VIP Exclusive

CGRC Certified Governance, Risk and Compliance VIP Practice Exam II

CGRC — The CGRC (Certified in Governance, Risk and Compliance), formerly CAP, is issued by (ISC)² and validates expertise in the NIST Risk Management Framework (RMF); the exam consists of 125 questions, has a 3-hour time limit, and requires a scaled score of 700 out of 1000 to pass.

29
Questions
180m
Time Limit
70.00%
To Pass
Question 1 of 29👑 VIP

A federal agency is preparing to authorize a new cloud-based case management system. The system will process Controlled Unclassified Information (CUI) and will be hosted by a FedRAMP-authorized cloud service provider (CSP). The Information System Security Officer (ISSO) is reviewing which security controls can be inherited from the CSP's existing authorization package. Which NIST RMF concept BEST describes the approach the ISSO should use to document these relationships?

Questions 2–29 and full explanations are VIP-exclusive.