22 Governance, Risk & Compliance Practice Questions & Answers
Every Governance, Risk & Compliance practice question from the ISC2 Certified in Cybersecurity (CC) Practice Test, with the correct answer and a short explanation.
Start practice test →1. A company describes its security programme as "GRC." Which statement best describes what each of the three parts contributes?
- A.Governance audits the deployed controls, risk management writes the policies, compliance selects the security tooling.
- B.Governance reports incidents to regulators, risk management buys insurance, compliance trains staff on secure behaviour.
- C.Governance funds the technology purchases, risk management runs the internal audits, compliance sets strategic direction.
- D.Governance sets direction and accountability, risk management treats mission threats, compliance meets obligations.✓ Answer
The three disciplines answer different questions. Governance is the senior-management and board function that sets direction, assigns accountability and provides oversight; risk management identifies, assesses and treats the risks that could stop the organization achieving its mission; compliance demonstrates that legal, regulatory and contractual obligations are being met. Combining them keeps decisions, risk decisions and evidence of obligation in one cycle.
Source: ISC2 Certified in Cybersecurity Exam Outline, Security Governance — Plan Governance, Risk and Compliance (GRC)Report a problem with this question
2. An organization passes every control test in its annual regulatory audit and is declared fully compliant. Why is it a mistake to conclude that it is therefore secure?
- A.Compliance is a purely technical exercise, so it can never say anything about administrative or physical controls.
- B.Compliance frameworks are written by regulators who have no access to the organization's actual risk register.
- C.A compliance regime sets a minimum baseline at one point in time, while threats change continuously.✓ Answer
- D.Compliance audits are performed by external parties, so their conclusions carry no weight inside the organization.
Compliance measures a defined set of requirements on a defined date; it is a floor, not a ceiling. An organization can satisfy every listed requirement and still carry unaddressed risks that the requirement set never contemplated, and its exposure changes the day after the audit. Security is managed continuously against the organization's own risk, while compliance evidences obligations to an outside party.
Source: ISC2 Certified in Cybersecurity Exam Outline, Security Governance — purpose and importance of GRCReport a problem with this question
3. A new GRC programme is being stood up. Which outcome BEST describes what the programme is intended to produce?
- A.A catalogue of approved security products that every business unit is required to purchase and deploy.
- B.A technical certification of each system, issued by the security team, that replaces management review.
- C.A guarantee that no security incident will occur while the programme's controls remain fully funded.
- D.A repeatable way to set direction, weigh risk against objectives, and evidence obligations.✓ Answer
A GRC programme exists to make decision-making repeatable: documented direction and accountability, a consistent method for judging risk against business objectives, and evidence that legal, regulatory and contractual obligations are satisfied. Its outputs are artifacts such as policies, a risk register and reporting, not a product list; and no programme can promise the absence of incidents.
Source: ISC2 Certified in Cybersecurity Exam Outline, Security Governance — purpose and importance of GRCReport a problem with this question
4. Management asks why the security team wants to adopt a published cybersecurity framework instead of writing everything from scratch. Which answer is correct?
- A.A framework supplies an organized set of outcomes and a shared vocabulary the organization tailors to its risk.✓ Answer
- B.A framework prescribes exact product configurations, so adopting it settles the technical decisions in advance.
- C.A framework certifies the organization automatically once its control list is copied into the policy set.
- D.A framework legally binds any organization that references it, which removes the need for internal policy.
A framework is a structuring tool: it organizes the outcomes a programme should achieve and gives everyone a common vocabulary for discussing them, so the organization does not have to invent the structure itself. Frameworks are voluntary unless a law or contract imposes one, they stop short of prescribing products, and adopting one does not by itself certify anything.
Source: ISC2 Certified in Cybersecurity Exam Outline, Security Governance — GRC frameworks and toolsReport a problem with this question
5. An organization wants a management-system standard against which it can be independently audited and certified for information security. Which one is designed for that purpose?
- A.ISO/IEC 27001, which states requirements for an information security management system✓ Answer
- B.ISO 31000, which provides principles and guidance for managing risk of any kind
- C.ISO/IEC 27002, which provides guidance and implementation advice for security controls
- D.The CIS Controls, which offer a prioritized list of defensive actions for practitioners
Certification requires auditable requirements, and ISO/IEC 27001 is the standard that states requirements for establishing and operating an information security management system, so an accredited body can audit conformity against it. ISO/IEC 27002 is guidance on controls, ISO 31000 is guidance on managing risk generally, and the CIS Controls are a prioritized practitioner list; none of the three is a certifiable management-system standard.
Source: ISO/IEC 27001, Information security management systems — Requirements, contrasted with ISO/IEC 27002 and ISO 31000Report a problem with this question
6. The NIST Cybersecurity Framework organizes cybersecurity outcomes into functions. Which function covers establishing and monitoring the organization's risk strategy, roles and policy?
- A.Identify — cataloguing assets, suppliers and the risks that affect them
- B.Protect — applying safeguards that limit or contain a possible event
- C.Govern — establishing and overseeing the risk strategy, roles and policy✓ Answer
- D.Detect — finding and analysing indications that an event has occurred
The Govern function is where the framework places the organizational context, risk management strategy, roles and responsibilities, policy and oversight — the decisions that inform how all the other functions are carried out. Identify catalogues assets and risks, Protect applies safeguards, and Detect finds evidence of events; none of those carries the strategy and accountability outcomes.
Source: NIST Cybersecurity Framework, Core Functions: Govern, Identify, Protect, Detect, Respond, RecoverReport a problem with this question
7. A compliance register lists HIPAA, SOX, GDPR and PCI DSS side by side. Which statement about how these obligations arise is correct?
- A.PCI DSS is federal law in the United States, so it outranks the contractual obligations in the register.
- B.PCI DSS is imposed through contracts with the card brands and acquirers, while the other three are law.✓ Answer
- C.All four are statutes, so a failure against any of them is enforced only by a government regulator.
- D.All four are voluntary guidance, so an organization may adopt whichever parts suit its own risk appetite.
HIPAA, SOX and GDPR are statutes enforced by government authorities, while PCI DSS is an industry standard that becomes binding through the merchant's contracts with the payment brands and its acquiring bank. The distinction matters because the consequences differ: regulatory penalties on one side, contractual remedies such as fines passed through the acquirer or loss of the ability to process cards on the other.
Source: PCI Security Standards Council, PCI DSS — enforced through payment brand and acquirer contracts; HIPAA, SOX and GDPR are statutesReport a problem with this question
8. A hardening document for developer laptops is labelled a guideline. A developer follows most of it but departs from two recommendations and documents why. How should a governance reviewer treat this?
- A.As a violation: every published security document carries the same mandatory force once it is approved.
- B.As a violation: guidelines outrank standards, so departing from one is the most serious deviation possible.
- C.Acceptably: a guideline is advisory, so a documented and reasoned departure is not a compliance violation.✓ Answer
- D.Acceptably: no security document binds staff until senior management signs a separate enforcement order.
In the governance document hierarchy, policies, standards and procedures are mandatory, but a guideline is explicitly discretionary: it recommends good practice and allows professional judgement. Because the developer applied judgement and recorded the reasoning, there is nothing to enforce; if the organization wanted the measures to be compulsory it should have published them as a standard.
Source: ISC2 Certified in Cybersecurity Exam Outline, Security Principles — policies, standards, procedures and guidelinesReport a problem with this question
9. A breach exposes customer records in a system configured by an administrator, at the direction of the system owner, under a policy approved by the board. Who is ACCOUNTABLE for the risk and who is RESPONSIBLE for the work?
- A.Senior leadership is accountable and cannot delegate that; owners and administrators do the work.✓ Answer
- B.The administrator is accountable, because the misconfiguration was made by his own hands at the keyboard.
- C.Accountability transfers to whoever performed the task, so it moved from the board down to the system owner.
- D.Accountability sits with the auditor who approved the control design during the most recent review cycle.
Governance separates the two ideas: responsibility for performing tasks can be delegated down to owners and practitioners, but accountability for the outcome stays with senior management and the board, who set direction and provide oversight. That is why residual risk decisions and policy approval sit at the top even when the hands-on work sits several layers below.
Source: ISC2 Certified in Cybersecurity Exam Outline, Security Governance — governance: senior management direction, accountability and oversightReport a problem with this question
10. After mitigation, a documented level of residual risk remains on a business application. Whose formal acceptance does governance doctrine require before the system stays in production?
- A.The security analyst who measured the residual risk during the assessment
- B.The senior manager or system owner accountable for the business function✓ Answer
- C.The external auditor who will review the control set at the next audit
- D.The administrator who configured the mitigating controls on that system
Accepting risk is a business decision, not a technical one, so it must be made by the person who is accountable for the business function and who can bear the consequences — the senior manager or system or data owner. Analysts measure and advise, administrators implement, and auditors examine, but none of them can bind the organization to carry a loss.
Source: ISC2 Certified in Cybersecurity Exam Outline, Security Principles — risk management: risk treatment and acceptance of residual riskReport a problem with this question
11. A company writes and funds a patching requirement for all servers. It also runs monthly checks that verify and record whether each server was actually patched. Which term applies to each activity, in that order?
- A.Due diligence, then due care — the investigation first, then the record kept for the auditor.
- B.Due process, then due care — the formal procedure first, then the decision to fund it.
- C.Due care, then negligence — funding a control and re-checking it duplicates the same effort.
- D.Due care, then due diligence — the prudent action first, then the verification that proves it.✓ Answer
Due care is doing what a prudent organization would do — here, requiring and funding patching. Due diligence is the ongoing investigation, verification and documentation that shows the duty was actually discharged — here, the monthly checks and records. The pair matters legally: due care establishes the standard of conduct, and due diligence produces the evidence that the standard was met.
Source: ISC2 Certified in Cybersecurity Exam Outline, Security Principles — professional and ethical conduct (due care and due diligence)Report a problem with this question
12. An ISC2 member finds that a client's instruction to conceal a serious flaw would leave the public exposed to harm. The Code of Ethics canons apply in a set order. How should the conflict be resolved?
- A.The canon on diligent service to principals comes first, so the client's instruction settles the matter.
- B.The canon protecting society and public trust comes first, ahead of service to the client.✓ Answer
- C.The canons carry equal weight, so the member may pick whichever canon best suits the engagement.
- D.The canon on advancing the profession comes first, so the member should defer to the client quietly.
The ISC2 Code of Ethics canons are listed in order of precedence, and the first is to protect society, the common good, necessary public trust and confidence, and the infrastructure. Because that canon outranks the duty of diligent and competent service to principals, a member facing this conflict cannot conceal a flaw that would harm the public in order to satisfy a client.
Source: ISC2 Code of Ethics, Canons (Canon I: protect society, the common good, necessary public trust and confidence, and the infrastructure)Report a problem with this question
13. A review finds staff in several departments pasting customer data into public generative AI tools that the company never approved or inventoried. Which governance step should come FIRST?
- A.Issue an acceptable-use policy for AI and inventory the AI services already in use.✓ Answer
- B.Block all outbound internet traffic from the affected departments until the tools disappear.
- C.Ask each department to keep using the tools and to report anything unusual they notice.
- D.Buy an enterprise AI platform first, and write the governance documents after it is deployed.
This is shadow AI, and governance addresses it the same way it addresses any unsanctioned service: state the rule and find out what exists. An acceptable-use policy tells staff what data may and may not be given to AI services, and an AI asset inventory reveals the exposure that must be assessed. Policy and visibility precede technology purchases or blanket blocking, which treat symptoms without a decision basis.
Source: ISC2 Certified in Cybersecurity Exam Outline, Security Governance — GRC and foundational AI concepts (AI acceptable use, AI asset inventory)Report a problem with this question
14. A programme reports two figures monthly: the percentage of servers patched within the agreed window, and the number of privileged accounts without multifactor authentication, which escalates to the risk committee once it passes a set threshold. How are these best classified?
- A.The patch percentage is a key risk indicator, and the threshold-bound account count measures performance.
- B.Both are key performance indicators, because each one counts a condition that exists in the environment today.
- C.Both are key risk indicators, because any number reported to a risk committee is by definition a KRI.
- D.The patch percentage is a key performance indicator; the thresholded account count is a key risk indicator.✓ Answer
A key performance indicator says how well the programme is doing what it promised — patching inside the agreed window is performance against a target. A key risk indicator is forward-looking: it has a defined threshold and warns that exposure is rising before a loss occurs, which is exactly what the unprotected privileged account count does. The audience for a figure does not determine its type.
Source: ISC2 Certified in Cybersecurity Exam Outline, Security Governance — Measure cybersecurity effectiveness (key metrics, key risk indicators)Report a problem with this question
15. A risk committee asks the security lead to propose a key risk indicator rather than another status number. Which characteristic must the proposed measure have?
- A.It must count the security events that the monitoring team has already closed this quarter.
- B.It must signal rising exposure ahead of a loss, against a threshold that triggers escalation.✓ Answer
- C.It must compare the team's actual spending with the budget approved at the start of the year.
- D.It must summarize the audit findings that were raised and resolved during the previous cycle.
What separates a key risk indicator from an ordinary metric is direction and consequence: it is chosen because it moves before the loss does, and it carries a defined threshold that triggers escalation or action when crossed. Counts of closed events, spending against budget and past audit findings all describe what has already happened, so they report status rather than warn of it.
Source: ISC2 Certified in Cybersecurity Exam Outline, Security Governance — Measure cybersecurity effectiveness (key risk indicators)Report a problem with this question
16. A monthly report lists the number of blocked emails, the number of firewall denies and the number of alerts generated. Nobody has ever changed anything because of these numbers. What is the core problem with them?
- A.They are collected too frequently, and monthly counts of this kind should be gathered once a year.
- B.They are quantitative, and governance metrics must always be qualitative to be meaningful to a board.
- C.They are countable but not decision-useful, because no one has tied them to an objective or an action.✓ Answer
- D.They are produced by automated tools, and only a human-compiled figure counts as a security metric.
A useful metric is tied to an objective and is capable of changing a decision: if the number goes up or down, someone does something differently. Activity counts like blocked emails or firewall denies measure how busy the tooling is, not whether the organization is better protected, so they generate reporting effort without informing any choice. Quantitative and automated measurement is not the flaw.
Source: ISC2 Certified in Cybersecurity Exam Outline, Security Governance — Measure cybersecurity effectiveness (key metrics)Report a problem with this question
17. An executive is told that 312 vulnerabilities were open at month end. She asks what that tells her. What does the metric need in order to answer her question?
- A.A conversion of the count into a percentage, which makes any point-in-time number interpretable.
- B.A baseline and the trend over prior periods, so the figure can be read as improving or worsening.✓ Answer
- C.A comparison with a competitor's published count, which is the only valid reference for a metric.
- D.A finer breakdown by scanner and by subnet, which turns the raw count into a governance measure.
A point-in-time count carries no meaning on its own because there is nothing to compare it against. Establishing a baseline and reporting the trend across periods lets the reader see direction — the exposure is shrinking or growing — which is what supports a decision. Percentages, finer technical breakdowns and competitor figures do not supply that reference point.
Source: ISC2 Certified in Cybersecurity Exam Outline, Security Governance — Measure cybersecurity effectiveness (key metrics, trends and reporting)Report a problem with this question
18. Three artifacts are proposed: a screen the operations team watches through the shift, a quarterly sheet rating each control area against its target, and a written quarterly narrative explaining what changed and why. Which names them in order?
- A.Dashboard, report, scorecard — live monitoring, target ratings, then the written quarterly summary.
- B.Scorecard, report, dashboard — ranked results, live monitoring, then the periodic written summary.
- C.Report, dashboard, scorecard — detailed narrative, target ratings, then the operational screen.
- D.Dashboard, scorecard, report — real-time monitoring, performance against targets, narrative context.✓ Answer
Each delivery vehicle suits a different rhythm and audience. A dashboard is visual and near-real-time for operational monitoring; a scorecard is periodic and rates performance against defined targets or goals; a report is a periodic written narrative that supplies detail and context. Choosing the wrong vehicle is a common reporting failure, because the artifact sets the reader's expectation of how current and how detailed the information is.
Source: ISC2 Certified in Cybersecurity Exam Outline, Security Governance — Measure cybersecurity effectiveness (dashboards, score cards, reports)Report a problem with this question
19. A security manager has fifteen minutes to brief the board of directors. Which content choice fits that audience?
- A.A list of every critical vulnerability found this quarter, with each affected hostname and its score.
- B.A walkthrough of the firewall rule changes made since the last meeting, in the order they were applied.
- C.Exposure to the business stated in terms of impact, with the decisions the board is being asked to make.✓ Answer
- D.The raw alert counts from each monitoring tool, so the board can judge the technology's performance itself.
Reporting must match the audience. A board governs: it needs risk framed as business impact and a clear statement of the decisions or resources being requested, because that is what it can act on. Hostname lists, rule changes and raw alert counts are operational detail that belongs with the technical teams; presenting them to directors consumes the briefing without informing any governance decision.
Source: ISC2 Certified in Cybersecurity Exam Outline, Security Governance — Measure cybersecurity effectiveness (reports and audience)Report a problem with this question
20. A company runs an AI model that scores loan applications. Risk staff want an AI-specific key risk indicator on the governance dashboard. Which measure fits that purpose?
- A.Tracking model drift, so that degrading output quality is seen before decisions are harmed.✓ Answer
- B.Recording the vendor's published accuracy claim, restated on the dashboard every quarter.
- C.Counting the total inference requests served, which shows how popular the model has become.
- D.Logging the number of feature requests the business has filed against the model this year.
Model drift is the gradual divergence between the conditions a model was trained on and the conditions it now operates in, and it degrades output quality before anyone notices bad decisions. Because it moves ahead of the loss and can be given a threshold that triggers review or retraining, it behaves as a key risk indicator. Request volumes, vendor claims and feature requests describe usage or expectation, not rising exposure.
Source: ISC2 Certified in Cybersecurity Exam Outline, Security Governance — Measure cybersecurity effectiveness (AI-specific key risk indicators on dashboards and reports)Report a problem with this question
21. A continuity plan for a customer-facing AI service currently backs up only the application database. What else must be protected so the service can actually be restored?
- A.The marketing material and the user documentation published alongside that service.
- B.The model weights, the training datasets and the configuration it depends on.✓ Answer
- C.The vendor contract and the invoices paid for the graphics processing capacity used.
- D.The web analytics history showing how many users reached the service each day.
Restoring an AI service means restoring the thing that produces the answers, not only the records it stored. The trained model weights, the datasets used to build and retrain the model, and the configuration that assembles them are what make the service functional, so a plan that omits them leaves the organization able to recover data but not capability. Contracts, documentation and analytics are useful records but restore nothing.
Source: ISC2 Certified in Cybersecurity Exam Outline, Security Governance — understand redundancy (backing up configurations, model weights and training datasets for AI services)Report a problem with this question
22. Awareness material at a firm teaches staff to spot phishing by looking for clumsy grammar and odd formatting. Why must that guidance be updated now that attackers use generative AI?
- A.AI writes fluent, personalized lures and clones voices, so wording is no longer a reliable tell.✓ Answer
- B.AI has made phishing so rare that awareness content should move on to other attack types.
- C.AI-generated messages are always blocked at the mail gateway, so users need no guidance at all.
- D.AI only affects voice calls, so the written awareness guidance can be left exactly as it is.
Generative AI removes the surface flaws that awareness programmes taught people to look for: it produces fluent, well-formatted, personalized messages at scale and can clone a familiar voice for a phone call or a recorded request. Awareness content therefore has to shift from spotting bad language to verifying the request itself through a known-good channel and reporting anything unexpected to the security team.
Source: ISC2 Certified in Cybersecurity Exam Outline, Security Governance — understand security awareness (AI amplifying social engineering and phishing)Report a problem with this question
Practice questions based on the ISC2 Certified in Cybersecurity (CC) Exam Outline. This site is not affiliated with or endorsed by ISC2, and these are not real exam questions. ISC2 revises the domains and their weights periodically and sets the exam length, passing standard and eligibility terms — confirm the current outline and requirements with ISC2 before you register. Official CC exam outline →