New game
Get Academic Plan

Security Audit Quiz

Quiz

Audit-focused questions

Download the paper version to play

3 times made

Created by

Czech Republic

Top 10 results

There are still no results for this game. Be the first to stay in the ranking! to identify yourself.
Make your own free game from our game creator
Compete against your friends to see who gets the best score in this game

Top Games

  1. time
    score
  1. time
    score
time
score
time
score
 
game-icon

Security Audit QuizOnline version

Audit-focused questions

by Jorge Carrillo. PhD
1

A multinational bank plans to retain customer ciphertext for 25 years. The encryption uses RSA-2048. From a 2026 audit perspective, the MOST critical recommendation is to:

2

An IS auditor discovers that an enterprise's CI/CD pipeline signs container images with a key stored as a plaintext GitHub Actions secret. The PRIMARY risk is:

3

Investigation reveals that an attacker compromised a federated identity by obtaining a valid refresh token through a malicious OAuth consent screen on a lookalike domain. This attack is BEST classified as:

4

Under the CISA Zero Trust Maturity Model 2.0, which characteristic MOST clearly distinguishes the "Optimal" stage of the Identity pillar from "Advanced"?

5

During a wireless audit, the auditor notes that the enterprise uses WPA3-SAE with a shared passphrase for all employees. The MOST appropriate recommendation is to:

6

An IaaS customer is breached when an S3 bucket containing backups is made public due to an IaC misconfiguration. When allocating accountability under the shared responsibility model, the MOST accurate statement is:

7

An enterprise uses an AI assistant embedded in its CRM. Employees paste customer PII into the assistant to summarize support cases. The MOST material control gap from an audit perspective is:

8

A penetration test finds that an attacker who gains any Active Directory user credentials can request service tickets and escalate to Domain Admin because a service account with SPN has the password "Summer2024!" set ten years ago. The BEST remediation is:

9

An auditor reviews a SASE deployment and finds that TLS inspection is disabled for all traffic due to privacy concerns. The GREATEST resulting risk is:

10

An IS auditor is asked to assess the risk of "harvest now, decrypt later" against VPN traffic protecting M&A negotiations. Which single factor MOST increases the risk rating?

11

Which observation would MOST clearly indicate a failure of crypto-agility in an enterprise?