ISC2 Governance, Risk and Compliance (CGRC) Practice Question

During the operations and maintenance phase of a FIPS 199 moderate-impact federal information system, a vendor releases a security patch that addresses a newly discovered vulnerability. According to NIST guidance, what should the security practitioner do before authorizing deployment of the patch to production?

  • Apply the patch to the production environment immediately, deferring testing to the next scheduled maintenance window.

  • Conduct a security impact analysis to evaluate how the patch affects existing controls and authorizations.

  • Decommission the affected software component and begin media sanitization procedures.

  • Update the Plan of Actions and Milestones to document the vulnerability and its planned remediation date.

ISC2 Governance, Risk and Compliance (CGRC)
Security and Privacy Governance, Risk Management, and Compliance Program
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot