ISC2
Free ISC2 CGRC Practice Questions
The ISC2 CGRC exam is up to 125 questions in 180 minutes, and the voucher costs $599. CertCrush provides 400 syllabus-aligned practice questions and 20 performance-based questions across all 7 exam domains, each with a full explanation. Free to try, no account required.
CGRC is the ISC2 certification for governance, risk and compliance work, centred on authorizing and maintaining information systems inside a risk management framework. Its seven domains follow the authorization lifecycle: set the system scope, select and implement controls, assess them, reach an authorization decision, then keep that decision current as the system changes.
Practice content last updated · Independently written and aligned to ISC2’s published exam objectives.
10
Sample questions
180 min
Exam time limit
70%
Practice pass mark
$599
Exam voucher
About the ISC2 CGRC Exam
CGRC is the ISC2 certification for the people who decide whether a system is allowed to operate. ISC2 renamed it from Certified Authorization Professional (CAP) in February 2023, and the change was to the name alone: the exam and the qualifications behind it stayed as they were. The credential still centres on the authorization process that turns a set of implemented controls into a documented, accepted risk decision. The exam is 125 items in three hours, scored out of 1000 with 700 to pass. Seven domains follow the lifecycle of a system authorization. You categorise the system and fix its boundary, select and tailor a control framework, implement the controls, assess or audit them, assemble the evidence that supports an authorization decision, and then hold compliance together while the system changes underneath you. Implementation of Security and Privacy Controls carries the most weight at 17 percent. Scope of the System carries the least at 10 percent, which understates it: draw the boundary wrong and every control decision after it is aimed at the wrong system. CGRC is approved under U.S. DoDM 8140.03, which is why it appears in federal and defence contractor job requirements. Outside government it maps onto any role where someone has to prove to an auditor or a regulator that a control works, including compliance officer, risk and controls analyst, third party risk manager and GRC architect. ISC2 asks for two years of cumulative paid work experience in at least one domain. Pass without it and you hold Associate of ISC2 status while you earn the experience.
Exam Domains Covered
Exam Format & Details
125 items in 180 minutes, made up of multiple choice plus advanced item types. Scored on a scaled 1000-point range with 700 to pass, which the practice exams here present as 70 percent. Delivered in English at Pearson VUE test centres, U.S. $599 in the Americas. ISC2 asks for two years of cumulative paid work experience in at least one of the seven domains; candidates who pass without it hold Associate of ISC2 status while they accrue it.
Why Practice Questions Matter
CGRC questions rarely ask you to recall a definition. They drop you at a point in the authorization lifecycle and ask what happens next, or who signs it. The line between the system owner, the authorizing official and the control assessor is worth real marks, and it is the sort of distinction that feels obvious until four plausible roles are on the screen together. Working through questions is how you find out whether you know which artifact belongs to which step, or whether you have only been recognising the vocabulary. Every explanation here says why the near-miss answer fails, not just why the right one is right.
Try ISC2 CGRC
Try 10 questions now. No account, no card.
A free account unlocks 25 questions per course plus readiness tracking.
Get full access to ISC2 CGRC
All questions, timed exams, flashcards, PDF study guide download & progress tracking.
Lifetime · all courses
$29.99
One payment · future courses included
30 seconds, then straight to checkout.
Pass, or your money back
Reach 85% readiness on this course, sit the real exam, and if you don't pass we refund it in full. Applies to this single-course purchase. Terms.
Try 2 performance tasks free
Drag-and-drop, sequencing and configuration tasks that mirror the interactive questions on the real ISC2 CGRC exam, marked with partial credit.
Sample Practice Questions
The following questions are a preview of the type of syllabus-aligned questions you will practise in CertCrush. They reflect the format and reasoning style of the ISC2 CGRC exam, not actual exam content.
Q1.A program manager asks which document the Assess step is expected to produce before the authorization package can be assembled. What is the correct answer?
- A.A FIPS 199 security category
- B.A tailored control baseline
- C.A Security Assessment Report
- D.An authorization decision document
Domain: Security and Privacy Governance, Risk Management, and Compliance Program
Q2.A senior official has reviewed a complete package of evidence and made a formal, written determination about a system's remaining risk. Which artefact records that determination?
- A.The Security Assessment Report
- B.The continuous monitoring strategy
- C.The system's System Security Plan
- D.The authorization decision document
Domain: Security and Privacy Governance, Risk Management, and Compliance Program
Q3.Which Risk Management Framework step produces a system's FIPS 199 security category?
- A.Categorize, which rates each information type
- B.Select, which chooses a tailored control baseline
- C.Assess, which tests the implemented controls
- D.Implement, which builds the chosen controls
Domain: Security and Privacy Governance, Risk Management, and Compliance Program
Q4.An authorized system has been running in production for eight months. The team continues to collect evidence that the original risk decision still holds and updates its open weaknesses. Which step of the framework are they performing?
- A.Assess, which tests controls and reports findings
- B.Authorize, which ends in a signed risk decision
- C.Monitor, which continues after authorization
- D.Prepare, which sets roles and risk tolerance
Domain: Security and Privacy Governance, Risk Management, and Compliance Program
Q5.A new system owner wants to begin selecting controls immediately, but the organization has never documented how much risk it is willing to accept and has not formally named an authorizing official. What should happen first?
- A.Apply the high impact baseline, since it is the most conservative available starting point
- B.Ask the Common Control Provider to define the organization's risk tolerance for the system
- C.Proceed with Select and let the Security Control Assessor determine the risk tolerance during Assess
- D.Complete the organization-level Prepare tasks that assign roles and document risk tolerance
Domain: Security and Privacy Governance, Risk Management, and Compliance Program
Q6.How is an Authorization to Operate best described?
- A.A named official's formal, time-bound decision that residual risk is acceptable
- B.A technical certification that a system contains no exploitable vulnerabilities
- C.A consensus statement issued by the security team once all findings are closed
- D.A permanent designation that stays valid for the life of the system
Domain: Security and Privacy Governance, Risk Management, and Compliance Program
Q7.A vendor tells a prospective customer that its platform is "certified secure" because the platform holds an Authorization to Operate. Why is that claim wrong?
- A.Authorizations are issued only to federal systems, so a commercial platform cannot hold one
- B.Authorization is acceptance of documented residual risk, not a guarantee that the system is secure
- C.A platform must hold a separate authorization from every customer's own authorizing official
- D.Certification of security is granted separately by the Security Control Assessor, not the authorizing official
Domain: Security and Privacy Governance, Risk Management, and Compliance Program
Q8.A system owner argues that because the system already holds an authorization, no further risk decision will ever be needed. Which characteristic of an authorization contradicts that view?
- A.It must be countersigned by the Security Control Assessor at the end of every quarter
- B.It automatically converts to a denial of authorization after any configuration change
- C.It carries a termination date and assumes conditions stay as they were
- D.It applies only to the controls the assessor tested, leaving all others unauthorized
Domain: Security and Privacy Governance, Risk Management, and Compliance Program
Q9.A governance policy was published two years ago, but no system team can produce evidence that any part of it was ever followed. What does that situation illustrate about the three functions of a governance, risk and compliance program?
- A.Governance is independent of compliance, so the policy remains fully effective
- B.Compliance evidence is only required for systems rated high under FIPS 199
- C.The absence of evidence converts the policy into a risk acceptance decision
- D.A governance policy with no compliance evidence has no practical effect
Domain: Security and Privacy Governance, Risk Management, and Compliance Program
Q10.A system team has just finished rating how much harm a loss of confidentiality, integrity or availability would cause to its information. Which Risk Management Framework step do they move into next?
- A.Implement, building the controls that were chosen
- B.Select, choosing a baseline from the control catalog
- C.Assess, testing the controls that were implemented
- D.Authorize, signing the formal risk acceptance
Domain: Security and Privacy Governance, Risk Management, and Compliance Program
ISC2 CGRC guides & exam news
Best GRC Certifications in 2026: CGRC vs CRISC vs CISA vs CISM (And Which One to Take First)
Four credentials dominate governance, risk and compliance hiring, and three of them will block you at the application stage if you lack the years. Here is what each GRC certification actually costs, what it tests, and the order to take them in.
ISC2 CGRC Explained: Domains, Cost and Is It Worth It in 2026?
A straight answer on whether the ISC2 CGRC is worth it in 2026. We cover the seven domains and their weights, the $599 exam fee, the two-year experience rule, and the one question that decides it: do you work with US federal frameworks?
CISSP Practice Questions: 20 Exam-Style Examples With Answers and Explanations (2026)
Twenty CISSP practice questions written to the real April 2024 exam outline, weighted across all eight domains. Every answer comes with the reasoning the exam actually rewards, not just a letter.
SSCP Practice Questions: 20 Exam-Style Examples With Answers (2026)
Twenty SSCP practice questions written to the real ISC2 domain weightings, each with the answer and a short explanation of why the wrong options fail. Use them to find your weak domain before you book the exam.
Frequently Asked Questions
Does the ISC2 CGRC course include performance-based questions?
Yes. The ISC2 CGRC course includes 20 performance-based questions (PBQs): hands-on tasks that mirror the interactive questions on the real exam, including drag-and-drop matching, sequencing and configuration screens. Each one is marked with partial credit, so you can see exactly which placements were wrong, and every task includes a full explanation. The first two are free to try.
What is included in the free ISC2 CGRC sample?
The free sample includes 10 syllabus-aligned practice questions, sample flashcards, and a preview chapter from the study guide. No account or payment is required to try the sample.
How many questions are in the full ISC2 CGRC course?
The full ISC2 CGRC course includes 400 practice questions and 20 performance-based tasks, covering all 7 exam domains. Every question carries a full explanation for the right answer and the wrong ones.
Are these official ISC2 exam questions?
No. CertCrush questions are independently written and syllabus-aligned. They mirror the format, difficulty, and reasoning style of the official exam. We are not affiliated with or endorsed by ISC2.
Which domains does the ISC2 CGRC course cover?
The course covers 7 exam domains: Security and Privacy Governance, Risk Management, and Compliance Program, Scope of the System, Selection and Approval of Framework, Security, and Privacy Controls, Implementation of Security and Privacy Controls, Assessment/Audit of Security and Privacy Controls, System Compliance, Compliance Maintenance.
Can I study on mobile?
Yes. CertCrush is fully responsive and works on phones, tablets, and desktops. The timed exam, flashcards, and study guide all work on mobile without installing an app.
What happens when I create an account?
Creating a free account lets you access full courses, track your weak areas by domain, and resume practice sessions across devices. No credit card is required to register.