What the (ISC)² CGRC (Governance, Risk and Compliance) exam covers
- Security and Privacy Governance, Risk Management, and Compliance Program122 questions
- Scope of the System76 questions
- Selection and Approval of Framework, Security, and Privacy Controls108 questions
- Implementation of Security and Privacy Controls130 questions
- Assessment/Audit of Security and Privacy Controls124 questions
- System Compliance106 questions
- Compliance Maintenance99 questions
Free (ISC)² CGRC (Governance, Risk and Compliance) sample questions
A sample of 10 questions with answers and explanations. Sign up free to practice all 765.
-
What is the primary purpose of the Prepare step in the NIST SP 800-37 Rev 2 Risk Management Framework?
- AEstablish organizational and system context, priorities, and needed resourcesCorrect
- BDetermine the system's confidentiality, integrity, and availability impact levels
- CSelect and tailor the applicable security control baseline for the system's needs
- DIssue the decision and documentation authorizing the system to begin operating
✓ Correct answer: APrepare is the first RMF step and operates at both the organization and system level. It establishes risk management roles, a risk management strategy, organizational risk tolerance, and identifies common controls so later steps have the context and resources they need.
Why the other options are wrong- BDetermining impact levels is the Categorize step, which uses FIPS 199 after Prepare has set the context.
- CChoosing and tailoring the control baseline happens in the Select step, using FIPS 200 and SP 800-53.
- DIssuing the authorization decision is the Authorize step, performed by the Authorizing Official much later.
-
Which THREE practices are examples of cybersecurity supply chain risk management (C-SCRM) as described in NIST SP 800-161? (Select three.)
- AReviewing a software bill of materials for known vulnerable componentsCorrect
- BConducting due diligence on a supplier before awarding a contractCorrect
- CBuilding supply chain security clauses into acquisition contract languageCorrect
- DRunning a penetration test against the organization's production web application
✓ Correct answer: A, B, CC-SCRM practices focus on the supplier relationship and the components entering the organization: reviewing SBOMs, performing supplier due diligence, and embedding security requirements into contracts before award. Penetration testing and drafting a system security plan are valuable RMF activities in their own right, but they address the deployed system itself rather than the supply chain that produced its components.
Why the other options are wrong- DPenetration testing assesses the deployed system's own security, not the risk introduced through its supply chain.
-
True or False: FIPS 199 does not apply to national security systems, which are instead categorized using CNSSI 1253.
- ATrueCorrect
- BFalse
✓ Correct answer: AThis statement is True. FIPS 199 and the broader FISMA-based RMF apply to federal information and information systems other than national security systems. National security systems are categorized instead under CNSSI 1253, issued by the Committee on National Security Systems, which parallels the FIPS 199 approach but falls outside FISMA's civilian-agency scope. Recognizing this boundary matters because CGRC scenarios sometimes test whether a system even falls under FIPS 199 at all, before any impact-level analysis of confidentiality, integrity, or availability begins.
Why the other options are wrong- BThis would be false only if FIPS 199 covered national security systems directly, but it explicitly excludes them in favor of CNSSI 1253.
-
An organization determines that a full audit log review requirement is impractical at the same frequency for a very large, high-transaction-volume system as for a small system, and adjusts the control's implementation approach accordingly. Which scoping consideration is being applied?
- AScalability-related scoping considerationCorrect
- BInfrastructure-related scoping consideration
- CPublic access-related scoping consideration
- DCommon control-related scoping consideration
✓ Correct answer: AScalability-related scoping considerations recognize that a control's literal implementation may need adjustment based on the size or scale of the system, such as transaction volume, without changing the underlying security or privacy objective the control serves. The implementation approach, not the underlying requirement itself, is what scales to match the system's operational size.
Why the other options are wrong- BInfrastructure-related scoping concerns physical versus virtual or centrally versus locally managed infrastructure, not raw system scale.
- CPublic access-related scoping concerns unauthenticated external users, not transaction volume or system size.
- DCommon control-related scoping concerns controls inherited from another provider, not adjusting for scale.
-
Where in the SSP is the system's configuration management baseline typically documented as part of implementing controls?
- AWithin the implementation statements for the CM control familyCorrect
- BWithin the rules of behavior appendix, and nowhere else
- CWithin the incident response plan appendix, and nowhere else
- DWithin the privacy impact assessment appendix, and nowhere else
✓ Correct answer: AConfiguration management controls (the CM family in SP 800-53) require the system to define and document a baseline configuration; that baseline and how it is maintained belongs in the implementation statements for those specific controls, not scattered into unrelated appendices. Assessors look there first to verify CM is actually in place before checking anything else in the plan.
Why the other options are wrong- BRules of behavior cover acceptable user conduct, not the technical configuration baseline.
- CThe incident response plan addresses handling security incidents, not baseline configuration.
- DThe privacy impact assessment addresses PII risk, not system configuration management.
-
Who is normally responsible for maintaining the alternate storage and processing site agreements cited in a system's contingency plan?
- AThe system ownerCorrect
- BThe independent assessor
- CThe authorizing official
- DThe privacy officer
✓ Correct answer: AThe system owner implements CP-6 and CP-7 by negotiating and keeping current the agreements covering alternate storage and processing sites, confirming capacity, access terms, and activation procedures remain valid over time, so recovery resources are genuinely available on short notice whenever a disruption actually forces the organization to activate the contingency plan, not only when a scheduled exercise is underway.
Why the other options are wrong- BThe independent assessor evaluates control effectiveness, not ongoing site contract management.
- CThe authorizing official accepts risk and grants an ATO, not manages contracts.
- DThe privacy officer focuses on PII handling, not facility recovery agreements.
-
What is the primary purpose of establishing rules of engagement for a security control assessment?
- ATo define the boundaries assessors must follow during testingCorrect
- BTo document the final authorization decision reached by the AO
- CTo record which controls passed and which controls failed
- DTo calculate the system's overall residual risk score
✓ Correct answer: ARules of engagement set clear operational boundaries, such as which systems and times are in scope, how testing may be conducted, and who to contact if something unexpected occurs, so that assessment activities, especially active testing, proceed safely without unintended disruption to the organization's operations.
Why the other options are wrong- BThe authorization decision is documented separately by the AO in the authorization package, not in rules of engagement.
- CPass and fail findings are recorded in the Security Assessment Report, not in the rules of engagement.
- DA residual risk score is a risk-analysis output, not something rules of engagement are used to calculate.
-
A system owner wants to close a POA&M item simply because its scheduled completion date has passed, even though remediation is incomplete. Is this appropriate?
- AYes, passing the date automatically closes any item
- BNo, closure needs verified completion, not a dateCorrect
- CYes, but only for low-risk weaknesses overall
- DNo, but only the AO may choose to keep it open
✓ Correct answer: BA completion date is a planning target, not proof that a fix actually occurred. Closing the item based on the calendar alone would misrepresent an unresolved weakness as though it were resolved, so the entry stays open, typically with a revised date and documented reason for the delay, until remediation is independently verified.
Why the other options are wrong- AAn expired target date signals slippage requiring a revised plan, not automatic closure of the underlying weakness.
- CEven a low-risk item still requires verified completion before it can be closed, regardless of its severity level.
- DKeeping an entry open for incomplete work is a routine action expected of the ISO or ISSO, not solely the AO.
-
Which of the following would NOT typically be found within the authorization decision document itself, even though it directly supports the decision?
- AThe authorization decision rendered by the AO
- BThe specific authorization termination date
- CDetailed raw assessment test resultsCorrect
- DConditions the AO attaches to the authorization
✓ Correct answer: CThe authorization decision document is a concise record of the decision, its conditions, and the termination date; it is not where detailed technical test results and raw evidence reside. That level of detail stays in the security assessment report and other supporting artifacts, which the decision document references rather than reproduces.
Why the other options are wrong- AThe decision itself is a core element that always appears in the authorization decision document.
- BThe authorization termination date is one of the standard elements documented directly within the decision document.
- DAny conditions the AO imposes are explicitly recorded in the authorization decision document as part of the decision.
-
Which THREE tiers make up the NIST risk management approach applied to ISCM? (Select THREE.)
- AOrganizationCorrect
- BMission/Business ProcessCorrect
- CVendor and Supplier Oversight
- DInformation SystemCorrect
✓ Correct answer: A, B, DNIST's tiered risk management approach, applied to ISCM, defines three levels: Tier 1 Organization for governance and risk tolerance, Tier 2 Mission/Business Process for prioritizing missions and common controls, and Tier 3 Information System where monitoring and assessments are carried out day to day, with information flowing up for aggregated reporting and down for guidance and prioritization. Each tier depends on the others to keep monitoring consistent across the organization.
Why the other options are wrong- CVendor or supplier oversight is addressed separately through supply chain risk management processes, it is not one of the three tiers defined for the organizational ISCM approach.
Who this (ISC)² CGRC (Governance, Risk and Compliance) practice exam is for
This practice set is for anyone preparing for the (ISC)² CGRC (Governance, Risk and Compliance) exam - from first-time candidates building a foundation to experienced professionals doing a final review before test day. If you learn best by working through realistic questions and reading why each answer is right or wrong, it is built for you.
How to use this (ISC)² CGRC (Governance, Risk and Compliance) practice exam
- Start with the free sample questions above to gauge your current baseline.
- Read the full explanation on every question, including why each wrong option is wrong.
- Track your weak domains and focus your study where you are losing the most marks.
- Once you are scoring consistently well, take a timed, full-length mock exam.
- Use your readiness score to decide when you are ready to book the real (ISC)² CGRC (Governance, Risk and Compliance) exam.
Related Security resources
- (ISC)² CGRC (Governance, Risk and Compliance) study guideKey concepts
- Security practice examsAll Security
- Certification pathWhere this fits
- Certification exam guides & tipsBlog
- Plans & pricingFree & paid
- (ISC)² CISSP practice examRelated
- CompTIA SecurityX (CAS-005, formerly CASP+) practice examRelated
- (ISC)² Certified in Cybersecurity (CC) practice examRelated
(ISC)² CGRC (Governance, Risk and Compliance) practice exam FAQ
How many questions are in the (ISC)² CGRC (Governance, Risk and Compliance) practice exam on CertGrid?
CertGrid has 765 practice questions for (ISC)² CGRC (Governance, Risk and Compliance), covering 7 exam domains. The real (ISC)² CGRC (Governance, Risk and Compliance) exam is 125 qs in 180 min. CertGrid's timed mock is a fixed 125 questions.
What is the passing score for (ISC)² CGRC (Governance, Risk and Compliance)?
ISC2 grades the CGRC on a 1000-point scaled score with 700 required to pass; the scaled score is not a raw percentage. CertGrid reports your percent-correct on this mock separately as a readiness indicator. You have about 180 min to complete it. CertGrid scores your practice attempts the same way so you know when you are ready.
Are these official (ISC)² CGRC (Governance, Risk and Compliance) exam questions?
No. CertGrid is an independent practice platform. We do not provide real or leaked exam questions. Our questions are original and designed to help you practice the concepts, scenarios, and difficulty style of the (ISC)² CGRC (Governance, Risk and Compliance) exam.
Can I practice (ISC)² CGRC (Governance, Risk and Compliance) for free?
Yes. You can start practicing (ISC)² CGRC (Governance, Risk and Compliance) for free with a fixed set of 20 practice questions per exam. Paid plans unlock full timed exams, complete explanations, and domain analytics.
What CertGrid is (and is not)
CertGrid is an independent IT certification practice platform for Azure, AWS, Google, Cisco, Security, Linux, Kubernetes, Terraform, and other certification tracks. It provides objective-mapped practice questions, readiness scoring, weak-domain drills, and explanations to help learners understand what to study next.
Independent & original. CertGrid is an independent practice platform and is not affiliated with or endorsed by ISC2. Questions are original practice items designed to mirror certification concepts and exam style. CertGrid does not provide official exam questions or braindumps.