(ISC)² · Free Practice Questions · Last reviewed May 2026
42real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
When selecting controls, you notice that a specific NIST 800-53 control includes 'assignment' statements. What is the purpose of these statements?
To define specific parameters for control implementation.
Assignments allow organizations to define values like 'every 30 days' or 'authorized personnel'.
To categorize the control by its priority level.
To link the control to a regulatory requirement.
To assign the control to a specific system administrator.
An organization is applying NIST SP 800-53 Rev. 5 controls to a cloud-based SaaS application. The authorization official requests that you perform 'supplementing' during the tailoring process. What is the correct action?
Replace a control with a vendor-provided security feature.
Add additional controls to the baseline to address specific threat vectors.
Supplementing specifically refers to the addition of controls.
Remove controls from the baseline that are technically infeasible.
Adjust the parameters of existing controls to lower operational impact.
A system owner determines that a specific NIST 800-53 control cannot be implemented due to legacy hardware constraints. They choose to implement a different control to mitigate the same risk. This is an example of what?
Risk Acceptance.
Baseline Tailoring.
Control Supplementation.
Compensating Control.
This is the definition of a compensating control.
When utilizing the NIST 800-53 control catalog, which field identifies the specific family to which a control belongs?
Control priority tag.
The assignment statement.
Control ID prefix.
The prefix denotes the family, such as AC for Access Control.
The control parameter list.
What document provides the most granular guidance on tailoring security controls for federal systems?
FIPS 200.
NIST SP 800-37.
CNSSI 1253.
NIST SP 800-53.
It contains the specific guidance for control selection and tailoring.
You are tailoring controls for a system that does not process PII. Which action should you take regarding the Privacy (PRIV) family controls in the NIST 800-53 catalog?
Replace the family with general security controls.
Keep the controls but set them to 'manual' mode.
Document the removal of the family with a justification.
Tailoring allows for the removal of non-applicable controls with justification.
Implement the controls as high-priority items.
Want more Control Selection practice?
Practice this domainWhen aligning GRC objectives with business goals, which metric best demonstrates the value of an integrated GRC program to a Board of Directors?
The number of tickets opened in the GRC helpdesk.
The total storage space consumed by evidence files.
The number of users logged into the GRC platform daily.
The percentage reduction in repeat audit findings.
This is a key performance indicator (KPI) demonstrating effective risk remediation.
Your GRC program requires that assessment evidence be stored in an immutable state for three years. In the GRC platform, which feature ensures this integrity?
Applying an 'Evidence Lock' or 'Retention Policy' to the record.
These features prevent modification of finalized evidence records.
Disabling the record deletion permission for all users.
Setting the record visibility to 'Public'.
Setting the 'Draft' workflow state to permanent.
You are configuring a GRC workflow to address 'High' severity findings. The requirement is that any finding classified as 'High' must be approved by the CISO before moving to the 'Remediated' state. Which mechanism should you configure?
Set up a Workflow Transition Condition triggered by the 'Severity' field.
Workflow transitions allow for conditional routing based on specific metadata values.
Configure a global Business Rule to auto-close all findings.
Change the default notification email template for findings.
Modify the User Permission set for the CISO account.
An organization is transitioning from a siloed risk management approach to an integrated GRC program. During the initial implementation, data inconsistency between the Risk Register and the Compliance Control library is observed. Which action best facilitates 'Common Control Framework' (CCF) mapping?
Create manual spreadsheets to reconcile the data outside the GRC platform.
Force all business units to use identical risk taxonomy naming conventions.
Disable the Regulatory Requirement module to focus only on Risks.
Implement a 'Many-to-Many' relationship mapping between Controls and Regulatory Requirements.
This is the standard architectural approach to CCF implementation in GRC systems.
A multinational company needs to ensure that GRC data access complies with regional data residency laws. Which configuration feature should be utilized?
Setting all user passwords to match the local language.
Encrypting the entire GRC database with one key.
Implementing 'Data Partitioning' or 'Regional Access Scoping'.
This allows restricting data storage and access to specific geographic regions.
Conducting a system-wide vulnerability scan.
The GRC team has determined that 'Residual Risk' is being calculated incorrectly because the 'Control Effectiveness' score is not reflecting the latest audit results. Which architectural fix is required?
Update the manual risk assessment survey annually.
Configure a 'Dynamic Link' between Audit Testing Results and Risk Rating calculations.
Automating the data flow between audit results and risk scoring is the best practice for accurate residual risk calculation.
Increase the frequency of full organizational risk assessments.
Require the CISO to manually approve all risk score changes.
Want more GRC Program practice?
Practice this domainWhich of the following is an example of a 'System Boundary' document that assists with the RMF process?
The System Security Plan (SSP) boundary description.
The SSP is the authoritative source for the security boundary.
The Annual Security Awareness Training log.
The Privacy Threshold Analysis (PTA).
The System Development Life Cycle (SDLC) policy.
A federal agency is using FIPS 199 to categorize a system that processes public health data. The confidentiality impact is Low, integrity is Moderate, and availability is Moderate. What is the overall system categorization?
Not Categorized
Low
High
Moderate
The highest value among Low, Moderate, and Moderate is Moderate.
When classifying an information system under FIPS 199, which stakeholder should typically sign off on the final categorization?
The Lead System Administrator.
The Information System Owner (ISO).
The ISO is the accountable party for the system categorization.
The Chief Information Security Officer (CISO).
The Third-Party Auditor.
When defining the scope of an information system, what is the primary purpose of identifying 'common controls'?
To ensure they are manually tested for every individual system.
To increase the system's FIPS 199 impact level.
To identify controls that are implemented once and applied to multiple systems.
Efficiency in control implementation is a primary goal of common control identification.
To exclude them from the System Security Plan (SSP).
Your organization is transitioning to a 'System of Systems' architecture. When defining the boundary for one sub-system, what is the best practice to avoid scope creep?
Define the boundary based on the specific services and data flows owned by the sub-system.
Focusing on ownership and data flow control keeps the authorization boundary precise.
Include only the database tier.
Include the entire enterprise infrastructure to be safe.
Include all internal network segments regardless of use.
You are defining the authorization boundary for a cloud-hosted application in the NIST Risk Management Framework. Which component must be explicitly included within the boundary according to NIST SP 800-37?
The cloud service provider's physical security controls for the hosting data center.
The authorization boundary encompasses the service environment providing the security controls.
The end-user's local home router configuration.
The public internet backbone routing protocols.
The organization's global human resources policy.
Want more Scope OF System practice?
Practice this domainDuring the compliance determination phase, you discover that a legacy application lacks multi-factor authentication (MFA) but is isolated within a physically secured enclave. Which action should you take to document this in the Security Assessment Report (SAR)?
Force an upgrade to the application
Document the compensating control and assess its effectiveness
Compensating controls are valid methods to meet security requirements.
Immediately revoke the Authorization to Operate (ATO)
Mark the control as 'Not Applicable'
An Authorizing Official (AO) is reviewing a Plan of Action and Milestones (POA&M) for a high-impact system. What is the AO's primary responsibility regarding this document?
Drafting the mitigation tasks
Conducting the security controls assessment
Implementing the technical patches
Accepting the residual risk associated with the POA&M
The AO signs off on the risk acceptance.
An Authorizing Official grants an 'ATO with Conditions.' What does this mean for the system owner?
The system is unauthorized for production use
The system is prohibited from processing sensitive data
The system must meet specific security requirements to remain authorized
Conditions require timely remediation of identified risks.
The system is permanently compliant
You are utilizing the NIST SP 800-37 R2 process for an Authorization to Operate (ATO). At what point is the Security Assessment Report (SAR) presented to the Authorizing Official?
During the 'Categorize' step
After the 'Monitor' step
During the 'Prepare' step
After the 'Assess' step and before the 'Authorize' step
The SAR is a required input for the authorization decision.
You are performing a compliance determination on a system that shares data with an external partner. What is the most important factor in the authorization boundary determination?
The ownership and control of the components
Boundary is defined by what the system owner has the authority to protect.
The cost of the hardware
The physical location of the server racks
The number of users accessing the system
While reviewing a system's compliance, you notice the Security Control Assessor (SCA) used an interview method for a technical control that requires automated testing. How should you address this in your review?
Accept the findings as-is
Escalate to the Chief Information Officer (CIO)
Request a re-assessment using the 'Test' method
Technical controls require testing (functional verification) rather than just interviews.
Update the System Security Plan (SSP) to match the interview
Want more System Compliance practice?
Practice this domainWhen configuring Cisco ASA firewall rules, you notice that traffic is being dropped despite an 'allow' access-list. What is the most likely cause?
The interface is not assigned to a security zone
The traffic is encrypted by VPN
Missing 'permit ip any any' at the top
The rule is placed after a 'deny ip any any' rule in the same list
ASA access lists are processed sequentially; the first match wins.
You are implementing Windows AppLocker. You want to ensure that only signed binaries from your organization are executed. Which configuration should you choose?
Create a Path Rule for C:\Program Files\*
Configure the 'Audit only' mode in Group Policy
Create a Hash Rule for every existing executable
Create a Publisher Rule based on the certificate issuer and product name
This ensures only binaries signed by your organization's CA are permitted.
You are configuring a SIEM (e.g., Splunk) to monitor failed login attempts. What is the most efficient way to reduce noise while maintaining audit integrity?
Apply filters on the Universal Forwarder
Filtering at the source (forwarder) prevents ingestion of noise.
Disable logging on the domain controller
Delete logs after ingestion
Increase log rotation frequency
To ensure compliance with PCI-DSS for a database, you must implement FDE (Full Disk Encryption). Which tool is appropriate for a Linux-based server?
BitLocker
IPsec
dm-crypt/LUKS
This is the native Linux kernel disk encryption framework.
VeraCrypt
You are configuring an AWS Security Group for a web server. To allow incoming HTTPS traffic from the internet while restricting all other traffic, which rule should you apply?
Inbound Rule: Type HTTPS, Port 443, Source 0.0.0.0/0
This correctly allows HTTPS traffic from any source.
Outbound Rule: Type HTTPS, Port 443, Destination 0.0.0.0/0
Inbound Rule: Type All Traffic, Port All, Source 0.0.0.0/0
Inbound Rule: Type HTTPS, Port 443, Source 127.0.0.1/32
You are setting up an IDS/IPS (e.g., Snort). Where should you place the sensor to monitor both internal and external traffic?
Directly on the public ISP router
Inside the isolated guest Wi-Fi network
On a Span Port of the core distribution switch
This allows monitoring of internal and external traffic flows.
On the WAN interface of the firewall
Want more Control Implementation practice?
Practice this domainDuring a control assessment, you use the 'examine, interview, and test' methods. Which of these is classified as an 'objective' evidence gathering technique?
Reviewing policies
Interviewing the IT manager
Observing physical access
Testing technical controls
Testing provides verifiable technical evidence.
When conducting an assessment using the SCAP protocol, what is the primary purpose of the OVAL component?
To provide a language for checking system configuration state
OVAL defines checks to identify configuration issues.
To standardize the transfer of vulnerability data
To define the severity of a vulnerability
To manage the lifecycle of a POA&M
You are preparing a NIST SP 800-53A security control assessment. Which methodology step is performed immediately after the 'Prepare for Assessment' phase?
Analyze Security Assessment Results
Develop the Plan of Action and Milestones (POA&M)
Assess Security Controls
The assessment phase follows preparation.
Authorize the Information System
Which document serves as the primary agreement between an assessor and the target organization outlining the scope of an audit?
Interconnection Security Agreement
Rules of Engagement
ROE serves as the governance agreement.
Security Assessment Plan
Risk Assessment Report
System Security Plan
You are assessing an organization's compliance with SOC 2. The auditor requests evidence of 'Trust Services Criteria'. Which evidence is most relevant for the Availability criterion?
Privacy policy publication
Encryption of data at rest
Disaster recovery plan test results
DR tests demonstrate that systems can be recovered.
User access review logs
During a FedRAMP audit, you discover that a customer's cloud environment does not meet a required control. What is the mandatory next step to track this non-compliance?
Document the weakness in a Plan of Action and Milestones (POA&M)
POA&M is the standard artifact for tracking identified gaps.
Immediately terminate the cloud service
Perform a penetration test
Request a waiver from the JAB
Update the System Security Plan (SSP) to reflect compliance
Want more Assessment And Audit practice?
Practice this domainYour organization uses Tenable.io for continuous monitoring of vulnerability status. You notice that several high-severity vulnerabilities remain 'open' despite being marked as 'patched' in your configuration management database. What is the most likely cause?
The Nessus scanner plugin needs an update to recognize the patch.
The scan policy is set to 'Discovery' instead of 'Audit'.
The scan agent was decommissioned prematurely.
The vulnerability scan was not performed after the patch was applied.
Continuous monitoring requires validation scans to confirm patch effectiveness before updating the compliance status.
You are managing a system under NIST SP 800-37 R2. During the ongoing authorization phase, you notice a significant change in the system's security posture due to a recent software update. What is the most appropriate next step in the continuous monitoring process?
Immediately decommission the system.
Update the System Security Plan (SSP) and submit for re-certification.
Wait until the annual assessment cycle to review the change.
Perform a security impact analysis on the change.
A security impact analysis determines if the change affects the existing security control baseline.
You are using Microsoft Endpoint Configuration Manager (MECM) to enforce compliance. You need to verify if specific registry keys are set correctly across all workstations. Which feature should you use?
Configuration Items (CIs).
CIs allow you to define and monitor specific registry keys for compliance.
Application Catalog.
Client Health Reports.
Software Metering.
When decommissioning an IT asset that stores sensitive information, which of the following is the most important step before releasing the hardware for disposal?
Sanitize the storage media according to an approved standard.
Sanitization is the only method to ensure data is permanently removed before the hardware leaves organizational control.
Update the asset inventory list.
Remove the BIOS password.
Format the primary operating system partition.
Deactivate the user accounts associated with the system.
A cloud environment uses AWS Config to maintain compliance. You need to ensure that all S3 buckets are private. Which AWS Config feature should you configure to automatically remediate non-compliant buckets?
AWS Config Remediation Actions.
Remediation actions allow the execution of Systems Manager documents to fix non-compliant configurations.
AWS CloudTrail Event Selectors.
AWS Config Aggregators.
AWS Config Conformance Packs.
You are overseeing the decommissioning of a legacy database server holding PII. Per NIST SP 800-88 guidelines, which method ensures the media is sanitized to a level where the data cannot be recovered even with laboratory techniques?
Clear the file system using a standard OS format command.
Destroy the hard drive via shredding or incineration.
Destroy renders the target data recovery infeasible using state-of-the-art laboratory techniques.
Overwrite the drive once with zeros.
Purge the data using a cryptographic erase (CE) method.
Want more Compliance Maintenance practice?
Practice this domainThe CGRC exam has 200 questions and must be completed in 120 minutes. The passing score is 700/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 7 domains: Control Selection, GRC Program, Scope OF System, System Compliance, Control Implementation, Assessment And Audit, Compliance Maintenance. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official (ISC)² CGRC exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.