CGRC Exam Question 136

Aggregate of directives, regulations, rules, and practices that prescribes how an organization manages, protects, and distributes information.
Response:
  • CGRC Exam Question 137

    A discussion-based exercise where personnel with roles and responsibilities in a particular IT plan meet in a classroom setting or in breakout groups to validate the content of the plan by discussing their roles during an emergency and their responses to a particular emergency situation. A facilitator initiates the discussion by presenting a scenario and asking questions based on the scenario.
    This best defines a...
    Response:
  • CGRC Exam Question 138

    A passive technique that monitors network communication, decodes protocols, and examines headers and payloads for information of interest. It is both a review technique and a target identification and analysis technique.
    Response:
  • CGRC Exam Question 139

    The level of assessor independence is determined based on applicable laws, executive orders, directives, regulations, policies, or standards. Who determines the level of assessor independence? Response:
  • CGRC Exam Question 140

    What may Colvine Tech do if they determine that the root cause of an unauthorized change is an adversarial attack?
    Response: