ISC2 Governance, Risk and Compliance (CGRC) Practice Question

During a pre-authorization quality review, you discover that a section of the draft System Security Plan (SSP) for a new federal moderate-impact system is blank. Without this information, the Authorizing Official cannot confirm that the selected NIST SP 800-53 baseline is appropriate. Which missing element must be completed before the package is submitted?

  • The schedule for the next annual penetration test

  • The system's FIPS 199 security categorization results

  • A list of outstanding POA&M findings and milestones

  • Copies of vendor hardware and software maintenance contracts

ISC2 Governance, Risk and Compliance (CGRC)
System Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot