ISC2 · CGRC
Validates expertise in information security governance, risk management, and compliance, covering security and privacy governance, risk management, compliance and audit, information system authorization, and continuous monitoring.
Practice Questions
850
≈ 6 practice exams
Duration
180 minutes
Passing Score
700/1000
Difficulty
ProfessionalLast Updated
Feb 2026
Use this CGRC practice exam to prepare for Certified in Governance, Risk and Compliance (CGRC) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 850 questions for ISC2 CGRC, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to patterns in your missed answers. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The Certified in Governance, Risk and Compliance (CGRC) is a professional-level certification offered by ISC2 that validates expertise in designing, implementing, and maintaining information security governance, risk, and compliance programs. Formerly known as the Certified Authorization Professional (CAP), it was officially rebranded as the CGRC on February 15, 2023, reflecting its broader applicability beyond U.S. federal authorization frameworks to enterprise GRC practices globally. The credential demonstrates a practitioner's ability to advocate for security risk management in pursuit of information system authorization in accordance with legal and regulatory requirements, spanning frameworks such as NIST RMF, COBIT, ISO/IEC standards, and FedRAMP.
The certification covers seven domains encompassing the full lifecycle of information system compliance: governance program establishment, system scoping, control selection and approval, control implementation, assessment and audit, system compliance authorization, and ongoing compliance maintenance. It is accredited by the ANSI National Accreditation Board (ANAB) under ISO/IEC Standard 17024, and is approved by the U.S. Department of Defense under DoDM 8140.03, making it a recognized credential in both private sector and federal government environments.
The CGRC is designed for IT, information security, and information assurance professionals who work in or aspire to governance, risk management, and compliance roles. Target job titles include cybersecurity auditors, compliance officers, GRC architects, GRC managers, risk and compliance project managers, enterprise risk managers, and information assurance managers. It is best suited for mid-career professionals who operate at the intersection of security and regulatory frameworks, particularly those who manage authorization processes or oversee compliance programs.
Candidates who do not yet meet the experience requirements but pass the exam may become an Associate of ISC2 while they accumulate the necessary work history. The certification is especially relevant for professionals working in or with U.S. federal agencies, defense contractors, or organizations subject to NIST-based compliance mandates, though its updated scope makes it equally applicable to global enterprises managing multi-framework compliance obligations.
Candidates must have a minimum of two cumulative years of paid work experience in one or more of the seven CGRC domains. There is no requirement that experience span all domains — depth in a single relevant domain such as risk management, compliance auditing, or security control assessment qualifies. No specific prior certification is required, though familiarity with foundational information security concepts, risk management principles, and regulatory frameworks (NIST SP 800-37, NIST SP 800-53, ISO/IEC 27001, FedRAMP) is strongly recommended as these underpin the entire CBK.
Candidates who pass the CGRC exam but lack the requisite experience may hold the Associate of ISC2 designation while working toward the two-year threshold. Practical exposure to system authorization or accreditation processes, security control selection and implementation, or compliance auditing in a professional environment significantly improves readiness for the exam.
The CGRC exam consists of 125 items delivered over 3 hours. Questions include both traditional multiple-choice and advanced item types, which may include drag-and-drop, hotspot, and other scenario-based formats designed to assess applied knowledge rather than rote memorization. The exam is administered through Pearson VUE at authorized testing centers and via online proctoring.
Scoring uses a scaled model with a maximum of 1,000 points, and the passing score is 700 out of 1,000. The exam does not use negative scoring. Candidates who fail may retake the exam; ISC2 enforces a mandatory 30-day waiting period after the first failed attempt, 90 days after the second, and 180 days after the third and any subsequent attempts.
The CGRC commands strong salary premiums in the cybersecurity market. According to Certification Magazine's Salary Survey 75, CGRC holders earn an average of $118,980 annually in the United States and $114,150 globally, positioning it among the higher-paying ISC2 credentials. The certification aligns directly with roles such as GRC analyst, compliance officer, information assurance manager, risk manager, and cybersecurity auditor — positions that are in sustained demand as organizations face expanding regulatory obligations under frameworks including CMMC, FedRAMP, HIPAA, and SOC 2.
The CGRC's DoD 8140.03 approval makes it particularly valuable for professionals pursuing or maintaining positions within U.S. federal agencies and defense contractors, where authorized practitioners are required by policy. The credential reached 5,000 worldwide holders in early 2026, reflecting growing global adoption beyond its federal roots. In the 2024 ISC2 Cybersecurity Workforce Study, GRC ranked among the top technical skills in demand at 13% — just behind risk assessment and management — signaling strong and sustained employer appetite for credentialed GRC practitioners.
5 sample questions with answers and explanations. The full bank has 850 questions, enough for 6 full-length practice exams.
Preview — answers shown1. An organization implements NIST Cybersecurity Framework 2.0 (February 2024) alongside mandatory RMF processes for federal compliance. A CISO maps CSF subcategories to RMF tasks as documented in SP 800-37 Rev 2. Which CSF 2.0 core function was newly added and focuses on cybersecurity governance and risk management strategy? (Select one!)
Explanation
Govern is the new core function added in CSF 2.0, released February 2024. It focuses on establishing and monitoring the organization's cybersecurity risk management strategy, expectations, and policy, providing governance context for the other functions. The original CSF 1.0 (2014) had five functions: Identify, Protect, Detect, Respond, and Recover. Govern was added to CSF 2.0 to emphasize that cybersecurity is fundamentally an enterprise risk management issue requiring C-suite and board-level governance. SP 800-37 Rev 2 maps CSF subcategories to RMF tasks, showing how CSF provides communication language while RMF provides execution methodology.
2. A Chief Information Officer establishes enterprise-wide information security responsibilities under FISMA requirements. The CIO delegates day-to-day security program management to a designated official. Which official typically receives this delegated authority from the CIO? (Select one!)
Explanation
The Senior Agency Information Security Officer (SAISO), also known as the Chief Information Security Officer (CISO), is designated by the CIO to carry out the CIO's security responsibilities under FISMA. The SAISO serves as the primary liaison between the CIO and authorizing officials, system owners, and common control providers, handling day-to-day security program operations. The Authorizing Official accepts risk for specific systems and reports to senior leadership but is not under the CIO's direct delegation. The ISSO manages security for individual systems, not enterprise-wide programs. The Risk Executive Function provides organization-wide risk oversight but operates independently of CIO delegation.
3. An organization implements Task P-4 to develop organizationally-tailored control baselines aligned with the NIST Cybersecurity Framework. The CISO notes that Task P-4 is marked as optional in NIST SP 800-37 Rev 2. Which other Prepare task is also designated as optional? (Select one!)
Explanation
Only two tasks in the entire RMF are designated as optional: Task P-4 (Organizationally-Tailored Control Baselines and CSF Profiles) and Task P-6 (Impact-Level Prioritization). All other 39 tasks are mandatory. Task P-6 involves creating a prioritized list of systems within each impact level to guide resource allocation, which some organizations may not need if they have alternative prioritization mechanisms. Task P-1 (role assignment) is mandatory for establishing governance. Task P-7 (ISCM strategy) is mandatory for all organizations. Task P-18 (system registration) is mandatory to maintain system inventory and tracking.
4. An organization implements NIST SP 800-137 Information Security Continuous Monitoring across all three tiers defined in SP 800-39. The Risk Executive asks which tier is responsible for establishing risk tolerance and making strategic risk decisions. Which tier fulfills this responsibility? (Select one!)
Explanation
Tier 1 operates at the organization level and establishes governance structures, risk tolerance, and strategic risk decisions that flow down to lower tiers. Tier 2 focuses on mission/business process architecture and translates organizational risk decisions into mission-specific requirements. Tier 3 implements operational controls at the information system level. While risk management operates across all tiers with bidirectional communication, strategic governance and risk tolerance establishment are Tier 1 responsibilities.
5. A federal agency's Chief Information Officer is establishing the organization's first formal risk management program under FISMA requirements. According to NIST SP 800-37 Rev 2, which Prepare step task must the CIO complete to designate the Senior Agency Information Security Officer? (Select one!)
Explanation
Task P-1 establishes risk management roles across the organization, including the CIO's designation of the SAISO. This is an organization-level Prepare task with the CIO as the primary responsible role. Task P-2 develops the risk management strategy after roles are assigned. Task P-7 addresses continuous monitoring strategy development, which occurs after role assignment. Task P-18 is a system-level task for registering individual systems, not establishing organizational roles.
Certified Cloud Security Professional (CCSP)
CCSP · 850 questions
Certified in Cybersecurity (CC)
CC · 838 questions
Certified Secure Software Lifecycle Professional (CSSLP)
CSSLP · 841 questions
Certified Information Systems Security Professional (CISSP)
CISSP · 850 questions
Information Systems Security Architecture Professional (ISSAP)
ISSAP · 850 questions
Information Systems Security Management Professional (ISSMP)
ISSMP · 833 questions
$17.99
One-time access to this exam