CBA Information Technology Audits 3 — Questions and Answers
Question 1: A bank's IT auditor is assessing vendor management controls for a cloud-based core banking provider. Which document is MOST important to review?
- The vendor's marketing brochure
- The Service Level Agreement and right-to-audit clause (Correct answer)
- The vendor's employee handbook
- The vendor's office lease agreement
Correct answer: The Service Level Agreement and right-to-audit clause
The SLA defines performance commitments and the right-to-audit clause ensures the bank can verify the vendor's controls, which is essential for regulatory compliance.
Question 2: An auditor reviewing a bank's IT change management process finds that emergency changes are frequently implemented without post-implementation review. What risk does this create?
- Increased project costs
- Unauthorized or poorly tested changes may persist in the production environment (Correct answer)
- Longer system development cycles
- Higher vendor dependency
Correct answer: Unauthorized or poorly tested changes may persist in the production environment
Without post-implementation reviews, emergency changes may introduce security vulnerabilities or operational errors that remain undetected in production.
Question 3: When auditing a bank's network segmentation controls, what is the auditor PRIMARILY assessing?
- Whether network hardware is under warranty
- Whether sensitive systems are isolated from less-secure network zones (Correct answer)
- Whether network cables are properly labeled
- Whether internet bandwidth is sufficient
Correct answer: Whether sensitive systems are isolated from less-secure network zones
Network segmentation isolates sensitive banking systems (e.g., core banking, cardholder data environments) from general networks, limiting the blast radius of a breach.
Question 4: Which BEST describes the purpose of penetration testing in a bank's IT audit program?
- To measure network bandwidth capacity
- To simulate real-world attacks and identify exploitable vulnerabilities before malicious actors do (Correct answer)
- To test employee computer proficiency
- To validate software licensing compliance
Correct answer: To simulate real-world attacks and identify exploitable vulnerabilities before malicious actors do
Penetration testing proactively identifies vulnerabilities by simulating actual attacker techniques, allowing the bank to remediate weaknesses before they are exploited.
Question 5: A bank IT auditor finds that developers have access to the production environment. What control deficiency does this represent?
- A violation of software licensing terms
- A lack of segregation of duties between development and production (Correct answer)
- An inadequate testing environment
- A bandwidth allocation issue
Correct answer: A lack of segregation of duties between development and production
Developers with production access can introduce unauthorized code changes or access sensitive data, violating the segregation of duties principle.
Question 6: During a business continuity audit, an IT auditor reviews a bank's Recovery Time Objective (RTO). What does the RTO define?
- The maximum acceptable data loss measured in time
- The maximum tolerable downtime before a system must be restored (Correct answer)
- The minimum time required to perform a backup
- The frequency of disaster recovery testing
Correct answer: The maximum tolerable downtime before a system must be restored
RTO defines the maximum acceptable period of time that a business process can be offline before the impact becomes unacceptable to the organization.
Question 7: An IT auditor discovers a bank stores cardholder data beyond the authorized retention period. Which standard does this MOST directly violate?
- SOX Section 404
- PCI DSS Requirement 3 (Correct answer)
- GLBA Safeguards Rule
- FFIEC Authentication Guidance
Correct answer: PCI DSS Requirement 3
PCI DSS Requirement 3 specifically governs the protection and retention of stored cardholder data, prohibiting storage beyond business necessity.
A bank's IT auditor is assessing vendor management controls for a cloud-based core banking provider.
Which document is MOST important to review?