CGRC · domain
Control Selection
Practise (ISC)2 Certified in Governance, Risk and Compliance (CGRC) (CGRC) Control Selection practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Control Selection questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Control Selection
Control Selection questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Control Selection exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Control Selection questions (27)
Click any question to see the full explanation, or start a practice session above.
During a control audit, you find that the organization has documented a 'common control' for password complexity. What does this imply for individual systems?
Hard2What document provides the most granular guidance on tailoring security controls for federal systems?
Easy3An organization is applying NIST SP 800-53 Rev. 5 controls to a cloud-based SaaS application. The authorization official requests that you perform 'supplementing' during the tailoring process. What is the correct action?
Hard4Which THREE actions are essential to correctly manage assignments in NIST 800-53 controls?
Hard5Which TWO of the following are considered 'common controls'?
Medium6Which TWO of the following characterize the 'Select' step in the RMF?
Medium7Your organization has decided to use a 'Control Overlay' for a cloud environment. What is the primary benefit of using an overlay?
Medium8Which THREE factors should an organization consider when applying control overlays?
Hard9You are preparing a security plan for a federal information system categorized as MODERATE impact. According to NIST SP 800-53B, what is the primary objective of the initial control baseline selection process?
Medium10What is the primary role of the authorization official (AO) during the Control Selection phase?
Medium11When selecting controls for a system that uses mobile devices, you apply an overlay. What is the correct relationship between the baseline and the overlay?
Medium12Which THREE of the following are benefits of using the NIST 800-53 control framework?
Hard13When utilizing the NIST 800-53 control catalog, which field identifies the specific family to which a control belongs?
Easy14Which THREE of the following are components that must be included when documenting a compensating control?
Hard15Which TWO of the following statements regarding the 'Tailoring' process are accurate?
Medium16If a control is determined to be 'system-specific', what does that mean?
Easy17During tailoring, what is the 'Refinement' process?
Medium18You are assessing a system. You find a control that is marked as 'Inherited'. What is the most critical item to verify?
Hard19You are tailoring controls for a system that does not process PII. Which action should you take regarding the Privacy (PRIV) family controls in the NIST 800-53 catalog?
Medium20Which document defines the security control baselines (Low, Moderate, High) for federal information systems?
Easy21A control in the NIST 800-53 catalog has a parameter that reads: '[Assignment: organization-defined frequency]'. What is your responsibility as the system owner?
Medium22You are tailoring a baseline and encounter a control marked as 'Not Applicable'. What is the correct documentation approach?
Hard23Which TWO of the following are valid reasons for tailoring a NIST 800-53 control baseline?
Medium24A system owner determines that a specific NIST 800-53 control cannot be implemented due to legacy hardware constraints. They choose to implement a different control to mitigate the same risk. This is an example of what?
Hard25Your organization is applying NIST SP 800-53 controls to a hybrid cloud infrastructure. What is the main purpose of utilizing the 'Control Catalog'?
Hard26When selecting controls, you notice that a specific NIST 800-53 control includes 'assignment' statements. What is the purpose of these statements?
Medium27Which of the following describes a 'Hybrid' control?
EasyOther domains
All CGRC exam domains
Frequently asked questions
- What does the Control Selection domain cover on the CGRC exam?
- Control Selection questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 27 Control Selection questions in the CGRC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Control Selection questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.