GRC Analyst interview questions
100 real questions with model answers and explanations for Junior candidates.
See a GRC Analyst resume example →Practice with flashcards
Spaced repetition · Hunter Pass
Questions
Governance sets direction and accountability, risk management handles uncertainty, and compliance tracks obligations and proof.
- Governance appears in artifacts such as committee charters, approved policies, decision rights, and reporting cadence.
- Risk work identifies scenarios, rates likelihood and impact, assigns owners, and records treatment in the risk register.
- Compliance work maps laws, contracts, and frameworks to controls, then collects evidence that those controls operate.
Why interviewers ask this: The interviewer checks whether you connect each part of GRC to distinct work products rather than treating the acronym as one activity.
Governance turns leadership decisions into documented authority, rules, and oversight routines.
- An information security policy states management's direction and names accountable roles.
- A risk committee charter defines membership, decision rights, quorum, and escalation thresholds.
- Meeting minutes and approved action logs show that leaders reviewed risks and assigned follow-up work.
Why interviewers ask this: A strong answer names governance artifacts that make decisions traceable instead of describing governance as general management.
They form different layers of direction, from mandatory intent to optional advice.
- A policy states a mandatory management rule, such as requiring access to follow least privilege.
- A standard gives mandatory measurable detail, such as requiring MFA for all privileged accounts.
- A procedure lists the steps to perform a task, such as the Okta access-review workflow.
- A guideline recommends a useful approach but allows justified alternatives, such as suggested password-manager practices.
Why interviewers ask this: The interviewer evaluates whether you can classify common documents by authority and level of detail.
I would place the measurable requirement in an access-control standard and link it to the broader access policy.
- The policy should state management's requirement for strong authentication and controlled privileged access.
- The standard should name the covered accounts, approved factors such as FIDO2 security keys, and any deadline.
- The implementation procedure should show how administrators enroll the factor and how reviewers verify enrollment.
- Any temporary deviation should reference an approved exception record rather than weakening the standard text.
Why interviewers ask this: A strong answer places one concrete requirement in the correct document hierarchy and preserves exception traceability.
A control objective states the result needed, while a control activity is the specific action used to achieve it.
- An objective might be that production access is limited to authorized personnel.
- A related activity could be a quarterly Okta access review approved by each application owner.
- The control narrative should connect the activity, frequency, owner, evidence, and population back to the objective.
Why interviewers ask this: The interviewer checks whether you can turn a broad control goal into a testable recurring activity.
A control owner is accountable for keeping the control defined, performed, evidenced, and corrected when it fails.
- The owner confirms the control narrative, frequency, systems in scope, and people who perform or review it.
- The owner provides evidence such as an Okta export and signed review record for the requested period.
- If testing finds an exception, the owner agrees on remediation, a due date, and any interim control.
- A GRC analyst coordinates and tests the record but does not silently become the owner of every control.
Why interviewers ask this: A strong answer separates control accountability from the GRC analyst's coordination and testing role.
A manual control relies on a person, an automated control runs through configured technology, and a hybrid control combines both.
- A manager's quarterly review of an Okta access report is manual because the decision requires human judgment.
- An Okta rule that blocks access without MFA is automated, so testing should inspect its configuration, change history, and logs.
- A hybrid control may have AWS Config flag a public bucket and an analyst review and resolve the alert.
- Automation reduces repetitive effort but does not make a poorly scoped or misconfigured control effective.
Why interviewers ask this: The interviewer checks whether you can distinguish how controls operate and select evidence for their human and system-driven steps.
Yes, but the control record should distinguish the separate activities and evidence supporting each function.
- An identity platform may prevent an unapproved role assignment through an approval workflow.
- The same platform may produce a report that detects dormant privileged accounts during a monthly review.
- I would document the approval log and review report separately so a tester can verify each purpose.
- Calling the whole platform a control is too broad because the configured activities are what auditors test.
Why interviewers ask this: A strong answer recognizes mixed control functions while keeping the tested activities and evidence precise.
Design effectiveness asks whether the control, if performed as written, can reasonably achieve its objective.
- I would check whether the control covers the correct systems, population, frequency, owner, and risk.
- A quarterly review of only employees is poorly designed if contractors also have production access.
- A walkthrough, control narrative, process diagram, and configured workflow can support the design assessment.
- Good design does not prove the activity actually happened during the audit period.
Why interviewers ask this: The interviewer evaluates whether you can identify a design gap before looking at execution evidence.
Operating effectiveness asks whether the control ran as designed, at the required frequency, throughout the tested period.
- For a quarterly access review, I would expect four completed reviews in a twelve-month period.
- Samples should show timely reviewer approval, the complete user population, and follow-up on identified access removals.
- A missed quarter or unsigned review is an operating exception even when the control design is sound.
- Testing results should state the period, sample, evidence examined, exception, and conclusion.
Why interviewers ask this: A strong answer distinguishes evidence of repeated execution from evidence that the control was merely well designed.
A SOC 2 examination is an independent attestation on controls relevant to selected Trust Services Criteria.
- Management defines the service organization's system, scope, commitments, and controls.
- A licensed CPA firm performs the examination under AICPA attestation standards and issues the report.
- The report is generally restricted-use material shared with customers and other parties who understand the service.
- SOC 2 is not a government certification or a guarantee that the service has no security weaknesses.
Why interviewers ask this: The interviewer checks whether you understand SOC 2 as a scoped CPA attestation rather than a universal security certificate.
Type I addresses control design at a specified date, while Type II also tests operating effectiveness over a period.
- A Type I report can support an initial readiness milestone because its opinion is tied to an as-of date.
- A Type II report covers a stated review period, often several months, and includes tests of controls and results.
- Evidence for Type II must demonstrate recurring operation, such as every quarterly review within the period.
- Neither type automatically covers systems or criteria excluded from the report scope.
Why interviewers ask this: A strong answer clearly distinguishes an as-of design opinion from testing performance over time.
The categories are Security, Availability, Processing Integrity, Confidentiality, and Privacy.
- Security, also called the common criteria, is included in every SOC 2 examination.
- Availability addresses commitments for system operation, while Processing Integrity addresses complete, valid, accurate, timely, and authorized processing.
- Confidentiality concerns information designated as confidential, while Privacy concerns personal information across its lifecycle.
- The engagement scope should include only categories supported by actual customer commitments and system risks.
Why interviewers ask this: The interviewer checks whether you know the five categories and can state what each adds to the report scope.
The system description, selected Trust Services Criteria, boundaries, commitments, and control inventory make the scope testable.
- The system description identifies services, infrastructure, software, people, procedures, data, and relevant subservice organizations.
- An in-scope inventory names the applications, cloud accounts, locations, and teams supporting the service.
- A criteria-to-control matrix shows which controls address each selected criterion.
- Scope changes should be versioned because adding a service or vendor can change the population and evidence requests.
Why interviewers ask this: A strong answer names the artifacts that let an auditor connect the described service to systems and controls.
An information security management system is the governed set of processes used to manage information security risk within a defined scope.
- The ISMS includes scope, leadership responsibilities, risk assessment, risk treatment, objectives, competence, documentation, and performance evaluation.
- Records such as the risk register, Statement of Applicability, internal audit, and management review show the system operating.
- Continual improvement means nonconformities and changing risks feed corrective actions and updates.
- The ISMS is broader than a folder of security policies or a list of technical controls.
Why interviewers ask this: The interviewer checks whether you understand ISO 27001 as a management system supported by connected records.
Clauses 4 through 10 contain certifiable ISMS requirements, while Annex A provides a reference set of information security controls.
- The clauses cover context, leadership, planning, support, operation, performance evaluation, and improvement.
- Risk treatment determines which Annex A controls and other controls are necessary for the organization.
- An auditor can raise a nonconformity against a clause requirement even when no individual Annex A control has failed.
- Treating Annex A as the whole standard misses the management-system requirements.
Why interviewers ask this: A strong answer separates mandatory management-system requirements from the control reference used in risk treatment.
The Statement of Applicability records every necessary control, whether from Annex A or another source, with its implementation status and selection rationale.
- Risk treatment is compared with Annex A to verify that no necessary control from the reference set was omitted.
- The statement also includes controls required by laws, contracts, other frameworks, or the organization's own design when Annex A is not sufficient.
- Every included control needs a justification, and every excluded Annex A control needs a defensible reason.
- Control identifiers, owners, and evidence links should be precise, and scope or risk changes should trigger review.
Why interviewers ask this: The interviewer evaluates whether you understand the Statement of Applicability as the complete risk-treatment control record, not only an Annex A checklist.
NIST CSF 2.0 organizes cybersecurity outcomes under Govern, Identify, Protect, Detect, Respond, and Recover.
- Govern sets organizational context, strategy, roles, policy, oversight, and supply-chain risk direction.
- Identify covers assets and risks, while Protect covers safeguards such as identity, data security, and awareness.
- Detect addresses finding events, Respond covers handling them, and Recover covers restoring operations and communicating recovery.
- A GRC analyst maps existing controls and evidence to outcomes rather than treating the functions as six project phases.
Why interviewers ask this: A strong answer names the current CSF 2.0 functions and explains how they support control mapping.
A Current Profile records prioritized outcomes the organization presently achieves, while a Target Profile records the desired state.
- The profile should reflect the organization's mission, threats, obligations, risk appetite, and available resources.
- Comparing the two produces gaps that can be assigned owners, priorities, budgets, and due dates.
- Evidence links should support Current Profile claims instead of relying only on workshop opinion.
- A profile is organization-specific and is not a certificate or universal maturity score.
Why interviewers ask this: The interviewer checks whether you can use CSF Profiles as evidence-based planning artifacts.
PCI DSS scope starts with the cardholder data environment and connected or security-impacting systems, while the assessment path is set with the entity governing the compliance program, such as the acquirer or payment brand.
- The cardholder data environment includes people, processes, and technology that store, process, or transmit cardholder data or sensitive authentication data.
- Connected-to and security-impacting systems remain in scope unless effective segmentation and scope reduction are demonstrated.
- The governing compliance entity confirms SAQ eligibility and type or a ROC path, including whether a QSA or an Internal Security Assessor (ISA) may perform the assessment.
- The Attestation of Compliance records the result but does not replace the required evidence and testing.
Why interviewers ask this: A strong answer connects payment-data scope to the validation route required by the governing compliance entity and names QSA and ISA roles correctly.
Locked questions
- 21
What makes evidence suitable for testing a control?
testing - 22
What is a population in control testing?
testing - 23
What is a sample in control testing, and how should it be documented?
testing - 24
How does period evidence differ from as-of evidence?
- 25
How would you test the completeness of an evidence population?
evidence-population - 26
How would you test the accuracy of an evidence export?
- 27
Why should evidence record its source and collection method?
- 28
Why do timestamps matter in audit evidence?
- 29
Why is an API export usually preferable to a screenshot for audit evidence?
evidence-automation - 30
How would you handle evidence retention and an external auditor request?
retention - 31
What fields should a basic information-security risk register contain?
risk-managementrisk-registerrisk - 32
How do asset, threat, and vulnerability appear in a risk-register entry?
vulnerabilitiesrisk-management - 33
How would you estimate likelihood for a risk-register entry?
estimationrisk-management - 34
How would you estimate impact for a risk-register entry?
estimationrisk-management - 35
What is the difference between inherent and residual risk?
risk-management - 36
Who should be the owner of a risk in the risk register?
risk-managementrisk-registerrisk - 37
What are the common risk treatment options?
risk-management - 38
What should a risk-acceptance record contain?
risk-management - 39
Why are due dates and review dates important in a risk register?
risk-managementrisk-registerrisk - 40
What is a key risk indicator, and how would you record one?
risk-management - 41
What are the basic stages of an information-security policy lifecycle?
policy-management - 42
How would you verify that a policy is current and properly approved?
policy-management - 43
What evidence would you collect for a quarterly access review?
- 44
An access review identifies a former contractor with production access. What should the GRC record show?
- 45
What evidence supports a basic production change-management control?
- 46
What evidence demonstrates completion of annual security-awareness training?
- 47
How would you review a vendor security questionnaire at a basic level?
procurement - 48
A vendor returns an incomplete security questionnaire. What would you do next?
procurement - 49
Why do TPRM programs assign vendors to tiers?
procurementthird-party-risk - 50
What should a control or policy exception record contain?
policy-managementerror-handling - 51
Drata marks AWS Config evidence for SOC 2 CC6.6 as failed because 3 of 42 accounts are missing; how would you validate the collection?
validationcompliancesoc-operations - 52
Vanta collected a CloudTrail screenshot for a quarterly SOC 2 test, but it has no account ID or capture date; what would you do?
compliancecloud-securitysoc-operations - 53
An Okta access-review export in Drata lists 486 users, while the HR roster has 501 active workers; how would you reconcile it?
- 54
GitHub shows 127 merged pull requests for the quarter, but Jira shows only 119 approved change tickets; how would you validate the SOC 2 evidence?
validationcompliancesoc-operations - 55
Vanta says 96% of GitHub repositories enforce branch protection, but 12 archived repositories are included; how would you prepare the evidence?
- 56
Drata collected an AWS Config result today for an audit period that ended 30 days ago; can it support the period-end control?
config - 57
An auditor receives a manually filtered Okta CSV whose filename says March 31, but the file metadata shows April 3; how would you verify its lineage and as-of date?
lineage - 58
An Okta collector in Vanta has not synced for 9 days, and the auditor needs the current MFA report by Friday; what would you do?
identity-access - 59
A SOC 2 request asks for 25 approved production changes, but Jira has 640 tickets for the quarter; how would you build the population?
compliancesoc-operationssoc-2 - 60
You receive 30 evidence files from AWS, Okta, GitHub, and Jira with names such as final2.csv; how would you package them in Drata?
- 61
For a quarterly Okta access review, the population is 320 users and the sample is 25; how would you test the control?
- 62
HR lists 18 terminated workers this month; how would you test the leaver control using Okta and Jira?
- 63
A department had 36 employee role changes last quarter; how would you sample and test mover access?
- 64
Jira contains 84 production changes for April; how would you test a sample of 20 for approval and segregation of duties?
segregation-of-duties - 65
The emergency-change policy requires approval within 24 hours after deployment; 7 emergency Jira tickets exist this quarter, so how would you test them?
policy-managementdeployment - 66
The backup dashboard shows 92 daily jobs for the month and 4 failures; how would you test the backup control?
backups - 67
A quarterly restore test says successful but covers only 1 of 12 critical systems; how would you assess it?
system-design - 68
The annual incident-response tabletop must include eight business functions, but the attendee list omits Legal and the action log does not show Communications participation; how would you test the control?
incidents - 69
A vulnerability SLA requires critical findings within 15 days; Qualys shows 28 closed findings, so how would you test a sample of 10?
vulnerabilities - 70
One of 15 sampled access removals missed the 8-hour SLA by 3 hours; how would you record the result?
- 71
A Jira intake says an unencrypted spreadsheet was emailed externally once; should it enter the risk register as an issue or a risk?
risk-managementrisk-registerspread - 72
A product team requests a 90-day exception to the MFA policy through Jira; how would you classify and process it?
concurrencyerror-handlingidentity-access - 73
A Jira risk intake says only vendor may fail; what details would you request before adding it to the register?
procurementrisk-management - 74
The risk register has two entries for the same unsupported database, scored 12 and 20; how would you clean them up?
risk-managementrisk-registerdatabase - 75
A risk owner left the company, and 9 open register entries still name them; what would you do?
riskrisk-management - 76
A medium risk is marked mitigate, but its Jira remediation epic has no due date or assignee; how would you follow up?
risk-management - 77
A control issue was fixed in Jira, but the related risk register entry remains high; should you close it?
risk-managementrisk-registerrisk - 78
A Jira issue is 12 days overdue, and the owner says the fix is 80% done; how would you report and follow it?
- 79
A register entry has passed its six-month review date by 45 days; how would you refresh it?
- 80
A risk owner must choose among mitigate, transfer, accept, and avoid for an unsupported file server; how would you prepare the Jira decision?
riskrisk-management - 81
A new vendor will process customer names and email addresses; what intake details would you collect in OneTrust before sending the questionnaire?
procurementconcurrency - 82
OneTrust intake shows a vendor stores payroll data for 2,400 employees and supports payroll day; how would you assign a tier?
procurement - 83
A vendor's SOC 2 report lists an access-control exception affecting the service you plan to buy; how would you assess it?
compliancesoc-operationssoc-2 - 84
A high-tier vendor provides ISO 27001 certification but no SOC 2 report; is the document set sufficient?
governancecompliancesoc-operations - 85
A vendor's SOC 2 report expired 4 months ago, and the new report is not ready; what evidence would you request?
compliancesoc-operationssoc-2 - 86
OneTrust shows a low-tier marketing tool, but a new API will send it 600,000 customer profiles; what would you do?
api - 87
A vendor questionnaire says data is encrypted according to industry standards; what follow-up would you enter in OneTrust?
procurementencryption - 88
Legal asks whether the security addendum must require 24-hour incident notice when the questionnaire says 72 hours; how would you support review?
incidents - 89
A vendor uses 6 subprocessors, but its data-flow diagram names only 4; how would you resolve the discrepancy?
procurement - 90
A medium-tier vendor is due for annual reassessment, but the business plans to terminate it in 45 days; what would you do?
procurement - 91
An auditor requests the April Okta access-review file by tomorrow, but the control owner sent a May export; how would you respond?
- 92
An approved policy exception allows one legacy server to skip MFA only if its privileged accounts are reviewed weekly; two review records are missing this month. What would you do?
policy-managementerror-handlingidentity-access - 93
Drata shows a quarterly control as green, but its attached AWS Config evidence is 14 months old; how would you handle it?
config - 94
A GitHub PR was merged on June 12, Jira says approval on June 13, and the deployment log says June 11; how would you resolve the dates?
deployment - 95
A test of 25 change tickets finds 3 deployments without prior approval; how would you report the failed control?
deployment - 96
A control owner uploads a corrected spreadsheet after you found 6 missing rows, but gives no explanation; can you replace the original?
spreadsheetsspread - 97
A Jira remediation ticket says done after branch protection was enabled on 9 repositories; how would you verify closure?
closures - 98
An auditor asks for 40 files across 8 controls by Friday, and 11 are missing on Wednesday; how would you report status?
- 99
Two audit workpapers cite different populations for the same Okta review, 498 and 503 users; how would you correct the package?
- 100
A failed access-review control has remediation due in 30 days; what concise weekly update would you provide?