ISC2 Governance, Risk and Compliance (CGRC) Practice Question
A CGRC holds quarterly compliance reviews. You find production firewall configuration commits lack any linkage to approved change tickets, making audits difficult. Which control enhancement would most directly improve traceability while still allowing daily operational changes?
Disable configuration locking so multiple engineers can edit concurrently and speed up deployments.
Configure the change management or version-control tool to auto-insert the approved ticket ID into every commit and require signed commits.
Permit administrators to implement urgent rule changes directly on devices and record them manually at month-end.
Store all change documentation on an unversioned shared drive instead of in the change-tracking system.
Embedding the unique change-request identifier into every configuration commit binds the recorded system change to its formal approval record. This creates an auditable trail that shows who made the change, what was changed, and which ticket authorized it-fulfilling NIST SP 800-53 CM-3 requirements for documenting, approving, and tracking configuration changes. Simply uploading changes later, disabling locks, or keeping documentation outside the change tool weakens accountability and does not guarantee that each live change can be matched to an approved request.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is NIST SP 800-53 CM-3?
Open an interactive chat with Bash
How do signed commits improve traceability?
Open an interactive chat with Bash
Why is embedding ticket IDs into commits important for audits?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Compliance Maintenance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .