ISC · domain
Governance Risk And Compliance
Practise (ISC)2 Information Systems Security Architecture Professional (CISSP-ISSAP, Aug 2025 blueprint) (ISC) Governance Risk And Compliance practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Governance Risk And Compliance questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Governance Risk And Compliance
Governance Risk And Compliance questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Governance Risk And Compliance exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Governance Risk And Compliance questions (40)
Click any question to see the full explanation, or start a practice session above.
When establishing a Third-Party Risk Management (TPRM) process, which THREE factors must be considered during the initial due diligence?
Medium2When designing a secure multi-region cloud architecture, which THREE governance aspects must be clearly defined for data residency compliance?
Hard3Which governance model is characterized by decision-making being centralized at the corporate level to ensure consistency across the entire organization?
Easy4A firm wants to implement an 'Infrastructure-as-Code' security gate. Using AWS CloudFormation, which feature should be utilized to perform security checks on templates before they are provisioned?
Hard5To implement governance for containerized workloads, which Kubernetes feature should an architect use to enforce that only images from a trusted registry are deployed?
Medium6An organization must maintain HIPAA compliance in a hybrid cloud. Which architecture pattern best enables strict separation of duties between the administrative team and the data encryption keys?
Hard7To implement effective Risk Management integration into architecture using the FAIR (Factor Analysis of Information Risk) framework, which THREE metrics must an architect define for each identified scenario?
Hard8Which TWO factors are critical when establishing a Risk Appetite statement for a new cloud-native architecture?
Easy9Which TWO actions should be taken when integrating a new cloud service into an existing GRC program?
Medium10An organization is building a microservices architecture. To ensure compliance with GDPR, where should the data classification metadata be enforced to ensure that PII is not stored in non-compliant regions?
Hard11When using Google Cloud, which service is the primary point of integration for security policies to be applied across the entire organization hierarchy?
Medium12An architect is deploying a global application and needs to ensure that all HTTP traffic is redirected to HTTPS. Which service in AWS should be used to enforce this compliance globally?
Medium13Which document is considered the authoritative 'System Security Plan' (SSP) for an information system undergoing a formal authorization process?
Easy14An organization is migrating sensitive workloads to Azure. The compliance team mandates that all storage account keys be rotated automatically. Which service should the architect configure to meet this requirement?
Medium15Which THREE components are critical for an ISSAP architect when designing an audit trail that meets the legal requirements for non-repudiation?
Medium16A firm needs to ensure that only approved machine images (AMIs) are used in production. Which AWS service should be used to create a golden image pipeline that enforces compliance before images are shared?
Hard17In the context of the NIST Cybersecurity Framework (CSF) 2.0, which newly introduced function focuses on managing the supply chain and third-party risk?
Easy18When implementing a Zero Trust Architecture in Google Cloud Platform (GCP), which component is the core Policy Decision Point (PDP) used to govern access to applications based on context-aware identity and device posture?
Easy19To ensure compliance with the Payment Card Industry Data Security Standard (PCI DSS) requirement for secure system component configuration, which AWS native service provides a dashboard to continuously monitor and remediate misconfigurations?
Medium20Which risk management framework is most commonly used for aligning business objectives with IT capabilities in large enterprises?
Easy21When designing an architecture for GDPR compliance, which THREE technical controls should be prioritized to satisfy the 'Right to be Forgotten' requirement?
Medium22Which document is the primary foundational document in the COBIT framework that provides a governance perspective on how information technology should support business objectives?
Easy23Which THREE components are critical to implement an effective 'Security as Code' architecture?
Hard24In the context of the CISSP-ISSAP, which governance activity involves verifying that the architecture aligns with business requirements through regular audits?
Easy25An ISSAP architect is designing a system that must be compliant with the General Data Protection Regulation (GDPR). Which THREE technical safeguards should be implemented to ensure data confidentiality?
Hard26An organization is using Azure to host sensitive data. To prevent data exfiltration, the architect needs to restrict storage account access to only the corporate network. Which feature should be used?
Hard27An ISSAP architect is designing a multi-region deployment on AWS. To ensure data sovereignty compliance for GDPR, which S3 configuration strategy must be enforced using Service Control Policies (SCPs)?
Hard28An ISSAP architect is designing a cloud environment that must comply with PCI-DSS 4.0. Which specific AWS feature should be configured within the AWS Control Tower to ensure that all new member accounts automatically inherit the necessary preventative guardrails for non-compliant S3 bucket configurations?
Medium29An organization is migrating to Azure and must align with NIST SP 800-53 controls. Which THREE actions should the architect perform within Microsoft Defender for Cloud to facilitate continuous compliance posture management?
Hard30Which THREE criteria are most important when selecting a Cloud Service Provider (CSP) based on the Shared Responsibility Model for an ISSAP architect?
Medium31A healthcare provider is deploying a multi-tenant application on GCP. To comply with data isolation requirements, which service should the architect use to ensure traffic between VPCs is strictly governed by network policy?
Medium32What is the primary function of an Information Security Steering Committee (ISSC) in the context of enterprise security governance?
Easy33To satisfy SOC2 Type II requirements regarding access lifecycle management, which TWO configurations should an architect verify within Okta for all privileged administrative accounts?
Medium34When using Azure Policy to enforce governance, which effect type should be used if the architect wants to log non-compliance without blocking the deployment of resources?
Medium35An organization requires that all cloud storage assets are encrypted using customer-managed keys. Which service should the architect configure to track the key usage and verify compliance?
Hard36An architect is evaluating compliance for an enterprise multi-cloud environment. Which THREE capabilities must be included in a centralized GRC platform for it to be effective?
Hard37An ISSAP architect is working with developers to ensure that the code repository is compliant with secure coding standards. Which tool within the GitHub ecosystem is specifically designed to detect secrets (e.g., API keys) before they are committed?
Medium38When designing an architecture to meet NIST 800-53 controls, which AWS service should be used to enforce resource tagging for all assets to ensure proper cost and compliance tracking?
Medium39What is the primary objective of a 'Compliance Gap Analysis' in a cloud migration project?
Easy40What is the primary role of a 'Compliance Liaison' in an enterprise architecture team?
EasyOther domains
All ISC exam domains
Frequently asked questions
- What does the Governance Risk And Compliance domain cover on the ISC exam?
- Governance Risk And Compliance questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 40 Governance Risk And Compliance questions in the ISC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Governance Risk And Compliance questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.