ISC2 Governance, Risk and Compliance (CGRC) Practice Question
Your team is deploying a mission-owner application on an IaaS cloud that already has FedRAMP Moderate authorization. When drafting the System Security Plan, you must show which requirements are fully inherited from the cloud provider. Which control would you MOST likely mark as inherited with no implementation statement of your own?
PE-2 Physical access authorizations for the cloud facilities
CM-6 Applying security patches to guest operating-system images
SI-10 Input validation for web form fields in the application code
AC-2 Provisioning and deprovisioning of application-level user roles
Physical and environmental protection of the cloud data centers, represented by NIST SP 800-53 control PE-2 (Physical Access Authorizations), is implemented and continuously managed by the cloud provider as part of its FedRAMP authorization. Because the mission-owner application cannot influence badge systems, guards, or visitor-escort procedures, the responsibility is entirely the CSP's, so the control is documented in the SSP as inherited. Application-level input validation, in-guest operating-system patching, and role assignment inside the application all reside within the customer's boundary; therefore they are implemented (or at least shared) by the system owner and cannot be recorded as fully inherited.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does PE-2 (Physical Access Authorizations) entail in NIST SP 800-53?
Open an interactive chat with Bash
What is FedRAMP Moderate authorization?
Open an interactive chat with Bash
What is the difference between inherited and customer-implemented controls?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Selection and Approval of Framework, Security, and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .