ISC2 Governance, Risk and Compliance (CGRC) Practice Question

During the RMF Select step you have already determined that a new web-based employee self-service portal is "low impact" for confidentiality, integrity, and availability. However, it will collect and store employees' Social Security numbers and home addresses. According to NIST privacy-risk guidance, which single factor most clearly requires you to establish a separate privacy control baseline for the system?

  • The system is accessible from the public Internet, increasing its attack surface.

  • The system requires administrator accounts with broad privileged access.

  • The system is hosted in a FedRAMP Moderate cloud service environment.

  • The system will create, collect, process, or store personally identifiable information (PII).

ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot