Information Security Audit: Frameworks, Standards and Control Testing
Published:
Questions
30
Duration
30 min
Faculty-reviewed
0
Updated
09 Jun 2026
About this mock
This test covers the core frameworks, standards, and methodologies that practitioners use to plan, execute, and report on information security audits. Questions draw on ISO/IEC 27001 and the Information Security Management System lifecycle, the NIST Cybersecurity Framework's five functions, COBIT governance principles, PCI-DSS cardholder data environment requirements, and foundational data-protection principles under major regulatory regimes. The test also probes the practical skills auditors need in the field: selecting appropriate evidence types, applying statistical and judgement-based sampling, testing preventive versus detective controls, and interpreting control gaps. Scenarios are drawn from realistic audit situations spanning financial services, healthcare, cloud-hosted environments, and cross-border data transfers, reflecting the global nature of information security governance. Designed for practitioners and advanced learners who want to move beyond definition recall and engage with applied audit decision-making.
Sources & references
Questions in this mock are written and verified against the following sources. Citations are recorded per question and shown in the explanation after submission.
- cited in 7 questions
ISO/IEC 27001:2022 Information Security Management Systems
Clause 9.3.2 Management Review Inputs
- cited in 5 questions
ISACA IT Audit and Assurance Standards and Guidelines
Guideline 2205: Evidence, Testing of Controls
- cited in 4 questions
General Data Protection Regulation (GDPR) 2016/679
Chapter V Articles 44-49: Transfers of Personal Data to Third Countries
- cited in 3 questions
COBIT 2019 Framework: Governance and Management Objectives
EDM01 Ensure Governance Framework Setting and Maintenance; EDM03 Ensure Risk Optimisation
- cited in 2 questions
NIST Cybersecurity Framework Version 1.1
Core: Recover Function, RC.IM Subcategory
- cited in 2 questions
NIST Special Publication 800-40 Rev. 4: Guide to Enterprise Patch Management Planning
Section 3: Risk-Based Prioritisation Using CVSS and Threat Context
- cited in 2 questions
PCI DSS v4.0
Requirement 1.3.2 Restricting Inbound and Outbound CDE Traffic
- cited in 1 question
ISO/IEC 27001:2022 and ISO/IEC 27002:2022
Control 8.28 Secure Coding; ISO/IEC 27002:2022 Implementation Guidance
- cited in 1 question
AICPA SOC 2 Trust Services Criteria (2017 with revisions)
Confidentiality Criteria (C1.1, C1.2) and Logical Access Controls (CC6.1)
- cited in 1 question
PCI DSS v4.0 and SAQ A Instructions
PCI-DSS v4.0 Scoping Guidance and SAQ A Eligibility Criteria
- cited in 1 question
PCI DSS v4.0 and PCI P2PE Standard v3.1
PCI P2PE Standard: Merchant Requirements and Scoping Guidance
- cited in 1 question
The Digital Personal Data Protection Act, 2023 (India)
Data Fiduciary obligations on personal data breach and the Data Protection Board of India
How our mocks are built
Questions are written and edited by the ForensicSpot team and cited from peer-reviewed forensic textbooks, official syllabi and primary case law. Each one is verified before publishing. Detailed explanations show after you submit, so the test stays a real test. See a mistake? Tell us.
Common questions
What does the Information Security Audit: Frameworks, Standards and Control Testing mock cover?+
This test covers the core frameworks, standards, and methodologies that practitioners use to plan, execute, and report on information security audits. Questions draw on ISO/IEC 27001 and the Information Security Management System lifecycle, the NIST Cybersecurity Framework's five functions, COBIT governance principles, PCI-DSS cardholder data environment requirements, and foundational data-protection principles under major regulatory regimes. The test also probes the practical skills auditors ne
How many questions and how long is the test?+
30 multiple-choice questions, 30 minutes total. Difficulty: medium. Tier: Premium.
Who is this mock for?+
Forensic science students and aspirants who want timed, exam-style practice with explanations and verified source citations on Information Security Audit and Compliance. Useful for postgraduate entrance preparation and for BSc / MSc forensic students testing their recall under time.
Are the questions reviewed?+
Each question carries a verified source citation. Faculty review for individual questions is in progress.
Do I need an account to take this mock?+
Yes, a free ForensicSpot account is required to start a timed attempt — this lets you save progress, see per-question explanations after submission, and track your topic-level performance over time.