Certified Internal Auditor Technology & Digital Applications 4 — Questions and Answers
Question 1: Which framework is MOST widely used to guide IT governance and management of enterprise IT?
- COSO
- COBIT (Correct answer)
- ISO 27001
- NIST CSF
Correct answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is the leading framework specifically designed for IT governance and management.
Question 2: What does the term 'data integrity' mean in an IT audit context?
- Data is accessible only to authorized users
- Data is accurate, complete, and unaltered during processing (Correct answer)
- Data is available whenever needed by users
- Data is encrypted to prevent unauthorized disclosure
Correct answer: Data is accurate, complete, and unaltered during processing
Data integrity ensures that data remains accurate, complete, and consistent throughout its lifecycle and is not improperly modified.
Question 3: An organization uses multi-factor authentication (MFA). Which scenario represents a residual risk DESPITE MFA being in place?
- Brute-force attacks guessing a single password
- SIM-swapping attacks compromising SMS-based MFA tokens (Correct answer)
- Password dictionary attacks on user accounts
- Unauthorized users lacking valid credentials
Correct answer: SIM-swapping attacks compromising SMS-based MFA tokens
SIM-swapping allows attackers to redirect SMS tokens to themselves, bypassing SMS-based MFA and representing a residual risk even when MFA is deployed.
Question 4: When reviewing an organization's API security, an internal auditor should MOST be concerned about which vulnerability?
- APIs using JSON rather than XML data formats
- Exposed APIs lacking authentication and authorization controls (Correct answer)
- High API call volumes during peak business hours
- APIs that communicate over internal networks only
Correct answer: Exposed APIs lacking authentication and authorization controls
APIs without proper authentication and authorization can be exploited to access sensitive data or functionality without valid credentials.
Question 5: Which recovery metric defines the maximum acceptable data loss measured in time after a disaster?
- Recovery Time Objective (RTO)
- Mean Time to Recover (MTTR)
- Recovery Point Objective (RPO) (Correct answer)
- Maximum Tolerable Downtime (MTD)
Correct answer: Recovery Point Objective (RPO)
The Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time, determining backup frequency requirements.
Question 6: A company stores sensitive customer data in a public cloud. Which shared responsibility model concept is MOST critical for the auditor to understand?
- The cloud provider is responsible for all data security
- Security responsibilities are divided between the provider and the customer (Correct answer)
- The customer has no security responsibilities in the cloud
- The cloud provider's compliance certifications cover all customer data
Correct answer: Security responsibilities are divided between the provider and the customer
The shared responsibility model divides security obligations between the cloud provider and the customer, and customers retain responsibility for their data and access controls.
Question 7: Which technique do internal auditors use to analyze 100% of a dataset rather than a statistical sample?
- Attribute sampling
- Continuous auditing with data analytics (Correct answer)
- Substantive testing on judgmental samples
- Walkthrough procedures
Correct answer: Continuous auditing with data analytics
Continuous auditing with data analytics tools enables auditors to analyze entire populations of data, eliminating sampling risk.
Which framework is MOST widely used to guide IT governance and management of enterprise IT?