[2024] Get Top-Rated ISC CGRC Exam Dumps Now [Q10-Q35]

Share

[2024] Get Top-Rated ISC CGRC Exam Dumps Now

Passing Key To Getting CGRC Certified Exam Engine PDF

NEW QUESTION # 10
What is the purpose of a Privacy impact assessment?
Response:

  • A. To determine the level of voilation of CIA
  • B. To determine if the information system processes PII
  • C. To determine the extent to which proposed or actual changes to the system or its environment of operation can affect or have affected the system's security posture
  • D. To determine the level of impact of the violation of the confidentiality of PII

Answer: D


NEW QUESTION # 11
Which reference document describes the contents of a Plan of Action and Milestone (POA&M) updating and replacing OMB M 02-01?
Response:

  • A. OMB M-04-09
  • B. OMB M-02-14
  • C. OMB M 02-11
  • D. OMB M-02-09

Answer: D


NEW QUESTION # 12
A major subdivision or component of an information system consisting of information, information technology, and personnel that perform one or more specific functions.
Response:

  • A. Fix system
  • B. Closed system
  • C. Open system
  • D. Subsystem

Answer: D


NEW QUESTION # 13
POAM update frequency is at discretion of System Owner but should be frequent enough to provide an accurate status of progress in remediation.
Response:

  • A. True
  • B. False

Answer: A


NEW QUESTION # 14
The authorizing official may choose to authorize the system to operate only for a short period of time if it is necessary to test the system in the environment of operation before all controls are fully in place.
This type of authorization was formally referred to as:
Response:

  • A. Authorization to use common controls
  • B. Interim authority to test
  • C. Authorization to test
  • D. Authorization to operate

Answer: B


NEW QUESTION # 15
At which point in the Risk Management Framework (RMF) process is a system analyzed for changes that impact the security and privacy posture of the system?
Response:

  • A. Select
  • B. Monitor
  • C. Assess
  • D. Implement

Answer: B


NEW QUESTION # 16
Shoulder surfing is a type of in-person attack in which the attacker gathers information about the premises of an organization. This attack is often performed by looking surreptitiously at the keyboard of an employee's computer while he is typing in his password at any access point such as a terminal/Web site.
Which of the following is violated in a shoulder surfing attack? Response:

  • A. Integrity
  • B. Confidentiality
  • C. Availability
  • D. Authenticity

Answer: B


NEW QUESTION # 17
Any information about an individual maintained by an agency, including (1) any information that can be used to distinguish or trace an individual's identity, such as name, social security number, date and place of birth, mother's maiden name, or biometric records; and (2) any other information that is linked or linkable to an individual, such as medical, educational, financial, and employment information.
Response:

  • A. Personally Identifiable Information (PII)
  • B. Core Nodal Switching Subsystem (CNSS)
  • C. Industry Standard Architecture (ISA)
  • D. Privacy Impact Assessment (PIA)

Answer: A


NEW QUESTION # 18
All components of an information system to be authorized for operation by an authorizing official and excludes separately authorized systems, to which the information system is connected best defines:
Response:

  • A. Authorization Boundary
  • B. Network Boundary
  • C. System Boundary
  • D. Creditation Boundary

Answer: A


NEW QUESTION # 19
In which of the following testing methodologies do assessors use all available documentation and work under no constraints, and attempt to circumvent the security features of an information system? Response:

  • A. Penetration test
  • B. Full operational test
  • C. Walk-through test
  • D. Paper test

Answer: A


NEW QUESTION # 20
Which role has the supporting responsibility to coordinate changes to the system, assess the security impact and update the system security plan?
Response:

  • A. Senior agency information security officer
  • B. Common control provider
  • C. Information system owner (ISO)
  • D. Information system security officer (ISSO)

Answer: D


NEW QUESTION # 21
What are the four business areas of BRM?
Response:

  • A. 1. purpose of government (missions or services to citizens)
    2. mechanisms the government uses to achieve its purpose(modes of delivery)
    3. support functions necessary to conduct government ((missions or services to citizens)
    4. resource management functions that support all areas of the government's business (support delivery of services)
  • B. 1. support functions necessary to conduct government (support delivery of services)
    2. resource management functions that support all areas of the government's business (management of resources)
    3. mechanisms the government uses to achieve its purpose (missions or services to citizens)
    4. purpose of government (modes of delivery)
  • C. 1. purpose of government (support delivery of services)
    2. mechanisms the government uses to achieve its purpose(modes of delivery)
    3. resource management functions that support all areas of the government's business (missions or services to citizens)
    4. support functions necessary to conduct government (support delivery of services)
  • D. 1. purpose of government (missions or services to citizens)
    2. mechanisms the government uses to achieve its purpose(modes of delivery)
    3. support functions necessary to conduct government (support delivery of services)
    4. resource management functions that support all areas of the government's business (management of resources)

Answer: D


NEW QUESTION # 22
Testing must include an assessment of the _____________ as described in the system security plan, as recorded in the risk assessment, and reflected in the accreditation boundary; all should be the same.
Response:

  • A. System Boundary
  • B. Authorization Boundary
  • C. All of the above
  • D. None of these
  • E. Network Boundary

Answer: A


NEW QUESTION # 23
The RMF Step and task where the security controls are selected and documented in the Security Plan.
Response:

  • A. RMF Step 2, Task 4
  • B. RMF Step 2, Task 2
  • C. RMF Step 2, Task 1
  • D. RMF Step 2, Task 3

Answer: B


NEW QUESTION # 24
Which of the following acts is used to recognize the importance of information security to the economic and national security interests of the United States?
Response:

  • A. Computer Misuse Act
  • B. Lanham Act
  • C. Computer Fraud and Abuse Act
  • D. FISMA

Answer: D


NEW QUESTION # 25
The security controls for an information system that primarily are implemented by people (as opposed to systems) are known as Response:

  • A. Technical controls
  • B. Operational controls
  • C. Logical controls
  • D. Management controls

Answer: B


NEW QUESTION # 26
Which NIST Special publication provides guidance on security assessment reports? Response:

  • A. NIST SP 800-53A
  • B. NIST SP 800-18
  • C. NIST SP 800-37
  • D. NIST SP 800-53

Answer: A


NEW QUESTION # 27
The process of determining the security category for information or an information system.
Security categorization methodologies are described in CNSS Instruction 1253 for national security systems and in FIPS 199 for other than national security systems Response:

  • A. Adequate Security
  • B. Security Controls
  • C. Security Category
  • D. Security Categorization

Answer: D


NEW QUESTION # 28
Who has the responsibility to track corrective actions to their completion keeping the approving authority informed with periodic updates as directed?
Response:

  • A. The ISSSE
  • B. The ISSO
  • C. The ISO
  • D. The SISO

Answer: C


NEW QUESTION # 29
In which of the 6 steps of RMF is the System Boundary defined? Response:

  • A. Step 2
  • B. Step 3
  • C. Step 4
  • D. Step 1

Answer: D


NEW QUESTION # 30
NIST SP 800-64 Rev 2 has been withdrawn but security professionals can still find guidance on system development lifecycle in which Publication?
Response:

  • A. NIST SP 800-160
  • B. NIST SP 800-60
  • C. NIST SP 800-59
  • D. NIST SP 800-53

Answer: A


NEW QUESTION # 31
Which of the following tasks are identified by the Plan of Action and Milestones document? Each correct answer represents a complete solution. Choose all that apply.
Response:

  • A. Any milestones that are needed in meeting the tasks
  • B. The plans that need to be implemented
  • C. The resources needed to accomplish the elements of the plan
  • D. Scheduled completion dates for the milestones
  • E. The tasks that are required to be accomplished

Answer: A,C,D,E


NEW QUESTION # 32
You are the project manager for a construction project. The project includes a work that involves very high financial risks. You decide to insure processes so that any ill happening can be compensated. Which type of strategies have you used to deal with the risks involved with that particular work? Response:

  • A. Transfer
  • B. Accept
  • C. Avoid
  • D. Mitigate

Answer: A


NEW QUESTION # 33
Which of the following is used to indicate that the software has met a defined quality level and is ready for mass distribution either by electronic means or by physical media? Response:

  • A. CRO
  • B. ATM
  • C. RTM
  • D. DAA

Answer: C


NEW QUESTION # 34
Which of the following are the objectives of the security certification documentation task? Each correct answer represents a complete solution. Choose all that apply.
Response:

  • A. To assemble the final security accreditation package and then submit it to the authorizing o fficial
  • B. To provide the certification findings and recommendations to the information system owner
  • C. To update the system security plan based on the results of the security assessment
  • D. To prepare the Plan of Action and Milestones (POAM) based on the security assessment

Answer: A,B,C,D


NEW QUESTION # 35
......

CGRC exam questions for practice in 2024 Updated 725 Questions: https://www.actual4cert.com/CGRC-real-questions.html

CGRC Exam Dumps Pass with Updated Tests Dumps: https://drive.google.com/open?id=1TRVYjZZBqX0BNX4YaNITqJMCZhG70s_2