Technology & Digital Applications Flashcards
7 cards from real Certified Internal Auditor practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Technology & Digital Applications flashcards as text
Which type of malware encrypts an organization's files and demands payment for the decryption key?
Answer: Ransomware
Ransomware encrypts victim files or systems and extorts payment in exchange for providing the decryption key.
An auditor reviewing a vendor's SOC 2 Type II report is primarily evaluating which aspect of third-party risk?
Answer: Effectiveness of the vendor's controls over a period of time
A SOC 2 Type II report provides an independent assessment of whether a service organization's controls operated effectively over a specified review period.
What is the PRIMARY purpose of network segmentation from an information security perspective?
Answer: Limiting lateral movement by containing breaches to isolated segments
Network segmentation limits an attacker's ability to move laterally through the environment by isolating systems into separate network zones.
An organization's data classification policy assigns 'confidential' to certain records. Which control is MOST directly aligned with enforcing this classification?
Answer: Role-based access control restricting confidential data to authorized roles
Role-based access control directly enforces data classification by ensuring only authorized roles can access confidential information.
Which audit approach involves embedding continuous monitoring routines directly within an application to report exceptions in near real time?
Answer: Embedded audit modules
Embedded audit modules are routines inserted into application systems that automatically capture and report exception transactions for auditor review.
When evaluating an organization's digital transformation initiative, an internal auditor should FIRST assess which of the following?
Answer: Alignment of the initiative with the organization's strategic objectives and risk appetite
Auditors should first confirm that the digital transformation initiative aligns with organizational strategy and fits within the defined risk appetite before evaluating technical details.
Which Internet of Things (IoT) security risk is MOST challenging for organizations to manage?
Answer: Large volumes of unmanaged devices with limited security capabilities running on corporate networks
Many IoT devices lack robust security features and cannot be easily patched, making it difficult for organizations to manage the large attack surface they create.