Module Assessment — Enterprise Governance, Risk & Compliance (GRC)
Module Assessment — Enterprise Governance, Risk & Compliance (GRC)
Section titled “Module Assessment — Enterprise Governance, Risk & Compliance (GRC)”Assessment Overview
Section titled “Assessment Overview”Congratulations!
You have completed Module 15 — Enterprise Governance, Risk & Compliance (GRC).
Throughout this module you learned how enterprise organizations build mature governance programs, manage cyber risks, comply with international standards, prepare for audits, manage third-party risks, build resilient organizations, and communicate cybersecurity performance to executive leadership.
This assessment validates your understanding before progressing to enterprise-level security architecture and leadership responsibilities.
Assessment Information
Section titled “Assessment Information”| Item | Details |
|---|---|
| Module | Module 15 — Enterprise Governance, Risk & Compliance (GRC) |
| Assessment Type | Multiple Choice Assessment |
| Questions | 40 |
| Passing Score | 70% |
| Time Limit | 60 Minutes |
| Difficulty | Intermediate |
Skills Being Assessed
Section titled “Skills Being Assessed”You will be evaluated on:
- Governance
- Enterprise Risk Management
- Security Policies
- Security Standards
- Compliance Frameworks
- Risk Assessments
- Security Audits
- Third-Party Risk
- Business Continuity
- Disaster Recovery
- Executive Reporting
- GRC Leadership
Enterprise Scenario
Section titled “Enterprise Scenario”CloudNova Technologies is preparing for its annual Board Security Review and ISO 27001 surveillance audit.
As a Cloud Security Engineer, you have been asked to assist the Governance, Risk & Compliance (GRC) team by reviewing enterprise security controls, validating compliance, assessing risks, and preparing evidence for executive reporting.
Successfully completing this assessment demonstrates that you understand enterprise GRC practices and can contribute effectively to governance and compliance programs.
Section 1 — Governance
Section titled “Section 1 — Governance”Question 1
Section titled “Question 1”What is the primary purpose of security governance?
A. Install software
B. Align security with business objectives
C. Increase internet speed
D. Configure firewalls
✅ Answer: B
Question 2
Section titled “Question 2”Who is primarily responsible for enterprise security strategy?
A. Intern
B. CISO
C. End User
D. Customer
✅ Answer: B
Question 3
Section titled “Question 3”Security policies are generally:
A. Optional
B. High-level mandatory management documents
C. Source code
D. Configuration files
✅ Answer: B
Question 4
Section titled “Question 4”Which document provides step-by-step implementation instructions?
A. Policy
B. Standard
C. Procedure
D. Guideline
✅ Answer: C
Question 5
Section titled “Question 5”Governance primarily focuses on:
A. Executive oversight
B. Hardware repair
C. Software installation
D. Programming
✅ Answer: A
Section 2 — Risk Management
Section titled “Section 2 — Risk Management”Question 6
Section titled “Question 6”Risk is generally calculated using:
A. Asset + Network
B. Threat + Vulnerability + Impact
C. CPU + Memory
D. Firewall + VPN
✅ Answer: B
Question 7
Section titled “Question 7”Which is a valid risk treatment option?
A. Mitigate
B. Accept
C. Transfer
D. All of the above
✅ Answer: D
Question 8
Section titled “Question 8”A Risk Register contains:
A. Employee salaries
B. Documented organizational risks
C. Source code
D. DNS records
✅ Answer: B
Question 9
Section titled “Question 9”Residual Risk is:
A. Remaining risk after controls are applied
B. Initial risk
C. Accepted malware
D. Firewall configuration
✅ Answer: A
Question 10
Section titled “Question 10”Risk Appetite is defined by:
A. Executive leadership
B. Interns
C. Customers
D. Vendors
✅ Answer: A
Section 3 — Compliance
Section titled “Section 3 — Compliance”Question 11
Section titled “Question 11”ISO/IEC 27001 focuses on:
A. Wireless Networking
B. Information Security Management Systems
C. Web Development
D. Programming
✅ Answer: B
Question 12
Section titled “Question 12”PCI DSS applies primarily to:
A. Healthcare
B. Payment Card Data
C. Cloud Storage
D. DNS
✅ Answer: B
Question 13
Section titled “Question 13”GDPR protects:
A. Source Code
B. Personal Data
C. Databases
D. Firewalls
✅ Answer: B
Question 14
Section titled “Question 14”SOC 2 evaluates:
A. Trust Services Criteria
B. Cloud Providers
C. Linux
D. Kubernetes
✅ Answer: A
Question 15
Section titled “Question 15”Compliance demonstrates that:
A. Security controls meet required obligations
B. Networks are faster
C. Storage is larger
D. Applications run quicker
✅ Answer: A
Section 4 — Audits
Section titled “Section 4 — Audits”Question 16
Section titled “Question 16”An Internal Audit is usually performed by:
A. Internal Audit Team
B. Customers
C. Hackers
D. Vendors
✅ Answer: A
Question 17
Section titled “Question 17”Audit evidence includes:
A. Security policies
B. Logs
C. Risk assessments
D. All of the above
✅ Answer: D
Question 18
Section titled “Question 18”Audit findings should:
A. Be ignored
B. Be remediated
C. Be deleted
D. Never be documented
✅ Answer: B
Question 19
Section titled “Question 19”An audit primarily verifies:
A. Control effectiveness
B. Internet bandwidth
C. CPU performance
D. Storage capacity
✅ Answer: A
Question 20
Section titled “Question 20”Continuous compliance means:
A. Monitoring controls continuously
B. Auditing once every ten years
C. Never reviewing policies
D. Ignoring evidence
✅ Answer: A
Section 5 — Third-Party Risk
Section titled “Section 5 — Third-Party Risk”Question 21
Section titled “Question 21”Third-party risk management evaluates:
A. Vendors
B. Cloud providers
C. SaaS platforms
D. All of the above
✅ Answer: D
Question 22
Section titled “Question 22”Supply chain attacks often target:
A. Trusted software providers
B. Keyboards
C. Printers
D. Office furniture
✅ Answer: A
Question 23
Section titled “Question 23”Vendor due diligence should occur:
A. Before onboarding
B. After a breach
C. Never
D. Only after contract renewal
✅ Answer: A
Question 24
Section titled “Question 24”High-risk vendors require:
A. Greater oversight
B. Less monitoring
C. No assessment
D. Smaller contracts
✅ Answer: A
Question 25
Section titled “Question 25”Open-source dependencies should be:
A. Continuously monitored
B. Ignored
C. Deleted
D. Hidden
✅ Answer: A
Section 6 — Business Continuity
Section titled “Section 6 — Business Continuity”Question 26
Section titled “Question 26”BCP stands for:
A. Business Continuity Planning
B. Backup Control Process
C. Business Cloud Platform
D. Business Change Plan
✅ Answer: A
Question 27
Section titled “Question 27”Disaster Recovery primarily focuses on:
A. Restoring IT services
B. Hiring employees
C. Managing payroll
D. Marketing
✅ Answer: A
Question 28
Section titled “Question 28”RTO measures:
A. Maximum acceptable downtime
B. Backup size
C. CPU speed
D. Storage
✅ Answer: A
Question 29
Section titled “Question 29”RPO measures:
A. Acceptable data loss
B. Password complexity
C. Internet latency
D. VPN speed
✅ Answer: A
Question 30
Section titled “Question 30”Recovery plans should be:
A. Tested regularly
B. Written once
C. Hidden
D. Optional
✅ Answer: A
Section 7 — Security Metrics
Section titled “Section 7 — Security Metrics”Question 31
Section titled “Question 31”KPIs measure:
A. Performance
B. Risk
C. Hardware
D. Storage
✅ Answer: A
Question 32
Section titled “Question 32”KRIs measure:
A. Risk exposure
B. Programming quality
C. Disk space
D. CPU usage
✅ Answer: A
Question 33
Section titled “Question 33”Executives prefer reports focused on:
A. Business impact
B. CLI commands
C. Packet captures
D. Source code
✅ Answer: A
Question 34
Section titled “Question 34”Security dashboards should summarize:
A. KPIs
B. KRIs
C. Compliance
D. All of the above
✅ Answer: D
Question 35
Section titled “Question 35”Security maturity should:
A. Continuously improve
B. Stay static
C. Decrease
D. Be ignored
✅ Answer: A
Section 8 — GRC Leadership
Section titled “Section 8 — GRC Leadership”Question 36
Section titled “Question 36”A successful GRC leader should:
A. Communicate business risk
B. Ignore executives
C. Avoid reporting
D. Eliminate documentation
✅ Answer: A
Question 37
Section titled “Question 37”Governance should align with:
A. Business strategy
B. Gaming
C. Social media
D. Advertising
✅ Answer: A
Question 38
Section titled “Question 38”Enterprise GRC primarily supports:
A. Secure business operations
B. Faster internet
C. Programming languages
D. Hardware upgrades
✅ Answer: A
Question 39
Section titled “Question 39”Continuous improvement is achieved by:
A. Measuring and reviewing regularly
B. Ignoring findings
C. Deleting reports
D. Avoiding audits
✅ Answer: A
Question 40
Section titled “Question 40”The ultimate goal of GRC is:
A. Enable secure, compliant and risk-aware business operations
B. Reduce documentation
C. Eliminate governance
D. Replace leadership
✅ Answer: A
Congratulations!
Section titled “Congratulations!”🎉 Congratulations on completing the Enterprise Governance, Risk & Compliance (GRC) Assessment.
You have successfully completed the Cloud Security Engineer Learning Path and demonstrated your understanding of enterprise governance, risk management, compliance, security operations, cloud security, AI fundamentals, Kubernetes security, and modern cybersecurity practices.
You are now prepared to apply these skills in enterprise cloud environments and continue building your expertise through hands-on GoHackersCloud Labs.