Security Control Auditing Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security Control Auditing flashcards as text
An auditor reviewing identity and access management finds that 45 service accounts have passwords that have never been rotated. What is the MOST significant risk this presents?
Answer: Credential exposure from historical breaches going unmitigated
Static passwords on service accounts create persistent exposure if credentials were ever compromised, as there is no rotation to limit the window of unauthorized access.
Which audit standard specifically addresses the responsibilities of auditors when they discover potential illegal acts during a financial and IT control audit?
Answer: AU-C Section 250 (SAS 99)
AU-C Section 250 (formerly SAS 99) requires auditors to consider the possibility of illegal acts and establish reporting obligations when such acts are discovered.
A cybersecurity auditor is evaluating an organization's incident response capability. Which metric BEST indicates whether the IR process is maturing over time?
Answer: Mean time to detect (MTTD) and mean time to respond (MTTR) trends over multiple quarters
MTTD and MTTR trend data directly measure IR operational effectiveness over time, revealing whether the organization is improving at detecting and containing incidents.
Under FISMA audit requirements, which document establishes the security baseline for a federal information system and serves as the primary artifact an auditor reviews?
Answer: System Security Plan (SSP)
The System Security Plan (SSP) documents how security requirements are met for a federal system and is the primary document auditors use to assess FISMA compliance.
An auditor finds that a healthcare organization's risk assessment was last completed three years ago and does not reflect a recent EHR system migration. Under HIPAA, this represents a violation of which requirement?
Answer: §164.308(a)(1) – Risk analysis must be accurate and thorough of the current environment
HIPAA §164.308(a)(1) requires organizations to conduct an accurate and thorough risk analysis of the current environment — a stale assessment missing a major system migration fails this requirement.
During an audit of a security awareness program, which evidence would BEST demonstrate that training is actually changing employee behavior?
Answer: A reduction in simulated phishing click rates over successive campaigns
Declining simulated phishing click rates provide behavioral evidence that training is changing how employees respond to real threats, not just measuring participation.
An organization recently acquired a subsidiary and is integrating it into the corporate security program. Which audit activity should be performed FIRST to scope the integration effort?
Answer: Conduct a gap assessment comparing the subsidiary's controls against the parent's security standards
A gap assessment establishes the baseline difference between the subsidiary's current control posture and the required standards, which scopes all subsequent integration work.