โ† All CA Flashcard Decks

Information Systems Flashcards

7 cards from real CA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Information Systems flashcards as text
  1. An auditor reviewing an ERP system wants to ensure no single user can both approve purchase orders and record payments. This is an example of:

    Answer: Separation of duties

    Separation of duties prevents fraud and errors by requiring different individuals to perform incompatible functions within a process.

  2. Which encryption standard is currently recommended by NIST for protecting sensitive government and commercial data?

    Answer: AES

    AES (Advanced Encryption Standard) with 128-, 192-, or 256-bit keys is the NIST-approved standard for symmetric encryption.

  3. In the context of IT auditing, a 'logic bomb' refers to:

    Answer: Malicious code that executes when a specific condition or date is met

    A logic bomb is dormant malicious code triggered by a specific event, such as a date, user action, or system condition.

  4. Which SDLC phase involves translating system requirements into detailed technical specifications?

    Answer: System design

    The system design phase converts the logical requirements identified during analysis into detailed technical blueprints for construction.

  5. A company uses tokenization for credit card data. What does tokenization accomplish?

    Answer: Replaces sensitive data with a non-sensitive placeholder that maps back to the original

    Tokenization substitutes sensitive data with a token that has no exploitable value, reducing PCI DSS scope.

  6. Which type of audit log would be most useful for investigating unauthorized changes to a general ledger?

    Answer: Database transaction log

    A database transaction log records all insert, update, and delete operations, enabling forensic reconstruction of unauthorized changes.

  7. The concept of 'data integrity' in information systems means that data is:

    Answer: Accurate, complete, and unaltered during storage and transmission

    Data integrity ensures information remains accurate, consistent, and unmodified except through authorized processes.