ISC2 Governance, Risk and Compliance (CGRC) Practice Question
After selecting the NIST SP 800-53 moderate baseline for a new cloud-hosted system, the risk assessment reveals that administrators will sometimes perform remote maintenance from personally owned laptops on untrusted networks. To apply an appropriate security practice as a control enhancement, which additional requirement should be documented in the System Security Plan (SSP)?
Reduce audit log retention from 90 to 30 days to minimize storage costs.
Disable automatic session timeouts to prevent disruption of long-running administrative tasks.
Require multifactor authentication for all privileged remote sessions.
Permit the use of legacy SSH version 1 clients for backward compatibility.
Because privileged users may connect from unmanaged, potentially insecure devices and networks, the threat of credential theft or session hijacking increases. Requiring multifactor authentication (MFA) for all privileged remote sessions is a widely adopted safeguard that aligns with NIST SP 800-53 Revision 5 control IA-2(11), which mandates MFA for remote access by both privileged and non-privileged users. Implementing MFA makes it far harder for attackers to compromise accounts with stolen passwords alone. By contrast, reducing log retention, allowing obsolete SSH v1, or disabling session timeouts would decrease security and fail to mitigate the identified risk.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is multifactor authentication (MFA) and why is it important?
Open an interactive chat with Bash
What is NIST SP 800-53 and why is it used in security frameworks?
Open an interactive chat with Bash
Why is remote maintenance from personal and unmanaged laptops risky?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .