Controls & Risk
Audit Basics
QA in Practice
IT & Systems
Workplace Scenario
100

This type of control stops an issue before it happens.

What is a preventative control?

100

This is selecting a subset of data to test instead of everything.

What is sampling?

100

Reviewing work to ensure it meet standards is called this.

What is quality assurance? 

100

This principle means users should only have access needed for their job.

What is least privilege?

100

You test only what you expect to pass instead of trying to break it.

What is confirmation bias?

200

This control identifies issues after they occur.

What is a detective control?

200

This type of testing checks if a control is working effectively over time.

What is operating effectiveness (OE)?

200

This common issue happens when reviewers approve without fully checking.

What is the rubber stamp effect?

200

Reviewing user access regularly is known as this.

What is access review?

200

A control exist but no one follows it consistently.

What is a control failure?

300

Risk is commonly defined as this x impact.

What is likelihood?

300

This type of testing checks if a control is designed properly. 

What is design effectiveness (DE)?

300

Too many alerts causing people to ignore them is called this.

What is alert fatigue?

300

This happens when users have more access than necessary.

What is excessive access?

300

An issue happens because one small step was missed in a process.

What is a process gap?

M
e
n
u