ISC2 Certified in Governance, Risk and Compliance (CGRC) – Quiz 1 / 15 Category: ISC2 Certified in Governance, Risk and Compliance (CGRC) 1. Which of the following individuals is responsible for the final accreditation decision? A. Certification Agent B. User Representative C. Information System Owner D. Risk Executive 2 / 15 Category: ISC2 Certified in Governance, Risk and Compliance (CGRC) 2. Which of the following acts promote a risk-based policy for cost effective security? A. Clinger-Cohen Act B. Lanham Act C. Computer Misuse Act D. Paperwork Reduction Act (PRA) 3 / 15 Category: ISC2 Certified in Governance, Risk and Compliance (CGRC) 3. You are the project manager for TTP project. You are in the Identify Risks process. You have to create the risk register. Which of the following are included in the risk register? A. List of potential responses B. List of identified risks C. List of mitigation techniques D. List of key stakeholders 4 / 15 Category: ISC2 Certified in Governance, Risk and Compliance (CGRC) 4. Which of the following acts is used to recognize the importance of information security to the economic and national security interests of the United States? A. Computer Fraud and Abuse Act B. FISMA B. FISMA D. Computer Misuse Act 5 / 15 Category: ISC2 Certified in Governance, Risk and Compliance (CGRC) 5. Numerous information security standards promote good security practices and define frameworks or systems to structure the analysis and design for managing information security controls. Which of the following are the international information security standards? A. Human resources security B. Organization of information security C. Risk assessment and treatment D. AU audit and accountability 6 / 15 Category: ISC2 Certified in Governance, Risk and Compliance (CGRC) 6. Which of the following processes is used to protect the data based on its secrecy, sensitivity, or confidentiality? A. Change Control B. Data Hiding C. Configuration Management D. Data Classification 7 / 15 Category: ISC2 Certified in Governance, Risk and Compliance (CGRC) 7. Which of the following is NOT a phase of the security certification and accreditation process? A. Initiation B. Security certification C. Operation D. Maintenance 8 / 15 Category: ISC2 Certified in Governance, Risk and Compliance (CGRC) 8. Which of the following is NOT considered an environmental threat source? A. Pollution B. Hurricane C. Chemical D. Water 9 / 15 Category: ISC2 Certified in Governance, Risk and Compliance (CGRC) 9. A part of a project deals with the hardware work. As a project manager, you have decided to hire a company to deal with all hardware work on the project. Which type of risk response is this? A. Avoidance B. Mitigation C. Exploit D. Transference 10 / 15 Category: ISC2 Certified in Governance, Risk and Compliance (CGRC) 10. Management wants you to create a visual diagram of what resources will be utilized in the project deliverables. What type of a chart is management asking you to create? A. Work breakdown structure B. Resource breakdown structure C. RACI chart D. Roles and responsibility matrix 11 / 15 Category: ISC2 Certified in Governance, Risk and Compliance (CGRC) 11. Which of the following is an entry in an object’s discretionary access control list (DACL) that grants permissions to a user or group? A. Access control entry (ACE) B. Discretionary access control entry (DACE) C. Access control list (ACL) D. Security Identifier (SID) 12 / 15 Category: ISC2 Certified in Governance, Risk and Compliance (CGRC) 12. Adrian is the project manager of the NHP Project. In her project there are several work packages that deal with electrical wiring. Rather than to manage the risk internally she has decided to hire a vendor to complete all work packages that deal with the electrical wiring. By removing the risk internally to a licensed electrician Adrian feels more comfortable with project team being safe. What type of risk response has Adrian used in this example? A. Mitigation B. Transference C. Avoidance D. Acceptance 13 / 15 Category: ISC2 Certified in Governance, Risk and Compliance (CGRC) 13. Information risk management (IRM) is the process of identifying and assessing risk, reducing it to an acceptable level, and implementing the right mechanisms to maintain that level. What are the different categories of risk? Each correct answer represents a complete solution. Choose all that apply. A. System interaction B. Human interaction C. Equipment malfunction D. Inside and outside attacks E. Social status F. Physical damage 14 / 15 Category: ISC2 Certified in Governance, Risk and Compliance (CGRC) 14. Gary is the project manager of his organization. He is managing a project that is similar to a project his organization completed recently. Gary has decided that he will use the information from the past project to help him and the project team to identify the risks that may be present in the project. Management agrees that this checklist approach is ideal and will save time in the project. Which of the following statement is most accurate about the limitations of the checklist analysis approach for Gary? A. The checklist analysis approach is fast but it is impossible to build and exhaustive checklist. B. The checklist analysis approach only uses qualitative analysis. C. The checklist analysis approach saves time, but can cost more. D. The checklist is also known as top down risk assessment 15 / 15 Category: ISC2 Certified in Governance, Risk and Compliance (CGRC) 15. Which of the following recovery plans includes a monitoring process and triggers for initiating planned actions? A. Business continuity plan B. Contingency plan C. Continuity of Operations Plan D. Disaster recovery plan Your score is 0% Restart quiz Send feedback