Phase 0 · Self-assessment — Where would you start? · Lesson 1 of 2
Quiz
·
25 min
·
+20 pts
Twenty questions across five skill domains. Each one tests a different capability the GRC Engineer role requires. Get them right and you know where to skip ahead. Get them wrong and you know exactly which phase to spend more time in.
There is no failure here. The quiz is for your benefit, not gatekeeping.
Reading your self-assessment results
Quick check
Which SOC 2 Trust Services Criterion covers logical access controls — the place IAM policies, MFA, and IdP configuration land?
Quick check
In AWS IAM, you want to allow a role to read objects from `s3://audit-bucket/*` but explicitly nothing else. What's the smallest correct policy shape?
Quick check
Your CISO asks: 'For SOC 2 CC6.1, what does AWS handle vs. what do we handle?' What's the cleanest answer?
Quick check
You see this in a Terraform module review. Should it pass?
Quick check
An external auditor asks for evidence that you remove access when an employee leaves. What's the best response?
Quick check
Your company stores customer credit card numbers. Which standard specifically governs how you handle that data?
Quick check
What is the difference between encryption at rest and encryption in transit?
Quick check
An AWS KMS key has a key policy that grants Encrypt and Decrypt to a role, but also has a condition key requiring kms:ViaService = s3.us-east-1.amazonaws.com. What does the condition do?
Quick check
What does MDM (Mobile Device Management) primarily give a security team?
Quick check
Your company uses Conditional Access policies that require a compliant device to access cloud apps. An employee complains they cannot log in from their personal laptop. What is happening?
Quick check
What is the primary purpose of network segmentation in a cloud environment?
Quick check
A security group in AWS has an inbound rule allowing 0.0.0.0/0 on port 22 (SSH). Should this pass a compliance review?
Quick check
What is the difference between a policy and a control?
Quick check
You need to prove to an auditor that your S3 buckets have been encrypted for the entire audit period (12 months). What is the strongest evidence?
Quick check
What does OPA (Open Policy Agent) do?
Quick check
What is the relationship between likelihood and impact in a risk assessment?
Quick check
What is the purpose of a risk register?
Quick check
Under HIPAA, how many days does a covered entity have to notify affected individuals after discovering a breach of unsecured PHI?
Quick check
During an incident, what should happen BEFORE any remediation begins?
Quick check
What is the difference between a SOC 2 Type I and a SOC 2 Type II report?
16-20 correct: You have strong fundamentals across all domains. Jump to Phase 2 (Identity & Access) or Phase 8 (Translation Layer) for the depth that makes you dangerous.
11-15 correct: Solid foundation with some gaps. Start at Phase 1 (Foundations) to fill them, then move to Phase 2. Pay extra attention to the domains where you missed questions.
6-10 correct: You know some domains well and others not at all. That is the most common profile. Start at Phase 1 and work through sequentially. The phases you are strong in will go fast.
0-5 correct: Start at the beginning. The bootcamp assumes zero prerequisites. Every concept is explained from first principles. You will not be lost. Phase 0 → Phase 1 → Phase 2.
There is no leaderboard for the assessment. The point is honest calibration.