ISC2 Governance, Risk and Compliance (CGRC) Practice Question

While preparing the SSP for a FISMA-moderate web service hosted in a FedRAMP Moderate IaaS, you analyze NIST SP 800-53 control PE-3 (Physical Access Control). The provider owns and documents all facility protections in its customer responsibility matrix. How should PE-3 be recorded in your SSP?

  • Classify PE-3 as a hybrid control because administrators still request badge access to visit the facility.

  • Remove PE-3 from the baseline, noting it is not applicable to virtualized workloads.

  • List PE-3 as system-specific since all Moderate-baseline controls must appear in every SSP.

  • Record PE-3 as an inherited control and reference the provider's FedRAMP package.

ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot