ISC2 CAP | Certified Authorization Professional (CGRC) Exam Guide & Practice Questions
The ISC2 CAP examination, officially titled the Certified Authorization Professional and transitioned by ISC2 to Certified in Governance, Risk and Compliance (CGRC), is the premier credential for information security professionals responsible for authorizing, securing, and maintaining enterprise information systems within formal risk management frameworks. Administered globally by ISC2, this certification validates an engineer’s and risk manager's expertise in executing the National Institute of Standards and Technology (NIST) Risk Management Framework (RMF), establishing security control baselines, assembling authorization packages, and ensuring continuous regulatory compliance across commercial, federal civilian, and defense infrastructures.
Modern digital governance requires structured oversight rather than disconnected defensive measures. Federal agencies, defense industrial base contractors, and regulated financial and healthcare institutions must obtain and defend an Authority to Operate (ATO) under strict legal mandates like FISMA, FedRAMP, HIPAA, and DoD standards. Information System Security Officers (ISSOs), Security Control Assessors (SCAs), and Authorizing Officials (AOs) must know how to categorize systems based on impact levels, select and tailor NIST SP 800-53 controls, assess control implementation efficacy, manage Plan of Action and Milestones (POA&M) documents, and maintain continuous monitoring.
Practicing with verified CAP certification exam questions enables candidates to master scenario-based stems, distinguish between governance roles, and navigate complex authorization challenges under timed testing conditions. Utilizing targeted ISC2 CAP practice questions ensures complete alignment with the official ISC2 examination blueprint.
Official ISC2 Exam Information
Attribute | Official ISC2 Specification |
Exam Vendor | ISC2 (International Information System Security Certification Consortium) |
Exam Code | CAP (transitioned to CGRC in the ISC2 credential portfolio) |
Exam Name | Certified Authorization Professional / Certified in Governance, Risk and Compliance (CGRC) |
Associated Credential | Certified in Governance, Risk and Compliance (CGRC, formerly CAP) |
Target Audience | ISSOs, ISSMs, Security Control Assessors (SCAs), Authorizing Official Designated Representatives (AODRs), GRC Analysts, and Defense Contractors |
Testing Delivery Partner | Pearson VUE (Authorized Physical Testing Centers) |
Exam Duration | 3 Hours (180 Minutes) |
Number of Questions | 125 Questions (100 scored items, 25 unscored pretest questions) |
Question Formats | Multiple Choice and Advanced Innovative Item Types |
Passing Score | 700 out of 1000 Scaled Points |
Experience Requirement | 2 years of cumulative, paid work experience in 1 or more of the 7 exam domains |
Associate Option | Candidates without 2 years of experience can become an Associate of ISC2 with 3 years to satisfy requirements |
Official Training | Official ISC2 Online Self-Paced Training & CGRC CBK Courseware |
Exam Registration Fee | $599 USD |
Retake Policy | Attempt 1 to 2: 30-day wait; Attempt 2 to 3: 60-day wait; Attempt 3 to 4: 90-day wait (Max 4 attempts per 12-month period) |
Credential Maintenance | 3-Year Cycle: 60 Continuing Professional Education (CPE) credits total plus $135 USD Annual Maintenance Fee (AMF) |
Curriculum Freshness | Verified September 2026 (Reflecting Official ISC2 CGRC/CAP Blueprint) |
Career Opportunities & Industry Benefits
Department of Defense (DoD) & Federal Mandate Mapping: Fully recognized and mapped under the DoD 8140/8570 workforce framework, satisfying mandatory requirements for Information Assurance Management (IAM Level I/II) and cybersecurity assessment roles.
High Demand in Government & Defense Contracting: Serves as the primary credential sought by aerospace, defense, and civilian contractors responsible for securing government IT backbones, cloud FedRAMP enclaves, and intelligence systems.
Core Job Roles: Information System Security Officer (ISSO), Information System Security Manager (ISSM), Security Control Assessor (SCA), GRC Architect, Authorizing Official Representative, and Compliance Project Manager.
Lucrative Earning Potential: Professionals possessing authorization and RMF expertise command substantial compensation packages, with average annual salaries ranging between $115,000 and $165,000+ depending on operational clearance levels and defense program scope.
Official Syllabus Percentage Breakdown (7 Blueprint Domains)
The ISC2 CAP / CGRC examination evaluates candidate proficiency across seven core domains aligned with the complete risk management and system authorization lifecycle:
Domain # | Official Blueprint Domain | Percentage Weight | Core Framework & Lifecycle Focus |
Domain 1 | Security and Privacy Governance, Risk Management, and Compliance Program | 16% | Governance principles, RMF integration, regulatory landscape (FISMA, FedRAMP, HIPAA), SDLC |
Domain 2 | Scope of the System | 10% | System boundary definition, information types, FIPS 199 impact categorization, system architecture |
Domain 3 | Selection and Approval of Framework, Security, and Privacy Controls | 14% | Baseline allocation (NIST SP 800-53B), tailoring, overlays, control inheritance, monitoring strategy |
Domain 4 | Implementation of Security and Privacy Controls | 17% | System Security Plan (SSP), control documentation, mandatory/compensating controls, engineering integration |
Domain 5 | Assessment/Audit of Security and Privacy Controls | 16% | Assessment planning (NIST SP 800-53A), Examine/Interview/Test methods, SAR generation, finding remediation |
Domain 6 | System Compliance | 14% | Authorization package compilation (SSP, SAR, POA&M), residual risk analysis, AO authorization decisions (ATO) |
Domain 7 | Compliance Maintenance | 13% | Continuous monitoring (ConMon), ongoing assessments, configuration change control, decommissioning |
Detailed Exam Blueprint & Core Technical Concepts
1.0 Governance, Risk Management & Regulatory Foundations (Domain 1)
Risk Management Framework (RMF) Lifecycle: Operationalizing the seven steps of NIST SP 800-37 Rev. 2: Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor.
Organizational Roles and Responsibilities: Establishing operational boundaries between the Authorizing Official (AO), Authorizing Official Designated Representative (AODR), Information System Owner (ISO), Information System Security Officer (ISSO), and Security Control Assessor (SCA).
Legal and Regulatory Mandates: Navigating the Federal Information Security Modernization Act (FISMA), Federal Risk and Authorization Management Program (FedRAMP), Privacy Act of 1974, HIPAA/HITECH, and OMB Circular A-130.
System Development Life Cycle (SDLC) Integration: Integrating privacy and cybersecurity controls into each phase of the SDLC (Initiation, Development/Acquisition, Implementation/Assessment, Operations/Maintenance, Disposal) to minimize authorization delays.
2.0 Scoping & Categorization (Domain 2)
System Boundary Identification: Differentiating internal system components from external dependencies, interconnection security agreements (ISAs), and shared cloud infrastructure boundaries.
Information Types and Categorization: Identifying data types stored, processed, or transmitted using NIST SP 800-60; applying FIPS Publication 199 security categorization baselines.
The High-Water Mark Principle: Evaluating potential impact levels (Low, Moderate, High) across the core security objectives (Confidentiality, Integrity, and Availability) to assign the system's overall security category.
3.0 Control Selection, Tailoring & Implementation (Domains 3 & 4)
NIST SP 800-53 Rev. 5 Control Catalog: Navigating 20 control families (e.g., AC Access Control, AU Audit and Accountability, IA Identification and Authentication, SC System and Communications Protection).
Control Baselines & Overlays: Selecting initial control baselines using NIST SP 800-53B; applying specialized overlays (e.g., privacy overlays, cloud overlays, national security system overlays).
Tailoring and Inheritance: Tailoring baseline controls through scoping guidance, parameter assignments, and compensating controls; distinguishing between Common Controls (inherited from an enterprise hosting provider), Hybrid Controls, and System-Specific Controls.
System Security Plan (SSP) Formulation: Documenting system boundaries, operational environment, interconnected systems, and precise descriptions of how each security and privacy control is satisfied.
4.0 Assessment, Authorization & Continuous Monitoring (Domains 5, 6 & 7)
Security Assessment Methodologies: Developing the Security Assessment Plan (SAP) based on NIST SP 800-53A; executing assessment actions across three foundational testing methods:
Examine: Reviewing policies, specifications, system architecture diagrams, and audit logs.
Interview: Conducting structured discussions with engineers, administrators, and stakeholders.
Test: Executing automated vulnerability scanners, penetration tests, and manual verification scripts.
The Authorization Package: Compiling the three mandatory artifacts presented to the Authorizing Official:
System Security Plan (SSP): Comprehensive control implementation details.
Security Assessment Report (SAR): Independent findings and assessment results.
Plan of Action and Milestones (POA&M): Planned remediation corrective actions, resource costs, and milestone completion target dates.
Authorizing Official Decisions: Analyzing residual risk against organizational risk tolerance to issue formal determinations: Authorization to Operate (ATO), Authorization to Operate with Conditions, Interim Authority to Test (IATT), or Denial of Authorization to Operate (DATO).
Continuous Monitoring (ConMon): Executing ongoing assessment of control effectiveness (NIST SP 800-137); managing Security Content Automation Protocol (SCAP) telemetry; evaluating configuration drift; conducting system decommissioning and data sanitization (NIST SP 800-88).
Official Exam Format & Testing Rules
Linear Test Delivery: The CAP / CGRC exam is a fixed-form, non-adaptive computer-based test delivered at Pearson VUE test centers. Every candidate receives 125 questions across a 3-hour (180-minute) testing session.
Scored vs. Unscored Questions: Out of the 125 total questions, exactly 100 questions are scored, while 25 items are unscored experimental pretest questions used by ISC2 to validate future exam forms. Pretest questions are indistinguishable from scored questions, so treat every question with equal diligence.
Scaled Passing Standard: The exam requires a scaled passing score of 700 out of 1000 points. Because question difficulties are psychometrically weighted, raw question percentages do not correspond directly to 70%.
Time Management Strategy: With 125 questions over 180 minutes, you have roughly 86 seconds per item. Scenarios describing system architectures, interconnectivity challenges, or assessor findings require focused, disciplined reading to avoid running out of time.
Proven Preparation Strategy
Master the Exact Flow of the NIST RMF
Know the Distinct Responsibilities of RMF Roles
Understand Common Control Inheritance
Train with Realistic Scenario Testlets
Prepare for Your Certification Today
Validating your ability to navigate the complete Risk Management Framework lifecycle, assemble defensible authorization packages, evaluate residual risk, and maintain continuous compliance is essential for high-level federal and enterprise GRC roles.
Strengthen your command of NIST standards and ATO workflows, evaluate realistic authorization scenarios, and test your knowledge using free CAP dumps to ensure you achieve certification success on your first attempt.
Start practicing now and pass your ISC2 CAP exam with confidence at ExamTopicsBase.