WorksheetsCompliance & Audit Quiz
Total questions: 30
Worksheet time: 15mins
The primary objective of a security compliance audit is to:
Identify vulnerabilities using tools
Ensure adherence to laws, standards, and policies
Perform penetration testing
Monitor real-time attacks
Which factor MOST influences whether an organization needs an external audit?
Size of IT team
Regulatory requirement
Type of software used
Number of users
Which of the following is NOT a type of security audit?
Internal audit
External audit
Compliance audit
Vulnerability scan
Independence of auditors is a principle that ensures:
Faster audits
No management involvement
Unbiased audit opinion
Use of automated tools only
Correct sequence of a security audit is:
Reporting → Planning → Fieldwork
Planning → Fieldwork → Reporting
Fieldwork → Planning → Reporting
Planning → Reporting → Fieldwork
Which skill is MOST critical for an IT auditor?
Programming
Networking
Analytical & judgment ability
Ethical hacking
The internal audit team should ideally report to:
IT Manager
CIO
CEO / Audit Committee
System Administrator
Security evaluation mainly focuses on:
Attacker techniques
Control effectiveness
Incident response speed
Malware behavior
In assurance models, higher assurance level implies:
More automation
More documentation
More rigorous evaluation
More penetration testing
Which is NOT part of evaluation methodology?
Scope definition
Evidence collection
Control testing
Incident exploitation
NIST Cybersecurity Framework core functions include all EXCEPT:
Identify
Protect
Detect
Penetrate
NIST framework is best described as:
A law
A certification
A voluntary framework
A compliance mandate
GDPR applies primarily to:
Only EU companies
Any entity processing EU personal data
Only government organizations
Only cloud providers
Which is considered personal data under GDPR?
Server IP
Employee salary
Email address
Company registration number
GDPR violation penalties are based on:
Company size only
Fixed fine
Percentage of global turnover
Number of employees
ISO/IEC 27001 primarily focuses on:
Network security
Risk-based ISMS
Application security
Penetration testing
ISO 27001 follows which management cycle?
SDLC
PDCA
DMAIC
Agile
Statement of Applicability (SoA) is used to:
List vulnerabilities
Justify selected controls
Document incidents
Perform audits
SOX Act mainly applies to:
Healthcare organizations
Publicly traded companies
IT service providers
Banks only
SOC reports are issued by:
Internal auditors
Management
Independent auditors
Regulators
COBIT is primarily used for:
Service management
IT governance
Incident handling
Change management
COBIT differs from ITIL because COBIT:
Is operational
Focuses on governance
Is tool-based
Is vendor-specific
Health Insurance Portability and Accountability Act protects:
Financial data
Cardholder data
Health information
Employee data
PCI DSS compliance levels are based on:
Revenue
Number of transactions
Company size
Geography
CIS Critical Security Controls are:
Legal requirements
Best practice security controls
Audit checklists
Compliance laws
CIS Benchmarks mainly provide:
Policies
Secure configuration guidelines
Risk matrices
Legal interpretations
SSE-CMM focuses on:
Product quality
Software security maturity
Network monitoring
Cloud compliance
IT Act 2008 in India primarily addresses:
Cyber crimes & electronic records
Financial fraud
Healthcare compliance
Cloud governance
Digital Personal Data Protection Act 2023 is closest in intent to:
SOX
HIPAA
GDPR
PCI DSS
In a global bank internal audit, the MOST critical area is:
Antivirus deployment
Regulatory compliance mapping
Developer access speed
User awareness training
