CIA CIA Information Technology & Systems 2 — Questions and Answers
Question 1: Which COBIT framework domain is most focused on acquiring and implementing IT solutions?
- Align, Plan and Organize
- Build, Acquire and Implement (Correct answer)
- Deliver, Service and Support
- Monitor, Evaluate and Assess
Correct answer: Build, Acquire and Implement
The 'Build, Acquire and Implement' domain of COBIT covers how IT solutions are acquired, developed, and put into production.
Question 2: An internal auditor reviewing IT application controls would examine which of the following?
- Firewall configurations
- Input validation and edit checks within a specific application (Correct answer)
- Server room physical access logs
- Network intrusion detection system alerts
Correct answer: Input validation and edit checks within a specific application
Application controls are embedded within specific systems and include input validation, processing controls, and output controls.
Question 3: What does 'RPO' stand for in business continuity planning, and what does it measure?
- Recovery Point Objective; the maximum tolerable data loss measured in time (Correct answer)
- Recovery Process Objective; the steps needed to restore systems
- Residual Protection Outcome; remaining risk after controls
- Redundancy Planning Option; backup system alternatives
Correct answer: Recovery Point Objective; the maximum tolerable data loss measured in time
Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time before a disaster.
Question 4: An auditor finds that a company does not perform penetration testing. This gap most directly affects the assessment of:
- Financial statement accuracy
- IT security vulnerability management (Correct answer)
- Accounts payable processing controls
- Fixed asset depreciation schedules
Correct answer: IT security vulnerability management
Penetration testing is a key component of vulnerability management that identifies exploitable weaknesses in IT security.
Question 5: Under a CIA audit, which of the following would be classified as an IT application control rather than a general control?
- Physical security of the data center
- Automated three-way match of purchase orders, receipts, and invoices (Correct answer)
- Patch management procedures
- User access provisioning process
Correct answer: Automated three-way match of purchase orders, receipts, and invoices
An automated three-way match is an application control embedded in the accounts payable system to prevent payment errors.
Question 6: Which encryption concept ensures that a sender cannot later deny having sent a message?
- Symmetric encryption
- Non-repudiation via digital signatures (Correct answer)
- Hashing for data integrity
- Public key infrastructure certificate revocation
Correct answer: Non-repudiation via digital signatures
Non-repudiation, achieved through digital signatures, provides proof of origin so a sender cannot deny sending a message.
Which COBIT framework domain is most focused on acquiring and implementing IT solutions?