>_ CYBERVERSE.AI
GRC interview question
What is a Statement of Applicability and how do you build one?
What interviewers are really testing
SoA as the bridge between risk assessment and Annex A
Justified inclusions AND exclusions
Awareness of the 2022 revision structure
A strong answer framework
List all Annex A controls (93 in the 2022 revision)
Mark each applicable or not
Justify every exclusion with a risk-based reason
Reference the implemented control or implementation plan
Obtain risk-owner sign-off and keep it versioned
Follow-ups you should be ready for
Can leadership (A.5) controls be excluded?
SoA vs risk register - the difference?
Reading answers is not the same as defending them.
Practice this question live with an AI interviewer that scores you out of 100.
Practice this question free at CyberVerse AI →
More real GRC interview questions
A domain controller is making outbound connections to an external IP on port 443. No maintenance is scheduled. How do you investigate?
A user reports clicking a link in a phishing email. Walk me through your response.
How would you write a Splunk search to detect multiple failed logins followed by a success?