ISC Certified in Governance Risk and Compliance - CGRC FREE EXAM DUMPS QUESTIONS & ANSWERS
Frank is the project manager of the NHH Project. He is working with the project team to create a plan to document the procedures to manage risks throughout the project. This document will define how risks will be identified and quantified.
It will also define how contingency plans will be implemented by the project team. What document is Frank and the NHH Project team creating in this scenario? Response:
It will also define how contingency plans will be implemented by the project team. What document is Frank and the NHH Project team creating in this scenario? Response:
Correct Answer: C
Vote an answer
You are preparing to start the qualitative risk analysis process for your project. You will be relying on some organizational process assets to influence the process. Which one of the following is NOT a probable reason for relying on organizational process assets as an input for qualitative risk analysis? Response:
Correct Answer: A
Vote an answer
The process of determining the security category for information or an information system.
Security categorization methodologies are described in CNSS Instruction 1253 for national security systems and in FIPS 199 for other than national security systems Response:
Security categorization methodologies are described in CNSS Instruction 1253 for national security systems and in FIPS 199 for other than national security systems Response:
Correct Answer: B
Vote an answer
Applying the first three steps in the RMF to legacy systems can be viewed in what way to determine if the necessary and sufficient security controls have been appropriately selected and allocated? Response:
Correct Answer: D
Vote an answer
The test plan should evaluate plans that support the IS; such as Incident Response, Disaster Recovery, and _______________ Plan to ensure they are up to date & meet the protection needs of the system Response:
Correct Answer: A
Vote an answer
In which of the following phases do the system security plan update and the Plan of Action and Milestones (POAM) update take place?
Response:
Response:
Correct Answer: D
Vote an answer
Which NIST publication provides guidance on the three tiers in the risk management hierarchy including Tier 1, Tier 2, and Tier 3?
Response:
Response:
Correct Answer: D
Vote an answer
Which of the three-tiered approaches to risk management address risk at the IS security control level & their allocation?
Response:
Response:
Correct Answer: D
Vote an answer
An organization monitors the hard disks of its employees' computers from time to time. Which policy does this pertain to?
Response:
Response:
Correct Answer: D
Vote an answer
An occurrence that actually or potentially jeopardizes the confidentiality, integrity, or availability of an information system or the information the system processes, stores, or transmits or that constitutes a violation or imminent threat of violation of security policies, security procedures, or acceptable use policies.
Response:
Response:
Correct Answer: D
Vote an answer
Developmental testing and evaluation is a type of control Assessment and its activities include the following except one.
Response:
Response:
Correct Answer: A
Vote an answer
One of the primary goals in conducting analysis of the test results from a scan during Security Control Assessment (SCA) is to Response:
Correct Answer: D
Vote an answer