CSC Security Control Auditing 3 — Questions and Answers
Question 1: Under the COSO Internal Control – Integrated Framework, which component addresses the organization's commitment to integrity and ethical values?
- Risk Assessment
- Control Activities
- Control Environment (Correct answer)
- Monitoring Activities
Correct answer: Control Environment
The Control Environment is the foundational component of COSO that sets the tone at the top, including commitment to integrity and ethical values.
Question 2: During a vulnerability assessment audit, an auditor finds that critical patches are applied within 72 hours but the policy requires 24 hours. What type of gap is this?
- Design gap
- Operating effectiveness gap (Correct answer)
- Scope gap
- Inherent gap
Correct answer: Operating effectiveness gap
An operating effectiveness gap means the control exists and is designed correctly but does not perform as required during actual execution.
Question 3: When auditing encryption controls, which factor is MOST important to verify for data at rest on a database server?
- The cipher suite version used by TLS
- That database columns containing sensitive data use AES-256 or equivalent encryption (Correct answer)
- That the database server uses HTTPS for admin access
- That backup tapes are sent offsite monthly
Correct answer: That database columns containing sensitive data use AES-256 or equivalent encryption
For data at rest, auditors verify that sensitive fields are encrypted using strong algorithms like AES-256 at the storage layer, not transport encryption.
Question 4: A CIS Controls audit maps findings to the Implementation Group (IG) framework. Which IG is recommended as the minimum baseline for all enterprises regardless of size?
- IG1 (Correct answer)
- IG2
- IG3
- IG0
Correct answer: IG1
CIS IG1 represents the essential cyber hygiene controls that all organizations should implement regardless of size, resource, or risk profile.
Question 5: Which audit evidence type carries the highest reliability when evaluating the existence of a security control?
- Oral confirmation from the IT manager
- Screenshots provided by the auditee
- System-generated logs obtained directly by the auditor (Correct answer)
- Written management representations
Correct answer: System-generated logs obtained directly by the auditor
Evidence obtained directly by the auditor from source systems is more reliable than evidence provided by the auditee, which could be manipulated.
Question 6: An auditor is assessing a change management process. Which control objective should be verified FIRST to ensure unauthorized changes cannot reach production?
- Change tickets are approved by two managers
- Development and production environments are separated (Correct answer)
- All changes are logged in the ITSM tool
- Rollback procedures exist for all changes
Correct answer: Development and production environments are separated
Separation of development and production environments is foundational — without it, developers can push unauthorized changes directly to production regardless of other controls.
Question 7: In a HIPAA security rule audit, which safeguard category covers workstation use policies and physical access to ePHI systems?
- Administrative safeguards
- Physical safeguards (Correct answer)
- Technical safeguards
- Organizational safeguards
Correct answer: Physical safeguards
HIPAA Physical Safeguards govern physical access to electronic systems housing ePHI, including workstation use, access controls, and device disposal.
Under the COSO Internal Control – Integrated Framework, which component addresses the organization's commitment to integrity and ethical values?