ISC2 Governance, Risk and Compliance (CGRC) Practice Question

An information system operating under a three-year Authorization to Operate (ATO) will reach its authorization termination date in 60 days. Continuous monitoring shows that all security controls remain effective. To keep the system online without interruption, what should the system owner do next?

  • Ask the information system security officer to issue a six-month temporary extension of the existing ATO.

  • Compile and transmit an updated authorization package to the authorizing official to obtain a new ATO before the current one expires.

  • Disable non-essential services on the expiration date and continue operating under the assumption that risk is minimal.

  • File the latest continuous monitoring results with no additional action until the system undergoes a significant change.

ISC2 Governance, Risk and Compliance (CGRC)
System Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot