DORA

DORA Practitioner

Implementing DORA in practice: incident classification thresholds, third-party contracts, and resilience testing programmes.

13 questions · 75% to pass · free

eurocompliant.com is not an accredited certification body. This is a self-paced educational assessment; the certificate confirms completion only, not a professional, statutory, or accredited qualification.

Your details

We'll email your certificate here if you pass. We may occasionally follow up about eurocompliant.com - you can unsubscribe any time.

Question 1 of 13

Under Article 34, which factors help determine whether an ICT-related incident or cyber threat is classified as 'major' or 'significant'?

Select all that apply.

Question 2 of 13

Article 19-type reporting obligations under DORA generally require financial entities to report major ICT-related incidents to whom?

Question 3 of 13

What is the purpose of Article 30's provisions on key contractual provisions for ICT third-party arrangements?

Question 4 of 13

Under Article 29, what is a 'preliminary assessment of ICT concentration risk' primarily concerned with?

Question 5 of 13

Under DORA, financial entities remain fully responsible for compliance with their ICT risk management obligations even when they outsource ICT functions to third parties.

Question 6 of 13

Article 44 introduces threat-led penetration testing (TLPT). Which entities are generally subject to this more advanced testing?

Question 7 of 13

What role do 'independent testers' typically play in a threat-led penetration test under DORA-aligned frameworks (e.g. TIBER-EU)?

Question 8 of 13

Under Article 6, what must the ICT risk management framework be reviewed and, where necessary, updated?

Question 9 of 13

What is the significance of maintaining a 'register of information' on contractual arrangements with ICT third-party providers?

Question 10 of 13

Article 10 requires financial entities to have mechanisms to promptly detect anomalous activities. What is this primarily aimed at supporting?

Question 11 of 13

Which elements would typically be part of a financial entity's ICT business continuity policy under DORA?

Select all that apply.

Question 12 of 13

Proportionality is a recurring theme in DORA — smaller and less complex financial entities may apply certain requirements in a manner proportionate to their size, nature, scale and complexity.

Question 13 of 13

What is a key difference between an 'ICT-related incident' and an 'ICT-related incident' classified as 'major' under DORA's framework?

0 of 13 answered