CSC Security Control Auditing 2 — Questions and Answers
Question 1: During a security control audit, an auditor discovers that a firewall rule set has not been reviewed in 18 months. Which audit finding category best describes this?
- Control deficiency (Correct answer)
- Material weakness
- Significant deficiency
- Observation
Correct answer: Control deficiency
An unreviewed firewall rule set represents a control deficiency where the control is not operating as designed or intended.
Question 2: Which sampling method selects audit samples based on the monetary value or risk weighting of transactions?
- Random sampling
- Stratified sampling
- Judgmental sampling
- Monetary unit sampling (Correct answer)
Correct answer: Monetary unit sampling
Monetary unit sampling (MUS) gives each dollar unit an equal chance of selection, focusing audit attention on higher-value transactions.
Question 3: An organization uses a third-party service for payroll processing. Under SOC 2 Type II auditing, what document provides assurance about the service provider's controls?
- Penetration test report
- SOC 2 Type II report from the service organization (Correct answer)
- Vendor security questionnaire
- ISO 27001 certificate
Correct answer: SOC 2 Type II report from the service organization
A SOC 2 Type II report from the service organization provides independent assurance that its controls operated effectively over a defined period.
Question 4: What is the primary purpose of a compensating control in an audit context?
- To replace a failed detective control
- To satisfy a compliance requirement when the primary control cannot be implemented (Correct answer)
- To document exceptions in the audit trail
- To monitor the effectiveness of preventive controls
Correct answer: To satisfy a compliance requirement when the primary control cannot be implemented
Compensating controls are alternative measures that satisfy a compliance requirement when the standard control is not feasible to implement.
Question 5: An auditor is testing access controls and pulls a list of all user accounts. She compares this to HR termination records. What audit procedure is she performing?
- Reconciliation (Correct answer)
- Substantive testing
- Walkthrough
- Observation
Correct answer: Reconciliation
Reconciliation compares two data sets from different sources to identify discrepancies, here matching active accounts against HR termination data.
Question 6: Which NIST SP 800-53A assessment method involves the auditor watching personnel perform their duties to verify control operation?
- Interview
- Examine
- Test
- Observe (Correct answer)
Correct answer: Observe
NIST SP 800-53A defines 'Observe' as watching activities or processes being performed to verify that controls operate as documented.
Question 7: A control audit reveals that privileged access reviews are performed annually instead of the required quarterly cadence. This is best documented as a:
- Risk acceptance
- Policy exception
- Audit finding with a root cause and remediation plan (Correct answer)
- Inherent risk
Correct answer: Audit finding with a root cause and remediation plan
Deviations from required control frequencies are documented as audit findings with root cause analysis and a remediation timeline for management response.
During a security control audit, an auditor discovers that a firewall rule set has not been reviewed in 18 months.
Which audit finding category best describes this?