โ† All Certified Internal Auditor Flashcard Decks

Technology & Digital Applications Flashcards

7 cards from real Certified Internal Auditor practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Technology & Digital Applications flashcards as text
  1. Which cloud deployment model provides dedicated infrastructure exclusively for a single organization?

    Answer: Private cloud

    A private cloud provides dedicated infrastructure exclusively for one organization, offering greater control and security.

  2. An internal auditor reviewing IT general controls (ITGCs) would primarily focus on which of the following?

    Answer: Change management, access controls, and IT operations

    ITGCs encompass change management, logical access controls, and IT operations that underpin all application controls.

  3. What is the primary purpose of a data loss prevention (DLP) solution?

    Answer: Monitoring and preventing unauthorized transfer of sensitive data

    DLP solutions monitor, detect, and block unauthorized transmission of sensitive data outside the organization.

  4. Which blockchain characteristic ensures that once a transaction is recorded it cannot be altered?

    Answer: Immutability

    Immutability means that recorded blockchain transactions are cryptographically linked and cannot be changed without invalidating subsequent blocks.

  5. An auditor assessing robotic process automation (RPA) controls should prioritize reviewing which risk?

    Answer: Bot credentials with excessive privileges performing unauthorized actions

    RPA bots with overprivileged credentials can perform unauthorized actions at scale, making access control a critical risk.

  6. In the context of IT audit, what does a 'penetration test' simulate?

    Answer: An attacker attempting to exploit system vulnerabilities

    A penetration test simulates real-world attacks to identify exploitable vulnerabilities before malicious actors can leverage them.

  7. Which principle requires that users receive only the minimum system access needed to perform their job functions?

    Answer: Least privilege

    The principle of least privilege limits user access rights to only what is necessary, reducing the attack surface and potential for misuse.