ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While tailoring the NIST SP 800-53 moderate baseline for a federal web application, the ISSO discovers the system exchanges protected health information between two internal subnets separated by a controlled interface in another enclave. To satisfy the added confidentiality need, which control enhancement or security practice should most immediately be incorporated?
Replace SC-7 boundary protection with AC-6 least privilege to restrict user permissions on the application servers.
Augment SC-8 with control enhancement (1) to require FIPS-validated cryptographic protection for information in transit across the interface.
Add MP-6 media sanitization procedures for disposal of decommissioned storage devices used by the application.
Implement AU-6(3) centralized correlation to improve detection of anomalous security events.
Because the data moves between security domains and contains protected health information, the baseline requirement for transmission protection must be strengthened with an explicit cryptographic safeguard. Control enhancement SC-8(1) extends the basic Transmission Confidentiality and Integrity control by requiring FIPS-validated encryption (or equivalent physical safeguards) for data in transit. The other options address different security objectives-least-privilege access (AC-6), media sanitization (MP-6), and audit log correlation (AU-6)-none of which mitigate the specific risk to data confidentiality during network transmission.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is NIST SP 800-53?
Open an interactive chat with Bash
What does FIPS-validated cryptographic protection mean?
Open an interactive chat with Bash
Why is SC-8(1) better for this scenario than other controls like AC-6 or MP-6?
Open an interactive chat with Bash
What is NIST SP 800-53?
Open an interactive chat with Bash
What does SC-8(1) specifically address?
Open an interactive chat with Bash
What is FIPS-validated cryptography?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .