ISC CGRC Exam Overview:
| Certification Vendor: | ISC2 |
|---|---|
| Exam Name: | ISC2 Certified in Governance, Risk and Compliance (CGRC) Examination |
| Exam Number: | CGRC |
| Exam Format: | Multiple choice |
| Exam Price: | 749 USD (standard registration, subject to regional variation) |
| Exam Duration: | 180 minutes |
| Related Certifications: | SSCP CCSP CISSP |
| Certificate Validity Period: | 3 years |
| Real Exam Qty: | 125 |
| Available Languages: | English |
| Passing Score: | 700/1000 (scaled score) |
| Recommended Training: | CGRC Exam Preparation Resources ISC2 Official CGRC Training |
| Exam Registration: | Pearson VUE ISC2 Registration Portal ISC2 CGRC Official Certification Page |
| Sample Questions: | ISC CGRC Sample Questions |
| Exam Way: | Computer-based testing via Pearson VUE (in-person test centers or online proctored where available) |
| Pre Condition: | ISC2 recommends at least 5 years of cumulative paid work experience in at least two of the CGRC domains. One year may be waived with an existing ISC2 credential or approved education. |
| Official Syllabus URL: | https://www.isc2.org/certifications/cgrc |
ISC CGRC Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Topic 1: Monitoring and Continuous Compliance | - Compliance monitoring techniques - Audit and assurance processes |
| Topic 2: Incident and Exception Management | - Compliance deviation handling - Incident reporting and escalation |
| Topic 3: Risk Management | - Risk identification and assessment - Risk treatment and mitigation strategies |
| Topic 4: Scope and Context Definition | - Organizational scope identification - Regulatory and legal requirement mapping |
| Topic 5: Control Frameworks and Implementation | - Security and compliance control selection - Control implementation and validation |
| Topic 6: GRC Program Maintenance and Improvement | - Continuous improvement processes - Metrics and reporting in GRC programs |
| Topic 7: Governance, Risk, and Compliance Program | - Stakeholder roles and responsibilities in GRC - GRC principles and framework development |
ISC Certified in Governance Risk and Compliance Sample Questions:
Question 1
The loss of confidentiality, integrity, or availability could be expected to have a serious adverse effect on organizational operations, organizational assests, or individuals. Thus the potential impact is..
Response:
A. Low
B. Moderate
C. Severe
D. High
Question 2
A complex system of systems composed of subsystems and services that are part of a continuously evolving, complex community of people, devices, information and services interconnected by a network that enhances information sharing and collaboration. Subsystems and services may or may not be developed or owned by the same entity, and, in general, will not be continually present during the full lifecycle of the system of systems.
Response:
A. Event-Driven Architecture
B. Federal Enterprise Architecture
C. Industry Standard Architecture
D. Net-Centric Architecture
Question 3
NIST SP 800-39 requires that the Security Control Assessor's findings should be:
Response:
A. Factual and unbiased
B. Assessed in accordance with NIST SP 800-30 procedures
C. Only documented with System Owner Agreement
D. Technically focused and detailed
Question 4
The mitigation of violations of security policies and recommended practices.
Response:
A. Appointment Handling
B. Appendage Handling
C. Episode Handling
D. Incident Handling
Question 5
An assessment procedure consists of a set of which things, each with an associated set of potential assessment methods and assessment objects?
Response:
A. Operational requirements
B. Security controls
C. Assessment objects
D. Assessment objectives
Solutions:
| Question 1 Answer: B | Question 2 Answer: D | Question 3 Answer: A | Question 4 Answer: D | Question 5 Answer: D |


PDF Version Demo






We are confident about the products and aim to help you pass with ease. In case of failure, we will provide a no hassle full money back guarantee for the purchasing fee.
1374 Customer Reviews
Quality and ValueITbraindumps Practice Exams are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development - no all study materials.
Tested and ApprovedWe are committed to the process of vendor and third party approvals. We believe professionals and executives alike deserve the confidence of quality coverage these authorizations provide.
Easy to PassIf you prepare for the exams using our ITbraindumps testing engine, It is easy to succeed for all certifications in the first attempt. You don't have to deal with all dumps or any free torrent / rapidshare all stuff.
Try Before BuyITbraindumps offers free demo of each product. You can check out the interface, question quality and usability of our practice exams before you decide to buy.