CGRC Security Assessment 4 — Questions and Answers
Question 1: Which assessment method involves evaluating security controls by reviewing documentation, interviewing personnel, and observing system behavior?
- Penetration testing
- Red team exercise
- Security control assessment (Correct answer)
- Threat modeling
Correct answer: Security control assessment
Security control assessments use three methods—examine, interview, and test—to determine if controls are implemented correctly and operating as intended.
Question 2: What is the primary risk associated with conducting a penetration test without a signed rules of engagement (ROE) document?
- The test results will not be legally admissible
- The assessor may face legal liability for activities that would otherwise be authorized (Correct answer)
- The test scope will automatically expand to all systems
- Findings cannot be included in the security assessment report
Correct answer: The assessor may face legal liability for activities that would otherwise be authorized
Without a signed ROE, penetration testing activities lack explicit authorization, which could expose assessors to criminal liability under computer fraud laws.
Question 3: During continuous monitoring, an organization detects a significant change to a critical system. What is the most appropriate immediate action?
- Wait until the next annual assessment to evaluate the change
- Assess the impact of the change on the system's security posture and update authorization documents (Correct answer)
- Immediately revoke the system's authorization to operate
- Notify all system users of the detected change
Correct answer: Assess the impact of the change on the system's security posture and update authorization documents
Significant changes trigger impact analysis to determine whether existing security controls remain adequate and whether reauthorization is needed.
Question 4: Which FedRAMP security assessment concept requires cloud service providers to maintain a continuously updated inventory of their security posture?
- Authority to Operate (ATO)
- Continuous Authorization
- Joint Authorization Board (JAB)
- Continuous Monitoring (ConMon) (Correct answer)
Correct answer: Continuous Monitoring (ConMon)
FedRAMP Continuous Monitoring (ConMon) requires CSPs to maintain ongoing visibility into their security posture through regular vulnerability scanning and reporting.
Question 5: An assessor is evaluating network segmentation controls. Which technique would best validate that segments are properly isolated?
- Reviewing firewall rule documentation only
- Conducting network traffic analysis and attempting cross-segment connections (Correct answer)
- Interviewing network engineers about segmentation design
- Checking change management logs for firewall modifications
Correct answer: Conducting network traffic analysis and attempting cross-segment connections
Actively testing network segments by attempting cross-segment connections provides empirical evidence that segmentation controls are functioning as intended.
Question 6: What distinguishes a red team exercise from a standard penetration test?
- Red team exercises are always conducted by external vendors
- Red team exercises simulate full adversary campaigns including physical and social engineering over an extended period (Correct answer)
- Penetration tests focus on physical security while red team exercises focus on network security
- Red team exercises do not produce written reports
Correct answer: Red team exercises simulate full adversary campaigns including physical and social engineering over an extended period
Red team exercises emulate realistic adversary campaigns using multiple attack vectors including physical intrusion and social engineering over extended timeframes, unlike focused penetration tests.
Question 7: Which control assessment method would be most appropriate to verify that an organization's incident response procedures are effective?
- Examining the incident response policy document
- Conducting a tabletop exercise or simulation (Correct answer)
- Interviewing the CISO about incident response priorities
- Reviewing past incident tickets for completeness
Correct answer: Conducting a tabletop exercise or simulation
Tabletop exercises and simulations test incident response procedures in practice, revealing gaps that documentation review or interviews cannot identify.
Which assessment method involves evaluating security controls by reviewing documentation, interviewing personnel, and observing system behavior?