GRC Professional (GRCP) Certification Exam — Questions and Answers
Question 1: Which of the following is a risk of having too many overlapping policies?
- Conflicting requirements may confuse employees and create compliance gaps (Correct answer)
- Employees will have too much clarity on expectations
- Regulatory bodies will require fewer controls
- Auditors will have difficulty finding policy violations
Correct answer: Conflicting requirements may confuse employees and create compliance gaps
Overlapping or conflicting policies create ambiguity about which requirement to follow, increasing the risk of non-compliance.
Question 2: Under HIPAA, which governance role is responsible for overseeing the organization's compliance with privacy regulations?
- Data Steward
- Privacy Officer (Correct answer)
- Compliance Auditor
- Chief Information Security Officer (CISO)
Correct answer: Privacy Officer
HIPAA requires covered entities to designate a Privacy Officer responsible for developing and implementing privacy policies and procedures.
Question 3: What is the role of the Chief Risk Officer (CRO) in an ERM program?
- Auditing internal controls independently of management
- Owning all operational risks across the enterprise
- Overseeing the ERM framework and ensuring risk is integrated into strategic decisions (Correct answer)
- Approving all financial transactions above a certain threshold
Correct answer: Overseeing the ERM framework and ensuring risk is integrated into strategic decisions
The CRO leads the ERM function, designs the risk framework, and ensures risk considerations are embedded in strategy and business processes.
Question 4: Which of the following best describes a Privacy Impact Assessment (PIA)?
- A systematic process for evaluating privacy risks of a new system or process (Correct answer)
- A legal contract between data processors and controllers
- A technical scan for malware on data servers
- A financial audit of marketing spend on data advertising
Correct answer: A systematic process for evaluating privacy risks of a new system or process
A PIA is a structured analysis used to identify and mitigate privacy risks before deploying a new project, system, or business process involving personal data.
Question 5: Which PCI DSS requirement mandates that cardholder data environments must restrict inbound and outbound traffic to only that which is necessary?
- Requirement 6 — Develop and maintain secure systems
- Requirement 1 — Install and maintain network security controls (Correct answer)
- Requirement 3 — Protect stored account data
- Requirement 10 — Log and monitor all access
Correct answer: Requirement 1 — Install and maintain network security controls
PCI DSS Requirement 1 focuses on network security controls, including firewalls and router configurations that restrict unnecessary traffic to and from the cardholder data environment.
Question 6: Which risk identification technique involves gathering input from a panel of experts through multiple anonymous rounds of questionnaires to reach consensus?
- Control self-assessment
- Delphi technique (Correct answer)
- Fault tree analysis
- SWOT analysis
Correct answer: Delphi technique
The Delphi technique uses iterative, anonymous expert surveys to converge on a consensus view of risk likelihood and impact.
Question 7: What does a risk mitigation strategy aim to do?
- Increase vulnerability
- Delay risk actions
- Reduce or eliminate risk impact (Correct answer)
- Increase risk exposure
Correct answer: Reduce or eliminate risk impact
A risk mitigation strategy is a planned approach designed to lessen the severity or likelihood of an identified risk occurring. The primary aim is to implement controls or actions that either reduce the potential negative impact if the risk materializes or decrease the probability of the risk event happening in the first place. This proactive approach helps protect organizational assets and objectives.
Question 8: Which key performance indicator (KPI) in risk management measures how quickly an organization can restore operations after a disruption?
- Recovery Time Objective (RTO) (Correct answer)
- Mean Time Between Failures (MTBF)
- Risk Tolerance Threshold (RTT)
- Recovery Point Objective (RPO)
Correct answer: Recovery Time Objective (RTO)
RTO defines the maximum acceptable length of time to restore a business function after an incident.
Question 9: Which term describes the risk that remains after all controls and mitigation strategies have been applied?
- Secondary risk
- Control risk
- Inherent risk
- Residual risk (Correct answer)
Correct answer: Residual risk
Residual risk is the level of risk that persists even after risk responses and controls have been implemented.
Question 10: Which BCP component addresses how an organization will communicate with employees, customers, and stakeholders during a crisis?
- Business impact analysis
- IT disaster recovery plan
- Crisis communication plan (Correct answer)
- Risk register
Correct answer: Crisis communication plan
The crisis communication plan defines messaging, channels, and responsibilities for notifying all relevant parties during a disruption.
Question 11: In the Three Lines of Defense model, which line is responsible for risk ownership and day-to-day control implementation?
- Board of directors
- Second line (risk and compliance functions)
- Internal audit
- First line (operational management) (Correct answer)
Correct answer: First line (operational management)
The first line of defense — operational management — owns risks and is responsible for implementing and maintaining effective internal controls.
Question 12: A GRC analyst is assessing which business functions to prioritize in recovery. Which tool best supports this decision?
- Penetration test
- Risk register update
- Business Impact Analysis (BIA) (Correct answer)
- Vulnerability scan
Correct answer: Business Impact Analysis (BIA)
The BIA identifies critical business functions, their dependencies, and the impact of disruption, directly informing recovery prioritization.
Question 13: Which ISO standard specifically provides guidance on governance of information security, acting as a companion to ISO/IEC 27001?
- ISO/IEC 27701
- ISO/IEC 27002
- ISO/IEC 27005
- ISO/IEC 27014 (Correct answer)
Correct answer: ISO/IEC 27014
ISO/IEC 27014 provides guidance on governance of information security for board-level and executive evaluation, direction, and monitoring.
Question 14: What is the role of the 'three lines of defense' model in governance and internal control?
- Establish escalation paths for compliance violations
- Define cybersecurity perimeter zones
- Segregate IT duties across infrastructure teams
- Clarify responsibilities for risk management across operations, risk/compliance, and internal audit (Correct answer)
Correct answer: Clarify responsibilities for risk management across operations, risk/compliance, and internal audit
The three lines model assigns risk ownership to operational management (1st), oversight functions (2nd), and independent assurance (3rd).
Question 15: What is 'residual risk' in the context of internal controls?
- The risk of a control failure
- Risk identified during the audit but not yet remediated
- Risk remaining after controls have been applied (Correct answer)
- Risk that has been fully eliminated by controls
Correct answer: Risk remaining after controls have been applied
Residual risk is the level of risk that remains after management has implemented controls to reduce inherent risk.
Question 16: In a GRC context, 'tone at the top' refers to:
- Senior leadership's visible commitment to ethical behavior and compliance (Correct answer)
- The topmost tier of a risk classification matrix
- The volume level of executive presentations
- The frequency of board-level GRC reporting
Correct answer: Senior leadership's visible commitment to ethical behavior and compliance
Tone at the top describes the ethical climate and culture of compliance that senior leaders establish through their own behavior and communications, which sets expectations throughout the organization.
Question 17: What is the primary purpose of a vendor risk tiering model?
- To identify which vendors should receive volume discounts
- To allocate due diligence intensity based on the risk each vendor poses (Correct answer)
- To sequence vendor contract renewal dates
- To rank vendors by revenue contribution for budgeting
Correct answer: To allocate due diligence intensity based on the risk each vendor poses
Risk tiering ensures that high-risk vendors receive more rigorous due diligence while low-risk vendors receive lighter-touch reviews, optimizing resources.
Question 18: Which regulation governs the privacy of student education records at institutions receiving federal funding?
- FERPA (Correct answer)
- GLBA
- COPPA
- HIPAA
Correct answer: FERPA
FERPA (Family Educational Rights and Privacy Act) protects the privacy of student education records at federally funded educational institutions.
Question 19: A healthcare organization is concerned about potential violations of the Health Insurance Portability and Accountability Act (HIPAA). To strengthen its legal and regulatory compliance, the GRC team decides to implement a control. Which of the following is an example of a 'preventive' control in this context?
- Enforcing role-based access controls to limit access to patient data to only authorized personnel. (Correct answer)
- Implementing a security incident response plan to handle data breaches.
- Reviewing and revoking access rights for employees who have left the organization.
- Conducting regular audits of patient record access logs.
Correct answer: Enforcing role-based access controls to limit access to patient data to only authorized personnel.
A preventive control is designed to stop a compliance violation from occurring in the first place. Role-based access controls proactively limit access to sensitive patient data, thereby preventing unauthorized viewing or use. The other options are detective (auditing logs) or corrective/responsive (incident response plan, revoking access after departure) controls.
Question 20: Under GDPR, which legal basis allows an organization to process personal data without consent when it is necessary to fulfill a contract with the data subject?
- Legitimate interests
- Legal obligation
- Vital interests
- Contractual necessity (Correct answer)
Correct answer: Contractual necessity
Article 6(1)(b) of GDPR permits processing personal data without consent when it is necessary for the performance of a contract to which the data subject is a party.
Question 21: A 'control deficiency' exists when:
- A control is overly complex and redundant
- Management disagrees with auditor findings
- A control prevents all unauthorized transactions
- A control is missing or not operating effectively enough to prevent or detect misstatements (Correct answer)
Correct answer: A control is missing or not operating effectively enough to prevent or detect misstatements
A control deficiency occurs when the design or operation of a control does not allow management to prevent or detect misstatements on a timely basis.
Question 22: A company adopts COBIT 2019 and focuses on the management objective 'APO12 Managed Risk.' This objective belongs to which COBIT domain?
- Monitor, Evaluate and Assess (MEA)
- Build, Acquire and Implement (BAI)
- Align, Plan and Organize (APO) (Correct answer)
- Deliver, Service and Support (DSS)
Correct answer: Align, Plan and Organize (APO)
APO (Align, Plan and Organize) is the domain containing APO12 Managed Risk, reflecting its strategic and planning nature.
Question 23: Which concept refers to the ability of an organization to anticipate, prepare for, respond to, and adapt to incremental change and sudden disruptions?
- Business continuity compliance
- Organizational resilience (Correct answer)
- Fault tolerance
- Risk avoidance
Correct answer: Organizational resilience
Organizational resilience encompasses the adaptive capacity of a business to withstand and recover from both gradual changes and abrupt disruptions.
Question 24: What is risk assessment in the context of internal controls?
- Identify, evaluate, and prioritize risks (Correct answer)
- Ignore potential risks
- Increase risk exposure
- Delay assessments
Correct answer: Identify, evaluate, and prioritize risks
Risk assessment in internal controls is the systematic process of identifying potential threats and vulnerabilities that could impact an organization's objectives. It involves evaluating the likelihood and impact of these risks, and then prioritizing them based on their severity. This process enables management to design and implement appropriate controls to mitigate the most significant risks effectively.
Question 25: Which governance concept describes the board's responsibility to ensure the organization acts in the long-term interests of shareholders and other stakeholders?
- Resource dependency theory
- Stewardship theory
- Agency theory (Correct answer)
- Stakeholder theory
Correct answer: Agency theory
Agency theory addresses the relationship between principals (shareholders) and agents (management), and the board's role in aligning these interests.
Question 26: Which Three Lines Model component is responsible for providing independent assurance to the board?
- External auditors
- First line (operations)
- Third line (internal audit) (Correct answer)
- Second line (risk/compliance functions)
Correct answer: Third line (internal audit)
The third line (internal audit) provides independent, objective assurance and advice to the board on governance, risk, and control.
Question 27: What is the purpose of a risk owner in a GRC program?
- To report the risk directly to regulators
- To insure the organization against the risk
- To be accountable for managing and monitoring a specific risk (Correct answer)
- To calculate the monetary value of the risk
Correct answer: To be accountable for managing and monitoring a specific risk
A risk owner is an individual assigned responsibility for ensuring that a specific risk is adequately identified, assessed, and treated.
Question 28: GDPR Article 83 establishes maximum fines of up to €20 million or what percentage of global annual turnover for the most serious violations?
- 10%
- 6%
- 4% (Correct answer)
- 2%
Correct answer: 4%
GDPR's highest tier of fines can reach €20 million or 4% of the organization's total global annual turnover, whichever is higher.
Question 29: Which cybersecurity governance document outlines acceptable and prohibited uses of organizational IT resources by employees?
- Incident Response Plan (IRP)
- Disaster Recovery Plan (DRP)
- Acceptable Use Policy (AUP) (Correct answer)
- System Security Plan (SSP)
Correct answer: Acceptable Use Policy (AUP)
An Acceptable Use Policy defines what employees may and may not do with organizational IT resources, setting behavioral expectations.
Question 30: What is the purpose of scenario analysis in ERM?
- To calculate exact loss amounts for each risk
- To explore plausible future states and assess their potential risk impacts (Correct answer)
- To assign monetary values to intangible assets
- To rank risks based on historical frequency data
Correct answer: To explore plausible future states and assess their potential risk impacts
Scenario analysis examines hypothetical but plausible situations to evaluate how different conditions could affect organizational risk exposure.
Question 31: In the context of GRC, 'control self-assessment' (CSA) is best described as:
- An external auditor's evaluation of internal controls
- A process where management and staff evaluate their own controls' effectiveness (Correct answer)
- A vendor's assessment of their customer's security posture
- A regulatory examination of compliance programs
Correct answer: A process where management and staff evaluate their own controls' effectiveness
Control self-assessment involves process owners and employees evaluating the adequacy and effectiveness of controls in their own area of responsibility.
Question 32: What is the purpose of a vendor scorecard in ongoing third-party risk management?
- To calculate the financial value each vendor provides
- To document vendor contact information in a centralized registry
- To rank vendors for preferred-supplier pricing negotiations
- To track and visualize key performance and risk indicators for a vendor over time (Correct answer)
Correct answer: To track and visualize key performance and risk indicators for a vendor over time
A vendor scorecard aggregates KPIs and KRIs into a dashboard that enables ongoing comparison of vendor performance and risk posture over time.
Question 33: A 'control gap' is BEST described as:
- The difference between planned and actual audit hours
- A missing signature on an audit work paper
- A time delay between when a control operates and when it is tested
- A situation where a required control does not exist or is not operating effectively (Correct answer)
Correct answer: A situation where a required control does not exist or is not operating effectively
A control gap exists when an identified risk has no corresponding control or the existing control is insufficient to mitigate that risk.
Question 34: The first stage of the policy lifecycle is 'Initiation' or 'Creation'. What is the most common trigger for initiating a new corporate policy or significantly revising an existing one?
- A request from the marketing department for a new branding guide.
- The appointment of a new Chief Compliance Officer.
- A new regulatory requirement or the identification of a new significant risk. (Correct answer)
- The annual employee satisfaction survey results.
Correct answer: A new regulatory requirement or the identification of a new significant risk.
Policies are fundamental GRC tools created to address specific needs. The most compelling drivers for policy creation are external obligations, such as new laws or regulations, or internal drivers like the outcome of a risk assessment that identifies an unmitigated risk that needs to be addressed.
Question 35: A guidelines document says employees 'should' encrypt sensitive emails. What does this language indicate?
- The guideline has legal standing equal to a policy
- Encryption is mandatory and will be technically enforced
- Encryption violates company policy
- Encryption is a recommended practice but not required (Correct answer)
Correct answer: Encryption is a recommended practice but not required
The word 'should' indicates a recommendation rather than a mandatory control, distinguishing guidelines from standards and policies.
Question 36: Which concept requires organizations to collect only the minimum amount of personal data necessary for a stated purpose?
- Data portability
- Data minimization (Correct answer)
- Data residency
- Data sovereignty
Correct answer: Data minimization
Data minimization is the principle of limiting personal data collection to what is directly relevant and necessary to accomplish a specified purpose.
Question 37: In the context of internal auditing, what does 'independence' mean?
- Auditors are not employees of the company
- The audit is conducted without management's knowledge
- The internal audit function is free from conditions that threaten objectivity (Correct answer)
- The auditor has no formal reporting structure
Correct answer: The internal audit function is free from conditions that threaten objectivity
Independence means the internal audit function operates without interference or bias, typically reporting to the audit committee rather than operational management.
Question 38: Which GRC model principle emphasizes that risk management activities should be proportional to the size and complexity of the organization?
- Scalability (Correct answer)
- Integration
- Transparency
- Accountability
Correct answer: Scalability
Scalability ensures that GRC frameworks are appropriately sized and tailored to the organization's complexity, not applied in a one-size-fits-all manner.
Question 39: In ISO 31000:2018, what is the term for the potential positive or negative consequence of a risk event?
- Risk criterion
- Consequence (Correct answer)
- Risk owner
- Likelihood
Correct answer: Consequence
ISO 31000 defines 'consequence' as the outcome of an event affecting objectives, which can be positive or negative.
Question 40: In the context of regulatory compliance, what is 'regulatory capture'?
- When regulators begin to advance the interests of the industry they regulate rather than the public interest (Correct answer)
- When a regulator issues a formal enforcement action against a company
- When a government agency captures and centralizes data from regulated firms
- When a company acquires a regulated entity
Correct answer: When regulators begin to advance the interests of the industry they regulate rather than the public interest
Regulatory capture occurs when regulatory agencies prioritize the commercial or political interests of the industries they oversee rather than the broader public interest.
Question 41: Which of the following BEST defines fourth-party risk within a Third-Party Risk Management (TPRM) program?
- The risk that a primary vendor will fail to meet its contractual obligations due to its own internal control failures.
- The risk of engaging multiple vendors from the same high-risk geographic location.
- The risk associated with the offboarding process when terminating a contract with a third-party vendor.
- The risk posed by a vendor's subcontractor, whose failure could impact the services the primary vendor delivers to your organization. (Correct answer)
Correct answer: The risk posed by a vendor's subcontractor, whose failure could impact the services the primary vendor delivers to your organization.
Fourth-party risk is the risk introduced by your vendors' vendors (i.e., their subcontractors or suppliers). An organization does not have a direct contractual relationship with these fourth parties, but their performance or security failures can still significantly impact the services received from the primary third-party vendor.
Question 42: Which COSO ERM principle states that organizations should develop a 'portfolio view' of risk?
- Develops Portfolio View (Correct answer)
- Defines Risk Appetite
- Analyzes Business Context
- Pursues Improvement in Enterprise Risk Management
Correct answer: Develops Portfolio View
The 'Develops Portfolio View' principle requires management to aggregate risks across business units to understand the total risk profile relative to appetite.
Question 43: What is a 'compensating control'?
- A control that replaces financial losses
- A backup procedure for IT systems
- A control that detects fraud after the fact
- An alternative control that mitigates risk when the primary control is not feasible (Correct answer)
Correct answer: An alternative control that mitigates risk when the primary control is not feasible
Compensating controls provide alternative risk mitigation when standard controls cannot be implemented due to cost or operational constraints.
Question 44: In IT governance, a 'tollgate' review is best described as:
- An automated compliance scan run quarterly
- A board-level review of annual IT budget
- A formal checkpoint where a project must meet criteria before proceeding (Correct answer)
- A continuous monitoring process for all IT systems
Correct answer: A formal checkpoint where a project must meet criteria before proceeding
A tollgate review is a structured decision point where stakeholders evaluate whether a project meets predefined criteria before authorizing the next phase.
Question 45: Which quantitative technique uses repeated random sampling to model the probability distribution of risk outcomes?
- Monte Carlo simulation (Correct answer)
- Delphi technique
- SWOT analysis
- Bowtie analysis
Correct answer: Monte Carlo simulation
Monte Carlo simulation runs thousands of random scenarios to produce a probability distribution of possible outcomes, quantifying risk exposure.
Question 46: In SOX compliance, which section requires management to assess and report on internal controls over financial reporting?
- Section 302
- Section 404 (Correct answer)
- Section 409
- Section 802
Correct answer: Section 404
SOX Section 404 mandates that management assess the effectiveness of internal controls over financial reporting annually.
Question 47: The Right to Audit clause in a vendor contract primarily serves to:
- Allow the vendor to audit the client's systems for compliance
- Grant the organization the ability to examine the vendor's controls and records (Correct answer)
- Establish financial penalties for service outages
- Define the vendor's liability cap for data breaches
Correct answer: Grant the organization the ability to examine the vendor's controls and records
A Right to Audit clause gives the contracting organization (or its designee) the authority to review the vendor's security controls, processes, and records.
Question 48: A control that automatically prevents a transaction from proceeding when a threshold is exceeded is best described as a:
- Manual control
- Compensating control
- Detective control
- Automated preventive control (Correct answer)
Correct answer: Automated preventive control
Automated preventive controls use system logic to block non-compliant transactions before they are completed.
Question 49: An organization's cybersecurity governance program includes a risk register. What is the primary purpose of maintaining this document?
- To record employee security training completion dates
- To list all software vulnerabilities found during penetration testing
- To track identified risks, their likelihood, impact, and treatment status over time (Correct answer)
- To document all security incidents that have occurred
Correct answer: To track identified risks, their likelihood, impact, and treatment status over time
A risk register is a central repository that captures identified risks along with their assessment, ownership, and treatment plans for ongoing governance oversight.
Question 50: Management's response to an audit finding typically includes:
- Reclassification of the finding as immaterial
- Payment of a penalty to the internal audit department
- Agreement or disagreement with the finding and a corrective action plan with a target date (Correct answer)
- A legal challenge to the auditor's conclusions
Correct answer: Agreement or disagreement with the finding and a corrective action plan with a target date
Management responses address whether they concur with the finding and outline planned remediation steps and timelines.
Question 51: The concept of 'risk appetite' is best defined as:
- The amount and type of risk an organization is willing to accept in pursuit of its objectives (Correct answer)
- The regulatory limit on risk exposure
- The cost of all active risk controls
- The maximum loss an organization can absorb before insolvency
Correct answer: The amount and type of risk an organization is willing to accept in pursuit of its objectives
Risk appetite reflects senior management's and the board's willingness to take on risk while pursuing strategic goals.
Question 52: A third-party vendor stores sensitive customer data on behalf of your organization. Which risk category does this primarily represent?
- Compliance risk
- Third-party/supply chain risk (Correct answer)
- Operational risk
- Strategic risk
Correct answer: Third-party/supply chain risk
Risks arising from reliance on external vendors or partners are classified as third-party or supply chain risks.
Question 53: Key Risk Indicators (KRIs) are best described as:
- Policy documents that define acceptable risk thresholds
- Audit findings documenting control deficiencies
- Leading metrics that provide early warning signals that a risk may be increasing (Correct answer)
- Lagging metrics that confirm a risk event has already occurred
Correct answer: Leading metrics that provide early warning signals that a risk may be increasing
KRIs are forward-looking metrics that signal a rising probability of a risk materializing, enabling proactive management before the event occurs.
Question 54: Which of the following is a primary objective of establishing a formal IT Governance framework within an organization?
- To give the IT department complete autonomy over technology decisions.
- To ensure the IT department has the latest technology.
- To align IT strategy with business strategy and objectives. (Correct answer)
- To minimize all IT-related expenditures.
Correct answer: To align IT strategy with business strategy and objectives.
The fundamental purpose of IT governance is to ensure that IT investments and activities are aligned with and support the overall business strategy and objectives. It provides a structure for decision-making and accountability to ensure that IT delivers value to the business, manages risks, and optimizes resources.
Question 55: When should a policy undergo an unscheduled review?
- Whenever an employee requests a review
- Only when the annual review cycle arrives
- After a significant security incident, regulatory change, or major business change (Correct answer)
- Only when auditors request it
Correct answer: After a significant security incident, regulatory change, or major business change
Trigger-based reviews ensure policies remain relevant when significant events occur between scheduled review cycles.
Question 56: Which regulatory framework in the US financial sector specifically requires covered institutions to maintain business continuity and recovery programs?
- HIPAA Security Rule
- FFIEC Business Continuity Management booklet (Correct answer)
- PCI DSS Requirement 12
- SOC 2 Type II
Correct answer: FFIEC Business Continuity Management booklet
The FFIEC Business Continuity Management booklet provides supervisory guidance requiring financial institutions to maintain robust BCM programs.
Question 57: Under the COSO ERM framework, 'risk appetite' is defined as:
- The percentage of risks that have been mitigated
- The maximum loss the organization can absorb before becoming insolvent
- The amount of risk an organization is willing to accept in pursuit of its objectives (Correct answer)
- The total inventory of identified risks in the risk register
Correct answer: The amount of risk an organization is willing to accept in pursuit of its objectives
Risk appetite reflects the board-approved level of risk the organization is willing to take on while pursuing strategic goals.
Question 58: Which concept in regulatory compliance refers to the practice of treating similar regulatory requirements across different jurisdictions as a single, unified standard?
- Preemption
- Regulatory arbitrage
- Harmonization (Correct answer)
- Extraterritoriality
Correct answer: Harmonization
Harmonization is the process of aligning different regulatory requirements across jurisdictions into a common standard to reduce compliance complexity.
Question 59: Which of the following best describes a 'Key Risk Indicator' (KRI) in ERM?
- A forward-looking metric that signals increasing risk exposure (Correct answer)
- A control test result that confirms effectiveness
- A measure of past losses from risk events
- A financial ratio used in credit underwriting
Correct answer: A forward-looking metric that signals increasing risk exposure
KRIs are early-warning metrics that signal potential risk increases before a loss event occurs, enabling proactive management.
Question 60: Under the COSO ERM framework, which element directly links risk strategy to business objectives?
- Risk appetite statement
- Risk identification
- Strategy and Objective-Setting (Correct answer)
- Performance
Correct answer: Strategy and Objective-Setting
Strategy and Objective-Setting is the COSO ERM component where risk appetite is applied to align strategy with organizational objectives.
Question 61: Which standard provides internationally recognized guidance specifically for business continuity management systems?
- COBIT 2019
- ISO 27001
- NIST SP 800-53
- ISO 22301 (Correct answer)
Correct answer: ISO 22301
ISO 22301 is the international standard specifying requirements for planning, establishing, and implementing a Business Continuity Management System (BCMS).
Question 62: Which type of risk control is designed to detect and record security incidents after they occur?
- Preventive control
- Corrective control
- Detective control (Correct answer)
- Deterrent control
Correct answer: Detective control
Detective controls identify and log incidents that have already happened, such as intrusion detection systems and audit logs.
Question 63: ISO 31000:2018 identifies 'communication and consultation' as a process that should occur at which stage of the risk management process?
- Only when risks are escalated to the board
- Only during risk treatment
- Only during risk assessment
- Throughout all stages of the risk management process (Correct answer)
Correct answer: Throughout all stages of the risk management process
ISO 31000 specifies that communication and consultation with stakeholders should be an ongoing activity throughout all stages of the risk management process.
Question 64: During the audit planning phase, an internal auditor identifies and analyzes potential events that could hinder the achievement of organizational objectives. They then assess the likelihood and potential impact of these events. This process is known as:
- Risk assessment (Correct answer)
- Continuous monitoring
- Control testing
- Compliance verification
Correct answer: Risk assessment
Risk assessment is the process of identifying, analyzing, and evaluating risks to the achievement of objectives. This is a fundamental step in audit planning, as it helps auditors focus their efforts on the areas of highest risk to the organization.
Question 65: Which of the following best describes a primary objective of establishing an ERM framework within an organization?
- To satisfy the requirements of external auditors exclusively.
- To completely eliminate all strategic and operational risks.
- To replace the need for internal controls and departmental risk management.
- To provide a structured and consistent approach for identifying, assessing, and managing risks across the enterprise. (Correct answer)
Correct answer: To provide a structured and consistent approach for identifying, assessing, and managing risks across the enterprise.
The core purpose of an ERM framework is to establish a consistent, enterprise-wide approach to managing risk. It provides a structure for identifying potential events that may affect the entity, managing risk to be within its risk appetite, and providing reasonable assurance regarding the achievement of entity objectives. It is not possible to eliminate all risks, and while it aids audits, its purpose is much broader. ERM integrates with, rather than replaces, internal controls.
Question 66: Which internal control principle requires that no single individual can initiate, approve, and record a transaction?
- Need to know
- Least privilege
- Defense in depth
- Segregation of duties (Correct answer)
Correct answer: Segregation of duties
Segregation of duties (SoD) divides critical tasks among multiple people to prevent fraud and errors.
Question 67: During a risk committee meeting, a new manager suggests that the company's ERM framework should focus on responding to risks by either avoiding or accepting them. A GRC professional should advise that this view is incomplete because a comprehensive risk response strategy also includes:
- Transferring and escalating
- Enhancing and exploiting
- Ignoring and delaying
- Reducing and sharing (Correct answer)
Correct answer: Reducing and sharing
A standard ERM framework includes four primary risk responses: Avoid, Accept, Reduce (or Mitigate), and Share (or Transfer). Reducing risk involves implementing controls to lower its likelihood or impact. Sharing risk typically involves transferring a portion of it to a third party, such as through insurance.
Question 68: When a GRC framework refers to 'residual risk,' it means the risk that remains after:
- Control measures have been applied (Correct answer)
- Risk transfer to an insurer occurs
- Initial risk identification is complete
- The board formally accepts the risk
Correct answer: Control measures have been applied
Residual risk is the level of risk remaining after controls and mitigating measures have been implemented.
Question 69: What distinguishes a 'significant deficiency' from a 'material weakness' in internal controls?
- A material weakness applies only to IT controls
- A significant deficiency is more severe than a material weakness
- They are synonymous terms used interchangeably
- A material weakness represents a reasonable possibility of material misstatement; a significant deficiency is less severe (Correct answer)
Correct answer: A material weakness represents a reasonable possibility of material misstatement; a significant deficiency is less severe
A material weakness is more severe, indicating a reasonable possibility of a material misstatement; a significant deficiency is noteworthy but less severe.
Question 70: In risk assessment, Expected Monetary Value (EMV) is calculated as:
- The annualized premium paid for risk transfer through insurance
- Probability of risk occurrence multiplied by the financial impact of the risk (Correct answer)
- The cost of controls divided by residual risk exposure
- The sum of all risk scores across all business units
Correct answer: Probability of risk occurrence multiplied by the financial impact of the risk
EMV = Probability × Impact, providing a single financial figure that represents the weighted average expected loss from a risk event.
Question 71: Which regulatory framework governs export controls on dual-use items, software, and technology from the United States?
- Office of Foreign Assets Control (OFAC) sanctions
- Foreign Corrupt Practices Act (FCPA)
- International Traffic in Arms Regulations (ITAR)
- Export Administration Regulations (EAR) (Correct answer)
Correct answer: Export Administration Regulations (EAR)
The Export Administration Regulations (EAR) govern the export and re-export of most commercial and dual-use items, software, and technology.
Question 72: Under NIST SP 800-53, which control family specifically addresses security planning at the organizational level?
- Planning (PL) (Correct answer)
- Risk Assessment (RA)
- System and Services Acquisition (SA)
- Program Management (PM)
Correct answer: Planning (PL)
The Planning (PL) control family in NIST SP 800-53 covers system security plans and rules of behavior.
Question 73: A firm's BIA reveals that its order-processing system must be restored within 4 hours. This figure represents the:
- RPO
- RTO (Correct answer)
- MTPD
- MTD
Correct answer: RTO
RTO is the target duration within which a system must be restored after a disruption to avoid unacceptable consequences.
Question 74: In the NIST Cybersecurity Framework (CSF), which function focuses on limiting the impact of a cybersecurity incident?
- Identify
- Respond (Correct answer)
- Recover
- Protect
Correct answer: Respond
The Respond function of NIST CSF focuses on containing the impact of a cybersecurity incident once it has been detected.
Question 75: In a risk heat map, which axis typically represents the likelihood of a risk occurring?
- Horizontal axis (X-axis) (Correct answer)
- Both axes equally
- Neither axis — heat maps don't show likelihood
- Vertical axis (Y-axis)
Correct answer: Horizontal axis (X-axis)
Convention varies, but likelihood (probability) is most commonly plotted on the X-axis and impact on the Y-axis in risk heat maps.
Question 76: A global financial services firm is updating its GRC framework. A key objective is to ensure that its anti-money laundering (AML) program is effective across all jurisdictions in which it operates. Which of the following is the MOST critical first step in strengthening its regulatory compliance for AML?
- Rolling out mandatory AML training for all customer-facing employees across the globe.
- Hiring a former regulator to lead the internal audit function for the AML program.
- Implementing a new transaction monitoring software to automate the detection of suspicious activities.
- Conducting a comprehensive, enterprise-wide AML risk assessment to identify and understand specific risks. (Correct answer)
Correct answer: Conducting a comprehensive, enterprise-wide AML risk assessment to identify and understand specific risks.
A foundational element of any effective compliance program, especially for AML, is a thorough risk assessment. This process allows the organization to identify, understand, and prioritize the specific money laundering and terrorist financing risks it faces. All other activities, such as implementing technology, hiring experts, or training staff, should be informed by the results of this risk assessment to ensure they are targeted and effective.
Question 77: A policy owner role is BEST described as:
- An external auditor who reviews the policy annually
- Any employee who has read and signed the policy
- The person who writes the policy document
- The executive accountable for the policy's content, accuracy, and enforcement (Correct answer)
Correct answer: The executive accountable for the policy's content, accuracy, and enforcement
The policy owner is accountable for ensuring the policy remains accurate, current, and effectively implemented.
Question 78: Under GDPR, a Data Protection Impact Assessment (DPIA) is MANDATORY when processing is likely to result in:
- Processing data of more than 1,000 individuals
- High risk to the rights and freedoms of natural persons (Correct answer)
- Cross-border data transfers within the EU
- Any use of cookies on a website
Correct answer: High risk to the rights and freedoms of natural persons
Article 35 of GDPR requires a DPIA when processing is likely to result in a high risk to the rights and freedoms of individuals, particularly for systematic profiling or sensitive data processing.
Question 79: A walkthrough in an audit context is used to:
- Test all transactions in a population
- Walk auditors through the office floor plan
- Trace a transaction from initiation to recording to verify controls work as described (Correct answer)
- Physically inspect inventory on hand
Correct answer: Trace a transaction from initiation to recording to verify controls work as described
A walkthrough traces a single transaction end-to-end to confirm that described controls are actually operating.
Question 80: Which governance principle requires that board members and executives avoid situations where personal interests conflict with organizational interests?
- Director independence
- Stewardship
- Conflict of interest management (Correct answer)
- Fiduciary duty
Correct answer: Conflict of interest management
Conflict of interest management requires individuals to disclose and abstain from decisions where personal gain could compromise their objectivity.
Question 81: ISO/IEC 27001:2022 replaced which previous version of the standard?
- ISO/IEC 27001:2005
- ISO/IEC 27001:2018
- ISO/IEC 27001:2020
- ISO/IEC 27001:2013 (Correct answer)
Correct answer: ISO/IEC 27001:2013
ISO/IEC 27001:2022 replaced the 2013 version, introducing restructured Annex A controls and alignment with ISO Annex SL harmonized structure.
Question 82: Which COSO ERM component is responsible for setting the tone at the top and defining the organization's risk appetite?
- Governance and Culture (Correct answer)
- Review and Revision
- Control Activities
- Information and Communication
Correct answer: Governance and Culture
Governance and Culture is the COSO ERM 2017 component that establishes tone at the top, risk culture, and risk appetite.
Question 83: During policy review, stakeholders disagree on the acceptable use of personal devices for work email. What is the best next step?
- Conduct a risk assessment to inform the decision (Correct answer)
- Delay the policy until consensus is naturally reached
- Adopt the most restrictive option without analysis
- The CISO decides unilaterally and publishes the policy
Correct answer: Conduct a risk assessment to inform the decision
A risk assessment provides objective data on threats, vulnerabilities, and impacts to support informed stakeholder decision-making.
Question 84: Which audit procedure involves tracing a transaction from initiation through completion to understand the entire process flow?
- Observation
- Walkthrough (Correct answer)
- Confirmation
- Recalculation
Correct answer: Walkthrough
A walkthrough traces a single transaction end-to-end to verify the auditor's understanding of the process and identify control points.
Question 85: Which cybersecurity governance activity involves simulating a breach scenario to test whether incident response procedures are effective?
- Tabletop exercise (Correct answer)
- Control self-assessment
- Vulnerability assessment
- Security baseline review
Correct answer: Tabletop exercise
A tabletop exercise is a discussion-based simulation where stakeholders walk through a hypothetical incident scenario to evaluate their response procedures.
Question 86: Which metric defines the maximum acceptable amount of data loss measured in time during a disaster?
- Maximum Tolerable Downtime (MTD)
- Mean Time to Recover (MTTR)
- Recovery Time Objective (RTO)
- Recovery Point Objective (RPO) (Correct answer)
Correct answer: Recovery Point Objective (RPO)
RPO specifies the point in time to which data must be restored, defining the maximum tolerable data loss window.
Question 87: Which of the following BEST supports a risk-based approach to vendor due diligence?
- Applying identical assessment questionnaires to all vendors regardless of criticality
- Scaling the depth and frequency of assessments based on the vendor's risk tier and data access (Correct answer)
- Limiting assessments to vendors that process financial data
- Outsourcing all due diligence to the vendor's own compliance team
Correct answer: Scaling the depth and frequency of assessments based on the vendor's risk tier and data access
A risk-based approach tailors due diligence intensity to each vendor's risk profile, ensuring efficient use of assessment resources.
Question 88: Which ISO standard provides a framework specifically for risk management principles and guidelines applicable to any organization?
- ISO 31000 (Correct answer)
- ISO 9001
- ISO 27001
- ISO 22301
Correct answer: ISO 31000
ISO 31000 provides universal principles, a framework, and a process for managing risk applicable to any organization regardless of sector.
Question 89: Which concept describes the process of systematically identifying potential risks by examining all assets, threats, and vulnerabilities in a structured manner?
- Risk response planning
- Risk identification (Correct answer)
- Risk monitoring
- Risk acceptance
Correct answer: Risk identification
Risk identification is the process of finding, recognizing, and describing risks before they can be analyzed or treated, forming the first step of the risk management cycle.
Question 90: An organization uses a RACI matrix for its cybersecurity program. What does the 'A' in RACI represent?
- Auditable — the process that can be independently reviewed
- Assigned — the team given the task to complete
- Accountable — the person who owns the outcome and signs off (Correct answer)
- Authorized — the person permitted to access the system
Correct answer: Accountable — the person who owns the outcome and signs off
In a RACI matrix, 'Accountable' designates the single person who is ultimately answerable for the correct completion of a task or decision.
Question 91: An organization's TPRM policy requires vendors with access to PII to complete an annual security questionnaire. A vendor refuses to complete it. What is the BEST course of action?
- Accept the vendor's refusal and document the exception
- Escalate the issue; consider requiring an independent audit or terminating the relationship if the vendor remains non-compliant (Correct answer)
- Allow the vendor a permanent exemption if they are a large enterprise
- Remove the PII access requirement from the vendor's contract
Correct answer: Escalate the issue; consider requiring an independent audit or terminating the relationship if the vendor remains non-compliant
Non-compliance with assessment requirements is a material risk issue that should be escalated; the organization may need to enforce contractual remedies or exit the relationship.
Question 92: Which cybersecurity governance concept ensures that the controls implemented are proportional to the risk they address?
- Due diligence
- Least privilege
- Proportionality of controls (Correct answer)
- Defense in depth
Correct answer: Proportionality of controls
Proportionality of controls ensures resources spent on security measures are commensurate with the risk level, avoiding over- or under-investment.
Question 93: What is a best practice in implementing governance frameworks?
- Ignore stakeholders
- Involve key stakeholders (Correct answer)
- Limit stakeholder participation
- Focus only on senior management
Correct answer: Involve key stakeholders
Effective governance frameworks require broad acceptance and understanding across an organization. Involving key stakeholders, including employees, management, board members, and sometimes external parties, ensures that diverse perspectives are considered, fostering buy-in and making the framework more robust and relevant to the organization's specific context and needs. This collaborative approach enhances the framework's legitimacy and effectiveness.
Question 94: The concept of 'Privacy by Design' primarily means:
- Hiring a privacy attorney before launching a product
- Allowing users to opt out of data collection after sign-up
- Encrypting all databases after a breach occurs
- Embedding privacy protections into systems and processes from the outset (Correct answer)
Correct answer: Embedding privacy protections into systems and processes from the outset
Privacy by Design advocates for proactively integrating data privacy into the architecture of IT systems and business practices rather than treating it as an afterthought.
Question 95: Which risk mitigation technique involves duplicating critical systems to ensure availability during a failure?
- Encryption
- Redundancy (Correct answer)
- Patch management
- User training
Correct answer: Redundancy
Redundancy reduces the risk of system failure by maintaining backup components or systems that can take over if the primary fails.
Question 96: What is the first step in risk management?
- Identify potential risks (Correct answer)
- Increase workforce
- Implement controls
- Ignore risks
Correct answer: Identify potential risks
The foundational step in any effective risk management process is to systematically identify all potential risks that could impact an organization's objectives. Before risks can be analyzed, evaluated, or treated, they must first be recognized and documented. This initial identification phase ensures a comprehensive understanding of the risk landscape.
Question 97: Which document formally communicates the results of an internal audit to management and the audit committee?
- Audit work papers
- Risk register
- Audit report (Correct answer)
- Engagement letter
Correct answer: Audit report
The audit report summarizes findings, conclusions, and recommendations and is distributed to stakeholders after fieldwork is complete.
Question 98: In risk prioritization, which combination of factors typically determines a risk's priority for treatment?
- Vendor reputation and geographic location
- Regulatory penalty amounts and board meeting schedule
- Likelihood of occurrence and magnitude of potential impact (Correct answer)
- Cost of control implementation and audit frequency
Correct answer: Likelihood of occurrence and magnitude of potential impact
Risks are prioritized based on their likelihood (how probable) and impact (how severe), with high-likelihood/high-impact risks receiving the greatest attention and resources.
Question 99: What is the relationship between risk appetite and risk tolerance in GRC?
- Risk appetite applies to financial risk only; tolerance applies to operational risk
- They are synonymous terms used interchangeably
- Risk appetite is the broad level of risk accepted; risk tolerance is the acceptable variance around that level (Correct answer)
- Risk tolerance defines strategic objectives; risk appetite defines day-to-day operations
Correct answer: Risk appetite is the broad level of risk accepted; risk tolerance is the acceptable variance around that level
Risk appetite sets the overall amount of risk an organization is willing to accept, while risk tolerance defines the acceptable variation or deviation within that appetite.
Question 100: Which provision of the Gramm-Leach-Bliley Act (GLBA) requires financial institutions to develop a written information security program?
- Fair Lending Rule
- Pretexting Provisions
- Financial Privacy Rule
- Safeguards Rule (Correct answer)
Correct answer: Safeguards Rule
The GLBA Safeguards Rule requires financial institutions to implement a comprehensive written information security program to protect customer financial information.
GRC Professional (GRCP) Certification Exam
The GRC Professional (GRCP) certification validates an individual's understanding of the GRC capability and the ability to integrate governance, risk management, and compliance processes.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds