ISC2 Governance, Risk and Compliance (CGRC) Practice Question
A legacy business partner cannot modify its software stack to meet the baseline control that mandates TLS 1.2 encryption for all external data transmissions to your organization. To preserve equivalent confidentiality and integrity without altering the application protocols, which action represents the most appropriate alternate control?
Document the gap in the POA&M and request the Authorizing Official to accept the risk.
Place a segmentation firewall and enable anomaly monitoring on the partner connection.
Lower the data classification so unencrypted transmission over private circuits is acceptable.
Establish a site-to-site IPSec VPN tunnel between the two gateway firewalls to encapsulate all traffic.
Creating a site-to-site IPSec VPN tunnel encrypts and authenticates every packet between the organizations, delivering confidentiality and integrity comparable to TLS 1.2 without requiring changes to either endpoint application. Simply downgrading the data classification or requesting risk acceptance leaves the traffic unprotected. Segmentation and monitoring can limit exposure but do not provide the encryption required to meet the original control's intent, so they are not an equivalent replacement.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is IPSec VPN and how does it provide confidentiality and integrity?
Open an interactive chat with Bash
Why is TLS 1.2 encryption important for external data transmissions?
Open an interactive chat with Bash
What is a POA&M, and why does documenting the gap not fulfill the control's intent?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Implementation of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .