Courseiva

CGRC · topic practice

Compliance Maintenance practice questions

Practise (ISC)2 Certified in Governance, Risk and Compliance (CGRC) (CGRC) Compliance Maintenance practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Compliance Maintenance

What the exam tests

What to know about Compliance Maintenance

Compliance Maintenance questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Compliance Maintenance exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Compliance Maintenance questions

20 questions · select your answer, then reveal the explanation

Your organization uses Tenable.io for continuous monitoring of vulnerability status. You notice that several high-severity vulnerabilities remain 'open' despite being marked as 'patched' in your configuration management database. What is the most likely cause?

You are managing a system under NIST SP 800-37 R2. During the ongoing authorization phase, you notice a significant change in the system's security posture due to a recent software update. What is the most appropriate next step in the continuous monitoring process?

You are using Microsoft Endpoint Configuration Manager (MECM) to enforce compliance. You need to verify if specific registry keys are set correctly across all workstations. Which feature should you use?

When decommissioning an IT asset that stores sensitive information, which of the following is the most important step before releasing the hardware for disposal?

A cloud environment uses AWS Config to maintain compliance. You need to ensure that all S3 buckets are private. Which AWS Config feature should you configure to automatically remediate non-compliant buckets?

You are overseeing the decommissioning of a legacy database server holding PII. Per NIST SP 800-88 guidelines, which method ensures the media is sanitized to a level where the data cannot be recovered even with laboratory techniques?

During a routine audit of a federal system's continuous monitoring program, the auditor finds that the 'Security Control Assessment' results are three years old. What is the non-compliance violation?

In the context of configuration management for compliance, what is the primary purpose of a Configuration Baseline?

What is the primary function of a Security Content Automation Protocol (SCAP) tool in a continuous monitoring program?

Your organization is transitioning to a 'Continuous Authorization' model. Which component is critical to ensuring that the security control baseline remains effective despite frequent DevOps releases?

A system has received an Authority to Operate (ATO) with conditions. As the GRC officer, how do you handle these conditions in the continuous monitoring phase?

Which document is primarily used to track and manage changes to security controls under the continuous monitoring strategy?

You are configuring a SIEM (e.g., Splunk) for continuous monitoring. You need to alert when a firewall configuration changes. What is the most important log source for this requirement?

You are implementing 'decommissioning' procedures for a virtual machine (VM) in a cloud environment. What is the final step you must take to ensure compliance with data privacy regulations after the data has been deleted?

You are performing a configuration audit on a Linux server. Which file would you examine to ensure that the SSH daemon is not allowing root login?

Which of the following activities is a core component of the 'Ongoing Authorization' process?

You are defining the continuous monitoring frequency for a high-impact system. According to NIST guidance, what factors should most influence the selection of assessment frequency?

Which TWO of the following are considered essential elements of an effective continuous monitoring program?

Which TWO of the following documents should be updated during the continuous monitoring phase when a system configuration is changed?

Which TWO of the following are common challenges when implementing continuous monitoring in a legacy environment?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Compliance Maintenance sessions

Start a Compliance Maintenance only practice session

Every question in these sessions is drawn from the Compliance Maintenance domain — nothing else.

Related practice questions

Related CGRC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CGRC exam test about Compliance Maintenance?
Compliance Maintenance questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Compliance Maintenance questions in a focused session?
Yes — the session launcher on this page draws every question from the Compliance Maintenance domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CGRC topics?
Use the topic links above to move to related areas, or go back to the CGRC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CGRC exam covers. They are not copied from any real exam or dump site.