최신ISC Certified in Governance Risk and Compliance - CGRC무료샘플문제
문제1
The tiers of the NIST RMF are
Response:
The tiers of the NIST RMF are
Response:
정답: B
문제2
Anything that can exploit a vulnerability, intentionally or accidentally, and obtain, damage, or destroy an asset best describes Response:
Anything that can exploit a vulnerability, intentionally or accidentally, and obtain, damage, or destroy an asset best describes Response:
정답: B
문제3
The point in time to which data must be recovered after an outage.
Response:
The point in time to which data must be recovered after an outage.
Response:
정답: A
문제4
What RMF role is primarily responsible for Tasks 1, 2, and 3 in Assessing Security Controls?
Response:
What RMF role is primarily responsible for Tasks 1, 2, and 3 in Assessing Security Controls?
Response:
정답: A
문제5
An assessment procedure consists of a set of which things, each with an associated set of potential assessment methods and assessment objects?
Response:
An assessment procedure consists of a set of which things, each with an associated set of potential assessment methods and assessment objects?
Response:
정답: B
문제6
Measure of confidence that the security features, practices, procedures, and architecture of an information system accurately mediates and enforces the security policy.
Response:
Measure of confidence that the security features, practices, procedures, and architecture of an information system accurately mediates and enforces the security policy.
Response:
정답: C
문제7
The scope of activities associated with a system, encompassing the system's initiation, development and acquisition, implementation and maintenance, and ultimately its disposal that instigates another system initiation best describes Response:
The scope of activities associated with a system, encompassing the system's initiation, development and acquisition, implementation and maintenance, and ultimately its disposal that instigates another system initiation best describes Response:
정답: C
문제8
To help review or design security controls, they can be classified by several criteri
To help review or design security controls, they can be classified by several criteri
정답: A
문제9
Which role in the security authorization process is responsible for organizational information systems? Response:
Which role in the security authorization process is responsible for organizational information systems? Response:
정답: C
문제10
A written plan for recovering one or more information systems at an alternate facility in response to a major hardware or software failure or destruction of facilities.
Response:
A written plan for recovering one or more information systems at an alternate facility in response to a major hardware or software failure or destruction of facilities.
Response:
정답: D
문제11
Organization official that's responsible for procurement, development, integration, modification, operation, maintenance, and disposal of an Information System.
Response:
Organization official that's responsible for procurement, development, integration, modification, operation, maintenance, and disposal of an Information System.
Response:
정답: B