CGRC Control Selection Practice Question
During a control audit, you find that the organization has documented a 'common control' for password complexity. What does this imply for individual systems?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Individual systems do not need to address password complexity.
Common controls are controls provided by the infrastructure or enterprise that individual information systems inherit, reducing the burden on system owners.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Individual systems must override the common control.
Why it's wrong here
Overriding is generally not required for common controls.
- ✗
Common controls cannot be used for password complexity.
Why it's wrong here
Password policy is a classic example of a common control.
- ✗
Individual systems must report their own password status.
Why it's wrong here
The provider of the common control handles the reporting.
- ✓
Individual systems do not need to address password complexity.
Why this is correct
Inheritance means the control is satisfied at the enterprise level.
About these practice questions
One of 199 original CGRC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official (ISC)² exam blueprint
This CGRC practice question is part of Courseiva's free (ISC)² certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CGRC exam.