ISC2 Governance, Risk and Compliance (CGRC) Practice Question
A federal agency deploying a legacy application discovers the software cannot support the FIPS-validated encryption required by SC-13 (Cryptographic Protection) in the NIST SP 800-53 moderate baseline. Which action would serve as an effective compensating control to meet the intent of SC-13 while allowing the system to operate?
Place a reverse proxy that terminates all client connections using a FIPS 140-validated TLS module, then forwards traffic to the legacy application on an isolated internal network.
Increase vulnerability scanning of the legacy server from quarterly to monthly to identify unencrypted traffic more quickly.
Depend on existing badge-controlled physical access to the data center to prevent unauthorized interception of network traffic.
Postpone the system's Authorization to Operate until the vendor releases a FIPS-compliant version and document the delay in the POA&M.
SC-13 requires that data in transit be protected using FIPS-validated cryptographic mechanisms. When a legacy application cannot meet this requirement directly, a compensating control must provide security comparable to the original control. Terminating all network sessions at a reverse proxy that uses a FIPS 140-validated TLS module delivers the mandated cryptographic protection without modifying the legacy code, thereby satisfying the control's objective. Simply increasing scan frequency detects issues but does not provide encryption, physical access restrictions do not secure data in transit, and deferring deployment leaves the requirement unmet rather than compensating for it.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is FIPS validation in encryption?
Open an interactive chat with Bash
What is the role of a reverse proxy?
Open an interactive chat with Bash
What does SC-13 and NIST SP 800-53 moderate baseline mean?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Implementation of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .