Skip to content

Governance, Risk, and Compliance Questions

Practice questions for Governance, Risk, and Compliance topic in CompTIA SecurityX. 20 questions covering this domain.

20 questions8 easy7 medium5 hard
Q1
hard

A security program manager receives audit findings indicating that security controls are not consistently applied across business units. The root caus...

Q2
hard

An organization's security team has completed a quantitative risk assessment. The ALE for a specific threat scenario is $500,000. A proposed control c...

Q3
easy

What does a RACI matrix define in a security program?

Q4
easy

Which document type in a security program defines the mandatory rules that all employees must follow?

Q5
medium

An organization operating in the payment card industry must select a compliance framework to govern cardholder data protection. Which industry-specifi...

Q6
easy

Which threat modeling framework categorizes threats using the mnemonic STRIDE?

Q7
easy

Which risk assessment method assigns numerical monetary values to assets and potential losses?

Q8
medium

During a threat modeling session for a new web application, the team maps all external data flows crossing trust boundaries. Which threat modeling art...

Q9
medium

A GRC analyst needs to maintain a record of all hardware and software assets along with their configuration states across the enterprise. Which tool c...

Q10
medium

A security architect is reviewing a third-party SaaS provider contract. The provider will process regulated financial data on behalf of the organizati...

Q11
medium

A security architect is asked to assess the attack surface of a newly proposed API integration between two business systems. Which artifact should the...

Q12
easy

Which compliance framework provides a set of controls and management guidelines specifically aligned to information security management systems (ISMS)...

Q13
easy

Which IT governance framework provides a set of principles and practices for governing and managing enterprise IT, including security oversight?

Q14
easy

Which component of the MITRE ATT&CK framework describes the specific methods adversaries use to achieve a tactical objective?

Q15
hard

A security program manager discovers that the organization relies heavily on a single cloud provider for critical business operations, with no alterna...

Q16
hard

An organization subject to ISO/IEC 27001 certification is preparing for its surveillance audit. The auditor will specifically examine whether the orga...

Q17
medium

An organization's security team conducts an annual phishing simulation as part of its security awareness program. After the simulation, users who clic...

Q18
medium

A GRC analyst is mapping organizational security controls to multiple regulatory frameworks simultaneously. Which GRC tool capability BEST supports th...

Q19
hard

A multinational organization must comply with both PCI DSS and ISO/IEC 27001 simultaneously. The security team wants to avoid maintaining two complete...

Q20
easy

What is the purpose of a data governance policy that distinguishes between production, development, testing, and QA environments?

Sign in to see all 20 questions

Create a free account to browse all questions — completely free during our launch phase.