Data Management and Database Controls Flashcards
6 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Data Management and Database Controls flashcards as text
Which database concept ensures that a transaction is either fully completed or fully rolled back, preventing partial updates that could corrupt data integrity?
Answer: Atomicity
Atomicity is the ACID property that guarantees a transaction is treated as a single indivisible unit โ it either completes entirely or is completely rolled back if any part fails.
A CISA auditor reviewing database security should verify that database administrators (DBAs) are PREVENTED from:
Answer: Accessing application data they administer without authorization
Separation of duties requires that DBAs responsible for infrastructure not have unrestricted access to sensitive application data, preventing insider fraud and unauthorized data access.
Which data management control MOST effectively ensures that data has not been altered during storage or transmission?
Answer: Hash-based integrity checks
Hash-based integrity checks (e.g., SHA-256 checksums) generate a fixed-length fingerprint of data that changes if the data is altered, providing a reliable mechanism to detect unauthorized modification.
When auditing database access controls, a CISA auditor should confirm that the principle of least privilege is applied by verifying:
Answer: Users are granted only the minimum access required for their job function
The principle of least privilege requires granting users only the minimum database permissions necessary to perform their specific job functions, reducing the risk of unauthorized data access or modification.
Which technique protects sensitive data in non-production environments by replacing real values with realistic but fictitious data?
Answer: Data masking
Data masking replaces sensitive real data with structurally similar but fictional values, allowing development and testing to occur without exposing actual sensitive information.
A CISA auditor finds that database audit logging is disabled. The MOST significant risk this creates is:
Answer: Inability to detect or investigate unauthorized data access or modification
Disabled audit logging eliminates the organization's ability to detect unauthorized access, reconstruct fraudulent transactions, or investigate data breaches, representing a critical control gap.