CGRC Certified in Governance Risk and Compliance Practice Test
Build your confidence for CGRC Certified in Governance Risk and Compliance. Practice the concepts, understand the answers, and strengthen your knowledge one question at a time.
Try a sample questionExam overview and details
ISC2 GRC certification covering IT security governance, risk management frameworks, authorization processes, and compliance monitoring for security professionals. Administered by ISC2. Key domains include Implementation of Security and Privacy Controls, Assessment/Audit of Security and Privacy Controls, Security and Privacy Governance, Risk Management, and Compliance Program and Selection and Approval of Framework, Security, and Privacy Controls. The exam consists of 125 questions over 180 minutes.
Sample Questions
Choose an answer and explore the explanation to see how practice works.
A federal agency wants to apply specific control modifications for industrial control systems. Which mechanism is most appropriate per NIST SP 800-53 Rev 5?
An ISSO implements media protection per MP-6 (Media Sanitization). Which NIST publication provides federal guidance for media sanitization methods?
A federal agency is categorizing a system that handles unclassified Controlled Unclassified Information (CUI) related to law enforcement. Which combination of standards applies?
An agency operates two related systems that share components. The CIO directs that they be authorized together to reduce duplication. Which approach is most appropriate per NIST SP 800-37 Rev 2?
A SCA discovers during assessment that a control originally marked Satisfied is now non-compliant due to a recent system change. What is the proper action per SP 800-37r2?
Career Opportunities & Salary
Exam insights and study advice
In today's regulatory landscape, organizations face significant financial and reputational consequences for compliance failures. The CGRC provides a standardized, vendor-neutral methodology for managing cybersecurity risk and proving due diligence to auditors, regulators, and executive leadership. Holders of this certification are equipped to systematically protect organizational assets, justify security investments, and create a repeatable process for achieving and maintaining authorization to operate (ATO) for critical systems. This directly translates to reduced organizational risk, more efficient audit cycles, and a stronger security posture aligned with business objectives.
What this exam covers
Use the published domain weights to plan your study. Practice results do not predict your certification exam score.
01Implementation of Security and Privacy Controls
Examines the practical implementation of security and privacy controls within enterprise environments, ensuring that all deployed technical, operational, and management safeguards function as intended to protect sensitive organizational data assets and infrastructure.
02Assessment/Audit of Security and Privacy Controls
Covers the assessment and audit procedures required to evaluate security and privacy controls, verifying their operational effectiveness and ensuring that all identified vulnerabilities and deficiencies are properly documented, analyzed, and remediated.
03Security and Privacy Governance, Risk Management, and Compliance Program
This domain covers security and privacy governance principles, organizational risk management strategies, and structured compliance programs that form the foundation for effective information security management across enterprise operations and modern architectures.
04Selection and Approval of Framework, Security, and Privacy Controls
Addresses the selection and formal approval processes for governance frameworks, baseline security controls, and privacy controls designed to mitigate identified organizational risks and fulfill all mandatory regulatory requirements and internal security standards successfully.
05System Compliance
Focuses on evaluating overall system compliance against established regulatory requirements and organizational policies, culminating in formal authorization decisions that determine whether an information system can operate securely within its designated environment.
06Compliance Maintenance
Addresses ongoing compliance maintenance and continuous monitoring activities, ensuring that changes to information systems and their operating environments do not degrade the established security posture over the entire lifecycle of the deployment.
07Scope of the System
Focuses on defining, analyzing, and managing the exact scope of the system by establishing clear boundaries and performing system categorization to ensure all necessary components are adequately identified and appropriately protected under security policies.