ISC2 Certified in Governance, Risk and Compliance (CGRC) β Questions and Answers
Question 1: A company's board receives a monthly dashboard of compliance metrics. This practice best demonstrates which governance principle?
- Transparency and oversight (Correct answer)
- Legal compliance
- Operational efficiency
- Risk tolerance
Correct answer: Transparency and oversight
Providing the board with regular compliance metrics demonstrates transparency and enables effective oversight by the governing body.
Question 2: Which of the following is an objective of the System Characterization step under SP 800-30?
- Establish Data and Information Sensitivity Level (Correct answer)
- Establish System Testing Procedures
- Establish Threat and Vulnerability Matrix
- Establish System Control Framework
Correct answer: Establish Data and Information Sensitivity Level
Explanation: <br> One of the objectives of the System Characterization step under SP 800-30 is to establish the data and information sensitivity level. This involves identifying and categorizing the sensitivity of data and information processed, stored, or transmitted by the system. Understanding the sensitivity level helps in determining appropriate security controls and risk management measures to protect the information adequately.
Question 3: While tailoring a MODERATE baseline, a system owner wants to add a control from SP 800-53 that addresses a specific threat in the system's operating environment β a threat not reflected in the initial risk assessment. The new control has organization-defined parameters (ODPs) that were never configured by the organization. Which sequence of actions is correct?
- Add the control to the SSP with a note that ODPs are pending, implement the control using vendor defaults, and resolve the ODPs during the continuous monitoring phase.
- Configure the ODPs using organizational risk tolerance guidance or by requesting the organization's parameter values, document the tailored control in the SSP, and assess it during security assessment. (Correct answer)
- Escalate to the authorizing official to determine if a new risk assessment is required before any control additions are made outside the approved baseline.
- Reject the addition because controls outside the approved baseline tailoring guidance require a formal change control process and cannot be added during control selection.
Correct answer: Configure the ODPs using organizational risk tolerance guidance or by requesting the organization's parameter values, document the tailored control in the SSP, and assess it during security assessment.
Adding controls beyond the baseline is explicitly permitted β and often expected β when the threat environment warrants it. SP 800-37 and SP 800-53 both support this. The correct process is: configure any ODPs using organizational guidance (or request them), document the tailored addition in the SSP, and include the control in the security assessment scope. Option A is flawed because using vendor defaults for ODPs without organizational concurrence violates the intent of ODPs and may not align with risk tolerance. Option B overstates AO involvement β minor control additions don't require a new risk assessment, though judgment applies. Option D mischaracterizes the tailoring process; adding controls is a normal tailoring activity, not a special change control event.
Question 4: An AO is reviewing an authorization package and finds that most HIGH-impact controls are satisfied, but two critical controls have open POA&M items. The BEST course of action is:
- Issue an ATO with terms requiring timely remediation of the open items (Correct answer)
- Remove the controls from scope to clear the package
- Automatically deny authorization until all findings are closed
- Transfer the system to a lower-impact categorization
Correct answer: Issue an ATO with terms requiring timely remediation of the open items
An AO may issue an ATO with conditions requiring remediation of open items by specified milestones, balancing operational need against residual risk.
Question 5: What is the primary benefit of integrating threat intelligence feeds into a continuous monitoring program?
- Automating all incident response actions
- Replacing periodic penetration testing requirements
- Providing context about active threats to prioritize monitoring and response activities (Correct answer)
- Eliminating the need for internal vulnerability assessments
Correct answer: Providing context about active threats to prioritize monitoring and response activities
Threat intelligence feeds help organizations understand which threats are actively targeting their sector, allowing them to prioritize monitoring efforts on the most relevant risks.
Question 6: An organization's compliance policy requires annual vendor due diligence reviews. A critical vendor's contract renews mid-year without a review. This BEST represents which type of compliance failure?
- A design deficiency in the policy
- An operational failure to execute a defined control (Correct answer)
- An approved policy exception
- A regulatory gap in applicable law
Correct answer: An operational failure to execute a defined control
The policy (design) is sound, but the failure to execute the review on schedule is an operational control failure.
Question 7: Which of the following is a KEY output of the risk identification phase?
- An approved budget for risk mitigation activities
- A set of key risk indicators (KRIs) for ongoing monitoring
- A prioritized list of risk treatment options
- A risk register containing identified risks and their attributes (Correct answer)
Correct answer: A risk register containing identified risks and their attributes
The risk register is the primary output of risk identification, capturing each identified risk along with its description, owner, and relevant attributes.
Question 8: In Certified Governance Risk and Compliance, what role does continuing education play in policy development?
- To keep professionals current with evolving standards, technologies, and best practices (Correct answer)
- To prevent professionals from advancing in their careers
- To increase testing frequency for compliance purposes
- To replace initial certification requirements
Correct answer: To keep professionals current with evolving standards, technologies, and best practices
Continuing education ensures professionals stay current with new developments, evolving standards, and emerging best practices in their field, maintaining competence throughout their careers.
Question 9: A company operates in 12 countries with varying local laws. What is the BEST approach to compliance program design?
- Use a core global framework with local adaptations for jurisdiction-specific requirements (Correct answer)
- Create entirely separate programs for each country
- Apply the strictest single standard globally
- Follow only the laws of the country of incorporation
Correct answer: Use a core global framework with local adaptations for jurisdiction-specific requirements
A core global framework with local adaptations balances consistency and efficiency with the need to meet jurisdiction-specific legal requirements.
Question 10: According to the Risk Management Framework (RMF), which role has a primary responsibility to report the security status of the information system to the authorizing official (AO) and other appropriate organizational officials on an ongoing basis in accordance with the monitoring strategy?
- Information system security officer (ISSO)
- Independent assessor
- Senior information assurance officer (SIAO)
- Common control provider (Correct answer)
Correct answer: Common control provider
Explanation: <br> According to the Risk Management Framework (RMF), the Common Control Provider has the primary responsibility to report the security status of the information system to the authorizing official (AO) and other appropriate organizational officials on an ongoing basis in accordance with the monitoring strategy. The Common Control Provider ensures that common controls are effectively implemented and maintained across the organization's information systems.
Question 11: Which privacy-by-design principle requires that privacy protections be built into system architecture from the start rather than added on afterward?
- Privacy as the default setting
- Proactive not reactive; preventative not remedial (Correct answer)
- Visibility and transparency
- End-to-end security
Correct answer: Proactive not reactive; preventative not remedial
The 'proactive not reactive; preventative not remedial' principle of privacy by design means anticipating and preventing privacy-invasive events before they occur, rather than fixing problems after the fact.
Question 12: Which element distinguishes an effective compliance program from a merely 'paper' compliance program?
- The frequency of policy updates
- Demonstrated enforcement and corrective action (Correct answer)
- The size of the compliance budget
- The number of written policies
Correct answer: Demonstrated enforcement and corrective action
An effective compliance program demonstrates actual enforcement β including discipline and corrective action β rather than just having written policies that are not acted upon.
Question 13: The RMF starting point for architectural description includes the subcomponent of system boundaries, which represents what intended system?
- The system is owned by the authorizing official
- The system is overseen by the information system owner
- The systems that are immediately adjacent to the intended system (Correct answer)
- All other systems within the organization
Correct answer: The systems that are immediately adjacent to the intended system
Explanation: <br> In the Risk Management Framework (RMF), when defining system boundaries, the focus is on identifying the systems that are immediately adjacent to the intended system. This helps in understanding the interfaces and dependencies between systems, which is crucial for assessing and managing risks effectively.
Question 14: An organization operates a cloud-hosted system and wants to leverage an existing FedRAMP authorization. Which RMF concept supports reusing another system's security authorization package?
- Overlays
- Reciprocity (Correct answer)
- Continuous Monitoring
- Tailoring
Correct answer: Reciprocity
Reciprocity allows organizations to accept an existing authorization package rather than duplicating assessment efforts, reducing redundancy.
Question 15: Under IIA Standards, the internal audit function's independence is primarily safeguarded by:
- Having audit staff rotate roles with management
- Limiting audit scope to financial controls only
- Reporting functionally to the board or audit committee (Correct answer)
- Using only external auditors for sensitive reviews
Correct answer: Reporting functionally to the board or audit committee
Functional reporting to the board or audit committee preserves organizational independence by keeping internal audit free from management influence.
Question 16: An organization is selecting controls for a HIGH-impact system under NIST SP 800-53. Which document provides the STARTING POINT for selecting the initial control baseline?
- NIST SP 800-37 (RMF)
- FIPS 199 (Security Categorization)
- NIST SP 800-30 (Risk Assessment)
- NIST SP 800-53B (Control Baselines) (Correct answer)
Correct answer: NIST SP 800-53B (Control Baselines)
NIST SP 800-53B provides the control baselines β LOW, MODERATE, and HIGH β that serve as the starting point for control selection. Once the system is categorized (using FIPS 199), practitioners turn to SP 800-53B to identify the appropriate baseline, which is then tailored based on risk assessment results and organizational factors.
Question 17: What document formally records the outcome of the system categorization process and is included in the system security plan?
- Plan of action and milestones (POA&M)
- Security impact analysis report
- Privacy impact assessment (PIA)
- FIPS 199 system security categorization form (Correct answer)
Correct answer: FIPS 199 system security categorization form
The FIPS 199 categorization form documents the security category determination and is incorporated into the system security plan as formal evidence.
Question 18: An organization operating in multiple jurisdictions must consider different regulatory requirements in its risk assessments. This cross-border complexity is an example of:
- Compliance risk (Correct answer)
- Reputational risk
- Strategic risk
- Operational risk
Correct answer: Compliance risk
Compliance risk is the risk of legal or regulatory sanctions, financial loss, or reputational harm from failure to comply with applicable laws and regulations.
Question 19: A TPRM program assigns vendors to risk tiers. Which factor most directly determines a vendor's initial risk tier?
- Vendor's geographic location
- Vendor's annual revenue
- Length of the existing vendor relationship
- Criticality of services provided and data access level (Correct answer)
Correct answer: Criticality of services provided and data access level
Risk tiering is primarily driven by the sensitivity of data accessed and the criticality of services the vendor delivers to operations.
Question 20: Which NIST publication provides the primary guidance for categorizing federal information and information systems?
- FIPS 200
- FIPS 199 (Correct answer)
- NIST SP 800-53
- NIST SP 800-37
Correct answer: FIPS 199
FIPS 199 (Standards for Security Categorization of Federal Information and Information Systems) is the primary standard that defines security categories for federal information and systems.
Question 21: Which approach is most effective for mastering third-party risk in Certified Governance Risk and Compliance?
- Relying solely on on-the-job experience
- Combining theoretical study with practical application and regular review (Correct answer)
- Memorizing textbook definitions without understanding
- Studying only immediately before examinations
Correct answer: Combining theoretical study with practical application and regular review
The most effective approach combines theoretical understanding with practical application, reinforced by regular review and assessment, enabling deeper comprehension and long-term retention.
Question 22: Which of the following best describes 'audit universe'?
- The complete inventory of auditable entities and activities within an organization (Correct answer)
- The list of external stakeholders who receive audit reports
- The total number of auditors available for engagements
- The set of standards governing audit practice
Correct answer: The complete inventory of auditable entities and activities within an organization
The audit universe encompasses all potential auditable areas, including processes, systems, departments, and locations.
Question 23: What is the primary objective of third-party risk in Certified Governance Risk and Compliance?
- To generate revenue for testing organizations
- To limit access to the profession
- To ensure competence and proficiency in core third-party risk concepts (Correct answer)
- To replace practical experience entirely
Correct answer: To ensure competence and proficiency in core third-party risk concepts
The primary objective of third-party risk knowledge is to ensure practitioners have the competence and proficiency needed to perform effectively and safely in their professional roles.
Question 24: Which of the following best describes a 'HIGH' impact level under FIPS 199?
- No adverse effects on mission capabilities
- Serious adverse effects on organizational operations, assets, or individuals
- Limited adverse effects on organizational operations or assets
- Severe or catastrophic adverse effects on organizational operations, assets, or individuals (Correct answer)
Correct answer: Severe or catastrophic adverse effects on organizational operations, assets, or individuals
FIPS 199 defines a HIGH impact as one where a loss could be expected to have a severe or catastrophic adverse effect on organizational operations, assets, or individuals.
Question 25: Which of the following best describes due diligence in Certified Governance Risk and Compliance compliance programs?
- Following only the most basic requirements
- Conducting thorough investigation and analysis before making decisions (Correct answer)
- Making quick decisions without research
- Relying solely on past experience
Correct answer: Conducting thorough investigation and analysis before making decisions
Due diligence involves comprehensive investigation, analysis, and verification of relevant facts before making decisions, ensuring all regulatory and professional requirements are understood and met.
Question 26: During risk treatment, an organization decides to stop offering a high-risk product line to eliminate exposure. This strategy is:
- Risk transfer
- Risk acceptance
- Risk mitigation
- Risk avoidance (Correct answer)
Correct answer: Risk avoidance
Risk avoidance means eliminating the activity or condition that gives rise to the risk entirely, removing exposure rather than managing it.
Question 27: Under FedRAMP, what is the purpose of the Provisional Authority to Operate (P-ATO)?
- Allows agencies to operate systems without full authorization
- Authorizes penetration testing on federal systems
- Provides a temporary waiver for non-compliant systems
- Grants authorization from the Joint Authorization Board for cloud services used by multiple agencies (Correct answer)
Correct answer: Grants authorization from the Joint Authorization Board for cloud services used by multiple agencies
A FedRAMP P-ATO is granted by the Joint Authorization Board (JAB) and allows cloud service providers to offer services to multiple federal agencies under one authorization.
Question 28: A CGRC practitioner is reviewing the System Security Plan (SSP) and notices that some controls are marked as 'inherited' from a common control provider. What does inheriting a control mean in the context of the RMF?
- The system receives the security capability from an external provider and does not need to re-implement it (Correct answer)
- The control has been waived and does not apply to the system
- The system owner must re-implement the control locally to verify it works
- The control must be enhanced before it can be applied to the system
Correct answer: The system receives the security capability from an external provider and does not need to re-implement it
In the RMF, inheriting a control means the system leverages a security capability already implemented by a common control provider (e.g., a data center's physical security or a shared authentication service). The inheriting system documents this in its SSP and relies on the provider's authorization rather than re-implementing the control itself.
Question 29: Which management approach in Certified Governance Risk and Compliance emphasizes continuous improvement through small, incremental changes?
- Crisis management approach
- Complete organizational restructuring
- Laissez-faire management
- Kaizen methodology (Correct answer)
Correct answer: Kaizen methodology
Kaizen is a Japanese management philosophy that focuses on continuous improvement through small, incremental changes involving all employees, leading to sustained improvement over time.
Question 30: Under the Sarbanes-Oxley Act (SOX), which section requires management to assess and report on internal controls over financial reporting?
- Section 906
- Section 201
- Section 404 (Correct answer)
- Section 302
Correct answer: Section 404
SOX Section 404 requires management to assess the effectiveness of internal controls over financial reporting and have auditors attest to that assessment.
Question 31: Under GDPR, what is the maximum timeframe within which a data breach must be reported to the supervisory authority?
- 72 hours (Correct answer)
- 48 hours
- 7 days
- 24 hours
Correct answer: 72 hours
GDPR Article 33 requires that personal data breaches be reported to the supervisory authority within 72 hours of becoming aware of the breach, where feasible.
Question 32: Which of the following best describes the relationship between security and privacy under the CGRC framework?
- Security programs are required only for classified systems, while privacy applies to all
- Privacy compliance automatically satisfies all security requirements
- Security and privacy are independent programs with no overlap
- Security is a prerequisite for privacy, but privacy requirements extend beyond security controls (Correct answer)
Correct answer: Security is a prerequisite for privacy, but privacy requirements extend beyond security controls
Security controls protect confidentiality, integrity, and availability of information, but privacy also requires addressing data minimization, notice, consent, and individual rights beyond traditional security.
Question 33: During control selection, a risk analyst identifies that a required baseline control would cost significantly more to implement than the potential loss from the risk it mitigates. The organization decides not to implement the control. This decision is BEST described as:
- Risk acceptance with documented justification (Correct answer)
- Risk avoidance
- Risk transference
- Control compensation
Correct answer: Risk acceptance with documented justification
When an organization consciously decides not to implement a control because the cost outweighs the benefit and accepts the residual risk, this is risk acceptance. Proper risk acceptance requires documentation and authorization from the appropriate official. Risk avoidance eliminates the activity causing the risk, compensation involves alternative controls, and transference shifts risk to another party.
Question 34: Which authorization approach considers time elapsed since the authorization results were produced, the environment of operation, the criticality/sensitivity of the information, and the risk tolerance of the other organization?
- Single
- Leveraged (Correct answer)
- Joint
- Site-specific
Correct answer: Leveraged
Explanation: <br> The leveraged authorization approach considers factors such as time elapsed since the authorization results were produced, the environment of operation, the criticality/sensitivity of the information, and the risk tolerance of the other organization. This approach leverages existing authorization results and documentation to streamline the authorization process for similar systems or environments, reducing duplication of effort and ensuring consistency in security posture.
Question 35: A policy gap analysis MOST commonly identifies:
- Areas where no policy exists to address a known risk or requirement (Correct answer)
- Outdated procedures that need reformatting
- Vendors that have not signed data processing agreements
- Employees who have not completed policy training
Correct answer: Areas where no policy exists to address a known risk or requirement
A gap analysis compares current policy coverage against required risks or regulations to identify areas lacking adequate policy controls.
Question 36: What is the purpose of security impact analysis?
- To determine the extent to which proposed or actual changes to the system or its environment of operation can affect or have affected the systemβs security posture (Correct answer)
- None of the above
- To determine the level of impact of the violation of the confidentiality of PII
- To determine if the information system processes PII
Correct answer: To determine the extent to which proposed or actual changes to the system or its environment of operation can affect or have affected the systemβs security posture
Explanation: <br> Security impact analysis aims to assess the potential or actual impact of changes on the security posture of a system or its operational environment. It helps in understanding the risks associated with modifications and enables organizations to make informed decisions to safeguard their security posture.
Question 37: The Basel III framework primarily applies to which type of organization?
- Government agencies
- Insurance companies
- Banks and financial institutions (Correct answer)
- Healthcare organizations
Correct answer: Banks and financial institutions
Basel III is an international regulatory framework developed by the Basel Committee on Banking Supervision to strengthen regulation, supervision, and risk management of banks.
Question 38: In Certified Governance Risk and Compliance, what role does continuing education play in regulatory requirements?
- To keep professionals current with evolving standards, technologies, and best practices (Correct answer)
- To prevent professionals from advancing in their careers
- To replace initial certification requirements
- To increase testing frequency for compliance purposes
Correct answer: To keep professionals current with evolving standards, technologies, and best practices
Continuing education ensures professionals stay current with new developments, evolving standards, and emerging best practices in their field, maintaining competence throughout their careers.
Question 39: Under NERC CIP standards, what is the primary purpose of the BES Cyber System categorization (High, Medium, Low)?
- Setting backup frequency requirements
- Determining penalty amounts for violations
- Establishing incident response priorities
- Identifying the applicable security requirements for each system (Correct answer)
Correct answer: Identifying the applicable security requirements for each system
NERC CIP categorizes BES Cyber Systems as High, Medium, or Low impact to determine which security requirements apply, with stricter controls for higher-impact systems.
Question 40: During a PIA, an agency determines that a new web portal will collect users' home addresses and date of birth. Which analysis BEST demonstrates that the agency is applying fair information practice principles (FIPPs)?
- Verifying that the system has received an Authority to Operate (ATO) before collecting the data
- Ensuring that the system owner has signed a Rules of Behavior document
- Documenting the legal authority for collection, the purpose, and the planned retention and disposal schedule for the data (Correct answer)
- Confirming that the data will be encrypted at rest and in transit using AES-256
Correct answer: Documenting the legal authority for collection, the purpose, and the planned retention and disposal schedule for the data
Fair Information Practice Principles (FIPPs) require agencies to document the legal authority for collection, limit collection to what is necessary (data minimization), state the purpose, and define retention and disposal. While encryption and ATOs are important security measures, they address confidentiality and authorization β not the privacy-specific FIPPs that PIAs are designed to analyze.
Question 41: What is 'vendor concentration risk' in the context of third-party risk management?
- A vendor that focuses exclusively on one industry sector
- Risk arising from vendors that hold concentrated market share
- A vendor storing data in a single geographic location
- Over-reliance on a single vendor or small group of vendors for critical services (Correct answer)
Correct answer: Over-reliance on a single vendor or small group of vendors for critical services
Vendor concentration risk occurs when an organization depends too heavily on one vendor, meaning a failure or exit by that vendor could severely disrupt operations.
Question 42: When performing control tailoring, an organization adds additional controls beyond the baseline to address a specific, identified threat related to insider privilege abuse. What is this tailoring action called?
- Parameterization
- Scoping
- Control supplementation (Correct answer)
- Baseline substitution
Correct answer: Control supplementation
Control supplementation involves adding controls or control enhancements to a baseline to address specific threats, vulnerabilities, or risks that are not adequately covered by the baseline alone. In this case, insider threat concerns drive the addition of controls beyond what the standard HIGH baseline provides. Scoping removes non-applicable controls; parameterization assigns specific values to control parameters; baseline substitution is not a recognized NIST tailoring action.
Question 43: An organization is implementing a hybrid cloud system where some components reside on-premises and others in a FedRAMP-authorized CSP environment. During control selection, the security engineer wants to inherit controls from the CSP's authorization package. Which factor MOST critically determines whether a control can be legitimately inherited from the CSP?
- The control must appear as 'fully inherited' in the CSP's Customer Responsibility Matrix (CRM) with no customer implementation requirements.
- The CSP's authorization must be at the same or higher impact level as the organization's system.
- The organization's authorizing official must formally accept the CSP's risk posture in writing before inheritance is applied.
- The CSP's authorization boundary must explicitly encompass the specific service or feature the organization is consuming. (Correct answer)
Correct answer: The CSP's authorization boundary must explicitly encompass the specific service or feature the organization is consuming.
Control inheritance from a CSP is only valid when the CSP's authorization boundary explicitly covers the specific service being consumed. A CSP may hold a broad FedRAMP authorization, but if the organization is using a service or feature not within that boundary, inheritance is invalid regardless of the overall authorization level. The CRM (Option A) is important but secondary β the boundary scoping is the prerequisite. Impact level matching (Option C) is a common misconception; the organization must ensure adequate coverage but the boundary is the gating factor. AO acceptance (Option D) is good practice but does not itself validate inheritance.
Question 44: Which NIST SP 800-53 control family specifically addresses privacy requirements integrated into the security control framework?
- MP β Media Protection
- PT β PII Processing and Transparency (Correct answer)
- AT β Awareness and Training
- AC β Access Control
Correct answer: PT β PII Processing and Transparency
NIST SP 800-53 Rev. 5 introduced the PT (PII Processing and Transparency) family, which includes controls for consent, purpose specification, and data minimization.
Question 45: What is the key difference between compliance monitoring and compliance auditing?
- Monitoring is done by regulators; auditing is done internally
- Monitoring focuses on financial data; auditing covers all areas
- Monitoring is preventive; auditing is corrective
- Monitoring is ongoing and continuous; auditing is periodic and formal (Correct answer)
Correct answer: Monitoring is ongoing and continuous; auditing is periodic and formal
Compliance monitoring is a continuous, ongoing activity that checks day-to-day compliance, while auditing is a periodic, formal, and systematic evaluation.
Question 46: Which approach BEST supports continuous monitoring in a DevSecOps pipeline?
- Conducting manual code reviews for all commits
- Running security scans on finished products before deployment
- Embedding automated security testing and compliance checks at every stage of the CI/CD pipeline (Correct answer)
- Limiting continuous monitoring to production environments
Correct answer: Embedding automated security testing and compliance checks at every stage of the CI/CD pipeline
Embedding automated security checks throughout the CI/CD pipeline (shift-left) enables continuous monitoring from code commit through deployment, catching issues early.
Question 47: An organization discovers that a compensating control is needed because implementing a required baseline control is technically infeasible. What document must be formally approved to justify this?
- Security Assessment Report (SAR)
- Risk Acceptance Memo
- Plan of Action Waiver / Control Tailoring Justification (Correct answer)
- Plan of Action and Milestones (POA&M)
Correct answer: Plan of Action Waiver / Control Tailoring Justification
A tailoring justification (sometimes called a waiver) must be documented and approved by the Authorizing Official when a baseline control cannot be implemented.
Question 48: When documenting a compliance policy, which attribute is MOST important to include to ensure the policy remains enforceable and current?
- The full text of all applicable regulations
- Version number, effective date, review date, and policy owner (Correct answer)
- A list of every system the policy governs
- The names of all employees who reviewed the policy
Correct answer: Version number, effective date, review date, and policy owner
Version control, effective and review dates, and an identified owner ensure the policy can be tracked, maintained, and enforced over time.
Question 49: Which phase of the audit lifecycle involves confirming the audit's scope, objectives, and approach with management before fieldwork begins?
- Audit reporting
- Preliminary survey / planning meeting (Correct answer)
- Follow-up review
- Audit completion
Correct answer: Preliminary survey / planning meeting
The planning meeting (sometimes called an entrance conference) aligns auditor and management expectations before substantive testing starts.
Question 50: Which type of third-party risk arises when a vendor's unethical practices damage your organization's public reputation?
- Strategic risk
- Compliance risk
- Operational risk
- Reputational risk (Correct answer)
Correct answer: Reputational risk
Reputational risk occurs when association with a vendor whose practices are unethical or controversial reflects negatively on your organization.
Question 51: When a new policy conflicts with a previously existing policy, the APPROPRIATE resolution is to:
- Allow both policies to coexist and let employees decide which applies
- Formally retire or update the older policy to eliminate the conflict (Correct answer)
- Escalate the conflict to an external auditor for resolution
- Apply the older policy since it was established first
Correct answer: Formally retire or update the older policy to eliminate the conflict
Conflicting policies create compliance confusion; the older document should be formally superseded, updated, or retired to maintain a coherent policy framework.
Question 52: An organization is implementing a new cloud-based payroll system that processes sensitive employee data. During control selection, the security team must choose between implementing a hardware security module (HSM) or software-based encryption. Which NIST SP 800-53 control family is MOST directly relevant to this decision?
- Configuration Management (CM)
- System and Communications Protection (SC) (Correct answer)
- Audit and Accountability (AU)
- Access Control (AC)
Correct answer: System and Communications Protection (SC)
System and Communications Protection (SC) directly governs cryptographic protection mechanisms, including encryption of data in transit and at rest. SC controls address the use of cryptographic modules (like HSMs) and encryption algorithms to protect sensitive information, making it the most relevant control family for this decision.
Question 53: What is the principle of data minimization in the context of privacy protection?
- Encrypting all PII using the strongest available algorithm
- Storing PII in the fewest number of databases possible
- Limiting access to PII to only one authorized user
- Collecting and retaining only the minimum amount of PII necessary for the stated purpose (Correct answer)
Correct answer: Collecting and retaining only the minimum amount of PII necessary for the stated purpose
Data minimization requires that organizations collect only the PII that is directly relevant and necessary to accomplish the specified purpose, reducing exposure risk.
Question 54: Under which circumstance is attorney-client privilege most likely to protect a compliance investigation report?
- When the report is marked 'confidential'
- When conducted at the direction of legal counsel for the purpose of providing legal advice (Correct answer)
- When the report is shared with all employees
- When the compliance officer holds a law degree
Correct answer: When conducted at the direction of legal counsel for the purpose of providing legal advice
Attorney-client privilege protects investigation reports when they are conducted at the direction of counsel for the purpose of rendering legal advice to the organization.
Question 55: A policy states that all passwords must be changed every 90 days. An employee with a disability cannot remember frequently changing passwords. What is the BEST compliance approach?
- Document a formal exception with compensating controls such as MFA (Correct answer)
- Grant a permanent policy exception with no compensating controls
- Deny any accommodation and enforce the policy strictly
- Remove the password requirement entirely for that employee
Correct answer: Document a formal exception with compensating controls such as MFA
A documented exception with compensating controls like MFA maintains security intent while accommodating the employee's needs.
Question 56: A CGRC professional performing a risk assessment notices that two separate low-level risks, when combined, create a high-impact exposure. This is best described as:
- Cascading risk
- Compound risk
- Aggregate risk (Correct answer)
- Residual risk
Correct answer: Aggregate risk
Aggregate risk refers to the combined effect of multiple individual risks that together create a larger overall exposure than each risk alone would suggest.
Question 57: What is the primary purpose of a Regulatory Change Management process within a compliance program?
- To track, assess, and implement changes to applicable laws and regulations (Correct answer)
- To eliminate outdated internal policies
- To report compliance violations to regulators proactively
- To lobby regulators for favorable rule changes
Correct answer: To track, assess, and implement changes to applicable laws and regulations
Regulatory Change Management ensures the organization identifies, evaluates, and responds to new or amended regulations affecting its operations.
Question 58: A system owner wants to accept the residual risk after implementing security controls. Which RMF step does this decision occur in?
- Monitor
- Implement
- Assess
- Authorize (Correct answer)
Correct answer: Authorize
The Authorize step is where the Authorizing Official (AO) formally accepts residual risk and grants or denies an Authorization to Operate (ATO).
Question 59: Which of the following BEST describes a 'compliance gap analysis'?
- A review of employee satisfaction with compliance training
- A list of all regulations that do not apply to the organization
- A financial audit of compliance program costs
- An assessment comparing current practices against required compliance obligations to identify deficiencies (Correct answer)
Correct answer: An assessment comparing current practices against required compliance obligations to identify deficiencies
A gap analysis compares where the organization is against where it needs to be under applicable requirements, surfacing areas needing remediation.
Question 60: Which element distinguishes a SOC 2 Type II report from a SOC 2 Type I report?
- Type II is performed by government auditors, while Type I uses private firms
- Type II evaluates control effectiveness over a period of time, while Type I is point-in-time (Correct answer)
- Type II includes financial controls, while Type I focuses on security only
- Type II covers more Trust Service Criteria than Type I
Correct answer: Type II evaluates control effectiveness over a period of time, while Type I is point-in-time
A SOC 2 Type II report tests whether controls operated effectively over a specified review period (typically 6β12 months), whereas Type I only assesses whether controls are suitably designed at a single point in time.
Question 61: Which NIST publication provides the catalog of security and privacy controls used in the RMF Select step?
- NIST SP 800-53 (Correct answer)
- NIST SP 800-37
- NIST SP 800-60
- NIST SP 800-30
Correct answer: NIST SP 800-53
NIST SP 800-53 provides the catalog of security and privacy controls that organizations select from during the RMF Select step.
Question 62: What is the primary purpose of stakeholder analysis in Certified Governance Risk and Compliance audit management?
- To schedule project timelines
- To identify and understand the interests and influence of all parties affected by decisions (Correct answer)
- To calculate financial returns on investment
- To evaluate employee attendance records
Correct answer: To identify and understand the interests and influence of all parties affected by decisions
Stakeholder analysis identifies all parties who have an interest in or are affected by a project or decision, assessing their level of influence and interest to develop appropriate engagement strategies.
Question 63: Which concept refers to a system's ability to inherit security controls implemented by a common control provider?
- Control inheritance (Correct answer)
- Control aggregation
- Control delegation
- Control abstraction
Correct answer: Control inheritance
Control inheritance allows a system to leverage and rely on controls already implemented by a shared infrastructure or service provider without re-implementing them.
Question 64: What is a compensating control?
- A control that monitors the effectiveness of other controls
- An alternative control used when the required control cannot be implemented (Correct answer)
- A control applied only during incident response
- A control that exceeds baseline requirements
Correct answer: An alternative control used when the required control cannot be implemented
A compensating control provides equivalent protection when the primary required control cannot be implemented due to technical or operational constraints.
Question 65: In Certified Governance Risk and Compliance, what does the PDCA cycle stand for?
- Plan, Do, Check, Act (Correct answer)
- Process, Design, Create, Analyze
- Prioritize, Delegate, Communicate, Approve
- Prepare, Develop, Control, Assess
Correct answer: Plan, Do, Check, Act
The PDCA cycle (Plan-Do-Check-Act) is a continuous improvement framework where you plan the change, implement it, check the results, and act on what you learned to refine the process.
Question 66: In Certified Governance Risk and Compliance, what does the PDCA cycle stand for?
- Prioritize, Delegate, Communicate, Approve
- Prepare, Develop, Control, Assess
- Plan, Do, Check, Act (Correct answer)
- Process, Design, Create, Analyze
Correct answer: Plan, Do, Check, Act
The PDCA cycle (Plan-Do-Check-Act) is a continuous improvement framework where you plan the change, implement it, check the results, and act on what you learned to refine the process.
Question 67: Which metric best measures the efficiency of the audit process?
- Audit committee satisfaction score
- Actual audit hours versus budgeted hours (Correct answer)
- Percentage of recommendations implemented
- Number of findings per audit
Correct answer: Actual audit hours versus budgeted hours
Comparing actual to budgeted hours directly measures how efficiently audit resources were used during an engagement.
Question 68: An auditor discovers a control deficiency that could lead to material misstatement but has not yet caused one. This is classified as:
- A control gap
- A material weakness
- A significant deficiency (Correct answer)
- An immaterial finding
Correct answer: A significant deficiency
A significant deficiency is a control deficiency that is less severe than a material weakness but important enough to merit attention.
Question 69: Which of the following is considered a 'leading indicator' of compliance program effectiveness?
- Number of incidents reported to regulators
- Percentage of high-risk employees completing targeted training (Correct answer)
- Number of regulatory enforcement actions received
- Total fines paid in the prior year
Correct answer: Percentage of high-risk employees completing targeted training
Leading indicators like targeted training completion rates measure preventive actions taken before problems occur, unlike lagging indicators that measure outcomes after violations.
Question 70: Which governance document formally defines the authority, responsibilities, and membership of a board committee?
- Strategic plan
- Committee charter (Correct answer)
- Risk register
- Policy statement
Correct answer: Committee charter
A committee charter formally establishes the authority, scope, responsibilities, and composition of a board committee.
Question 71: What is the role of 'tone at the top' in an effective compliance program?
- Senior leadership visibly demonstrating commitment to ethical conduct and compliance (Correct answer)
- The decibel level of security alarms in the facility
- It refers to the volume level of compliance training sessions
- The compliance officer's communication style with regulators
Correct answer: Senior leadership visibly demonstrating commitment to ethical conduct and compliance
Tone at the top means senior leadership models and champions ethical behavior, which is a foundational driver of organizational compliance culture.
Question 72: A federal agency is selecting controls for a system that processes CUI but is not yet formally categorized under FIPS 199. The program manager instructs the security team to begin with the MODERATE baseline to 'get started.' Under NIST RMF, what is the most significant problem with this approach?
- Preliminary control selection is permitted as long as the categorization is completed before the Authorization to Operate is issued
- CUI systems are required to use CMMC control sets rather than NIST SP 800-53 baselines regardless of FIPS 199 categorization status
- Control selection must follow a completed FIPS 199 categorization and FIPS 200 minimum-security determination; applying a baseline prior to categorization means controls may be misaligned with actual system impact levels (Correct answer)
- The MODERATE baseline is exclusively reserved for national security systems and cannot be applied to civilian CUI systems without a waiver
Correct answer: Control selection must follow a completed FIPS 199 categorization and FIPS 200 minimum-security determination; applying a baseline prior to categorization means controls may be misaligned with actual system impact levels
NIST RMF Step 2 (Categorize) must be completed before Step 3 (Select Controls). The FIPS 199 categorization drives the impact level, which in turn determines the appropriate NIST SP 800-53 baseline under FIPS 200. Starting with a MODERATE baseline before categorization risks selecting an incorrect baseline β the system could warrant HIGH controls, or scoping decisions may be made on false assumptions. Preliminary selection is not sanctioned by RMF as a substitute for the formal categorization step.
Question 73: Which regulatory requirement directly mandates that covered entities ensure their business associates implement appropriate safeguards for protected health information (PHI)?
- SOX Section 404
- PCI DSS Requirement 12.8
- HIPAA Privacy and Security Rules (Correct answer)
- GDPR Article 28
Correct answer: HIPAA Privacy and Security Rules
HIPAA requires covered entities to obtain satisfactory assurances from business associates β typically via a BAA β that PHI will be appropriately protected.
Question 74: In Certified Governance Risk and Compliance, what is the primary purpose of regulatory compliance?
- To ensure adherence to laws, rules, and standards that govern the profession (Correct answer)
- To maximize organizational profits
- To eliminate the need for internal policies
- To reduce employee workloads
Correct answer: To ensure adherence to laws, rules, and standards that govern the profession
Regulatory compliance ensures that organizations and professionals follow all applicable laws, regulations, and standards, protecting the public and maintaining professional integrity.
Question 75: Which best describes the 'tone at the top' principle in compliance programs?
- Top executives approve all compliance policies
- Compliance training begins with executive leadership
- Senior leaders model ethical behavior and visibly support compliance (Correct answer)
- Executives receive stricter penalties for violations
Correct answer: Senior leaders model ethical behavior and visibly support compliance
Tone at the top means senior leadership actively demonstrates commitment to ethical conduct and compliance, which shapes the organizational culture.
Question 76: Under FISMA, how often must federal systems with an ATO undergo reauthorization if no significant change occurs?
- Every year
- Continuous monitoring replaces fixed reauthorization cycles (Correct answer)
- Every three years
- Every two years
Correct answer: Continuous monitoring replaces fixed reauthorization cycles
NIST SP 800-37 Rev. 2 shifted from fixed 3-year reauthorization cycles to ongoing authorization supported by continuous monitoring.
Question 77: Under the NIST Cybersecurity Framework, which function most directly addresses identifying and managing third-party risks?
- Respond
- Identify (Correct answer)
- Recover
- Protect
Correct answer: Identify
The Identify function of the NIST CSF includes supply chain risk management and establishing an understanding of third-party dependencies.
Question 78: Which document produced during the RMF process describes a system's security and privacy requirements, the controls selected to satisfy those requirements, and the implementation status of each control?
- Authorization Decision Document (ADD)
- Security Assessment Report (SAR)
- Privacy Impact Assessment (PIA)
- System Security Plan (SSP) (Correct answer)
Correct answer: System Security Plan (SSP)
The System Security Plan (SSP) is the primary document that records selected controls, their implementation details, and planned milestones.
Question 79: An organization operating a moderate-impact system discovers that a required baseline control has an inherited implementation from a common control provider, but the provider's assessment results are over 18 months old. The system owner wants to accept the inheritance as-is to avoid re-assessment costs. What is the MOST appropriate action under NIST RMF guidance?
- Escalate to the Authorizing Official to issue a temporary waiver covering the gap until the common control provider completes its next assessment cycle
- Remove the inherited designation and implement the control locally to ensure assessment currency aligns with the system's own authorization cycle
- Accept the inherited control as-is, since common controls are the provider's responsibility and reassessment is not required at the system level
- Determine whether the inherited control still satisfies the system's security requirements and document the rationale; if assessment results are stale beyond organizational policy, request updated evidence or apply compensating controls (Correct answer)
Correct answer: Determine whether the inherited control still satisfies the system's security requirements and document the rationale; if assessment results are stale beyond organizational policy, request updated evidence or apply compensating controls
NIST SP 800-37 Rev. 2 requires system owners to verify that inherited controls continue to satisfy the system's security requirements. When assessment evidence is stale beyond organizational policy thresholds, the system owner must either obtain updated evidence from the provider, supplement with compensating controls, or formally document residual risk β not simply accept stale results by default. Blanket acceptance ignores the system owner's ongoing responsibility for inherited control adequacy.
Question 80: During a CGRC assessment, an auditor reviews an organization's consent management practices. Which characteristic makes consent valid under GDPR?
- Implied consent based on continued use of the service
- A blanket consent clause embedded in the employment contract
- Pre-checked boxes included in terms and conditions
- Freely given, specific, informed, and unambiguous indication of agreement (Correct answer)
Correct answer: Freely given, specific, informed, and unambiguous indication of agreement
GDPR requires consent to be freely given, specific, informed, and unambiguous β pre-ticked boxes and implied consent do not meet this standard.
Question 81: Which practice helps organizations detect when a vendor's financial instability could threaten service continuity?
- Reviewing vendor SLA uptime statistics monthly
- Conducting quarterly tabletop exercises with the vendor
- Monitoring vendor credit ratings, financial filings, and news alerts (Correct answer)
- Reviewing vendor employee turnover rates annually
Correct answer: Monitoring vendor credit ratings, financial filings, and news alerts
Monitoring credit ratings, public financial filings, and news provides early warning signals of financial distress that could affect a vendor's ability to deliver services.
Question 82: When applying the RMF, what does 'tailoring' security controls mean?
- Documenting controls in the System Security Plan
- Adding, removing, or modifying controls from a baseline to fit the system's environment (Correct answer)
- Assigning controls to specific staff members
- Replacing all baseline controls with custom-built solutions
Correct answer: Adding, removing, or modifying controls from a baseline to fit the system's environment
Tailoring allows organizations to adjust the control baseline by adding compensating controls, scoping controls, or applying parameter values appropriate to their risk environment.
Question 83: Which of the following best describes a 'compliance management system' (CMS)?
- A reporting dashboard for senior management
- A database of all applicable laws and regulations
- An integrated framework of policies, processes, and controls to meet compliance obligations (Correct answer)
- A software tool for tracking regulatory filings
Correct answer: An integrated framework of policies, processes, and controls to meet compliance obligations
A CMS is an integrated framework encompassing policies, procedures, training, monitoring, and corrective action processes that together manage compliance obligations.
Question 84: In Certified Governance Risk and Compliance, what role does continuing education play in authorization process?
- To prevent professionals from advancing in their careers
- To replace initial certification requirements
- To increase testing frequency for compliance purposes
- To keep professionals current with evolving standards, technologies, and best practices (Correct answer)
Correct answer: To keep professionals current with evolving standards, technologies, and best practices
Continuing education ensures professionals stay current with new developments, evolving standards, and emerging best practices in their field, maintaining competence throughout their careers.
Question 85: An organization uses automated tools to continuously collect security data but never analyzes or acts on the reports. Which ISCM principle is being violated?
- Tiered risk management
- Defense in depth
- Least privilege
- Analyze and report findings (Correct answer)
Correct answer: Analyze and report findings
Collecting data without analysis and action defeats the purpose of ISCM; findings must be reviewed and drive corrective actions.
Question 86: Which of the following scenarios BEST illustrates 'willful blindness' in the context of compliance?
- An employee who misunderstands a complex regulatory requirement
- An executive who was not present during a compliance briefing
- A manager who deliberately avoids learning about subordinates' questionable conduct (Correct answer)
- A compliance officer who misses a regulatory deadline
Correct answer: A manager who deliberately avoids learning about subordinates' questionable conduct
Willful blindness occurs when a person deliberately avoids acquiring knowledge of facts that would make them aware of a legal violation, which courts treat similarly to actual knowledge.
Question 87: The concept of 'duty of care' in board governance requires directors to:
- Act in an informed and diligent manner when making decisions (Correct answer)
- Personally guarantee the company's financial obligations
- Attend every operational meeting
- Approve all contracts above a set threshold
Correct answer: Act in an informed and diligent manner when making decisions
Duty of care requires directors to make decisions on an informed basis, exercising the diligence and prudence of a reasonable person.
Question 88: In Certified Governance Risk and Compliance, what role does continuing education play in governance principles?
- To replace initial certification requirements
- To keep professionals current with evolving standards, technologies, and best practices (Correct answer)
- To increase testing frequency for compliance purposes
- To prevent professionals from advancing in their careers
Correct answer: To keep professionals current with evolving standards, technologies, and best practices
Continuing education ensures professionals stay current with new developments, evolving standards, and emerging best practices in their field, maintaining competence throughout their careers.
Question 89: A compliance officer identifies a control that mitigates risk but is not explicitly required by any regulation. The cost to maintain the control is high. What should the officer recommend?
- Remove the control immediately to reduce costs
- Conduct a cost-benefit analysis and present findings to leadership for a risk-based decision (Correct answer)
- Transfer the risk to a third party without further analysis
- Add the control to the regulatory requirement list
Correct answer: Conduct a cost-benefit analysis and present findings to leadership for a risk-based decision
A cost-benefit analysis provides the data leadership needs to make an informed, risk-based decision about maintaining or removing the control.
Question 90: ISO/IEC 27001 requires organizations to establish, implement, maintain, and continually improve what type of system?
- Quality management system
- Business continuity management system
- Information security management system (ISMS) (Correct answer)
- Risk management framework
Correct answer: Information security management system (ISMS)
ISO/IEC 27001 specifies the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).
Question 91: Which of the following BEST describes the purpose of a compliance monitoring program?
- To detect policy violations and assess control effectiveness on an ongoing basis (Correct answer)
- To create new compliance policies annually
- To train employees on regulatory requirements
- To replace internal audits entirely
Correct answer: To detect policy violations and assess control effectiveness on an ongoing basis
Compliance monitoring provides continuous assessment of whether controls are operating effectively and policies are being followed.
Question 92: An organization is selecting controls for a system that processes Controlled Unclassified Information (CUI) and has been assigned a MODERATE impact level. Which baseline from NIST SP 800-53 should serve as the starting point for control selection?
- High baseline to ensure maximum protection
- There is no baseline β all controls must be selected individually
- Low baseline, then add controls as needed
- Moderate baseline (Correct answer)
Correct answer: Moderate baseline
NIST SP 800-53 provides three control baselines β Low, Moderate, and High β corresponding to the system's impact level as determined through FIPS 199 categorization. A system categorized as MODERATE should begin with the Moderate baseline. Organizations then tailor this baseline by adding, removing, or modifying controls based on their specific environment, threat landscape, and operational requirements.
Question 93: In NIST SP 800-53, what does the CM control family address?
- Compliance Measurements
- Configuration Management (Correct answer)
- Change Monitoring
- Contingency Management
Correct answer: Configuration Management
The CM (Configuration Management) family includes controls for establishing and maintaining baseline configurations and tracking changes to systems.
Question 94: An organization outsources its payroll processing. Which risk category is MOST relevant if the payroll vendor suffers a ransomware attack?
- Strategic risk
- Market risk
- Operational risk (Correct answer)
- Liquidity risk
Correct answer: Operational risk
A ransomware attack disrupting payroll processing represents operational risk, as it impairs a critical business function delivered by a third party.
Question 95: What is the consequence of non-compliance with regulations in Certified Governance Risk and Compliance?
- Only a verbal warning for first offenses
- Automatic waiver of requirements after appeal
- No consequences if discovered within 30 days
- Potential penalties including fines, license revocation, and legal liability (Correct answer)
Correct answer: Potential penalties including fines, license revocation, and legal liability
Non-compliance can result in serious consequences including financial penalties, loss of professional licensure, legal liability, reputational damage, and in some cases criminal prosecution.
Question 96: Which stakeholder is ultimately responsible for accepting residual risk identified through continuous monitoring activities?
- System Owner
- Risk Executive
- Chief Information Security Officer (CISO)
- Authorizing Official (AO) (Correct answer)
Correct answer: Authorizing Official (AO)
The Authorizing Official (AO) holds accountability for accepting residual risk and maintaining the system's authorization to operate.
Question 97: Policy communication strategies should PRIMARILY ensure that:
- Policy documents remain confidential to reduce risk
- Only managers receive policy training
- Policies are accessible only to compliance staff
- All affected parties are aware of and understand their obligations (Correct answer)
Correct answer: All affected parties are aware of and understand their obligations
Effective policy communication ensures that everyone subject to the policy understands their responsibilities, which is essential for compliance.
Question 98: Which HIPAA rule specifically addresses the electronic exchange of health information and establishes national standards for electronic healthcare transactions?
- Security Rule
- Breach Notification Rule
- Privacy Rule
- Transactions and Code Sets Rule (Correct answer)
Correct answer: Transactions and Code Sets Rule
The HIPAA Transactions and Code Sets Rule establishes standardized formats for electronic health information exchange, such as claims and remittance advices.
Question 99: In Certified Governance Risk and Compliance, what is the primary function of strategic planning in audit management?
- To set long-term goals and determine the best approach to achieve them (Correct answer)
- To manage the organization's social media presence
- To handle day-to-day operational tasks
- To conduct annual performance reviews
Correct answer: To set long-term goals and determine the best approach to achieve them
Strategic planning involves defining the organization's direction, making decisions on allocating resources, and establishing priorities to achieve long-term objectives.
Question 100: In Certified Governance Risk and Compliance, why is regulatory requirements knowledge important for professional certification?
- It is important only for entry-level positions
- It demonstrates competence and ensures practitioners meet established standards (Correct answer)
- It has no practical relevance to daily work
- It is only required for administrative purposes
Correct answer: It demonstrates competence and ensures practitioners meet established standards
Professional certification in specific knowledge areas demonstrates that practitioners have met established competency standards, ensuring quality of service and public protection.
Question 101: Which party is TYPICALLY responsible for formally approving an enterprise-wide security policy?
- The IT helpdesk manager
- External auditors
- Front-line employees
- Senior leadership or the board of directors (Correct answer)
Correct answer: Senior leadership or the board of directors
Enterprise-wide policies require executive or board-level approval to grant them organizational authority and demonstrate tone at the top.
Question 102: Under SOX Section 302, who is primarily responsible for certifying the accuracy of financial disclosures?
- CEO and CFO (Correct answer)
- The board of directors
- External auditors
- The compliance officer
Correct answer: CEO and CFO
SOX Section 302 requires the CEO and CFO to personally certify the accuracy of financial statements and internal controls.
Question 103: What does the term 'policy exception' refer to in a compliance program?
- A policy that applies only to senior executives
- A permanent waiver of all policy requirements
- A documented deviation from policy with defined compensating controls and approval (Correct answer)
- An undocumented workaround approved verbally by management
Correct answer: A documented deviation from policy with defined compensating controls and approval
A policy exception is a formally documented, approved deviation that includes compensating controls and a defined expiration date.
Question 104: When an agency accepts the existing authorization of a system operated by another agency, this is known as:
- Authorization reciprocity (Correct answer)
- Joint authorization
- Mutual recognition
- Delegated authorization
Correct answer: Authorization reciprocity
Authorization reciprocity allows agencies to accept each other's authorizations, reducing duplicative assessment effort.
Question 105: During a contingency plan test, an organization uses actual production data and physically shuts down the primary data center, requiring IT staff to activate the alternate site. This type of test is BEST described as which of the following?
- Full interruption test (Correct answer)
- Tabletop exercise
- Structured walk-through
- Parallel test
Correct answer: Full interruption test
A full interruption test (also called a full-scale test) involves actually shutting down the primary system and activating the backup/alternate site, making it the most realistic but also most disruptive and risky test type. A parallel test runs both sites simultaneously. A tabletop exercise is discussion-based. A structured walk-through reviews the plan without operational activation.
Question 106: Which element of a compliance program specifically addresses ensuring that disciplinary measures are applied consistently?
- The enforcement and discipline component (Correct answer)
- The regulatory horizon scanning process
- The compliance risk assessment process
- The compliance communications plan
Correct answer: The enforcement and discipline component
The enforcement and discipline component ensures that violations are consistently identified, investigated, and sanctioned, which deters future misconduct.
Question 107: Which NIST Special Publication provides the primary guidance for developing and maintaining a System Security Plan for federal information systems?
- NIST SP 800-18 (Correct answer)
- NIST SP 800-53
- NIST SP 800-37
- NIST SP 800-60
Correct answer: NIST SP 800-18
NIST SP 800-18, 'Guide for Developing Security Plans for Federal Information Systems,' provides direct guidance on SSP development. SP 800-37 covers the RMF process broadly, SP 800-53 covers the control catalog, and SP 800-60 covers system categorization.
Question 108: A financial services firm must comply with both FISMA and PCI DSS. How should their ISCM program address overlapping control requirements?
- Run separate monitoring programs for each framework to avoid confusion
- Leverage a unified monitoring program that maps common controls to both frameworks simultaneously (Correct answer)
- Prioritize FISMA requirements since it is a federal mandate
- Use PCI DSS as the baseline and supplement with FISMA-specific controls
Correct answer: Leverage a unified monitoring program that maps common controls to both frameworks simultaneously
A unified ISCM program with control mapping reduces duplication of effort by assessing shared controls once and satisfying multiple framework requirements.
Question 109: Which of the following BEST describes the concept of risk appetite?
- The total risk exposure before controls are applied
- The maximum risk an organization can withstand before insolvency
- The residual risk after all controls have been implemented
- The amount of risk an organization is willing to accept in pursuit of objectives (Correct answer)
Correct answer: The amount of risk an organization is willing to accept in pursuit of objectives
Risk appetite is the broad-based amount of risk an organization is willing to accept in pursuit of its mission and strategic goals.
Question 110: A CGRC practitioner is reviewing a control that requires multi-factor authentication (MFA) for all privileged accounts. The organization currently uses a single-factor hardware token that generates a time-based one-time password (TOTP). How should this control be characterized?
- Fully satisfied, because TOTP constitutes a second factor when combined with a username
- Partially satisfied β a Plan of Action and Milestones (POA&M) should document the gap (Correct answer)
- Not satisfied, because TOTP alone is a single-factor authentication method
- Satisfied only if the privileged accounts belong to administrators, not developers
Correct answer: Partially satisfied β a Plan of Action and Milestones (POA&M) should document the gap
A username combined with a TOTP token represents something you know (username/password) plus something you have (the token), which typically constitutes two factors. However, if the organization is only using the token without a separate password, it remains single-factor. In the common implementation where a password plus TOTP is used, MFA is satisfied. If the control is not fully met β for example, if some privileged accounts are excluded β a POA&M should document the gap and remediation timeline. Given the ambiguity in the scenario about the full implementation, partial satisfaction with a POA&M is the most prudent answer.
Question 111: Which practice ensures that vendor access to organizational systems is removed promptly when no longer needed?
- Just-in-time provisioning and automated deprovisioning (Correct answer)
- Annual vendor performance reviews
- Quarterly penetration testing of vendor systems
- Vendor onboarding checklist completion
Correct answer: Just-in-time provisioning and automated deprovisioning
Just-in-time provisioning grants access only when needed, and automated deprovisioning ensures timely revocation, reducing the window of unauthorized access.
Question 112: NIST SP 800-53B defines three control baselines. An organization is selecting controls for a Privacy Overlay application where the system processes PII for 50,000 individuals but poses LOW availability impact and MODERATE confidentiality and integrity impact. The Privacy Overlay adds controls beyond the MODERATE baseline. At what point in the RMF process does the organization formally integrate Privacy Overlay controls into the control baseline?
- During Step 4 (Assess), when the assessor identifies privacy control gaps and adds missing controls to the assessment scope
- During Step 1 (Categorize), when the privacy threshold analysis determines that PII is present and the overlay is automatically triggered
- During Step 6 (Monitor), when continuous monitoring reveals that MODERATE baseline controls are insufficient for the volume of PII processed
- During Step 2 (Select), after establishing the initial baseline and then applying overlays, tailoring guidance, and organizational parameters to produce the final control set (Correct answer)
Correct answer: During Step 2 (Select), after establishing the initial baseline and then applying overlays, tailoring guidance, and organizational parameters to produce the final control set
Control selection β including the application of overlays such as the Privacy Overlay β occurs in RMF Step 2 (Select). The process is: establish the initial baseline based on system categorization β apply overlays β tailor controls β document organization-defined parameter values β produce the final tailored control set documented in the SSP. Step 1 identifies that PII is present, but the formal integration of overlay controls into the baseline happens in Step 2. Controls are not added during assessment (Step 4) or monitoring (Step 6) β those steps evaluate and maintain controls already selected.
Question 113: Which management approach in Certified Governance Risk and Compliance emphasizes continuous improvement through small, incremental changes?
- Crisis management approach
- Kaizen methodology (Correct answer)
- Laissez-faire management
- Complete organizational restructuring
Correct answer: Kaizen methodology
Kaizen is a Japanese management philosophy that focuses on continuous improvement through small, incremental changes involving all employees, leading to sustained improvement over time.
Question 114: Which body is ultimately responsible for setting the risk appetite of an organization?
- Board of Directors (Correct answer)
- Senior Management
- Chief Risk Officer
- Internal Audit Committee
Correct answer: Board of Directors
The Board of Directors holds ultimate responsibility for defining and approving the organization's risk appetite.
Question 115: What is the purpose of including a 'scope' section in a policy document?
- To describe penalties for non-compliance
- To define which people, systems, or processes the policy applies to (Correct answer)
- To list the policy's references and citations
- To outline the policy development methodology used
Correct answer: To define which people, systems, or processes the policy applies to
The scope section clarifies applicability boundaries, specifying which entities, locations, or activities must comply with the policy.
Question 116: An organization is categorizing a system that transmits sensitive law enforcement information across agency networks. Which security objective is most likely to be rated High?
- Accountability
- Integrity
- Confidentiality (Correct answer)
- Availability
Correct answer: Confidentiality
Sensitive law enforcement information, if disclosed to unauthorized parties, could jeopardize investigations and personal safety, warranting a High confidentiality impact.
Question 117: A healthcare organization must comply with both HIPAA and state privacy laws that are stricter than HIPAA. Which standard should govern their compliance program?
- The state law, because it provides greater protection to individuals (Correct answer)
- They must comply with HIPAA only and ignore stricter state requirements
- HIPAA, because federal law preempts state law
- Whichever standard is less costly to implement
Correct answer: The state law, because it provides greater protection to individuals
HIPAA allows states to enact stricter privacy protections, and organizations must comply with the more stringent standard.
Question 118: What does CVSS Base Score measure in the context of vulnerability assessment?
- The number of systems affected by a vulnerability
- The financial impact of a successful exploitation
- The intrinsic severity of a vulnerability independent of time or environment (Correct answer)
- The likelihood that a vulnerability will be exploited in the next 30 days
Correct answer: The intrinsic severity of a vulnerability independent of time or environment
The CVSS Base Score represents the intrinsic characteristics of a vulnerability that are constant over time and across environments.
Question 119: Which approach BEST supports consistent policy language across a large organization?
- Using a centralized policy template and style guide (Correct answer)
- Allowing each department to write policies independently
- Restricting policy authorship to the CISO only
- Publishing policies only in legal department format
Correct answer: Using a centralized policy template and style guide
A centralized template and style guide standardizes structure, terminology, and format, ensuring consistency and reducing confusion across the policy library.
Question 120: A risk assessment reveals that a HIGH-impact system's selected control baseline does not adequately address an emerging threat specific to the organization's mission environment. What tailoring action should the security engineer take?
- Augment the baseline by adding supplemental controls to address the identified threat (Correct answer)
- Document the threat in the POA&M and defer remediation to the next authorization cycle
- Switch the system to a MODERATE baseline to reduce the control burden
- Apply scoping guidance to remove controls unrelated to the threat
Correct answer: Augment the baseline by adding supplemental controls to address the identified threat
When a baseline does not sufficiently address identified threats, organizations should augment it by selecting additional controls or control enhancements. This is a standard tailoring action defined in NIST SP 800-53B. Downgrading the baseline or deferring without action would increase residual risk beyond acceptable levels for a HIGH-impact system.
Question 121: Which compliance framework is MOST commonly used as a baseline for US federal government contractors handling controlled unclassified information (CUI)?
- ISO 27001
- PCI DSS
- NIST SP 800-171 (Correct answer)
- COBIT 2019
Correct answer: NIST SP 800-171
NIST SP 800-171 defines the security requirements for protecting CUI in non-federal systems and is required for most federal contractors.
Question 122: In a multi-tier RMF implementation, which organizational tier is responsible for defining mission and business processes that drive information security requirements?
- Tier 2 β Mission/Business Process (Correct answer)
- Tier 4 β Operational
- Tier 3 β Information System
- Tier 1 β Organization
Correct answer: Tier 2 β Mission/Business Process
NIST SP 800-37 defines Tier 2 as the Mission/Business Process level, where enterprise architects and process owners translate organizational goals into security requirements.
Question 123: In enterprise risk management (ERM), which framework introduced the concept of risk in relation to strategy and performance?
- NIST Risk Management Framework
- COSO ERM 2017 (Correct answer)
- ISO 31000:2018
- COBIT 2019
Correct answer: COSO ERM 2017
COSO ERM 2017 (Enterprise Risk Management β Integrating with Strategy and Performance) explicitly linked risk management to strategy-setting and business performance.
Question 124: Which NIST publication provides guidance on conducting risk assessments as part of the RMF Prepare step?
- NIST SP 800-53
- NIST SP 800-30 (Correct answer)
- NIST SP 800-60
- NIST SP 800-37
Correct answer: NIST SP 800-30
NIST SP 800-30 provides the Guide for Conducting Risk Assessments, which supports threat and vulnerability identification during the Prepare and Assess steps.
Question 125: In Certified Governance Risk and Compliance, what is the purpose of baseline assessment?
- To compare performance across different organizations
- To establish a starting point for measuring future progress (Correct answer)
- To determine budget allocations
- To provide a final evaluation of performance
Correct answer: To establish a starting point for measuring future progress
Baseline assessment establishes the initial level of knowledge, skill, or condition before any intervention or training begins, providing a reference point for measuring subsequent progress.
Question 126: In ISO 31000, which component provides the mandate and commitment for risk management?
- Risk communication and consultation
- Risk treatment
- Establishing the context
- Principles and framework (Correct answer)
Correct answer: Principles and framework
ISO 31000 structures risk management into Principles, Framework, and Process β the framework provides the mandate and commitment from leadership.
ISC2 Certified in Governance, Risk and Compliance (CGRC)
The CGRC certifies professionals in applying risk management frameworks (RMF) to authorize and maintain information systems, covering governance, compliance, and control selection across the system authorization lifecycle.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong β answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds