IT Governance and Cybersecurity Flashcards
7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 IT Governance and Cybersecurity flashcards as text
A company undergoes a SOC 2 Type II audit. What distinguishes Type II from Type I?
Answer: Type II tests control effectiveness over a period of time; Type I only tests design at a point in time
SOC 2 Type II evaluates whether controls operated effectively over an audit period (typically 6–12 months), while Type I only assesses control design at a single point in time.
Which cybersecurity governance principle requires that individuals only access information necessary to perform their job functions?
Answer: Need to know
The need-to-know principle limits access to information strictly required for an individual's specific job role, minimizing exposure of sensitive data.
An organization's cybersecurity governance program includes a risk register. What is the primary purpose of maintaining this document?
Answer: To track identified risks, their likelihood, impact, and treatment status over time
A risk register is a central repository that captures identified risks along with their assessment, ownership, and treatment plans for ongoing governance oversight.
Under HIPAA, which governance role is responsible for overseeing the organization's compliance with privacy regulations?
Answer: Privacy Officer
HIPAA requires covered entities to designate a Privacy Officer responsible for developing and implementing privacy policies and procedures.
Which cybersecurity governance activity involves simulating a breach scenario to test whether incident response procedures are effective?
Answer: Tabletop exercise
A tabletop exercise is a discussion-based simulation where stakeholders walk through a hypothetical incident scenario to evaluate their response procedures.
A GRC analyst is asked to perform due diligence on a cloud provider. Which action is most appropriate?
Answer: Review the provider's SOC 2 report, certifications, and conduct a security questionnaire
Due diligence on cloud providers involves reviewing third-party audit reports, certifications (ISO 27001, SOC 2), and completing standardized security questionnaires.
Which element of an IT governance framework defines the authority and decision-making rights for IT-related decisions across the organization?
Answer: IT governance structure / decision rights model
An IT governance structure or decision rights model defines who has authority to make specific IT decisions, ensuring accountability and alignment.