ISC2 Governance, Risk and Compliance (CGRC) Practice Question
During a quarterly continuous-monitoring meeting, the ISSO learns that a CVSS 9.8 privilege-escalation flaw was announced for the system's operating system. A vendor patch has passed internal testing and is available. Organizational policy, aligned with FISMA, requires critical patches be applied within 15 days or formally accepted as risk. Which action BEST maintains compliance?
Schedule installation of the patch in the next approved maintenance window within 15 days and document the action in the POA&M.
Request a waiver from the Authorizing Official to delay patching until the next major operating-system upgrade in six months.
Disable the affected listening port and close the vulnerability ticket as permanently mitigated without installing the patch.
Note the vulnerability in meeting minutes and postpone any action until the next quarterly review.
Applying the vendor patch within the policy's 15-day window eliminates the critical vulnerability and meets the requirement to perform timely security updates. Recording the activity in the POA&M provides the audit trail needed for ongoing risk tracking. Seeking a six-month waiver, closing the ticket after a temporary workaround, or postponing the decision until the next quarterly review all leave the system exposed and violate the defined remediation timeline, undermining both risk management and compliance obligations.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is CVSS and why is it important?
Open an interactive chat with Bash
What is a POA&M and why is it used in risk management?
Open an interactive chat with Bash
How does FISMA influence patch management policies?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Compliance Maintenance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .