ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While preparing for a controls assessment, you need to collect evidence that the organization's encryption key-rotation control is functioning. Which artifact would provide the most persuasive operational evidence of compliance?
Last year's penetration test report covering encryption vulnerabilities
Interview notes with the cryptographic engineer describing the rotation procedure
A signed key-management policy requiring annual key rotation
System audit logs from the key-management tool confirming keys were rotated on schedule
System-generated audit logs that show when encryption keys were rotated demonstrate that the control is not only documented but is actually operating. Policies prove management intent, interviews give subjective assurance, and a penetration test focused on other vulnerabilities offers only indirect evidence. NIST SP 800-53A notes that records produced by the control itself are the strongest form of evidence for verifying operational effectiveness.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is key rotation in encryption?
Open an interactive chat with Bash
What is NIST SP 800-53A?
Open an interactive chat with Bash
Why are system audit logs considered persuasive operational evidence?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Assessment/Audit of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .