Practice CGRC Assessment And Audit questions with full explanations on every answer.
Start practicing
Assessment And Audit — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
During a control assessment, you use the 'examine, interview, and test' methods. Which of these is classified as an 'objective' evidence gathering technique?
2When conducting an assessment using the SCAP protocol, what is the primary purpose of the OVAL component?
3You are preparing a NIST SP 800-53A security control assessment. Which methodology step is performed immediately after the 'Prepare for Assessment' phase?
4Which document serves as the primary agreement between an assessor and the target organization outlining the scope of an audit?
5You are assessing an organization's compliance with SOC 2. The auditor requests evidence of 'Trust Services Criteria'. Which evidence is most relevant for the Availability criterion?
6During a FedRAMP audit, you discover that a customer's cloud environment does not meet a required control. What is the mandatory next step to track this non-compliance?
7A security auditor needs to verify that the principle of least privilege is applied to a Linux server. Which audit activity is most appropriate?
8An organization is moving to a cloud-native infrastructure. What is the most significant change in the assessment of 'inherited' controls?
9Which type of audit is performed by an internal department to assess the effectiveness of security controls without external pressure?
10When an assessment report indicates a 'High' risk finding, what is the primary responsibility of the system owner regarding the POA&M?
11You are performing a gap analysis. What is the correct order of operations for a professional assessment?
12Which standard provides the framework for conducting information security audits?
13During an audit of an IAM system, the auditor notices that inactive accounts are not being disabled. Which control is failing?
14What is the primary goal of the 'Assessment Reporting' phase?
15You are assessing a system for compliance with FIPS 140-3. Which evidence provides the strongest validation?
16When conducting an audit, what is 'sampling'?
17What is the purpose of a 'pre-assessment' meeting?
18Which TWO methods are commonly used to gather assessment evidence?
19During an assessment, you identify that an organization is not logging administrative access. What is the most appropriate recommendation in the final report?
20Which document defines the specific security controls that an organization must implement based on its risk assessment?
21What is the primary function of an assessor's 'working papers'?
22You are auditing a backup solution. Which metric is most critical for the Availability audit?
23Which TWO elements are required to be included in a Plan of Action and Milestones (POA&M)?
24Which technique is best to detect 'false negatives' during a security control assessment?
25Which TWO of the following are primary components of an effective security control assessment report?
26Which TWO types of controls are specifically examined during an audit?
27Which TWO factors contribute to the 'scope' of an information security audit?
28Which THREE activities are part of the 'Assessment Execution' phase?
29Which THREE items are critical when verifying an organization's Compliance with NIST SP 800-53?
30Which THREE actions are essential for maintaining 'integrity' of audit evidence?
31Which THREE roles are typically involved in a security assessment?
32Which THREE types of findings might appear in an audit report?
The Assessment And Audit domain covers the key concepts tested in this area of the CGRC exam blueprint published by (ISC)². Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all CGRC domains — no account required.
The Courseiva CGRC question bank contains 32 questions in the Assessment And Audit domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Assessment And Audit domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included