← All CBA Flashcard Decks

Information Technology Audits Flashcards

7 cards from real CBA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Information Technology Audits flashcards as text
  1. A bank's IT auditor is reviewing the effectiveness of data loss prevention (DLP) controls. Which scenario represents a DLP control FAILURE?

    Answer: A bulk file of customer SSNs is successfully emailed to an external personal account

    Successfully emailing a bulk file of customer SSNs externally indicates the DLP system failed to detect and block the unauthorized exfiltration of sensitive data.

  2. When auditing IT controls for a bank's automated clearing house (ACH) operations, which control is MOST critical to verify?

    Answer: Dual authorization controls for ACH file releases exceeding defined dollar thresholds

    Dual authorization for high-value ACH files prevents a single individual from initiating and releasing large fund transfers, mitigating fraud and error risk.

  3. An IT auditor finds that a bank's employees are not required to complete cybersecurity awareness training. What risk does this MOST directly create?

    Answer: Higher susceptibility to social engineering attacks such as phishing

    Untrained employees are primary targets for phishing and social engineering attacks, making human error the leading cause of security breaches.

  4. During a disaster recovery test, a bank's IT systems are restored but customer transaction data is missing for the last 4 hours before the declared disaster. Which metric was NOT achieved?

    Answer: Recovery Point Objective (RPO)

    RPO defines the maximum acceptable data loss measured in time; missing 4 hours of transaction data indicates the backup frequency did not meet the defined RPO.

  5. An IT auditor reviewing a bank's cryptographic controls finds that MD5 is used to hash stored passwords. What should be reported?

    Answer: MD5 is cryptographically broken and should be replaced with a modern algorithm such as bcrypt or SHA-256

    MD5 is cryptographically broken, vulnerable to collision attacks, and is not appropriate for password hashing regardless of salting; modern algorithms like bcrypt are required.

  6. A bank outsources its data center operations. Under OCC guidance, who retains ULTIMATE responsibility for the security of customer data?

    Answer: The bank itself

    OCC guidance makes clear that banks cannot outsource their regulatory responsibilities — the bank retains ultimate accountability for data security even when operations are outsourced.

  7. An IT auditor is evaluating a bank's controls over API security for open banking integrations. Which control is MOST important to verify?

    Answer: OAuth 2.0 implementation with proper token scoping and expiration controls

    OAuth 2.0 with properly scoped and time-limited tokens is the foundational security control for API access management in open banking environments.