ISC2 Governance, Risk and Compliance (CGRC) Practice Question

During the Select step of the RMF, you must establish a security control baseline for an information system that FIPS 199 has categorized as MODERATE impact. Which statement best describes how the NIST SP 800-53 moderate-impact baseline is constructed?

  • It replaces the low-impact control set with entirely new, stronger controls, and excludes any controls that appear only in the low baseline.

  • It retains every control in the low-impact baseline and adds the controls and enhancements specifically identified for moderate (M) impact systems.

  • It is selected solely at the Authorizing Official's discretion and does not depend on FIPS 199 impact categorization or FIPS 200 requirements.

  • It consists exclusively of controls that NIST labels moderate (M), intentionally omitting low (L) controls to avoid redundancy.

ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot