Courseiva
Back to (ISC)2 Certified in Governance, Risk and Compliance (CGRC) (CGRC) questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise (ISC)2 Certified in Governance, Risk and Compliance (CGRC) (CGRC) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
CGRC
exam code
(ISC)²
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related CGRC topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummulti select
Full question →

In the context of the RMF, which THREE of the following are considered 'Information System' components that contribute to the authorization boundary? (Select THREE)

Question 2mediummulti select
Full question →

Which TWO of the following entities are typically responsible for maintaining compliance in a cloud environment under a shared responsibility model?

Question 3mediummulti select
Full question →

Which TWO of the following represent best practices for password management?

Question 4easymulti select
Full question →

Which TWO types of controls are specifically examined during an audit?

Question 5hardmulti select
Full question →

Which THREE of the following are elements of a secure incident response control set?

Question 6easymulti select
Full question →

Which TWO of the following are primary components of an effective security control assessment report?

Question 7hardmulti select
Full question →

Which THREE actions are essential for maintaining 'integrity' of audit evidence?

Question 8hardmulti select
Full question →

Which THREE actions are essential to correctly manage assignments in NIST 800-53 controls?

Question 9easymulti select
Full question →

Which THREE activities are part of the 'Assessment Execution' phase?

Question 10mediummulti select
Full question →

Which TWO of the following are critical requirements for implementing an effective patch management program?

Question 11mediummulti select
Full question →

Which TWO of the following are recommended practices for managing firewall rules?

Question 12hardmulti select
Full question →

Which THREE actions are required when preparing to decommission a system that stored 'Classified' information?

Question 13hardmulti select
Full question →

Which TWO elements are required to be included in a Plan of Action and Milestones (POA&M)?

Question 14mediummulti select
Full question →

Which TWO methods are commonly used to gather assessment evidence?

Question 15mediummulti select
Full question →

Which TWO factors contribute to the 'scope' of an information security audit?

Question 16mediummulti select
Full question →

Which TWO of the following are common challenges when implementing continuous monitoring in a legacy environment?

Question 17hardmulti select
Full question →

Which THREE of the following are components of a secure server hardening process?

Question 18mediummulti select
Full question →

Which THREE artifacts are commonly used by the Authorizing Official (AO) to validate the system boundary? (Select THREE)

Question 19easymulti select
Full question →

Which TWO of the following are examples of physical security controls?

Question 20hardmulti select
Full question →

Which THREE categories of controls are identified in NIST SP 800-53?

These CGRC practice questions are part of Courseiva's free (ISC)² certification practice question bank. Courseiva provides original exam-style CGRC questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.