Security Control Auditing Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security Control Auditing flashcards as text
A SOC 2 audit is scoping a SaaS provider's trust service criteria. The customer contracts require the vendor to notify customers within 72 hours of a breach. Which trust service criterion does this directly support?
Answer: Security
Breach notification requirements fall under the Security criterion (CC9) in SOC 2, which covers how the organization communicates security incidents.
An auditor is evaluating the design of a multi-factor authentication (MFA) control. Which design element MOST reduces risk of MFA bypass attacks?
Answer: Requiring phishing-resistant MFA such as FIDO2/WebAuthn
FIDO2/WebAuthn provides phishing-resistant MFA because the authentication is bound to the legitimate domain, preventing credential interception attacks.
During a PCI DSS audit, the QSA reviews network diagrams and finds that cardholder data environment (CDE) systems share a VLAN with point-of-sale terminals and corporate workstations. This violates which PCI DSS requirement?
Answer: Requirement 1 – Network security controls
PCI DSS Requirement 1 mandates network security controls including proper network segmentation to isolate the CDE from untrusted networks and systems.
Which term describes the process of aggregating audit findings across multiple control domains to identify systemic organizational weaknesses?
Answer: Thematic analysis
Thematic analysis groups individual audit findings by underlying root cause or pattern to reveal systemic weaknesses that individual findings might not highlight.
An internal audit team is assessing the effectiveness of DLP (Data Loss Prevention) controls. Which test would BEST verify that the DLP solution is operating as configured?
Answer: Attempt to exfiltrate synthetic test data matching DLP rules and verify alerts trigger
The most effective operating effectiveness test is to attempt the action the control is designed to prevent and verify the control responds correctly.
A cloud security audit finds that S3 buckets storing PII have public access enabled. Under NIST RMF, which step is the auditor's finding most directly associated with?
Answer: Assess
The Assess step of NIST RMF involves determining whether security controls are implemented correctly and producing findings when controls fail — exactly what this audit finding represents.
When an auditor issues a qualified opinion on an internal control report, it means:
Answer: Specific controls have exceptions but the overall system of controls is otherwise effective
A qualified opinion means the auditor found specific exceptions or weaknesses in particular areas while finding the overall system of controls otherwise effective.