Prepare for the Certified in Governance, Risk and Compliance (CGRC) certification by ISC² with free exam-style practice questions on CyberCertPrep. The CGRC exam has 125 questions, a time limit of CGRC hours, and a passing score of 70%.
Choose from Practice mode, Exam Simulation, Weak Areas review, and Daily Challenge. Track your progress with detailed analytics and study with flashcards.
Certified in Governance, Risk and Compliance (CGRC) Exam Domain
Focus your study on this domain with targeted practice questions. This domain accounts for 11% of your CGRC exam score.
The Authorization/Approval of Information System domain is one of 7 exam domains on the Certified in Governance, Risk and Compliance (CGRC) certification exam by ISC². At 11% of the total exam, this domain is important but should be balanced with higher-weighted domains in your study plan.
The CGRC exam consists of 125 questions with a time limit of 3 hours and a passing score of 70%. That means approximately 14 questions on your exam will come from the Authorization/Approval of Information System domain.
Access Control List (ACL)
A list of permissions attached to an object that specifies which users or system processes are granted access to resourc...
Authentication
The process of verifying the identity of a user, device, or system before granting access to resources. Authentication t...
Authorization
The process of determining what resources or actions an authenticated user is permitted to access. While authentication ...
Least Privilege
The principle of giving users, processes, and systems only the minimum levels of access needed to perform their job func...
Role-Based Access Control (RBAC)
An approach to restricting system access to authorized users based on their role within an organization rather than indi...
Firewall
A network security system that monitors and controls incoming and outgoing network traffic based on predetermined securi...
IDS (Intrusion Detection System)
A device or software application that monitors a network or systems for malicious activity or policy violations and gene...
IPS (Intrusion Prevention System)
A network security tool that monitors network traffic flows to detect and actively prevent identified threats in real ti...
These certifications also cover topics related to Authorization/Approval of Information System:
Systems & Application Security — 14% of exam
Information Security Governance — 17% of exam
Information Systems Auditing Process — 21% of exam
Information Technology & Security — 22% of exam
Intrusion Detection Systems — 25% of exam
Information Security & Ethical Hacking Overview — 6% of exam