Browse all practice questions for the Information Systems and Controls (ISC) CPA Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Information Systems and Controls (ISC) CPA Practice Exam 2026 – Your All-in-One Guide to Mastering CPA Success! course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • Which authentication method requires users to input a numeric code they have memorized?
  • What do Pools represent in BPMN diagrams?
  • What is a characteristic of hashing?
  • Which regulation is considered the strictest privacy law in the world?
  • How do network address translation firewalls enhance privacy?
  • What is emphasized by maintaining an information security policy in PCI DSS?
  • What method can attackers use to obtain confidential data through technology?
  • What does the "carve out" method refer to in SOC reports?
  • What does a circle or rectangle with rounded edges represent in a data flow diagram?
  • Which type of attack involves an attacker who intercepts and potentially alters the communications between two parties?
  • What is a drawback of bus topology?
  • What does the Bring Your Own Device (BYOD) Policy primarily focus on?
  • Which of the following statements is included in a Disclaimer SOC report?
  • What type of authentication uses physical devices to verify identity?
  • Which attack occurs when a user’s legitimate request is captured and transmitted again by the attacker?
  • How are disruption impacts classified in the BIA process?
  • What role do Culture, Ethics, and Behavior play in the success of management and governance according to COBIT?
  • What is the formula for calculating the Annualized Rate of Occurrence (ARO)?
  • Which tier in the NIST Privacy Framework is characterized as 'risk-informed'?
  • What does confidentiality in trust services entail?
  • What does the Exposure Factor (EF) represent in loss estimation?
  • What feature of next-generation firewalls allows for customization?
  • What should an auditor do regarding subsequent events?
  • Which of the following best describes context-aware authentication?
  • What is the difference between replication and mirroring?
  • Which step involves gaining approval from management in the change management process?
  • Which of the following best defines redundancy as it relates to system availability?
  • What is the last step in the PASTA threat methodology?
  • What characterizes Discretionary Access Control?
  • What happens to the purchase order after the receiving department enters the quantity received?
  • In COBIT, what is the purpose of risk optimization within the EDM governance objective?
  • What is the purpose of estimating losses in the BIA process?
  • Which is NOT a component of network infrastructure management?
  • Which topology connects nodes in a linear or tree format?
  • What is the main purpose of Security Policies in an organization?
  • What describes the physical layout of nodes in a network?
  • Which of the following is a primary component of the NIST Privacy Framework?
  • What does a Personal Identification Number (PIN) primarily consist of?
  • What is one of the main goals of the PCI DSS?
  • What does the acronym 'S' stand for in COSO Risk Assessment?
  • What is considered a component of offshore operations?
  • What does CIS Control 3 emphasize regarding data?
  • Which statement is true regarding compliance requirements?
  • In the context of a Relational Database, what are fields?
  • Which type of change environment is used to deploy applications?
  • What does the term 'managed security' imply in the context of the APO management objectives?
  • What must an organization regularly test as part of PCI DSS compliance?
  • What does provisioning refer to in an organization?
  • Which of the following is a risk associated with cloud computing?
  • In disaster recovery, what is a key aspect of systems availability controls?
  • What is the first stage in a cyberattack?
  • Which factor is crucial when approving and deploying patches?
  • What risk is associated with mobile technologies regarding application security?
  • At which OSI layer does error correction typically occur?
  • What does the term "baseline configuration" refer to in change management?
  • What does tokenization do to production data?
  • Which type of firewall combines packet-filtering with network address translation?
  • Which of the following is a form of security policy enforcement in DLP?
  • What tool helps in centralizing and assisting with log analysis in network security?
  • What is the primary focus of the monitoring component in the COSO framework?
  • What is the primary function of Antivirus Software Monitoring?
  • A walkthrough allows a company to understand which of the following?
  • What is a key benefit of using an ERP system across different business functions?
  • Which type of malware is specifically designed to lock and deny access to files until a ransom is paid?
  • What type of adjustments are made in the AIS process before generating financial reports?
  • Which phase of the General Incident Response Plan involves assembling personnel and tools?
  • What type of events do crisis management plans typically address?
  • Which trust service is primarily concerned with ensuring system availability?
  • Who is required to provide written representations during an audit?
  • When forming an opinion in a SOC engagement, what is considered to ensure the opinion is valid?
  • What is the main focus of patch management as described in the process?
  • What is typically a requirement upon hiring according to the Acceptable Use Policy?
  • In patch management, what does a proactive approach involve?
  • What is a defining feature of Community Cloud?
  • What is a common disadvantage of mesh topology?
  • Which protocol is an example of the Data Link Layer (Layer 2)?
  • What does the 'Archival' step in the Data Lifecycle refer to?
  • What aspect does the COSO Risk Assessment component emphasize when analyzing potential fraud?
  • What does vishing combine with to deceive individuals?
  • What characteristic distinguishes circuit-level gateway firewalls?
  • What should be considered when managing access controls in organizations?
  • Process Layering and Isolation helps in:
  • What does WiFi Protected Access primarily aim to achieve?
  • What is one effect of moving from a SaaS model to an IaaS model in cloud services?
  • In the OSI model, which layer adds Media Access Control (MAC) addresses to data packets?
  • What defines active data collection in an organization?
  • Which component of COSO's framework involves analyzing the likelihood of cyber risks?
  • Which function of the NIST Cybersecurity Framework involves monitoring the network for active attacks?
  • What is the purpose of port scanning in network security?
  • What does an end-to-end governance system consider?
  • In the VAST methodology, what is emphasized for handling threats?
  • What is the primary function of a vulnerability tool in an organization?
  • What is primarily assessed during a security assessment?
  • What is one method used to test Incident Response Plans?
  • In the context of application-based attacks, what does cross-site scripting (XSS) exploit?
  • Which of the following defines the Recovery Time Objective (RTO)?
  • What does the term 'Deficiency in Design' refer to in a SOC engagement?
  • Which component of an Accounting Information System is aimed at internal management issues like budgeting?
  • What do security program champions primarily do?
  • Which disaster recovery site type is the least expensive and does not have any equipment in place?
  • Which subsystem of an Accounting Information System is primarily responsible for processing daily financial transactions?
  • Which of the following is a consequence of a data breach?
  • Which of the following is NOT one of the Six Principles for a Governance System?
  • In security assessments, what is often included in the security assessment findings?
  • What is indicated by Intermediate Events in BPMN?
  • What is emphasized in the COSO framework under organizational structure?
  • For SOC audits, what is a critical aspect when determining materiality?
  • What is the focus of risk assessment procedures in SOC 2 and 3 engagements?
  • Which opinion is given when there are material but not pervasive issues identified in the audit?
  • What is the goal of a buffer overflow attack?
  • What is one aspect of Database Hardening?
  • Which component is responsible for data input in a computer system?
  • In the Production Cycle, what are tracked alongside production costs?
  • Which of the following describes a "Warm Site"?
  • What does HITECH stand for?
  • What does the "Recover" function in the NIST Cybersecurity Framework support?
  • Which risk classification is typically associated with a high compliance requirement?
  • What aspect of DLP focuses on preventing unauthorized data transfers from a single computer or device?
  • What is the purpose of the Cloud Controls Matrix?
  • What does a service auditor do when issuing a modified opinion?
  • What is the purpose of preparing a depreciation schedule in the Fixed Asset Cycle?
  • When is the inclusive method typically required in auditing?
  • Which of the following is true about notifying individuals of subsequent events?
  • What shape is used to represent a task in BPMN activity models?
  • How do attackers often carry out supply chain attacks?
  • What type of attack refers to altering existing network resources to gain unauthorized access?
  • What type of logs is critical for testing and implementing change policies?
  • What is meant by Recovery Time Actual (RTA)?
  • What is a potential impact of a high threat landscape classification?
  • What does robotic process automation (RPA) primarily involve?
  • What type of data do protocols like HTTP and FTP operate on?
  • What is key to successful testing during the change management process?
  • In what step of the Data Lifecycle is data created or captured from external sources?
  • Which backup method typically requires the most time to perform?
  • Which of the following describes an event in the context of incident response?
  • What is involved in determining the extent of procedures during an audit?
  • How many controls and subcategories are defined in CIS Controls Version 8?
  • What do Services, Infrastructure, and Applications provide in the COBIT Governance System?
  • What does CIS Control 16 focus on safeguarding?
  • In COBIT, an organization with more than 250 employees is classified as what size?
  • What is a common strategy used in denial of service attacks to disrupt network operations?
  • What does acceptance testing evaluate in a new application?
  • What encompasses the overall layout and topology of network resources?
  • Which requirement focuses on protecting stored cardholder data?
  • What limitation is generally mentioned in SOC reports?
  • Which of the following practices is essential during the patch management process?
  • What is one requirement under “Maintain a Vulnerability Management Program” in PCI DSS?
  • What should be done to mitigate device mismanagement in the Internet of Things (IoT)?
  • Which of the following presents a risk associated with outsourcing?
  • What is the focus of the 'Recovery' phase in the NIST Privacy Framework?
  • What does the HR and Payroll Cycle allocate in its functions?
  • What organization developed guidance for internal control and enterprise risk management?
  • How many tiers are present in the NIST Privacy Framework?
  • Which component of the CRRIME OIE framework involves risk assessment activities?
  • Which phase in threat modeling involves quantifying the impact of an attack?
  • Which of the following is NOT a category of control family in SP 800-53?
  • What function does the Session Layer (Layer 5) perform in the OSI model?
  • Which choice best describes a composite primary key?
  • What is the primary role of a Cloud Service Provider (CSP)?
  • In applying COSO to blockchain, which type of controls are emphasized?
  • What is noted in a qualified SOC 1 opinion?
  • What is a responsibility of management regarding CUECs?
  • What distinguishes a qualified SOC 2 report from a SOC 1 report?
  • What distinguishes a Type 2 SOC report from a Type 1 SOC report?
  • Which control involves updating software and systems regularly to mitigate risks?
  • What role does Monitoring play in cyber security as per COSO's framework?
  • Which component of the COSO framework focuses on ethics and integrity?
  • What is the primary downside of symmetric encryption?
  • In which cloud model would you mainly develop applications while using some managed services?
  • What element is NOT typically a part of the risk profile in COBIT?
  • What does a system requirement specify?
  • Layered Security comprises which of the following controls?
  • What best describes Cloud Computing?
  • Which of the following is a goal of the APO management objective in the COBIT Core Model?
  • What is one of the main functions of general controls in an information system?
  • What is the initial step in a typical payment card transaction?
  • Which type of attack is characterized by flooding a network with an overwhelming amount of traffic from multiple sources?
  • Which of the following is NOT classified as an End-User Device?
  • Under HIPAA, who qualifies as a covered entity?
  • What is a key function of the Treasury Cycle?
  • What is the primary function of basic packet-filtering firewalls?
  • What is a fundamental aspect of the processes component within the COBIT Governance System?
  • Which implementation group is characterized by having limited cybersecurity defense mechanisms?
  • What is the primary focus of the "Event ID" in the CRRIME OIE model?
  • What type of network architecture connects multiple offices over a large geographical area?
  • Natural Language Processing (NLP) software is primarily used for what purpose?
  • What additional criteria are required for confidentiality, availability, processing integrity, and privacy according to trust services?
  • Which concept restricts data access based on necessity in order to perform a job function?
  • What is the consequence of a failure to disclose a significant subsequent event?
  • Which type of testing is performed after unit testing to ensure that all components work together?
  • What is the primary function of Media Access Control (MAC) Filtering?
  • How do servers function within a network?
  • Which of the following is NOT a responsibility of the service auditor in a SOC report?
  • In which attack type do attackers use stolen credentials to gain access?
  • Which management objective covers the organization of resources for effective technology use?
  • Which of the following is a function of Structured Query Language (SQL)?
  • What attack technique uses a fake identity to create urgency for a target?
  • Which category of data would be classified as "confidential" under CIS Control 3?
  • What is NOT a basic policy or procedure to adopt for change management controls?
  • Which of the following types of data is typically included in an ODS?
  • What is the primary purpose of the COBIT 2019 Framework?
  • What does purging data from the system signify?
  • Which device can be viewed as a more advanced form of a hub?
  • What is a key characteristic of the "Assessing" component in risk management?
  • What is the main idea behind Complementary Subservice Organization Controls (CSOC)?
  • What is NOT one of the four key components of a SOC report?
  • What defines Rule-Based Access Control?
  • What is one method to address risk material misstatement (RMM) in an audit?
  • The Mean Time to Contain refers to:
  • Risk-Based Access Controls apply measures based on what aspect?
  • Which of the following is NOT typically a feature of whitelisting?
  • Who is the intended primary audience for SP 800-53?
  • What technique is utilized in SQL injection attacks?
  • What is the primary purpose of penetration testing?
  • Which of the following best describes "Focus" as a design principle?
  • What is a Race Condition in the context of system security?
  • What does encryption do to data at rest and in transit?
  • What characterizes a Parasitic Virus?
  • Which attack uses legitimate pieces of code to execute operations in a harmful manner?
  • Which methodology focuses on simulating attacks for threat analysis?
  • Which of the following would NOT be included in the auditor's test of controls?
  • Which scoring system is used to assess vulnerabilities?
  • What is one purpose of a fire drill in a walkthrough context?
  • Which of the following is one of the steps in a walkthrough?
  • Which type of scams does email protection primarily guard against?
  • What is the primary purpose of an Incident Response Plan (IRP)?
  • Which protocol operates at the Transport Layer (Layer 4) of the OSI model?
  • Which technology allows devices such as laptops and smartphones to connect to the internet wirelessly?
  • What aspect of access control do Risk-Based Access Controls mainly focus on?
  • Which conversion method involves implementing a new system while still using the old one?
  • Which type of report is restricted from certain potential users according to SOC regulations?
  • How does System Hardening reduce risks for organizations?
  • Who is primarily responsible for carrying out governance policies according to the described framework?
  • Which CIS design principle emphasizes that controls should be measurable?
  • What is a firewall designed to do?
  • Which of the following describes a factory IT role?
  • What does a protocol define in networking?
  • How does the 'living off the land' (LotL) tactic relate to cybersecurity?
  • In the context of network attacks, what does "spoofing" refer to?
  • What is a defining feature of mesh topology?
  • Which framework was improved by NIST in 1995 to include cybersecurity?
  • Which group is NOT considered a threat agent in cybersecurity?
  • How many layers are in the OSI model?
  • What is the main purpose of using a modem in a network?
  • What does Tier 2 of the NIST Implementation Tiers suggest about cybersecurity awareness?
  • What is the function of signal modifiers?
  • What happens if an explanation of matters is added to a SOC report?
  • Which of the following is a key characteristic of Cloud Service Providers?
  • Which of the following methods is NOT a type of conversion?
  • What does Infrastructure as a Service (IaaS) primarily provide?
  • Which of the following is a requirement under the HITECH Act?
  • Which principle emphasizes the importance of aligning a governance framework with major standards and regulations?
  • Which of the following is NOT a component of a Security Assessment Report (SAR)?
  • What is a common method used in brute-force attacks?
  • What is the first step in a walkthrough process?
  • The NIST Cybersecurity Framework consists of how many categories?
  • What characterizes a 'First Mover' strategy in technology adoption?
  • What is the first step in a patch management program?
  • What is a primary advantage of the Agile Method?
  • What is the primary purpose of a disaster recovery plan?
  • What principle of GDPR emphasizes data accuracy?
  • What is the purpose of the SELECT clause in SQL?
  • What is essential for effective internal controls according to COSO Principle 14?
  • Which process represents the first step in the Extract, Transform, Load (ETL) method?
  • What is the primary benefit of the 'Hybrid Control' approach in SP 800-53?
  • Which layer is responsible for routing addresses within the OSI model?
  • In a Type 1 SOC report, what is stated regarding operating effectiveness?
  • What does Network Hardening specifically focus on?
  • Which conversion method gradually adds volume to the new system while still operating the old system?
  • Which SQL command is used to combine records from two or more tables based on a related column?
  • What do compliance violations refer to in cloud computing risks?
  • Which component of COSO Enterprise Risk Management focuses on defining risk appetite?
  • In the context of security, what does the principle of Least Privilege primarily ensure?
  • What is a characteristic of the publication phase in the data lifecycle?
  • What is the main focus of the "Information, Communication, and Reporting" component in COSO?
  • Which of the following best describes Log Analysis in the context of access controls?
  • Which of the following is a potential risk associated with cloud computing?
  • What type of audit opinion indicates that management's description of the system fairly presents the system with effective controls?
  • What is a common challenge identified in the Information and Technology factor of COBIT?
  • What is the primary purpose of the Recovery Point Objective (RPO)?
  • Which of the following is NOT a function of COSO's Information and Communication component?
  • How is Single Loss Expectancy (SLE) calculated?
  • What is one significant advantage of utilizing shared services in IT systems?
  • Which component is primarily responsible for improving network traffic?
  • What element plays a key role in influencing the technology adoption strategy in COBIT?
  • What does the term 'gap analysis' signify in the context of the NIST framework?
  • What is the first component of the NIST Cybersecurity Framework?
  • What does a modem do in terms of internet connectivity?
  • What should be evaluated in terms of materiality when forming an opinion?
  • What is the purpose of an Access Control List (ACL)?
  • What is the primary function of a router in a network?
  • What aspect of database normalization does the Third Normal Form (3NF) require?
  • What does the risk profile in COBIT primarily indicate?
  • What aspect is NOT typically included in the description of test of controls?
  • What does an arrow symbolize in a data flow diagram?
  • Which characteristic defines a Data Lake?
  • In the context of risk response, which of the following options is NOT a valid approach?
  • What is a structured walkthrough?
  • What key feature does an Enterprise Resource Planning (ERP) system provide?
  • Which layer of the OSI model is responsible for data encryption?
  • Which trust service focuses on the protection of sensitive information?
  • What is the first step in the Data Lifecycle Process?
  • In the payment process, what role does the merchant electronic gateway account play?
  • Which technology is used to create secure communications over the internet?
  • What is a common expectation for controls at a subservice organization?
  • What does purpose limitation require regarding data processing?
  • What does the term 'materiality' refer to in the context of SOC reports?
  • What does Maximum Tolerable Downtime (MTD) refer to?
  • Which of the following describes a Start Event in BPMN?
  • Which of the following is an example of a detective control?
  • In SOC engagements, what primarily focuses on risk assessment?
  • What does the 'current profile' refer to in the NIST framework?
  • What must a Type 2 report include that a Type 1 report does not?
  • What is one method included in corrective controls for improving security?
  • What is the main purpose of the Application Layer (Layer 7) in the OSI model?
  • Which of the following is a part of the NIST Special Publication 800-39 risk management framework?
  • Which of the following is an example of tokenization?
  • Which of the following should be disabled to prevent malware installation?
  • What is a common integration risk that may affect change implementation?
  • Which of the following is NOT one of the components included in the COBIT framework for management and governance objectives?
  • Which of the following is included in the concept of Processing Integrity?
  • Networking ACLs primarily regulate what type of traffic?
  • Where in a SOC engagement report are CUECs usually identified?
  • What is a potential risk associated with outsourcing?
  • What is a Data Dictionary used for?
  • Which type of flow is represented by dotted lines in BPMN?
  • How are nodes arranged in a ring topology?
  • What method helps in classifying the severity of vulnerabilities?
  • In SP 800-53, what is meant by 'System Specific Control'?
  • What does Recovery Point Actual (RPA) measure?
  • Which of the following best describes a hub?
  • What does a Virtual Private Network (VPN) primarily offer?
  • Endpoint-Based DLP systems are responsible for which of the following?
  • What method involves using deceptive emails that appear legitimate to obtain personal information?
  • Which component of the COBIT 2019 framework is concerned with organizational culture and behavior?
  • Which of the following is a feature of Relational Databases?
  • What is a common feature of vishing attacks?
  • What does the Fixed Asset Cycle calculate when disposing of an asset?
  • Which of the following provides guidance for translating desired behaviors into actionable practices in COBIT Governance System?
  • Which type of token generates fixed passcodes based on time?
  • What typically minimizes initial capital expenditure in cloud computing?
  • What does the 'timing' aspect refer to in SOC audit procedures?
  • What is a critical part of a data recovery strategy?
  • What is a business continuity plan primarily concerned with?
  • What does privacy primarily protect?
  • What is the primary advantage of a star topology in network design?
  • What is the main purpose of the COBIT 2019 Implementation Guide?
  • Which method is NOT typically included in COBIT IT implementation methods?
  • What type of organization is characterized by Tier 4 in the Implementation Tiers?
  • Which SOC report focuses specifically on internal control over financial reporting?
  • Which of the following best describes a neural network?
  • What does business resiliency refer to?
  • What is a common vulnerability related to default application settings?
  • During the Purchasing and Disbursements Cycle, what does the company submit after receiving a vendor's product?
  • What does "embedded software code" in the context of cyber attacks mean?
  • Which of the following is a safeguard for data at rest?
  • What is Tier 1 of the NIST Implementation Tiers characterized by?
  • Policy-Based Access Control combines which of the following?
  • What type of report determines if security controls comply with established goals?
  • Which term describes an approach that creates urgency through a fabricated identity?
  • What does the HAVING clause do in SQL queries?
  • What is the primary goal of conducting security interviews during assessments?
  • What is the purpose of the inclusive method in the context of auditing?
  • What type of passcode generation does an asynchronous token rely on?
  • What phrase typically appears in a qualified opinion section?
  • Which of the following is NOT typically considered an insurable loss in cyber insurance?
  • What is the primary goal during the preparation phase of the data lifecycle?
  • What is a misstatement description in a SOC engagement?
  • What is the primary purpose of a Data Mart?
  • What is a key function of firewalls in cybersecurity?
  • What does EDM stand for within the COBIT Core Model Governance Objective?
  • Which of these factors is NOT typically associated with risks in outsourcing?
  • Who submits the payment request to the third-party network in a payment transaction?
  • Which act is known for promoting healthcare privacy and security?
  • Which organization developed COBIT in 1996?
  • Which cloud computing deployment model combines private and public elements?
  • In SOC reports, which section is specifically mentioned for Type 1 reports?
  • What is a common financial impact of cyber extortion losses?
  • How do phishing simulations help employees?
  • What is the primary focus of the BAI management objective?
  • What is a significant disadvantage of application-level gateway firewalls?
  • What principle is emphasized in access control management?
  • According to CIS Controls, what is the most important initial step for organizations?
  • Which of the following is a disadvantage of ring topology?
  • What does the sourcing model for IT refer to?
  • Which of the following SQL commands is considered the first clause in a SELECT statement?
  • What is passive data collection?
  • Which of the following categories is included in the Financial perspective of the balanced scorecard for Enterprise Goals?
  • What does a 'Slow Adopter' strategy entail?
  • Which type of mobile app appears legitimate but is actually malicious?
  • Filesystems use ACLs to:
  • Which of the following is NOT a responsibility of network infrastructure hardware?
  • Which component functions as the connection point for critical pieces of a computer?
  • Which legislative act requires minimum controls for federal information systems?
  • Which of the following is NOT a type of Social Engineering Attack?
  • What does availability ensure in an information system context?
  • What does a Service Set Identifier (SSID) represent in a wireless network?
  • What plays a crucial role in determining materiality for SOC 2?
  • Which function does a proxy serve in a network?
  • Which piece of hardware is necessary for connecting a computer to the Internet?
  • What does the 'nature' aspect refer to in procedures of SOC audits?
  • What do timing channels utilize as a method for covert communication?
  • What is the primary goal of cybersecurity?
  • What is an important aspect of Endpoint Hardening?
  • What type of backup involves copying all data items that have changed since the last backup?
  • Which of the following is NOT included in the report for subservice organizations?
  • What type of incident response team is best suited for larger organizations with geographical dispersion?
  • What is the final reporting action in the Revenue and Collections Cycle?
  • Which of the following is NOT a complexity in obtaining data from an external source?
  • What does Mobile Code typically do?
  • During the purging phase of the data lifecycle, what happens to the data?
  • What is the objective of the "Internal Environment" component in the CRRIME OIE framework?
  • What does asymmetric encryption use to encrypt messages?
  • Which of these is an example of an external peripheral device?
  • What kind of attack identifies known websites of supply chain partners to exploit?
  • How many standardized frameworks are listed from NIST?
  • A business continuity plan is considered more comprehensive than which of the following?
  • What is the main purpose of the NIST framework profiles?
  • What characterizes a blockchain control system?
  • What is the purpose of masking in data protection?
  • Which operating system is commonly used on mobile devices?
  • What method is commonly used in a phishing attack?
  • In data flow diagrams, what does an open-ended rectangle represent?
  • What does DTSPD stand for in the context of change environments?
  • What characterizes a Star Schema in database design?
  • What does the archival phase involve in the data lifecycle?
  • Which attack involves redirecting a user to a malicious website through altered URLs?
  • Which management component of COBIT is responsible for continuous monitoring and assessments?
  • What does the term "sensitive personal information" refer to in the context of privacy?
  • What is the purpose of enterprise log management?
  • Which of the following illustrates both logical and physical flows?
  • What best describes a system's software in a SOC context?
  • Which category of personnel is critical for the success of security awareness programs?
  • Which step in the Data Lifecycle involves analyzing and using the data?
  • Who does GDPR apply to?
  • Which element in an audit involves determining the tolerable rate of deviation?
  • Which method of data protection is considered the highest form?
  • What is crucial for maintaining the operational environment of data centers?
  • What is one requirement for auditors regarding independence in the inclusive method?
  • Which control is focused on restricting user access to sensitive data?
  • Which layer is primarily responsible for the proper formatting of video and image data?
  • In the COSO framework, what does 'CA' stand for in the context of existing control activities?
  • How is the threat landscape categorized in COBIT?
  • What is the primary purpose of the decision-making entities within an organization as defined by COBIT Governance System?
  • What language signals an adverse SOC 1 report?
  • In COBIT, what does the 'Risk Profile' design factor assess?
  • Which control emphasizes the importance of security awareness and training programs?
  • In which year was the National Institute of Standards and Technology established?
  • Which of the following is NOT a goal of PCI DSS?
  • What shape is used to represent a gateway in BPMN activity models?
  • What is a characteristic of the Private cloud deployment model?
  • What does Single Sign-On (SSO) enable a user to do?
  • Which organization is known for creating a cybersecurity recovery framework?
  • What is a key element in an incident response management program?
  • Which type of attack involves injecting code into a company's website to target users?
  • What is an adverse event in the field of cybersecurity?
  • Which trust service is often analyzed during risk management planning?
  • What is the primary goal of a Data Loss Prevention (DLP) program?
  • Which component is considered the brain of the internal computer hardware?
  • Which trust service is primarily focused on the integrity of data processing?
  • What does the Purchasing and Disbursement Cycle record in the GL?
  • What is a common characteristic of a reverse shell attack?
  • What are two common attacks on networks?
  • What is a primary key in a relational database?
  • Which of the following best describes the analytics and usage phase of the data lifecycle?
  • Which strategy involves compromising a vendor to launch an attack on their clients?
  • Which SQL clause is used to filter results based on a condition?
  • What is the primary action taken in the Payroll Cycle?
  • Which of the following is a feature of the Financial Reporting System within an Accounting Information System?
  • What is one of the phases of threat modeling?
  • What type of controls are labeled as 'Common Control' in SP 800-53?
  • According to SP800-63B, how often should passwords be changed?
  • What elements are part of the SOC system?
  • What is a significant impact on risk when moving from a private cloud to a public cloud?
  • In the COBIT framework, what type of IT role is considered critical for innovation and business operations?
  • Which component of the COSO framework focuses on the efficiency of business operations?
  • What is a Reasonableness Test designed to do in an Accounting Information System?
  • What type of access does a proxy server provide?
  • What is a service commitment in the context of SOC?
  • What is a key focus of CIS Control 1?
  • What is typically the focus of the "Responding" component in NIST risk management?
  • Which component aims to ensure compliance with external requirements as part of MEA objectives?
  • What is the purpose of testing patches in a non-production environment?
  • Which type of DLP system scans files on devices such as printers and USB drives?
  • Multi-Factor Authentication (MFA) uses what to validate identity?
  • What is concealed in the context of information security?
  • In an effective Incident Response Plan, what is meant by 'learning'?
  • What is a potential outcome of quality risks in outsourcing?
  • What is the average cost of a data breach for an organization?
  • What is the focus of unit testing in software development?
  • What must auditors agree on when planning SOC engagements?
  • Which type of virus deletes or overwrites information on a file?
  • What aspect of technology does robotic process automation utilize?
  • What is an advantage of using a ring topology?
  • Which of the following is an example of a mobile technology risk related to connectivity?
  • What type of flow in BPMN connects objects within the same pool?
  • What is the main benefit of using Software as a Service (SaaS)?
  • What is the primary basis for an adverse opinion in a SOC report?
  • Which of the following is typically considered a back-end device?
  • What characteristic does biometrics use for identification?
  • Which cycle includes recording cash, interest, and investment activity?
  • Which of the following is an example of a corrective control?
  • What does COBIT stand for?
  • What is the main focus of IT infrastructure controls in relation to system availability?
  • Which type of DLP system prevents the transfer of outgoing data on the network?
  • What type of behaviors should security awareness training include?
  • Which of the following methods can be categorized as a covert channel in data communication?
  • What must an auditor's test of controls include?
  • Which step is NOT part of the Change Management Process?
  • Which change environment focuses on debugging code to identify errors?
  • In what context is the term 'offshore operations' typically used?
  • When considering risk in cloud computing, what does 'vendor lock-in' refer to?
  • In the context of COSO, what does "Performance" refer to?
  • What is the primary focus of abstraction in information systems?
  • What is the primary purpose of the Center for Internet Security (CIS)?
  • Which risk arises from outdated IoT firmware?
  • Which responsibility is unique to SOC 1 engagements during the planning stage?
  • What is the primary risk associated with not managing software assets effectively as per CIS Control 2?
  • What role does a gateway play in networking?
  • What are Smart Cards primarily designed to do?
  • Which statement best describes a key function of the General Ledger in an AIS?
  • What is the first step in the AIS (Accounting Information System) process?
  • What type of framework is utilized for structuring Enterprise Goals in COBIT?
  • Which of the following is NOT a type of cyberattack?
  • Which of the following is an example of an Internet of Things (IoT) device?
  • Role-Based Access Control modifies user access based on what factor?
  • What security measure ensures users cannot access more data than they need to perform their roles?
  • What principle assumes a company's network is always at risk, even after user authentication?
  • Which step in the business impact analysis (BIA) process involves identifying critical resources?
  • In information security, what is the primary goal of protecting systems and information?
  • What is a characteristic of a social engineering attack?
  • In the Revenue and Collections Cycle, what is the first step after a customer orders goods?
  • Which of the following is NOT a process driven by IT systems?
  • What is firmware primarily responsible for?
  • In the context of accounting information systems, which control type is focused on ensuring data integrity during input?
  • What does a post-incident review help organizations achieve?
  • What is the primary function of digital signatures?
  • Keystroke logging is designed to track what?
  • What aspect does the "Governance and Culture" component of COSO encompass?
  • Which of the following best defines data minimization?
  • What does the 'Storage Limitation' principle in GDPR state?
  • According to COSO Principle 13, what type of information should organizations focus on acquiring?
  • What does STRIDE stand for in threat modeling?
  • In a Relational Database, what do the terms "tables" and "attributes" refer to?
  • Which fee might be considered in calculating cyber extortion losses?
  • Which type of attack relies on creating false communications to impersonate legitimate users?
  • Which of the following is NOT a component of HIPAA safeguards?
  • Which type of safeguard includes security management and training under HIPAA?
  • What is required for independence in SOC engagements?
  • What does NIST stand for?
  • In CIS Implementation Group 2, what is a primary characteristic?
  • What is an Operational Data Store (ODS) primarily used for?
  • CIS Control 2 requires organizations to manage what aspect of their systems?
  • Which of the following is NOT one of the 11 design factors listed in COBIT 2019?
  • Which of the following is NOT one of the main components of the NIST Cybersecurity Framework?
  • How is the 'Enterprise Strategy' characterized in the COBIT framework?
  • What level of granularity is provided by Swim Lanes in BPMN?
  • Which aspect of COSO encompasses commitment to competence?
  • When should security considerations be integrated into the software development lifecycle?
  • What is the purpose of URL filtering in web protection?
  • What term describes the time taken to detect an incident?
  • What is a primary benefit of using an Application Software Provider (ASP) for ERP systems?
  • What is one of the auditor's responsibilities when planning SOC engagements?
  • What principle does First Normal Form (1NF) enforce in database design?
  • Which of the following is a focus area in COBIT?
  • What does a Deviation or Exception indicate in a SOC engagement?
  • What best describes a Data Warehouse?
  • Which additional requirement is specific to Type 2 SOC reports?
  • According to the requirements for trust services, which of the following is essential for access control?
  • Which step focused on assessing the effectiveness of the DLP program comes last in the walkthrough steps?
  • What type of DLP system is focused on preventing data transfer from cloud services?
  • Which term refers specifically to phishing attempts that target high-ranking executives?
  • Which risk factor is associated with a lack of stakeholder support during a project?
  • Which authentication technology involves using location, time, and point of access for validation?
  • What is a key feature of single sign-on (SSO) systems?
  • What is the significance of the 'People, Skills, Competencies' element in the COBIT Governance System?
  • Which type of threats are classified as external threats in cybersecurity?
  • Which of the following is a method that allows only specific applications to run on a system?
  • In IG3, organizations typically have what level of cybersecurity?
  • What does PCI DSS stand for?
  • What is the most common method for storing structured data?
  • What does ‘high’ classification in disruption impact signify in the BIA process?
  • In the context of database schemas, what is a Dimension Table?
  • In the COSO framework, what does 'T' represent in the context of existing control activities?
  • What is the main objective of Network Segmentation or Isolation?
  • In the context of EDM, which component is primarily focused on risk?
  • What is the intention behind malware?
  • What distinguishes a Data Model from a Database Schema?
  • What is the main function of mirroring in data management?
  • Which of the following is classified as a preventative control?
  • What role does a Network Monitoring Tool play in access control?
  • What is the focus of the COBIT 2019 Framework?
  • What does the DSS management objective focus on in the COBIT framework?
  • What does the 'Protect' component of the NIST Privacy Framework focus on?
  • Which organization developed the Open Systems Interconnection (OSI) model?
  • What does the term "VAACT" refer to in Processing Integrity?
  • Which design factor would focus on the impact of regulations on IT governance according to COBIT?
  • Which item should be described in the management's description of the system?
  • During the implementation of a CSP, what is a crucial step regarding governance?
  • What does 'PHI' stand for in the context of HIPAA?
  • Which control focuses on monitoring and defending against internal and external security threats?
  • Which of the following tools can assist in asset reconfiguration according to security standards?
  • Which characteristic describes the Waterfall Model in project management?
  • What is a key activity included in the synthesis phase of the data lifecycle?
  • What is the primary purpose of SQL Injection attacks?
  • Which component is considered the most critical in an Incident Response Plan?
  • What is obfuscation in the context of data protection?
  • Which approach must be taken if a type 1 or type 2 auditor's report is available for a subservice organization?
  • Examples of detective controls do NOT typically include:
  • Which type of physical attack involves following someone into a secured area?
  • What does Mean Time to Repair (MTTR) represent?
  • What is a primary disadvantage of asymmetric encryption?
  • What does the "Review and Revision" component of COSO focus on?
  • Which characteristic is not associated with CIS Controls?
  • What is the auditor's responsibility if a security breach occurs?
  • Who maintains the Common Vulnerabilities and Exposures (CVE) Dictionary?
  • What is a message digest or hash value created by?
  • What does the Physical Layer (Layer 1) do with messages?
  • What do Complementary User Entity Controls (CUECs) refer to?
  • What is the primary benefit of edge-enabled devices?
  • What is a critical function of the card network in the payment process?
  • Which technology is considered a common internet protocol?
  • Which CIS implementation group would involve security mechanisms suitable for organizations handling sensitive client data?
  • Which aspect is essential for the COBIT Governance System to operate effectively?
  • Which type of database model includes attributes like primary keys and foreign keys?
  • What is the main benefit of conducting a Full Backup on a regular basis?
  • In an Accounting Information System, which type of control helps to ensure that processing is accurate and complete?
  • Which factor is NOT considered in determining materiality for SOC 1?
  • What must be done to verify patches that have been deployed?
  • What is the primary purpose of BPMN Activity Models?
  • What is the purpose of the HIPAA Security Rule?
  • How is confidentiality defined according to NIST?
  • What is the role of data encryption during the preparation phase?
  • What is NOT a type of log utilized for network monitoring?
  • Which of the following components is crucial for the delivery and support of services in the COBIT framework?
  • What is the purpose of NIST SP 800-53?
  • What is the main objective of Host-Based Attacks?
  • What is a primary focus of COSO Principle 11 regarding technology controls?
  • In COBIT 2019, what is a primary focus area for creating a tailored enterprise governance system for IT?
  • What is the purpose of incident response teams in relation to security assessment reports?
  • What does an Incident Response Timeline commonly illustrate?
  • What is the first step in the NIST Cybersecurity Framework regarding vulnerabilities?
  • Which of the following is NOT a risk related to cloud computing?
  • Which PCI DSS requirement involves using a firewall configuration?
  • Which phase of incident response focuses on the restoration of normal IT operations?
  • What is the primary focus of the Control Environment component in COSO's framework?
  • Which of the following does NOT fall under the SOC system?
  • Which process involves evaluating third-party service providers with access to sensitive data?
  • What do foreign-sourced attacks typically exploit?
  • What does Annualized Loss Expectancy (ALE) measure?
  • Which key AIS function involves approving or denying credit?
  • According to PCI DSS, what should access to cardholder data be based on?
  • Why is it difficult to scale symmetric encryption?
  • What is a fundamental purpose of the Data Lifecycle process?
  • Which of the following is NOT a metric for assessing system availability?
  • What is the first recommended step when implementing a Cloud Service Provider?
  • Which of the following best explains the focus of preventative controls in an internal control framework?
  • What type of cipher involves replacing letters with symbols?
  • What does a Fact Table contain in a database schema?
  • In a disaster recovery context, what is a "Hot Site"?
  • How does a switch differ from a router?
  • Which of the following is NOT a step in implementing a DLP program?
  • What is one of the key functions of the treasury cycle in an AIS?
  • Which virus type uses multiple methods to infect files?
  • Which of the following is considered a system availability control?
  • What is the intended outcome of the transform stage in the ETL process?
  • Which scenario involves tampering with systems to add unauthorized devices?
  • What does a LEFT JOIN do in SQL?
  • What component provides temporary storage in a computer system?
  • In which SOC engagements is establishing an overall strategy especially important?
  • What is one of the goals specifically mentioned under the 'Growth' category in the COBIT framework?
  • Which tier indicates that an organization’s cybersecurity practices are integrated into planning?
  • What does the implementation of mitigation and contingency plans involve in business continuity planning?
  • What is an example of acceptance criteria in document systems controls?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy