How should this be reflected in the system's authorization boundary?
Hard5In the context of the RMF, which THREE of the following are considered 'Information System' components that contribute to the authorization boundary? (Select THREE)
Medium6Which THREE artifacts are commonly used by the Authorizing Official (AO) to validate the system boundary? (Select THREE)
Medium7A federal agency is using FIPS 199 to categorize a system that processes public health data. The confidentiality impact is Low, integrity is Moderate, and availability is Moderate. What is the overall system categorization?
Medium8When a system boundary is complex and spans multiple geographic locations, what should the practitioner focus on to ensure security consistency?
Hard9When classifying an information system under FIPS 199, which stakeholder should typically sign off on the final categorization?
Medium10You are documenting the system inventory in the Security Assessment Plan (SAP). Which artifact is most effective for demonstrating that all system interconnections have been properly inventoried?
Hard11Which NIST publication provides the definitive guidance on FIPS 199 security categorization?
Easy12When defining the system boundary, which TWO of the following factors should be considered? (Select TWO)
Medium13When defining the scope of an information system, what is the primary purpose of identifying 'common controls'?
Easy14Which THREE of the following are essential components of an effective system inventory for a federal agency? (Select THREE)
Hard15Which TWO statements regarding FIPS 199 'High Water Mark' are accurate? (Select TWO)
Hard16Which of the following is an example of a 'System Boundary' document that assists with the RMF process?
Easy17An Information System Owner (ISO) is deciding whether to include a legacy database within a new application's authorization boundary. What is the deciding factor?
Medium18Which document is mandatory to finalize the system categorization and begin the RMF process?
Medium19When applying FIPS 199 to an information system, which TWO security objectives must be evaluated for potential impact? (Select TWO)
Easy20You are defining the authorization boundary for a cloud-hosted application in the NIST Risk Management Framework. Which component must be explicitly included within the boundary according to NIST SP 800-37?
EasyOther domains
All CGRC exam domains
Frequently asked questions
- What does the Scope OF System domain cover on the CGRC exam?
- DHCP questions usually test address assignment, scopes, relay agents, excluded addresses and why a client cannot obtain an IP address.
- How many questions are in this domain?
- This page lists all 20 Scope OF System questions in the CGRC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Scope OF System questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.