Courseiva

CGRC · topic practice

Control Implementation practice questions

Practise (ISC)2 Certified in Governance, Risk and Compliance (CGRC) (CGRC) Control Implementation practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Control Implementation

What the exam tests

What to know about Control Implementation

Control Implementation questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Control Implementation exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Control Implementation questions

20 questions · select your answer, then reveal the explanation

When configuring Cisco ASA firewall rules, you notice that traffic is being dropped despite an 'allow' access-list. What is the most likely cause?

You are implementing Windows AppLocker. You want to ensure that only signed binaries from your organization are executed. Which configuration should you choose?

You are configuring a SIEM (e.g., Splunk) to monitor failed login attempts. What is the most efficient way to reduce noise while maintaining audit integrity?

To ensure compliance with PCI-DSS for a database, you must implement FDE (Full Disk Encryption). Which tool is appropriate for a Linux-based server?

You are configuring an AWS Security Group for a web server. To allow incoming HTTPS traffic from the internet while restricting all other traffic, which rule should you apply?

You are setting up an IDS/IPS (e.g., Snort). Where should you place the sensor to monitor both internal and external traffic?

You are deploying a PKI solution using Microsoft AD CS. You need to ensure that compromised certificates can be revoked. What must be configured?

You need to enforce MFA on Azure AD (Microsoft Entra ID) users. Which policy type is the most recommended for modern authentication control?

Question 9hardmultiple choice
Study the full AAA explanation →

When implementing an 802.1X environment, what is the role of the RADIUS server?

In VMware vSphere, what is the best practice for securing virtual machine consoles?

You are securing a database server. What is the most effective administrative control to minimize the impact of a compromised DBA account?

You are managing an AWS S3 bucket that stores sensitive PII. Which control is the primary mechanism to prevent public access?

What is the physical security control used to prevent piggybacking at an entry point?

A developer needs to access a production server. To maintain the highest level of security, how should you implement this access?

You are configuring a Linux firewall using 'iptables'. Which chain should you use to filter traffic destined for the local host?

When performing vulnerability management, what is the purpose of a 'credentialed scan'?

You are deploying an EDR (Endpoint Detection and Response) solution. Which configuration minimizes false positives while maintaining visibility?

Which administrative control is essential before deploying a new security tool to production?

Which type of control is an alarm system installed in a server room?

You are hardening a web server. You need to ensure that only secure ciphers are used for TLS connections. Where is this typically configured?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Control Implementation sessions

Start a Control Implementation only practice session

Every question in these sessions is drawn from the Control Implementation domain — nothing else.

Related practice questions

Related CGRC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CGRC exam test about Control Implementation?
Control Implementation questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Control Implementation questions in a focused session?
Yes — the session launcher on this page draws every question from the Control Implementation domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CGRC topics?
Use the topic links above to move to related areas, or go back to the CGRC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CGRC exam covers. They are not copied from any real exam or dump site.