ISC2 Governance, Risk and Compliance (CGRC) Practice Question
After completing interviews, documentation reviews, and technical testing on a cloud-based payment system, you begin drafting the initial security assessment report that will be shared with the system owner and authorizing official. To ensure they can immediately start prioritizing and planning risk responses, which information must be captured in this preliminary report before distribution?
Formal executive signatures indicating acceptance of all residual risks
A concise statement of every identified risk, linking the deficient control to its likelihood, potential impact, and overall risk rating
A fully developed project schedule for installing new security tools to remediate the findings
Raw log files and the entire vulnerability-scanner output collected during testing
The initial assessment (or security assessment) report is expected to present the specific risks discovered during the assessment. For each deficient or missing control, the assessor should describe the vulnerability or control weakness, the associated threat scenario, and the potential impact, then assign a likelihood and overall risk rating. This concise risk statement enables stakeholders to understand severity and urgency so they can decide whether to accept, mitigate, transfer, or avoid each risk. Detailed remediation project plans, formal approval signatures, and complete technical evidence repositories are useful in later stages, but they are not required elements of the preliminary report and can overwhelm or mislead decision makers at this point.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does 'likelihood' refer to in the risk assessment process?
Open an interactive chat with Bash
What is meant by 'overall risk rating' in a security assessment report?
Open an interactive chat with Bash
Why is it important to link deficient controls to specific threats in a preliminary report?
Open an interactive chat with Bash
What is the purpose of a security assessment report in risk management?
Open an interactive chat with Bash
What is meant by likelihood and impact in the context of risk assessment?
Open an interactive chat with Bash
Why is it important to exclude raw technical evidence like log files in the preliminary assessment report?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Assessment/Audit of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .