An unhandled error has occurred. Reload X
मुख्य सामग्री पर जाएं

CGRC: Certified in Governance, Risk and Compliance Exam Practice Test

117 प्रश्न उपलब्ध

The Certified in Governance, Risk and Compliance (CGRC) certification, formerly known as the Certified Authorization Professional (CAP), is a premier credential offered by (ISC)². It validates a professional's comprehensive ability to implement, manage, and assess the security and privacy controls that safeguard an organization's information systems and data. The CGRC credential is built upon the NIST Risk Management Framework (RMF), providing a standardized, rigorous methodology for system authorization and continuous monitoring. Earning the CGRC demonstrates mastery in translating governance objectives and regulatory requirements into actionable security controls, effectively managing risk, and ensuring ongoing compliance. It is a critical certification for professionals responsible for the security assessment and authorization process, particularly within U.S. federal agencies, government contractors, and any organization adhering to rigorous compliance standards like FISMA, FedRAMP, and similar frameworks. Holders are recognized for their expertise in bridging the gap between technical security measures and organizational governance.

117 अभ्यास प्रश्न
1 घंटा 57 मिनट अभ्यास समय
अभ्यास शुरू करें
प्रश्न बैंक 117 आधिकारिक उद्देश्यों के विरुद्ध जाँचे गए अभ्यास प्रश्न.
(ISC)2117 अभ्यास प्रश्न56 उत्तरों के साथ जाँचने योग्य संदर्भब्लूप्रिंट 1.0बैंक 2026-05-04 को अपडेट हुआ

नमूना प्रश्न

पूरी परीक्षा कैसी है देखने के लिए कुछ प्रश्न आज़माएं।

117 में से 56 उत्तरों में जाँचने योग्य संदर्भ है।

D7: Compliance Maintenance

Westport Defense Supplier is preparing CGRC work for a CUI design repository hosted in a SaaS enclave. The environment is subject to NIST SP 800-171 Rev. 3 and CMMC 2.0; it handles controlled drawings, export-control markings, and supplier attestations. During planning, the business sponsor wants a single-page risk summary, and the SaaS vendor advertises SOC 2 Type II. For incident response maintenance, which action should the CGRC practitioner recommend?

D4: Implementation of Security and Privacy Controls

Cedar River Benefits Agency is preparing CGRC work for a cloud case-management system moving to FedRAMP Moderate. The environment is subject to FISMA, OMB A-130, and FedRAMP Rev. 5; it handles benefits records, tax identifiers, and scanned appeals. During planning, the managed-service provider offers a standard evidence packet, and the vendor also changed its logo in the release notes. For shared responsibility, which action should the CGRC practitioner recommend?

Risk Management

Summit Treasury Bureau is preparing CGRC work for a financial reporting system using common controls. The environment is subject to FISMA, OMB M-22-09, and NIST SP 800-37 Rev. 2; it handles budget submissions, SSO assertions, and audit logs. During planning, a recent audit found two low-risk documentation gaps, and training attendance dipped during holidays. For non-repudiation and integrity, which action should the CGRC practitioner recommend?

Risk Management

Borealis Health Exchange is preparing CGRC work for a Moderate-impact patient eligibility platform. The environment is subject to HIPAA, state breach notification, and FIPS 199; it handles claims data, address history, and lab order metadata. During planning, the system owner wants to reuse last year's authorization memo, and an unrelated help-desk backlog grew 18 percent. For risk framing, which action should the CGRC practitioner recommend?

D3: Selection and Approval of Framework, Security, and Privacy Controls

Helio Federal Lab is preparing CGRC work for a research collaboration environment with inherited identity services. The environment is subject to NIST RMF, FIPS 199, and SP 800-53 Rev. 5; it handles grant data, vulnerability reports, and privileged admin logs. During planning, operations has a maintenance freeze in 19 days, and two nonproduction servers are scheduled for disposal. For control enhancements, which action should the CGRC practitioner recommend?

परीक्षा ब्लूप्रिंट

01Compliance Management
02Continuous Monitoring and Reporting
03Governance of Enterprise Risk and Security
04Risk Management
05Risk Management Framework (RMF) and Control Implementation
06Security Assessment and Authorization (A&A)

परीक्षा विवरण CGRC

परीक्षा कोड CGRC
विक्रेता (ISC)2

अक्सर पूछे जाने वाले प्रश्न

CGRC प्रमाणन के लिए योग्य होने के लिए अनुभव की आवश्यकताएँ क्या हैं?

CGRC के लिए योग्य होने के लिए, आपके पास CGRC CBK के सात क्षेत्रों में से एक या अधिक में न्यूनतम दो वर्षों का संचयी, भुगतान किया गया कार्य अनुभव होना चाहिए। चार वर्षीय कॉलेज डिग्री या (ISC)² पूर्वापेक्षा सूची से अनुमोदित प्रमाणपत्र एक वर्ष के आवश्यक अनुभव के लिए प्रतिस्थापित किया जा सकता है। जिन उम्मीदवारों के पास आवश्यक अनुभव नहीं है, वे (ISC)² के सहयोगी बनने के लिए परीक्षा दे सकते हैं और फिर आवश्यक अनुभव प्राप्त करने के लिए उन्हें पांच वर्ष मिलेंगे।

CGRC अन्य सुरक्षा प्रमाणनों जैसे CISSP या CISM से कैसे भिन्न है?

जहाँ CISSP सुरक्षा प्रबंधन विषयों की एक विस्तृत श्रृंखला को कवर करता है और CISM सूचना सुरक्षा प्रबंधन पर केंद्रित है, CGRC अत्यधिक विशिष्ट है। यह सुरक्षा मूल्यांकन, प्राधिकरण, और निरंतर निगरानी की विशिष्ट प्रक्रियाओं में गहराई से उतरता है, मुख्य रूप से NIST जोखिम प्रबंधन ढांचे के दृष्टिकोण से। CGRC विशेष रूप से एक संरचित, दोहराने योग्य जीवनचक्र के भीतर शासन और अनुपालन को लागू करने के 'कैसे' पर केंद्रित है, जिससे यह प्रणाली मान्यता और ऑडिट में सीधे शामिल भूमिकाओं के लिए आवश्यक बनाता है।

क्या CGRC केवल उन पेशेवरों के लिए प्रासंगिक है जो अमेरिकी संघीय सरकार के साथ काम कर रहे हैं?

हालांकि CGRC की नींव NIST RMF में है, जो इसे अमेरिकी संघीय एजेंसियों और ठेकेदारों (जैसे, FISMA और FedRAMP के तहत) के लिए एक स्वर्ण मानक बनाता है, इसके सिद्धांत सार्वभौमिक रूप से लागू होते हैं। यह ढांचा शासन और अनुपालन प्रबंधन के लिए एक मजबूत, जोखिम-आधारित पद्धति प्रदान करता है जिसे वित्त, स्वास्थ्य देखभाल, महत्वपूर्ण बुनियादी ढाँचे, और अन्य भारी विनियमित उद्योगों में विश्व स्तर पर अपनाया गया है, जो सुरक्षा नियंत्रण प्रबंधन के लिए एक परिपक्व, प्रक्रिया-उन्मुख दृष्टिकोण की तलाश कर रहे हैं।

CGRC परीक्षा का प्रारूप और अवधि क्या है?

CGRC परीक्षा एक कंप्यूटर-आधारित परीक्षण है जिसमें 125 बहुविकल्पीय प्रश्न होते हैं। उम्मीदवारों को परीक्षा पूरी करने के लिए 3 घंटे दिए जाते हैं। प्रश्नों को CGRC CBK के सात क्षेत्रों से अवधारणाओं को लागू करने की क्षमता और ज्ञान दोनों का आकलन करने के लिए डिज़ाइन किया गया है। उत्तीर्ण स्कोर 1000 अंकों में से 700 है।

CGRC बनाए रखने के लिए निरंतर व्यावसायिक शिक्षा (CPE) की आवश्यकताएँ क्या हैं?

अपने CGRC प्रमाणन को बनाए रखने के लिए, आपको तीन साल के चक्र में 90 निरंतर व्यावसायिक शिक्षा (CPE) क्रेडिट अर्जित करने होंगे और वार्षिक रखरखाव शुल्क (AMF) का भुगतान करना होगा। आपको (ISC)² नैतिकता के कोड का पालन भी करना होगा। CPE क्रेडिट उन गतिविधियों के माध्यम से अर्जित किए जा सकते हैं जैसे संबंधित प्रशिक्षण में भाग लेना, सुरक्षा से संबंधित सामग्री प्रकाशित करना, सम्मेलनों में प्रस्तुत करना, या GRC क्षेत्रों से संबंधित अन्य पेशेवर विकास गतिविधियों में संलग्न होना।