최신ISC Certified in Governance Risk and Compliance - CGRC무료샘플문제
문제1
Which of the following roles is also known as the accreditor? Response:
Which of the following roles is also known as the accreditor? Response:
정답: C
문제2
Functional description of security control implementation must include which of the following, primarily as related to technical controls employed in the system? Response:
Functional description of security control implementation must include which of the following, primarily as related to technical controls employed in the system? Response:
정답: D
문제3
An organization monitors the hard disks of its employees' computers from time to time. Which policy does this pertain to?
Response:
An organization monitors the hard disks of its employees' computers from time to time. Which policy does this pertain to?
Response:
정답: D
문제4
Who plays the Central role in that he is responsible for system operation, implementation of security controls, and continuous monitoring.
Response:
Who plays the Central role in that he is responsible for system operation, implementation of security controls, and continuous monitoring.
Response:
정답: C
문제5
What are the responsibilities of a system owner?
Each correct answer represents a complete solution. Choose all that apply.
Response:
What are the responsibilities of a system owner?
Each correct answer represents a complete solution. Choose all that apply.
Response:
정답: A,B,C
문제6
Which of the following refers to a process that is used for implementing information security?
Response:
Which of the following refers to a process that is used for implementing information security?
Response:
정답: B
문제7
True or False; After an ATO is granted, ongoing continuous monitoring is performed on all identified security controls as well as physical environment, etc..
Response:
True or False; After an ATO is granted, ongoing continuous monitoring is performed on all identified security controls as well as physical environment, etc..
Response:
정답: A
문제8
The potential impact is high if-The loss of confidentiality, integrity, or availability could be expected to have a..........................
Response:
The potential impact is high if-The loss of confidentiality, integrity, or availability could be expected to have a..........................
Response:
정답: B
문제9
According to NIST SP 800-39, Managing Information System Risk, when an organization responds to risk by eliminating the activity or technology that are the basis for the risk, that organization is (accepting risk, avoiding risk, transferring risk, mitigating risk)? Response:
According to NIST SP 800-39, Managing Information System Risk, when an organization responds to risk by eliminating the activity or technology that are the basis for the risk, that organization is (accepting risk, avoiding risk, transferring risk, mitigating risk)? Response:
정답: D
문제10
In which of the following phases does the change management process start? Response:
In which of the following phases does the change management process start? Response:
정답: A
문제11
A security assessment plan comprises of all of the following except one Response:
A security assessment plan comprises of all of the following except one Response:
정답: D
문제12
What is the purpose for scoping guidance?
Response:
What is the purpose for scoping guidance?
Response:
정답: D