ISC2 CGRC PRACTICE
EXAM 125 QUESTIONS
Question 1: A multinational organization is creating a new governance, risk, and compliance program. Which action should occur FIRST to keep the program aligned with the business?
Choices:
1) Purchase a GRC platform 2) Identify organizational objectives and applicable risk/compliance obligations 3) Adopt every control in a single framework 4) Schedule external audits for all systems Correct Answer: Identify organizational objectives and applicable risk/compliance obligations Explanation: A GRC program should begin with the organization's mission, objectives, risk context, and applicable obligations. Tools, control selection, and audit schedules should follow that foundation.Page 1
Question 2: Which statement BEST distinguishes risk appetite from risk tolerance?
Choices:
1) Risk appetite is the broad amount of risk an organization is willing to pursue or retain, while risk tolerance sets acceptable variation around specic objectives 2) Risk appetite applies only to privacy risk, while risk tolerance applies only to security risk 3) Risk appetite is dened by auditors, while risk tolerance is dened by system administrators 4) Risk appetite is a list of controls, while risk tolerance is a list of threats Correct Answer: Risk appetite is the broad amount of risk an organization is willing to pursue or retain, while risk tolerance sets acceptable variation around specic objectives Explanation: Risk appetite is the high-level amount and type of risk an organization is willing to accept in pursuit of objectives. Risk tolerance translates that appetite into more specic acceptable ranges or thresholds.Question 3: A policy states that sensitive data must be protected, while a separate document species required encryption algorithms and key lengths. What is the second document MOST likely to be?
Choices:
1) A guideline 2) A standard 3) A risk register 4) An audit report
Correct Answer: A standard
Explanation: Standards provide mandatory, specic requirements that support policy.Guidelines are generally advisory, while risk registers and audit reports serve dierent governance purposes.Page 2
Question 4: What is the PRIMARY benet of integrating security and privacy requirements into the system development life cycle from the requirements phase?
Choices:
1) It eliminates the need for later testing 2) It reduces the need for executive oversight 3) It allows controls to be designed into the system before costly rework is required 4) It guarantees regulatory compliance Correct Answer: It allows controls to be designed into the system before costly rework is required Explanation: Early integration makes security and privacy requirements part of design decisions, reducing expensive rework and improving traceability. It does not eliminate testing or guarantee compliance.Question 5: An organization is documenting the information lifecycle for customer records. Which activity belongs in that lifecycle?
Choices:
1) Selecting the corporate logo 2) Dening retention and approved destruction methods 3) Setting employee vacation schedules 4) Choosing an auditor's sampling method
Correct Answer: Dening retention and approved destruction methods
Explanation: The information lifecycle includes creation or collection, use, storage, sharing, retention, archival, and disposal or destruction requirements for each information type.Page 3