Security Control Auditing Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Control Auditing flashcards as text
During a security control audit, an auditor discovers that a firewall rule set has not been reviewed in 18 months. Which audit finding category best describes this?
Answer: Control deficiency
An unreviewed firewall rule set represents a control deficiency where the control is not operating as designed or intended.
Which sampling method selects audit samples based on the monetary value or risk weighting of transactions?
Answer: Monetary unit sampling
Monetary unit sampling (MUS) gives each dollar unit an equal chance of selection, focusing audit attention on higher-value transactions.
An organization uses a third-party service for payroll processing. Under SOC 2 Type II auditing, what document provides assurance about the service provider's controls?
Answer: SOC 2 Type II report from the service organization
A SOC 2 Type II report from the service organization provides independent assurance that its controls operated effectively over a defined period.
What is the primary purpose of a compensating control in an audit context?
Answer: To satisfy a compliance requirement when the primary control cannot be implemented
Compensating controls are alternative measures that satisfy a compliance requirement when the standard control is not feasible to implement.
An auditor is testing access controls and pulls a list of all user accounts. She compares this to HR termination records. What audit procedure is she performing?
Answer: Reconciliation
Reconciliation compares two data sets from different sources to identify discrepancies, here matching active accounts against HR termination data.
Which NIST SP 800-53A assessment method involves the auditor watching personnel perform their duties to verify control operation?
Answer: Observe
NIST SP 800-53A defines 'Observe' as watching activities or processes being performed to verify that controls operate as documented.
A control audit reveals that privileged access reviews are performed annually instead of the required quarterly cadence. This is best documented as a:
Answer: Audit finding with a root cause and remediation plan
Deviations from required control frequencies are documented as audit findings with root cause analysis and a remediation timeline for management response.