Data Management and Database Controls Flashcards
6 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Data Management and Database Controls flashcards as text
A CISA auditor reviewing database security finds that stored procedures are used for all application-database interactions. This is PRIMARILY considered a best practice because:
Answer: They prevent SQL injection by parameterizing inputs and limiting direct table access
Stored procedures with parameterized inputs prevent SQL injection attacks and can be configured to limit application access to specific procedures rather than underlying tables, reducing the attack surface.
Which concept describes the property that committed database transactions are permanently saved even in the event of a system failure?
Answer: Durability
Durability is the ACID property that guarantees once a transaction is committed, it remains permanently recorded even if the system crashes immediately after the commit.
When auditing data warehouses, a CISA auditor should verify that ETL (Extract, Transform, Load) processes include which control to ensure data quality?
Answer: Reconciliation controls comparing record counts and totals between source and target
Reconciliation controls that compare record counts, checksums, and aggregate totals between source systems and the data warehouse ensure completeness and accuracy of data loaded through ETL processes.
A CISA auditor should verify that database encryption keys are:
Answer: Managed separately from the encrypted data using a dedicated key management system
Encryption keys must be stored and managed separately from the encrypted data they protect; storing keys alongside encrypted data effectively negates the protection that encryption provides.
Which database auditing approach captures all SQL statements executed against a database, providing the most comprehensive audit trail?
Answer: Full database activity monitoring (DAM)
Database Activity Monitoring (DAM) captures all SQL statements in real time, including privileged user actions, providing a comprehensive audit trail that detects unauthorized or anomalous database activity.
Under the US Health Insurance Portability and Accountability Act (HIPAA), covered entities must implement which type of controls to protect electronic Protected Health Information (ePHI) stored in databases?
Answer: Administrative, physical, and technical safeguards
HIPAA's Security Rule requires covered entities to implement a combination of administrative safeguards (policies), physical safeguards (facility controls), and technical safeguards (encryption, access controls) to protect ePHI.