Question 1
Which act recognizes the importance of information security to the economic and national interests of the United States?
Correct Answer:
FISMA
Explanation:
The Federal Information Security Management Act (FISMA) acknowledges the critical role of information security in protecting the economic and national interests of the United States. Enacted in 2002 and revised in 2014 under the Federal Information Security Modernization Act, FISMA establishes a framework for securing federal information systems. It mandates that federal agencies develop, document, and implement an information security program that includes risk management processes and security controls. The act emphasizes the need for a comprehensive approach to safeguarding sensitive information, which has implications not only for government operations but also for national security and economic stability. This makes it clear that FISMA is pivotal in promoting a robust information security posture within federal agencies, recognizing the overarching threat landscape that can impact the public sector and, by extension, the country as a whole. Other acts listed have distinct focuses; for example, the Computer Fraud and Abuse Act deals primarily with computer crimes, and the Lanham Act addresses trademark issues rather than security. The Computer Misuse Act, originating in the UK, is not applicable in a U.S. context. Therefore, FISMA stands out as the act that explicitly recognizes the importance of information security to both economic and national interests.
Question 2
What is the first step a project manager should take when a new significant risk is identified?
Correct Answer:
Add it to the risk register
Explanation:
The first step a project manager should take when a new significant risk is identified is to add it to the risk register. This is because the risk register serves as a central repository for all identified risks and is essential for tracking and managing risks throughout the project lifecycle. By documenting the risk, the project manager ensures that there is a formal record of the risk, which can then be assessed, monitored, and communicated effectively to stakeholders. Once the risk is recorded in the risk register, it can be prioritized based on its potential impact and likelihood, and appropriate responses can be developed. This structured approach allows the project team to maintain a clear overview of all risks and their statuses, which is critical for informed decision-making and effective risk management. In contrast, simply ignoring the risk would leave the project vulnerable to unforeseen complications, while informing stakeholders immediately might be premature without a thorough understanding of the risk's implications. Conducting a team meeting to solve the risk may also be necessary, but it should follow the initial step of formally registering the risk for proper evaluation and action planning.
Question 3
What is the main purpose of conducting a risk assessment in project management?
Correct Answer:
To analyze potential risks that may impact project success
Explanation:
The main purpose of conducting a risk assessment in project management is to analyze potential risks that may impact project success. This process involves identifying various risks that could affect the project's objectives, timeline, and overall outcomes. By systematically evaluating these risks, project managers can prioritize them based on their likelihood and potential impact, which enables informed decision-making and effective risk management strategies. This proactive approach helps to minimize negative consequences and enhances the chances of project delivery within the agreed-upon parameters, such as budget, time, and scope. Recognizing risks also plays a critical role in developing mitigation strategies, allowing project teams to address potential challenges before they materialize, thereby safeguarding the project’s success.
Question 4
In qualitative risk analysis, which approach is considered a proactive risk management technique?
Correct Answer:
Prioritizing risks
Explanation:
In qualitative risk analysis, prioritizing risks is considered a proactive risk management technique because it involves identifying and ranking potential risks based on their likelihood and impact. This prioritization helps organizations focus their efforts and resources on the most critical risks that could affect their objectives, ensuring that they can address these risks before they escalate into more serious issues. By systematically analyzing and scoring each risk, organizations can allocate resources effectively and implement risk mitigation strategies tailored to the priority level of each risk. This proactive approach supports the overall risk management process by enabling informed decision-making and encouraging timely action to minimize potential damage. Creating a contingency plan is related to risk management but typically occurs after risks have been identified and prioritized; it prepares an organization to respond if a risk materializes. Performing a qualitative analysis itself is a part of the risk assessment process and does not actively manage risks. Reviewing historical data helps inform risk analysis but does not directly address risks in a proactive manner.
Question 5
What characteristic must be assessed alongside the probability of each identified risk in qualitative risk analysis?
Correct Answer:
Impact
Explanation:
In qualitative risk analysis, assessing the impact alongside the probability of each identified risk is essential because it helps prioritize risks based on their potential effect on the organization. The impact refers to the extent of the damage or loss that could result from a risk occurring. By understanding both the likelihood of a risk happening and the severity of its consequences, organizations can make informed decisions about which risks require immediate attention and resource allocation. Considering the impact means that organizations can focus not only on how often a risk may occur but also on how detrimental it can be to operations, projects, or objectives. This dual assessment allows for a balanced approach to risk management, ensuring that resources are directed toward addressing the most significant threats to the organization's success.
Question 1
Exam overview

About this Exam

The Certified Governance, Risk, and Compliance (CGRC) certification, offered by ISC2, is the gold standard credential for IT and security professionals tasked with the authorization and maintenance of information systems. It demonstrates that you possess the advanced technical knowledge and leadership skills required to effectively manage risk within the Risk Management Framework (RMF). The CGRC is designed for professionals including auditors, information security officers, and risk analysts who specialize in aligning an organization’s information security posture with its regulatory compliance requirements and business objectives.

More details

Additional Information

What the Course Entails and Exam Details

The CGRC exam evaluates your competence in managing organizational risk while complying with strict governmental and corporate regulations. It covers seven critical domains based on the Risk Management Framework.

You must be prepared to demonstrate expertise in these areas: Information Security Risk Management Program (understanding foundational security definitions and legal requirements); Categorization of Information Systems (identifying system boundaries and analyzing their potential impact); Selection of Security Controls (choosing the appropriate safeguards and documenting them in a robust security plan); Implementation of Security Controls (managing the deployment of security architecture); Assessment of Security Controls (planning and performing control assessments, as well as managing remediation); Authorization of Information Systems (preparing the authorization package and accepting risk); and Continuous Monitoring (implementing a monitoring strategy and processing system changes).

Mastering these domains requires deep understanding of official governance frameworks, notably including NIST Special Publication 800-37.

 

 

 What to Expect in the Final Exam

The actual CGRC final exam is a challenging, computer-based assessment. You will have a strictly enforced time limit of 3 hours (180 minutes) to complete the test.

The exam consists of 125 multiple-choice questions that cover all seven domains. Some questions will test direct recall of definitions and standards, while others will be complex, scenario-based questions that require you to apply governance and risk principles to practical situations.

To pass, you must achieve a scaled score of 700 or higher out of 1000 possible points.

The CGRC exam is not a adaptive test; it is linear. You must answer each question as it is presented and will not be able to return to previous questions or review your answers once you submit them, making efficient time management absolute necessity.

 

 

 How to Study and Exam Centers

Preparation for the CGRC requires a structured and rigorous approach. Start by downloading the official ISC2 CGRC Exam Outline (syllabus) to understand the weightings of each domain and identify your weakest areas.

The most effective study method combines multiple resources. We recommend utilizing the Official ISC2 CGRC Study Guide (the premier textbook for this exam) alongside official ISC2 online self-study training courses or authorized instructor-led bootcamps. Actively taking high-quality CGRC practice exams is perhaps the most critical study step. These mock tests will help you familiarize yourself with the question formatting, build stamina for the 3-hour exam window, and learn the specific nuances of how ISC2 phrase their complex scenarios. Be sure to focus heavily on learning why an answer is correct, rather than just memorizing it.

The CGRC exam is not available as an online proctored test from home. You must schedule and take your exam in-person at a physical, authorized testing facility managed exclusively by Pearson VUE, which is the official delivery partner for all ISC2 certifications. Visit the Pearson VUE website to create an account, pay the exam fee, and locate the authorized professional testing center nearest you to schedule your preferred date and time. Make sure to review the location’s specific rules and identification requirements well before your exam date.

 

 

 Job Opportunities from the Course

Earning your CGRC certification significantly elevates your credibility and opens doors to lucrative career opportunities across both the private and public sectors. It is especially critical for those supporting or working directly within US federal agencies due to strict DoD 8570/8140 compliance mandates. Below is a clear list of the high-impact job titles and career paths this certification unlocks:

  • Information System Security Officer (ISSO)
  • Information System Security Manager (ISSM)
  • Risk Management Framework (RMF) Analyst
  • IT Security Auditor
  • Compliance Officer / Manager
  • Security Control Assessor
  • Data Privacy Officer
  • Governance, Risk, and Compliance (GRC) Specialist
  • Chief Information Security Officer (CISO)
  • Chief Risk Officer (CRO)

 

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions