ISC2 Governance, Risk and Compliance (CGRC) Practice Question

During a federal agency's security categorization exercise, the assessor finds that for its most critical information type, confidentiality is rated Moderate, integrity Low, and availability High. Under FIPS 199 guidance, what overall impact level should be assigned to the system?

  • Assign separate impact levels for each control family instead of one overall rating.

  • Moderate, calculated by averaging the three impact values and rounding up.

  • Moderate, since confidentiality is often the primary consideration for federal systems.

  • High, because the highest single impact rating dictates the system's overall categorization.

ISC2 Governance, Risk and Compliance (CGRC)
Scope of the System
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot