TechNuggets Academy

Governance, Risk, and Compliance

Free CompTIA SecurityX practice — 6 questions on Governance, Risk, and Compliance, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Governance, Risk, and Compliance
A financial services organization must continuously prove compliance with PCI DSS 4.0 Requirement 11.3 (vulnerability scanning) to auditors without manual evidence collection every quarter. Which approach BEST achieves compliance-as-code for this requirement?
Automated ingestion of scanner output mapped to control IDs (e.g., via OSCAL) and rendered as live dashboards is the definition of compliance-as-code: continuous, machine-readable evidence rather than point-in-time manual collection.
Question 2 of 6 · Governance, Risk, and Compliance
A risk assessment determines a data center flood scenario has a Single Loss Expectancy (SLE) of $2,000,000 and an Annualized Rate of Occurrence (ARO) of 0.1. A proposed mitigation control costs $150,000 annually and would reduce the ARO to 0.02. Which statement correctly evaluates the control using Annualized Loss Expectancy (ALE)?
ALE = SLE x ARO. Before control: $2,000,000 x 0.1 = $200,000. After control: $2,000,000 x 0.02 = $40,000. The reduction ($160,000) exceeds the control cost ($150,000), so the control produces a net benefit of $10,000, justifying implementation.
Question 3 of 6 · Governance, Risk, and Compliance
An enterprise is evaluating a critical software vendor under a supply chain risk management program aligned with NIST SP 800-161. The vendor refuses to provide a Software Bill of Materials (SBOM) citing intellectual property concerns, but offers a signed attestation of secure development practices. Which action BEST addresses this scenario?
NIST SP 800-161 and related federal guidance (EO 14028) emphasize SBOM as a contractual requirement for critical suppliers because it provides component-level visibility (including transitive open-source dependencies) that attestations alone cannot deliver, enabling ongoing vulnerability management.
Question 4 of 6 · Governance, Risk, and Compliance
A US-based SaaS company processes personal data of EU residents and must transfer that data from EU-based servers to US-based servers following the invalidation of the original EU-US Privacy Shield framework. Which mechanism, when implemented with a Transfer Impact Assessment and supplementary technical measures, satisfies GDPR Chapter V cross-border transfer requirements?
Following Schrems II, SCCs remain a valid transfer mechanism only when paired with a documented Transfer Impact Assessment and supplementary technical safeguards (e.g., strong encryption) to address surveillance risk in the destination country.
Question 5 of 6 · Governance, Risk, and Compliance
A CISO defines the organization's risk appetite as 'moderate risk acceptance to achieve strategic growth objectives.' The board subsequently approves a specific rule stating that no single cybersecurity incident may cause more than $5 million in financial impact before mandatory board notification and escalation are triggered. Which risk management concept does the $5 million threshold represent?
Risk appetite is the broad, qualitative statement of how much risk an organization is willing to accept in pursuit of objectives; risk tolerance is the specific, quantifiable threshold that defines the acceptable variance and triggers escalation once breached — exactly what the $5 million figure represents.
Question 6 of 6 · Governance, Risk, and Compliance
A multinational enterprise must simultaneously comply with ISO 27001, NIST CSF 2.0, and SOC 2 Type II due to differing customer contractual requirements. The GRC team wants to reduce duplicate audit evidence collection and control testing effort across all three. Which approach is the BEST enterprise governance solution?
A control mapping (crosswalk) approach that consolidates overlapping requirements into a common control set enables a 'test once, comply many' model, reducing duplicate testing and evidence collection while still satisfying each distinct framework's requirements.
Ready for the real thing?

The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.

undefined $34.99 with code FREETEST33 — valid through Oct 6.

Get my $34.99 deal →