Skip to content
Information Security Audit and Compliancehard Premium

Information Security Audit: Risk Assessment, Cloud and Compliance

Published:

Questions

30

Duration

30 min

Faculty-reviewed

0

Updated

09 Jun 2026

Score, per-question explanations and topic breakdown shown right after you submit.

About this mock

This test evaluates advanced competency in information security auditing across the full risk-management lifecycle. Topics span quantitative risk metrics including Single Loss Expectancy, Annualized Rate of Occurrence, and Annualized Loss Expectancy; qualitative risk frameworks and their limitations; security maturity models such as CMMI and the SSE-CMM; continuous auditing and monitoring architectures; cloud-specific audit challenges including shared-responsibility boundaries and multi-tenancy risks; third-party and supply-chain risk assessment methodologies; audit report structure, findings classification, and remediation tracking; and compliance obligations across multiple regulatory jurisdictions including GDPR, HIPAA, SOX, and PCI-DSS. Questions are framed at the analysis level, requiring candidates to distinguish between closely related standards, apply principles to scenario-based fact patterns, and evaluate the appropriateness of specific controls or audit approaches in complex operational contexts.

Sources & references

Questions in this mock are written and verified against the following sources. Citations are recorded per question and shown in the explanation after submission.

  • ISACA CISA Review Manual

    Risk-based audit planning and quantitative risk analysis (SLE, ARO, ALE)

    cited in 3 questions
  • CSA Security Guidance for Critical Areas of Focus in Cloud Computing v4.0

    Domain 11: Encryption and Key Management

    cited in 2 questions
  • ISO 22301:2019: Security and Resilience - Business Continuity Management Systems - Requirements

    Business impact analysis and recovery objectives

    cited in 1 question
  • EDPB Guidelines 05/2020 on consent under Regulation 2016/679

    Children's consent and Article 8

    cited in 1 question
  • ISACA COBIT 2019 Framework: Governance and Management Objectives

    BAI06 Managed IT Changes

    cited in 1 question
  • Tony Cox, "What's Wrong with Risk Matrices?", Risk Analysis (2008)

    Limitations of ordinal risk-matrix scoring

    cited in 1 question
  • EU Directive 2022/2555 (NIS2): on measures for a high common level of cybersecurity across the Union

    Article 23, reporting obligations for significant incidents

    cited in 1 question
  • NIST SP 800-115: Technical Guide to Information Security Testing and Assessment

    Post-testing activities and remediation

    cited in 1 question
  • NIST SP 800-57 Part 1 Rev. 5: Recommendation for Key Management

    Key management for certification authorities and cryptoperiods

    cited in 1 question
  • NIST SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations

    AU-6 audit review, analysis, and reporting; SI-4 system monitoring and anomalous behaviour detection

    cited in 1 question
  • EDPB Recommendations 01/2020 on Measures that Supplement Transfer Tools to Ensure Compliance with the EU Level of Protection of Personal Data

    Use cases for technical supplementary measures

    cited in 1 question
  • Office of the Australian Information Commissioner: Data breach preparation and response - A guide to managing data breaches under the Privacy Act 1988

    Identifying eligible data breaches and the serious harm test

    cited in 1 question
  • NIST SP 800-161 Rev. 1: Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations

    C-SCRM practices and risk response

    cited in 1 question
  • AICPA: SOC 2 Reporting on an Examination of Controls at a Service Organization Relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy (SSAE 18)

    Subservice organizations and the carve-out method

    cited in 1 question
  • AICPA: SOC 2 Reporting on an Examination of Controls at a Service Organization (SSAE 18) and Trust Services Criteria

    Description of tests of controls and reporting of exceptions

    cited in 1 question
  • Board of Governors of the Federal Reserve System SR 11-7 / OCC Bulletin 2011-12: Supervisory Guidance on Model Risk Management

    Model validation: independence and scope of validation activities

    cited in 1 question
  • CIS Amazon Web Services Foundations Benchmark

    Identity and access management, least privilege for IAM policies

    cited in 1 question
  • ISO/IEC 21827: Information Technology - Systems Security Engineering - Capability Maturity Model

    Process capability levels

    cited in 1 question
  • ISO/IEC 17021-1: Conformity assessment - Requirements for bodies providing audit and certification of management systems

    Two-stage initial certification audit, Stage 1 and Stage 2

    cited in 1 question
  • CMMI Institute / ISACA: CMMI for Services (CMMI-SVC)

    Maturity Level 4, quantitatively managed processes

    cited in 1 question
  • Center for Internet Security: CIS Critical Security Controls v8

    Control 7, Continuous Vulnerability Management

    cited in 1 question
  • HHS: HIPAA Security Rule Guidance and 45 CFR 164.308(b) Business Associate Contracts

    Business associate contract requirements

    cited in 1 question
  • PCI Security Standards Council: PCI DSS v4.0

    Requirement 6.4.3, payment page script management

    cited in 1 question
  • NIST SP 800-137: Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations

    Defining metrics and analysis criteria for continuous monitoring

    cited in 1 question
  • PCAOB Auditing Standard AS 2201: An Audit of Internal Control Over Financial Reporting That Is Integrated with an Audit of Financial Statements

    IT general controls within the scope of an ICFR audit

    cited in 1 question
  • HHS Office for Civil Rights: Guidance on Risk Analysis Requirements under the HIPAA Security Rule

    Elements of a risk analysis

    cited in 1 question
  • Article 29 Working Party Guidelines on Data Protection Impact Assessment (WP248 rev.01), endorsed by the EDPB

    Criteria for processing likely to result in a high risk

    cited in 1 question

How our mocks are built

Questions are written and edited by the ForensicSpot team and cited from peer-reviewed forensic textbooks, official syllabi and primary case law. Each one is verified before publishing. Detailed explanations show after you submit, so the test stays a real test. See a mistake? Tell us.

Common questions

What does the Information Security Audit: Risk Assessment, Cloud and Compliance mock cover?+

This test evaluates advanced competency in information security auditing across the full risk-management lifecycle. Topics span quantitative risk metrics including Single Loss Expectancy, Annualized Rate of Occurrence, and Annualized Loss Expectancy; qualitative risk frameworks and their limitations; security maturity models such as CMMI and the SSE-CMM; continuous auditing and monitoring architectures; cloud-specific audit challenges including shared-responsibility boundaries and multi-tenancy

How many questions and how long is the test?+

30 multiple-choice questions, 30 minutes total. Difficulty: hard. Tier: Premium.

Who is this mock for?+

Forensic science students and aspirants who want timed, exam-style practice with explanations and verified source citations on Information Security Audit and Compliance. Useful for postgraduate entrance preparation and for BSc / MSc forensic students testing their recall under time.

Are the questions reviewed?+

Each question carries a verified source citation. Faculty review for individual questions is in progress.

Do I need an account to take this mock?+

Yes, a free ForensicSpot account is required to start a timed attempt — this lets you save progress, see per-question explanations after submission, and track your topic-level performance over time.

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.