โ† All CPCA Flashcard Decks

Compliance and Auditing Flashcards

7 cards from real CPCA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Compliance and Auditing flashcards as text
  1. A CPCA is designing a continuous compliance monitoring program. Which approach provides the most real-time visibility into the compliance posture?

    Answer: Automated control testing with dashboards

    Automated continuous control testing with real-time dashboards provides ongoing visibility into compliance status rather than periodic point-in-time snapshots.

  2. Which risk treatment option involves transferring the financial consequences of a risk to a third party?

    Answer: Risk transfer

    Risk transfer shifts the financial burden of a risk to another party, such as purchasing cyber liability insurance or outsourcing a process.

  3. During a PCI DSS audit, an assessor reviews cardholder data flows. What document is commonly used to map where cardholder data is stored, processed, and transmitted?

    Answer: Data Flow Diagram (DFD)

    A Data Flow Diagram (DFD) visually maps where cardholder data enters, moves through, and exits an environment, which is essential for defining the PCI DSS scope.

  4. Which of the following is an example of a compensating control in a compliance framework?

    Answer: Implementing encryption in place of an unachievable technical requirement

    A compensating control is an alternative measure implemented when a primary required control cannot be met, such as using encryption to substitute for a specific technical safeguard.

  5. An organization operating under the Sarbanes-Oxley Act (SOX) must ensure which of the following regarding financial reporting systems?

    Answer: Internal controls over financial reporting must be documented and tested

    SOX Section 404 requires management to document, assess, and attest to the effectiveness of internal controls over financial reporting (ICFR).

  6. What is the primary role of a Chief Compliance Officer (CCO) in relation to audit findings?

    Answer: Overseeing the development and execution of remediation plans for audit findings

    The CCO is responsible for overseeing the organization's response to audit findings, including prioritizing and tracking remediation efforts to closure.

  7. Which standard provides a framework for information security management systems (ISMS) and is frequently used as a basis for compliance audits?

    Answer: ISO/IEC 27001

    ISO/IEC 27001 is the internationally recognized standard for establishing, implementing, maintaining, and continually improving an ISMS.