Courseiva

CGRC · domain

GRC Program

Practise RAM questions covering identification, installation, speeds, dual-channel, and troubleshooting for the CGRC exam.

32 questions10 easy11 medium11 hard

Focused practice

Practice GRC Program questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about GRC Program

RAM tests your ability to identify, install, and troubleshoot memory types, speeds, and configurations for PCs.

Identifying DDR3 vs DDR4 vs DDR5 physical and electrical differences

Matching RAM speed (MHz) to motherboard and CPU support

Calculating total memory capacity from module size and slots

Troubleshooting common RAM errors like beep codes and blue screens

Why learners struggle

Why GRC Program questions are commonly missed

RAM questions are commonly missed because learners confuse physical form factors (DIMM vs SO-DIMM) and fail to distinguish between memory speed (MHz) and latency (CL).

  • ·DIMM vs SO-DIMM — desktop vs laptop form factor confusion
  • ·DDR3 vs DDR4 vs DDR5 — notch position and voltage differences
  • ·MHz vs CL — speed vs latency trade-offs in performance
  • ·Single-channel vs dual-channel — bandwidth impact misconception
  • ·ECC vs non-ECC — error correction support in servers vs desktops
  • ·32-bit vs 64-bit — maximum addressable RAM limit

Watch out for

Common GRC Program exam traps

  • Confusing DDR3 and DDR4 notch positions and voltage requirements
  • Assuming dual-channel requires identical size modules only
  • Mixing ECC and non-ECC RAM in a single system
  • Forgetting that 32-bit OS limits usable RAM to 4 GB

Question index

All GRC Program questions (32)

Click any question to see the full explanation, or start a practice session above.

1

When structuring a GRC program, which THREE components are critical for compliance management?

Easy
2

To ensure that GRC controls remain effective, the organization requires a 'Control Self-Assessment' (CSA) workflow that triggers automatically based on control criticality. Which setting should be modified?

Hard
3

You are configuring a 'Risk Appetite Statement'. The requirement is that any risk score exceeding the appetite must automatically trigger a 'Risk Treatment Plan' workflow. What needs to be configured?

Hard
4

Which role is typically responsible for defining the 'Risk Appetite' within a GRC governance framework?

Easy
5

An organization is integrating its GRC platform with an existing Active Directory infrastructure. To enforce the Principle of Least Privilege for internal auditors, which configuration step should be prioritized?

Easy
6

Which THREE of the following are necessary to establish a 'Continuous Control Monitoring' (CCM) program?

Hard
7

The organization's GRC workflow has a 'Request for Exception' process. The goal is to ensure that temporary risk exceptions are automatically reviewed before they expire. Which mechanism is most appropriate?

Hard
8

The organization has adopted a 'Defense-in-Depth' strategy. You are tasked with mapping controls to the NIST CSF framework within the GRC tool. What is the most effective way to manage the relationship between framework sub-categories and existing internal controls?

Hard
9

Which TWO of the following should be considered when selecting a GRC platform for an enterprise-wide program?

Medium
10

When establishing a GRC program structure, what is the primary purpose of defining a 'System of Record'?

Easy
11

The GRC program requires that all policies are reviewed annually. What is the most effective way to enforce this within the GRC platform?

Medium
12

An organization is transitioning from a siloed risk management approach to an integrated GRC program. During the initial implementation, data inconsistency between the Risk Register and the Compliance Control library is observed. Which action best facilitates 'Common Control Framework' (CCF) mapping?

Hard
13

The GRC team has determined that 'Residual Risk' is being calculated incorrectly because the 'Control Effectiveness' score is not reflecting the latest audit results. Which architectural fix is required?

Hard
14

When aligning GRC with business objectives, which THREE of the following represent effective strategic alignment?

Hard
15

In a mature GRC program, which TWO of the following activities are typical for the 'Risk Management' domain?

Medium
16

Which THREE of the following represent common challenges in maintaining an integrated GRC program?

Hard
17

When setting up a new GRC program, which TWO of the following are essential for ensuring successful adoption across the business?

Medium
18

When aligning GRC objectives with business goals, which metric best demonstrates the value of an integrated GRC program to a Board of Directors?

Easy
19

You are configuring a GRC workflow to address 'High' severity findings. The requirement is that any finding classified as 'High' must be approved by the CISO before moving to the 'Remediated' state. Which mechanism should you configure?

Medium
20

Which GRC component is used to document the organizational structure, such as business units and departments, to which risks are assigned?

Easy
21

Which GRC platform component is most critical for ensuring that executive leadership receives accurate, real-time risk posture data?

Easy
22

To ensure the integrity of the GRC 'System of Record', which THREE controls must be enforced?

Hard
23

An organization is integrating 'Third-Party Risk Management' (TPRM) into their GRC framework. They need to ensure that vendors with 'Critical' status undergo annual due diligence. Which configuration is required?

Hard
24

A company is implementing a 'Continuous Monitoring' program in their GRC tool. They need to ingest data from a Cloud Security Posture Management (CSPM) tool. What is the most efficient configuration approach?

Medium
25

A multinational company needs to ensure that GRC data access complies with regional data residency laws. Which configuration feature should be utilized?

Medium
26

Your GRC program requires that assessment evidence be stored in an immutable state for three years. In the GRC platform, which feature ensures this integrity?

Medium
27

Which THREE of the following roles are typically involved in a GRC Steering Committee?

Easy
28

When documenting a GRC policy, which TWO elements should be included to ensure effective governance?

Medium
29

You need to ensure that the 'Compliance Dashboard' is updated only when the 'Assessment Completion' status is 'Verified'. How can you achieve this?

Medium
30

Your GRC platform allows for 'Risk Heat Map' visualization. An executive wants to see only risks associated with 'Cybersecurity'. Which feature should you configure to support this view?

Medium
31

A GRC practitioner is auditing access. Which report provides the best overview of who has 'Write' access to sensitive compliance evidence?

Easy
32

What is the primary benefit of mapping regulatory requirements to internal controls in a GRC platform?

Easy

Frequently asked questions

What does the GRC Program domain cover on the CGRC exam?
RAM tests your ability to identify, install, and troubleshoot memory types, speeds, and configurations for PCs.
How many questions are in this domain?
This page lists all 32 GRC Program questions in the CGRC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only GRC Program questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-cgrc ISC2-CGRC grc program Practice Questions