ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While cataloging the data handled by an enterprise system, you must document the applicable safeguards for each information type. Which pairing of data type and typical handling requirement is accurate and aligns with commonly accepted regulatory or industry standards?
Technical drawings subject to ITAR - classify as Protected Health Information and apply HIPAA Security Rule controls.
Primary account numbers for credit cards - encrypt in transit and at rest in accordance with PCI DSS.
Employees' Social Security numbers - mark as Controlled Unclassified Information and apply the full NIST 800-171 control set.
Public marketing brochures - restrict access to authorized caregivers under the HIPAA Privacy Rule.
Primary account numbers (PANs) and other cardholder data fall under the Payment Card Industry Data Security Standard (PCI DSS). That standard explicitly requires protecting cardholder data when it is stored (Requirement 3) and encrypting it with strong cryptography whenever it is transmitted across open, public networks (Requirement 4). The other pairings are incorrect: ITAR-controlled technical data is not governed by HIPAA; Social Security numbers are usually treated as PII rather than automatically handled as CUI under NIST 800-171; publicly available marketing brochures do not require HIPAA caregiver access restrictions.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is PCI DSS and why is it important for handling credit card data?
Open an interactive chat with Bash
How do NIST 800-171 controls differ from PCI DSS requirements?
Open an interactive chat with Bash
What types of data fall under the ITAR regulations, and how is it different from HIPAA?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Scope of the System
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .