ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While categorizing a new federal case-management system under FIPS 199, you conclude that a successful attack could cause significant but not catastrophic financial losses and substantial impairment to agency operations. Confidentiality and integrity impacts are assessed as limited. Following FIPS 199's "high-water mark" methodology, which overall impact level should you record for the system?
Moderate
High
Separate ratings for each objective; no single overall impact level is required
FIPS 199 assigns three potential impact levels-low, moderate, and high-based on the expected adverse effect of a loss of confidentiality, integrity, or availability. The standard requires that the system's overall security categorization be set to the highest impact level identified among the three objectives (the so-called high-water mark). In this scenario, availability (and arguably integrity of services) is rated as causing serious, but not catastrophic, adverse effects-language that maps to the Moderate impact definition in FIPS 199. Because confidentiality and integrity are only limited (Low), the highest rating is Moderate, so the overall impact level for the system is Moderate. Options citing Low are incorrect because they ignore the serious operational and financial consequences identified. A High rating would be appropriate only if the effects were expected to be catastrophic or cause loss of life, which is not indicated here.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is FIPS 199?
Open an interactive chat with Bash
What is the high-water mark methodology?
Open an interactive chat with Bash
Why is availability rated higher in this scenario?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Scope of the System
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .