ISC2

Free ISC2 CGRC Practice Questions

The ISC2 CGRC exam is up to 125 questions in 180 minutes, and the voucher costs $599. CertCrush provides 400 syllabus-aligned practice questions and 20 performance-based questions across all 7 exam domains, each with a full explanation. Free to try, no account required.

CGRC is the ISC2 certification for governance, risk and compliance work, centred on authorizing and maintaining information systems inside a risk management framework. Its seven domains follow the authorization lifecycle: set the system scope, select and implement controls, assess them, reach an authorization decision, then keep that decision current as the system changes.

Practice content last updated · Independently written and aligned to ISC2’s published exam objectives.

10

Sample questions

180 min

Exam time limit

70%

Practice pass mark

$599

Exam voucher

About the ISC2 CGRC Exam

CGRC is the ISC2 certification for the people who decide whether a system is allowed to operate. ISC2 renamed it from Certified Authorization Professional (CAP) in February 2023, and the change was to the name alone: the exam and the qualifications behind it stayed as they were. The credential still centres on the authorization process that turns a set of implemented controls into a documented, accepted risk decision. The exam is 125 items in three hours, scored out of 1000 with 700 to pass. Seven domains follow the lifecycle of a system authorization. You categorise the system and fix its boundary, select and tailor a control framework, implement the controls, assess or audit them, assemble the evidence that supports an authorization decision, and then hold compliance together while the system changes underneath you. Implementation of Security and Privacy Controls carries the most weight at 17 percent. Scope of the System carries the least at 10 percent, which understates it: draw the boundary wrong and every control decision after it is aimed at the wrong system. CGRC is approved under U.S. DoDM 8140.03, which is why it appears in federal and defence contractor job requirements. Outside government it maps onto any role where someone has to prove to an auditor or a regulator that a control works, including compliance officer, risk and controls analyst, third party risk manager and GRC architect. ISC2 asks for two years of cumulative paid work experience in at least one domain. Pass without it and you hold Associate of ISC2 status while you earn the experience.

Exam Domains Covered

Security and Privacy Governance, Risk Management, and Compliance Program · 16%Scope of the System · 10%Selection and Approval of Framework, Security, and Privacy Controls · 14%Implementation of Security and Privacy Controls · 17%Assessment/Audit of Security and Privacy Controls · 16%System Compliance · 14%Compliance Maintenance · 13%

Exam Format & Details

125 items in 180 minutes, made up of multiple choice plus advanced item types. Scored on a scaled 1000-point range with 700 to pass, which the practice exams here present as 70 percent. Delivered in English at Pearson VUE test centres, U.S. $599 in the Americas. ISC2 asks for two years of cumulative paid work experience in at least one of the seven domains; candidates who pass without it hold Associate of ISC2 status while they accrue it.

Why Practice Questions Matter

CGRC questions rarely ask you to recall a definition. They drop you at a point in the authorization lifecycle and ask what happens next, or who signs it. The line between the system owner, the authorizing official and the control assessor is worth real marks, and it is the sort of distinction that feels obvious until four plausible roles are on the screen together. Working through questions is how you find out whether you know which artifact belongs to which step, or whether you have only been recognising the vocabulary. Every explanation here says why the near-miss answer fails, not just why the right one is right.

Back to home
Free Sample

Try ISC2 CGRC

Try 10 questions now. No account, no card.

A free account unlocks 25 questions per course plus readiness tracking.

Get full access to ISC2 CGRC

All questions, timed exams, flashcards, PDF study guide download & progress tracking.

This course

$9.99

one-time

Pass or refund
Create account and buy

30 seconds, then straight to checkout.

September only

Lifetime · all courses

$29.99

One payment · future courses included

Create account and buy

30 seconds, then straight to checkout.

PASS GUARANTEEOR MONEY BACK

Pass, or your money back

Reach 85% readiness on this course, sit the real exam, and if you don't pass we refund it in full. Applies to this single-course purchase. Terms.

Try 2 performance tasks free

Drag-and-drop, sequencing and configuration tasks that mirror the interactive questions on the real ISC2 CGRC exam, marked with partial credit.

Start free

Sample Practice Questions

The following questions are a preview of the type of syllabus-aligned questions you will practise in CertCrush. They reflect the format and reasoning style of the ISC2 CGRC exam, not actual exam content.

Q1.A program manager asks which document the Assess step is expected to produce before the authorization package can be assembled. What is the correct answer?

  • A.A FIPS 199 security category
  • B.A tailored control baseline
  • C.A Security Assessment Report
  • D.An authorization decision document

Domain: Security and Privacy Governance, Risk Management, and Compliance Program

Q2.A senior official has reviewed a complete package of evidence and made a formal, written determination about a system's remaining risk. Which artefact records that determination?

  • A.The Security Assessment Report
  • B.The continuous monitoring strategy
  • C.The system's System Security Plan
  • D.The authorization decision document

Domain: Security and Privacy Governance, Risk Management, and Compliance Program

Q3.Which Risk Management Framework step produces a system's FIPS 199 security category?

  • A.Categorize, which rates each information type
  • B.Select, which chooses a tailored control baseline
  • C.Assess, which tests the implemented controls
  • D.Implement, which builds the chosen controls

Domain: Security and Privacy Governance, Risk Management, and Compliance Program

Q4.An authorized system has been running in production for eight months. The team continues to collect evidence that the original risk decision still holds and updates its open weaknesses. Which step of the framework are they performing?

  • A.Assess, which tests controls and reports findings
  • B.Authorize, which ends in a signed risk decision
  • C.Monitor, which continues after authorization
  • D.Prepare, which sets roles and risk tolerance

Domain: Security and Privacy Governance, Risk Management, and Compliance Program

Q5.A new system owner wants to begin selecting controls immediately, but the organization has never documented how much risk it is willing to accept and has not formally named an authorizing official. What should happen first?

  • A.Apply the high impact baseline, since it is the most conservative available starting point
  • B.Ask the Common Control Provider to define the organization's risk tolerance for the system
  • C.Proceed with Select and let the Security Control Assessor determine the risk tolerance during Assess
  • D.Complete the organization-level Prepare tasks that assign roles and document risk tolerance

Domain: Security and Privacy Governance, Risk Management, and Compliance Program

Q6.How is an Authorization to Operate best described?

  • A.A named official's formal, time-bound decision that residual risk is acceptable
  • B.A technical certification that a system contains no exploitable vulnerabilities
  • C.A consensus statement issued by the security team once all findings are closed
  • D.A permanent designation that stays valid for the life of the system

Domain: Security and Privacy Governance, Risk Management, and Compliance Program

Q7.A vendor tells a prospective customer that its platform is "certified secure" because the platform holds an Authorization to Operate. Why is that claim wrong?

  • A.Authorizations are issued only to federal systems, so a commercial platform cannot hold one
  • B.Authorization is acceptance of documented residual risk, not a guarantee that the system is secure
  • C.A platform must hold a separate authorization from every customer's own authorizing official
  • D.Certification of security is granted separately by the Security Control Assessor, not the authorizing official

Domain: Security and Privacy Governance, Risk Management, and Compliance Program

Q8.A system owner argues that because the system already holds an authorization, no further risk decision will ever be needed. Which characteristic of an authorization contradicts that view?

  • A.It must be countersigned by the Security Control Assessor at the end of every quarter
  • B.It automatically converts to a denial of authorization after any configuration change
  • C.It carries a termination date and assumes conditions stay as they were
  • D.It applies only to the controls the assessor tested, leaving all others unauthorized

Domain: Security and Privacy Governance, Risk Management, and Compliance Program

Q9.A governance policy was published two years ago, but no system team can produce evidence that any part of it was ever followed. What does that situation illustrate about the three functions of a governance, risk and compliance program?

  • A.Governance is independent of compliance, so the policy remains fully effective
  • B.Compliance evidence is only required for systems rated high under FIPS 199
  • C.The absence of evidence converts the policy into a risk acceptance decision
  • D.A governance policy with no compliance evidence has no practical effect

Domain: Security and Privacy Governance, Risk Management, and Compliance Program

Q10.A system team has just finished rating how much harm a loss of confidentiality, integrity or availability would cause to its information. Which Risk Management Framework step do they move into next?

  • A.Implement, building the controls that were chosen
  • B.Select, choosing a baseline from the control catalog
  • C.Assess, testing the controls that were implemented
  • D.Authorize, signing the formal risk acceptance

Domain: Security and Privacy Governance, Risk Management, and Compliance Program

Frequently Asked Questions

Does the ISC2 CGRC course include performance-based questions?

Yes. The ISC2 CGRC course includes 20 performance-based questions (PBQs): hands-on tasks that mirror the interactive questions on the real exam, including drag-and-drop matching, sequencing and configuration screens. Each one is marked with partial credit, so you can see exactly which placements were wrong, and every task includes a full explanation. The first two are free to try.

What is included in the free ISC2 CGRC sample?

The free sample includes 10 syllabus-aligned practice questions, sample flashcards, and a preview chapter from the study guide. No account or payment is required to try the sample.

How many questions are in the full ISC2 CGRC course?

The full ISC2 CGRC course includes 400 practice questions and 20 performance-based tasks, covering all 7 exam domains. Every question carries a full explanation for the right answer and the wrong ones.

Are these official ISC2 exam questions?

No. CertCrush questions are independently written and syllabus-aligned. They mirror the format, difficulty, and reasoning style of the official exam. We are not affiliated with or endorsed by ISC2.

Which domains does the ISC2 CGRC course cover?

The course covers 7 exam domains: Security and Privacy Governance, Risk Management, and Compliance Program, Scope of the System, Selection and Approval of Framework, Security, and Privacy Controls, Implementation of Security and Privacy Controls, Assessment/Audit of Security and Privacy Controls, System Compliance, Compliance Maintenance.

Can I study on mobile?

Yes. CertCrush is fully responsive and works on phones, tablets, and desktops. The timed exam, flashcards, and study guide all work on mobile without installing an app.

What happens when I create an account?

Creating a free account lets you access full courses, track your weak areas by domain, and resume practice sessions across devices. No credit card is required to register.