NEW
Font size
WorksheetsAudit Compliance and Security Quiz
Total questions: 40
Worksheet time: 20mins
Compliance audit primarily verifies:
Network vulnerabilities
Adherence to legal and regulatory requirements
Application performance
Incident response time
Which audit is conducted by employees of the same organization?
External audit
Regulatory audit
Internal audit
Third-party audit
Which factor MOST affects audit scope definition?
Available tools
Business objectives
Number of servers
Auditor experience
Which principle ensures auditors do not audit their own work?
Confidentiality
Independence
Integrity
Accountability
Which is NOT a security audit phase?
Planning
Fieldwork
Exploitation
Reporting
An auditor must primarily demonstrate:
Programming skills
Objectivity
System administration skills
Vendor certification
Which personal ability is MOST critical for auditors?
Aggression
Judgment and analytical thinking
Coding ability
Social engineering
Audit decisions are MOST influenced by:
Budget constraints
Regulatory requirements
Number of employees
Tool availability
Which violates audit ethics?
Maintaining confidentiality
Accepting gifts from auditee
Evidence-based reporting
Professional skepticism
Security evaluation focuses on:
Threat intelligence
Control effectiveness
Malware analysis
Log correlation
Assurance levels primarily indicate:
Network maturity
Degree of confidence in controls
Number of audits conducted
Compliance cost
Which assurance level provides maximum confidence?
Informal assurance
Limited assurance
Reasonable assurance
High assurance
Evaluation methodology does NOT include:
Evidence collection
Risk assessment
Control testing
Active exploitation
NIST Cybersecurity Framework core functions are:
Prevent, Protect, Patch
Identify, Protect, Detect, Respond, Recover
Plan, Do, Check, Act
Assess, Audit, Improve
NIST framework is best described as:
Mandatory law
Certification standard
Voluntary best-practice framework
Compliance checklist
GDPR applies when:
Data is stored in EU only
EU citizen data is processed
Company is EU-based
Organization is government-owned
Which is a “special category” of personal data under GDPR?
Email ID
IP address
Health data
Company name
GDPR mandates breach notification within:
24 hours
48 hours
72 hours
7 days
ISO/IEC 27001 is focused on:
Network security tools
Risk-based ISMS
Application coding standards
Vulnerability management
ISO 27001 follows which cycle?
SDLC
DMAIC
PDCA
Agile
Statement of Applicability (SoA) defines:
Identified risks
Selected and excluded controls
Incident reports
Legal obligations
SOX Act focuses mainly on:
Data privacy
Financial reporting controls
Network monitoring
Incident response
SOC 2 reports are based on:
ISO controls
Trust Service Criteria
NIST controls
COBIT processes
SOC reports are prepared by:
Internal IT team
Management
Independent auditors
Regulators
COBIT primarily addresses:
Service delivery
IT governance
Incident management
Change management
COBIT vs ITIL — correct difference:
COBIT is operational
ITIL is governance-focused
COBIT focuses on control & governance
ITIL is audit-centric
HIPAA protects:
Cardholder data
Financial records
Protected Health Information (PHI)
Employee payroll
PCI DSS compliance levels depend on:
Company size
Geography
Number of card transactions
Annual revenue
PCI DSS applies to organizations that:
Store personal data
Process payment card data
Handle healthcare records
Offer cloud services
CIS Critical Security Controls are:
Legal mandates
Best-practice security controls
Audit standards
Regulatory laws
CIS Benchmarks provide:
Risk scoring
Secure configuration guidelines
Legal mapping
Compliance penalties
SSE-CMM evaluates:
Software performance
Security process maturity
Network throughput
Cloud readiness
IT Act 2008 primarily addresses:
Cyber crimes and electronic records
Financial compliance
Healthcare data
International trade
Digital Personal Data Protection Act 2023 governs:
Network security
Personal data processing in India
Financial reporting
Software licensing
DPDP Act is conceptually closest to:
HIPAA
SOX
GDPR
PCI DSS
In a bank audit, MOST critical compliance area is:
Antivirus deployment
Regulatory mapping and controls
Developer productivity
Password complexity
Developers having direct production access violates:
Availability principle
Segregation of duties
Confidentiality
Business continuity
Using real customer data in testing violates:
Logging policy
Data minimization
Patch management
Backup policy
Audit evidence must be:
Verbal
Assumed
Sufficient and reliable
Management-approved
Final audit output is:
Vulnerability list
Risk register
Audit report with opinion
Penetration test result
