ISC2 Governance, Risk and Compliance (CGRC) Practice Question
Six weeks after an initial audit flagged an overly permissive firewall rule, the assessor returns to verify that the corrective action is effective. Which approach best satisfies the requirement to reassess and validate the remediation?
Test the firewall by attempting the previously allowed traffic and review the current rule set for correctness.
Examine the approved change request and the exported configuration file, without further steps.
Accept the system owner's attestation and close the finding because the remediation window has expired.
Interview the firewall administrator to confirm the change was made.
Validating a corrective action must generate objective evidence that the underlying deficiency is resolved. Merely interviewing the administrator or reviewing change paperwork provides limited assurance. Actively testing the firewall by sending traffic that should now be blocked and examining the live rule set combines the "test" and "examine" assessment methods recommended by NIST SP 800-53A for high-assurance verification. This directly demonstrates that the new control is functioning as intended. Accepting an attestation or relying solely on documentation leaves the effectiveness of the fix unproven.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is NIST SP 800-53A?
Open an interactive chat with Bash
Why is it important to test the firewall instead of trusting documentation or administrator interviews?
Open an interactive chat with Bash
What does 'overly permissive firewall rule' mean?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Assessment/Audit of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .