ISC2Free

CGRC Free Practice Questions

This practice bank exercises foundational knowledge in risk assessment, security controls, governance frameworks, and compliance. Learners must identify primary purposes of risk assessments, differentiate preventive, detective, and corrective controls, and apply principles like least privilege. Key decisions involve understanding data owner responsibilities, recognizing governance functions such as Identify, and recalling core concepts like the CIA triad. The questions also test awareness of configuration auditing, security policy, continuous monitoring, and security metrics. Mastery of these topics supports effective governance, risk management, and compliance (GRC) practices required for the CGRC certification.

15
practice questions
20
recall cards
15
explanations
0
sign-ups required
Exam-focused analysis

What this CGRC practice set measures

This is an analysis of the practice bank, not a claim about the vendor's live exam blueprint. Use it to identify the knowledge, judgment, and recall patterns exercised here, then verify your coverage against the current official exam guide.

Risk Assessment and Management

Risk assessment is central to information security, enabling organizations to identify and prioritize threats and vulnerabilities. The practice bank emphasizes that risk assessments provide a basis for informed security investment decisions. Recognizing the primary purpose—identifying and prioritizing potential threats and vulnerabilities—is critical. This understanding aligns with the Identify function of governance frameworks, which defines strategic objectives and risk appetite. Learners must grasp that risk assessment informs resource allocation and security strategy.

  • Risk assessments prioritize threats and vulnerabilities based on likelihood and impact.
  • They guide decisions on security investments and resource allocation.
  • The Identify function establishes organizational context and risk appetite.
  • Effective risk management relies on accurate and ongoing assessments.

Security Controls and Principles

Security controls are categorized as preventive, detective, or corrective. Preventive controls (e.g., access controls, training) aim to stop incidents before they occur. Detective controls (e.g., IDS) identify incidents after the fact. Corrective controls restore systems post-event. The principle of least privilege grants users only the minimum access needed, reducing misuse risk. Data integrity is ensured through checksums and digital signatures. Understanding these distinctions and principles is essential for designing and evaluating security architectures.

  • Preventive controls stop unwanted actions; detective controls identify them after.
  • Least privilege minimizes access to reduce accidental or malicious misuse.
  • Checksums and digital signatures verify data accuracy and detect tampering.
  • Intrusion Detection Systems (IDS) are classic detective controls.

Governance and Compliance

A security governance framework provides clear accountability and decision-making structures. Key roles include data owners, who classify data and define protection requirements. Compliance with regulations necessitates specific mandated practices and reporting. Security policies are high-level statements of intent, while procedures and standards provide detailed guidance. The Identify function within governance frameworks defines strategic objectives and risk appetite. Effective governance ensures consistent security practices and regulatory adherence.

  • Data owners are accountable for classification and protection of information.
  • Regulatory compliance requires following mandated controls and reporting.
  • Security policies set strategic direction; procedures implement details.
  • Governance frameworks clarify roles, responsibilities, and decision-making.

Monitoring and Metrics

Continuous monitoring detects and responds to security events in real time, supporting timely risk management. Configuration auditing compares system setups against benchmarks to identify risky deviations. Security metrics measure the effectiveness and efficiency of security processes, helping leadership gauge performance. Security awareness training educates users to reduce human-related incidents like phishing. These activities form a feedback loop for ongoing improvement and risk reduction.

  • Continuous monitoring enables real-time detection and response to events.
  • Configuration auditing verifies systems against secure benchmarks.
  • Metrics quantify security process effectiveness for leadership.
  • Security awareness training reduces human error and phishing success.
Active recall deck

Practice CGRC with real flashcards

Read the prompt, commit to an answer, then flip the card. Move through the deck at your own pace and repeat any topic that does not come back quickly.

20 free cards

Card 1 of 20

1 reviewed this session

Static practice bank

Start the 15-question diagnostic

The complete question bank is embedded in this pre-rendered page. There is no database request or second content download when you begin.

Question 1 of 15

What is the primary purpose of a risk assessment in an information security program?

Show hint

Identify the purpose and value of risk assessments.

1 correct answers

Study workflow

Turn one CGRC attempt into a study plan

  1. 1

    Perform a Risk Assessment

    Identify assets, threats, and vulnerabilities. Assess likelihood and impact for each risk. Prioritize based on risk appetite defined by leadership. Document findings and recommended controls. Use the assessment to guide resource allocation and security planning.

  2. 2

    Implement Least Privilege

    Define job roles and required access. Grant only necessary permissions for each role. Regularly review and revoke excessive rights. Use tools like role-based access control (RBAC) to enforce policies. Monitor for unauthorized privilege escalation.

  3. 3

    Establish a Governance Framework

    Define strategic objectives and risk appetite. Assign data owners and security roles. Develop policies, standards, and procedures. Create a reporting structure for accountability. Regularly review and update governance documents.

  4. 4

    Conduct Configuration Auditing

    Select baseline benchmarks (e.g., CIS, NIST). Scan systems against benchmarks to find deviations. Prioritize and remediate critical non-compliance. Automate auditing where possible. Document and report results to management.

  5. 5

    Develop Security Metrics

    Identify key performance indicators (KPIs) aligned with goals. Collect data on incidents, patching, training completion. Analyze trends and present to stakeholders. Use metrics to drive improvement. Review and adjust metrics periodically for relevance.

FAQ

Questions about this exam practice page

Clear boundaries on what the bank covers, how to use it, and where official vendor information still matters.

What is the primary purpose of a risk assessment in the CGRC context?+

In CGRC, risk assessment identifies and prioritizes threats and vulnerabilities to inform security investments and align with governance and risk appetite, as emphasized in the practice bank.

What is the difference between preventive and detective controls?+

Preventive controls stop incidents before they occur (e.g., firewalls, training). Detective controls identify incidents after they happen (e.g., IDS, alarms). Both are essential for security.

What is the role of a data owner in security governance?+

Data owners classify data and define protection requirements. They are accountable for the integrity and appropriate use of information, though technical tasks may be delegated to security teams.

How does continuous monitoring support risk management?+

Continuous monitoring detects and responds to security events in real time, enabling timely risk treatment. It is a key component of ongoing governance and compliance.

What is the CIA triad and why is it foundational?+

The CIA triad stands for Confidentiality, Integrity, and Availability. It provides the core objectives for protecting information and systems, guiding security control selection and governance.

Keep studying

Build the next review session

Browse another free bank or use the study strategy guide to turn your misses into spaced review.