Free CGRC Practice Test Questions and Answers (2026)

View Mode
Q: 1
An application that requires special attention to security due to the risk and magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of the information in the application. Note: All federal applications require some level of protection. Certain applications, because of the information in them, however, require special management oversight and should be treated as major. Adequate security for other applications should be provided by security of the systems in which they operate. Response:
Options
Q: 2
What is the comprehensive assessment of the management, operational, and technical security controls in an information system, made in support of security accreditation, to determine the extent to which the controls are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the security requirements for the system. Response:
Options
Q: 3
Applying the first three steps in the RMF to legacy systems can be viewed in what way to determine if the necessary and sufficient security controls have been appropriately selected and allocated? Response:
Options
Q: 4
Information developed from Federal Information Processing Standard (FIPS) 199 may be used as an input to which authorization package document? Response:
Options
Q: 5
What is Step 6? Response:
Options
Q: 6
Which of the following governance bodies provides management, operational and technical controls to satisfy security requirements? Response:
Options
Q: 7
An updated risk assessment in response to the security control assessment along with inputs from the risk executive helps to determine and prioritize… Response:
Options
Q: 8
The objective of Configuration Manager and control is "not to" document all proposed or actual changes to an IS & to assess the impact of changes on security of system. Response:
Options
Q: 9
Measure of confidence that the security features, practices, procedures, and architecture of an information system accurately mediates and enforces the security policy. Response:
Options
Q: 10
NIST SP 800-39 requires that the Security Control Assessor’s findings should be: Response:
Options
Q: 11
The Security Category that guards against the improper modification or destruction of information and includes ensuring information non-repudiation & authenticity. Response:
Options
Q: 12
The Security Content Automation Protocol (SCAP) is a method for which of the following? Response:
Options
Q: 13
A key part of the risk-based decision process is the recognition that regardless of the risk response, There remains some risks known as: Response:
Options
Q: 14
When SCA conducted assessments are conducted in parallel with system development/acquisition & implementation; it "does not" permit early identification of weaknesses & cost-effective corrective action; True or False? Response:
Options
Q: 15
In the case of a complex information system, where a “leveraged authorization” that involves two agencies will be conducted, what is the minimum number of system boundaries/accreditation boundaries that can exist? Response:
Options
Q: 16
The Organization Level (Tier 1) strategy addresses/requires........ Response:
Options
Q: 17
A discrete set of resources organized for the collection, processing, maintenance, or disposition of information best describes one of the following Response:
Options
Q: 18
Which of the following is NOT considered an environmental threat source? Response:
Options
Q: 19
What are the responsibilities of a system owner? Each correct answer represents a complete solution. Choose all that apply. Response:
Options
Q: 20
The Information System Security Officer (ISSO) and Information System Security Engineer (ISSE) play the role of a supporter and advisor, respectively. Which of the following statements are true about ISSO and ISSE?
Options
Question 1 of 20

What's covered in this practice questions set

1: Information Security Risk Management Program · 6 questions

📖 About this Domain

This domain covers the foundational processes for establishing an organization's information security risk management program. It emphasizes the creation and implementation of a risk management framework (RMF) that aligns with organizational governance and the system development life cycle (SDLC).

🎓 What You Will Learn

  • You will learn the core processes of risk management, including risk framing, assessment, response, and monitoring.
  • You will learn to integrate established risk management frameworks, such as the NIST RMF, into organizational processes.
  • You will learn the relationship between risk management and governance, including defining risk appetite and risk tolerance.
  • You will learn to incorporate legal, regulatory, and compliance drivers into the risk management program.

🛠️ Skills You Will Build

  • You will build the skill to establish and manage a risk management program using frameworks like NIST SP 800-37.
  • You will build the skill to perform risk assessments, identifying threats, vulnerabilities, likelihood, and impact.
  • You will build the skill to develop risk management policies, standards, and procedures supporting organizational goals.
  • You will build the skill to communicate risk posture and treatment plans to key stakeholders, including the Authorizing Official (AO).

💡 Top Tips to Prepare

  • Master the seven steps of the NIST Risk Management Framework (RMF) and their specific inputs and outputs.
  • Clearly differentiate between risk appetite, risk tolerance, and risk capacity for scenario-based questions.
  • Understand how risk management activities are integrated into each phase of the System Development Life Cycle (SDLC).
  • Focus on the distinct roles and responsibilities within the risk governance structure, such as the System Owner and Information Owner.

5: Assessment/Audit of Security and Privacy Controls · 4 questions

📖 About this Domain

This domain covers 5: Assessment/Audit of Security and Privacy Controls concepts and practices.

🎓 What You Will Learn

  • Key concepts and fundamentals
  • Best practices and methodologies
  • Real-world application scenarios

🛠️ Skills You Will Build

  • Technical expertise in 5: Assessment/Audit of Security and Privacy Controls
  • Analytical and problem-solving skills
  • Practical implementation abilities

6: Authorization/Approval of Information System · 4 questions

📖 About this Domain

This domain covers 6: Authorization/Approval of Information System concepts and practices.

🎓 What You Will Learn

  • Key concepts and fundamentals
  • Best practices and methodologies
  • Real-world application scenarios

🛠️ Skills You Will Build

  • Technical expertise in 6: Authorization/Approval of Information System
  • Analytical and problem-solving skills
  • Practical implementation abilities

3: Selection and Approval of Security and Privacy Controls · 2 questions

📖 About this Domain

This domain covers the Risk Management Framework (RMF) Step 2, focusing on the selection of security and privacy controls. It details the process of identifying control baselines, tailoring them based on risk assessment, and documenting the final control set. The core activity is translating risk decisions into actionable security and privacy requirements for a system.

🎓 What You Will Learn

  • Identify appropriate control baselines from sources like NIST SP 800-53 and leverage common control inheritance to optimize implementation.
  • Select and tailor controls using scoping, parameterization, and compensating controls to align with the system's operational environment.
  • Develop a continuous monitoring (ConMon) strategy to define how selected controls will be assessed for ongoing effectiveness.
  • Understand the formal process for reviewing the selected control set and obtaining approval from the Authorizing Official (AO).

🛠️ Skills You Will Build

  • Ability to analyze system categorization results to select the correct initial control baseline.
  • Proficiency in tailoring controls and documenting the rationale and implementation details within the System Security Plan (SSP).
  • Competency in creating a control monitoring strategy that supports the organization's risk management objectives.
  • Skill in articulating the security posture defined by the control set to stakeholders for formal risk acceptance and approval.

💡 Top Tips to Prepare

  • Master the structure of NIST SP 800-53, including control families, baselines, and the relationship between security and privacy controls.
  • Clearly differentiate between tailoring actions like scoping considerations, parameterization, and applying compensating controls.
  • Recognize the System Security Plan (SSP) as the key artifact for documenting the results of the control selection process.
  • Connect how system categorization from RMF Step 1 directly informs the control baseline selection in this domain.

4: Implementation of Security and Privacy Controls · 2 questions

📖 About this Domain

This domain covers 4: Implementation of Security and Privacy Controls concepts and practices.

🎓 What You Will Learn

  • Key concepts and fundamentals
  • Best practices and methodologies
  • Real-world application scenarios

🛠️ Skills You Will Build

  • Technical expertise in 4: Implementation of Security and Privacy Controls
  • Analytical and problem-solving skills
  • Practical implementation abilities

2: Scope of the Information System · 2 questions

📖 About this Domain

This domain covers 2: Scope of the Information System concepts and practices.

🎓 What You Will Learn

  • Key concepts and fundamentals
  • Best practices and methodologies
  • Real-world application scenarios

🛠️ Skills You Will Build

  • Technical expertise in 2: Scope of the Information System
  • Analytical and problem-solving skills
  • Practical implementation abilities

7: Continuous Monitoring of Security and Privacy Controls

📖 About this Domain

This domain covers 7: Continuous Monitoring of Security and Privacy Controls concepts and practices.

🎓 What You Will Learn

  • Key concepts and fundamentals
  • Best practices and methodologies
  • Real-world application scenarios

🛠️ Skills You Will Build

  • Technical expertise in 7: Continuous Monitoring of Security and Privacy Controls
  • Analytical and problem-solving skills
  • Practical implementation abilities

Premium Access Includes

  • Quiz Simulator
  • Exam Mode
  • Progress Tracking
  • Question Saving
  • Flash Cards
  • Drag & Drops
  • 3 Months Access
  • PDF Downloads
Get Premium Access
Scroll to Top

FLASH OFFER

Days
Hours
Minutes
Seconds

avail 10% DISCOUNT on YOUR PURCHASE