ISC2 CGRC Practice Exam 125 Questions (1)

PROFESSIONAL EXAMS
Loading...

Loading secure study guide viewer...

Page 0 of 0

Document Text

ISC2 CGRC PRACTICE

EXAM 125 QUESTIONS

Question 1: A multinational organization is creating a new governance, risk, and compliance program. Which action should occur FIRST to keep the program aligned with the business?

Choices:

1) Purchase a GRC platform 2) Identify organizational objectives and applicable risk/compliance obligations 3) Adopt every control in a single framework 4) Schedule external audits for all systems Correct Answer: Identify organizational objectives and applicable risk/compliance obligations Explanation: A GRC program should begin with the organization's mission, objectives, risk context, and applicable obligations. Tools, control selection, and audit schedules should follow that foundation.Page 1

Question 2: Which statement BEST distinguishes risk appetite from risk tolerance?

Choices:

1) Risk appetite is the broad amount of risk an organization is willing to pursue or retain, while risk tolerance sets acceptable variation around speci�c objectives 2) Risk appetite applies only to privacy risk, while risk tolerance applies only to security risk 3) Risk appetite is de�ned by auditors, while risk tolerance is de�ned by system administrators 4) Risk appetite is a list of controls, while risk tolerance is a list of threats Correct Answer: Risk appetite is the broad amount of risk an organization is willing to pursue or retain, while risk tolerance sets acceptable variation around speci�c objectives Explanation: Risk appetite is the high-level amount and type of risk an organization is willing to accept in pursuit of objectives. Risk tolerance translates that appetite into more speci�c acceptable ranges or thresholds.Question 3: A policy states that sensitive data must be protected, while a separate document speci�es required encryption algorithms and key lengths. What is the second document MOST likely to be?

Choices:

1) A guideline 2) A standard 3) A risk register 4) An audit report

Correct Answer: A standard

Explanation: Standards provide mandatory, speci�c requirements that support policy.Guidelines are generally advisory, while risk registers and audit reports serve di�erent governance purposes.Page 2

Question 4: What is the PRIMARY bene�t of integrating security and privacy requirements into the system development life cycle from the requirements phase?

Choices:

1) It eliminates the need for later testing 2) It reduces the need for executive oversight 3) It allows controls to be designed into the system before costly rework is required 4) It guarantees regulatory compliance Correct Answer: It allows controls to be designed into the system before costly rework is required Explanation: Early integration makes security and privacy requirements part of design decisions, reducing expensive rework and improving traceability. It does not eliminate testing or guarantee compliance.Question 5: An organization is documenting the information lifecycle for customer records. Which activity belongs in that lifecycle?

Choices:

1) Selecting the corporate logo 2) De�ning retention and approved destruction methods 3) Setting employee vacation schedules 4) Choosing an auditor's sampling method

Correct Answer: De�ning retention and approved destruction methods

Explanation: The information lifecycle includes creation or collection, use, storage, sharing, retention, archival, and disposal or destruction requirements for each information type.Page 3

Download Study Guide

Buy This Guide

$39.00 One-time purchase
Buy Now
  • Full access to this guide
  • Download anytime
  • No expiration

Study Guide Information

Category: PROFESSIONAL EXAMS
Description:

ISC2 CGRC PRACTICE EXAM 125 QUESTIONS Question 1: A multinational organization is creating a new governance, risk, and compliance program. Which action should occur FIRST to keep the program aligne...

Get this guide $39.00