GRC Professional (GRCP) Certification Exam — Questions and Answers
Question 1: What does 'risk velocity' refer to in enterprise risk management?
- The number of risks identified in a period
- The frequency of risk committee meetings
- The financial magnitude of a risk event
- The speed at which a risk could impact the organization if it materializes (Correct answer)
Correct answer: The speed at which a risk could impact the organization if it materializes
Risk velocity measures how quickly a risk could escalate from identification to impact, influencing how rapidly a response must be activated.
Question 2: In risk prioritization, which combination of factors typically determines a risk's priority for treatment?
- Regulatory penalty amounts and board meeting schedule
- Vendor reputation and geographic location
- Cost of control implementation and audit frequency
- Likelihood of occurrence and magnitude of potential impact (Correct answer)
Correct answer: Likelihood of occurrence and magnitude of potential impact
Risks are prioritized based on their likelihood (how probable) and impact (how severe), with high-likelihood/high-impact risks receiving the greatest attention and resources.
Question 3: A global manufacturing company is implementing an Enterprise Risk Management (ERM) framework. The Chief Risk Officer (CRO) wants to ensure the framework is adaptable to different business units and promotes a proactive risk culture. Which ERM framework is best known for its flexible, principles-based approach that can be customized to any organization's context?
- COBIT Framework
- NIST Risk Management Framework
- ISO 31000 (Correct answer)
- COSO ERM - Integrating with Strategy and Performance
Correct answer: ISO 31000
ISO 31000 is recognized for its flexible and principles-based approach, providing guidelines rather than mandatory requirements. This allows organizations to tailor the framework to their specific size, industry, and risk context. COSO ERM is more prescriptive, particularly for organizations focused on financial reporting and internal controls. NIST RMF is primarily for managing information security risk within U.S. federal agencies, and COBIT is a framework for the governance and management of enterprise IT.
Question 4: Which tool is most commonly used to document and track identified risks, their likelihood, potential impact, and assigned owners within an organization?
- Policy repository
- Risk register (Correct answer)
- Audit log
- Control matrix
Correct answer: Risk register
A risk register is the primary GRC artifact for cataloging risks along with their attributes such as likelihood, impact, owner, and mitigation status.
Question 5: When a vendor relationship ends, which action is MOST critical from a data security standpoint?
- Conducting a vendor satisfaction survey
- Archiving all vendor invoices for seven years
- Issuing a press release about the vendor change
- Ensuring the vendor destroys or returns all organizational data per contract terms (Correct answer)
Correct answer: Ensuring the vendor destroys or returns all organizational data per contract terms
Data destruction or return during offboarding prevents residual data exposure and is a core requirement in most data processing agreements.
Question 6: Which of the following best describes a 'standard' in GRC context?
- A specific mandatory requirement supporting a policy (Correct answer)
- A high-level statement of management intent
- A legal requirement from a regulatory body
- A recommended optional practice
Correct answer: A specific mandatory requirement supporting a policy
Standards are mandatory, specific requirements that operationalize policies and define minimum acceptable levels of compliance.
Question 7: What is the relationship between risk appetite and risk tolerance in GRC?
- Risk appetite is the broad level of risk accepted; risk tolerance is the acceptable variance around that level (Correct answer)
- Risk tolerance defines strategic objectives; risk appetite defines day-to-day operations
- Risk appetite applies to financial risk only; tolerance applies to operational risk
- They are synonymous terms used interchangeably
Correct answer: Risk appetite is the broad level of risk accepted; risk tolerance is the acceptable variance around that level
Risk appetite sets the overall amount of risk an organization is willing to accept, while risk tolerance defines the acceptable variation or deviation within that appetite.
Question 8: Which of the following is a primary objective of the COSO 'Internal Control – Integrated Framework'?
- To mandate specific IT security technologies for all public companies.
- To exclusively focus on preventing external cybersecurity threats.
- To provide a universal standard for product quality assurance.
- To help organizations design and implement effective internal controls to achieve objectives in operations, reporting, and compliance. (Correct answer)
Correct answer: To help organizations design and implement effective internal controls to achieve objectives in operations, reporting, and compliance.
The COSO framework is designed to help organizations establish, assess, and enhance their internal control systems. Its primary objectives cover the effectiveness and efficiency of operations, the reliability of financial and non-financial reporting, and compliance with applicable laws and regulations.
Question 9: A technology company is deciding between the COSO ERM and ISO 31000 frameworks. The company operates globally and has a diverse range of stakeholders. A key difference the GRC team should consider is that:
- ISO 31000 focuses solely on financial risks, while COSO ERM covers all risk categories.
- COSO ERM is primarily used in Europe, while ISO 31000 is dominant in North America.
- ISO 31000 results in a formal certification, whereas COSO ERM does not.
- COSO ERM is more prescriptive and detailed, often favored by audit and accounting professionals, while ISO 31000 is a more concise, high-level guideline. (Correct answer)
Correct answer: COSO ERM is more prescriptive and detailed, often favored by audit and accounting professionals, while ISO 31000 is a more concise, high-level guideline.
A significant distinction between the two frameworks is their presentation and level of detail. COSO's framework is substantially longer and more detailed, with a historical focus on internal controls and accounting, making it popular with auditors. ISO 31000 is a shorter, more flexible set of principles and guidelines. Neither framework offers a formal certification for compliance. Geographically, ISO 31000 has broader international adoption, while COSO is more prevalent in North America.
Question 10: Under the COSO ERM framework, which element directly links risk strategy to business objectives?
- Risk appetite statement
- Performance
- Strategy and Objective-Setting (Correct answer)
- Risk identification
Correct answer: Strategy and Objective-Setting
Strategy and Objective-Setting is the COSO ERM component where risk appetite is applied to align strategy with organizational objectives.
Question 11: What is the definition of 'residual risk' in a GRC context?
- The risk transferred to insurers or third parties
- The portion of risk that remains after controls and mitigation measures have been applied (Correct answer)
- The maximum possible loss from a single risk event
- The total of all identified risks before assessment
Correct answer: The portion of risk that remains after controls and mitigation measures have been applied
Residual risk is the remaining level of risk exposure after the organization has implemented its chosen controls and mitigation actions.
Question 12: In the NIST Cybersecurity Framework (CSF), which function focuses on limiting the impact of a cybersecurity incident?
- Protect
- Identify
- Respond (Correct answer)
- Recover
Correct answer: Respond
The Respond function of NIST CSF focuses on containing the impact of a cybersecurity incident once it has been detected.
Question 13: A SOC 2 Type II report differs from a SOC 2 Type I report in that it:
- Covers more Trust Service Criteria than Type I
- Tests controls over a period of time rather than at a single point in time (Correct answer)
- Is issued by the client organization rather than a third-party auditor
- Requires PCI DSS compliance as a prerequisite
Correct answer: Tests controls over a period of time rather than at a single point in time
SOC 2 Type II evaluates the operational effectiveness of controls over a defined period (usually 6–12 months), whereas Type I only assesses design at a point in time.
Question 14: Which of the following best describes 'governance washing' in a corporate context?
- Automating governance activities to reduce human oversight
- Publicly claiming strong governance practices without substantive implementation (Correct answer)
- Implementing excessive governance controls beyond regulatory requirements
- Transferring governance responsibilities to a third-party provider
Correct answer: Publicly claiming strong governance practices without substantive implementation
Governance washing refers to organizations projecting an image of strong governance through marketing or disclosures while failing to implement meaningful controls.
Question 15: What is the primary purpose of a Risk Appetite Statement in an ERM program?
- To set boundaries on how much risk the organization will accept in pursuit of its strategy (Correct answer)
- To assign risk owners to each identified risk
- To document past risk events and their impacts
- To enumerate every risk the organization faces
Correct answer: To set boundaries on how much risk the organization will accept in pursuit of its strategy
A Risk Appetite Statement communicates the board-approved level of risk the organization is willing to accept while pursuing its strategic objectives.
Question 16: Which of the following best describes a 'Key Risk Indicator' (KRI) in ERM?
- A measure of past losses from risk events
- A financial ratio used in credit underwriting
- A control test result that confirms effectiveness
- A forward-looking metric that signals increasing risk exposure (Correct answer)
Correct answer: A forward-looking metric that signals increasing risk exposure
KRIs are early-warning metrics that signal potential risk increases before a loss event occurs, enabling proactive management.
Question 17: Which of the following statements about risk tolerance vs. risk appetite is MOST accurate?
- They are synonymous and used interchangeably in all frameworks
- Risk appetite is broader and strategic; risk tolerance is the specific acceptable variation around that appetite (Correct answer)
- Risk appetite applies to financial risks only; risk tolerance applies to operational risks
- Risk tolerance is set by the board; risk appetite is set by management
Correct answer: Risk appetite is broader and strategic; risk tolerance is the specific acceptable variation around that appetite
Risk appetite expresses the overall level of risk an organization accepts in pursuit of value; risk tolerance specifies acceptable deviations from objectives within that appetite.
Question 18: What is the role of the Sarbanes-Oxley Act (SOX) in compliance?
- Increase legal loopholes
- Increase corporate profits
- Ensure accurate reporting and controls (Correct answer)
- Reduce regulatory oversight
Correct answer: Ensure accurate reporting and controls
The Sarbanes-Oxley Act (SOX) is a federal law passed in response to major corporate accounting scandals, primarily designed to protect investors by improving the accuracy and reliability of financial reporting. It mandates strict internal controls over financial reporting and increases accountability for corporate executives and auditors. SOX aims to prevent fraud and enhance corporate governance.
Question 19: The Right to Audit clause in a vendor contract primarily serves to:
- Allow the vendor to audit the client's systems for compliance
- Grant the organization the ability to examine the vendor's controls and records (Correct answer)
- Define the vendor's liability cap for data breaches
- Establish financial penalties for service outages
Correct answer: Grant the organization the ability to examine the vendor's controls and records
A Right to Audit clause gives the contracting organization (or its designee) the authority to review the vendor's security controls, processes, and records.
Question 20: An organization's legal department has identified a new data privacy regulation in a key market that will take effect in six months. What is the GRC professional's most appropriate immediate action?
- Immediately purchase and implement a new compliance management software.
- Assign the responsibility for compliance entirely to the IT department since it involves data.
- Wait for the regulatory body to publish detailed implementation guidance before taking any action.
- Conduct a gap analysis to compare the new regulatory requirements against the organization's current policies and controls. (Correct answer)
Correct answer: Conduct a gap analysis to compare the new regulatory requirements against the organization's current policies and controls.
The most logical and effective first step is to conduct a gap analysis. This will identify where the organization's current practices fall short of the new requirements. The results of this analysis will then inform a detailed action plan, which might include policy updates, new control implementation, training, and potentially new technology. Acting without this analysis could lead to wasted resources and ineffective compliance.
Question 21: Which of the following BEST supports a risk-based approach to vendor due diligence?
- Applying identical assessment questionnaires to all vendors regardless of criticality
- Outsourcing all due diligence to the vendor's own compliance team
- Limiting assessments to vendors that process financial data
- Scaling the depth and frequency of assessments based on the vendor's risk tier and data access (Correct answer)
Correct answer: Scaling the depth and frequency of assessments based on the vendor's risk tier and data access
A risk-based approach tailors due diligence intensity to each vendor's risk profile, ensuring efficient use of assessment resources.
Question 22: Which ISO standard provides guidance specifically on information security governance for boards and senior executives?
- ISO/IEC 27005
- ISO/IEC 27014 (Correct answer)
- ISO/IEC 27001
- ISO/IEC 27035
Correct answer: ISO/IEC 27014
ISO/IEC 27014 provides guidance on concepts and principles for the governance of information security at the organizational level.
Question 23: After a BCP activation, which activity ensures lessons are captured and the plan is improved?
- Post-incident or post-exercise review (after-action review) (Correct answer)
- Root cause analysis only for IT failures
- Immediate re-testing within 24 hours
- Regulatory self-assessment
Correct answer: Post-incident or post-exercise review (after-action review)
An after-action review systematically captures what worked, what failed, and what should be improved in the BCP following an activation or exercise.
Question 24: Which type of audit evidence is generally considered the MOST reliable?
- Inquiry from process owners
- Verbal confirmation from management
- Internally generated documents
- Externally obtained documentary evidence (Correct answer)
Correct answer: Externally obtained documentary evidence
Evidence obtained from independent third parties outside the entity is considered more reliable than internally produced records.
Question 25: Which component of the COSO ERM framework 2017 update reflects the integration of strategy-setting with enterprise risk management?
- Control activities
- Information, communication, and reporting
- Risk assessment
- Strategy and objective-setting (Correct answer)
Correct answer: Strategy and objective-setting
The 2017 COSO ERM update emphasized 'Strategy and Objective-Setting' as the component linking ERM directly to organizational strategy.
Question 26: An organization must demonstrate cybersecurity compliance to a federal agency. Which US framework is most likely mandated for federal information systems?
- CIS Controls
- NIST RMF (Risk Management Framework) (Correct answer)
- PCI DSS
- SOC 2 Type II
Correct answer: NIST RMF (Risk Management Framework)
NIST RMF is the mandatory framework for federal agencies under FISMA to manage security and privacy risks for information systems.
Question 27: Which COSO ERM 2017 component focuses on tracking performance against risk-adjusted targets and identifying changes in risk?
- Review and Revision (Correct answer)
- Information and Communication
- Governance and Culture
- Strategy and Objective-Setting
Correct answer: Review and Revision
Review and Revision involves monitoring the ERM program's effectiveness, tracking performance, and updating the approach as the risk landscape changes.
Question 28: A company's accounts payable clerk also approves invoices for payment. This represents a failure in:
- Segregation of duties (Correct answer)
- Change management controls
- Physical access controls
- IT general controls
Correct answer: Segregation of duties
When one individual both authorizes and processes payments, a key segregation of duties requirement is violated.
Question 29: Which scenario best illustrates a 'pandemic' as a BCP threat category distinct from physical disasters?
- Widespread employee illness simultaneously reduces workforce availability company-wide (Correct answer)
- A cyberattack encrypts all files
- A hurricane destroys the primary data center
- A power grid failure affects the region for 72 hours
Correct answer: Widespread employee illness simultaneously reduces workforce availability company-wide
Pandemics threaten workforce availability across all locations simultaneously, unlike physical disasters that target specific facilities or infrastructure.
Question 30: In risk management, 'threat modeling' is best described as:
- Assigning dollar values to each identified threat
- Simulating cyberattacks on live production systems
- A structured process for identifying, enumerating, and prioritizing potential threats to a system (Correct answer)
- Creating a list of all possible insurance claims
Correct answer: A structured process for identifying, enumerating, and prioritizing potential threats to a system
Threat modeling proactively identifies threats, vulnerabilities, and countermeasures during design or assessment to improve security posture.
Question 31: Which element is NOT one of the three pillars of the EU-US Data Privacy Framework that replaced Privacy Shield?
- Binding corporate rules for transfers (Correct answer)
- Data minimization requirements
- Safeguards on US government access to data
- Redress mechanisms for EU individuals
Correct answer: Binding corporate rules for transfers
The EU-US Data Privacy Framework's three pillars address data protection obligations, redress mechanisms, and US government surveillance safeguards — not binding corporate rules.
Question 32: In GRC, 'accountability' at the board level primarily means that directors are responsible for:
- Filing compliance reports directly with regulators on behalf of management
- Approving every individual risk mitigation action plan
- Personally executing all compliance tasks within the organization
- Providing oversight and ensuring management establishes and maintains an effective governance and risk framework (Correct answer)
Correct answer: Providing oversight and ensuring management establishes and maintains an effective governance and risk framework
Board-level accountability in GRC means directors oversee and challenge management's approach to governance and risk rather than performing operational compliance tasks themselves.
Question 33: What is the primary purpose of a 'compensating control'?
- To mitigate a risk when a primary control cannot be implemented (Correct answer)
- To reward auditors who find deficiencies
- To duplicate an existing control for redundancy
- To pay employees for identifying control gaps
Correct answer: To mitigate a risk when a primary control cannot be implemented
A compensating control provides alternative risk mitigation when the ideal primary control is not feasible.
Question 34: Which principle ensures that a policy is enforceable across the organization?
- The policy must be written in legal language only
- The policy must reference at least three external frameworks
- Senior management must visibly support and comply with the policy (Correct answer)
- Only IT personnel are required to follow the policy
Correct answer: Senior management must visibly support and comply with the policy
Management commitment and visible compliance signal that the policy applies equally to all levels, reinforcing its authority.
Question 35: An organization decides not to launch a new product line because the associated risks exceed its appetite. Which response strategy does this represent?
- Accept
- Reduce
- Transfer
- Avoid (Correct answer)
Correct answer: Avoid
Avoidance means not pursuing an activity or decision because the risk is deemed unacceptable relative to the potential reward.
Question 36: How does risk transfer work in risk mitigation?
- Transfer the risk to another party (Correct answer)
- Store the risk
- Increase exposure
- Ignore the risk
Correct answer: Transfer the risk to another party
Risk transfer is a strategy where the financial or operational burden of a potential risk is shifted from one party to another. This is commonly achieved through mechanisms like insurance, where an insurer assumes the financial risk in exchange for premiums, or through contractual agreements with third parties. It allows the original organization to reduce its direct exposure to certain risks.
Question 37: What does 'vendor lock-in' risk refer to in the context of third-party risk management?
- A vendor physically locking access to leased equipment upon contract expiration
- Difficulty or high cost of transitioning away from a vendor due to deep technical or contractual dependencies (Correct answer)
- A vendor refusing to allow subcontracting arrangements
- Regulatory prohibitions on switching cloud providers in regulated industries
Correct answer: Difficulty or high cost of transitioning away from a vendor due to deep technical or contractual dependencies
Vendor lock-in occurs when proprietary technologies, data formats, or exit barriers make switching vendors prohibitively expensive or complex, reducing organizational flexibility.
Question 38: Why is risk prioritization important?
- Reduce resources
- Ignore the risks
- Increase risk exposure
- Focus on the most critical risks first (Correct answer)
Correct answer: Focus on the most critical risks first
Risk prioritization is essential because organizations typically have limited resources to address all identified risks simultaneously. By prioritizing risks based on their assessed severity and likelihood, organizations can allocate resources efficiently to tackle the most critical threats first. This ensures that the most significant potential impacts on objectives are managed proactively, optimizing risk management efforts.
Question 39: What is the primary difference between qualitative and quantitative risk assessment?
- Qualitative uses descriptive rankings; quantitative uses numerical values and statistical methods (Correct answer)
- Qualitative is performed by auditors; quantitative is performed by management
- Qualitative applies only to cyber risk; quantitative applies to financial risk
- Qualitative uses monetary values; quantitative uses descriptive rankings
Correct answer: Qualitative uses descriptive rankings; quantitative uses numerical values and statistical methods
Qualitative assessments categorize risks using descriptive scales (high/medium/low), while quantitative assessments assign numerical probabilities and financial impact figures.
Question 40: Which Three Lines Model component is responsible for providing independent assurance to the board?
- First line (operations)
- External auditors
- Second line (risk/compliance functions)
- Third line (internal audit) (Correct answer)
Correct answer: Third line (internal audit)
The third line (internal audit) provides independent, objective assurance and advice to the board on governance, risk, and control.
Question 41: An organization storing sensitive data in AWS wants to achieve FedRAMP authorization. Which step must come FIRST in the formal authorization process?
- Obtain a Provisional Authorization to Operate (P-ATO) from the JAB
- Complete a System Security Plan (SSP) (Correct answer)
- Hire a Third Party Assessment Organization (3PAO)
- Conduct penetration testing
Correct answer: Complete a System Security Plan (SSP)
The FedRAMP authorization process begins with completing a System Security Plan (SSP) that documents all security controls implemented in the cloud system.
Question 42: Which framework is most commonly associated with enterprise risk management (ERM) and uses components such as risk appetite and risk culture?
- COSO ERM (Correct answer)
- COBIT 5
- NIST RMF
- ISO 27001
Correct answer: COSO ERM
The COSO ERM framework provides guidance on enterprise-wide risk management, including risk culture, governance, and appetite.
Question 43: Under Sarbanes-Oxley Section 302, who must personally certify the accuracy of financial reports?
- The audit committee chair
- All members of the board of directors
- The CFO and CEO (Correct answer)
- External auditors only
Correct answer: The CFO and CEO
SOX Section 302 requires the CEO and CFO to personally certify the accuracy and completeness of financial reports filed with the SEC.
Question 44: A BCP plan owner discovers the contact list has not been updated in 18 months. This violates which BCP principle?
- Risk acceptance
- Testing frequency
- Plan maintenance and currency (Correct answer)
- Change management integration
Correct answer: Plan maintenance and currency
BCPs must be regularly maintained and updated to remain accurate, including personnel contact information and organizational changes.
Question 45: An organization sets its RPO at zero for financial transaction data. What technology best supports this requirement?
- Synchronous real-time replication (Correct answer)
- Weekly full backup with incremental backups
- Asynchronous batch replication every 4 hours
- Daily tape backup
Correct answer: Synchronous real-time replication
Synchronous replication writes data to both primary and secondary locations simultaneously, ensuring zero data loss (RPO = 0).
Question 46: The ultimate goal of implementing an integrated GRC capability, as defined by OCEG, is to achieve:
- Complete Risk Elimination
- Principled Performance (Correct answer)
- Maximum Profitability
- Guaranteed Regulatory Approval
Correct answer: Principled Performance
OCEG defines the goal of GRC as achieving 'Principled Performance,' which is the reliable achievement of objectives while addressing uncertainty and acting with integrity. This concept encompasses not just compliance or risk mitigation but a holistic approach to performing well ethically and effectively.
Question 47: Which GRC model principle emphasizes that risk management activities should be proportional to the size and complexity of the organization?
- Scalability (Correct answer)
- Transparency
- Accountability
- Integration
Correct answer: Scalability
Scalability ensures that GRC frameworks are appropriately sized and tailored to the organization's complexity, not applied in a one-size-fits-all manner.
Question 48: What is a best practice in implementing governance frameworks?
- Limit stakeholder participation
- Focus only on senior management
- Ignore stakeholders
- Involve key stakeholders (Correct answer)
Correct answer: Involve key stakeholders
Effective governance frameworks require broad acceptance and understanding across an organization. Involving key stakeholders, including employees, management, board members, and sometimes external parties, ensures that diverse perspectives are considered, fostering buy-in and making the framework more robust and relevant to the organization's specific context and needs. This collaborative approach enhances the framework's legitimacy and effectiveness.
Question 49: Which key performance indicator (KPI) in risk management measures how quickly an organization can restore operations after a disruption?
- Risk Tolerance Threshold (RTT)
- Recovery Point Objective (RPO)
- Recovery Time Objective (RTO) (Correct answer)
- Mean Time Between Failures (MTBF)
Correct answer: Recovery Time Objective (RTO)
RTO defines the maximum acceptable length of time to restore a business function after an incident.
Question 50: How does continuous monitoring enhance internal controls?
- Ensure consistent application and adaptation (Correct answer)
- Reduce monitoring frequency
- Increase risk exposure
- Delay changes
Correct answer: Ensure consistent application and adaptation
Continuous monitoring enhances internal controls by providing ongoing oversight and real-time feedback on their performance. Instead of periodic checks, it ensures that controls are consistently applied and can adapt quickly to changing circumstances or emerging risks. This proactive approach allows for immediate detection and correction of control deficiencies, maintaining their effectiveness over time.
Question 51: The NIST Privacy Framework's 'Communicate-P' function focuses on:
- Increasing awareness of how privacy values are implemented in policies and practices (Correct answer)
- Encrypting personal data at rest and in transit
- Transferring privacy risk to third-party processors
- Filing breach notifications with regulators
Correct answer: Increasing awareness of how privacy values are implemented in policies and practices
The Communicate-P function involves developing and implementing activities to inform individuals and increase awareness of privacy policies and practices.
Question 52: In quantitative risk assessment, Monte Carlo simulation is used to:
- Assign controls to risks based on cost-benefit ratios
- Rank risks qualitatively using color-coded heat maps
- Calculate inherent risk before applying controls
- Run thousands of random scenarios to model the probability distribution of potential outcomes (Correct answer)
Correct answer: Run thousands of random scenarios to model the probability distribution of potential outcomes
Monte Carlo simulation repeatedly samples random values for uncertain variables to produce a statistical distribution of possible risk outcomes and their probabilities.
Question 53: In the context of GRC, 'control self-assessment' (CSA) is best described as:
- An external auditor's evaluation of internal controls
- A regulatory examination of compliance programs
- A vendor's assessment of their customer's security posture
- A process where management and staff evaluate their own controls' effectiveness (Correct answer)
Correct answer: A process where management and staff evaluate their own controls' effectiveness
Control self-assessment involves process owners and employees evaluating the adequacy and effectiveness of controls in their own area of responsibility.
Question 54: Which framework specifically provides a standardized questionnaire used widely in vendor security assessments?
- Shared Assessments SIG (Standardized Information Gathering) (Correct answer)
- NIST SP 800-37
- COBIT 2019
- ISO 31000
Correct answer: Shared Assessments SIG (Standardized Information Gathering)
The Shared Assessments SIG is a comprehensive, industry-standard questionnaire used to assess vendor security, privacy, and compliance controls.
Question 55: Which COBIT 2019 design factor primarily considers the organization's strategy for using IT — ranging from IT avoider to first mover?
- IT strategy (Correct answer)
- Compliance requirements
- Enterprise size
- Risk appetite
Correct answer: IT strategy
COBIT 2019's 'IT strategy' design factor categorizes organizations on a spectrum from IT avoider (minimal IT use) to first mover (IT as competitive differentiator).
Question 56: Which of the following best defines the 'Compliance' component within an integrated GRC framework?
- The process of identifying, assessing, and responding to potential threats to the organization's objectives.
- The process of adhering to applicable laws, regulations, industry standards, and internal policies. (Correct answer)
- The process of ensuring an organization's activities align with its strategic business goals and ethical standards.
- The system of rules, practices, and processes by which a company is directed and controlled.
Correct answer: The process of adhering to applicable laws, regulations, industry standards, and internal policies.
The 'Compliance' pillar of GRC is specifically focused on ensuring the organization operates within the boundaries set by external authorities (laws and regulations) and internal commitments (policies and codes of conduct). While the other options describe governance and risk management, this answer choice accurately defines the compliance function.
Question 57: What is the role of auditing in internal controls?
- Assess and ensure control effectiveness (Correct answer)
- Ignore compliance issues
- Increase risk exposure
- Promote fraud
Correct answer: Assess and ensure control effectiveness
Auditing plays a crucial role in internal controls by independently assessing whether these controls are designed and operating effectively. It helps identify weaknesses, non-compliance, or inefficiencies within the control system. By providing an objective evaluation, auditing ensures that controls are robust enough to mitigate risks and achieve organizational objectives.
Question 58: Which U.S. federal law primarily governs the privacy of health information held by covered entities and their business associates?
- GLBA
- CCPA
- FERPA
- HIPAA (Correct answer)
Correct answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) establishes national standards for protecting sensitive patient health information.
Question 59: What does 'control self-assessment' (CSA) involve?
- IT staff testing cybersecurity defenses
- External auditors evaluating management's controls
- Regulators reviewing compliance with laws
- Management and staff evaluating the effectiveness of their own controls (Correct answer)
Correct answer: Management and staff evaluating the effectiveness of their own controls
CSA is a technique where operational staff and management assess control effectiveness within their own units.
Question 60: Which of the following BEST describes a 'material weakness' in internal controls?
- A control deficiency where there is a reasonable possibility of material financial misstatement (Correct answer)
- A weakness that only affects IT systems
- Any failed control identified during an audit
- A minor control gap with no financial impact
Correct answer: A control deficiency where there is a reasonable possibility of material financial misstatement
A material weakness is the most severe level of deficiency, indicating a significant risk that financial statements could be materially misstated.
Question 61: What is segregation of duties in internal controls?
- Increase task duplication
- Divide responsibilities to prevent errors and fraud (Correct answer)
- Increase control over staff
- Centralize decision-making
Correct answer: Divide responsibilities to prevent errors and fraud
Segregation of duties is a fundamental internal control principle that involves dividing critical tasks among different individuals. This prevents any single person from having complete control over a process, thereby reducing the opportunity for errors, fraud, or misuse of assets. By separating responsibilities like authorization, record-keeping, and asset custody, it creates a system of checks and balances.
Question 62: Which type of risk arises from inadequate or failed internal processes, people, systems, or external events?
- Reputational risk
- Strategic risk
- Operational risk (Correct answer)
- Credit risk
Correct answer: Operational risk
Operational risk, as defined by Basel II/III, stems from breakdowns in internal processes, human errors, system failures, or external events.
Question 63: The California Consumer Privacy Act (CCPA) grants California residents the right to opt out of which specific business activity?
- Storage of biometric data
- Sale of their personal information (Correct answer)
- Use of cookies on websites
- Data encryption practices
Correct answer: Sale of their personal information
CCPA gives California residents the right to direct a business to stop selling their personal information to third parties.
Question 64: Which international standard provides a framework for information security risk management specifically?
- ISO 22301
- ISO 27005 (Correct answer)
- ISO 31000
- ISO 9001
Correct answer: ISO 27005
ISO 27005 provides guidelines for information security risk management and is designed to support implementation of ISO 27001.
Question 65: A healthcare organization is concerned about potential violations of the Health Insurance Portability and Accountability Act (HIPAA). To strengthen its legal and regulatory compliance, the GRC team decides to implement a control. Which of the following is an example of a 'preventive' control in this context?
- Implementing a security incident response plan to handle data breaches.
- Enforcing role-based access controls to limit access to patient data to only authorized personnel. (Correct answer)
- Reviewing and revoking access rights for employees who have left the organization.
- Conducting regular audits of patient record access logs.
Correct answer: Enforcing role-based access controls to limit access to patient data to only authorized personnel.
A preventive control is designed to stop a compliance violation from occurring in the first place. Role-based access controls proactively limit access to sensitive patient data, thereby preventing unauthorized viewing or use. The other options are detective (auditing logs) or corrective/responsive (incident response plan, revoking access after departure) controls.
Question 66: Which governance principle requires that decision-makers can be held responsible and must answer for their actions to stakeholders?
- Transparency
- Subsidiarity
- Stewardship
- Accountability (Correct answer)
Correct answer: Accountability
Accountability in governance means that individuals and organizations must answer for their decisions and actions to appropriate stakeholders and accept the consequences of those decisions.
Question 67: An organization's TPRM policy requires vendors with access to PII to complete an annual security questionnaire. A vendor refuses to complete it. What is the BEST course of action?
- Remove the PII access requirement from the vendor's contract
- Allow the vendor a permanent exemption if they are a large enterprise
- Escalate the issue; consider requiring an independent audit or terminating the relationship if the vendor remains non-compliant (Correct answer)
- Accept the vendor's refusal and document the exception
Correct answer: Escalate the issue; consider requiring an independent audit or terminating the relationship if the vendor remains non-compliant
Non-compliance with assessment requirements is a material risk issue that should be escalated; the organization may need to enforce contractual remedies or exit the relationship.
Question 68: The concept of 'materiality' in auditing refers to:
- The physical existence of assets being audited
- The significance of an error or misstatement that could influence users' decisions (Correct answer)
- The number of transactions selected for testing
- The type of material used in audit documentation
Correct answer: The significance of an error or misstatement that could influence users' decisions
Materiality defines the threshold above which misstatements could reasonably influence decisions of financial statement users.
Question 69: A bow-tie analysis in risk management is best described as:
- A process flowchart showing audit procedures
- A ranking tool that assigns numeric scores to risks based on severity
- A matrix mapping controls to risks in a two-by-two grid
- A diagram connecting risk causes on the left to consequences on the right with the hazard/risk event at the center (Correct answer)
Correct answer: A diagram connecting risk causes on the left to consequences on the right with the hazard/risk event at the center
A bow-tie diagram visually represents threat causes (left side), the central risk event, preventive controls, and consequence mitigation controls (right side).
Question 70: Which document type provides the 'why' behind security requirements and sets management intent?
- Standard
- Policy (Correct answer)
- Procedure
- Guideline
Correct answer: Policy
Policies communicate management's intent and the organization's position on a topic without prescribing specific implementation steps.
Question 71: An organization uses a RACI matrix for its cybersecurity program. What does the 'A' in RACI represent?
- Assigned — the team given the task to complete
- Auditable — the process that can be independently reviewed
- Accountable — the person who owns the outcome and signs off (Correct answer)
- Authorized — the person permitted to access the system
Correct answer: Accountable — the person who owns the outcome and signs off
In a RACI matrix, 'Accountable' designates the single person who is ultimately answerable for the correct completion of a task or decision.
Question 72: Under the FTC Act, the FTC has authority to take action against companies for unfair or deceptive privacy practices under which section?
- Section 5 (Correct answer)
- Section 12
- Section 702
- Section 230
Correct answer: Section 5
Section 5 of the FTC Act prohibits unfair or deceptive acts or practices in commerce, which the FTC uses as its primary authority to enforce consumer data privacy.
Question 73: A 'control deficiency' exists when:
- Management disagrees with auditor findings
- A control is overly complex and redundant
- A control prevents all unauthorized transactions
- A control is missing or not operating effectively enough to prevent or detect misstatements (Correct answer)
Correct answer: A control is missing or not operating effectively enough to prevent or detect misstatements
A control deficiency occurs when the design or operation of a control does not allow management to prevent or detect misstatements on a timely basis.
Question 74: From a GRC perspective, which of the following is the primary benefit of integrating Business Continuity Management (BCM) into the overall governance and risk management framework?
- It guarantees that the organization will never experience a service disruption.
- It replaces the need for cybersecurity insurance policies.
- It eliminates the need for the internal audit function to review disaster recovery capabilities.
- It ensures that the response to disruptive events is aligned with the organization's risk appetite and strategic objectives. (Correct answer)
Correct answer: It ensures that the response to disruptive events is aligned with the organization's risk appetite and strategic objectives.
Integrating BCM into a GRC framework ensures that business continuity efforts are not siloed. This alignment connects the identification of critical processes and the investment in recovery capabilities directly to the organization's strategic goals and its overall tolerance for risk (risk appetite). It provides a holistic view, ensuring that continuity planning supports overarching governance objectives.
Question 75: During the TPRM lifecycle, which phase occurs *after* a vendor has been onboarded and is focused on continuously tracking their performance, security posture, and adherence to contractual obligations?
- Risk Assessment
- Due Diligence
- Ongoing Monitoring (Correct answer)
- Contract Negotiation
Correct answer: Ongoing Monitoring
Ongoing monitoring is the phase of the TPRM lifecycle that takes place after a vendor is onboarded. It involves continuously assessing the vendor to ensure they remain compliant and uphold the agreements established in the contract and to detect any new or emerging risks in real-time.
Question 76: According to the COSO Internal Control-Integrated Framework, which component establishes the 'tone at the top' and includes the ethical values and integrity of the organization?
- Control Activities
- Control Environment (Correct answer)
- Risk Assessment
- Monitoring Activities
Correct answer: Control Environment
The Control Environment is the foundation for all other components of internal control, providing discipline and structure. It encompasses the integrity, ethical values, and competence of the entity's people, as well as management's philosophy and operating style.
Question 77: What is a 'compensating control'?
- A control that replaces financial losses
- An alternative control that mitigates risk when the primary control is not feasible (Correct answer)
- A backup procedure for IT systems
- A control that detects fraud after the fact
Correct answer: An alternative control that mitigates risk when the primary control is not feasible
Compensating controls provide alternative risk mitigation when standard controls cannot be implemented due to cost or operational constraints.
Question 78: Under the NIST Cybersecurity Framework 2.0, which new function was added compared to the original five?
- Protect
- Recover
- Respond
- Govern (Correct answer)
Correct answer: Govern
NIST CSF 2.0 added 'Govern' as a sixth function to emphasize cybersecurity governance at the organizational level.
Question 79: Which component of the COSO Internal Control framework addresses the organization's values, ethical standards, and the importance management places on integrity?
- Information and Communication
- Risk Assessment
- Control Environment (Correct answer)
- Monitoring Activities
Correct answer: Control Environment
The Control Environment is the foundation of COSO's internal control framework, encompassing tone at the top, values, ethics, and organizational structure.
Question 80: What is an audit trail?
- A record of activities for audit purposes (Correct answer)
- A report of all financial data
- A log of all staff actions
- A list of financial statements
Correct answer: A record of activities for audit purposes
An audit trail is a chronological record of activities, transactions, or system events that allows for reconstruction and verification. It provides documentary evidence of who did what, when, and where, making it possible to trace the flow of information or assets. This record is essential for auditors to review and validate processes, ensuring accountability and transparency.
Question 81: In GRC, a 'control objective' is best defined as:
- A regulatory requirement imposed by law
- A specific test procedure used by internal auditors
- A statement of the desired result or purpose to be achieved by implementing controls (Correct answer)
- A metric used to measure control performance
Correct answer: A statement of the desired result or purpose to be achieved by implementing controls
A control objective states the goal that a control is designed to achieve, providing the basis for designing and evaluating the control.
Question 82: Which risk mitigation technique involves duplicating critical systems to ensure availability during a failure?
- Patch management
- Redundancy (Correct answer)
- User training
- Encryption
Correct answer: Redundancy
Redundancy reduces the risk of system failure by maintaining backup components or systems that can take over if the primary fails.
Question 83: Which governance best practice addresses conflicts of interest by requiring board members to disclose personal financial interests related to company decisions?
- Related-party transaction disclosure (Correct answer)
- Proxy access provisions
- Director independence requirements
- Say-on-pay voting
Correct answer: Related-party transaction disclosure
Related-party transaction disclosure requires directors to reveal personal financial interests that could influence their objectivity on board decisions.
Question 84: In a GRC context, 'tone at the top' refers to:
- The frequency of board-level GRC reporting
- The volume level of executive presentations
- The topmost tier of a risk classification matrix
- Senior leadership's visible commitment to ethical behavior and compliance (Correct answer)
Correct answer: Senior leadership's visible commitment to ethical behavior and compliance
Tone at the top describes the ethical climate and culture of compliance that senior leaders establish through their own behavior and communications, which sets expectations throughout the organization.
Question 85: A global company is standardizing its policy management process. In the typical document hierarchy, which element provides detailed, step-by-step instructions on how to implement the mandatory requirements set forth by a standard?
- A guideline
- A control objective
- A procedure (Correct answer)
- A policy
Correct answer: A procedure
In the GRC document hierarchy, a policy sets the high-level strategic direction (the 'why'). A standard sets mandatory, specific requirements to support the policy (the 'what'). A procedure provides the detailed, step-by-step instructions on how to meet the standard's requirements (the 'how').
Question 86: In a mature GRC model, 'risk appetite' is best described as:
- The residual risk remaining after controls are applied
- The amount of risk an organization is willing to accept to achieve its objectives (Correct answer)
- The threshold at which regulatory penalties are triggered
- The maximum risk the organization can absorb before failing
Correct answer: The amount of risk an organization is willing to accept to achieve its objectives
Risk appetite is the level of risk an organization is prepared to accept in pursuit of its strategic goals, set by senior leadership.
Question 87: Which approach to third-party risk assessment relies on real-time or near-real-time data feeds about a vendor's security posture from external sources?
- Questionnaire-based assessment
- Continuous monitoring / cyber risk ratings (Correct answer)
- On-site inspection audit
- Contractual self-attestation
Correct answer: Continuous monitoring / cyber risk ratings
Cyber risk rating platforms (e.g., BitSight, SecurityScorecard) continuously scan external-facing vendor infrastructure to provide ongoing security posture signals.
Question 88: In continuous auditing, the primary advantage over traditional periodic audits is:
- Elimination of the need for external auditors
- Lower cost per audit cycle
- Less documentation required
- Near real-time monitoring that enables faster detection of anomalies (Correct answer)
Correct answer: Near real-time monitoring that enables faster detection of anomalies
Continuous auditing uses automated tools to monitor transactions constantly, allowing quicker identification and response to control failures.
Question 89: Which cybersecurity governance document outlines acceptable and prohibited uses of organizational IT resources by employees?
- System Security Plan (SSP)
- Incident Response Plan (IRP)
- Acceptable Use Policy (AUP) (Correct answer)
- Disaster Recovery Plan (DRP)
Correct answer: Acceptable Use Policy (AUP)
An Acceptable Use Policy defines what employees may and may not do with organizational IT resources, setting behavioral expectations.
Question 90: What distinguishes a 'significant deficiency' from a 'material weakness' in internal controls?
- A material weakness represents a reasonable possibility of material misstatement; a significant deficiency is less severe (Correct answer)
- A significant deficiency is more severe than a material weakness
- They are synonymous terms used interchangeably
- A material weakness applies only to IT controls
Correct answer: A material weakness represents a reasonable possibility of material misstatement; a significant deficiency is less severe
A material weakness is more severe, indicating a reasonable possibility of a material misstatement; a significant deficiency is noteworthy but less severe.
Question 91: Under GDPR, what is the relationship between a company that collects personal data and a vendor that processes it on the company's behalf?
- The company is the Data Controller and the vendor is the Data Processor (Correct answer)
- The vendor is the Data Controller and the company is the Data Processor
- Both are considered data subjects
- Both are Data Controllers with equal liability
Correct answer: The company is the Data Controller and the vendor is the Data Processor
GDPR defines the data-collecting company as the Controller and the vendor that processes data per the Controller's instructions as the Processor.
Question 92: The 'three lines of defense' model assigns internal audit to which line?
- Fourth line
- Third line (Correct answer)
- First line
- Second line
Correct answer: Third line
Internal audit is the third line of defense, providing independent assurance over the first (operations) and second (risk/compliance) lines.
Question 93: An organization implements a compliance training program but employees later repeat the same violations. According to the DOJ's guidance on effective compliance programs, what is the most likely deficiency?
- Failure to use e-learning platforms
- Training that is not reinforced through consistent enforcement and discipline (Correct answer)
- Lack of tone at the top
- Insufficient training frequency
Correct answer: Training that is not reinforced through consistent enforcement and discipline
The DOJ emphasizes that training must be supported by consistent disciplinary action; without enforcement, employees learn that policies are not seriously enforced.
Question 94: Which risk response strategy involves shifting the financial consequence of a risk to a third party, such as through insurance?
- Risk avoidance
- Risk transfer (Correct answer)
- Risk reduction
- Risk acceptance
Correct answer: Risk transfer
Risk transfer moves the financial burden of a risk to another party (e.g., insurer or vendor) while the organization may still retain some residual risk.
Question 95: Which COSO ERM principle states that organizations should develop a 'portfolio view' of risk?
- Pursues Improvement in Enterprise Risk Management
- Defines Risk Appetite
- Develops Portfolio View (Correct answer)
- Analyzes Business Context
Correct answer: Develops Portfolio View
The 'Develops Portfolio View' principle requires management to aggregate risks across business units to understand the total risk profile relative to appetite.
Question 96: Which regulation enacted after the 2001 financial scandals requires CEOs and CFOs to personally certify the accuracy of financial reports?
- Sarbanes-Oxley Act Section 302 (Correct answer)
- Investment Advisers Act
- Dodd-Frank Act
- Securities Exchange Act Section 10(b)
Correct answer: Sarbanes-Oxley Act Section 302
SOX Section 302 requires principal executive and financial officers to personally certify the accuracy and completeness of periodic SEC financial reports.
Question 97: An organization's GRC committee wants to validate its business continuity plan's effectiveness in a realistic manner without causing an actual business disruption. The team decides to conduct an exercise where key personnel gather in a conference room to talk through their roles and responsibilities during a simulated crisis scenario. What type of test is this?
- Parallel Test
- Tabletop Exercise (Correct answer)
- Full Interruption Test
- System Walk-through
Correct answer: Tabletop Exercise
A tabletop exercise is a discussion-based session where team members meet to discuss their roles and responses during a simulated emergency scenario. This type of test is designed to identify gaps in the plan and ensure personnel are familiar with procedures without the cost and risk of a live test, such as a full interruption or parallel test.
Question 98: A Control Self-Assessment (CSA) is a technique where:
- Management and staff assess the effectiveness of controls over their own processes (Correct answer)
- External auditors independently evaluate all key controls
- Regulators review control documentation submitted by the organization
- IT systems automatically test control configurations
Correct answer: Management and staff assess the effectiveness of controls over their own processes
CSA empowers process owners and their teams to evaluate control effectiveness themselves, promoting accountability and surfacing risk insights without waiting for formal audits.
Question 99: The King IV Report on Corporate Governance is principally applied in which country and is notable for which approach?
- USA; shareholder-centric mandatory disclosures
- UK; rules-based mandatory compliance
- South Africa; apply-and-explain principles-based approach (Correct answer)
- Australia; sector-specific industry codes
Correct answer: South Africa; apply-and-explain principles-based approach
King IV is a South African governance code using an 'apply and explain' approach, where organizations disclose how they apply each principle.
Question 100: In cybersecurity governance, what does a 'tone at the top' primarily influence?
- Security culture and employee behavior (Correct answer)
- Network segmentation design
- Technical firewall configurations
- Patch management schedules
Correct answer: Security culture and employee behavior
Tone at the top refers to leadership attitudes that shape organizational security culture and how seriously employees treat security policies.
GRC Professional (GRCP) Certification Exam
The GRC Professional (GRCP) certification validates an individual's understanding of the GRC capability and the ability to integrate governance, risk management, and compliance processes.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds