โ† All Certified Internal Auditor Flashcard Decks

Technology & Digital Applications Flashcards

7 cards from real Certified Internal Auditor practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Technology & Digital Applications flashcards as text
  1. When auditing an organization's use of artificial intelligence, which concern is MOST unique compared to traditional software audits?

    Answer: Model bias and explainability of automated decisions

    AI introduces unique risks around algorithmic bias and the inability to fully explain model decisions, which are not present in deterministic software.

  2. A company migrating its ERP system to the cloud should ensure which control is in place to prevent unauthorized data access during migration?

    Answer: Data encryption in transit

    Encrypting data in transit protects sensitive information from interception during the cloud migration process.

  3. Which metric best measures the effectiveness of an organization's patch management program?

    Answer: Percentage of critical vulnerabilities remediated within defined SLAs

    Measuring the percentage of critical vulnerabilities patched within SLAs directly assesses whether the patch management program is timely and effective.

  4. What is the role of a Security Information and Event Management (SIEM) system?

    Answer: Aggregating and correlating security log data for threat detection

    A SIEM collects, aggregates, and correlates security event data from multiple sources to identify potential threats and support incident response.

  5. Which type of IT audit procedure would BEST verify that terminated employees' access has been revoked?

    Answer: Comparing active user accounts to current employee records

    Comparing active system accounts against current HR records directly tests whether terminated employee access has actually been removed.

  6. In a containerized application environment, which security risk is MOST specific to container technology?

    Answer: Container escape allowing access to the host system

    Container escape vulnerabilities allow malicious processes to break out of the container sandbox and gain access to the underlying host system.

  7. An auditor discovers that application developers also have access to the production environment. This PRIMARILY represents a failure of which control?

    Answer: Segregation of duties

    Allowing developers access to production violates segregation of duties, as they could deploy unauthorized code or manipulate production data.