ISC2 Governance, Risk and Compliance (CGRC) Practice Question

While finalizing the System Security Plan (SSP) for a new payroll platform, which element would BEST satisfy the system purpose and functionality requirement for the authorizing official?

  • The latest vulnerability scan report with findings categorized by criticality.

  • A table listing all IP subnets and hostnames allocated to the platform.

  • A rack diagram detailing server locations, power consumption, and cabling within the data center.

  • A narrative explaining how the application supports payroll processing, interfaces with HR and banking systems, and identifies primary user roles.

ISC2 Governance, Risk and Compliance (CGRC)
Scope of the System
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot