ISC2 Governance, Risk and Compliance (CGRC) Practice Question

During continuous monitoring, your monthly authenticated vulnerability scan on a production web server reveals a medium-impact security weakness that cannot be fully remediated during the next maintenance window. Under RMF guidance, what is the FIRST action you should take with respect to the Plan of Action and Milestones (POA&M)?

  • Reclassify the finding as low impact and close it so it does not have to be tracked on the POA&M.

  • Pause system operation and request immediate reauthorization from the Authorizing Official before updating any documentation.

  • Create or update the POA&M entry detailing the weakness, planned corrective actions, responsible party, and target completion date.

  • Modify the System Security Plan to mark the affected control as not-applicable until the fix can be applied, noting it at the next annual review.

ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot