Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Compliance & Audit Quiz

Total questions: 30

Worksheet time: 15mins

Name
Class
Date
1.

The primary objective of a security compliance audit is to:

a)

Identify vulnerabilities using tools

b)

Ensure adherence to laws, standards, and policies

c)

Perform penetration testing

d)

Monitor real-time attacks

2.

Which factor MOST influences whether an organization needs an external audit?

a)

Size of IT team

b)

Regulatory requirement

c)

Type of software used

d)

Number of users

3.

Which of the following is NOT a type of security audit?

a)

Internal audit

b)

External audit

c)

Compliance audit

d)

Vulnerability scan

4.

Independence of auditors is a principle that ensures:

a)

Faster audits

b)

No management involvement

c)

Unbiased audit opinion

d)

Use of automated tools only

5.

Correct sequence of a security audit is:

a)

Reporting → Planning → Fieldwork

b)

Planning → Fieldwork → Reporting

c)

Fieldwork → Planning → Reporting

d)

Planning → Reporting → Fieldwork

6.

Which skill is MOST critical for an IT auditor?

a)

Programming

b)

Networking

c)

Analytical & judgment ability

d)

Ethical hacking

7.

The internal audit team should ideally report to:

a)

IT Manager

b)

CIO

c)

CEO / Audit Committee

d)

System Administrator

8.

Security evaluation mainly focuses on:

a)

Attacker techniques

b)

Control effectiveness

c)

Incident response speed

d)

Malware behavior

9.

In assurance models, higher assurance level implies:

a)

More automation

b)

More documentation

c)

More rigorous evaluation

d)

More penetration testing

10.

Which is NOT part of evaluation methodology?

a)

Scope definition

b)

Evidence collection

c)

Control testing

d)

Incident exploitation

11.

NIST Cybersecurity Framework core functions include all EXCEPT:

a)

Identify

b)

Protect

c)

Detect

d)

Penetrate

12.

NIST framework is best described as:

a)

A law

b)

A certification

c)

A voluntary framework

d)

A compliance mandate

13.

GDPR applies primarily to:

a)

Only EU companies

b)

Any entity processing EU personal data

c)

Only government organizations

d)

Only cloud providers

14.

Which is considered personal data under GDPR?

a)

Server IP

b)

Employee salary

c)

Email address

d)

Company registration number

15.

GDPR violation penalties are based on:

a)

Company size only

b)

Fixed fine

c)

Percentage of global turnover

d)

Number of employees

16.

ISO/IEC 27001 primarily focuses on:

a)

Network security

b)

Risk-based ISMS

c)

Application security

d)

Penetration testing

17.

ISO 27001 follows which management cycle?

a)

SDLC

b)

PDCA

c)

DMAIC

d)

Agile

18.

Statement of Applicability (SoA) is used to:

a)

List vulnerabilities

b)

Justify selected controls

c)

Document incidents

d)

Perform audits

19.

SOX Act mainly applies to:

a)

Healthcare organizations

b)

Publicly traded companies

c)

IT service providers

d)

Banks only

20.

SOC reports are issued by:

a)

Internal auditors

b)

Management

c)

Independent auditors

d)

Regulators

21.

COBIT is primarily used for:

a)

Service management

b)

IT governance

c)

Incident handling

d)

Change management

22.

COBIT differs from ITIL because COBIT:

a)

Is operational

b)

Focuses on governance

c)

Is tool-based

d)

Is vendor-specific

23.

Health Insurance Portability and Accountability Act protects:

a)

Financial data

b)

Cardholder data

c)

Health information

d)

Employee data

24.

PCI DSS compliance levels are based on:

a)

Revenue

b)

Number of transactions

c)

Company size

d)

Geography

25.

CIS Critical Security Controls are:

a)

Legal requirements

b)

Best practice security controls

c)

Audit checklists

d)

Compliance laws

26.

CIS Benchmarks mainly provide:

a)

Policies

b)

Secure configuration guidelines

c)

Risk matrices

d)

Legal interpretations

27.

SSE-CMM focuses on:

a)

Product quality

b)

Software security maturity

c)

Network monitoring

d)

Cloud compliance

28.

IT Act 2008 in India primarily addresses:

a)

Cyber crimes & electronic records

b)

Financial fraud

c)

Healthcare compliance

d)

Cloud governance

29.

Digital Personal Data Protection Act 2023 is closest in intent to:

a)

SOX

b)

HIPAA

c)

GDPR

d)

PCI DSS

30.

In a global bank internal audit, the MOST critical area is:

a)

Antivirus deployment

b)

Regulatory compliance mapping

c)

Developer access speed

d)

User awareness training