Prepare for the Certified in Governance, Risk and Compliance (CGRC) certification by ISC² with free exam-style practice questions on CyberCertPrep. The CGRC exam has 125 questions, a time limit of CGRC hours, and a passing score of 70%.
Choose from Practice mode, Exam Simulation, Weak Areas review, and Daily Challenge. Track your progress with detailed analytics and study with flashcards.
Certified in Governance, Risk and Compliance (CGRC) Exam Domain
Focus your study on this domain with targeted practice questions. This domain accounts for 13% of your CGRC exam score.
The Risk Management Framework domain is one of 8 exam domains on the Certified in Governance, Risk and Compliance (CGRC) certification exam by ISC². At 13% of the total exam, this domain is important but should be balanced with higher-weighted domains in your study plan.
The CGRC exam consists of 125 questions with a time limit of 3 hours and a passing score of 70%. That means approximately 16 questions on your exam will come from the Risk Management Framework domain.
Access Control List (ACL)
A list of permissions attached to an object that specifies which users or system processes are granted access to resourc...
Multi-Factor Authentication (MFA)
A security mechanism that requires two or more independent credentials to verify a user's identity, combining factors fr...
Single Sign-On (SSO)
An authentication scheme that allows a user to log in with a single set of credentials to access multiple applications a...
Zero Trust
A security model that requires strict identity verification for every person and device attempting to access resources, ...
IPS (Intrusion Prevention System)
A network security tool that monitors network traffic flows to detect and actively prevent identified threats in real ti...
SIEM (Security Information and Event Management)
A software solution that aggregates and analyzes security data from across the organization — including logs from firewa...
Ransomware
A type of malware that encrypts a victim's files or locks system access and demands a ransom payment (typically in crypt...
Cross-Site Scripting (XSS)
A web security vulnerability that allows attackers to inject malicious client-side scripts (usually JavaScript) into web...
These certifications also cover topics related to Risk Management Framework:
Risk Management — 12% of exam
Risk Identification, Monitoring and Analysis — 13% of exam
Governance Risk — 13% of exam
Security and Risk Management — 13% of exam
Information Risk Management — 13% of exam
Governance Management — 13% of exam