โ† All CBA Flashcard Decks

Information Technology Auditing Flashcards

6 cards from real CBA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Information Technology Auditing flashcards as text
  1. An IT auditor for a bank is reviewing the institution's use of a public cloud service provider for hosting a critical customer-facing application. Which of the following is the MOST important consideration for the auditor when assessing the bank's risk management in this scenario?

    Answer: The bank's process for reviewing the cloud provider's SOC (Service Organization Control) reports.

    While physical security and encryption are important, the bank cannot directly audit the cloud provider's data centers. Therefore, the most critical control is the bank's own due diligence process, which includes thoroughly reviewing third-party assurance reports like SOC 2 reports. These reports provide insight into the provider's control environment, security, availability, and processing integrity, which is essential for the bank to manage its own risk.

  2. During an audit of a bank's new core banking system implementation, a Certified Bank Auditor is evaluating the System Development Life Cycle (SDLC) process. The auditor's primary objective at the post-implementation review phase is to:

    Answer: Assess whether the system has met its intended business objectives and user requirements.

    The post-implementation review is conducted to determine if the newly developed system has achieved its stated objectives, is functioning as intended, and if users are satisfied. While budget, access rights, and change migration are important aspects of the overall project, the ultimate success of the system is measured by its ability to meet the business needs for which it was built.

  3. Which of the following is a primary objective of auditing IT General Controls (ITGCs) within a financial institution?

    Answer: To provide reasonable assurance that the overall IT control environment is effective and supports the reliability of application controls.

    ITGCs form the foundation of the IT control structure. They are the policies and procedures that apply to all or a large segment of the institution's information systems and help ensure their continued, proper operation. A strong ITGC environment is necessary for application controls (which are specific to individual software) to be effective and reliable. Auditing ITGCs addresses the framework within which applications and data are managed.

  4. A bank's internal audit department is conducting a review of the Business Continuity Plan (BCP). A key component of this audit is to evaluate the Recovery Time Objective (RTO) and Recovery Point Objective (RPO) for critical systems. What is the primary purpose of the RTO?

    Answer: To define the target time within which a business process must be restored after a disaster to avoid unacceptable consequences.

    The Recovery Time Objective (RTO) is a crucial metric in business continuity planning that defines the maximum acceptable length of time that can elapse before a specific business function must be restored after a disaster or disruption to avoid significant impact on the organization. The RPO, by contrast, relates to the acceptable amount of data loss.

  5. When auditing a bank's data governance framework, which of the following is the MOST critical principle for an auditor to verify?

    Answer: The establishment of clear ownership and accountability for critical data elements.

    A fundamental principle of effective data governance is establishing clear ownership and accountability. This ensures that there are designated individuals or teams responsible for the quality, security, and management of specific data assets throughout their lifecycle. Without clear ownership, it becomes difficult to enforce policies, maintain data quality, and manage risks effectively.

  6. A bank auditor is performing a cybersecurity risk assessment. The first step in this process is to identify the bank's inherent risk. Which of the following factors is MOST indicative of a high inherent cybersecurity risk?

    Answer: The bank offers complex international payment services and utilizes extensive online and mobile banking platforms.

    Inherent risk is the level of risk a bank faces based on its activities and business model, before considering any controls. Offering complex products like international payments and having a large digital footprint through online and mobile banking significantly increases the attack surface and the potential for cyber threats, thus leading to a higher inherent risk profile.