ISC2 Governance, Risk and Compliance (CGRC) Practice Question

While drafting the System Security Plan for a new web-based employee benefits portal, which of the following pieces of information best satisfies the requirement to describe the system's overall purpose and functionality from a business and operational perspective?

  • A network topology diagram that maps routers, switch ports, and firewall access control lists protecting the data center.

  • The most recent vulnerability scan results with associated findings and remediation deadlines.

  • A detailed inventory of each server's IP address, operating system version, and applied security patches.

  • A narrative explaining how the portal enables employees to enroll in benefits, identifies its primary user groups, and summarizes key functions such as payroll data exchange and HR reporting.

ISC2 Governance, Risk and Compliance (CGRC)
Scope of the System
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot