VIP Exclusive

CGRC Certified in Governance, Risk and Compliance VIP Practice Exam III

CGRC — The CGRC (Certified in Governance, Risk and Compliance), issued by ISC2, is a 125-question, 3-hour exam (scored 100–1000, passing 700) covering seven domains of the NIST Risk Management Framework: Information Security Risk Management Program, Scope of the Information System, Selection and Approval of Security and Privacy Controls, Implementation of Security and Privacy Controls, Assessment/Audit of Security and Privacy Controls, Authorization/Approval of Information System, and Continuous Monitoring.

30
Questions
180m
Time Limit
70.00%
To Pass
Question 1 of 30👑 VIP

A federal agency is deploying a new cloud-hosted human resources application that will process personally identifiable information (PII) for 45,000 employees. The ISSO is determining whether a full Privacy Impact Assessment (PIA) is required. Under OMB Circular A-130 and the Privacy Act of 1974, which condition MOST directly triggers the requirement to conduct a PIA before the system goes live?

Questions 2–30 and full explanations are VIP-exclusive.