E.g. someone running an automated vulnerability scanner that may not even be entirely appropriate for the application being scanned could be considered a pen test or perhaps OWASP mitigation.
TOTP software authenticator on the same machine as the password safe? Totally 2FA.
Security training for employees? Some mind-numbing videos of a consultant reading the OWASP list from 2011 over some powerpoint slides and mentioning some buzzwords, employees self-certify having watched these videos.
So stretching the truth could be:
Do you adhere to NIST?
The truth could be: "well not exactly but that's on our roadmap,we do somethings that are close enough." That would get a 'YES' check.
Or something like end to end encryption. The answer could be a 'YES' because a company uses front-end TLS and pretends to not completely understand the ask.
In this case it is mostly the business either forcing security to bs or another group (Sales?) filling out the response untruthfully because they are loosing revenue if they're honest.