ISC2 Governance, Risk and Compliance (CGRC) Practice Question

While performing scoping and applicability analysis for a new moderate-impact SaaS, you note that physical security of the hosting data center is already covered by the cloud provider. What is the appropriate way to treat NIST SP 800-53 control PE-3 in your System Security Plan?

  • Replace PE-3 with a compensating control such as enhanced logical access monitoring at the application layer.

  • List PE-3 as Not Applicable and delete it from the control summary since no on-premises equipment exists.

  • Identify PE-3 as an inherited control and reference the cloud provider's authorization evidence in the SSP.

  • Reassess the information system as low-impact so that PE-3 is no longer selected from the baseline.

ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot