Certified Internal Auditor Technology & Digital Applications 2 — Questions and Answers
Question 1: Which cloud deployment model provides dedicated infrastructure exclusively for a single organization?
- Public cloud
- Private cloud (Correct answer)
- Hybrid cloud
- Community cloud
Correct answer: Private cloud
A private cloud provides dedicated infrastructure exclusively for one organization, offering greater control and security.
Question 2: An internal auditor reviewing IT general controls (ITGCs) would primarily focus on which of the following?
- Application-level business logic validation
- Change management, access controls, and IT operations (Correct answer)
- User interface design and usability
- Network bandwidth and latency metrics
Correct answer: Change management, access controls, and IT operations
ITGCs encompass change management, logical access controls, and IT operations that underpin all application controls.
Question 3: What is the primary purpose of a data loss prevention (DLP) solution?
- Encrypting data at rest
- Monitoring and preventing unauthorized transfer of sensitive data (Correct answer)
- Backing up critical business data automatically
- Detecting malware on endpoints
Correct answer: Monitoring and preventing unauthorized transfer of sensitive data
DLP solutions monitor, detect, and block unauthorized transmission of sensitive data outside the organization.
Question 4: Which blockchain characteristic ensures that once a transaction is recorded it cannot be altered?
- Decentralization
- Transparency
- Immutability (Correct answer)
- Consensus
Correct answer: Immutability
Immutability means that recorded blockchain transactions are cryptographically linked and cannot be changed without invalidating subsequent blocks.
Question 5: An auditor assessing robotic process automation (RPA) controls should prioritize reviewing which risk?
- Slow processing speeds reducing efficiency
- Bot credentials with excessive privileges performing unauthorized actions (Correct answer)
- High licensing costs exceeding budget projections
- Insufficient logging of automated transactions
Correct answer: Bot credentials with excessive privileges performing unauthorized actions
RPA bots with overprivileged credentials can perform unauthorized actions at scale, making access control a critical risk.
Question 6: In the context of IT audit, what does a 'penetration test' simulate?
- Internal users attempting to bypass application controls
- An attacker attempting to exploit system vulnerabilities (Correct answer)
- Performance testing under peak load conditions
- Disaster recovery failover to backup systems
Correct answer: An attacker attempting to exploit system vulnerabilities
A penetration test simulates real-world attacks to identify exploitable vulnerabilities before malicious actors can leverage them.
Question 7: Which principle requires that users receive only the minimum system access needed to perform their job functions?
- Segregation of duties
- Defense in depth
- Least privilege (Correct answer)
- Need to know
Correct answer: Least privilege
The principle of least privilege limits user access rights to only what is necessary, reducing the attack surface and potential for misuse.
Which cloud deployment model provides dedicated infrastructure exclusively for a single organization?