SaveMyCert
Log in
5 of 5 free questions left today·for 30 a day
CC · Domain 2

Security Governance practice questions

Security Governance is worth 17% of the CC exam — the 4th-heaviest of the 5 domains. Governance, Risk, and Compliance; redundancy (BC/DR); security awareness; and measuring effectiveness. Official weighting 17.3%. 6 fully worked examples are further down this page, answers included.

Exam weight
17%
the 4th-heaviest of the 5 domains
Questions
80
across 4 topics
Free, no account
5/day
sign up free to remove the cap
Explanations
Every option
right and wrong

Build a practice session

5 free questions left today.

Domains

How many?

Mode

Ready when you are

10 fresh questions drawn across 1 of 5 domains, in Learn mode.

Focused review

Every question you answer incorrectly, and every question you flag while practising, is saved here automatically. Finish a session and you can come back to re-drill just those.

6 sample Security Governance questions, fully explained

Questions from the CC bank mapped to domain 2, with the answer key and the reasoning behind every option. None of them repeat the examples on the main CC practice page.

Question 1Security Governance

In the context of security, what is the primary role of governance?

Choose one.

  • a
    Leadership sets direction, establishes policy, and assigns accountability for security Correct

    Governance is the function through which senior leadership defines objectives, approves policy, and holds people accountable so security supports the business.

  • b
    Technicians configure firewalls and endpoint protection tools

    Configuring controls is an operational task carried out under governance direction, not governance itself.

  • c
    Auditors test controls to confirm they meet regulatory requirements

    Testing controls against regulations is a compliance and audit activity, not the leadership direction-setting role of governance.

  • d
    Analysts monitor logs for suspicious activity around the clock

    Log monitoring is a day-to-day security operations function, which executes under the direction that governance provides.

The concept

Governance is how organizational leadership directs and oversees security. Leaders define objectives, approve policies, allocate authority, and assign accountability so security activity aligns with business goals.

Why that’s the answer

Setting direction, establishing policy, and assigning accountability is the definition of governance. Configuring tools, auditing controls, and monitoring logs are all execution or verification activities performed under that governance, not governance itself.

How to reason it out
  1. Ask whether the activity is about deciding and overseeing or about doing the work.
  2. Governance activities involve leadership decisions such as policy approval and accountability assignment.
  3. Eliminate the options describing hands-on technical work or audit testing, which are execution and verification tasks.

Exam tip: Governance is leadership setting direction, policy, and accountability; it oversees rather than performing the technical work.

Governance, Risk, and Compliance (GRC) for the ISC2 CC Exam — the lesson that teaches this.

Question 2Security Governance

Which statement best describes compliance in a GRC program?

Choose one.

  • a
    Meeting only the requirements imposed by government regulators

    Compliance is broader than government regulation; an organization must also comply with its own internal policies, standards, and contractual obligations.

  • b
    Eliminating all security risk from the organization

    No program eliminates all risk; risk management reduces risk to an acceptable level, and compliance is about meeting stated requirements.

  • c
    Encrypting all data so that outside parties cannot read it

    Encryption is a technical control that may support certain requirements; it is not the definition of compliance.

  • d
    Meeting the requirements of external laws and regulations as well as internal policies Correct

    Compliance covers both external obligations, such as laws and regulations, and adherence to the organization's own internal policies and standards.

The concept

Compliance means conforming to requirements. Those requirements come from outside the organization, such as laws, regulations, and contracts, and from inside it, such as policies, standards, and procedures the organization has adopted.

Why that’s the answer

The correct option captures both halves: external laws and regulations plus internal policies. The distractors either narrow compliance to regulators only, confuse it with eliminating risk, or reduce it to a single technical control.

How to reason it out
  1. Recall that compliance obligations have two sources: external and internal.
  2. External sources include laws, regulations, and contracts; internal sources include the organization's own policies and standards.
  3. Eliminate options that mention only one source or that describe risk elimination or a specific control.

Exam tip: Compliance means meeting both external legal and regulatory requirements and the organization's own internal policies.

Governance, Risk, and Compliance (GRC) for the ISC2 CC Exam — the lesson that teaches this.

Question 3Security Governance

Within a GRC program, what does the risk discipline primarily involve?

Choose one.

  • a
    Removing every possible threat to the organization

    Threats cannot all be removed; risk management reduces and manages risk to an acceptable level rather than promising elimination.

  • b
    Identifying and managing risks so they stay within the appetite leadership has set Correct

    Risk management identifies, assesses, and treats risks so the organization operates within the level of risk its leadership has declared acceptable.

  • c
    Writing the disciplinary policy for employees who violate rules

    Disciplinary policy is a governance and human resources matter; it is not the core of the risk management discipline.

  • d
    Purchasing the newest security products every year

    Buying products is a procurement decision; controls should be selected based on assessed risk, not on a fixed purchasing schedule.

The concept

In GRC, the risk discipline is the ongoing process of identifying, assessing, and treating risks. Leadership sets the risk appetite, and risk management keeps the organization's actual risk exposure within that boundary.

Why that’s the answer

Managing risk within the appetite leadership sets is the textbook description of the risk component. Eliminating every threat is impossible, and disciplinary policies or product purchases are not what the risk discipline means.

How to reason it out
  1. Recall that leadership defines risk appetite as part of governance.
  2. Risk management then identifies, assesses, and treats risks to stay within that appetite.
  3. Eliminate options promising total elimination of threats or describing unrelated policy and purchasing activities.

Exam tip: Risk management keeps organizational risk within the appetite that leadership defines; it manages risk, it does not eliminate it.

Governance, Risk, and Compliance (GRC) for the ISC2 CC Exam — the lesson that teaches this.

Question 4Security Governance

What is the key difference between governance and management in an organization?

Choose one.

  • a
    Governance handles technical work and management handles strategy

    This reverses the roles; governance is the strategic, direction-setting layer and management runs the operational work.

  • b
    Governance and management are two names for the same function

    They are distinct functions; blending them removes the oversight that lets leadership independently verify that management is delivering.

  • c
    Governance decides direction and verifies outcomes, while management executes day-to-day activities Correct

    Governance sets objectives and policy and checks that results are achieved, while management plans and runs the operations that carry out that direction.

  • d
    Management approves policies and governance implements them

    This is backwards; governance approves policies and management implements them through procedures and operations.

The concept

Governance and management are complementary but separate. Governance, exercised by boards and senior leadership, decides direction, approves policy, and verifies results. Management executes: it plans, builds, runs, and monitors within the direction governance sets.

Why that’s the answer

Decide and verify versus execute is the classic distinction. The distractors either reverse the roles, merge the two functions, or invert who approves and who implements policy.

How to reason it out
  1. Assign strategic decisions, policy approval, and verification of outcomes to governance.
  2. Assign planning, implementation, and daily operation to management.
  3. Check each option against this split and eliminate any that swap or merge the roles.

Exam tip: Governance decides and verifies; management executes. Think of it as direction from the top, execution below.

Governance, Risk, and Compliance (GRC) for the ISC2 CC Exam — the lesson that teaches this.

Question 5Security Governance

Who is responsible for defining the organization's risk appetite?

Choose one.

  • a
    The help desk team that handles user tickets

    The help desk resolves user support issues; it has no authority to decide how much risk the whole organization will accept.

  • b
    External regulators who inspect the organization

    Regulators impose minimum legal requirements, but the organization's own leadership decides its appetite for risk beyond those obligations.

  • c
    Each individual employee, based on personal judgment

    If every employee chose a personal risk tolerance, decisions would be inconsistent; appetite must be set centrally by leadership so everyone works to the same boundary.

  • d
    Senior leadership, such as the board and executives Correct

    Deciding how much risk the organization is willing to accept is a governance decision, so it belongs to the board and executive leadership.

The concept

Risk appetite is the amount and type of risk an organization is willing to accept in pursuit of its objectives. Because it shapes strategy and resource decisions across the whole organization, defining it is a governance responsibility held by senior leadership.

Why that’s the answer

Only the board and executives have the authority and the organization-wide view needed to declare how much risk is acceptable. Support staff and individual employees operate within that appetite, and regulators set legal minimums rather than the organization's appetite.

How to reason it out
  1. Recall that risk appetite is an organization-wide boundary, not a per-team preference.
  2. Organization-wide boundaries are set through governance, which is exercised by senior leadership.
  3. Eliminate operational staff, outside regulators, and individual employees as the source of that decision.

Exam tip: Risk appetite comes from the top: senior leadership defines it, and risk management works within it.

Governance, Risk, and Compliance (GRC) for the ISC2 CC Exam — the lesson that teaches this.

Question 6Security Governance

An organization passes its annual regulatory audit but suffers a serious breach two months later. What does this scenario best illustrate?

Choose one.

  • a
    The audit must have been fraudulent

    A legitimate audit can be passed honestly and a breach can still occur, because audits verify requirements rather than guarantee protection against every attack.

  • b
    Regulations always exceed what real security requires

    The scenario shows the opposite tendency; regulations set a baseline that may fall short of what defending against real attacks requires.

  • c
    Audits cause breaches by revealing weaknesses to attackers

    Audit results are not shared with attackers; audits exist to find and fix weaknesses, not to expose them publicly.

  • d
    Being compliant is not the same as being secure Correct

    Compliance shows the organization met a defined set of requirements at a point in time; attackers are not limited to what a checklist covers, so compliant organizations can still be breached.

The concept

Compliance means meeting a defined set of requirements, while security means actually protecting assets against threats. Requirements are a baseline and a snapshot in time; threats evolve continuously, so meeting the baseline does not guarantee protection.

Why that’s the answer

Passing an audit and then being breached is the classic illustration that compliance and security are related but different goals. The other options invent audit fraud, overstate regulations, or wrongly blame the audit for the breach.

How to reason it out
  1. Note that the audit verified compliance with a fixed set of requirements at one point in time.
  2. Note that attackers exploit any weakness, including ones no requirement covers.
  3. Conclude that compliance is a baseline that supports security but does not guarantee it.

Exam tip: Compliance is a minimum baseline, not proof of security; an organization can be fully compliant and still be breached.

Governance, Risk, and Compliance (GRC) for the ISC2 CC Exam — the lesson that teaches this.

What CC domain 2 tests, topic by topic

The official exam guide breaks Security Governance into 4 topics. The question bank follows the same split, so a weak topic shows up as a cluster of misses you can go back and read.

Published CC practice questions per topic in Security Governance
TopicWhat it coversQuestions
Plan Governance, Risk, and Compliance (GRC)Official CC sub-domain (Security Governance, Sept-2026 outline). The purpose and importance of Governance, Risk, and Compliance (GRC), and GRC frameworks and tools.20
Understand redundancyOfficial CC sub-domain. Redundancy through Business Continuity (BC) and Disaster Recovery (DR).20
Understand security awarenessOfficial CC sub-domain. Organizational culture (importance of security, security leadership) and awareness concepts (social engineering, password protection, phishing).20
Measure cybersecurity effectivenessOfficial CC sub-domain. Key metrics and Key Risk Indicators (KRIs); and dashboards, scorecards, and reports.20
Total80

Revise Security Governance before you drill it

Other CC domains

Security Governance: your questions

Security Governance is domain 2 of the CC exam guide and carries 17% of the scored content — the 4th-heaviest of the 5 domains. On a 100-question paper that works out to roughly 17 questions, though ISC2 does not publish an exact per-domain count and individual exam forms vary.

Source

The domain weight and topic list on this page come from the official CC exam guide.