Certified in Governance, Risk, and Compliance (CGRC) Free Sample Questions

20 free sample questions225 in the full practice test

Try simulator

CGRC Sample Questions

  1. Question 1

    A federal agency is preparing a new data analytics platform for authorization. The platform will process publicly available datasets as well as sensitive citizen PII. The development team has proposed a system boundary that includes the cloud-based data lake and processing engines, but excludes the on-premises data ingestion servers that perform initial data cleansing. According to NIST SP 800-37 R2, what is the primary risk of this proposed boundary definition?

    Answer and explanation

    Correct answer: D

    The authorization boundary must encompass all components essential for the system's mission. By excluding the on-premises ingestion servers, which are integral to the data processing workflow, the agency creates a significant gap in its risk assessment. Vulnerabilities in these excluded servers could be exploited to compromise the data's integrity or confidentiality before it even reaches the assessed and authorized cloud environment. This introduces unmanaged risk, undermining the entire authorization effort.

  2. Question 2

    A healthcare provider is implementing a continuous monitoring program for its Electronic Health Record (EHR) system, which has a High impact categorization. The current strategy involves monthly vulnerability scans, quarterly access reviews, and annual penetration tests. A GRC analyst notes that while these activities are performed, the results are only reviewed during the annual assessment cycle. Which RMF step is being inadequately addressed in this scenario?

    Answer and explanation

    Correct answer: C

    According to NIST SP 800-137, a key part of the 'Monitor' step is not just collecting security data but analyzing and responding to it to maintain a current understanding of security posture. The scenario describes data collection (scans, reviews) but fails to incorporate ongoing analysis and response. Delaying the review of findings until the annual assessment defeats the purpose of continuous monitoring, which is to enable timely risk-based decisions. The process lacks the 'Analyze and Report' and 'Respond' functions of a mature monitoring program.

  3. Question 3

    Multiple answers

    A defense contractor is implementing the SI-4 (Information System Monitoring) control from NIST SP 800-53 on a classified system. The system owner has deployed a Security Information and Event Management (SIEM) tool that collects logs from all servers and network devices. To meet the full requirement of SI-4, which of the following activities are also necessary? (Select TWO)

    Answer and explanation

    Correct answers: A, C

  4. Question 4

    True or False: During the 'Select' step of the RMF, an organization is permitted to tailor a High baseline down to a Moderate baseline if the System Owner determines the cost of implementation is too high.

    Answer and explanation

    Correct answer: B

    This statement is false. The selection of a control baseline (Low, Moderate, High) is directly driven by the FIPS 199 security categorization of the system. An organization cannot change the baseline itself due to cost. Tailoring allows for the modification or removal of specific controls within the selected baseline, provided there is a sound risk-based justification. However, the fundamental baseline corresponding to the system's impact level must be used as the starting point.

  5. Question 5

    A financial services company, FinSecure, is preparing for its first formal authorization of a new cloud-native wealth management platform. The platform handles sensitive client financial data and PII, and has been categorized as High impact for confidentiality and integrity, and Moderate for availability. The company has a mature GRC program but has never applied the NIST RMF before.

    The Chief Risk Officer (CRO) has tasked the ISSM with establishing the foundational elements for the RMF process within the organization. The development teams are eager to start implementing controls, but the ISSM insists that several organization-level activities must be completed first as part of the RMF 'Prepare' step.

    Which of the following actions represents the MOST critical organization-level task FinSecure must complete before proceeding to system-specific control selection and implementation?

    Answer and explanation

    Correct answer: C

    The RMF 'Prepare' step begins at the organization level. Before any system-specific activities can be effectively carried out, the organization must establish its overarching risk management strategy. This includes defining risk tolerance, identifying common controls, and establishing the roles and responsibilities for risk management. This strategic foundation guides all subsequent RMF steps for all systems, including the wealth management platform. System registration and SSP development are system-level tasks that follow the establishment of this organizational strategy. Assessing common controls is part of the strategy but is not the strategy itself.

  6. Question 6

    A Security Control Assessor is reviewing the implementation of control AU-5 (Response to Audit Processing Failures) for a critical patient records database. The documentation in the SSP states: "In the event of an audit failure, the system will automatically shut down to prevent further activity." The assessor finds that while this mechanism is implemented, there is no procedure for alerting administrators about the shutdown. Which assessment finding is most accurate?

    Answer and explanation

    Correct answer: C

    NIST SP 800-53, control AU-5, explicitly requires the system to "Alert designated organizational officials in the event of an audit processing failure." The implemented solution of shutting down the system addresses part of the potential response, but without the required alerting mechanism, the control is not fully satisfied. A silent failure could lead to a prolonged, unnoticed outage. The conflict with availability is a separate risk consideration, but the direct reason the control is not satisfied is the missing alert function.

  7. Question 7

    An organization is preparing an Authorization to Operate (ATO) package for the Authorizing Official (AO). The package includes the System Security Plan (SSP), the Security Assessment Report (SAR), and the Plan of Action and Milestones (POA&M). The SAR identifies 5 High, 12 Moderate, and 20 Low findings. The POA&M details a remediation plan for all High and Moderate findings within 180 days. What is the primary purpose of including the POA&M in this package?

    Answer and explanation

    Correct answer: B

    The POA&M is a critical document for risk management. Its inclusion in the authorization package acknowledges that the system is not perfect but demonstrates a formal plan to systematically address and mitigate identified weaknesses over time. This allows the Authorizing Official to understand the current residual risk and the organization's commitment to reducing it, enabling an informed, risk-based decision on whether to grant an ATO.

  8. Question 8

    A system categorized as Moderate-Moderate-Moderate is being deployed. The ISSO is reviewing the draft System Security Plan (SSP) and notes that the development team has decided not to implement several applicable controls from the Moderate baseline, citing 'operational constraints'. However, no alternative or compensating controls are documented. What should be the ISSO's immediate next step?

    Answer and explanation

    Correct answer: C

    The RMF process allows for tailoring, but it must be a deliberate, risk-based process. Simply omitting controls due to 'operational constraints' without analysis is unacceptable. The correct procedure is for the system owner to provide a formal justification for why a baseline control is not applicable or cannot be implemented, assess the residual risk, and propose compensating controls that provide an equivalent level of security. The ISSO's role is to enforce this process before the SSP is considered complete.

  9. Question 9

    A university is developing a research portal that will handle controlled unclassified information (CUI) from a federal grant. According to FIPS 199, the potential impact of a loss of confidentiality is assessed as Moderate, loss of integrity as Moderate, and loss of availability as Low. What is the final security categorization for this system?

    Answer and explanation

    Correct answer: B

    FIPS 199 mandates the use of the 'high water mark' principle for determining the overall system categorization. The final categorization is the highest impact level assigned to any of the three security objectives (Confidentiality, Integrity, Availability). In this case, the impact levels are {Confidentiality: Moderate, Integrity: Moderate, Availability: Low}. The highest impact level is Moderate, so the overall system categorization is Moderate.

  10. Question 10

    After a system receives its ATO, a critical vulnerability is discovered in a core software component. The system owner performs a security impact analysis and determines the change to patch the vulnerability is 'significant'. According to the RMF, what is the most likely consequence of this determination?

    Answer and explanation

    Correct answer: B

    A determination that a change has a 'significant' impact on the security posture of an authorized system is a primary trigger for re-authorization. This means the change is substantial enough to potentially invalidate the previous risk assessment and authorization decision. The system will likely need to go through the Assess and Authorize steps of the RMF again, focusing on the changes but often requiring a comprehensive re-assessment before a new ATO can be issued.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 225 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon