Courseiva

ISC · topic practice

Governance Risk And Compliance practice questions

Practise (ISC)2 Information Systems Security Architecture Professional (CISSP-ISSAP, Aug 2025 blueprint) (ISC) Governance Risk And Compliance practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Governance Risk And Compliance

What the exam tests

What to know about Governance Risk And Compliance

Governance Risk And Compliance questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Governance Risk And Compliance exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Governance Risk And Compliance questions

20 questions · select your answer, then reveal the explanation

A firm is using Terraform for Infrastructure as Code (IaC) governance. The architect wants to prevent the deployment of insecure security groups. Which tool should be integrated into the CI/CD pipeline to perform static analysis against defined security policies?

When applying the SABSA (Sherwood Applied Business Security Architecture) framework to a new project, at which stage of the lifecycle is the 'Concept' of the architecture first aligned with business requirements?

To satisfy SOC2 Type II requirements regarding access lifecycle management, which TWO configurations should an architect verify within Okta for all privileged administrative accounts?

An ISSAP architect is designing a multi-region deployment on AWS. To ensure data sovereignty compliance for GDPR, which S3 configuration strategy must be enforced using Service Control Policies (SCPs)?

When implementing a Zero Trust Architecture in Google Cloud Platform (GCP), which component is the core Policy Decision Point (PDP) used to govern access to applications based on context-aware identity and device posture?

An organization is migrating sensitive workloads to Azure. The compliance team mandates that all storage account keys be rotated automatically. Which service should the architect configure to meet this requirement?

Which document is the primary foundational document in the COBIT framework that provides a governance perspective on how information technology should support business objectives?

An organization is migrating to Azure and must align with NIST SP 800-53 controls. Which THREE actions should the architect perform within Microsoft Defender for Cloud to facilitate continuous compliance posture management?

An ISSAP architect is designing a cloud environment that must comply with PCI-DSS 4.0. Which specific AWS feature should be configured within the AWS Control Tower to ensure that all new member accounts automatically inherit the necessary preventative guardrails for non-compliant S3 bucket configurations?

To implement effective Risk Management integration into architecture using the FAIR (Factor Analysis of Information Risk) framework, which THREE metrics must an architect define for each identified scenario?

To ensure compliance with the Payment Card Industry Data Security Standard (PCI DSS) requirement for secure system component configuration, which AWS native service provides a dashboard to continuously monitor and remediate misconfigurations?

An organization must maintain HIPAA compliance in a hybrid cloud. Which architecture pattern best enables strict separation of duties between the administrative team and the data encryption keys?

Which TWO factors are critical when establishing a Risk Appetite statement for a new cloud-native architecture?

When using Azure Policy to enforce governance, which effect type should be used if the architect wants to log non-compliance without blocking the deployment of resources?

An architect is evaluating compliance for an enterprise multi-cloud environment. Which THREE capabilities must be included in a centralized GRC platform for it to be effective?

In the context of the NIST Cybersecurity Framework (CSF) 2.0, which newly introduced function focuses on managing the supply chain and third-party risk?

A firm wants to implement an 'Infrastructure-as-Code' security gate. Using AWS CloudFormation, which feature should be utilized to perform security checks on templates before they are provisioned?

Which governance model is characterized by decision-making being centralized at the corporate level to ensure consistency across the entire organization?

Which THREE components are critical for an ISSAP architect when designing an audit trail that meets the legal requirements for non-repudiation?

A healthcare provider is deploying a multi-tenant application on GCP. To comply with data isolation requirements, which service should the architect use to ensure traffic between VPCs is strictly governed by network policy?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Governance Risk And Compliance sessions

Start a Governance Risk And Compliance only practice session

Every question in these sessions is drawn from the Governance Risk And Compliance domain — nothing else.

Related practice questions

Related ISC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the ISC exam test about Governance Risk And Compliance?
Governance Risk And Compliance questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Governance Risk And Compliance questions in a focused session?
Yes — the session launcher on this page draws every question from the Governance Risk And Compliance domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other ISC topics?
Use the topic links above to move to related areas, or go back to the ISC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the ISC exam covers. They are not copied from any real exam or dump site.