GRC IT Governance and Cybersecurity 5 — Questions and Answers
Question 1: A company undergoes a SOC 2 Type II audit. What distinguishes Type II from Type I?
- Type II tests control effectiveness over a period of time; Type I only tests design at a point in time (Correct answer)
- Type II covers more control categories than Type I
- Type II is performed by internal auditors; Type I by external auditors
- Type II applies to cloud providers; Type I applies to on-premises systems
Correct answer: Type II tests control effectiveness over a period of time; Type I only tests design at a point in time
SOC 2 Type II evaluates whether controls operated effectively over an audit period (typically 6–12 months), while Type I only assesses control design at a single point in time.
Question 2: Which cybersecurity governance principle requires that individuals only access information necessary to perform their job functions?
- Least privilege
- Need to know (Correct answer)
- Separation of duties
- Due care
Correct answer: Need to know
The need-to-know principle limits access to information strictly required for an individual's specific job role, minimizing exposure of sensitive data.
Question 3: An organization's cybersecurity governance program includes a risk register. What is the primary purpose of maintaining this document?
- To track identified risks, their likelihood, impact, and treatment status over time (Correct answer)
- To document all security incidents that have occurred
- To list all software vulnerabilities found during penetration testing
- To record employee security training completion dates
Correct answer: To track identified risks, their likelihood, impact, and treatment status over time
A risk register is a central repository that captures identified risks along with their assessment, ownership, and treatment plans for ongoing governance oversight.
Question 4: Under HIPAA, which governance role is responsible for overseeing the organization's compliance with privacy regulations?
- Privacy Officer (Correct answer)
- Chief Information Security Officer (CISO)
- Data Steward
- Compliance Auditor
Correct answer: Privacy Officer
HIPAA requires covered entities to designate a Privacy Officer responsible for developing and implementing privacy policies and procedures.
Question 5: Which cybersecurity governance activity involves simulating a breach scenario to test whether incident response procedures are effective?
- Tabletop exercise (Correct answer)
- Vulnerability assessment
- Security baseline review
- Control self-assessment
Correct answer: Tabletop exercise
A tabletop exercise is a discussion-based simulation where stakeholders walk through a hypothetical incident scenario to evaluate their response procedures.
Question 6: A GRC analyst is asked to perform due diligence on a cloud provider. Which action is most appropriate?
- Review the provider's SOC 2 report, certifications, and conduct a security questionnaire (Correct answer)
- Run a penetration test against the provider's production environment
- Request full access to the provider's source code for review
- Monitor the provider's network traffic logs in real time
Correct answer: Review the provider's SOC 2 report, certifications, and conduct a security questionnaire
Due diligence on cloud providers involves reviewing third-party audit reports, certifications (ISO 27001, SOC 2), and completing standardized security questionnaires.
Question 7: Which element of an IT governance framework defines the authority and decision-making rights for IT-related decisions across the organization?
- IT governance structure / decision rights model (Correct answer)
- IT risk appetite statement
- IT service catalog
- IT disaster recovery plan
Correct answer: IT governance structure / decision rights model
An IT governance structure or decision rights model defines who has authority to make specific IT decisions, ensuring accountability and alignment.
A company undergoes a SOC 2 Type II audit.
What distinguishes Type II from Type I?