Information Technology Audits Flashcards
7 cards from real CBA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Information Technology Audits flashcards as text
A bank's IT auditor is reviewing the effectiveness of data loss prevention (DLP) controls. Which scenario represents a DLP control FAILURE?
Answer: A bulk file of customer SSNs is successfully emailed to an external personal account
Successfully emailing a bulk file of customer SSNs externally indicates the DLP system failed to detect and block the unauthorized exfiltration of sensitive data.
When auditing IT controls for a bank's automated clearing house (ACH) operations, which control is MOST critical to verify?
Answer: Dual authorization controls for ACH file releases exceeding defined dollar thresholds
Dual authorization for high-value ACH files prevents a single individual from initiating and releasing large fund transfers, mitigating fraud and error risk.
An IT auditor finds that a bank's employees are not required to complete cybersecurity awareness training. What risk does this MOST directly create?
Answer: Higher susceptibility to social engineering attacks such as phishing
Untrained employees are primary targets for phishing and social engineering attacks, making human error the leading cause of security breaches.
During a disaster recovery test, a bank's IT systems are restored but customer transaction data is missing for the last 4 hours before the declared disaster. Which metric was NOT achieved?
Answer: Recovery Point Objective (RPO)
RPO defines the maximum acceptable data loss measured in time; missing 4 hours of transaction data indicates the backup frequency did not meet the defined RPO.
An IT auditor reviewing a bank's cryptographic controls finds that MD5 is used to hash stored passwords. What should be reported?
Answer: MD5 is cryptographically broken and should be replaced with a modern algorithm such as bcrypt or SHA-256
MD5 is cryptographically broken, vulnerable to collision attacks, and is not appropriate for password hashing regardless of salting; modern algorithms like bcrypt are required.
A bank outsources its data center operations. Under OCC guidance, who retains ULTIMATE responsibility for the security of customer data?
Answer: The bank itself
OCC guidance makes clear that banks cannot outsource their regulatory responsibilities — the bank retains ultimate accountability for data security even when operations are outsourced.
An IT auditor is evaluating a bank's controls over API security for open banking integrations. Which control is MOST important to verify?
Answer: OAuth 2.0 implementation with proper token scoping and expiration controls
OAuth 2.0 with properly scoped and time-limited tokens is the foundational security control for API access management in open banking environments.