WorksheetsEY + GRC + Auditing + IT + Cybersecurity Quiz
Total questions: 56
Worksheet time: 9mins
Which of the following best describes the purpose of GRC?
Increase sales and revenue
Align IT with business goals, manage risks, ensure compliance
Reduce hardware costs
Automate HR operations
In risk management, which is NOT a risk response strategy?
Avoidance
Mitigation
Acceptance
Duplication
Which framework is commonly used for IT governance?
ISO 9001
COBIT
CMMI
PMBOK
Which is an example of compliance risk?
Competitor gaining market share
Employee fraud
Violation of GDPR data protection rules
System downtime
The “Three Lines of Defense” model in GRC includes all EXCEPT:
Operational Management
Risk & Compliance Functions
Internal Audit
External Customers
Which law/regulation primarily deals with protecting health data?
HIPAA
SOX
GDPR
PCI-DSS
In risk assessment, the formula for risk is typically:
Risk = Threat ÷ Vulnerability
Risk = Likelihood × Impact
Risk = Asset + Control
Risk = Compliance × Policy
What is the main objective of an IT audit?
Increase revenue
Ensure IT controls safeguard assets and data
Reduce headcount
Improve marketing campaigns
Which of the following is a preventive control?
Firewall configuration
Log monitoring
Incident response
Audit trail review
SOX (Sarbanes-Oxley Act) is mainly concerned with:
Environmental safety
Financial reporting integrity
HR hiring process
Customer privacy laws
Internal audits are primarily designed to:
Replace external audits
Provide independent assurance within the organization
Prepare tax filings
Approve business loans
Which of these is a detective control?
CCTV cameras
Antivirus software blocking malware
Firewalls
Encryption
Which standard provides guidelines for ISMS?
ISO 27001
ISO 31000
ISO 9001
PCI DSS
A compliance audit typically assesses:
Market share
Adherence to laws, policies, and standards
Employee performance
Customer satisfaction
Which of the following is NOT an audit type?
Financial Audit
Operational Audit
Compliance Audit
Product Audit
EY is part of the 'Big 4'. The other firms are:
PwC, Deloitte, KPMG
Accenture, IBM, Capgemini
BCG, McKinsey, Bain
Oracle, SAP, Infosys
EY’s motto 'Building a better working world' mainly reflects:
Revenue growth
Client relationships and global impact
Marketing campaigns
Automation only
Which of the following is NOT one of EY’s service lines?
Assurance
Tax
Advisory/Consulting
Manufacturing
If a client resists adopting a security recommendation, best response is:
Force implementation
Ignore the issue
Explain risks, provide evidence, suggest alternatives
Escalate immediately
What is EY’s global headquarters location?
London
New York
Paris
Toronto
Which skill is most valued in consulting interviews?
Memorizing regulations
Clear communication & problem-solving
Only technical knowledge
Following hierarchy
When answering behavioral questions at EY, best framework is:
SWOT
STAR
ROI
PESTEL
What does CIA triad stand for?
Confidentiality, Integrity, Availability
Control, Integration, Authentication
Compliance, Investigation, Authorization
Confidentiality, Inspection, Access
Which port does HTTPS typically use?
2021
80
443
D
In databases, SQL injection is an example of:
Network attack
Application-layer attack
Hardware attack
Physical security breach
Which of these is a symmetric encryption algorithm?
RSA
AES
ECC
Diffie-Hellman
In cloud computing, which model provides both platform and infrastructure?
SaaS
PaaS
IaaS
None
Which is the strongest password?
admin123
P@ssword
Summer2025
t$9!XyZ#4qLD
Which is NOT a malware type?
Trojan
Worm
Firewall
Ransomware
Which of the following is NOT a programming language?
Python
Java
HTML
C++
Which attack overwhelms a system with traffic?
SQL Injection
DDoS
XSS
Phishing
Main purpose of SIEM system?
Block phishing emails
Collect & analyze security logs
Encrypt data
Replace firewalls
Which is an example of social engineering?
Brute force
Phishing email
Buffer overflow
Keylogger
Which standard is for Payment Card Industry security?
HIPAA
PCI-DSS
ISO 27001
SOX
Which framework was developed by NIST?
COBIT
ITIL
NIST CSF
CISSP
What does Zero Trust mean?
Never assume trust
Trust only internal networks
No encryption
One firewall for all
Which malware encrypts files and demands ransom?
Worm
Ransomware
Spyware
Rootkit
Which tool is used for vulnerability scanning?
Wireshark
Nessus
Burp Suite
Metasploit
Phishing is:
Exploiting network vulnerabilities
Sending deceptive emails to steal credentials
Infecting systems via USB
Server misconfig exploit
Which principle ensures access only as needed?
Separation of Duties
Least Privilege
Integrity
Defense in Depth
Purpose of penetration testing?
Repair vulnerabilities
Identify and exploit vulnerabilities
Monitor logs
Configure firewalls
Which encryption uses public/private keys?
Symmetric
Hashing
Asymmetric
Steganography
Which tool is most used for packet analysis?
Nmap
Wireshark
Splunk
Nessus
Which OWASP Top 10 vulnerability allows malicious scripts?
CSRF
XSS
SQL Injection
Broken Auth
Correct order of incident response?
ID → Containment → Eradication → Recovery → Lessons
Containment → Eradication → ID → Recovery
Recovery → Eradication → Containment → ID
ID → Recovery → Containment → Lessons
Which law protects EU citizens' data?
HIPAA
SOX
GDPR
CCPA
Which is a common insider threat?
Nation-state hacking
Disgruntled employee
DDoS attack
MITM attack
What does hashing ensure?
Confidentiality
Integrity
Availability
Access Control
Which cloud model places most responsibility on customer?
SaaS
PaaS
IaaS
Hybrid
Which certification is most relevant for GRC & auditing?
CEH
CISSP
CISM
CISA
What is the full form of GRC?
Governance, Risk & Compliance
Global Regulatory Compliance
General Risk Control
Governance, Rules & Control
What is the full form of ISO?
International Security Organization
International Standards Organization
Information Systems Office
International Standards for Operations
What is the full form of TCP/IP?
Transmission Control Protocol / Internet Protocol
Transfer Control Process / Internal Protocol
Transmission Central Protocol / Internet Process
Telecommunication Control Protocol / IP
What is the full form of ChatGPT?
Chat Generative Pretrained Transformer
Chat General Processing Tool
Chat Generated Protocol Transfer
Chat Graphical Programming Technology
What is the full form of PCI-DSS?
Payment Card Industry Data Security Standard
Personal Computer Integration Data Secure Standard
Payment Compliance Industry Digital Security System
Public Card Industry Digital Security Standard
What is the full form of GDPR?
General Data Protection Regulation
Global Data Privacy Rules
General Digital Protection Requirement
Global Digital Privacy Regulation
