ISC2 Governance, Risk and Compliance (CGRC) Practice Question
During weekly automated continuous-monitoring scans, you discover that several production servers within the system's authorization boundary are missing a newly released critical security patch. According to NIST Risk Management Framework guidance for ongoing authorization, what should be your first response to maintain an acceptable risk posture?
First record the missing patch in the Plan of Action and Milestones and assign remediation dates.
Disable the monitoring sensors temporarily to suppress further alerts until maintenance can be scheduled.
Apply the critical patch (or implement an approved interim mitigation) immediately, then update documentation.
Delay any action until the next scheduled security assessment to gather corroborating evidence.
Under RMF Step 7 (Monitor) and the broader continuous-monitoring strategy (per NIST SP 800-37 Rev. 2 and SP 800-137), organizations are expected to respond to newly discovered vulnerabilities as quickly as practical. The immediate action is to eliminate or reduce the risk-by installing the critical patch or, if that is temporarily infeasible, deploying an approved interim mitigation. After the corrective action is initiated, the weakness is documented in the Plan of Action and Milestones (POA&M) so that remediation efforts, responsible parties, and target dates can be tracked. Deferring action, turning off sensors, or submitting a full re-authorization package are not required initial steps and would leave the system exposed or impose unnecessary administrative burden.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the NIST Risk Management Framework (RMF)?
Open an interactive chat with Bash
What is a Plan of Action and Milestones (POA&M)?
Open an interactive chat with Bash
What is an approved interim mitigation?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Security and Privacy Governance, Risk Management, and Compliance Program
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .