Your question is Owning a Security Controls Audit. Take a moment with it on the right.
Talk me through your thinking if you like. When you're confident, submit your answer and I'll grade it like a real screen (7/10 or better passes).
Tell me about a time you had to assess or audit a client's internal security controls when the environment was complex or poorly documented. How did you structure your approach, work with stakeholders to validate gaps, and communicate your findings and recommendations?