ISC2 · CGRC
Validates expertise in information security governance, risk management, and compliance, covering security and privacy governance, risk management, compliance and audit, information system authorization, and continuous monitoring.
Practice Questions
850
≈ 6 practice exams
Duration
180 minutes
Passing Score
700/1000
Difficulty
ProfessionalLast Updated
Feb 2026
Use this CGRC practice exam to prepare for Certified in Governance, Risk and Compliance (CGRC) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 850 questions for ISC2 CGRC, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to patterns in your missed answers. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The Certified in Governance, Risk and Compliance (CGRC) is a professional-level certification offered by ISC2 that validates expertise in designing, implementing, and maintaining information security governance, risk, and compliance programs. Formerly known as the Certified Authorization Professional (CAP), it was officially rebranded as the CGRC on February 15, 2023, reflecting its broader applicability beyond U.S. federal authorization frameworks to enterprise GRC practices globally. The credential demonstrates a practitioner's ability to advocate for security risk management in pursuit of information system authorization in accordance with legal and regulatory requirements, spanning frameworks such as NIST RMF, COBIT, ISO/IEC standards, and FedRAMP.
The certification covers seven domains encompassing the full lifecycle of information system compliance: governance program establishment, system scoping, control selection and approval, control implementation, assessment and audit, system compliance authorization, and ongoing compliance maintenance. It is accredited by the ANSI National Accreditation Board (ANAB) under ISO/IEC Standard 17024, and is approved by the U.S. Department of Defense under DoDM 8140.03, making it a recognized credential in both private sector and federal government environments.
The CGRC is designed for IT, information security, and information assurance professionals who work in or aspire to governance, risk management, and compliance roles. Target job titles include cybersecurity auditors, compliance officers, GRC architects, GRC managers, risk and compliance project managers, enterprise risk managers, and information assurance managers. It is best suited for mid-career professionals who operate at the intersection of security and regulatory frameworks, particularly those who manage authorization processes or oversee compliance programs.
Candidates who do not yet meet the experience requirements but pass the exam may become an Associate of ISC2 while they accumulate the necessary work history. The certification is especially relevant for professionals working in or with U.S. federal agencies, defense contractors, or organizations subject to NIST-based compliance mandates, though its updated scope makes it equally applicable to global enterprises managing multi-framework compliance obligations.
Candidates must have a minimum of two cumulative years of paid work experience in one or more of the seven CGRC domains. There is no requirement that experience span all domains — depth in a single relevant domain such as risk management, compliance auditing, or security control assessment qualifies. No specific prior certification is required, though familiarity with foundational information security concepts, risk management principles, and regulatory frameworks (NIST SP 800-37, NIST SP 800-53, ISO/IEC 27001, FedRAMP) is strongly recommended as these underpin the entire CBK.
Candidates who pass the CGRC exam but lack the requisite experience may hold the Associate of ISC2 designation while working toward the two-year threshold. Practical exposure to system authorization or accreditation processes, security control selection and implementation, or compliance auditing in a professional environment significantly improves readiness for the exam.
The CGRC exam consists of 125 items delivered over 3 hours. Questions include both traditional multiple-choice and advanced item types, which may include drag-and-drop, hotspot, and other scenario-based formats designed to assess applied knowledge rather than rote memorization. The exam is administered through Pearson VUE at authorized testing centers and via online proctoring.
Scoring uses a scaled model with a maximum of 1,000 points, and the passing score is 700 out of 1,000. The exam does not use negative scoring. Candidates who fail may retake the exam; ISC2 enforces a mandatory 30-day waiting period after the first failed attempt, 90 days after the second, and 180 days after the third and any subsequent attempts.
The CGRC commands strong salary premiums in the cybersecurity market. According to Certification Magazine's Salary Survey 75, CGRC holders earn an average of $118,980 annually in the United States and $114,150 globally, positioning it among the higher-paying ISC2 credentials. The certification aligns directly with roles such as GRC analyst, compliance officer, information assurance manager, risk manager, and cybersecurity auditor — positions that are in sustained demand as organizations face expanding regulatory obligations under frameworks including CMMC, FedRAMP, HIPAA, and SOC 2.
The CGRC's DoD 8140.03 approval makes it particularly valuable for professionals pursuing or maintaining positions within U.S. federal agencies and defense contractors, where authorized practitioners are required by policy. The credential reached 5,000 worldwide holders in early 2026, reflecting growing global adoption beyond its federal roots. In the 2024 ISC2 Cybersecurity Workforce Study, GRC ranked among the top technical skills in demand at 13% — just behind risk assessment and management — signaling strong and sustained employer appetite for credentialed GRC practitioners.
5 sample questions with answers and explanations. The full bank has 850 questions, enough for 6 full-length practice exams.
Preview — answers shown1. A federal contractor must protect Controlled Unclassified Information (CUI) and comply with NIST SP 800-171 Rev 3 requirements. The contractor's compliance team reviews the updated publication released in May 2024. How many security requirements must the contractor address, and how many control families organize these requirements? (Select one!)
Explanation
NIST SP 800-171 Rev 3, finalized May 14, 2024, contains 97 security requirements organized into 17 control families. This represents a reduction from Rev 2's 110 requirements through elimination of redundant requirements, while expanding from 14 to 17 families by adding Planning, Program Management, and System and Services Acquisition families. The 150 requirement count corresponds to the Low baseline in SP 800-53B, not SP 800-171. The 110/14 combination was Rev 2, which is now superseded.
2. An organization operates 180 information systems across three impact levels: 45 Low-impact, 95 Moderate-impact, and 40 High-impact systems. The Risk Executive implements Task P-6 impact-level prioritization to focus limited assessment resources on the highest-risk systems within each tier. Task P-6 is identified in NIST SP 800-37 Rev 2 as having which characteristic? (Select one!)
Explanation
Task P-6 (Impact-Level Prioritization) is one of only two optional tasks in the entire 41-task NIST RMF framework, along with Task P-4 (Organizationally-Tailored Control Baselines and CSF Profiles). All other 39 tasks are mandatory. Task P-6 allows organizations to create prioritized lists of systems within each impact level to focus resources on highest-risk systems first, but this prioritization activity is not required. The task does not become mandatory based on impact level or number of systems operated. While prioritization is a best practice for large system portfolios, NIST explicitly designates P-6 as optional, giving organizations flexibility in how they allocate assessment and authorization resources.
3. During Task S-3 control allocation, a Security Architect must allocate IA-2 Identification and Authentication controls for a multi-tenant cloud-based case management system. The organization operates a centralized enterprise identity provider that handles authentication for all users across 50 systems. Individual systems must implement multi-factor authentication requirements specific to their sensitivity levels. How should IA-2 be allocated? (Select one!)
Explanation
Hybrid controls split responsibility between a common control provider and system owners. The common portion is inherited while the system-specific portion must be implemented locally. In this scenario, the centralized enterprise identity provider implements the base IA-2 authentication service (common portion) that all systems inherit. Individual systems implement their specific multi-factor authentication requirements, session management, and authentication strength policies (system-specific portion). A Shared Responsibility Matrix or Customer Responsibility Matrix documents this split. Hybrid controls are common for authentication, encryption, access control, and audit logging where enterprise infrastructure provides baseline capabilities while systems add specific requirements. This allocation model appears frequently on the CGRC exam and requires understanding how inheritance and local implementation interact. Pure common or system-specific allocations fail to capture the shared responsibility accurately.
4. A Control Assessor evaluates a cryptographic module used for protecting sensitive data in a High-impact national security system. The module uses AES-256 encryption but has not undergone validation through the Cryptographic Module Validation Program (CMVP). The System Owner claims the implementation is secure because it uses FIPS-approved algorithms. What should the assessor conclude regarding compliance with cryptographic requirements? (Select one!)
Explanation
FISMA requires federal agencies to use cryptographic modules validated under the FIPS 140 standard through the Cryptographic Module Validation Program (CMVP), a joint NIST and Canadian Centre for Cyber Security effort. Using FIPS-approved algorithms (like AES-256) is necessary but not sufficient; the entire cryptographic module including the algorithm implementation must be validated to ensure it correctly and securely implements the cryptography. Unvalidated cryptography is treated as effectively unprotected plaintext because implementation flaws, side-channel vulnerabilities, or key management weaknesses could completely compromise the encryption regardless of algorithm strength. FIPS 140-3 defines four security levels (Level 1 through Level 4), and the required level depends on the sensitivity and risk, not automatically Level 4 for High-impact systems. Compensating controls cannot substitute for CMVP validation when federal law and policy mandate validated modules. The System Owner must either use a validated module or obtain a formal waiver through appropriate channels.
5. A Security Control Assessor completes assessment of a High-impact command and control system and prepares the Security Assessment Report (SAR) for Task A-4. The assessment identified: 15 controls fully effective, 8 controls with minor implementation weaknesses not affecting effectiveness, 4 controls with significant deficiencies requiring remediation, and 2 controls implemented differently from the SSP but providing equivalent protection. How should the assessor document the 2 controls implemented differently? (Select one!)
Explanation
NIST SP 800-37 Rev 2 and ISC2 CGRC guidance establish that when controls are implemented differently from documented plans, even if providing equivalent or better protection, the discrepancy must be formally resolved by the Authorizing Official. The SSP is the authoritative baseline for control implementation. Any deviation, regardless of effectiveness, creates a documentation mismatch that the AO must adjudicate. The assessor cannot independently determine compliance for deviations. Marking them as compliant without formal resolution bypasses required governance. Marking them non-compliant may be inaccurate if protection is equivalent. The System Owner should update the SSP, but the AO must first formally accept the deviation.
Certified Cloud Security Professional (CCSP)
CCSP · 850 questions
Certified in Cybersecurity (CC)
CC · 838 questions
Certified Secure Software Lifecycle Professional (CSSLP)
CSSLP · 841 questions
Certified Information Systems Security Professional (CISSP)
CISSP · 850 questions
Information Systems Security Architecture Professional (ISSAP)
ISSAP · 850 questions
Information Systems Security Management Professional (ISSMP)
ISSMP · 833 questions
$17.99
One-time access to this exam