New game
Download
Get Academic Plan
Share game
Integrate it into your platform

You can integrate the game into an LMS compatible with LTI 1.1 or LTI 1.3 such as Canvas, Moodle, or Blackboard. This way, the scores will be automatically saved into the platform’s gradebook.
Download
You have exceeded the maximum number of games you can integrate into Google Classroom with your current Plan.

To integrate as many games as you want in Google Classroom, you need an Academic Plan or a Commercial Plan.

You have exceeded the maximum number of games you can integrate into Microsoft Teams with your current Plan.

To integrate as many games as you want in Microsoft Teams, you need an Academic Plan or a Commercial Plan.

Downloading games is an exclusive feature for users with an Academic Plan or a Commercial Plan.

Get your Academic Plan or your Commercial Plan now and start integrating your games into your LMS, website or blog.

If you wish, you can download a demo game here and test its integration:

Security Audit Quiz

Quiz

Played 3

About this activity

Audit-focused questions

Created by

Czech Republic

Download the paper version to play

Make your own free game from our game creator
Compete against your friends to see who gets the best score in this game

Top Games

%
Anonymous
Anonymous
%
%
%
You have exceeded the maximum number of games you can print with your current Plan.

To print as many games as you want, you need an Academic Plan or a Commercial Plan.

Print your game
Security Audit Quiz
 

Security Audit QuizOnline version

Audit-focused questions

by Jorge Carrillo. PhD
1

A multinational bank plans to retain customer ciphertext for 25 years. The encryption uses RSA-2048. From a 2026 audit perspective, the MOST critical recommendation is to:

2

An IS auditor discovers that an enterprise's CI/CD pipeline signs container images with a key stored as a plaintext GitHub Actions secret. The PRIMARY risk is:

3

Investigation reveals that an attacker compromised a federated identity by obtaining a valid refresh token through a malicious OAuth consent screen on a lookalike domain. This attack is BEST classified as:

4

Under the CISA Zero Trust Maturity Model 2.0, which characteristic MOST clearly distinguishes the "Optimal" stage of the Identity pillar from "Advanced"?

5

During a wireless audit, the auditor notes that the enterprise uses WPA3-SAE with a shared passphrase for all employees. The MOST appropriate recommendation is to:

6

An IaaS customer is breached when an S3 bucket containing backups is made public due to an IaC misconfiguration. When allocating accountability under the shared responsibility model, the MOST accurate statement is:

7

An enterprise uses an AI assistant embedded in its CRM. Employees paste customer PII into the assistant to summarize support cases. The MOST material control gap from an audit perspective is:

8

A penetration test finds that an attacker who gains any Active Directory user credentials can request service tickets and escalate to Domain Admin because a service account with SPN has the password "Summer2024!" set ten years ago. The BEST remediation is:

9

An auditor reviews a SASE deployment and finds that TLS inspection is disabled for all traffic due to privacy concerns. The GREATEST resulting risk is:

10

An IS auditor is asked to assess the risk of "harvest now, decrypt later" against VPN traffic protecting M&A negotiations. Which single factor MOST increases the risk rating?

11

Which observation would MOST clearly indicate a failure of crypto-agility in an enterprise?