ISC2 · CGRC
Validates expertise in information security governance, risk management, and compliance, covering security and privacy governance, risk management, compliance and audit, information system authorization, and continuous monitoring.
Practice Questions
850
≈ 6 practice exams
Duration
180 minutes
Passing Score
700/1000
Difficulty
ProfessionalLast Updated
Feb 2026
Use this CGRC practice exam to prepare for Certified in Governance, Risk and Compliance (CGRC) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 850 questions for ISC2 CGRC, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to patterns in your missed answers. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The Certified in Governance, Risk and Compliance (CGRC) is a professional-level certification offered by ISC2 that validates expertise in designing, implementing, and maintaining information security governance, risk, and compliance programs. Formerly known as the Certified Authorization Professional (CAP), it was officially rebranded as the CGRC on February 15, 2023, reflecting its broader applicability beyond U.S. federal authorization frameworks to enterprise GRC practices globally. The credential demonstrates a practitioner's ability to advocate for security risk management in pursuit of information system authorization in accordance with legal and regulatory requirements, spanning frameworks such as NIST RMF, COBIT, ISO/IEC standards, and FedRAMP.
The certification covers seven domains encompassing the full lifecycle of information system compliance: governance program establishment, system scoping, control selection and approval, control implementation, assessment and audit, system compliance authorization, and ongoing compliance maintenance. It is accredited by the ANSI National Accreditation Board (ANAB) under ISO/IEC Standard 17024, and is approved by the U.S. Department of Defense under DoDM 8140.03, making it a recognized credential in both private sector and federal government environments.
The CGRC is designed for IT, information security, and information assurance professionals who work in or aspire to governance, risk management, and compliance roles. Target job titles include cybersecurity auditors, compliance officers, GRC architects, GRC managers, risk and compliance project managers, enterprise risk managers, and information assurance managers. It is best suited for mid-career professionals who operate at the intersection of security and regulatory frameworks, particularly those who manage authorization processes or oversee compliance programs.
Candidates who do not yet meet the experience requirements but pass the exam may become an Associate of ISC2 while they accumulate the necessary work history. The certification is especially relevant for professionals working in or with U.S. federal agencies, defense contractors, or organizations subject to NIST-based compliance mandates, though its updated scope makes it equally applicable to global enterprises managing multi-framework compliance obligations.
Candidates must have a minimum of two cumulative years of paid work experience in one or more of the seven CGRC domains. There is no requirement that experience span all domains — depth in a single relevant domain such as risk management, compliance auditing, or security control assessment qualifies. No specific prior certification is required, though familiarity with foundational information security concepts, risk management principles, and regulatory frameworks (NIST SP 800-37, NIST SP 800-53, ISO/IEC 27001, FedRAMP) is strongly recommended as these underpin the entire CBK.
Candidates who pass the CGRC exam but lack the requisite experience may hold the Associate of ISC2 designation while working toward the two-year threshold. Practical exposure to system authorization or accreditation processes, security control selection and implementation, or compliance auditing in a professional environment significantly improves readiness for the exam.
The CGRC exam consists of 125 items delivered over 3 hours. Questions include both traditional multiple-choice and advanced item types, which may include drag-and-drop, hotspot, and other scenario-based formats designed to assess applied knowledge rather than rote memorization. The exam is administered through Pearson VUE at authorized testing centers and via online proctoring.
Scoring uses a scaled model with a maximum of 1,000 points, and the passing score is 700 out of 1,000. The exam does not use negative scoring. Candidates who fail may retake the exam; ISC2 enforces a mandatory 30-day waiting period after the first failed attempt, 90 days after the second, and 180 days after the third and any subsequent attempts.
The CGRC commands strong salary premiums in the cybersecurity market. According to Certification Magazine's Salary Survey 75, CGRC holders earn an average of $118,980 annually in the United States and $114,150 globally, positioning it among the higher-paying ISC2 credentials. The certification aligns directly with roles such as GRC analyst, compliance officer, information assurance manager, risk manager, and cybersecurity auditor — positions that are in sustained demand as organizations face expanding regulatory obligations under frameworks including CMMC, FedRAMP, HIPAA, and SOC 2.
The CGRC's DoD 8140.03 approval makes it particularly valuable for professionals pursuing or maintaining positions within U.S. federal agencies and defense contractors, where authorized practitioners are required by policy. The credential reached 5,000 worldwide holders in early 2026, reflecting growing global adoption beyond its federal roots. In the 2024 ISC2 Cybersecurity Workforce Study, GRC ranked among the top technical skills in demand at 13% — just behind risk assessment and management — signaling strong and sustained employer appetite for credentialed GRC practitioners.
5 sample questions with answers and explanations. The full bank has 850 questions, enough for 6 full-length practice exams.
Preview — answers shown1. A defense contractor implements Task P-16 enterprise architecture integration for a new supply chain management system that will interface with the Defense Logistics Agency (DLA) and store data in the contractor's existing on-premises data center. The enterprise architect identifies that the data center is certified to FIPS 140-2 Level 2 but DoD now requires FIPS 140-3 Level 2 cryptographic modules per updated policy. What should the security architect specify in Task P-17 requirements allocation? (Select one!)
Explanation
FIPS 140-3 replaced FIPS 140-2 as the current cryptographic module validation standard. When requirements change during system development, security architects must balance compliance with operational continuity. The appropriate allocation specifies FIPS 140-3 Level 2 for new implementations while allowing existing FIPS 140-2 modules to continue under CMVP transition guidance until they require replacement or recertification. Specifying only FIPS 140-2 would fail to meet current DoD requirements. Immediately requiring replacement of all existing validated modules would be cost-prohibitive and operationally disruptive. Specifying Level 3 (requiring tamper-resistance and identity-based authentication) exceeds stated requirements without justification. Even when connecting to agency systems using encryption, the contractor system must implement cryptographic protections for data at rest and for authentication functions per SC family controls.
2. An organization implements SP 800-30 Rev 1 risk assessment methodology. The risk assessor uses a semi-quantitative approach with 5x5 matrices for likelihood and impact. For a specific threat scenario, the assessor determines Likelihood: Very High (5) and Impact: Moderate (3), yielding Risk Score: 15. The Risk Executive questions whether qualitative labels can be directly multiplied to produce meaningful risk scores. What is the fundamental limitation with this approach? (Select one!)
Explanation
NIST SP 800-30 Rev 1 explicitly states that risk is determined as Risk = f(Likelihood, Impact), indicating risk is a function of likelihood and impact, not a simple arithmetic product. Risk relationships are not necessarily linear; doubling likelihood or impact does not necessarily double risk. Organizations must define the risk determination function based on their risk model. Simple multiplication of scale values (5 × 3 = 15) imposes a mathematical relationship that may not reflect organizational risk tolerance or the actual nature of risk aggregation. Semi-quantitative approaches use scales with numerical anchors but do not require conversion before applying the risk function. The 5x5 matrix can be used in semi-quantitative approaches if properly defined. Independent assessment reduces bias but does not address the fundamental mathematical issue.
3. A Risk Executive is establishing Task P-5 common control identification for the enterprise. The organization operates data centers in three geographic regions, each with distinct physical security implementations due to local building designs. Which approach for PE-3 (Physical Access Control) is MOST appropriate? (Select one!)
Explanation
Creating three separate common controls, one per data center with individual authorizations, is most appropriate per NIST SP 800-53 guidance. While PE-3 is typically a common control candidate, the distinct physical implementations across three data centers with different building designs mean they cannot be treated as a single homogeneous control. Each data center should be assessed and authorized independently as a common control at its location, allowing systems in each region to inherit from their respective data center authorization. Designating as a single enterprise common control falsely implies uniform implementation when material differences exist. System-specific designation eliminates the inheritance benefit for multiple systems per location. Hybrid designation incorrectly suggests systems must implement portions of physical access control, when data center physical controls are entirely provided by the facilities team.
4. A multinational corporation subject to GDPR, HIPAA, and PCI-DSS requirements implements a governance framework to align technology investments with organizational strategy while meeting multiple regulatory obligations. The Chief Information Officer wants to select a framework that provides process-based IT governance with enterprise risk management integration and control objectives mappable to multiple compliance requirements. Which framework should the CIO select as the primary governance structure? (Select one!)
Explanation
COBIT is specifically designed for process-based IT governance with enterprise risk management integration and provides control objectives that can map to multiple frameworks and compliance requirements. COBIT focuses on aligning technology with business strategy and provides governance oversight. NIST RMF is mandatory for U.S. federal agencies and focuses on authorization lifecycle, not broad IT governance. ISO 27001 provides an information security management system with certification but is less focused on IT governance alignment with business strategy. NIST CSF provides a voluntary risk management approach but lacks the comprehensive IT governance and business alignment structure of COBIT.
5. A Risk Executive conducts Task P-3 (Risk Assessment—Organization) to establish enterprise-level risk context before system-specific RMF activities begin. The assessment identifies five organization-wide threat scenarios with varying likelihoods and impacts. For the threat of ransomware affecting enterprise file services, the risk team determines: Likelihood = High (adversary capability is high, intent is confirmed through threat intelligence, targeting is opportunistic), Impact = Moderate (significant operational disruption for 3-5 days, financial impact of $400K-$800K, no loss of life). Using NIST SP 800-30 Rev 1 risk determination methodology, how should this risk level be expressed and what is the primary purpose of completing this organization-level risk assessment? (Select one!)
Explanation
Per NIST SP 800-30 Rev 1, risk is determined as a function of likelihood and impact: Risk = f(Likelihood, Impact). Using a typical 5x5 risk matrix, High likelihood combined with Moderate impact generally produces an overall risk level of High or Medium-High (depending on organizational scaling). Task P-3 is an organization-level Prepare step task that establishes the risk context for the entire RMF process before system-specific activities begin. The organization-wide risk assessment informs: the risk management strategy (Task P-2), identification and prioritization of common controls (Task P-5), development of organizationally-tailored control baselines (Task P-4), and continuous monitoring strategy (Task P-7). This assessment does not directly determine authorization priorities for individual systems or mandate specific baselines. System categorization per FIPS 199 remains the driver for baseline selection. The organization-level risk assessment provides shared threat and vulnerability context that system owners incorporate into their system-level risk assessments (Task P-14) rather than being included in Security Assessment Reports, which document control assessment findings.
Certified Cloud Security Professional (CCSP)
CCSP · 850 questions
Certified in Cybersecurity (CC)
CC · 838 questions
Certified Secure Software Lifecycle Professional (CSSLP)
CSSLP · 841 questions
Certified Information Systems Security Professional (CISSP)
CISSP · 850 questions
Information Systems Security Architecture Professional (ISSAP)
ISSAP · 850 questions
Information Systems Security Management Professional (ISSMP)
ISSMP · 833 questions
$17.99
One-time access to this exam