An unhandled error has occurred. Reload X
Skip to main content

CGRC: Certified in Governance, Risk and Compliance Exam Practice Test

117 questions available

The Certified in Governance, Risk and Compliance (CGRC) certification, formerly known as the Certified Authorization Professional (CAP), is a premier credential offered by (ISC)². It validates a professional's comprehensive ability to implement, manage, and assess the security and privacy controls that safeguard an organization's information systems and data. The CGRC credential is built upon the NIST Risk Management Framework (RMF), providing a standardized, rigorous methodology for system authorization and continuous monitoring. Earning the CGRC demonstrates mastery in translating governance objectives and regulatory requirements into actionable security controls, effectively managing risk, and ensuring ongoing compliance. It is a critical certification for professionals responsible for the security assessment and authorization process, particularly within U.S. federal agencies, government contractors, and any organization adhering to rigorous compliance standards like FISMA, FedRAMP, and similar frameworks. Holders are recognized for their expertise in bridging the gap between technical security measures and organizational governance.

117 Practice Questions
1 hour 57 minutes Practice Time
Start Practice
The bank 117 Practice questions checked against the official objectives.
(ISC)2117 practice questions56 answers with a checkable referenceBlueprint 1.0Bank updated 2026-05-04

Sample Questions

Try a few questions to see what the full exam is like.

56 of 117 answers carry a checkable reference.

D7: Compliance Maintenance

Westport Defense Supplier is preparing CGRC work for a CUI design repository hosted in a SaaS enclave. The environment is subject to NIST SP 800-171 Rev. 3 and CMMC 2.0; it handles controlled drawings, export-control markings, and supplier attestations. During planning, the business sponsor wants a single-page risk summary, and the SaaS vendor advertises SOC 2 Type II. For incident response maintenance, which action should the CGRC practitioner recommend?

D4: Implementation of Security and Privacy Controls

Cedar River Benefits Agency is preparing CGRC work for a cloud case-management system moving to FedRAMP Moderate. The environment is subject to FISMA, OMB A-130, and FedRAMP Rev. 5; it handles benefits records, tax identifiers, and scanned appeals. During planning, the managed-service provider offers a standard evidence packet, and the vendor also changed its logo in the release notes. For shared responsibility, which action should the CGRC practitioner recommend?

Risk Management

Summit Treasury Bureau is preparing CGRC work for a financial reporting system using common controls. The environment is subject to FISMA, OMB M-22-09, and NIST SP 800-37 Rev. 2; it handles budget submissions, SSO assertions, and audit logs. During planning, a recent audit found two low-risk documentation gaps, and training attendance dipped during holidays. For non-repudiation and integrity, which action should the CGRC practitioner recommend?

Risk Management

Borealis Health Exchange is preparing CGRC work for a Moderate-impact patient eligibility platform. The environment is subject to HIPAA, state breach notification, and FIPS 199; it handles claims data, address history, and lab order metadata. During planning, the system owner wants to reuse last year's authorization memo, and an unrelated help-desk backlog grew 18 percent. For risk framing, which action should the CGRC practitioner recommend?

D3: Selection and Approval of Framework, Security, and Privacy Controls

Helio Federal Lab is preparing CGRC work for a research collaboration environment with inherited identity services. The environment is subject to NIST RMF, FIPS 199, and SP 800-53 Rev. 5; it handles grant data, vulnerability reports, and privileged admin logs. During planning, operations has a maintenance freeze in 19 days, and two nonproduction servers are scheduled for disposal. For control enhancements, which action should the CGRC practitioner recommend?

Why This Certification Opens Doors

The CGRC certification is a significant career differentiator that signals to employers a validated, expert-level competency in the critical intersection of governance, risk, and compliance. In an era of escalating cyber threats and complex regulatory landscapes, organizations actively seek professionals who can navigate and implement structured risk management frameworks. Achieving the CGRC enhances professional credibility, opens doors to advanced roles such as Information System Security Officer (ISSO), GRC Analyst, and Authorizing Official/Designated Representative, and often commands higher earning potential. It is a globally recognized benchmark of excellence, signifying a commitment to the highest standards of professional practice and ethical responsibility in information security governance.

Exam Blueprint

01Compliance Management
02Continuous Monitoring and Reporting
03Governance of Enterprise Risk and Security
04Risk Management
05Risk Management Framework (RMF) and Control Implementation
06Security Assessment and Authorization (A&A)

Exam Details CGRC

Exam Code CGRC
Vendor (ISC)2

Frequently Asked Questions

What are the experience requirements to qualify for the CGRC certification?

To qualify for the CGRC, you must have a minimum of two years of cumulative, paid work experience in one or more of the seven domains of the CGRC CBK. A four-year college degree or an approved credential from the (ISC)² prerequisite list can substitute for one year of the required experience. Candidates without the required experience can still take the exam to become an Associate of (ISC)² and will then have five years to gain the necessary experience.

How does the CGRC differ from other security certifications like CISSP or CISM?

While the CISSP covers a broad range of security management topics and the CISM focuses on information security management, the CGRC is highly specialized. It delves deeply into the specific processes of security assessment, authorization, and continuous monitoring, primarily through the lens of the NIST Risk Management Framework. The CGRC is particularly focused on the 'how' of implementing governance and compliance within a structured, repeatable lifecycle, making it essential for roles directly involved in system accreditation and audit.

Is the CGRC relevant only for professionals working with the U.S. federal government?

While the CGRC's foundation in the NIST RMF makes it a gold standard for U.S. federal agencies and contractors (e.g., under FISMA and FedRAMP), its principles are universally applicable. The framework provides a robust, risk-based methodology for managing governance and compliance that is adopted by organizations worldwide in finance, healthcare, critical infrastructure, and other heavily regulated industries seeking a mature, process-oriented approach to security control management.

What is the format and duration of the CGRC exam?

The CGRC exam is a computer-based test consisting of 125 multiple-choice questions. Candidates are given 3 hours to complete the exam. The questions are designed to assess both knowledge and the ability to apply concepts from the seven domains of the CGRC CBK. A passing score is 700 out of 1000 points.

What are the Continuing Professional Education (CPE) requirements for maintaining the CGRC?

To maintain your CGRC certification, you must earn 90 Continuing Professional Education (CPE) credits over a three-year cycle and pay an Annual Maintenance Fee (AMF). You must also adhere to the (ISC)² Code of Ethics. CPE credits can be earned through activities such as attending relevant training, publishing security-related content, presenting at conferences, or engaging in other professional development activities related to the GRC domains.