CGRC: Certified in Governance, Risk and Compliance Exam Practice Test
The Certified in Governance, Risk and Compliance (CGRC) certification, formerly known as the Certified Authorization Professional (CAP), is a premier credential offered by (ISC)². It validates a professional's comprehensive ability to implement, manage, and assess the security and privacy controls that safeguard an organization's information systems and data. The CGRC credential is built upon the NIST Risk Management Framework (RMF), providing a standardized, rigorous methodology for system authorization and continuous monitoring. Earning the CGRC demonstrates mastery in translating governance objectives and regulatory requirements into actionable security controls, effectively managing risk, and ensuring ongoing compliance. It is a critical certification for professionals responsible for the security assessment and authorization process, particularly within U.S. federal agencies, government contractors, and any organization adhering to rigorous compliance standards like FISMA, FedRAMP, and similar frameworks. Holders are recognized for their expertise in bridging the gap between technical security measures and organizational governance.
नमूना प्रश्न
पूरी परीक्षा कैसी है देखने के लिए कुछ प्रश्न आज़माएं।
117 में से 56 उत्तरों में जाँचने योग्य संदर्भ है।
Westport Defense Supplier is preparing CGRC work for a CUI design repository hosted in a SaaS enclave. The environment is subject to NIST SP 800-171 Rev. 3 and CMMC 2.0; it handles controlled drawings, export-control markings, and supplier attestations. During planning, the business sponsor wants a single-page risk summary, and the SaaS vendor advertises SOC 2 Type II. For incident response maintenance, which action should the CGRC practitioner recommend?
Cedar River Benefits Agency is preparing CGRC work for a cloud case-management system moving to FedRAMP Moderate. The environment is subject to FISMA, OMB A-130, and FedRAMP Rev. 5; it handles benefits records, tax identifiers, and scanned appeals. During planning, the managed-service provider offers a standard evidence packet, and the vendor also changed its logo in the release notes. For shared responsibility, which action should the CGRC practitioner recommend?
Summit Treasury Bureau is preparing CGRC work for a financial reporting system using common controls. The environment is subject to FISMA, OMB M-22-09, and NIST SP 800-37 Rev. 2; it handles budget submissions, SSO assertions, and audit logs. During planning, a recent audit found two low-risk documentation gaps, and training attendance dipped during holidays. For non-repudiation and integrity, which action should the CGRC practitioner recommend?
Borealis Health Exchange is preparing CGRC work for a Moderate-impact patient eligibility platform. The environment is subject to HIPAA, state breach notification, and FIPS 199; it handles claims data, address history, and lab order metadata. During planning, the system owner wants to reuse last year's authorization memo, and an unrelated help-desk backlog grew 18 percent. For risk framing, which action should the CGRC practitioner recommend?
Helio Federal Lab is preparing CGRC work for a research collaboration environment with inherited identity services. The environment is subject to NIST RMF, FIPS 199, and SP 800-53 Rev. 5; it handles grant data, vulnerability reports, and privileged admin logs. During planning, operations has a maintenance freeze in 19 days, and two nonproduction servers are scheduled for disposal. For control enhancements, which action should the CGRC practitioner recommend?