ISC2 Governance, Risk and Compliance (CGRC) Practice Question

Your agency is developing a new cloud-based benefits portal using a secure SDLC. The team has completed requirements and is now entering the design phase. Which security activity should receive top priority during this phase to embed security early?

  • Conduct penetration testing of the staging environment to validate deployed controls.

  • Define and document the system's security architecture, selecting and allocating appropriate controls.

  • Perform static code analysis to identify vulnerabilities in application source code.

  • Draft and execute a media sanitization plan for retiring legacy components.

ISC2 Governance, Risk and Compliance (CGRC)
Security and Privacy Governance, Risk Management, and Compliance Program
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot