1. What is ISO 27001 ? Junior A. US law setting privacy and security requirements for protected health information B. international standard for establishing and certifying an information security management system C. voluntary framework organizing security around Identify, Protect, Detect, Respond, Recover (and Govern) D. AICPA audit report attesting controls for security, availability, confidentiality, and privacy Answer + AI explanation with Pro
2. Which term means: "international standard for establishing and certifying an information security management system"? Junior A. Audit trail B. ISO 27001 C. Gap assessment D. SOC 2 Answer + AI explanation with Pro
3. Which statement is correct? Junior A. ISO 27001 — US law setting privacy and security requirements for protected health information B. ISO 27001 — AICPA audit report attesting controls for security, availability, confidentiality, and privacy C. ISO 27001 — international standard for establishing and certifying an information security management system D. ISO 27001 — catalog of US federal security and privacy controls organized into control families Answer + AI explanation with Pro
4. What is SOC 2 ? Junior A. AICPA audit report attesting controls for security, availability, confidentiality, and privacy B. comparing current controls against a framework to identify deficiencies before an audit C. voluntary framework organizing security around Identify, Protect, Detect, Respond, Recover (and Govern) D. Type I assesses control design at a point in time; Type II tests operating effectiveness over a period Answer + AI explanation with Pro
5. Which term means: "AICPA audit report attesting controls for security, availability, confidentiality, and privacy"? Junior A. Audit trail B. Type I vs Type II (SOC 2) C. Gap assessment D. SOC 2 Answer + AI explanation with Pro
6. Which statement is correct? Junior A. SOC 2 — catalog of US federal security and privacy controls organized into control families B. SOC 2 — AICPA audit report attesting controls for security, availability, confidentiality, and privacy C. SOC 2 — tamper-evident record of who did what and when, used for accountability and investigation D. SOC 2 — encoding control checks into automated policies that continuously validate configurations Answer + AI explanation with Pro
7. What is PCI DSS ? Junior A. tamper-evident record of who did what and when, used for accountability and investigation B. EU regulation governing the protection and processing of personal data C. payment card industry standard for protecting cardholder data D. catalog of US federal security and privacy controls organized into control families Answer + AI explanation with Pro
8. Which term means: "payment card industry standard for protecting cardholder data"? Junior A. SOC 2 B. Gap assessment C. PCI DSS D. Audit trail Answer + AI explanation with Pro
9. Which statement is correct? Junior A. PCI DSS — encoding control checks into automated policies that continuously validate configurations B. PCI DSS — payment card industry standard for protecting cardholder data C. PCI DSS — Type I assesses control design at a point in time; Type II tests operating effectiveness over a period D. PCI DSS — international standard for establishing and certifying an information security management system Answer + AI explanation with Pro
10. What is GDPR ? Junior A. Type I assesses control design at a point in time; Type II tests operating effectiveness over a period B. payment card industry standard for protecting cardholder data C. EU regulation governing the protection and processing of personal data D. comparing current controls against a framework to identify deficiencies before an audit Answer + AI explanation with Pro
11. Which term means: "EU regulation governing the protection and processing of personal data"? Junior A. Data classification B. SOC 2 C. GDPR D. PCI DSS Answer + AI explanation with Pro
12. Which statement is correct? Junior A. GDPR — Type I assesses control design at a point in time; Type II tests operating effectiveness over a period B. GDPR — voluntary framework organizing security around Identify, Protect, Detect, Respond, Recover (and Govern) C. GDPR — US law setting privacy and security requirements for protected health information D. GDPR — EU regulation governing the protection and processing of personal data Answer + AI explanation with Pro
13. What is NIST Cybersecurity Framework ? Mid A. EU regulation governing the protection and processing of personal data B. voluntary framework organizing security around Identify, Protect, Detect, Respond, Recover (and Govern) C. international standard for establishing and certifying an information security management system D. comparing current controls against a framework to identify deficiencies before an audit Answer + AI explanation with Pro
14. Which term means: "voluntary framework organizing security around Identify, Protect, Detect, Respond, Recover (and Govern)"? Mid A. NIST Cybersecurity Framework B. PCI DSS C. GDPR D. Type I vs Type II (SOC 2) Answer + AI explanation with Pro
15. Which statement is correct? Mid A. NIST Cybersecurity Framework — Type I assesses control design at a point in time; Type II tests operating effectiveness over a period B. NIST Cybersecurity Framework — labeling data by sensitivity to apply appropriate handling and protection controls C. NIST Cybersecurity Framework — voluntary framework organizing security around Identify, Protect, Detect, Respond, Recover (and Govern) D. NIST Cybersecurity Framework — payment card industry standard for protecting cardholder data Answer + AI explanation with Pro
16. What is HIPAA ? Mid A. EU regulation governing the protection and processing of personal data B. Type I assesses control design at a point in time; Type II tests operating effectiveness over a period C. international standard for establishing and certifying an information security management system D. US law setting privacy and security requirements for protected health information Answer + AI explanation with Pro
17. Which term means: "US law setting privacy and security requirements for protected health information"? Mid A. HIPAA B. Data classification C. GDPR D. NIST Cybersecurity Framework Answer + AI explanation with Pro
18. Which statement is correct? Mid A. HIPAA — international standard for establishing and certifying an information security management system B. HIPAA — Type I assesses control design at a point in time; Type II tests operating effectiveness over a period C. HIPAA — EU regulation governing the protection and processing of personal data D. HIPAA — US law setting privacy and security requirements for protected health information Answer + AI explanation with Pro
19. What is Data classification ? Mid A. labeling data by sensitivity to apply appropriate handling and protection controls B. tamper-evident record of who did what and when, used for accountability and investigation C. international standard for establishing and certifying an information security management system D. AICPA audit report attesting controls for security, availability, confidentiality, and privacy Answer + AI explanation with Pro
20. Which term means: "labeling data by sensitivity to apply appropriate handling and protection controls"? Mid A. Data classification B. ISO 27001 C. Audit trail D. GDPR Answer + AI explanation with Pro
21. Which statement is correct? Mid A. Data classification — voluntary framework organizing security around Identify, Protect, Detect, Respond, Recover (and Govern) B. Data classification — labeling data by sensitivity to apply appropriate handling and protection controls C. Data classification — Type I assesses control design at a point in time; Type II tests operating effectiveness over a period D. Data classification — catalog of US federal security and privacy controls organized into control families Answer + AI explanation with Pro
22. What is Audit trail ? Mid A. catalog of US federal security and privacy controls organized into control families B. voluntary framework organizing security around Identify, Protect, Detect, Respond, Recover (and Govern) C. payment card industry standard for protecting cardholder data D. tamper-evident record of who did what and when, used for accountability and investigation Answer + AI explanation with Pro
23. Which term means: "tamper-evident record of who did what and when, used for accountability and investigation"? Mid A. Audit trail B. Data classification C. GDPR D. NIST 800-53 Answer + AI explanation with Pro
24. Which statement is correct? Mid A. Audit trail — comparing current controls against a framework to identify deficiencies before an audit B. Audit trail — payment card industry standard for protecting cardholder data C. Audit trail — voluntary framework organizing security around Identify, Protect, Detect, Respond, Recover (and Govern) D. Audit trail — tamper-evident record of who did what and when, used for accountability and investigation Answer + AI explanation with Pro
25. What is NIST 800-53 ? Senior A. Type I assesses control design at a point in time; Type II tests operating effectiveness over a period B. catalog of US federal security and privacy controls organized into control families C. AICPA audit report attesting controls for security, availability, confidentiality, and privacy D. tamper-evident record of who did what and when, used for accountability and investigation Answer + AI explanation with Pro
26. Which term means: "catalog of US federal security and privacy controls organized into control families"? Senior A. Compliance as code B. NIST Cybersecurity Framework C. NIST 800-53 D. PCI DSS Answer + AI explanation with Pro
27. Which statement is correct? Senior A. NIST 800-53 — international standard for establishing and certifying an information security management system B. NIST 800-53 — AICPA audit report attesting controls for security, availability, confidentiality, and privacy C. NIST 800-53 — comparing current controls against a framework to identify deficiencies before an audit D. NIST 800-53 — catalog of US federal security and privacy controls organized into control families Answer + AI explanation with Pro
28. What is Type I vs Type II (SOC 2) ? Senior A. payment card industry standard for protecting cardholder data B. AICPA audit report attesting controls for security, availability, confidentiality, and privacy C. voluntary framework organizing security around Identify, Protect, Detect, Respond, Recover (and Govern) D. Type I assesses control design at a point in time; Type II tests operating effectiveness over a period Answer + AI explanation with Pro
29. Which term means: "Type I assesses control design at a point in time; Type II tests operating effectiveness over a period"? Senior A. NIST 800-53 B. Data classification C. ISO 27001 D. Type I vs Type II (SOC 2) Answer + AI explanation with Pro
30. Which statement is correct? Senior A. Type I vs Type II (SOC 2) — US law setting privacy and security requirements for protected health information B. Type I vs Type II (SOC 2) — labeling data by sensitivity to apply appropriate handling and protection controls C. Type I vs Type II (SOC 2) — Type I assesses control design at a point in time; Type II tests operating effectiveness over a period D. Type I vs Type II (SOC 2) — voluntary framework organizing security around Identify, Protect, Detect, Respond, Recover (and Govern) Answer + AI explanation with Pro
Showing 30 of 36 Compliance & Frameworks (NIST/ISO/SOC2) questions — the full set, with answers, explanations and an AI tutor on every question, is inside.