โ† All Certified Internal Auditor Flashcard Decks

Technology & Digital Applications Flashcards

7 cards from real Certified Internal Auditor practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Technology & Digital Applications flashcards as text
  1. Which framework is MOST widely used to guide IT governance and management of enterprise IT?

    Answer: COBIT

    COBIT (Control Objectives for Information and Related Technologies) is the leading framework specifically designed for IT governance and management.

  2. What does the term 'data integrity' mean in an IT audit context?

    Answer: Data is accurate, complete, and unaltered during processing

    Data integrity ensures that data remains accurate, complete, and consistent throughout its lifecycle and is not improperly modified.

  3. An organization uses multi-factor authentication (MFA). Which scenario represents a residual risk DESPITE MFA being in place?

    Answer: SIM-swapping attacks compromising SMS-based MFA tokens

    SIM-swapping allows attackers to redirect SMS tokens to themselves, bypassing SMS-based MFA and representing a residual risk even when MFA is deployed.

  4. When reviewing an organization's API security, an internal auditor should MOST be concerned about which vulnerability?

    Answer: Exposed APIs lacking authentication and authorization controls

    APIs without proper authentication and authorization can be exploited to access sensitive data or functionality without valid credentials.

  5. Which recovery metric defines the maximum acceptable data loss measured in time after a disaster?

    Answer: Recovery Point Objective (RPO)

    The Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time, determining backup frequency requirements.

  6. A company stores sensitive customer data in a public cloud. Which shared responsibility model concept is MOST critical for the auditor to understand?

    Answer: Security responsibilities are divided between the provider and the customer

    The shared responsibility model divides security obligations between the cloud provider and the customer, and customers retain responsibility for their data and access controls.

  7. Which technique do internal auditors use to analyze 100% of a dataset rather than a statistical sample?

    Answer: Continuous auditing with data analytics

    Continuous auditing with data analytics tools enables auditors to analyze entire populations of data, eliminating sampling risk.