CGRC CGRC Information Security Controls 4 — Questions and Answers
Question 1: Which NIST SP 800-53 control family specifically addresses the protection of system and communications at the boundary of an information system?
- Access Control (AC)
- System and Communications Protection (SC) (Correct answer)
- Configuration Management (CM)
- Incident Response (IR)
Correct answer: System and Communications Protection (SC)
The SC (System and Communications Protection) family covers boundary protection, cryptographic controls, and network segmentation.
Question 2: An organization discovers that a compensating control is needed because implementing a required baseline control is technically infeasible. What document must be formally approved to justify this?
- Plan of Action and Milestones (POA&M)
- Security Assessment Report (SAR)
- Risk Acceptance Memo
- Plan of Action Waiver / Control Tailoring Justification (Correct answer)
Correct answer: Plan of Action Waiver / Control Tailoring Justification
A tailoring justification (sometimes called a waiver) must be documented and approved by the Authorizing Official when a baseline control cannot be implemented.
Question 3: Under NIST SP 800-53, which control requires organizations to monitor and control communications at external boundaries and key internal boundaries?
- SC-7 Boundary Protection (Correct answer)
- AC-17 Remote Access
- SI-3 Malicious Code Protection
- CA-3 Information Exchange
Correct answer: SC-7 Boundary Protection
SC-7 (Boundary Protection) specifically mandates monitoring and controlling network communications at external and key internal boundaries.
Question 4: A security control assessment reveals that an implemented control partially satisfies the stated requirements. How should this finding be categorized?
- Satisfied
- Other Than Satisfied — Control Deficiency (Correct answer)
- Not Applicable
- Compensating Control Accepted
Correct answer: Other Than Satisfied — Control Deficiency
NIST SP 800-53A uses 'Other Than Satisfied' to classify controls that are partially implemented or partially effective.
Question 5: Which of the following best describes the purpose of continuous monitoring in the context of NIST RMF Step 6?
- To eliminate the need for future security assessments
- To maintain ongoing awareness of security and privacy posture over time (Correct answer)
- To replace the Authorization to Operate once granted
- To automate all remediation activities without human oversight
Correct answer: To maintain ongoing awareness of security and privacy posture over time
RMF Step 6 (Monitor) aims to maintain ongoing situational awareness of the security and privacy posture of information systems.
Question 6: When conducting a security control assessment, which method involves the assessor executing a control procedure themselves to verify it works as intended?
- Examine
- Interview
- Test (Correct answer)
- Review
Correct answer: Test
The 'Test' assessment method in NIST SP 800-53A involves the assessor exercising or activating the control mechanism to observe its operation.
Question 7: An organization wants to ensure that sensitive data stored in a cloud environment is unreadable if the cloud provider is compromised. Which control approach best addresses this concern?
- Mandatory Access Control (MAC) enforced by the CSP
- Customer-managed encryption with keys stored outside the CSP (Correct answer)
- CSP-managed encryption at rest
- Data Loss Prevention (DLP) monitoring only
Correct answer: Customer-managed encryption with keys stored outside the CSP
Customer-managed encryption keys stored outside the CSP environment ensure data remains unreadable to the provider even if their infrastructure is breached.
Which NIST SP 800-53 control family specifically addresses the protection of system and communications at the boundary of an information system?