โ† All CBA Flashcard Decks

Information Technology Audits Flashcards

7 cards from real CBA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Information Technology Audits flashcards as text
  1. A bank's IT auditor is assessing vendor management controls for a cloud-based core banking provider. Which document is MOST important to review?

    Answer: The Service Level Agreement and right-to-audit clause

    The SLA defines performance commitments and the right-to-audit clause ensures the bank can verify the vendor's controls, which is essential for regulatory compliance.

  2. An auditor reviewing a bank's IT change management process finds that emergency changes are frequently implemented without post-implementation review. What risk does this create?

    Answer: Unauthorized or poorly tested changes may persist in the production environment

    Without post-implementation reviews, emergency changes may introduce security vulnerabilities or operational errors that remain undetected in production.

  3. When auditing a bank's network segmentation controls, what is the auditor PRIMARILY assessing?

    Answer: Whether sensitive systems are isolated from less-secure network zones

    Network segmentation isolates sensitive banking systems (e.g., core banking, cardholder data environments) from general networks, limiting the blast radius of a breach.

  4. Which BEST describes the purpose of penetration testing in a bank's IT audit program?

    Answer: To simulate real-world attacks and identify exploitable vulnerabilities before malicious actors do

    Penetration testing proactively identifies vulnerabilities by simulating actual attacker techniques, allowing the bank to remediate weaknesses before they are exploited.

  5. A bank IT auditor finds that developers have access to the production environment. What control deficiency does this represent?

    Answer: A lack of segregation of duties between development and production

    Developers with production access can introduce unauthorized code changes or access sensitive data, violating the segregation of duties principle.

  6. During a business continuity audit, an IT auditor reviews a bank's Recovery Time Objective (RTO). What does the RTO define?

    Answer: The maximum tolerable downtime before a system must be restored

    RTO defines the maximum acceptable period of time that a business process can be offline before the impact becomes unacceptable to the organization.

  7. An IT auditor discovers a bank stores cardholder data beyond the authorized retention period. Which standard does this MOST directly violate?

    Answer: PCI DSS Requirement 3

    PCI DSS Requirement 3 specifically governs the protection and retention of stored cardholder data, prohibiting storage beyond business necessity.