CIA CIA Information Technology & Systems 1 — Questions and Answers
Question 1: Which IT general control category is most directly concerned with ensuring that only authorized users can access financial systems?
- Logical access controls (Correct answer)
- Change management controls
- Computer operations controls
- System development controls
Correct answer: Logical access controls
Logical access controls restrict system access to authorized users through passwords, roles, and authentication mechanisms.
Question 2: In an IT audit, a 'segregation of duties' weakness most commonly occurs when a single user can both:
- Read reports and print them
- Initiate transactions and approve them (Correct answer)
- View audit logs and export them
- Create user accounts and delete files
Correct answer: Initiate transactions and approve them
Segregation of duties requires that transaction initiation and approval be performed by different individuals to prevent fraud.
Question 3: What is the primary purpose of an IT change management process?
- To speed up software deployments
- To ensure changes to systems are authorized, tested, and documented (Correct answer)
- To track user complaints about software
- To monitor network bandwidth usage
Correct answer: To ensure changes to systems are authorized, tested, and documented
Change management controls ensure that all system modifications are properly authorized, tested, and documented before implementation.
Question 4: A CIA examiner reviewing a company's IT controls finds that system administrators also perform end-user functions. This is an example of a failure in:
- Business continuity planning
- Segregation of duties (Correct answer)
- Data encryption standards
- Patch management
Correct answer: Segregation of duties
Allowing system administrators to also perform end-user functions violates segregation of duties by giving one person excessive control.
Question 5: Which of the following best describes a 'data dictionary' in the context of IT general controls?
- A list of approved software vendors
- A repository defining the structure, format, and relationships of data elements (Correct answer)
- A log of all database transactions
- A glossary of IT audit terms
Correct answer: A repository defining the structure, format, and relationships of data elements
A data dictionary documents the definitions, formats, and relationships of data elements used across an organization's systems.
Question 6: During a CIA audit, an auditor assesses whether backups are stored offsite. This control is primarily designed to support:
- Access control compliance
- Business continuity and disaster recovery (Correct answer)
- Change management procedures
- User authentication standards
Correct answer: Business continuity and disaster recovery
Offsite backup storage ensures that data can be recovered in the event of a disaster that destroys the primary site.
Which IT general control category is most directly concerned with ensuring that only authorized users can access financial systems?