ISC2 Governance, Risk and Compliance (CGRC) Practice Question

A development team proposes adding real-time database replication to a new cloud availability zone to improve application performance. As the information system security officer (ISSO), what is the FIRST action you should take to decide whether this change can proceed without violating the system's approved security and privacy baselines?

  • Update the plan of action and milestones (POA&M) with potential vulnerabilities introduced by replication before analyzing the change.

  • Request that the Change Control Board schedule the production rollout during a low-usage maintenance window.

  • Conduct a formal security impact analysis to determine which existing controls will be affected or need enhancement.

  • Deploy the replication feature in a test environment and rely on continuous monitoring to discover any control gaps.

ISC2 Governance, Risk and Compliance (CGRC)
Compliance Maintenance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot