CGRC Certified in Governance Risk and Compliance Practice Test

140 preguntas disponibles

Gana confianza para CGRC Certified in Governance Risk and Compliance. Practica los conceptos, comprende las respuestas y refuerza tus conocimientos pregunta a pregunta.

Probar una pregunta
Prueba 5 preguntas gratis
No necesitas cuenta. Una cuenta gratuita incluye 20 preguntas de este examen.
Examen de certificación
125 Preguntas del examen
3 horas Límite de Tiempo
Tu práctica
140 Preguntas de práctica
2 horas 20 minutos Tiempo de Práctica
Prueba 5 preguntas gratis
No necesitas cuenta. Una cuenta gratuita incluye 20 preguntas de este examen.
El banco 140 Preguntas de práctica verificadas con los objetivos oficiales.
ISC2140 preguntas de práctica
Temario verificadoVerificado con ISC2 official objectivesMetadatos verificados 2026-09-17Cómo verificamos

Descripción y detalles del examen

ISC2 GRC certification covering IT security governance, risk management frameworks, authorization processes, and compliance monitoring for security professionals. Administered by ISC2. Key domains include Implementation of Security and Privacy Controls, Assessment/Audit of Security and Privacy Controls, Security and Privacy Governance, Risk Management, and Compliance Program and Selection and Approval of Framework, Security, and Privacy Controls. The exam consists of 125 questions over 180 minutes.

Preguntas de Muestra

Elige una respuesta y consulta la explicación para ver cómo funciona la práctica.

Selection and Approval of Framework, Security, and Privacy Controls

A federal agency wants to apply specific control modifications for industrial control systems. Which mechanism is most appropriate per NIST SP 800-53 Rev 5?

Implementation of Security and Privacy Controls

An ISSO implements media protection per MP-6 (Media Sanitization). Which NIST publication provides federal guidance for media sanitization methods?

Scope of the System

A federal agency is categorizing a system that handles unclassified Controlled Unclassified Information (CUI) related to law enforcement. Which combination of standards applies?

Scope of the System

An agency operates two related systems that share components. The CIO directs that they be authorized together to reduce duplication. Which approach is most appropriate per NIST SP 800-37 Rev 2?

Assessment/Audit of Security and Privacy Controls

A SCA discovers during assessment that a control originally marked Satisfied is now non-compliant due to a recent system change. What is the proper action per SP 800-37r2?

Oportunidades profesionales y salario

Salario medio: $129,180mercado de EE. UU.– Information Security Analysts

Fuente: BLS Occupational Employment and Wage Statistics, May 2025 -- Information Security Analysts (SOC 15-1212), US national. Occupation median, not a certification salary. (2025)

Information Security Analysts

Los rangos son cifras del mercado de EE. UU. salvo que se muestre un rango local.

Qué temas cubre este examen

Usa las ponderaciones publicadas de los dominios para planificar tu estudio. Los resultados de práctica no predicen tu puntuación en el examen de certificación.

01Implementation of Security and Privacy Controls

17%

Examines the practical implementation of security and privacy controls within enterprise environments, ensuring that all deployed technical, operational, and management safeguards function as intended to protect sensitive organizational data assets and infrastructure.

02Assessment/Audit of Security and Privacy Controls

16%

Covers the assessment and audit procedures required to evaluate security and privacy controls, verifying their operational effectiveness and ensuring that all identified vulnerabilities and deficiencies are properly documented, analyzed, and remediated.

03Security and Privacy Governance, Risk Management, and Compliance Program

16%

This domain covers security and privacy governance principles, organizational risk management strategies, and structured compliance programs that form the foundation for effective information security management across enterprise operations and modern architectures.

04Selection and Approval of Framework, Security, and Privacy Controls

14%

Addresses the selection and formal approval processes for governance frameworks, baseline security controls, and privacy controls designed to mitigate identified organizational risks and fulfill all mandatory regulatory requirements and internal security standards successfully.

05System Compliance

14%

Focuses on evaluating overall system compliance against established regulatory requirements and organizational policies, culminating in formal authorization decisions that determine whether an information system can operate securely within its designated environment.

06Compliance Maintenance

13%

Addresses ongoing compliance maintenance and continuous monitoring activities, ensuring that changes to information systems and their operating environments do not degrade the established security posture over the entire lifecycle of the deployment.

07Scope of the System

10%

Focuses on defining, analyzing, and managing the exact scope of the system by establishing clear boundaries and performing system categorization to ensure all necessary components are adequately identified and appropriately protected under security policies.

Detalles del Examen ISC2-CGRC | 3 horas

Código del Examen ISC2-CGRC
Proveedor ISC2
Límite de Tiempo 3 horas
Preguntas del examen 125

Preguntas Frecuentes

¿Cuál es la principal diferencia entre el CGRC y el CISSP?

¿Necesito experiencia práctica con el NIST RMF para aprobar?

¿Qué tan actualizados deben estar mis materiales de referencia?

¿Esta certificación solo es valiosa para contratistas del gobierno federal de EE. UU.?

¿Cuál es la forma más efectiva de estudiar para las preguntas basadas en escenarios?