
Latest ISC CGRC Exam questions and answers
iPassleader CGRC Exam Practice Test Questions (Updated 725 Questions)
NEW QUESTION # 172
The Security Category that primarily deals with ensuring timely and reliable access to information.
Response:
- A. Authenticity
- B. Confidentiality
- C. Integrity
- D. Availability
Answer: D
NEW QUESTION # 173
Who has the responsibility to review and ensure that only substantive items are incorporated in the plan of action and milestones?
Response:
- A. Authorizing Official
- B. Information System Owner
- C. Common Control Provider
- D. Information Owner
Answer: A
NEW QUESTION # 174
The potential impact is low if-The loss of confidentiality, integrity, or availability could be expected to have a...............
Response:
- A. Severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals.
- B. serious adverse effect on organizational operations, organizational assets, or individuals
- C. limited adverse effect on organizational operations, organizational assets, or individuals.
- D. no adverse effect on organizational operations, organizational assets, or individuals.
Answer: C
NEW QUESTION # 175
Which of the following BEST defines the purpose of security assessment? Response:
- A. To perform initial risk estimate and security categorization of the information system (IS)
- B. To determine the extent to which the security controls are implemented correctly and operating as intended
- C. To perform oversight and monitor the security controls in the information system (IS)
- D. To determine if the remaining known vulnerability pose an acceptable level of risk
Answer: B
NEW QUESTION # 176
The person primarily responsible for RMF Step 1, Categorization.
Response:
- A. Information System Owner
- B. Plan of Action and Milestones
- C. System Development Life-Cycle
- D. Risk Management Framework
Answer: A
NEW QUESTION # 177
Sam is the project manager of a construction project in south Florid
- A. Passive acceptance
- B. Mitigation
- C. Avoidance
- D. Active acceptance
- E. This area of the United States is prone to hurricanes during certain parts of the year. As part of the project plan Sam and the project team acknowledge the possibility of hurricanes and the damage the hurricane could have on the project's deliverables, the schedule of the project, and the overall cost of the project.
Once Sam and the project stakeholders acknowledge the risk of the hurricane they go on planning the project as if the risk is not likely to happen. What type of risk response is Sam using?
Response:
Answer: C
NEW QUESTION # 178
A key part of the risk-based decision process is the recognition that regardless of the risk response, There remains some risks known as:
Response:
- A. Risk tolerance level
- B. Residual risk
- C. Risk analysis
- D. Risk mitigation
Answer: B
NEW QUESTION # 179
The emphasis of the revised NIST SP 800-37 process is on.............
Response:
- A. Building information security controls into government information systems by applying up-to-date management, operational and technical security controls.
- B. Developing leadership to use, analyze and manage technical security of government information systems
- C. Providing senior leaders essential information to facilitate decision making with regard to risk acceptance.
- D. Maintaining awareness of the security posture of information systems through the application of
"enhanced monitoring processes." - E. Creating secured environment to provide guidance to individuals involved in security information systems
Answer: A,C,D
NEW QUESTION # 180
A General principle is that the scope of certification testing should include all controls defined in what document; SAR, SP, POAM?
Response:
- A. Assessment Plan
- B. Security Plan
- C. Contingency Plan
- D. Remediation plan
Answer: B
NEW QUESTION # 181
Documenting the description of the system in the system security plan is the primary responsibility of which Risk Management Framework (RMF) role?
Response:
- A. Information owner
- B. Information system owner
- C. Information system security officer (ISSO)
- D. Authorizing official (AO)
Answer: B
NEW QUESTION # 182
Who has the primary responsibility to report the authorization decision? Response:
- A. The authorizing official (AO) and the Information System Owner (ISO)
- B. The Information System Owner (ISO) and Authorizing Official Designated Representative (AODR)
- C. The Authorizing Official (AO) and Authorizing Official Designated Representative (AODR)
- D. The Common Control Provider (CCP) and the Information System Owner (ISO)
Answer: C
NEW QUESTION # 183
The RMF Step and task where the security controls are selected and documented in the Security Plan.
Response:
- A. RMF Step 2, Task 4
- B. RMF Step 2, Task 2
- C. RMF Step 2, Task 1
- D. RMF Step 2, Task 3
Answer: B
NEW QUESTION # 184
The monitoring frequency for each security control is based on which of the following?
- A. Authorization limit date
- B. None of the above
- C. Organizational continuous monitoring strategy
- D. Decisions of the SCA
- E. Response:
Answer: D
NEW QUESTION # 185
Which of the following roles is used to ensure that the confidentiality, integrity, and availability of the services are maintained to the levels approved on the Service Level Agreement (SLA)?
Response:
- A. The Change Manager
- B. The IT Security Manager
- C. The Configuration Manager
- D. The Service Level Manager
Answer: A
NEW QUESTION # 186
A planning estimate for the amount of days that it takes to assess a Moderate system is ___ - ___ days.
Response:
- A. 3-6
- B. 3-5
- C. 5-7
- D. 4-7
Answer: B
NEW QUESTION # 187
Is it a good or bad idea for the inspecting team to work with host staff to correct weaknesses on the spot when possible?
Response:
- A. Harmful
- B. Good
- C. Offensive
- D. Bad
Answer: B
NEW QUESTION # 188
The Information system owner should strive to test every control at least every ___ years & most critical controls continuously.
Response:
- A. Three
- B. Six
- C. Four
- D. Two
Answer: A
NEW QUESTION # 189
Process of controlling modifications to hardware, firmware, software, and documentation to protect the information system against improper modification prior to, during, and after system implementation.
Response:
- A. Security Controls
- B. Configuration Control
- C. Contingency Plan
- D. Operations Plan
Answer: B
NEW QUESTION # 190
Security testing conducted from inside the organization's security perimeter.
Response:
- A. Internal Security Testing
- B. Application Security Testing
- C. Web Security Testing
- D. Software Security Testing
Answer: A
NEW QUESTION # 191
An application that requires special attention to security due to the risk and magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of the information in the application. Note: All federal applications require some level of protection. Certain applications, because of the information in them, however, require special management oversight and should be treated as major.
Adequate security for other applications should be provided by security of the systems in which they operate.
Response:
- A. Major Application
- B. Worthless Application
- C. Slight Application
- D. Humble Application
Answer: A
NEW QUESTION # 192
What is verifying the identity of a user, process, or device, often as a prerequisite to allowing access to resources in an information system.
Response:
- A. Verification
- B. Categorization
- C. Authentication
- D. Organizational
Answer: C
NEW QUESTION # 193
A security control that is implemented in an information system in part as a common control and in part as a system-specific control. See also Common Control and System-Specific Security Control.
Response:
- A. System-Specific Security Control
- B. Common control
- C. Network Security Controls
- D. Hybrid Security Control
Answer: D
NEW QUESTION # 194
System authorization is now used to refer to which of the following terms? Response:
- A. Continuous monitoring
- B. Security test and evaluation
- C. System security declaration
- D. Certification and accreditation
Answer: D
NEW QUESTION # 195
......
Pass Your ISC Exam with CGRC Exam Dumps: https://www.ipassleader.com/ISC/CGRC-practice-exam-dumps.html
Pass CGRC Exam Info and Free Practice Test: https://drive.google.com/open?id=1tY2CxPD0mJ99HTB9Q259SrcXzFxFPitK