ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While drafting the assessment project plan for a high-impact financial application, you discover that the team's commercial web-application scanner license will expire midway through testing. Two system administrators are already assigned and travel costs are funded. What is the most appropriate next step to ensure resources are properly allocated within the fixed budget and schedule?
Postpone the entire assessment until the next fiscal year when new funds are available for tool licensing.
Remove the vulnerability scanning portion from the assessment to stay within the current budget.
Proceed without action; perform manual configuration reviews instead of using an automated scanner when the license lapses.
Update the resource plan to cover renewal of the current scanner or procure a cost-effective alternative, and obtain stakeholder approval before finalizing the assessment plan.
A core task in preparing for an assessment is to confirm that all required resources-personnel, tools, and funds-will be available for the entire effort. Because the web-application scanner will lapse during execution, the assessor must revise the resource plan to address this gap (for example, by budgeting for renewal or selecting a lower-cost tool) and obtain stakeholder approval before finalizing the plan. Simply dropping the scanning activity or hoping manual reviews will suffice would compromise the agreed-upon scope and weaken control coverage, while delaying the assessment would disrupt the schedule and could violate compliance deadlines.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a web-application scanner and why is it important in a security assessment?
Open an interactive chat with Bash
Why is stakeholder approval necessary before finalizing the assessment plan?
Open an interactive chat with Bash
How do resource plans contribute to successful risk assessments?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Assessment/Audit of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .