Practice CGRC System Compliance questions with full explanations on every answer.
Start practicing
System Compliance — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
During the compliance determination phase, you discover that a legacy application lacks multi-factor authentication (MFA) but is isolated within a physically secured enclave. Which action should you take to document this in the Security Assessment Report (SAR)?
2An Authorizing Official (AO) is reviewing a Plan of Action and Milestones (POA&M) for a high-impact system. What is the AO's primary responsibility regarding this document?
3An Authorizing Official grants an 'ATO with Conditions.' What does this mean for the system owner?
4You are utilizing the NIST SP 800-37 R2 process for an Authorization to Operate (ATO). At what point is the Security Assessment Report (SAR) presented to the Authorizing Official?
5You are performing a compliance determination on a system that shares data with an external partner. What is the most important factor in the authorization boundary determination?
6While reviewing a system's compliance, you notice the Security Control Assessor (SCA) used an interview method for a technical control that requires automated testing. How should you address this in your review?
7An information system security officer (ISSO) is preparing the Security Assessment Plan (SAP) in the NIST Risk Management Framework. Which component must be identified first to ensure the assessment coverage is adequate?
8When determining compliance for a cloud-based service, which document serves as the primary evidence of the provider's security controls?
9What is the purpose of the Security Assessment Report (SAR)?
10Which document provides the formal authority to operate a system?
11You are auditing an organization's POA&M process. Which of the following indicates an ineffective process?
12A system is found to have a critical vulnerability that cannot be patched. You are documenting a risk acceptance request. What is the most critical piece of information to include for the AO?
13When a system is undergoing a major change, what is the impact on the existing ATO?
14If a security control is deemed 'Not Applicable' (NA) in the System Security Plan (SSP), what must the system owner provide?
15What is the relationship between the System Security Plan (SSP) and the Security Assessment Report (SAR)?
16Which role is responsible for the ongoing monitoring of security controls after an ATO is granted?
17A contractor provides a service for your organization. How do you ensure the contractor's system is compliant?
18What is the primary role of the Security Control Assessor (SCA)?
19Which phase of the RMF includes the 'continuous monitoring' of security controls?
20Which THREE of the following are valid components of an Authorization Package?
21When assessing a cloud service provider (CSP) using a FedRAMP-authorized solution, what is the primary benefit to your organization?
22Which TWO documents are essential for an Authorizing Official to make an informed risk-based decision?
23Which TWO factors should an ISSO consider when determining if a system change requires a re-authorization?
24Which THREE types of information should be included in a risk acceptance memo?
25Which THREE categories of controls are identified in NIST SP 800-53?
26Which TWO of the following are responsibilities of the Authorizing Official?
27Which TWO actions should an ISSO take when a critical security control is found to be ineffective during assessment?
28Which THREE elements are necessary for a compliant continuous monitoring program?
The System Compliance domain covers the key concepts tested in this area of the CGRC exam blueprint published by (ISC)². Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all CGRC domains — no account required.
The Courseiva CGRC question bank contains 28 questions in the System Compliance domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the System Compliance domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included