Information Technology Audits Flashcards
7 cards from real CBA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Information Technology Audits flashcards as text
A bank's IT auditor is assessing vendor management controls for a cloud-based core banking provider. Which document is MOST important to review?
Answer: The Service Level Agreement and right-to-audit clause
The SLA defines performance commitments and the right-to-audit clause ensures the bank can verify the vendor's controls, which is essential for regulatory compliance.
An auditor reviewing a bank's IT change management process finds that emergency changes are frequently implemented without post-implementation review. What risk does this create?
Answer: Unauthorized or poorly tested changes may persist in the production environment
Without post-implementation reviews, emergency changes may introduce security vulnerabilities or operational errors that remain undetected in production.
When auditing a bank's network segmentation controls, what is the auditor PRIMARILY assessing?
Answer: Whether sensitive systems are isolated from less-secure network zones
Network segmentation isolates sensitive banking systems (e.g., core banking, cardholder data environments) from general networks, limiting the blast radius of a breach.
Which BEST describes the purpose of penetration testing in a bank's IT audit program?
Answer: To simulate real-world attacks and identify exploitable vulnerabilities before malicious actors do
Penetration testing proactively identifies vulnerabilities by simulating actual attacker techniques, allowing the bank to remediate weaknesses before they are exploited.
A bank IT auditor finds that developers have access to the production environment. What control deficiency does this represent?
Answer: A lack of segregation of duties between development and production
Developers with production access can introduce unauthorized code changes or access sensitive data, violating the segregation of duties principle.
During a business continuity audit, an IT auditor reviews a bank's Recovery Time Objective (RTO). What does the RTO define?
Answer: The maximum tolerable downtime before a system must be restored
RTO defines the maximum acceptable period of time that a business process can be offline before the impact becomes unacceptable to the organization.
An IT auditor discovers a bank stores cardholder data beyond the authorized retention period. Which standard does this MOST directly violate?
Answer: PCI DSS Requirement 3
PCI DSS Requirement 3 specifically governs the protection and retention of stored cardholder data, prohibiting storage beyond business necessity.