ISC2 Governance, Risk and Compliance (CGRC) Practice Question
During a security control assessment, you discover that system administrators produce configuration screenshots while you simultaneously export the device's running configuration file. To ensure the evidence can support audit findings, which action should you take next before closing the evidence collection activity?
Request additional artifacts from administrators to strengthen the body of evidence for the same control.
Log the screenshots and configuration file in the assessment evidence register, noting the related control identifiers and collection details.
Generate a cryptographic hash of each artifact to prove they were not altered after collection.
Encrypt both artifacts and upload them to the secure audit repository for long-term retention.
For evidence to withstand later scrutiny, each item must be correlated to the specific control objective it supports and accompanied by details on when, where, and how it was obtained. Recording this metadata in the assessment worksheet provides traceability and allows other reviewers to validate that the artifacts actually demonstrate control implementation. Simply storing the files, encrypting them, or asking for more artifacts does not in itself establish this linkage, nor does generating a forensic hash if no one can tell which control the evidence addresses.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an assessment evidence register?
Open an interactive chat with Bash
Why is metadata important for audit evidence?
Open an interactive chat with Bash
What is a control identifier in the context of security assessments?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Assessment/Audit of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .