Sample questions
(ISC)2 Certified in Governance, Risk and Compliance (CGRC) (CGRC) practice questions
You are tailoring controls for a system that does not process PII. Which action should you take regarding the Privacy (PRIV) family controls in the NIST 800-53 catalog?
You are documenting the system inventory in the Security Assessment Plan (SAP). Which artifact is most effective for demonstrating that all system interconnections have been proper…
In the context of the RMF, which THREE of the following are considered 'Information System' components that contribute to the authorization boundary? (Select THREE)
An organization is applying NIST SP 800-53 Rev. 5 controls to a cloud-based SaaS application. The authorization official requests that you perform 'supplementing' during the tailor…
A control in the NIST 800-53 catalog has a parameter that reads: '[Assignment: organization-defined frequency]'. What is your responsibility as the system owner?
When an assessment report indicates a 'High' risk finding, what is the primary responsibility of the system owner regarding the POA&M?
Which document defines the specific security controls that an organization must implement based on its risk assessment?
If a control is determined to be 'system-specific', what does that mean?
Which TWO of the following entities are typically responsible for maintaining compliance in a cloud environment under a shared responsibility model?
A cloud environment uses AWS Config to maintain compliance. You need to ensure that all S3 buckets are private. Which AWS Config feature should you configure to automatically remed…
Which document serves as the primary agreement between an assessor and the target organization outlining the scope of an audit?
An organization is moving to a cloud-native infrastructure. What is the most significant change in the assessment of 'inherited' controls?
Which TWO of the following represent best practices for password management?
You are utilizing the NIST SP 800-37 R2 process for an Authorization to Operate (ATO). At what point is the Security Assessment Report (SAR) presented to the Authorizing Official?
What is the relationship between the System Security Plan (SSP) and the Security Assessment Report (SAR)?
When conducting an assessment using the SCAP protocol, what is the primary purpose of the OVAL component?
In the context of configuration management for compliance, what is the primary purpose of a Configuration Baseline?
What is the purpose of a 'pre-assessment' meeting?
Which TWO types of controls are specifically examined during an audit?
You need to enforce MFA on Azure AD (Microsoft Entra ID) users. Which policy type is the most recommended for modern authentication control?
Which THREE of the following are elements of a secure incident response control set?
When conducting an audit, what is 'sampling'?
Which TWO of the following are primary components of an effective security control assessment report?
You have determined that a system's data is publicly available, but the system is responsible for providing critical government services. If the system goes offline, the loss of av…