Information Technology Audits Flashcards
7 cards from real CBA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Information Technology Audits flashcards as text
During an IT audit, an auditor finds that a bank's privileged user accounts are shared among multiple administrators. What is the PRIMARY concern?
Answer: Inability to establish individual accountability
Shared privileged accounts eliminate individual accountability, making it impossible to attribute specific actions to a particular user during investigations.
Which framework is MOST commonly used by bank IT auditors to evaluate IT governance and management practices?
Answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is the primary framework used to evaluate IT governance and management in banking environments.
A bank's core banking system processes transactions without maintaining a complete audit log. Which risk does this PRIMARILY create?
Answer: Inability to detect and investigate unauthorized transactions
Without complete audit logs, the bank cannot detect unauthorized transactions, investigate fraud, or demonstrate regulatory compliance.
When auditing a bank's patch management process, what should an auditor verify FIRST?
Answer: The existence of a formal policy defining patch testing and deployment timelines
A formal patch management policy establishing testing requirements and deployment timelines is the foundational control that all other patch management activities depend on.
An IT auditor is reviewing a bank's data encryption practices. Which finding would be MOST critical to report?
Answer: Customer PII is transmitted over internal networks without encryption
Transmitting customer PII without encryption exposes sensitive data to interception and violates regulatory requirements, representing an immediate critical risk.
During an IT audit, an auditor discovers that a bank's firewall rules have not been reviewed in 36 months. What is the PRIMARY risk?
Answer: Outdated rules may permit unauthorized access or retain unnecessary open ports
Stale firewall rules may allow traffic that should be blocked or retain rules for decommissioned systems, creating unauthorized network access vulnerabilities.
Which control BEST mitigates the risk of SQL injection attacks against a bank's web-based customer portal?
Answer: Using parameterized queries and input validation
Parameterized queries prevent malicious SQL code from being executed by treating user input as data rather than executable code.