Practice CGRC Compliance Maintenance questions with full explanations on every answer.
Start practicing
Compliance Maintenance — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
Your organization uses Tenable.io for continuous monitoring of vulnerability status. You notice that several high-severity vulnerabilities remain 'open' despite being marked as 'patched' in your configuration management database. What is the most likely cause?
2You are managing a system under NIST SP 800-37 R2. During the ongoing authorization phase, you notice a significant change in the system's security posture due to a recent software update. What is the most appropriate next step in the continuous monitoring process?
3You are using Microsoft Endpoint Configuration Manager (MECM) to enforce compliance. You need to verify if specific registry keys are set correctly across all workstations. Which feature should you use?
4When decommissioning an IT asset that stores sensitive information, which of the following is the most important step before releasing the hardware for disposal?
5A cloud environment uses AWS Config to maintain compliance. You need to ensure that all S3 buckets are private. Which AWS Config feature should you configure to automatically remediate non-compliant buckets?
6You are overseeing the decommissioning of a legacy database server holding PII. Per NIST SP 800-88 guidelines, which method ensures the media is sanitized to a level where the data cannot be recovered even with laboratory techniques?
7During a routine audit of a federal system's continuous monitoring program, the auditor finds that the 'Security Control Assessment' results are three years old. What is the non-compliance violation?
8In the context of configuration management for compliance, what is the primary purpose of a Configuration Baseline?
9What is the primary function of a Security Content Automation Protocol (SCAP) tool in a continuous monitoring program?
10Your organization is transitioning to a 'Continuous Authorization' model. Which component is critical to ensuring that the security control baseline remains effective despite frequent DevOps releases?
11A system has received an Authority to Operate (ATO) with conditions. As the GRC officer, how do you handle these conditions in the continuous monitoring phase?
12Which document is primarily used to track and manage changes to security controls under the continuous monitoring strategy?
13You are configuring a SIEM (e.g., Splunk) for continuous monitoring. You need to alert when a firewall configuration changes. What is the most important log source for this requirement?
14You are implementing 'decommissioning' procedures for a virtual machine (VM) in a cloud environment. What is the final step you must take to ensure compliance with data privacy regulations after the data has been deleted?
15You are performing a configuration audit on a Linux server. Which file would you examine to ensure that the SSH daemon is not allowing root login?
16Which of the following activities is a core component of the 'Ongoing Authorization' process?
17You are defining the continuous monitoring frequency for a high-impact system. According to NIST guidance, what factors should most influence the selection of assessment frequency?
18Which TWO of the following are considered essential elements of an effective continuous monitoring program?
19Which TWO of the following documents should be updated during the continuous monitoring phase when a system configuration is changed?
20Which TWO of the following are common challenges when implementing continuous monitoring in a legacy environment?
21Which THREE of the following are valid methods of verifying that security controls are functioning as intended during continuous monitoring?
22Which THREE actions are required when preparing to decommission a system that stored 'Classified' information?
23A vulnerability scan identifies a 'missing patch' on a server. You discover that the patch cannot be applied due to compatibility issues with a critical legacy application. What is the correct compliance management action?
24Which THREE of the following items should be evaluated when performing a security impact analysis for a proposed system change?
25Which THREE of the following represent 'compensating controls' that might be used when a specific security control cannot be implemented exactly as required?
26Which TWO of the following entities are typically responsible for maintaining compliance in a cloud environment under a shared responsibility model?
The Compliance Maintenance domain covers the key concepts tested in this area of the CGRC exam blueprint published by (ISC)². Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all CGRC domains — no account required.
The Courseiva CGRC question bank contains 26 questions in the Compliance Maintenance domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Compliance Maintenance domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included