ISC2 Governance, Risk and Compliance (CGRC) Practice Question
To mitigate SQL injection risks on a public e-commerce site, the security team evaluates several proposals. Under NIST SP 800-53 control categories, which proposal represents a technical control rather than a management or operational control?
Deploy a web application firewall that inspects and blocks malicious SQL queries in real time.
Provide mandatory quarterly security awareness training on injection vulnerabilities for all developers.
Engage an external firm to conduct annual penetration tests of the web application.
Require developers to follow a secure coding policy and complete code-review checklists before each release.
A web application firewall is considered a technical control because it is implemented and executed by hardware or software that automatically enforces security functions-in this case, filtering and blocking malicious SQL queries. A secure coding policy with code-review checklists constitutes a management control, as it establishes governance and procedures. Developer security awareness training is an operational control carried out by personnel. Contracting periodic penetration tests is generally viewed as a management or operational oversight activity. Therefore, only the deployment of a web application firewall fits the definition of a technical control.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is NIST SP 800-53, and how does it categorize controls?
Open an interactive chat with Bash
How does a web application firewall (WAF) work to mitigate threats like SQL injection?
Open an interactive chat with Bash
Why is secure coding considered a management control rather than a technical control?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Implementation of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .