ISC2 Governance, Risk and Compliance (CGRC) Practice Question

Your organization's legacy industrial control system cannot support multi-factor authentication mandated by policy. Until the vendor provides a compliant update, which compensating control offers the most equivalent protection while remaining practical for day-to-day operations?

  • Increase the device's minimum password length to 12 characters and enforce 90-day password rotation.

  • Conduct semi-annual credential audits and vulnerability scans and record any weaknesses in the POA&M.

  • Place the control system in a dedicated, firewall-protected VLAN and require users to authenticate with MFA on a secured jump server before any access.

  • Add a login banner that warns users of monitoring and potential disciplinary action for unauthorized activities.

ISC2 Governance, Risk and Compliance (CGRC)
Implementation of Security and Privacy Controls
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot