Certified Internal Auditor Technology & Digital Applications 5 — Questions and Answers
Question 1: Which type of malware encrypts an organization's files and demands payment for the decryption key?
- Spyware
- Adware
- Ransomware (Correct answer)
- Rootkit
Correct answer: Ransomware
Ransomware encrypts victim files or systems and extorts payment in exchange for providing the decryption key.
Question 2: An auditor reviewing a vendor's SOC 2 Type II report is primarily evaluating which aspect of third-party risk?
- Financial stability of the vendor
- Effectiveness of the vendor's controls over a period of time (Correct answer)
- The vendor's regulatory compliance in all jurisdictions
- Vendor pricing and contract terms
Correct answer: Effectiveness of the vendor's controls over a period of time
A SOC 2 Type II report provides an independent assessment of whether a service organization's controls operated effectively over a specified review period.
Question 3: What is the PRIMARY purpose of network segmentation from an information security perspective?
- Improving network speed and bandwidth
- Limiting lateral movement by containing breaches to isolated segments (Correct answer)
- Reducing hardware costs through virtualization
- Simplifying network administration tasks
Correct answer: Limiting lateral movement by containing breaches to isolated segments
Network segmentation limits an attacker's ability to move laterally through the environment by isolating systems into separate network zones.
Question 4: An organization's data classification policy assigns 'confidential' to certain records. Which control is MOST directly aligned with enforcing this classification?
- Network firewall rules blocking inbound traffic
- Role-based access control restricting confidential data to authorized roles (Correct answer)
- Antivirus scanning of all incoming email attachments
- Regular vulnerability scans of web-facing servers
Correct answer: Role-based access control restricting confidential data to authorized roles
Role-based access control directly enforces data classification by ensuring only authorized roles can access confidential information.
Question 5: Which audit approach involves embedding continuous monitoring routines directly within an application to report exceptions in near real time?
- Control self-assessment
- Embedded audit modules (Correct answer)
- Substantive analytical procedures
- IT general control testing
Correct answer: Embedded audit modules
Embedded audit modules are routines inserted into application systems that automatically capture and report exception transactions for auditor review.
Question 6: When evaluating an organization's digital transformation initiative, an internal auditor should FIRST assess which of the following?
- The technical architecture of new digital platforms
- Alignment of the initiative with the organization's strategic objectives and risk appetite (Correct answer)
- The project manager's credentials and experience
- Cost savings projected from automation technologies
Correct answer: Alignment of the initiative with the organization's strategic objectives and risk appetite
Auditors should first confirm that the digital transformation initiative aligns with organizational strategy and fits within the defined risk appetite before evaluating technical details.
Question 7: Which Internet of Things (IoT) security risk is MOST challenging for organizations to manage?
- High cost of IoT device procurement
- Large volumes of unmanaged devices with limited security capabilities running on corporate networks (Correct answer)
- Slow data transmission speeds from IoT sensors
- Incompatibility between IoT platforms and cloud services
Correct answer: Large volumes of unmanaged devices with limited security capabilities running on corporate networks
Many IoT devices lack robust security features and cannot be easily patched, making it difficult for organizations to manage the large attack surface they create.
Which type of malware encrypts an organization's files and demands payment for the decryption key?