Courseiva

CGRC · domain

Control Selection

Practise (ISC)2 Certified in Governance, Risk and Compliance (CGRC) (CGRC) Control Selection practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

27 questions5 easy12 medium10 hard

Focused practice

Practice Control Selection questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Control Selection

Control Selection questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Control Selection exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Control Selection questions (27)

Click any question to see the full explanation, or start a practice session above.

1

During a control audit, you find that the organization has documented a 'common control' for password complexity. What does this imply for individual systems?

Hard
2

What document provides the most granular guidance on tailoring security controls for federal systems?

Easy
3

An organization is applying NIST SP 800-53 Rev. 5 controls to a cloud-based SaaS application. The authorization official requests that you perform 'supplementing' during the tailoring process. What is the correct action?

Hard
4

Which THREE actions are essential to correctly manage assignments in NIST 800-53 controls?

Hard
5

Which TWO of the following are considered 'common controls'?

Medium
6

Which TWO of the following characterize the 'Select' step in the RMF?

Medium
7

Your organization has decided to use a 'Control Overlay' for a cloud environment. What is the primary benefit of using an overlay?

Medium
8

Which THREE factors should an organization consider when applying control overlays?

Hard
9

You are preparing a security plan for a federal information system categorized as MODERATE impact. According to NIST SP 800-53B, what is the primary objective of the initial control baseline selection process?

Medium
10

What is the primary role of the authorization official (AO) during the Control Selection phase?

Medium
11

When selecting controls for a system that uses mobile devices, you apply an overlay. What is the correct relationship between the baseline and the overlay?

Medium
12

Which THREE of the following are benefits of using the NIST 800-53 control framework?

Hard
13

When utilizing the NIST 800-53 control catalog, which field identifies the specific family to which a control belongs?

Easy
14

Which THREE of the following are components that must be included when documenting a compensating control?

Hard
15

Which TWO of the following statements regarding the 'Tailoring' process are accurate?

Medium
16

If a control is determined to be 'system-specific', what does that mean?

Easy
17

During tailoring, what is the 'Refinement' process?

Medium
18

You are assessing a system. You find a control that is marked as 'Inherited'. What is the most critical item to verify?

Hard
19

You are tailoring controls for a system that does not process PII. Which action should you take regarding the Privacy (PRIV) family controls in the NIST 800-53 catalog?

Medium
20

Which document defines the security control baselines (Low, Moderate, High) for federal information systems?

Easy
21

A control in the NIST 800-53 catalog has a parameter that reads: '[Assignment: organization-defined frequency]'. What is your responsibility as the system owner?

Medium
22

You are tailoring a baseline and encounter a control marked as 'Not Applicable'. What is the correct documentation approach?

Hard
23

Which TWO of the following are valid reasons for tailoring a NIST 800-53 control baseline?

Medium
24

A system owner determines that a specific NIST 800-53 control cannot be implemented due to legacy hardware constraints. They choose to implement a different control to mitigate the same risk. This is an example of what?

Hard
25

Your organization is applying NIST SP 800-53 controls to a hybrid cloud infrastructure. What is the main purpose of utilizing the 'Control Catalog'?

Hard
26

When selecting controls, you notice that a specific NIST 800-53 control includes 'assignment' statements. What is the purpose of these statements?

Medium
27

Which of the following describes a 'Hybrid' control?

Easy

Frequently asked questions

What does the Control Selection domain cover on the CGRC exam?
Control Selection questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 27 Control Selection questions in the CGRC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Control Selection questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-cgrc ISC2-CGRC control selection Practice Questions