ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While completing the System Security Plan for a new cloud-hosted case-management application, the GRC analyst must write the subsection that documents the system's purpose and functionality. Which of the following draft sentences BEST satisfies that specific requirement?
The application enables investigators to log, track, and report regulatory compliance cases from intake through closure, supporting the agency's enforcement mission.
The system consists of two Ubuntu 22.04 servers hosted in AWS, connected by a load balancer in the agency's VPC.
System downtime exceeding four hours will degrade field operations and must be reported to the CIO within one business day.
All stored data is encrypted with AES-256 and all traffic is protected by TLS 1.3 to safeguard Controlled Unclassified Information.
The purpose and functionality subsection should explain what mission or business processes the information system supports and what it does from an operational perspective. Describing that the application "enables investigators to log, track, and report regulatory compliance cases from intake through closure, supporting the agency's enforcement mission" clearly articulates both the business function (regulatory case management) and how the system fulfills it. The other statements focus on architecture details, security controls, or continuity expectations, none of which constitute a direct description of the system's mission-supporting purpose.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the System Security Plan (SSP)?
Open an interactive chat with Bash
What does 'purpose and functionality' in the SSP entail?
Open an interactive chat with Bash
Why are architecture details, security controls, or continuity expectations separate from purpose and functionality in an SSP?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Scope of the System
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .