ISC2 Governance, Risk and Compliance (CGRC) Practice Question
Your team is implementing NIST SP 800-53 controls on a legacy SCADA network. The security baseline calls for FIPS-validated full-disk encryption to satisfy control SC-28 (Protection of Information at Rest), but the controllers cannot support that capability. Which compensating measure best preserves confidentiality of stored data while remaining feasible on the platform?
Install an endpoint detection and response agent on each SCADA server to identify malware and anomalous behavior.
Implement role-based access control and file-level encryption of sensitive data using an approved algorithm, with keys protected in a hardware security module.
Mirror all SCADA traffic to a central SIEM for real-time alerting and long-term log retention.
Conduct quarterly penetration tests and vulnerability scans against the SCADA segment to uncover exploitable weaknesses.
Granular file- or database-level encryption combined with strict role-based access control and secure key storage in an HSM maintains the confidentiality of sensitive data at rest even when full-disk encryption is not feasible. It employs approved cryptographic mechanisms aligned with SC-28 and SC-13, protecting the data itself and restricting decryption to authorized roles. The other options emphasize detection, testing, or monitoring and do not deliver equivalent cryptographic protection for data at rest.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is SC-28 and why is it important in this context?
Open an interactive chat with Bash
What does an HSM do, and why is it vital in implementing file-level encryption?
Open an interactive chat with Bash
Why is role-based access control important for SCADA networks?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Implementation of Security and Privacy Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .