CPCA Compliance and Auditing 4 — Questions and Answers
Question 1: A CPCA is designing a continuous compliance monitoring program. Which approach provides the most real-time visibility into the compliance posture?
- Annual third-party audits
- Quarterly self-assessments
- Automated control testing with dashboards (Correct answer)
- Monthly manual review of policy documents
Correct answer: Automated control testing with dashboards
Automated continuous control testing with real-time dashboards provides ongoing visibility into compliance status rather than periodic point-in-time snapshots.
Question 2: Which risk treatment option involves transferring the financial consequences of a risk to a third party?
- Risk avoidance
- Risk mitigation
- Risk acceptance
- Risk transfer (Correct answer)
Correct answer: Risk transfer
Risk transfer shifts the financial burden of a risk to another party, such as purchasing cyber liability insurance or outsourcing a process.
Question 3: During a PCI DSS audit, an assessor reviews cardholder data flows. What document is commonly used to map where cardholder data is stored, processed, and transmitted?
- Business Impact Analysis (BIA)
- Data Flow Diagram (DFD) (Correct answer)
- Risk Register
- System Security Plan (SSP)
Correct answer: Data Flow Diagram (DFD)
A Data Flow Diagram (DFD) visually maps where cardholder data enters, moves through, and exits an environment, which is essential for defining the PCI DSS scope.
Question 4: Which of the following is an example of a compensating control in a compliance framework?
- Implementing encryption in place of an unachievable technical requirement (Correct answer)
- Documenting a policy acknowledging a known risk
- Hiring additional staff to review logs manually
- Purchasing cyber insurance to cover potential losses
Correct answer: Implementing encryption in place of an unachievable technical requirement
A compensating control is an alternative measure implemented when a primary required control cannot be met, such as using encryption to substitute for a specific technical safeguard.
Question 5: An organization operating under the Sarbanes-Oxley Act (SOX) must ensure which of the following regarding financial reporting systems?
- All systems must be hosted in US-based data centers
- Internal controls over financial reporting must be documented and tested (Correct answer)
- Only C-suite executives may access financial data
- Financial data must be encrypted using AES-256
Correct answer: Internal controls over financial reporting must be documented and tested
SOX Section 404 requires management to document, assess, and attest to the effectiveness of internal controls over financial reporting (ICFR).
Question 6: What is the primary role of a Chief Compliance Officer (CCO) in relation to audit findings?
- Directly implementing technical remediations for identified vulnerabilities
- Overseeing the development and execution of remediation plans for audit findings (Correct answer)
- Conducting penetration tests to validate audit results
- Drafting legal responses to regulatory enforcement actions
Correct answer: Overseeing the development and execution of remediation plans for audit findings
The CCO is responsible for overseeing the organization's response to audit findings, including prioritizing and tracking remediation efforts to closure.
Question 7: Which standard provides a framework for information security management systems (ISMS) and is frequently used as a basis for compliance audits?
- NIST SP 800-61
- ISO/IEC 27001 (Correct answer)
- COBIT 5
- ITIL v4
Correct answer: ISO/IEC 27001
ISO/IEC 27001 is the internationally recognized standard for establishing, implementing, maintaining, and continually improving an ISMS.
A CPCA is designing a continuous compliance monitoring program.
Which approach provides the most real-time visibility into the compliance posture?