ISC2 Governance, Risk and Compliance (CGRC) Practice Question
While tailoring the security controls for a moderate-impact federal system, the team finds a legacy sensor that cannot use FIPS-validated cryptography required by control SC-13. Which action represents the most appropriate compensating control?
Route the sensor's traffic through a FIPS 140-validated encryption gateway that establishes an IPsec tunnel to all endpoints.
Record the limitation in the SSP and request an authorization waiver from the Authorizing Official without additional safeguards.
Disable encryption on the sensor and rely solely on an isolated VLAN to protect its network traffic.
Increase the frequency of manual audit log reviews on the sensor to once per day to detect anomalies.
Because the device cannot meet SC-13 directly, the organization must implement a control or set of controls that provide equivalent protection for data confidentiality and integrity. Terminating the sensor's traffic at a FIPS 140-validated encryption gateway and tunneling all communications through that secure channel achieves the same cryptographic strength that SC-13 intends, satisfies the requirement for FIPS-validated algorithms, and avoids modifying the legacy device. Simply documenting the deficiency or awaiting replacement without mitigation does not provide equivalent protection. Relying only on network segmentation or increased log reviews detects or limits exposure but does not deliver the necessary confidentiality safeguards, so those options do not fully compensate for the missing control.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is FIPS 140 validation and why is it required for cryptographic controls?
Open an interactive chat with Bash
What is an IPsec tunnel and how does it enhance security?
Open an interactive chat with Bash
What is the role of an encryption gateway in compensating for legacy devices?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .