wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

DORA Quiz (English)

Total questions: 29

Worksheet time: 15mins

Name
Class
Date
1.

What is the meaning of the acronym DORA in the context of the financial sector?

a)

Digital Operational Resilience Act

b)

Data Optimization and Risk Assessment

c)

Digital Oversight Regulation Act

d)

DORA the Explorer, Expert in Cyber-Risk

2.

On what date did the DORA regulation come into effect or will it come into effect?

a)

January 1, 2024

b)

January 17, 2025

c)

July 1, 2025

d)

January 17, 2026

3.

What is the main objective of the DORA regulation?

a)

Harmonize tax rules in the EU

b)

Strengthen the digital operational resilience of financial entities

c)

Regulate digital transactions between member states

d)

Ensure that no one panics when a server goes down

4.

Is DORA a regulation or a directive?

a)

A directive

b)

A regulation

c)

Both

5.

What types of entities are covered by DORA?

a)

Only banks

b)

All financial entities, including their third-party ICT suppliers

c)

Only technology companies

6.

According to DORA, what should financial entities do to manage ICT risks?

a)

Conduct annual assessments of ICT risks

b)

Outsource all ICT risks to third parties

c)

Ignore minor ICT risks

d)

Install a free antivirus and hope for the best

7.

What is the minimum frequency required to test digital operational resilience?

a)

Every month

b)

Once a year

c)

Every three years

d)

Every time a trainee clicks 'Delete all'.

8.

What does the principle of proportionality mean in the context of DORA?

a)

Apply the same rules to all companies, regardless of their size

b)

Adapt the requirements based on the size, nature, and risk profile of the entities

c)

Require a small business to have the same cybersecurity budget as a central bank.

9.

What elements must be included in the TIC inventory (information register) according to DORA?

a)

The critical functions supported by suppliers

b)

The non-critical functions supported by suppliers

c)

All TIC suppliers

10.

What should financial entities do in the event of a major ICT-related incident?

a)

Immediately inform the competent authorities

b)

Wait until the incident is resolved before informing anyone

c)

Not report the incident if it does not directly affect their clients

d)

Light a candle and hope no one notices.

11.

Which suppliers are specifically targeted by DORA?

a)

All ICT suppliers, regardless of their role

b)

Critical third-party suppliers for the essential functions of financial entities

12.

What should contracts with third-party ICT include according to DORA?

a)

Clauses on risk management and business continuity

b)

A detailed description of the services provided

c)

Only the cost of the service provided

d)

No specific contract/addendum is required

13.

What happens if a critical third-party provider does not comply with DORA?

a)

The concerned financial entity may be sanctioned by the competent authorities.

b)

The third-party provider is automatically excluded from the European market.

c)

It receives a very polite but very threatening letter from the EU.

14.

What is one of the key testing requirements according to DORA?

a)

Test only after a major incident

b)

Conduct regular digital operational resilience testing

c)

Test until there is almost nothing that works

15.

What types of incidents must be reported to the competent authorities according to DORA?

a)

All incidents, even minor ones

b)

Major incidents related to ICT and significant cyber threats

16.

Should incident reports follow a standardized format under DORA?

a)

Yes, in accordance with the technical standards established by European authorities.

b)

No, each entity can define its own format.

17.

Who is responsible for the implementation of DORA within a financial company?

a)

The IT department / ITSO

b)

The general management and the board of directors

c)

Michel, a nice guy

18.

Which authorities supervise compliance with DORA at the European level?

a)

EBA, ESMA and EIOPA

b)

The European Commission

c)

The CAA

19.

How does DORA promote the sharing of information on cyber threats?

a)

By requiring all entities to share their customer data with their peers.

b)

By encouraging a secure exchange of information between financial entities.

20.

What does DORA foresee to improve cooperation between competent authorities in the EU?

a)

The creation of a harmonized framework for supervision and enforcement of the regulation.

b)

The complete delegation of supervision to the Member States.

21.

DORA applies only to banks and large financial institutions.

a)

True

b)

False

22.

DORA requires that all financial entities have a documented digital continuity plan.

a)

True

b)

False

23.

DORA allows companies to completely outsource their responsibilities regarding ICT risks to their third-party suppliers.

a)

True

b)

False

24.

The principle of proportionality means that the requirements of DORA may vary depending on the size and risk profile of the financial entity.

a)

True

b)

False

25.

The sanctions for non-compliance with DORA may include fines for the concerned financial entity.

a)

True

b)

False

26.

DORA imposes an explicit obligation for continuous training on ICT risk management for the relevant personnel.

a)

True

b)

False

27.

DORA aims to improve digital operational resilience only within the national borders of the Member States.

a)

True

b)

False

28.

Companies should test their digital resilience only after a major incident.

a)

True

b)

False

29.

The DORA regulation replaces all other European regulations related to cybersecurity in the financial sector.

a)

True

b)

False