Skip to content
Information Security Audit and ComplianceeasyFree

Information Security Audit: Foundations and Controls

Published:

Questions

30

Duration

30 min

Faculty-reviewed

0

Updated

09 Jun 2026

Score, per-question explanations and topic breakdown shown right after you submit.

About this mock

This test covers the foundational vocabulary and concepts that underpin every information-security audit. You will work through the CIA triad and what each property means in practice, the three categories of controls (preventive, detective, corrective), and the essential elements of risk management including threats, vulnerabilities, and residual risk. The test also addresses audit types, the stages of a formal audit process, and core governance concepts such as segregation of duties, least privilege, and information-security policy hierarchies. Questions draw on internationally recognised frameworks including ISO/IEC 27001, COBIT, and NIST SP 800-53. No prior audit experience is assumed. A correct answer demonstrates that you can recall definitions accurately, distinguish closely related terms, and recognise which concept applies in a given scenario.

Sources & references

Questions in this mock are written and verified against the following sources. Citations are recorded per question and shown in the explanation after submission.

  • ISO/IEC 27001:2022 Information Security Management Systems

    Annex A, Control 5.9, Inventory of Information and Other Associated Assets

    cited in 7 questions
  • ISO/IEC 27005:2022 Information Security Risk Management Guidance

    Clause 3, Terms and Definitions; risk-assessment guidance

    cited in 4 questions
  • NIST SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations

    Control Family PE, Physical and Environmental Protection

    cited in 4 questions
  • ISO 19011:2018 Guidelines for Auditing Management Systems

    Clause 6, Conducting an Audit (process stages)

    cited in 2 questions
  • IIA International Standards for the Professional Practice of Internal Auditing

    Performance Standards 2200-2340, Engagement Planning and Performing the Engagement

    cited in 2 questions
  • ISO/IEC 27002:2022 Information Security, Cybersecurity and Privacy Protection - Information Security Controls

    Control 5.1, Policies for Information Security

    cited in 2 questions
  • ISACA CISA Review Manual (Certified Information Systems Auditor)

    Domain 5, Protection of Information Assets (control classifications)

    cited in 1 question
  • ISACA Information Systems Auditing: Tools and Techniques (IS Audit and Assurance Standards)

    Guidance on audit types and compliance testing

    cited in 1 question
  • ISACA COBIT 2019 Framework: Introduction and Methodology

    Chapter 1, Overview of COBIT and the Core Model

    cited in 1 question
  • ISO 31000:2018 Risk Management - Guidelines

    Principles and framework (risk attitude and risk appetite)

    cited in 1 question
  • NIST SP 800-37 Rev. 2: Risk Management Framework for Information Systems and Organizations

    Risk-management roles and the risk register

    cited in 1 question
  • NIST SP 800-57 Part 1 Rev. 5: Recommendation for Key Management

    Section on security services (non-repudiation and digital signatures)

    cited in 1 question
  • NIST SP 800-61 Rev. 2: Computer Security Incident Handling Guide

    Section 3.3, Containment, Eradication, and Recovery

    cited in 1 question
  • ISACA COBIT 2019 Framework: Governance and Management Objectives

    DSS06, Managed Business Process Controls (segregation of duties)

    cited in 1 question
  • NIST SP 800-92: Guide to Computer Security Log Management

    Section 2, Introduction to Computer Security Log Management

    cited in 1 question

How our mocks are built

Questions are written and edited by the ForensicSpot team and cited from peer-reviewed forensic textbooks, official syllabi and primary case law. Each one is verified before publishing. Detailed explanations show after you submit, so the test stays a real test. See a mistake? Tell us.

Common questions

What does the Information Security Audit: Foundations and Controls mock cover?+

This test covers the foundational vocabulary and concepts that underpin every information-security audit. You will work through the CIA triad and what each property means in practice, the three categories of controls (preventive, detective, corrective), and the essential elements of risk management including threats, vulnerabilities, and residual risk. The test also addresses audit types, the stages of a formal audit process, and core governance concepts such as segregation of duties, least priv

How many questions and how long is the test?+

30 multiple-choice questions, 30 minutes total. Difficulty: easy. Tier: Free.

Who is this mock for?+

Forensic science students and aspirants who want timed, exam-style practice with explanations and verified source citations on Information Security Audit and Compliance. Useful for postgraduate entrance preparation and for BSc / MSc forensic students testing their recall under time.

Are the questions reviewed?+

Each question carries a verified source citation. Faculty review for individual questions is in progress.

Do I need an account to take this mock?+

Yes, a free ForensicSpot account is required to start a timed attempt — this lets you save progress, see per-question explanations after submission, and track your topic-level performance over time.

Browse more mocks

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.