ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While compiling the System Security Plan for a new grants-management platform hosted in a private cloud, the security team must establish the system's authorization boundary. Which component should be documented as residing inside that boundary instead of being treated as an external interconnection?
The agency's public website that simply redirects visitors to the platform's login page.
The virtual database cluster that stores applicant data within the same cloud VPC.
The third-party payment gateway the platform calls via an encrypted API.
The enterprise Security Operations Center that passively receives copies of audit logs.
The authorization boundary must encompass every asset that processes, stores, or transmits the system's information. The virtual database cluster performs the core data storage and processing for applicant records, so it is unquestionably part of the information system itself and belongs inside the boundary. The public website that merely redirects users, the third-party payment gateway accessed through an external API, and the enterprise SOC receiving log copies are all separate systems or services; they are documented as interconnections, not as components internal to the authorization boundary.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an authorization boundary in a System Security Plan (SSP)?
Open an interactive chat with Bash
Why is a virtual database cluster considered inside the authorization boundary?
Open an interactive chat with Bash
How are external interconnections documented in an SSP?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Scope of the System
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .