Skip to content

CGRC Practice Questions

Prepare for CGRC with more than an answer.

225 questions in the full set20 sample questionsUpdated Jan 26, 2026
Exam fee
$599 USD
Level
Professional
Valid for
3 years
Domains covered on the exam 7
  1. Security and Privacy Governance, Risk Management, and Compliance Program16%
  2. Scope of the System10%
  3. Selection and Approval of Framework, Security, and Privacy Controls14%
  4. Implementation of Security and Privacy Controls17%
  5. Assessment/Audit of Security and Privacy Controls16%
  6. System Compliance14%
  7. Compliance Maintenance13%
  1. 1

    An organization can use the results of a previous assessment for a new authorization decision, provided that the results are still current, relevant, and accurate. This practice is known as ____________.

    Show answer details

    Correct answer: B

    Reciprocity is the principle of reusing assessment results and authorization decisions across different organizations or systems to reduce redundant testing and effort. It is a key concept in frameworks like FedRAMP and is encouraged by the RMF to improve efficiency, as long as the reused information is verified to be trustworthy.

  2. 2

    True or False: A Plan of Action and Milestones (POA&M) is considered a static document that is finalized during the 'Authorize' step and is only reviewed upon re-authorization.

    Show answer details

    Correct answer: B

    This statement is false. The POA&M is a dynamic risk management tool. It is a key input to the continuous monitoring process ('Monitor' step). The status of POA&M items must be regularly tracked, updated as remediation activities progress, and reviewed to ensure weaknesses are being addressed in a timely manner. It is a living document throughout the system's lifecycle.

  3. 3

    A system has been categorized with a High impact level for confidentiality. The system owner proposes tailoring out control AC-11 (Session Lock) because users find it inconvenient. Which of the following is the most compelling reason for the ISSM to reject this proposal?

    Show answer details

    Correct answer: A

    Tailoring decisions must be based on a risk assessment, not user preference or convenience. AC-11 is a critical control for protecting against unauthorized access to unattended sessions, directly supporting the confidentiality objective. For a High confidentiality system, the risk of not implementing this control is significant. A justification based on inconvenience is insufficient and would likely be rejected by an assessor and the AO.

  4. 4

    A project manager for a new logistics system is working with the ISSO to identify the information types the system will process. They have identified 'shipping manifests' and 'inventory levels'. To properly categorize the system according to NIST SP 800-60, what additional step must they take?

    flowchart TD A[Identify Business Functions] --> B{Identify Information Types}; B --> C[Map to NIST SP 800-60 Categories]; C --> D{Determine Provisional Impact Levels}; D --> E[Finalize System Categorization];
    Show answer details

    Correct answer: B

    NIST SP 800-60 provides a standardized catalog of information type categories (e.g., 'Logistics', 'Financial Management'). The purpose is to create consistency in categorization across the federal government. After identifying the business-specific information types ('shipping manifests'), the next step is to map them to these standard categories. This mapping then provides a provisional impact level (e.g., Logistics is provisionally Low-Moderate-Low), which serves as a starting point for the final FIPS 199 categorization.

  5. 5

    A key component of the RMF 'Prepare' step is the identification of common controls. Which of the following are benefits of establishing a robust common control program? (Select TWO)

    Show answer details

    Correct answer: A, C

  6. 6

    A government agency's primary data center was impacted by a regional power outage, causing their main citizen services portal to become unavailable. The disaster recovery plan was activated, and services were restored at a secondary site within the RTO. In the context of the RMF, this event primarily represents a failure of which security objective?

    Show answer details

    Correct answer: C

    The security objective of Availability is to ensure timely and reliable access to and use of information. A power outage that makes a system inaccessible is a direct impact on its availability. While the recovery plan worked, the initial event was an availability failure. Confidentiality relates to preventing unauthorized disclosure, and Integrity relates to preventing improper modification.

  7. 7

    A Security Assessor is tasked with creating a Security Assessment Plan (SAP). According to NIST SP 800-53A, which of the following is the MOST essential component of a well-formed SAP?

    Show answer details

    Correct answer: C

    The core purpose of the Security Assessment Plan is to provide a detailed roadmap for how the assessment will be conducted. This includes specifying the exact procedures—derived from NIST SP 800-53A—that will be used to verify each control's implementation. This level of detail ensures the assessment is comprehensive, repeatable, and transparent to all stakeholders, especially the system owner. While other elements like personnel and schedules are included, the procedures are the heart of the plan.

  8. 8

    A federal agency is preparing a new data analytics platform for authorization. The platform will process publicly available datasets as well as sensitive citizen PII. The development team has proposed a system boundary that includes the cloud-based data lake and processing engines, but excludes the on-premises data ingestion servers that perform initial data cleansing. According to NIST SP 800-37 R2, what is the primary risk of this proposed boundary definition?

    Show answer details

    Correct answer: D

    The authorization boundary must encompass all components essential for the system's mission. By excluding the on-premises ingestion servers, which are integral to the data processing workflow, the agency creates a significant gap in its risk assessment. Vulnerabilities in these excluded servers could be exploited to compromise the data's integrity or confidentiality before it even reaches the assessed and authorized cloud environment. This introduces unmanaged risk, undermining the entire authorization effort.

  9. 9

    A healthcare provider is implementing a continuous monitoring program for its Electronic Health Record (EHR) system, which has a High impact categorization. The current strategy involves monthly vulnerability scans, quarterly access reviews, and annual penetration tests. A GRC analyst notes that while these activities are performed, the results are only reviewed during the annual assessment cycle. Which RMF step is being inadequately addressed in this scenario?

    Show answer details

    Correct answer: C

    According to NIST SP 800-137, a key part of the 'Monitor' step is not just collecting security data but analyzing and responding to it to maintain a current understanding of security posture. The scenario describes data collection (scans, reviews) but fails to incorporate ongoing analysis and response. Delaying the review of findings until the annual assessment defeats the purpose of continuous monitoring, which is to enable timely risk-based decisions. The process lacks the 'Analyze and Report' and 'Respond' functions of a mature monitoring program.

  10. 10

    A defense contractor is implementing the SI-4 (Information System Monitoring) control from NIST SP 800-53 on a classified system. The system owner has deployed a Security Information and Event Management (SIEM) tool that collects logs from all servers and network devices. To meet the full requirement of SI-4, which of the following activities are also necessary? (Select TWO)

    Show answer details

    Correct answer: A, C

Create an account to continue.