ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While preparing for an external audit, a security compliance analyst reviews how the organization documents its required annual security and privacy awareness training. Which action will provide the strongest evidence that the AT-2 control is satisfied and that record-retention expectations under the RMF are being met?
Place the training slide deck and answer key on the corporate intranet so employees can consult the material at any time.
Report only the organization's overall training completion percentage on quarterly dashboards and delete the underlying user data after submission.
Archive individual completion certificates that include the employee's identifier, date of completion, and course title in a centrally managed repository for the full policy-mandated retention period.
Request a single email from each department head asserting that all staff have completed the awareness course.
AT-2 in NIST SP 800-53 requires the organization to document and retain records for each individual who completes security and privacy awareness training. Storing an individual certificate or electronically signed acknowledgement that shows the employee's identity, the date of completion, and the course taken-and keeping that record in a centrally managed repository for the period defined by policy-allows auditors to trace compliance back to every user. Merely posting training materials, relying on verbal or email attestations, or keeping only aggregate completion metrics does not meet the requirement for individual, reviewable evidence and will not satisfy audit demands.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the AT-2 control in NIST SP 800-53?
Open an interactive chat with Bash
Why is individual record retention required under AT-2?
Open an interactive chat with Bash
What is a centrally managed repository in RMF, and why is it important?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Compliance Maintenance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .