Compliance & GRC Quiz
Governance, risk, and compliance — frameworks, audits, and the regulatory side of running IT responsibly.
This category currently has 100 questions in the SERVBG quiz bank. Below are a few sample questions — the full interactive quiz shuffles through the whole set with instant scoring.
Sample questions
In ISO/IEC 27001:2022, how many controls are listed in Annex A?
- 93
- 78
- 114
- 133
- 101
Which document in an ISO 27001 ISMS explicitly records which Annex A controls are applicable and justifies exclusions?
- Asset Register
- ISMS Policy
- Internal Audit Report
- Statement of Applicability (SoA)
- Risk Treatment Plan
Under ISO 27001:2022, which of the following is a NEW control theme that did NOT exist as a separate theme in the 2013 edition?
- Physical controls
- Organizational controls
- Operational controls
- Technological controls (Theme D)
- People controls
ISO 27001 requires internal audits to be conducted at what minimum frequency?
- Only before certification renewal
- Every two years
- Annually without exception
- At planned intervals determined by the organisation
- Every six months
During ISMS scope definition, an organisation excludes its data centre operations. Which statement is correct?
- Excluded areas require a separate ISO 27001 certificate.
- Exclusions are freely allowed if documented in the risk register only.
- Scope exclusions only need approval from the certification body.
- Exclusions must not affect the organisation's ability to achieve intended ISMS outcomes and must be justified in the SoA.
- ISO 27001 prohibits any scope exclusions once certification is sought.
Related categories
Python (Coding)
Python syntax, standard-library usage, and the language idioms that come up in day-to-day scripting and application work.
JavaScript (Coding)
Core JavaScript language behavior, async patterns, and the quirks that trip up both beginners and experienced developers.
Linux
Linux command-line usage, file permissions, process management, and the everyday admin tasks every sysadmin and developer needs.
Security
General information security concepts — threats, defenses, and the fundamentals every IT professional should know.
Hardware
Computer hardware components, how they interact, and the troubleshooting knowledge behind keeping systems running.