Practice CGRC Control Implementation questions with full explanations on every answer.
Start practicing
Control Implementation — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
When configuring Cisco ASA firewall rules, you notice that traffic is being dropped despite an 'allow' access-list. What is the most likely cause?
2You are implementing Windows AppLocker. You want to ensure that only signed binaries from your organization are executed. Which configuration should you choose?
3You are configuring a SIEM (e.g., Splunk) to monitor failed login attempts. What is the most efficient way to reduce noise while maintaining audit integrity?
4To ensure compliance with PCI-DSS for a database, you must implement FDE (Full Disk Encryption). Which tool is appropriate for a Linux-based server?
5You are configuring an AWS Security Group for a web server. To allow incoming HTTPS traffic from the internet while restricting all other traffic, which rule should you apply?
6You are setting up an IDS/IPS (e.g., Snort). Where should you place the sensor to monitor both internal and external traffic?
7You are deploying a PKI solution using Microsoft AD CS. You need to ensure that compromised certificates can be revoked. What must be configured?
8You need to enforce MFA on Azure AD (Microsoft Entra ID) users. Which policy type is the most recommended for modern authentication control?
9When implementing an 802.1X environment, what is the role of the RADIUS server?
10In VMware vSphere, what is the best practice for securing virtual machine consoles?
11You are securing a database server. What is the most effective administrative control to minimize the impact of a compromised DBA account?
12You are managing an AWS S3 bucket that stores sensitive PII. Which control is the primary mechanism to prevent public access?
13What is the physical security control used to prevent piggybacking at an entry point?
14A developer needs to access a production server. To maintain the highest level of security, how should you implement this access?
15You are configuring a Linux firewall using 'iptables'. Which chain should you use to filter traffic destined for the local host?
16When performing vulnerability management, what is the purpose of a 'credentialed scan'?
17You are deploying an EDR (Endpoint Detection and Response) solution. Which configuration minimizes false positives while maintaining visibility?
18Which administrative control is essential before deploying a new security tool to production?
19Which type of control is an alarm system installed in a server room?
20You are hardening a web server. You need to ensure that only secure ciphers are used for TLS connections. Where is this typically configured?
21When configuring an email security gateway (e.g., Proofpoint), which record should be added to DNS to prevent domain spoofing?
22You are managing access to a file server. You want to ensure that users can read files but not delete them. What is this an example of?
23Which document is used to standardize the implementation of security controls across an organization?
24You are implementing Disk Encryption using BitLocker. You want to ensure that the recovery key is stored securely. Where should it be stored?
25Which TWO of the following are examples of physical security controls?
26Which TWO of the following represent best practices for password management?
27Which TWO of the following are considered 'technical' security controls?
28Which TWO of the following are recommended practices for managing firewall rules?
29Which TWO of the following are examples of administrative security controls?
30Which TWO of the following are critical requirements for implementing an effective patch management program?
31Which THREE of the following are steps required to properly decommission a server containing sensitive data?
32Which THREE of the following are components of a secure server hardening process?
33Which TWO of the following are effective ways to secure endpoints against malware?
34Which THREE of the following are elements of a secure incident response control set?
The Control Implementation domain covers the key concepts tested in this area of the CGRC exam blueprint published by (ISC)². Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all CGRC domains — no account required.
The Courseiva CGRC question bank contains 34 questions in the Control Implementation domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Control Implementation domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included