Information Technology and Systems Flashcards
6 cards from real BEC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Information Technology and Systems flashcards as text
Which of the following is an example of a general controls in IT?
Answer: Access controls governing who can log into the system
General IT controls apply broadly to the IT environment (access controls, change management, physical security), while application controls are specific to individual programs.
Big Data is typically characterized by which three 'V's?
Answer: Volume, Velocity, and Variety
Big Data is classically defined by Volume (enormous size), Velocity (high-speed generation), and Variety (diverse formats including structured and unstructured data).
An IT audit trail (transaction log) is most useful for:
Answer: Providing a chronological record of system activities for accountability and forensic review
An audit trail records a time-stamped log of all system and user activities, enabling auditors and investigators to reconstruct events and establish accountability.
Agile software development differs from traditional Waterfall methodology primarily because Agile:
Answer: Delivers software in iterative, incremental cycles with continuous stakeholder feedback
Agile methodology uses short development iterations (sprints) with ongoing collaboration and adaptation, contrasting with Waterfall's rigid sequential phase approach.
A two-factor authentication (2FA) system enhances security by requiring:
Answer: Something the user knows plus something the user has or is
2FA combines two distinct authentication factors — typically a password (something you know) with a physical token or biometric (something you have or are) — making unauthorized access much harder.
In IT risk management, a vulnerability is best described as:
Answer: A weakness in a system that could be exploited by a threat
A vulnerability is a flaw or weakness in hardware, software, or procedures that a threat actor could exploit to gain unauthorized access or cause harm.