ISC2 Governance, Risk and Compliance (CGRC) Practice Question

Your project has moved from design into coding, and developers are writing new application modules. To embed security controls during the Development phase of the SDLC, which activity should you prioritize before the code is compiled or executed?

  • Perform a post-implementation review of system audit logs to confirm security-relevant events were recorded.

  • Develop and approve the media sanitization and disposal plan for components reaching end-of-life.

  • Submit the system package to the Authorizing Official to obtain a formal Authorization to Operate (ATO).

  • Run static application security testing tools against the new source code to detect insecure constructs early.

ISC2 Governance, Risk and Compliance (CGRC)
Security and Privacy Governance, Risk Management, and Compliance Program
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot