Courseiva
Back to (ISC)2 Certified in Governance, Risk and Compliance (CGRC) (CGRC) questions

Scenario-based practice

Hard Difficulty Questions

Practise (ISC)2 Certified in Governance, Risk and Compliance (CGRC) (CGRC) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
CGRC
exam code
(ISC)²
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related CGRC topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

You are documenting the system inventory in the Security Assessment Plan (SAP). Which artifact is most effective for demonstrating that all system interconnections have been properly inventoried?

Question 2hardmultiple choice
Full question →

An organization is applying NIST SP 800-53 Rev. 5 controls to a cloud-based SaaS application. The authorization official requests that you perform 'supplementing' during the tailoring process. What is the correct action?

Question 3hardmultiple choice
Full question →

An organization is moving to a cloud-native infrastructure. What is the most significant change in the assessment of 'inherited' controls?

Question 4hardmulti select
Full question →

Which THREE of the following are elements of a secure incident response control set?

Question 5hardmultiple choice
Full question →

You are deploying a PKI solution using Microsoft AD CS. You need to ensure that compromised certificates can be revoked. What must be configured?

Question 6hardmultiple choice
Full question →

You are assessing a system for compliance with FIPS 140-3. Which evidence provides the strongest validation?

Question 7hardmultiple choice
Full question →

Which technique is best to detect 'false negatives' during a security control assessment?

Question 8hardmulti select
Full question →

Which THREE actions are essential for maintaining 'integrity' of audit evidence?

Question 9hardmulti select
Full question →

Which THREE actions are essential to correctly manage assignments in NIST 800-53 controls?

Question 10hardmultiple choice
Full question →

During an assessment, you identify that an organization is not logging administrative access. What is the most appropriate recommendation in the final report?

Question 11hardmultiple choice
Full question →

You are implementing Windows AppLocker. You want to ensure that only signed binaries from your organization are executed. Which configuration should you choose?

Question 12hardmultiple choice
Full question →

A system owner determines that a specific NIST 800-53 control cannot be implemented due to legacy hardware constraints. They choose to implement a different control to mitigate the same risk. This is an example of what?

Question 13hardmultiple choice
Full question →

A system has received an Authority to Operate (ATO) with conditions. As the GRC officer, how do you handle these conditions in the continuous monitoring phase?

Question 14hardmulti select
Full question →

Which THREE actions are required when preparing to decommission a system that stored 'Classified' information?

Question 15hardmultiple choice
Full question →

During an audit of an IAM system, the auditor notices that inactive accounts are not being disabled. Which control is failing?

Question 16hardmulti select
Full question →

Which TWO elements are required to be included in a Plan of Action and Milestones (POA&M)?

Question 17hardmultiple choice
Full question →

You are deploying an EDR (Endpoint Detection and Response) solution. Which configuration minimizes false positives while maintaining visibility?

Question 18hardmultiple choice
Study the full AAA explanation →

When implementing an 802.1X environment, what is the role of the RADIUS server?

Question 19hardmultiple choice
Full question →

You are hardening a web server. You need to ensure that only secure ciphers are used for TLS connections. Where is this typically configured?

Question 20hardmultiple choice
Full question →

A developer needs to access a production server. To maintain the highest level of security, how should you implement this access?

These CGRC practice questions are part of Courseiva's free (ISC)² certification practice question bank. Courseiva provides original exam-style CGRC questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.