Courseiva

CGRC · domain

Assessment And Audit

Practise (ISC)2 Certified in Governance, Risk and Compliance (CGRC) (CGRC) Assessment And Audit practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

32 questions10 easy12 medium10 hard

Focused practice

Practice Assessment And Audit questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Assessment And Audit

Assessment And Audit questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Assessment And Audit exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Assessment And Audit questions (32)

Click any question to see the full explanation, or start a practice session above.

1

What is the primary function of an assessor's 'working papers'?

Easy
2

During an audit of an IAM system, the auditor notices that inactive accounts are not being disabled. Which control is failing?

Hard
3

Which THREE activities are part of the 'Assessment Execution' phase?

Easy
4

Which THREE types of findings might appear in an audit report?

Medium
5

Which TWO factors contribute to the 'scope' of an information security audit?

Medium
6

You are auditing a backup solution. Which metric is most critical for the Availability audit?

Medium
7

You are assessing an organization's compliance with SOC 2. The auditor requests evidence of 'Trust Services Criteria'. Which evidence is most relevant for the Availability criterion?

Hard
8

When conducting an audit, what is 'sampling'?

Medium
9

Which technique is best to detect 'false negatives' during a security control assessment?

Hard
10

During an assessment, you identify that an organization is not logging administrative access. What is the most appropriate recommendation in the final report?

Hard
11

Which TWO methods are commonly used to gather assessment evidence?

Medium
12

Which TWO types of controls are specifically examined during an audit?

Easy
13

Which THREE actions are essential for maintaining 'integrity' of audit evidence?

Hard
14

Which THREE items are critical when verifying an organization's Compliance with NIST SP 800-53?

Hard
15

A security auditor needs to verify that the principle of least privilege is applied to a Linux server. Which audit activity is most appropriate?

Easy
16

Which THREE roles are typically involved in a security assessment?

Medium
17

Which TWO elements are required to be included in a Plan of Action and Milestones (POA&M)?

Hard
18

You are performing a gap analysis. What is the correct order of operations for a professional assessment?

Medium
19

You are preparing a NIST SP 800-53A security control assessment. Which methodology step is performed immediately after the 'Prepare for Assessment' phase?

Medium
20

An organization is moving to a cloud-native infrastructure. What is the most significant change in the assessment of 'inherited' controls?

Hard
21

Which document defines the specific security controls that an organization must implement based on its risk assessment?

Easy
22

What is the purpose of a 'pre-assessment' meeting?

Easy
23

Which type of audit is performed by an internal department to assess the effectiveness of security controls without external pressure?

Easy
24

Which document serves as the primary agreement between an assessor and the target organization outlining the scope of an audit?

Easy
25

When an assessment report indicates a 'High' risk finding, what is the primary responsibility of the system owner regarding the POA&M?

Medium
26

Which TWO of the following are primary components of an effective security control assessment report?

Easy
27

During a control assessment, you use the 'examine, interview, and test' methods. Which of these is classified as an 'objective' evidence gathering technique?

Medium
28

What is the primary goal of the 'Assessment Reporting' phase?

Easy
29

When conducting an assessment using the SCAP protocol, what is the primary purpose of the OVAL component?

Medium
30

During a FedRAMP audit, you discover that a customer's cloud environment does not meet a required control. What is the mandatory next step to track this non-compliance?

Hard
31

Which standard provides the framework for conducting information security audits?

Medium
32

You are assessing a system for compliance with FIPS 140-3. Which evidence provides the strongest validation?

Hard

Frequently asked questions

What does the Assessment And Audit domain cover on the CGRC exam?
Assessment And Audit questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 32 Assessment And Audit questions in the CGRC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Assessment And Audit questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
(ISC)2 Certified in Governance, Risk and Compliance (CGRC) (CGRC) Assessment And Audit Practice Questions