โ† All CPCA Flashcard Decks

Compliance and Auditing Flashcards

7 cards from real CPCA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Compliance and Auditing flashcards as text
  1. During a compliance audit, an auditor discovers that an employee has been granted access to systems beyond what their job role requires. What principle has been violated?

    Answer: Least privilege

    The least privilege principle requires that users be granted only the minimum access necessary to perform their job functions.

  2. Which of the following best describes a compliance gap analysis?

    Answer: A comparison between current security controls and required standards

    A gap analysis compares an organization's current state against required compliance standards to identify areas needing remediation.

  3. A CPCA is reviewing audit logs and notices that log entries have timestamps that are inconsistent with each other. What is the most likely root cause?

    Answer: Lack of time synchronization across systems using NTP

    Inconsistent timestamps across systems are typically caused by lack of synchronized clocks, which is addressed by implementing NTP (Network Time Protocol).

  4. Under SOC 2 auditing, which of the following Trust Service Criteria (TSC) is considered mandatory for all SOC 2 reports?

    Answer: Security (Common Criteria)

    The Security (Common Criteria) category is the only mandatory TSC in a SOC 2 report; all other criteria are optional and selected based on business needs.

  5. An organization wants to demonstrate compliance with payment card industry requirements. Which standard should they audit against?

    Answer: PCI DSS

    PCI DSS (Payment Card Industry Data Security Standard) is the framework specifically designed for organizations that handle cardholder data.

  6. What is the primary purpose of an audit trail in a compliance program?

    Answer: To provide a chronological record of system activities for accountability

    An audit trail provides a sequential record of events and activities, enabling accountability and forensic investigation when needed.

  7. Which type of audit involves an independent third party evaluating an organization's controls against a defined standard?

    Answer: External audit

    An external audit is conducted by an independent third party to provide an objective assessment of an organization's compliance posture.