최신 CGRC 무료덤프 - ISC Certified in Governance Risk and Compliance
Risks with low ratings of probability and impact are included on a ____ for future monitoring.
Response:
Response:
정답: C
A SCAP specification for communicating the characteristics of vulnerabilities and measuring their relative severity.
Response:
Response:
정답: C
The change control board team at Colvine Tech has determined the security impact of proposed changes to an application, what would be the team's next action? Response:
정답: B
Which of the following processes provides a standard set of activities, general tasks, and a management structure to certify and accredit systems, which maintain the information assurance and the security posture of a system or site?
Response:
Response:
정답: C
Which of the following components ensures that risks are examined for all new proposed change requests in the change control system?
Response:
Response:
정답: D
According to the Risk Management Framework (RMF), which role has a primary responsibility to report the security status of the information system to the authorizing official (AO) and other appropriate organizational officials on an ongoing basis in accordance with the monitoring strategy? Response:
정답: C
Overlays can be implemented as part of control tailoring. In which step of the assessment and authorization process is control tailoring done?
Response:
Response:
정답: A
Another term used to refer to a Security Controls Assessment or security review; is? Response:
정답: C
A set of specifications for a system, or Configuration Item (CI) within a system, that has been formally reviewed and agreed on at a given point in time, and which can be changed only through change control procedures. The baseline configuration is used as a basis for future builds, releases, and/or changes.
Response:
Response:
정답: C
The Software Development Life-Cycle phase that maps to RMF Step 2 (select controls), Task 4, SP Approval?
Response:
Response:
정답: B
Which of the following statements correctly describes DIACAP residual risk? Response:
정답: A
Which of the following control families belongs to the management class of security controls?
Response:
Response:
정답: D
What are the three classifications for security controls for information systems? Response:
정답: C
Which of the following professionals plays the role of a monitor and takes part in the organization's configuration management process?
Response:
Response:
정답: C