ISC2 Certified in Governance, Risk and Compliance (CGRC) — Questions and Answers
Question 1: Which of the following BEST describes the purpose of a compliance monitoring program?
- To detect policy violations and assess control effectiveness on an ongoing basis (Correct answer)
- To create new compliance policies annually
- To train employees on regulatory requirements
- To replace internal audits entirely
Correct answer: To detect policy violations and assess control effectiveness on an ongoing basis
Compliance monitoring provides continuous assessment of whether controls are operating effectively and policies are being followed.
Question 2: An organization outsources its payroll processing. Which risk category is MOST relevant if the payroll vendor suffers a ransomware attack?
- Operational risk (Correct answer)
- Strategic risk
- Market risk
- Liquidity risk
Correct answer: Operational risk
A ransomware attack disrupting payroll processing represents operational risk, as it impairs a critical business function delivered by a third party.
Question 3: Under which U.S. federal law are agencies required to conduct a Privacy Impact Assessment (PIA) before developing or procuring information technology that collects, maintains, or disseminates personally identifiable information (PII)?
- The Clinger-Cohen Act of 1996
- The Privacy Act of 1974
- The E-Government Act of 2002 (Correct answer)
- The Federal Information Security Modernization Act (FISMA) of 2014
Correct answer: The E-Government Act of 2002
Section 208 of the E-Government Act of 2002 specifically mandates PIAs for federal IT systems that collect or use PII. The Privacy Act of 1974 governs records systems but does not require PIAs. FISMA addresses security programs, and the Clinger-Cohen Act addresses IT acquisition and management.
Question 4: Which NIST publication provides the primary framework for implementing an Information Security Continuous Monitoring (ISCM) program?
- NIST SP 800-30
- NIST SP 800-137 (Correct answer)
- NIST SP 800-53
- NIST SP 800-39
Correct answer: NIST SP 800-137
NIST SP 800-137 specifically addresses Information Security Continuous Monitoring for federal information systems and organizations.
Question 5: What is the primary purpose of conducting a third-party compliance due diligence review before entering a business relationship?
- To comply with import/export documentation requirements
- To satisfy investor relations requirements
- To identify and mitigate compliance risks the third party may introduce (Correct answer)
- To negotiate better contract terms
Correct answer: To identify and mitigate compliance risks the third party may introduce
Third-party due diligence identifies compliance risks — such as FCPA violations, sanctions exposure, or data privacy risks — that could be introduced into the organization through the business relationship.
Question 6: Which scenario represents an integrity impact of High under FIPS 199?
- Temporary unavailability of a low-priority reporting tool
- Unauthorized disclosure of a public-facing website's content
- Disclosure of internal meeting schedules to unauthorized staff
- Incorrect modification of electronic health records leading to patient harm (Correct answer)
Correct answer: Incorrect modification of electronic health records leading to patient harm
High integrity impact occurs when unauthorized modification could have severe or catastrophic consequences, such as patient harm from corrupted medical records.
Question 7: A cloud service provider seeks authorization to serve multiple federal agencies through a single assessment. This approach is called:
- Delegated Authorization
- FedRAMP Authorization (Correct answer)
- Joint Authorization
- Reciprocity Agreement
Correct answer: FedRAMP Authorization
FedRAMP provides a standardized approach for cloud service providers to obtain a single authorization that multiple federal agencies can leverage.
Question 8: What is the key difference between compliance monitoring and compliance auditing?
- Monitoring focuses on financial data; auditing covers all areas
- Monitoring is ongoing and continuous; auditing is periodic and formal (Correct answer)
- Monitoring is preventive; auditing is corrective
- Monitoring is done by regulators; auditing is done internally
Correct answer: Monitoring is ongoing and continuous; auditing is periodic and formal
Compliance monitoring is a continuous, ongoing activity that checks day-to-day compliance, while auditing is a periodic, formal, and systematic evaluation.
Question 9: An organization identifies a high-severity vulnerability in a production system that has an active ATO. What RMF action is most appropriate?
- Immediately revoke the ATO and shut down the system
- Transfer the risk to the system's vendor
- Wait until the next annual review to address it
- Update the SSP and notify the AO; remediate based on POA&M timelines (Correct answer)
Correct answer: Update the SSP and notify the AO; remediate based on POA&M timelines
Newly discovered vulnerabilities should be documented in the POA&M, the SSP updated as needed, and the AO notified so they can determine if the authorization remains valid.
Question 10: Which type of security control assessment method involves reviewing policy documents and system configuration files to verify control implementation?
- Interview
- Observe
- Examine (Correct answer)
- Test
Correct answer: Examine
The Examine method involves reviewing documentation, specifications, and records to assess whether controls are in place as described.
Question 11: What is a best practice in Certified Governance Risk and Compliance continuous monitoring?
- A practice used only by large organizations
- Any practice that is easy to implement
- The cheapest available approach
- A method or technique recognized as superior based on evidence and expert consensus (Correct answer)
Correct answer: A method or technique recognized as superior based on evidence and expert consensus
Best practices are methods, techniques, or approaches that are recognized through evidence, research, and expert consensus as producing superior results and are recommended for adoption.
Question 12: Which regulatory framework requires publicly traded US companies to establish internal controls over financial reporting and have management assess their effectiveness?
- HIPAA
- Sarbanes-Oxley Act Section 404 (Correct answer)
- Federal Trade Commission Act
- Gramm-Leach-Bliley Act
Correct answer: Sarbanes-Oxley Act Section 404
SOX Section 404 mandates that management assess and report on the effectiveness of internal controls over financial reporting, with external auditor attestation.
Question 13: Which activity is most important when a high-risk vendor relationship is terminated?
- Issuing a final invoice reconciliation
- Ensuring data is returned or securely destroyed per contract terms (Correct answer)
- Updating the vendor's risk tier classification in the registry
- Sending a formal termination notice to regulators
Correct answer: Ensuring data is returned or securely destroyed per contract terms
Offboarding a high-risk vendor must include verified data return or destruction to prevent unauthorized retention of sensitive information.
Question 14: An organization is selecting controls for a system that processes Controlled Unclassified Information (CUI) and has been assigned a MODERATE impact level. Which baseline from NIST SP 800-53 should serve as the starting point for control selection?
- There is no baseline — all controls must be selected individually
- Moderate baseline (Correct answer)
- Low baseline, then add controls as needed
- High baseline to ensure maximum protection
Correct answer: Moderate baseline
NIST SP 800-53 provides three control baselines — Low, Moderate, and High — corresponding to the system's impact level as determined through FIPS 199 categorization. A system categorized as MODERATE should begin with the Moderate baseline. Organizations then tailor this baseline by adding, removing, or modifying controls based on their specific environment, threat landscape, and operational requirements.
Question 15: A federal agency's information system processes personally identifiable information (PII). Which RMF consideration becomes especially important during the Categorize step?
- Privacy impact must be assessed alongside security categorization (Correct answer)
- Availability impact must always be rated High
- PII eliminates the need for a Moderate baseline
- PII systems are automatically classified as national security systems
Correct answer: Privacy impact must be assessed alongside security categorization
NIST SP 800-37 Rev. 2 integrated privacy into the RMF, requiring privacy impact assessment alongside security categorization for systems processing PII.
Question 16: A 'sunset clause' in a policy document refers to:
- A section describing policy communication to employees
- A list of superseded older policy versions
- A provision that the policy is reviewed annually
- An automatic expiration date after which the policy must be reviewed or renewed (Correct answer)
Correct answer: An automatic expiration date after which the policy must be reviewed or renewed
Sunset clauses build in automatic expiration dates to ensure policies do not remain in force indefinitely without periodic review.
Question 17: The CGRC domain of Policy Development MOST aligns with which GRC pillar?
- Assurance
- Compliance only
- Risk
- Governance (Correct answer)
Correct answer: Governance
Policy development is a core governance activity that establishes the organizational rules, authority structures, and frameworks that guide risk and compliance activities.
Question 18: While selecting controls for a new system, a practitioner finds that a required control (AU-9, Protection of Audit Information) cannot be fully implemented due to a technical limitation in the logging platform. What is the MOST appropriate approach per NIST RMF guidance?
- Proceed to authorization without implementing AU-9 since the technical limitation is a valid exemption
- Delay the authorization until AU-9 can be fully implemented regardless of schedule impacts
- Document the limitation, implement a compensating control that provides equivalent protection, and obtain AO approval (Correct answer)
- Replace AU-9 with an unrelated control that is easier to implement
Correct answer: Document the limitation, implement a compensating control that provides equivalent protection, and obtain AO approval
When a required control cannot be implemented as specified, NIST RMF guidance allows for compensating controls — alternative measures that provide equivalent or comparable protection. The compensating control must be documented with a justification, and the authorizing official (AO) must review and accept the residual risk. Simply skipping the control, substituting unrelated controls, or delaying indefinitely are not appropriate RMF responses.
Question 19: What is the significance of a 'critical vendor' designation within a TPRM program?
- The vendor undergoes enhanced due diligence, more frequent assessments, and has contingency plans (Correct answer)
- The vendor receives preferential pricing due to strategic importance
- The vendor is automatically approved for multi-year contract renewals
- The vendor is exempt from standard security questionnaire requirements
Correct answer: The vendor undergoes enhanced due diligence, more frequent assessments, and has contingency plans
Critical vendors are subject to heightened scrutiny, more frequent risk reassessments, and must have documented contingency or substitution plans due to the impact their failure would have.
Question 20: During a CGRC assessment, an auditor reviews an organization's consent management practices. Which characteristic makes consent valid under GDPR?
- Freely given, specific, informed, and unambiguous indication of agreement (Correct answer)
- A blanket consent clause embedded in the employment contract
- Pre-checked boxes included in terms and conditions
- Implied consent based on continued use of the service
Correct answer: Freely given, specific, informed, and unambiguous indication of agreement
GDPR requires consent to be freely given, specific, informed, and unambiguous — pre-ticked boxes and implied consent do not meet this standard.
Question 21: A CGRC practitioner is advising on control selection for a system shared by multiple programs within an agency. Several of the required controls are already implemented at the organizational level and maintained by a central team. How should these be treated?
- Documented as compensating controls in the system's POA&M
- Removed from the system's control baseline since they are redundant
- Inherited as common controls, referencing the providing system's SSP (Correct answer)
- Re-implement them at the system level to ensure layered defense
Correct answer: Inherited as common controls, referencing the providing system's SSP
Common controls are controls that are implemented at an organizational, site, or program level and inherited by multiple systems. When a system can inherit a control from a common control provider, it should document this inheritance in its SSP, referencing the authoritative source. This avoids duplication of effort and leverages centrally managed security capabilities. Common controls must be documented and authorized, not simply assumed.
Question 22: Which factor most directly determines the length of an ATO authorization period?
- The vendor's software support lifecycle
- The number of controls assessed
- The system's categorization level (Low/Moderate/High)
- Organizational policy and the AO's risk acceptance decision (Correct answer)
Correct answer: Organizational policy and the AO's risk acceptance decision
The ATO period is determined by organizational policy and the AO's judgment about acceptable risk over time, not automatically by categorization.
Question 23: A third-party assessment organization (3PAO) conducts the security assessment for a cloud system. This primarily strengthens the authorization process by:
- Replacing the need for an AO authorization decision
- Reducing the cost of the assessment
- Providing independence and objectivity in control evaluation (Correct answer)
- Eliminating the requirement for a POA&M
Correct answer: Providing independence and objectivity in control evaluation
3PAOs provide independent, objective assessment of security controls, increasing confidence in the SAR findings used by the AO.
Question 24: Which standard-setting body issues the International Standards for the Professional Practice of Internal Auditing?
- The Institute of Internal Auditors (IIA) (Correct answer)
- PCAOB
- AICPA
- ISACA
Correct answer: The Institute of Internal Auditors (IIA)
The IIA publishes the International Standards for the Professional Practice of Internal Auditing, which govern internal audit globally.
Question 25: A CGRC practitioner is helping an organization select compensating controls after determining that a required control cannot be implemented due to a legacy system constraint. Which criteria must compensating controls satisfy?
- They must provide equivalent protection and be documented with a clear rationale tied to the original control's intent (Correct answer)
- They must be cheaper to implement than the original control
- They must be selected from the same control family as the original control
- They must be approved by NIST before being applied
Correct answer: They must provide equivalent protection and be documented with a clear rationale tied to the original control's intent
Compensating controls must provide equivalent or comparable protection to the original control they replace, and the selection must be accompanied by documented rationale explaining why the original control could not be implemented and how the compensating control achieves the same security objective. They do not need to come from the same control family, be pre-approved by NIST, or necessarily be cheaper — cost is not the deciding factor; equivalence of protection is.
Question 26: There are many prospective risks, categories of risk, and manners in which risk is evaluated. Federal law requires the consideration of mission, assets, other organizations and:
- None of the above
- Financial
- Individuals (Correct answer)
- Policy
Correct answer: Individuals
Explanation: <br> Federal law requires the consideration of mission, assets, other organizations, and individuals when evaluating risks. This emphasizes the importance of assessing risks not only in terms of organizational objectives and assets but also in terms of potential impacts on individuals who may be affected by the risks.
Question 27: During continuous monitoring, an organization detects a new zero-day vulnerability affecting a critical system. The FIRST step should be to:
- Notify all users that the system is under attack
- Assess the risk to determine likelihood and potential impact (Correct answer)
- Transfer responsibility to the vendor who built the system
- Immediately shut down the affected system
Correct answer: Assess the risk to determine likelihood and potential impact
The first step is always to assess the risk — understanding likelihood and potential impact — before deciding on an appropriate response action.
Question 28: In a cloud-shared responsibility model, which continuous monitoring activities remain the customer's responsibility even when using an IaaS provider?
- Physical security of data center facilities
- Hypervisor patch management
- Monitoring of operating systems, applications, and data the customer deploys (Correct answer)
- Network infrastructure availability monitoring
Correct answer: Monitoring of operating systems, applications, and data the customer deploys
In IaaS, the provider secures the underlying infrastructure, but the customer is responsible for monitoring their own OS, applications, and data.
Question 29: In a multi-tier RMF implementation, which organizational tier is responsible for defining mission and business processes that drive information security requirements?
- Tier 3 – Information System
- Tier 2 – Mission/Business Process (Correct answer)
- Tier 4 – Operational
- Tier 1 – Organization
Correct answer: Tier 2 – Mission/Business Process
NIST SP 800-37 defines Tier 2 as the Mission/Business Process level, where enterprise architects and process owners translate organizational goals into security requirements.
Question 30: An organization determines that the cost of a control exceeds the potential loss it would prevent. The BEST action is to:
- Eliminate the underlying threat
- Implement the control anyway for compliance
- Transfer the risk to a third party
- Accept the residual risk (Correct answer)
Correct answer: Accept the residual risk
When control costs exceed potential losses, accepting the residual risk is the rational response based on cost-benefit analysis.
ISC2 Certified in Governance, Risk and Compliance (CGRC)
The CGRC certifies professionals in applying risk management frameworks (RMF) to authorize and maintain information systems, covering governance, compliance, and control selection across the system authorization lifecycle.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds