โ† All CBA Flashcard Decks

Information Technology Audits Flashcards

7 cards from real CBA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Information Technology Audits flashcards as text
  1. A bank IT auditor is testing controls over logical access to the general ledger system. Which test is MOST relevant?

    Answer: Verifying that user access is provisioned based on documented job roles and approved by management

    Logical access controls must be tied to defined job roles with management approval to ensure the principle of least privilege is enforced.

  2. Which log type would an IT auditor MOST likely review to detect brute-force login attempts against a bank's online banking system?

    Answer: Authentication failure logs

    Authentication failure logs capture repeated failed login attempts, which is the primary indicator of a brute-force attack against user accounts.

  3. An IT auditor finds that a bank's Security Information and Event Management (SIEM) system has not been tuned and generates thousands of daily alerts. What is the PRIMARY risk?

    Answer: Alert fatigue causing analysts to miss genuine security incidents

    Excessive false-positive alerts cause alert fatigue, leading security analysts to overlook or ignore genuine threats buried in noise.

  4. When auditing a bank's mobile banking application, which control addresses the risk of sensitive data being cached on a customer's device?

    Answer: Disabling local data storage and caching of account information within the app

    Disabling local caching prevents sensitive account data from being stored on the device where it could be accessed if the device is lost or stolen.

  5. An IT auditor is assessing a bank's controls over end-of-life (EOL) software. Which risk is MOST significant?

    Answer: No vendor security patches available, leaving known vulnerabilities permanently unmitigated

    EOL software no longer receives security patches, meaning newly discovered vulnerabilities will never be fixed, leaving the bank permanently exposed.

  6. A bank auditor is reviewing IT controls for a recent merger integration. What is the MOST important IT risk to assess during system consolidation?

    Answer: Data integrity and the risk of data corruption or loss during migration

    System consolidation during mergers carries high risk of data corruption, data loss, and integrity failures that can affect financial reporting and operations.

  7. Which BEST describes the role of a bank IT auditor when reviewing a new fintech partnership?

    Answer: Assessing whether adequate due diligence and ongoing monitoring controls exist for the third-party relationship

    IT auditors assess whether the bank has performed adequate due diligence and established ongoing monitoring to manage risks introduced by third-party fintech relationships.