Courseiva

CGRC · domain

Control Implementation

Practise (ISC)2 Certified in Governance, Risk and Compliance (CGRC) (CGRC) Control Implementation practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

34 questions12 easy11 medium11 hard

Focused practice

Practice Control Implementation questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Control Implementation

Control Implementation questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Control Implementation exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Control Implementation questions (34)

Click any question to see the full explanation, or start a practice session above.

1

You are setting up an IDS/IPS (e.g., Snort). Where should you place the sensor to monitor both internal and external traffic?

Easy
2

Which type of control is an alarm system installed in a server room?

Easy
3

Which TWO of the following represent best practices for password management?

Medium
4

Which TWO of the following are critical requirements for implementing an effective patch management program?

Medium
5

Which TWO of the following are examples of administrative security controls?

Easy
6

You are configuring a Linux firewall using 'iptables'. Which chain should you use to filter traffic destined for the local host?

Medium
7

Which administrative control is essential before deploying a new security tool to production?

Easy
8

You are deploying a PKI solution using Microsoft AD CS. You need to ensure that compromised certificates can be revoked. What must be configured?

Hard
9

What is the physical security control used to prevent piggybacking at an entry point?

Easy
10

When performing vulnerability management, what is the purpose of a 'credentialed scan'?

Medium
11

Which THREE of the following are steps required to properly decommission a server containing sensitive data?

Hard
12

To ensure compliance with PCI-DSS for a database, you must implement FDE (Full Disk Encryption). Which tool is appropriate for a Linux-based server?

Easy
13

You are implementing Windows AppLocker. You want to ensure that only signed binaries from your organization are executed. Which configuration should you choose?

Hard
14

When implementing an 802.1X environment, what is the role of the RADIUS server?

Hard
15

Which TWO of the following are considered 'technical' security controls?

Easy
16

Which THREE of the following are components of a secure server hardening process?

Hard
17

You are managing access to a file server. You want to ensure that users can read files but not delete them. What is this an example of?

Medium
18

You are configuring a SIEM (e.g., Splunk) to monitor failed login attempts. What is the most efficient way to reduce noise while maintaining audit integrity?

Medium
19

You are hardening a web server. You need to ensure that only secure ciphers are used for TLS connections. Where is this typically configured?

Hard
20

You are configuring an AWS Security Group for a web server. To allow incoming HTTPS traffic from the internet while restricting all other traffic, which rule should you apply?

Medium
21

Which TWO of the following are effective ways to secure endpoints against malware?

Easy
22

When configuring Cisco ASA firewall rules, you notice that traffic is being dropped despite an 'allow' access-list. What is the most likely cause?

Hard
23

You are managing an AWS S3 bucket that stores sensitive PII. Which control is the primary mechanism to prevent public access?

Medium
24

You are implementing Disk Encryption using BitLocker. You want to ensure that the recovery key is stored securely. Where should it be stored?

Hard
25

In VMware vSphere, what is the best practice for securing virtual machine consoles?

Easy
26

You need to enforce MFA on Azure AD (Microsoft Entra ID) users. Which policy type is the most recommended for modern authentication control?

Medium
27

When configuring an email security gateway (e.g., Proofpoint), which record should be added to DNS to prevent domain spoofing?

Medium
28

Which TWO of the following are recommended practices for managing firewall rules?

Medium
29

Which THREE of the following are elements of a secure incident response control set?

Hard
30

Which TWO of the following are examples of physical security controls?

Easy
31

Which document is used to standardize the implementation of security controls across an organization?

Easy
32

You are securing a database server. What is the most effective administrative control to minimize the impact of a compromised DBA account?

Easy
33

A developer needs to access a production server. To maintain the highest level of security, how should you implement this access?

Hard
34

You are deploying an EDR (Endpoint Detection and Response) solution. Which configuration minimizes false positives while maintaining visibility?

Hard

Frequently asked questions

What does the Control Implementation domain cover on the CGRC exam?
Control Implementation questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 34 Control Implementation questions in the CGRC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Control Implementation questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-cgrc ISC2-CGRC control implementation Practice Questions