Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

EY + GRC + Auditing + IT + Cybersecurity Quiz

Total questions: 56

Worksheet time: 9mins

Name
Class
Date
1.

Which of the following best describes the purpose of GRC?

a)

Increase sales and revenue

b)

Align IT with business goals, manage risks, ensure compliance

c)

Reduce hardware costs

d)

Automate HR operations

2.

In risk management, which is NOT a risk response strategy?

a)

Avoidance

b)

Mitigation

c)

Acceptance

d)

Duplication

3.

Which framework is commonly used for IT governance?

a)

ISO 9001

b)

COBIT

c)

CMMI

d)

PMBOK

4.

Which is an example of compliance risk?

a)

Competitor gaining market share

b)

Employee fraud

c)

Violation of GDPR data protection rules

d)

System downtime

5.

The “Three Lines of Defense” model in GRC includes all EXCEPT:

a)

Operational Management

b)

Risk & Compliance Functions

c)

Internal Audit

d)

External Customers

6.

Which law/regulation primarily deals with protecting health data?

a)

HIPAA

b)

SOX

c)

GDPR

d)

PCI-DSS

7.

In risk assessment, the formula for risk is typically:

a)

Risk = Threat ÷ Vulnerability

b)

Risk = Likelihood × Impact

c)

Risk = Asset + Control

d)

Risk = Compliance × Policy

8.

What is the main objective of an IT audit?

a)

Increase revenue

b)

Ensure IT controls safeguard assets and data

c)

Reduce headcount

d)

Improve marketing campaigns

9.

Which of the following is a preventive control?

a)

Firewall configuration

b)

Log monitoring

c)

Incident response

d)

Audit trail review

10.

SOX (Sarbanes-Oxley Act) is mainly concerned with:

a)

Environmental safety

b)

Financial reporting integrity

c)

HR hiring process

d)

Customer privacy laws

11.

Internal audits are primarily designed to:

a)

Replace external audits

b)

Provide independent assurance within the organization

c)

Prepare tax filings

d)

Approve business loans

12.

Which of these is a detective control?

a)

CCTV cameras

b)

Antivirus software blocking malware

c)

Firewalls

d)

Encryption

13.

Which standard provides guidelines for ISMS?

a)

ISO 27001

b)

ISO 31000

c)

ISO 9001

d)

PCI DSS

14.

A compliance audit typically assesses:

a)

Market share

b)

Adherence to laws, policies, and standards

c)

Employee performance

d)

Customer satisfaction

15.

Which of the following is NOT an audit type?

a)

Financial Audit

b)

Operational Audit

c)

Compliance Audit

d)

Product Audit

16.

EY is part of the 'Big 4'. The other firms are:

a)

PwC, Deloitte, KPMG

b)

Accenture, IBM, Capgemini

c)

BCG, McKinsey, Bain

d)

Oracle, SAP, Infosys

17.

EY’s motto 'Building a better working world' mainly reflects:

a)

Revenue growth

b)

Client relationships and global impact

c)

Marketing campaigns

d)

Automation only

18.

Which of the following is NOT one of EY’s service lines?

a)

Assurance

b)

Tax

c)

Advisory/Consulting

d)

Manufacturing

19.

If a client resists adopting a security recommendation, best response is:

a)

Force implementation

b)

Ignore the issue

c)

Explain risks, provide evidence, suggest alternatives

d)

Escalate immediately

20.

What is EY’s global headquarters location?

a)

London

b)

New York

c)

Paris

d)

Toronto

21.

Which skill is most valued in consulting interviews?

a)

Memorizing regulations

b)

Clear communication & problem-solving

c)

Only technical knowledge

d)

Following hierarchy

22.

When answering behavioral questions at EY, best framework is:

a)

SWOT

b)

STAR

c)

ROI

d)

PESTEL

23.

What does CIA triad stand for?

a)

Confidentiality, Integrity, Availability

b)

Control, Integration, Authentication

c)

Compliance, Investigation, Authorization

d)

Confidentiality, Inspection, Access

24.

Which port does HTTPS typically use?

a)

2021

b)

80

c)

443

d)

D

25.

In databases, SQL injection is an example of:

a)

Network attack

b)

Application-layer attack

c)

Hardware attack

d)

Physical security breach

26.

Which of these is a symmetric encryption algorithm?

a)

RSA

b)

AES

c)

ECC

d)

Diffie-Hellman

27.

In cloud computing, which model provides both platform and infrastructure?

a)

SaaS

b)

PaaS

c)

IaaS

d)

None

28.

Which is the strongest password?

a)

admin123

b)

P@ssword

c)

Summer2025

d)

t$9!XyZ#4qLD

29.

Which is NOT a malware type?

a)

Trojan

b)

Worm

c)

Firewall

d)

Ransomware

30.

Which of the following is NOT a programming language?

a)

Python

b)

Java

c)

HTML

d)

C++

31.

Which attack overwhelms a system with traffic?

a)

SQL Injection

b)

DDoS

c)

XSS

d)

Phishing

32.

Main purpose of SIEM system?

a)

Block phishing emails

b)

Collect & analyze security logs

c)

Encrypt data

d)

Replace firewalls

33.

Which is an example of social engineering?

a)

Brute force

b)

Phishing email

c)

Buffer overflow

d)

Keylogger

34.

Which standard is for Payment Card Industry security?

a)

HIPAA

b)

PCI-DSS

c)

ISO 27001

d)

SOX

35.

Which framework was developed by NIST?

a)

COBIT

b)

ITIL

c)

NIST CSF

d)

CISSP

36.

What does Zero Trust mean?

a)

Never assume trust

b)

Trust only internal networks

c)

No encryption

d)

One firewall for all

37.

Which malware encrypts files and demands ransom?

a)

Worm

b)

Ransomware

c)

Spyware

d)

Rootkit

38.

Which tool is used for vulnerability scanning?

a)

Wireshark

b)

Nessus

c)

Burp Suite

d)

Metasploit

39.

Phishing is:

a)

Exploiting network vulnerabilities

b)

Sending deceptive emails to steal credentials

c)

Infecting systems via USB

d)

Server misconfig exploit

40.

Which principle ensures access only as needed?

a)

Separation of Duties

b)

Least Privilege

c)

Integrity

d)

Defense in Depth

41.

Purpose of penetration testing?

a)

Repair vulnerabilities

b)

Identify and exploit vulnerabilities

c)

Monitor logs

d)

Configure firewalls

42.

Which encryption uses public/private keys?

a)

Symmetric

b)

Hashing

c)

Asymmetric

d)

Steganography

43.

Which tool is most used for packet analysis?

a)

Nmap

b)

Wireshark

c)

Splunk

d)

Nessus

44.

Which OWASP Top 10 vulnerability allows malicious scripts?

a)

CSRF

b)

XSS

c)

SQL Injection

d)

Broken Auth

45.

Correct order of incident response?

a)

ID → Containment → Eradication → Recovery → Lessons

b)

Containment → Eradication → ID → Recovery

c)

Recovery → Eradication → Containment → ID

d)

ID → Recovery → Containment → Lessons

46.

Which law protects EU citizens' data?

a)

HIPAA

b)

SOX

c)

GDPR

d)

CCPA

47.

Which is a common insider threat?

a)

Nation-state hacking

b)

Disgruntled employee

c)

DDoS attack

d)

MITM attack

48.

What does hashing ensure?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Access Control

49.

Which cloud model places most responsibility on customer?

a)

SaaS

b)

PaaS

c)

IaaS

d)

Hybrid

50.

Which certification is most relevant for GRC & auditing?

a)

CEH

b)

CISSP

c)

CISM

d)

CISA

51.

What is the full form of GRC?

a)

Governance, Risk & Compliance

b)

Global Regulatory Compliance

c)

General Risk Control

d)

Governance, Rules & Control

52.

What is the full form of ISO?

a)

International Security Organization

b)

International Standards Organization

c)

Information Systems Office

d)

International Standards for Operations

53.

What is the full form of TCP/IP?

a)

Transmission Control Protocol / Internet Protocol

b)

Transfer Control Process / Internal Protocol

c)

Transmission Central Protocol / Internet Process

d)

Telecommunication Control Protocol / IP

54.

What is the full form of ChatGPT?

a)

Chat Generative Pretrained Transformer

b)

Chat General Processing Tool

c)

Chat Generated Protocol Transfer

d)

Chat Graphical Programming Technology

55.

What is the full form of PCI-DSS?

a)

Payment Card Industry Data Security Standard

b)

Personal Computer Integration Data Secure Standard

c)

Payment Compliance Industry Digital Security System

d)

Public Card Industry Digital Security Standard

56.

What is the full form of GDPR?

a)

General Data Protection Regulation

b)

Global Data Privacy Rules

c)

General Digital Protection Requirement

d)

Global Digital Privacy Regulation