ISC2 Governance, Risk and Compliance (CGRC) Practice Question
To mitigate SQL injection risks on a public e-commerce site, the security team evaluates several proposals. Under NIST SP 800-53 control categories, which proposal represents a technical control rather than a management or operational control?
Engage an external firm to conduct annual penetration tests of the web application.
Require developers to follow a secure coding policy and complete code-review checklists before each release.
Provide mandatory quarterly security awareness training on injection vulnerabilities for all developers.
Deploy a web application firewall that inspects and blocks malicious SQL queries in real time.
A web application firewall is considered a technical control because it is implemented and executed by hardware or software that automatically enforces security functions-in this case, filtering and blocking malicious SQL queries. A secure coding policy with code-review checklists constitutes a management control, as it establishes governance and procedures. Developer security awareness training is an operational control carried out by personnel. Contracting periodic penetration tests is generally viewed as a management or operational oversight activity. Therefore, only the deployment of a web application firewall fits the definition of a technical control.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is NIST SP 800-53, and how does it categorize controls?
Open an interactive chat with Bash
How does a web application firewall (WAF) work to mitigate threats like SQL injection?
Open an interactive chat with Bash
Why is secure coding considered a management control rather than a technical control?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Implementation of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .