SSCP Security Auditing & Compliance Standards 3 — Questions and Answers
Question 1: Which ISO 27001 document establishes the scope, objectives, and policies of an organization's information security management system?
- Statement of Applicability
- Risk Treatment Plan
- Information Security Policy (Correct answer)
- Asset Inventory
Correct answer: Information Security Policy
The Information Security Policy sets top-level direction and commitment from management for the ISMS, defining scope and objectives.
Question 2: During a compliance audit, the auditor requests evidence of patch management activities. Which artifact BEST demonstrates timely patching?
- A written patch management policy
- Patch deployment logs with timestamps (Correct answer)
- A risk acceptance letter for unpatched systems
- Vendor patch release notes
Correct answer: Patch deployment logs with timestamps
Patch deployment logs with timestamps provide objective evidence that patches were actually applied and within acceptable timeframes.
Question 3: Which GDPR principle requires that personal data be collected for specified, explicit, and legitimate purposes?
- Data minimization
- Purpose limitation (Correct answer)
- Storage limitation
- Integrity and confidentiality
Correct answer: Purpose limitation
The purpose limitation principle under GDPR requires organizations to collect data only for clearly defined, lawful purposes.
Question 4: The concept of 'separation of duties' in an audit context is designed primarily to prevent:
- Unauthorized network access
- Single-person fraud or error going undetected (Correct answer)
- Weak encryption implementation
- Insecure software development
Correct answer: Single-person fraud or error going undetected
Separation of duties ensures no single individual can complete a sensitive process alone, reducing the risk of undetected fraud or error.
Question 5: Which framework is commonly used as a baseline for auditing IT governance and aligns IT goals with business objectives?
- COBIT (Correct answer)
- OWASP
- MITRE ATT&CK
- CVE
Correct answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) provides a framework for IT governance and management aligned with business goals.
Question 6: A financial services firm must comply with regulations requiring retention of electronic communications for at least 7 years. This is MOST directly governed by:
- HIPAA
- PCI DSS
- SEC Rule 17a-4 (Correct answer)
- FISMA
Correct answer: SEC Rule 17a-4
SEC Rule 17a-4 governs retention requirements for electronic records in broker-dealers, including a minimum 7-year retention period for most records.
Question 7: Which audit sampling method selects items based on their monetary value or risk significance, giving higher-value items a greater chance of selection?
- Random sampling
- Stratified sampling
- Monetary unit sampling (Correct answer)
- Block sampling
Correct answer: Monetary unit sampling
Monetary unit sampling (MUS) weights selection probability by item value, focusing audit effort on higher-risk, higher-value transactions.
Which ISO 27001 document establishes the scope, objectives, and policies of an organization's information security management system?