wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Audit Compliance and Security Quiz

Total questions: 40

Worksheet time: 20mins

Name
Class
Date
1.

Compliance audit primarily verifies:

a)

Network vulnerabilities

b)

Adherence to legal and regulatory requirements

c)

Application performance

d)

Incident response time

2.

Which audit is conducted by employees of the same organization?

a)

External audit

b)

Regulatory audit

c)

Internal audit

d)

Third-party audit

3.

Which factor MOST affects audit scope definition?

a)

Available tools

b)

Business objectives

c)

Number of servers

d)

Auditor experience

4.

Which principle ensures auditors do not audit their own work?

a)

Confidentiality

b)

Independence

c)

Integrity

d)

Accountability

5.

Which is NOT a security audit phase?

a)

Planning

b)

Fieldwork

c)

Exploitation

d)

Reporting

6.

An auditor must primarily demonstrate:

a)

Programming skills

b)

Objectivity

c)

System administration skills

d)

Vendor certification

7.

Which personal ability is MOST critical for auditors?

a)

Aggression

b)

Judgment and analytical thinking

c)

Coding ability

d)

Social engineering

8.

Audit decisions are MOST influenced by:

a)

Budget constraints

b)

Regulatory requirements

c)

Number of employees

d)

Tool availability

9.

Which violates audit ethics?

a)

Maintaining confidentiality

b)

Accepting gifts from auditee

c)

Evidence-based reporting

d)

Professional skepticism

10.

Security evaluation focuses on:

a)

Threat intelligence

b)

Control effectiveness

c)

Malware analysis

d)

Log correlation

11.

Assurance levels primarily indicate:

a)

Network maturity

b)

Degree of confidence in controls

c)

Number of audits conducted

d)

Compliance cost

12.

Which assurance level provides maximum confidence?

a)

Informal assurance

b)

Limited assurance

c)

Reasonable assurance

d)

High assurance

13.

Evaluation methodology does NOT include:

a)

Evidence collection

b)

Risk assessment

c)

Control testing

d)

Active exploitation

14.

NIST Cybersecurity Framework core functions are:

a)

Prevent, Protect, Patch

b)

Identify, Protect, Detect, Respond, Recover

c)

Plan, Do, Check, Act

d)

Assess, Audit, Improve

15.

NIST framework is best described as:

a)

Mandatory law

b)

Certification standard

c)

Voluntary best-practice framework

d)

Compliance checklist

16.

GDPR applies when:

a)

Data is stored in EU only

b)

EU citizen data is processed

c)

Company is EU-based

d)

Organization is government-owned

17.

Which is a “special category” of personal data under GDPR?

a)

Email ID

b)

IP address

c)

Health data

d)

Company name

18.

GDPR mandates breach notification within:

a)

24 hours

b)

48 hours

c)

72 hours

d)

7 days

19.

ISO/IEC 27001 is focused on:

a)

Network security tools

b)

Risk-based ISMS

c)

Application coding standards

d)

Vulnerability management

20.

ISO 27001 follows which cycle?

a)

SDLC

b)

DMAIC

c)

PDCA

d)

Agile

21.

Statement of Applicability (SoA) defines:

a)

Identified risks

b)

Selected and excluded controls

c)

Incident reports

d)

Legal obligations

22.

SOX Act focuses mainly on:

a)

Data privacy

b)

Financial reporting controls

c)

Network monitoring

d)

Incident response

23.

SOC 2 reports are based on:

a)

ISO controls

b)

Trust Service Criteria

c)

NIST controls

d)

COBIT processes

24.

SOC reports are prepared by:

a)

Internal IT team

b)

Management

c)

Independent auditors

d)

Regulators

25.

COBIT primarily addresses:

a)

Service delivery

b)

IT governance

c)

Incident management

d)

Change management

26.

COBIT vs ITIL — correct difference:

a)

COBIT is operational

b)

ITIL is governance-focused

c)

COBIT focuses on control & governance

d)

ITIL is audit-centric

27.

HIPAA protects:

a)

Cardholder data

b)

Financial records

c)

Protected Health Information (PHI)

d)

Employee payroll

28.

PCI DSS compliance levels depend on:

a)

Company size

b)

Geography

c)

Number of card transactions

d)

Annual revenue

29.

PCI DSS applies to organizations that:

a)

Store personal data

b)

Process payment card data

c)

Handle healthcare records

d)

Offer cloud services

30.

CIS Critical Security Controls are:

a)

Legal mandates

b)

Best-practice security controls

c)

Audit standards

d)

Regulatory laws

31.

CIS Benchmarks provide:

a)

Risk scoring

b)

Secure configuration guidelines

c)

Legal mapping

d)

Compliance penalties

32.

SSE-CMM evaluates:

a)

Software performance

b)

Security process maturity

c)

Network throughput

d)

Cloud readiness

33.

IT Act 2008 primarily addresses:

a)

Cyber crimes and electronic records

b)

Financial compliance

c)

Healthcare data

d)

International trade

34.

Digital Personal Data Protection Act 2023 governs:

a)

Network security

b)

Personal data processing in India

c)

Financial reporting

d)

Software licensing

35.

DPDP Act is conceptually closest to:

a)

HIPAA

b)

SOX

c)

GDPR

d)

PCI DSS

36.

In a bank audit, MOST critical compliance area is:

a)

Antivirus deployment

b)

Regulatory mapping and controls

c)

Developer productivity

d)

Password complexity

37.

Developers having direct production access violates:

a)

Availability principle

b)

Segregation of duties

c)

Confidentiality

d)

Business continuity

38.

Using real customer data in testing violates:

a)

Logging policy

b)

Data minimization

c)

Patch management

d)

Backup policy

39.

Audit evidence must be:

a)

Verbal

b)

Assumed

c)

Sufficient and reliable

d)

Management-approved

40.

Final audit output is:

a)

Vulnerability list

b)

Risk register

c)

Audit report with opinion

d)

Penetration test result