ISC2 Governance, Risk and Compliance (CGRC) Practice Question
You are assessing a moderate-impact system that stores CUI in a SaaS file-sharing platform. The baseline requires encryption of data at rest with a FIPS 140-validated module, but the provider only supplies proprietary encryption that is not validated. Which compensating control most directly fulfills the underlying security objective?
Rely on the provider's SOC 2 Type II report as evidence the proprietary encryption is adequate.
Document a risk acceptance in the POA&M and defer action until the next authorization cycle.
Perform client-side encryption using a FIPS 140-validated module before files are uploaded to the service.
Place the SaaS URL behind the organization's web proxy that enforces TLS 1.2.
The baseline control seeks to ensure data at rest is protected with cryptography that has been independently validated under FIPS 140. Applying client-side encryption with a FIPS-validated module before data leaves the organization achieves the same confidentiality objective, even though the SaaS provider's storage layer lacks validation. Relying on a SOC 2 report does not guarantee FIPS compliance, while placing the service behind a TLS-enforcing proxy protects data in transit, not at rest. Simply accepting the risk postpones, rather than mitigates, the deficiency and therefore does not provide equivalent protection.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is CUI, and why does it need encryption?
Open an interactive chat with Bash
What is FIPS 140 and why is validation important?
Open an interactive chat with Bash
How does client-side encryption fulfill the baseline security requirement?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .