CGRC Sample Questions

CGRC Sample Questions & Answers

Built around the Risk Management Framework, the outline walks through preparing a program, categorizing a system, choosing and implementing controls, assessing them, authorizing the system, and monitoring compliance afterward.

Launch the full CGRC simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    Assessment/Audit of Security and Privacy Controls · Control Assessment and Findings

    A Security Control Assessor is reviewing the implementation of control AU-5 (Response to Audit Processing Failures) for a critical patient records database. The documentation in the SSP states: "In the event of an audit failure, the system will automatically shut down to prevent further activity." The assessor finds that while this mechanism is implemented, there is no procedure for alerting administrators about the shutdown. Which assessment finding is most accurate?

    Show answer & explanation

    Correct answer: C

    NIST SP 800-53, control AU-5, explicitly requires the system to "Alert designated organizational officials in the event of an audit processing failure." The implemented solution of shutting down the system addresses part of the potential response, but without the required alerting mechanism, the control is not fully satisfied. A silent failure could lead to a prolonged, unnoticed outage. The conflict with availability is a separate risk consideration, but the direct reason the control is not satisfied is the missing alert function.

  2. Question 2Intermediate

    System Compliance · Authorization Package Development

    An organization is preparing an Authorization to Operate (ATO) package for the Authorizing Official (AO). The package includes the System Security Plan (SSP), the Security Assessment Report (SAR), and the Plan of Action and Milestones (POA&M). The SAR identifies 5 High, 12 Moderate, and 20 Low findings. The POA&M details a remediation plan for all High and Moderate findings within 180 days. What is the primary purpose of including the POA&M in this package?

    Show answer & explanation

    Correct answer: B

    The POA&M is a critical document for risk management. Its inclusion in the authorization package acknowledges that the system is not perfect but demonstrates a formal plan to systematically address and mitigate identified weaknesses over time. This allows the Authorizing Official to understand the current residual risk and the organization's commitment to reducing it, enabling an informed, risk-based decision on whether to grant an ATO.

  3. Question 3Intermediate

    Implementation of Security and Privacy Controls · Control Tailoring Justification

    A system categorized as Moderate-Moderate-Moderate is being deployed. The ISSO is reviewing the draft System Security Plan (SSP) and notes that the development team has decided not to implement several applicable controls from the Moderate baseline, citing 'operational constraints'. However, no alternative or compensating controls are documented. What should be the ISSO's immediate next step?

    Show answer & explanation

    Correct answer: C

    The RMF process allows for tailoring, but it must be a deliberate, risk-based process. Simply omitting controls due to 'operational constraints' without analysis is unacceptable. The correct procedure is for the system owner to provide a formal justification for why a baseline control is not applicable or cannot be implemented, assess the residual risk, and propose compensating controls that provide an equivalent level of security. The ISSO's role is to enforce this process before the SSP is considered complete.

  4. Question 4Beginner

    Scope of the System · System Categorization

    A university is developing a research portal that will handle controlled unclassified information (CUI) from a federal grant. According to FIPS 199, the potential impact of a loss of confidentiality is assessed as Moderate, loss of integrity as Moderate, and loss of availability as Low. What is the final security categorization for this system?

    Show answer & explanation

    Correct answer: B

    FIPS 199 mandates the use of the 'high water mark' principle for determining the overall system categorization. The final categorization is the highest impact level assigned to any of the three security objectives (Confidentiality, Integrity, Availability). In this case, the impact levels are {Confidentiality: Moderate, Integrity: Moderate, Availability: Low}. The highest impact level is Moderate, so the overall system categorization is Moderate.

  5. Question 5Advanced

    Compliance Maintenance · Security Impact Analysis

    After a system receives its ATO, a critical vulnerability is discovered in a core software component. The system owner performs a security impact analysis and determines the change to patch the vulnerability is 'significant'. According to the RMF, what is the most likely consequence of this determination?

    Show answer & explanation

    Correct answer: B

    A determination that a change has a 'significant' impact on the security posture of an authorized system is a primary trigger for re-authorization. This means the change is substantial enough to potentially invalidate the previous risk assessment and authorization decision. The system will likely need to go through the Assess and Authorize steps of the RMF again, focusing on the changes but often requiring a comprehensive re-assessment before a new ATO can be issued.

  6. Question 6Intermediate

    Selection and Approval of Framework, Security, and Privacy Controls · Privacy Control Selection

    A GRC analyst is tasked with selecting privacy controls for a new human resources system that processes employee PII. The analyst starts by selecting the appropriate baseline from NIST SP 800-53B. What is the next essential step the analyst must take to properly integrate privacy into the control selection process?

    Show answer & explanation

    Correct answer: B

    While the baseline provides a starting point, it is not sufficient for addressing all privacy risks. The RMF emphasizes that organizations must analyze the specific context in which PII is processed. This involves identifying the types of PII, the purpose of processing, and the potential problems (privacy risks) individuals could experience. Based on this analysis, the organization must select additional privacy controls and enhancements from the catalog in Appendix J of NIST SP 800-53 to supplement the baseline.

  7. Question 7Advanced

    Implementation of Security and Privacy Controls · Shared Control Responsibility

    A cloud service provider (CSP) offers an IaaS platform that has a FedRAMP High authorization. An agency deploys a new application on this platform. The agency's ISSO states that since the platform is FedRAMP High, the agency's application inherits all necessary controls and only needs a simple ATO. Why is this reasoning flawed?

    Show answer & explanation

    Correct answer: B

    The FedRAMP authorization for the IaaS platform covers controls at the infrastructure level (CSP responsibility). The agency, as the customer, retains responsibility for a significant number of controls related to the application itself, data, access management, and configurations (customer responsibility and shared controls). The agency must implement, document, and assess these controls as part of its own authorization process. Control inheritance is not total; it operates on a shared responsibility model.

  8. Question 8Beginner

    Assessment/Audit of Security and Privacy Controls · Assessment Methods

    During an assessment, an assessor uses the 'test' method to verify the implementation of a firewall rule. Which of the following best describes this activity?

    Show answer & explanation

    Correct answer: D

    NIST SP 800-53A defines three assessment methods: Examine, Interview, and Test. The 'Test' method involves exercising or executing system functions to verify they operate as intended. A port scan is a direct test of the firewall's functionality. Reviewing configuration files is 'Examine,' and asking an administrator is 'Interview.' Observing a demonstration is a form of 'Examine' as well.

  9. Question 9Beginner

    Security and Privacy Governance, Risk Management, and Compliance Program · Assessment Reciprocity

    An organization can use the results of a previous assessment for a new authorization decision, provided that the results are still current, relevant, and accurate. This practice is known as ____________.

    Show answer & explanation

    Correct answer: B

    Reciprocity is the principle of reusing assessment results and authorization decisions across different organizations or systems to reduce redundant testing and effort. It is a key concept in frameworks like FedRAMP and is encouraged by the RMF to improve efficiency, as long as the reused information is verified to be trustworthy.

  10. Question 10Beginner

    Compliance Maintenance · POA&M Management

    True or False: A Plan of Action and Milestones (POA&M) is considered a static document that is finalized during the 'Authorize' step and is only reviewed upon re-authorization.

    Show answer & explanation

    Correct answer: B

    This statement is false. The POA&M is a dynamic risk management tool. It is a key input to the continuous monitoring process ('Monitor' step). The status of POA&M items must be regularly tracked, updated as remediation activities progress, and reviewed to ensure weaknesses are being addressed in a timely manner. It is a living document throughout the system's lifecycle.

Ready for the real thing?

The full CGRC simulator has every exam-style question, timed mode, and instant scoring.

Go to the CGRC simulator →