18 cards · Foundations, Practitioner, Applied, Advanced, Expert
GRC interview questions and practice topics
Governance, risk and compliance (GRC): risk assessment, ISO 27001, SOC 2, NIST CSF, GDPR, policies, third-party risk and explaining security to the board.
Each card is a topic to explain out loud against the clock: 8 are real interview questions, the rest are concepts, live incidents and deep dives. Open one to see what a strong answer covers, or open cardosec and pick GRC as a focus.
L1 Foundations What it is
- BCP vs DR: RTO and RPOExplain
- Least PrivilegeExplain
- NIST Cybersecurity Framework 2.0Walk me through the NIST Cybersecurity Framework and how an organization would actually use it.Explain · Interview
- Risk vs Threat vs VulnerabilityExplain the difference between a risk, a threat, and a vulnerability, with one example tying them together.Explain · Interview
L2 Practitioner How it works
L3 Applied Abuse and defence in real systems
- Auditor Finds Orphaned AdminsAn auditor flags terminated users with live prod admin access. What do you do in the next 48 hours and after?Incident · Interview
- Payroll Vendor Breach NoticeA critical vendor tells you they were breached and your employee data was taken. How do you respond?Incident · Interview
- Risk Appetite and ToleranceHow would you define and operationalize a cyber risk appetite so that it actually drives decisions?Explain · Interview
- Security Awareness MetricsExplain
- Third-Party Vendor RiskExplain · Deep dive
- Zero Trust ArchitectureZero trust is often called a buzzword. What does it actually mean architecturally, and how would you start adopting it?Explain · Interview · Deep dive
L4 Advanced Edge cases, bypasses, trade-offs
L5 Expert Research-grade, architecture-level
Other domains
Web AppSec · Network · Identity & AD · Cloud · Cryptography · Blue team / DFIR · Malware & intel · Famous breaches · AI security