Judge the evidence, rate the risk, scope the assessment, start the clock
GRC work is hands-on; the hands are just on evidence rather than a terminal. Each scenario puts you in the practitioner's seat with the artefacts you would actually be handed, and asks you to judge them - including the ones that are perfectly sound, because an auditor who raises findings against working controls loses the engagement.
You are auditing a quarterly user access review against ISO/IEC 27001. Six artefacts were submitted as evidence. Decide which are audit evidence and which are management assertions wearing a lanyard, then conclude on the right finding.
Six rows of a risk register, and most of them are wrong in a way that survives every review. Separate real risk statements from control gaps dressed as risks, fix a residual rating that double-counts its own mitigation, and choose a treatment the appetite actually supports.
A retailer wants its PCI DSS scope reduced and its GDPR roles settled before assessment. Decide what segmentation genuinely takes out of scope, what quietly pulls it back in, and whether the company is a controller or a processor for each flow.
Facts arrive over nine days and several regulatory clocks are already running. Work out when awareness actually began, which notifications are owed to whom, and why waiting for a complete forensic picture is the one option guaranteed to be late.