โ† All CSC Flashcard Decks

Security Control Auditing Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Control Auditing flashcards as text
  1. During a security control audit, an auditor discovers that a firewall rule set has not been reviewed in 18 months. Which audit finding category best describes this?

    Answer: Control deficiency

    An unreviewed firewall rule set represents a control deficiency where the control is not operating as designed or intended.

  2. Which sampling method selects audit samples based on the monetary value or risk weighting of transactions?

    Answer: Monetary unit sampling

    Monetary unit sampling (MUS) gives each dollar unit an equal chance of selection, focusing audit attention on higher-value transactions.

  3. An organization uses a third-party service for payroll processing. Under SOC 2 Type II auditing, what document provides assurance about the service provider's controls?

    Answer: SOC 2 Type II report from the service organization

    A SOC 2 Type II report from the service organization provides independent assurance that its controls operated effectively over a defined period.

  4. What is the primary purpose of a compensating control in an audit context?

    Answer: To satisfy a compliance requirement when the primary control cannot be implemented

    Compensating controls are alternative measures that satisfy a compliance requirement when the standard control is not feasible to implement.

  5. An auditor is testing access controls and pulls a list of all user accounts. She compares this to HR termination records. What audit procedure is she performing?

    Answer: Reconciliation

    Reconciliation compares two data sets from different sources to identify discrepancies, here matching active accounts against HR termination data.

  6. Which NIST SP 800-53A assessment method involves the auditor watching personnel perform their duties to verify control operation?

    Answer: Observe

    NIST SP 800-53A defines 'Observe' as watching activities or processes being performed to verify that controls operate as documented.

  7. A control audit reveals that privileged access reviews are performed annually instead of the required quarterly cadence. This is best documented as a:

    Answer: Audit finding with a root cause and remediation plan

    Deviations from required control frequencies are documented as audit findings with root cause analysis and a remediation timeline for management response.

Security Control Auditing Flashcards โ€” CSC Study Cards with Answers