Information Security Audit: Foundations and Controls
Published:
Questions
30
Duration
30 min
Faculty-reviewed
0
Updated
09 Jun 2026
About this mock
This test covers the foundational vocabulary and concepts that underpin every information-security audit. You will work through the CIA triad and what each property means in practice, the three categories of controls (preventive, detective, corrective), and the essential elements of risk management including threats, vulnerabilities, and residual risk. The test also addresses audit types, the stages of a formal audit process, and core governance concepts such as segregation of duties, least privilege, and information-security policy hierarchies. Questions draw on internationally recognised frameworks including ISO/IEC 27001, COBIT, and NIST SP 800-53. No prior audit experience is assumed. A correct answer demonstrates that you can recall definitions accurately, distinguish closely related terms, and recognise which concept applies in a given scenario.
Sources & references
Questions in this mock are written and verified against the following sources. Citations are recorded per question and shown in the explanation after submission.
- cited in 7 questions
ISO/IEC 27001:2022 Information Security Management Systems
Annex A, Control 5.9, Inventory of Information and Other Associated Assets
- cited in 4 questions
ISO/IEC 27005:2022 Information Security Risk Management Guidance
Clause 3, Terms and Definitions; risk-assessment guidance
- cited in 4 questions
NIST SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations
Control Family PE, Physical and Environmental Protection
- cited in 2 questions
ISO 19011:2018 Guidelines for Auditing Management Systems
Clause 6, Conducting an Audit (process stages)
- cited in 2 questions
IIA International Standards for the Professional Practice of Internal Auditing
Performance Standards 2200-2340, Engagement Planning and Performing the Engagement
- cited in 2 questions
ISO/IEC 27002:2022 Information Security, Cybersecurity and Privacy Protection - Information Security Controls
Control 5.1, Policies for Information Security
- cited in 1 question
ISACA CISA Review Manual (Certified Information Systems Auditor)
Domain 5, Protection of Information Assets (control classifications)
- cited in 1 question
ISACA Information Systems Auditing: Tools and Techniques (IS Audit and Assurance Standards)
Guidance on audit types and compliance testing
- cited in 1 question
ISACA COBIT 2019 Framework: Introduction and Methodology
Chapter 1, Overview of COBIT and the Core Model
- cited in 1 question
ISO 31000:2018 Risk Management - Guidelines
Principles and framework (risk attitude and risk appetite)
- cited in 1 question
NIST SP 800-37 Rev. 2: Risk Management Framework for Information Systems and Organizations
Risk-management roles and the risk register
- cited in 1 question
NIST SP 800-57 Part 1 Rev. 5: Recommendation for Key Management
Section on security services (non-repudiation and digital signatures)
- cited in 1 question
NIST SP 800-61 Rev. 2: Computer Security Incident Handling Guide
Section 3.3, Containment, Eradication, and Recovery
- cited in 1 question
ISACA COBIT 2019 Framework: Governance and Management Objectives
DSS06, Managed Business Process Controls (segregation of duties)
- cited in 1 question
NIST SP 800-92: Guide to Computer Security Log Management
Section 2, Introduction to Computer Security Log Management
How our mocks are built
Questions are written and edited by the ForensicSpot team and cited from peer-reviewed forensic textbooks, official syllabi and primary case law. Each one is verified before publishing. Detailed explanations show after you submit, so the test stays a real test. See a mistake? Tell us.
Common questions
What does the Information Security Audit: Foundations and Controls mock cover?+
This test covers the foundational vocabulary and concepts that underpin every information-security audit. You will work through the CIA triad and what each property means in practice, the three categories of controls (preventive, detective, corrective), and the essential elements of risk management including threats, vulnerabilities, and residual risk. The test also addresses audit types, the stages of a formal audit process, and core governance concepts such as segregation of duties, least priv
How many questions and how long is the test?+
30 multiple-choice questions, 30 minutes total. Difficulty: easy. Tier: Free.
Who is this mock for?+
Forensic science students and aspirants who want timed, exam-style practice with explanations and verified source citations on Information Security Audit and Compliance. Useful for postgraduate entrance preparation and for BSc / MSc forensic students testing their recall under time.
Are the questions reviewed?+
Each question carries a verified source citation. Faculty review for individual questions is in progress.
Do I need an account to take this mock?+
Yes, a free ForensicSpot account is required to start a timed attempt — this lets you save progress, see per-question explanations after submission, and track your topic-level performance over time.