Compliance & Frameworks (NIST/ISO/SOC2) interview questions

36 Compliance & Frameworks (NIST/ISO/SOC2) questions from the Security bank, written for Indian campus drives and tech interviews. Every question has a verified answer and an AI-tutor explanation on placd.

Free to start: the 2-minute IT readiness check — six questions and a result.

Take the free IT readiness check

or take a mock interview set up for this area

1. What is ISO 27001?

Junior
  1. A.US law setting privacy and security requirements for protected health information
  2. B.international standard for establishing and certifying an information security management system
  3. C.voluntary framework organizing security around Identify, Protect, Detect, Respond, Recover (and Govern)
  4. D.AICPA audit report attesting controls for security, availability, confidentiality, and privacy

Answer + AI explanation with Pro

2. Which term means: "international standard for establishing and certifying an information security management system"?

Junior
  1. A.Audit trail
  2. B.ISO 27001
  3. C.Gap assessment
  4. D.SOC 2

Answer + AI explanation with Pro

3. Which statement is correct?

Junior
  1. A.ISO 27001 — US law setting privacy and security requirements for protected health information
  2. B.ISO 27001 — AICPA audit report attesting controls for security, availability, confidentiality, and privacy
  3. C.ISO 27001 — international standard for establishing and certifying an information security management system
  4. D.ISO 27001 — catalog of US federal security and privacy controls organized into control families

Answer + AI explanation with Pro

4. What is SOC 2?

Junior
  1. A.AICPA audit report attesting controls for security, availability, confidentiality, and privacy
  2. B.comparing current controls against a framework to identify deficiencies before an audit
  3. C.voluntary framework organizing security around Identify, Protect, Detect, Respond, Recover (and Govern)
  4. D.Type I assesses control design at a point in time; Type II tests operating effectiveness over a period

Answer + AI explanation with Pro

5. Which term means: "AICPA audit report attesting controls for security, availability, confidentiality, and privacy"?

Junior
  1. A.Audit trail
  2. B.Type I vs Type II (SOC 2)
  3. C.Gap assessment
  4. D.SOC 2

Answer + AI explanation with Pro

6. Which statement is correct?

Junior
  1. A.SOC 2 — catalog of US federal security and privacy controls organized into control families
  2. B.SOC 2 — AICPA audit report attesting controls for security, availability, confidentiality, and privacy
  3. C.SOC 2 — tamper-evident record of who did what and when, used for accountability and investigation
  4. D.SOC 2 — encoding control checks into automated policies that continuously validate configurations

Answer + AI explanation with Pro

7. What is PCI DSS?

Junior
  1. A.tamper-evident record of who did what and when, used for accountability and investigation
  2. B.EU regulation governing the protection and processing of personal data
  3. C.payment card industry standard for protecting cardholder data
  4. D.catalog of US federal security and privacy controls organized into control families

Answer + AI explanation with Pro

8. Which term means: "payment card industry standard for protecting cardholder data"?

Junior
  1. A.SOC 2
  2. B.Gap assessment
  3. C.PCI DSS
  4. D.Audit trail

Answer + AI explanation with Pro

9. Which statement is correct?

Junior
  1. A.PCI DSS — encoding control checks into automated policies that continuously validate configurations
  2. B.PCI DSS — payment card industry standard for protecting cardholder data
  3. C.PCI DSS — Type I assesses control design at a point in time; Type II tests operating effectiveness over a period
  4. D.PCI DSS — international standard for establishing and certifying an information security management system

Answer + AI explanation with Pro

10. What is GDPR?

Junior
  1. A.Type I assesses control design at a point in time; Type II tests operating effectiveness over a period
  2. B.payment card industry standard for protecting cardholder data
  3. C.EU regulation governing the protection and processing of personal data
  4. D.comparing current controls against a framework to identify deficiencies before an audit

Answer + AI explanation with Pro

11. Which term means: "EU regulation governing the protection and processing of personal data"?

Junior
  1. A.Data classification
  2. B.SOC 2
  3. C.GDPR
  4. D.PCI DSS

Answer + AI explanation with Pro

12. Which statement is correct?

Junior
  1. A.GDPR — Type I assesses control design at a point in time; Type II tests operating effectiveness over a period
  2. B.GDPR — voluntary framework organizing security around Identify, Protect, Detect, Respond, Recover (and Govern)
  3. C.GDPR — US law setting privacy and security requirements for protected health information
  4. D.GDPR — EU regulation governing the protection and processing of personal data

Answer + AI explanation with Pro

13. What is NIST Cybersecurity Framework?

Mid
  1. A.EU regulation governing the protection and processing of personal data
  2. B.voluntary framework organizing security around Identify, Protect, Detect, Respond, Recover (and Govern)
  3. C.international standard for establishing and certifying an information security management system
  4. D.comparing current controls against a framework to identify deficiencies before an audit

Answer + AI explanation with Pro

14. Which term means: "voluntary framework organizing security around Identify, Protect, Detect, Respond, Recover (and Govern)"?

Mid
  1. A.NIST Cybersecurity Framework
  2. B.PCI DSS
  3. C.GDPR
  4. D.Type I vs Type II (SOC 2)

Answer + AI explanation with Pro

15. Which statement is correct?

Mid
  1. A.NIST Cybersecurity Framework — Type I assesses control design at a point in time; Type II tests operating effectiveness over a period
  2. B.NIST Cybersecurity Framework — labeling data by sensitivity to apply appropriate handling and protection controls
  3. C.NIST Cybersecurity Framework — voluntary framework organizing security around Identify, Protect, Detect, Respond, Recover (and Govern)
  4. D.NIST Cybersecurity Framework — payment card industry standard for protecting cardholder data

Answer + AI explanation with Pro

16. What is HIPAA?

Mid
  1. A.EU regulation governing the protection and processing of personal data
  2. B.Type I assesses control design at a point in time; Type II tests operating effectiveness over a period
  3. C.international standard for establishing and certifying an information security management system
  4. D.US law setting privacy and security requirements for protected health information

Answer + AI explanation with Pro

17. Which term means: "US law setting privacy and security requirements for protected health information"?

Mid
  1. A.HIPAA
  2. B.Data classification
  3. C.GDPR
  4. D.NIST Cybersecurity Framework

Answer + AI explanation with Pro

18. Which statement is correct?

Mid
  1. A.HIPAA — international standard for establishing and certifying an information security management system
  2. B.HIPAA — Type I assesses control design at a point in time; Type II tests operating effectiveness over a period
  3. C.HIPAA — EU regulation governing the protection and processing of personal data
  4. D.HIPAA — US law setting privacy and security requirements for protected health information

Answer + AI explanation with Pro

19. What is Data classification?

Mid
  1. A.labeling data by sensitivity to apply appropriate handling and protection controls
  2. B.tamper-evident record of who did what and when, used for accountability and investigation
  3. C.international standard for establishing and certifying an information security management system
  4. D.AICPA audit report attesting controls for security, availability, confidentiality, and privacy

Answer + AI explanation with Pro

20. Which term means: "labeling data by sensitivity to apply appropriate handling and protection controls"?

Mid
  1. A.Data classification
  2. B.ISO 27001
  3. C.Audit trail
  4. D.GDPR

Answer + AI explanation with Pro

21. Which statement is correct?

Mid
  1. A.Data classification — voluntary framework organizing security around Identify, Protect, Detect, Respond, Recover (and Govern)
  2. B.Data classification — labeling data by sensitivity to apply appropriate handling and protection controls
  3. C.Data classification — Type I assesses control design at a point in time; Type II tests operating effectiveness over a period
  4. D.Data classification — catalog of US federal security and privacy controls organized into control families

Answer + AI explanation with Pro

22. What is Audit trail?

Mid
  1. A.catalog of US federal security and privacy controls organized into control families
  2. B.voluntary framework organizing security around Identify, Protect, Detect, Respond, Recover (and Govern)
  3. C.payment card industry standard for protecting cardholder data
  4. D.tamper-evident record of who did what and when, used for accountability and investigation

Answer + AI explanation with Pro

23. Which term means: "tamper-evident record of who did what and when, used for accountability and investigation"?

Mid
  1. A.Audit trail
  2. B.Data classification
  3. C.GDPR
  4. D.NIST 800-53

Answer + AI explanation with Pro

24. Which statement is correct?

Mid
  1. A.Audit trail — comparing current controls against a framework to identify deficiencies before an audit
  2. B.Audit trail — payment card industry standard for protecting cardholder data
  3. C.Audit trail — voluntary framework organizing security around Identify, Protect, Detect, Respond, Recover (and Govern)
  4. D.Audit trail — tamper-evident record of who did what and when, used for accountability and investigation

Answer + AI explanation with Pro

25. What is NIST 800-53?

Senior
  1. A.Type I assesses control design at a point in time; Type II tests operating effectiveness over a period
  2. B.catalog of US federal security and privacy controls organized into control families
  3. C.AICPA audit report attesting controls for security, availability, confidentiality, and privacy
  4. D.tamper-evident record of who did what and when, used for accountability and investigation

Answer + AI explanation with Pro

26. Which term means: "catalog of US federal security and privacy controls organized into control families"?

Senior
  1. A.Compliance as code
  2. B.NIST Cybersecurity Framework
  3. C.NIST 800-53
  4. D.PCI DSS

Answer + AI explanation with Pro

27. Which statement is correct?

Senior
  1. A.NIST 800-53 — international standard for establishing and certifying an information security management system
  2. B.NIST 800-53 — AICPA audit report attesting controls for security, availability, confidentiality, and privacy
  3. C.NIST 800-53 — comparing current controls against a framework to identify deficiencies before an audit
  4. D.NIST 800-53 — catalog of US federal security and privacy controls organized into control families

Answer + AI explanation with Pro

28. What is Type I vs Type II (SOC 2)?

Senior
  1. A.payment card industry standard for protecting cardholder data
  2. B.AICPA audit report attesting controls for security, availability, confidentiality, and privacy
  3. C.voluntary framework organizing security around Identify, Protect, Detect, Respond, Recover (and Govern)
  4. D.Type I assesses control design at a point in time; Type II tests operating effectiveness over a period

Answer + AI explanation with Pro

29. Which term means: "Type I assesses control design at a point in time; Type II tests operating effectiveness over a period"?

Senior
  1. A.NIST 800-53
  2. B.Data classification
  3. C.ISO 27001
  4. D.Type I vs Type II (SOC 2)

Answer + AI explanation with Pro

30. Which statement is correct?

Senior
  1. A.Type I vs Type II (SOC 2) — US law setting privacy and security requirements for protected health information
  2. B.Type I vs Type II (SOC 2) — labeling data by sensitivity to apply appropriate handling and protection controls
  3. C.Type I vs Type II (SOC 2) — Type I assesses control design at a point in time; Type II tests operating effectiveness over a period
  4. D.Type I vs Type II (SOC 2) — voluntary framework organizing security around Identify, Protect, Detect, Respond, Recover (and Govern)

Answer + AI explanation with Pro

Showing 30 of 36 Compliance & Frameworks (NIST/ISO/SOC2) questions — the full set, with answers, explanations and an AI tutor on every question, is inside.

Free to start

Start with a free readiness check

Sign up free for the 2-minute IT readiness check and a scored result. Answers, explanations and the AI tutor on every Compliance & Frameworks (NIST/ISO/SOC2) question come with Pro.

Take the free IT readiness check

or take a mock interview set up for this area

24,000+ questions & coding problemsSoftware & IT16,274 questionsGovernment jobs26 examsAptitudenew questions every timeAI practice interviewwith feedback65 topics to practiseMechanical1,149 questionsGATE ME9 papersEngineering Mathematics381 questions2-minute checkfreeDSA Problems1,422Civil1,005 questionsGATE CE9 papersCS Fundamentals1,209 questionsYour scores6 skillsSystem Design25Electrical / EEE1,047 questionsGATE EE9 papersRun your codeC++ · Java · PythonLow-Level Design144Electronics & Comm.975 questionsGATE EC9 papersAI help on every questionFull-Stack6,282Chemical1,005 questionsGATE CH9 papersAI whiteboardsystem designWork abroadEurope · remote · transfersESE ME1 paperGATE practice papers2019–2026ESE CE1 paperDate alertsbefore the last dateESE EE1 paperBehavioural courseHR round practiceESE ET1 paperResume optimizerProSSC JE ME1 paperApplication trackerSSC JE CE1 paperCompany-wise prepSSC JE EE1 paperRole roadmapsRRB JE1 subjectPriced in ₹UPI · cardsISRO SC1 paperGATE CS9 papersIBPS SO IT1 paperUGC NET CS1 paperSSC CGL26 papersIBPS PO26 papersRRB NTPC26 papersSSC CHSL26 papersIBPS Clerk26 papersSBI Clerk26 papersRRB Group D26 papersSSC CPO26 papersSSC GD26 papers