ISC2 Governance, Risk and Compliance (CGRC) Practice Question

During continuous monitoring, a critical vendor patch is released for a production payroll system that stores sensitive employee data. Waiting for the next scheduled monthly maintenance window would leave the system exposed. What is the most appropriate next step to manage the identified risk while remaining compliant?

  • Take the server offline until a full reauthorization assessment can be completed.

  • Submit an emergency change request, test and deploy the patch through the expedited change process, and record any residual risk in the POA&M.

  • Document the finding as an accepted risk until the next regular maintenance window.

  • Apply the patch immediately in production without change-control approval to minimize the attack window.

ISC2 Governance, Risk and Compliance (CGRC)
Compliance Maintenance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot