ISC2 Governance, Risk and Compliance (CGRC) Practice Question

During a vulnerability remediation sprint, a system administrator wants to fast-track a new kernel patch on a critical payment server to address a recently disclosed flaw. Under the organization's change management process, what is the administrator's first required step?

  • Submit a formal change request that includes risk and impact details for approval by the Change Control Board.

  • Schedule an emergency maintenance window and notify end users immediately after deploying the patch to production.

  • Update the security baseline documentation after installing the patch to reflect the new configuration.

  • Apply the patch in the development environment and, if tests pass, move it straight to production without additional approvals.

ISC2 Governance, Risk and Compliance (CGRC)
Compliance Maintenance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot