ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While preparing the System Security Plan (SSP) for an HR recruitment application, you must finalize the system boundary. Which component below should be treated as OUTSIDE the boundary and documented instead as an external service interface, assuming the described conditions are accurate?
The application database cluster on the same virtual private cloud and administered by the development team
The on-premises jump host used by administrators to manage production servers via SSH
A FedRAMP Moderate-authorized email notification API operated by a separate cloud provider and controlled through a service contract
A customer-facing web server hosted in the organization's AWS account and managed by the system owner
A component that is operated by another organization and authorized under a separate security package is normally considered external to the information system's authorization boundary. The FedRAMP-authorized email notification API is run by an independent cloud provider, governed by its own controls and assessment results, and is accessed through a contractual interface. Therefore, it should be recorded as an external service. The web server, database cluster, and on-premises jump host are all administered by the system owner (or the same administrative team) and reside in the same managed environment; they process, store, or transmit system data and so belong inside the system boundary.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a System Security Plan (SSP)?
Open an interactive chat with Bash
What is an authorization boundary?
Open an interactive chat with Bash
What is FedRAMP Moderate authorization?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Security and Privacy Governance, Risk Management, and Compliance Program
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .