CGRC · domain
Compliance Maintenance
Practise (ISC)2 Certified in Governance, Risk and Compliance (CGRC) (CGRC) Compliance Maintenance practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Compliance Maintenance questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Compliance Maintenance
Compliance Maintenance questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Compliance Maintenance exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Compliance Maintenance questions (26)
Click any question to see the full explanation, or start a practice session above.
During a routine audit of a federal system's continuous monitoring program, the auditor finds that the 'Security Control Assessment' results are three years old. What is the non-compliance violation?
Hard2You are configuring a SIEM (e.g., Splunk) for continuous monitoring. You need to alert when a firewall configuration changes. What is the most important log source for this requirement?
Medium3Which THREE of the following items should be evaluated when performing a security impact analysis for a proposed system change?
Hard4A cloud environment uses AWS Config to maintain compliance. You need to ensure that all S3 buckets are private. Which AWS Config feature should you configure to automatically remediate non-compliant buckets?
Medium5Which THREE of the following are valid methods of verifying that security controls are functioning as intended during continuous monitoring?
Hard6What is the primary function of a Security Content Automation Protocol (SCAP) tool in a continuous monitoring program?
Easy7In the context of configuration management for compliance, what is the primary purpose of a Configuration Baseline?
Easy8You are overseeing the decommissioning of a legacy database server holding PII. Per NIST SP 800-88 guidelines, which method ensures the media is sanitized to a level where the data cannot be recovered even with laboratory techniques?
Hard9A system has received an Authority to Operate (ATO) with conditions. As the GRC officer, how do you handle these conditions in the continuous monitoring phase?
Hard10Which THREE actions are required when preparing to decommission a system that stored 'Classified' information?
Hard11Which TWO of the following are common challenges when implementing continuous monitoring in a legacy environment?
Medium12Which document is primarily used to track and manage changes to security controls under the continuous monitoring strategy?
Easy13Which TWO of the following documents should be updated during the continuous monitoring phase when a system configuration is changed?
Medium14Your organization uses Tenable.io for continuous monitoring of vulnerability status. You notice that several high-severity vulnerabilities remain 'open' despite being marked as 'patched' in your configuration management database. What is the most likely cause?
Medium15You are implementing 'decommissioning' procedures for a virtual machine (VM) in a cloud environment. What is the final step you must take to ensure compliance with data privacy regulations after the data has been deleted?
Hard16A vulnerability scan identifies a 'missing patch' on a server. You discover that the patch cannot be applied due to compatibility issues with a critical legacy application. What is the correct compliance management action?
Medium17You are performing a configuration audit on a Linux server. Which file would you examine to ensure that the SSH daemon is not allowing root login?
Medium18Which THREE of the following represent 'compensating controls' that might be used when a specific security control cannot be implemented exactly as required?
Hard19Which TWO of the following entities are typically responsible for maintaining compliance in a cloud environment under a shared responsibility model?
Medium20You are managing a system under NIST SP 800-37 R2. During the ongoing authorization phase, you notice a significant change in the system's security posture due to a recent software update. What is the most appropriate next step in the continuous monitoring process?
Easy21Your organization is transitioning to a 'Continuous Authorization' model. Which component is critical to ensuring that the security control baseline remains effective despite frequent DevOps releases?
Hard22You are defining the continuous monitoring frequency for a high-impact system. According to NIST guidance, what factors should most influence the selection of assessment frequency?
Hard23Which TWO of the following are considered essential elements of an effective continuous monitoring program?
Medium24You are using Microsoft Endpoint Configuration Manager (MECM) to enforce compliance. You need to verify if specific registry keys are set correctly across all workstations. Which feature should you use?
Medium25When decommissioning an IT asset that stores sensitive information, which of the following is the most important step before releasing the hardware for disposal?
Easy26Which of the following activities is a core component of the 'Ongoing Authorization' process?
EasyOther domains
All CGRC exam domains
Frequently asked questions
- What does the Compliance Maintenance domain cover on the CGRC exam?
- Compliance Maintenance questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 26 Compliance Maintenance questions in the CGRC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Compliance Maintenance questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.