ISC2 CGRC PRACTICE
EXAM 125 QUESTIONS
Question 1: Which statement BEST distinguishes a policy from a procedure?
Choices:
1) A policy is always technical; a procedure is always legal 2) A policy states management intent and expectations; a procedure gives detailed steps for carrying them out 3) A procedure is approved only by external regulators 4) A policy is optional whenever a procedure exists Correct Answer: A policy states management intent and expectations; a procedure gives detailed steps for carrying them out Explanation: Policies communicate management direction and mandatory expectations.Procedures translate those expectations into repeatable operational steps.Page 1
Question 2: Which example is a technical control?
Choices:
1) Multi-factor authentication enforced by an identity platform 2) A security awareness policy 3) A governance committee charter 4) A background screening procedure
Correct Answer: Multi-factor authentication enforced by an identity platform
Explanation: Technical controls are implemented through hardware, software, or rmware mechanisms. Multi-factor authentication enforced by a platform is a technical safeguard.Question 3: What is the MAIN dierence between vulnerability scanning and penetration testing?
Choices:
1) Vulnerability scanning always proves business impact 2) Scanning identies potential weaknesses broadly; penetration testing actively attempts exploitation to demonstrate impact 3) Penetration testing never uses technical tools 4) They are identical methods with dierent names Correct Answer: Scanning identies potential weaknesses broadly; penetration testing actively attempts exploitation to demonstrate impact Explanation: Vulnerability scanning is generally used to identify known weaknesses or miscongurations, while penetration testing goes further by attempting controlled exploitation to validate attack paths and impact.Page 2
Question 4: A control is partly implemented by a central identity service and partly by an application team. What type of control is this?
Choices:
1) System-specic control only 2) Common control only 3) Not applicable control 4) Hybrid control
Correct Answer: Hybrid control
Explanation: A hybrid control has both common and system-specic portions. Documentation must clearly allocate responsibility for each portion so gaps are not created.Question 5: A privacy review identies unresolved concerns about a new data use.What should occur before a nal system compliance decision?
Choices:
1) Exclude privacy information because authorization is only technical 2) Assume consent resolves every privacy concern 3) Delete the privacy nding 4) Include the privacy risk and required privacy documentation in the decision package and obtain appropriate review Correct Answer: Include the privacy risk and required privacy documentation in the decision package and obtain appropriate review Explanation: Current CGRC scope integrates security and privacy. Relevant privacy risks, assessments, and documentation should be part of the evidence presented to the appropriate decision-makers.Page 3