Browse all practice questions for the Information Systems and Controls (ISC) CPA Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Information Systems and Controls (ISC) CPA Practice Exam 2026 - Free CPA Exam Practice Questions and Study Guide course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • What type of flow in BPMN connects objects within the same pool?
  • In the OSI model, which layer adds Media Access Control (MAC) addresses to data packets?
  • Which of the following is a method that allows only specific applications to run on a system?
  • Which authentication technology involves using location, time, and point of access for validation?
  • What is the primary purpose of an Incident Response Plan (IRP)?
  • What is the purpose of URL filtering in web protection?
  • What type of authentication uses physical devices to verify identity?
  • What is a fundamental aspect of the processes component within the COBIT Governance System?
  • Which legislative act requires minimum controls for federal information systems?
  • Which of the following best describes "Focus" as a design principle?
  • What is the purpose of incident response teams in relation to security assessment reports?
  • What is the primary purpose of the COBIT 2019 Framework?
  • What does privacy primarily protect?
  • What organization developed guidance for internal control and enterprise risk management?
  • Which of the following is a focus area in COBIT?
  • What is one method included in corrective controls for improving security?
  • Which of the following is a feature of the Financial Reporting System within an Accounting Information System?
  • Which attack uses legitimate pieces of code to execute operations in a harmful manner?
  • Which term describes an approach that creates urgency through a fabricated identity?
  • According to the requirements for trust services, which of the following is essential for access control?
  • What is the first step in the AIS (Accounting Information System) process?
  • Which of the following is a consequence of a data breach?
  • What is a business continuity plan primarily concerned with?
  • Which type of attack involves injecting code into a company's website to target users?
  • What kind of attack identifies known websites of supply chain partners to exploit?
  • Which type of testing is performed after unit testing to ensure that all components work together?
  • What is the first component of the NIST Cybersecurity Framework?
  • What aspect does the "Governance and Culture" component of COSO encompass?
  • Which principle emphasizes the importance of aligning a governance framework with major standards and regulations?
  • Which PCI DSS requirement involves using a firewall configuration?
  • In what context is the term 'offshore operations' typically used?
  • In a disaster recovery context, what is a "Hot Site"?
  • Which of the following is NOT one of the components included in the COBIT framework for management and governance objectives?
  • What is an important aspect of Endpoint Hardening?
  • Which of the following categories is included in the Financial perspective of the balanced scorecard for Enterprise Goals?
  • In SOC reports, which section is specifically mentioned for Type 1 reports?
  • What best describes Cloud Computing?
  • What do Services, Infrastructure, and Applications provide in the COBIT Governance System?
  • In disaster recovery, what is a key aspect of systems availability controls?
  • What is the primary purpose of penetration testing?
  • Who submits the payment request to the third-party network in a payment transaction?
  • When forming an opinion in a SOC engagement, what is considered to ensure the opinion is valid?
  • What method involves using deceptive emails that appear legitimate to obtain personal information?
  • Which component functions as the connection point for critical pieces of a computer?
  • How many tiers are present in the NIST Privacy Framework?
  • In COBIT 2019, what is a primary focus area for creating a tailored enterprise governance system for IT?
  • What is a key focus of CIS Control 1?
  • What does provisioning refer to in an organization?
  • What does confidentiality in trust services entail?
  • What does business resiliency refer to?
  • Which SQL clause is used to filter results based on a condition?
  • In which cloud model would you mainly develop applications while using some managed services?
  • In which year was the National Institute of Standards and Technology established?
  • What is a defining feature of mesh topology?
  • What type of framework is utilized for structuring Enterprise Goals in COBIT?
  • Which approach must be taken if a type 1 or type 2 auditor's report is available for a subservice organization?
  • Which phase of the General Incident Response Plan involves assembling personnel and tools?
  • When should security considerations be integrated into the software development lifecycle?
  • What does the acronym 'S' stand for in COSO Risk Assessment?
  • What is a fundamental purpose of the Data Lifecycle process?
  • Which of the following describes a "Warm Site"?
  • Which component of an Accounting Information System is aimed at internal management issues like budgeting?
  • What does the Physical Layer (Layer 1) do with messages?
  • What is the auditor's responsibility if a security breach occurs?
  • What is a characteristic of hashing?
  • Process Layering and Isolation helps in:
  • Which component is primarily responsible for improving network traffic?
  • Which disaster recovery site type is the least expensive and does not have any equipment in place?
  • What is a significant disadvantage of application-level gateway firewalls?
  • What characterizes a Parasitic Virus?
  • What is the last step in the PASTA threat methodology?
  • Which trust service is primarily focused on the integrity of data processing?
  • What does the 'Protect' component of the NIST Privacy Framework focus on?
  • Which of the following is NOT a responsibility of the service auditor in a SOC report?
  • Which item should be described in the management's description of the system?
  • What best describes a system's software in a SOC context?
  • Who is required to provide written representations during an audit?
  • Who maintains the Common Vulnerabilities and Exposures (CVE) Dictionary?
  • In a Relational Database, what do the terms "tables" and "attributes" refer to?
  • What must auditors agree on when planning SOC engagements?
  • What does an arrow symbolize in a data flow diagram?
  • Which of the following is a risk associated with cloud computing?
  • In COBIT, an organization with more than 250 employees is classified as what size?
  • In the Production Cycle, what are tracked alongside production costs?
  • What is the primary risk associated with not managing software assets effectively as per CIS Control 2?
  • What characterizes Discretionary Access Control?
  • What typically minimizes initial capital expenditure in cloud computing?
  • Which tier in the NIST Privacy Framework is characterized as 'risk-informed'?
  • What is the primary purpose of the Recovery Point Objective (RPO)?
  • Which step involves gaining approval from management in the change management process?
  • Which management component of COBIT is responsible for continuous monitoring and assessments?
  • Which of the following is a requirement under the HITECH Act?
  • According to PCI DSS, what should access to cardholder data be based on?
  • What is the primary downside of symmetric encryption?
  • Which type of safeguard includes security management and training under HIPAA?
  • What does the risk profile in COBIT primarily indicate?
  • What is a common expectation for controls at a subservice organization?
  • What is the first step in a walkthrough process?
  • How is Single Loss Expectancy (SLE) calculated?
  • What is the difference between replication and mirroring?
  • What type of controls are labeled as 'Common Control' in SP 800-53?
  • What is the primary action taken in the Payroll Cycle?
  • Which component is considered the brain of the internal computer hardware?
  • What does robotic process automation (RPA) primarily involve?
  • What is an advantage of using a ring topology?
  • What does the sourcing model for IT refer to?
  • What is the formula for calculating the Annualized Rate of Occurrence (ARO)?
  • Which control focuses on monitoring and defending against internal and external security threats?
  • What characteristic distinguishes circuit-level gateway firewalls?
  • What should be considered when managing access controls in organizations?
  • Which implementation group is characterized by having limited cybersecurity defense mechanisms?
  • Which type of token generates fixed passcodes based on time?
  • Which of the following best describes the analytics and usage phase of the data lifecycle?
  • What is a defining feature of Community Cloud?
  • What is a primary focus of COSO Principle 11 regarding technology controls?
  • Which statement best describes a key function of the General Ledger in an AIS?
  • Which of the following best defines redundancy as it relates to system availability?
  • Which group is NOT considered a threat agent in cybersecurity?
  • What principle is emphasized in access control management?
  • What is a potential outcome of quality risks in outsourcing?
  • When considering risk in cloud computing, what does 'vendor lock-in' refer to?
  • CIS Control 2 requires organizations to manage what aspect of their systems?
  • What is the primary focus of abstraction in information systems?
  • What plays a crucial role in determining materiality for SOC 2?
  • What must be done to verify patches that have been deployed?
  • Which layer is responsible for routing addresses within the OSI model?
  • How many standardized frameworks are listed from NIST?
  • In which SOC engagements is establishing an overall strategy especially important?
  • What is a service commitment in the context of SOC?
  • What is the main purpose of the NIST framework profiles?
  • Which of the following is NOT typically considered an insurable loss in cyber insurance?
  • Which requirement focuses on protecting stored cardholder data?
  • What does Recovery Point Actual (RPA) measure?
  • Which step focused on assessing the effectiveness of the DLP program comes last in the walkthrough steps?
  • Which of the following practices is essential during the patch management process?
  • What is the purpose of the inclusive method in the context of auditing?
  • Which component is considered the most critical in an Incident Response Plan?
  • What type of audit opinion indicates that management's description of the system fairly presents the system with effective controls?
  • Which type of physical attack involves following someone into a secured area?
  • What does the 'Archival' step in the Data Lifecycle refer to?
  • Which type of database model includes attributes like primary keys and foreign keys?
  • In the payment process, what role does the merchant electronic gateway account play?
  • What is the initial step in a typical payment card transaction?
  • Which type of change environment is used to deploy applications?
  • In the context of COSO, what does "Performance" refer to?
  • Which of the following tools can assist in asset reconfiguration according to security standards?
  • Which of the following is NOT a component of a Security Assessment Report (SAR)?
  • Which device can be viewed as a more advanced form of a hub?
  • How do attackers often carry out supply chain attacks?
  • In SOC engagements, what primarily focuses on risk assessment?
  • What best describes a Data Warehouse?
  • Which opinion is given when there are material but not pervasive issues identified in the audit?
  • What is the role of data encryption during the preparation phase?
  • What security measure ensures users cannot access more data than they need to perform their roles?
  • Which of the following is NOT a complexity in obtaining data from an external source?
  • Which of the following is NOT one of the Six Principles for a Governance System?
  • Which term refers specifically to phishing attempts that target high-ranking executives?
  • Which category of personnel is critical for the success of security awareness programs?
  • What phrase typically appears in a qualified opinion section?
  • What is a Reasonableness Test designed to do in an Accounting Information System?
  • What is the purpose of NIST SP 800-53?
  • In the VAST methodology, what is emphasized for handling threats?
  • Which type of mobile app appears legitimate but is actually malicious?
  • Which type of flow is represented by dotted lines in BPMN?
  • What is the first step in the Data Lifecycle Process?
  • Which of the following is a function of Structured Query Language (SQL)?
  • Which component of the COBIT 2019 framework is concerned with organizational culture and behavior?
  • Which of the following statements is included in a Disclaimer SOC report?
  • In the context of EDM, which component is primarily focused on risk?
  • Which backup method typically requires the most time to perform?
  • Which characteristic defines a Data Lake?
  • What type of access does a proxy server provide?
  • What is the primary purpose of BPMN Activity Models?
  • What is a common integration risk that may affect change implementation?
  • What is a key element in an incident response management program?
  • Which component aims to ensure compliance with external requirements as part of MEA objectives?
  • Which organization is known for creating a cybersecurity recovery framework?
  • What characterizes a blockchain control system?
  • Which methodology focuses on simulating attacks for threat analysis?
  • How do servers function within a network?
  • What is the primary purpose of the decision-making entities within an organization as defined by COBIT Governance System?
  • Which method is NOT typically included in COBIT IT implementation methods?
  • Which type of DLP system prevents the transfer of outgoing data on the network?
  • What distinguishes a Data Model from a Database Schema?
  • Which of the following is a part of the NIST Special Publication 800-39 risk management framework?
  • What is a critical function of the card network in the payment process?
  • What method is commonly used in a phishing attack?
  • What principle assumes a company's network is always at risk, even after user authentication?
  • What does NIST stand for?
  • What is the main objective of Host-Based Attacks?
  • What does the term "baseline configuration" refer to in change management?
  • Which risk classification is typically associated with a high compliance requirement?
  • Networking ACLs primarily regulate what type of traffic?
  • Which of the following is an example of tokenization?
  • What does acceptance testing evaluate in a new application?
  • Which authentication method requires users to input a numeric code they have memorized?
  • What is involved in determining the extent of procedures during an audit?
  • What limitation is generally mentioned in SOC reports?
  • What does a protocol define in networking?
  • Which of the following is NOT classified as an End-User Device?
  • What is a characteristic of a social engineering attack?
  • Who does GDPR apply to?
  • Which component of COSO Enterprise Risk Management focuses on defining risk appetite?
  • What type of behaviors should security awareness training include?
  • In information security, what is the primary goal of protecting systems and information?
  • What is a drawback of bus topology?
  • What is the intended outcome of the transform stage in the ETL process?
  • Which of the following is an example of a mobile technology risk related to connectivity?
  • Which of the following is NOT a category of control family in SP 800-53?
  • What does an Incident Response Timeline commonly illustrate?
  • What technique is utilized in SQL injection attacks?
  • What is emphasized in the COSO framework under organizational structure?
  • What attack technique uses a fake identity to create urgency for a target?
  • What is the purpose of the SELECT clause in SQL?
  • Which of the following is a safeguard for data at rest?
  • In COBIT, what does the 'Risk Profile' design factor assess?
  • What is one of the key functions of the treasury cycle in an AIS?
  • What shape is used to represent a task in BPMN activity models?
  • What shape is used to represent a gateway in BPMN activity models?
  • Layered Security comprises which of the following controls?
  • Which of the following is NOT included in the report for subservice organizations?
  • What is the primary purpose of SQL Injection attacks?
  • Which of the following is included in the concept of Processing Integrity?
  • What is the primary goal of a Data Loss Prevention (DLP) program?
  • Which step in the business impact analysis (BIA) process involves identifying critical resources?
  • Which of the following is NOT a risk related to cloud computing?
  • What does the "carve out" method refer to in SOC reports?
  • In patch management, what does a proactive approach involve?
  • In the COSO framework, what does 'T' represent in the context of existing control activities?
  • What does CIS Control 16 focus on safeguarding?
  • What is a common feature of vishing attacks?
  • Which of the following is typically considered a back-end device?
  • Which CIS implementation group would involve security mechanisms suitable for organizations handling sensitive client data?
  • A walkthrough allows a company to understand which of the following?
  • What is one of the goals specifically mentioned under the 'Growth' category in the COBIT framework?
  • What does the Fixed Asset Cycle calculate when disposing of an asset?
  • How is confidentiality defined according to NIST?
  • What is one requirement for auditors regarding independence in the inclusive method?
  • How many layers are in the OSI model?
  • Which risk arises from outdated IoT firmware?
  • What is a potential impact of a high threat landscape classification?
  • Which type of threats are classified as external threats in cybersecurity?
  • Which design factor would focus on the impact of regulations on IT governance according to COBIT?
  • Which of the following is classified as a preventative control?
  • Which of the following is an example of an Internet of Things (IoT) device?
  • What is concealed in the context of information security?
  • Examples of detective controls do NOT typically include:
  • Which of the following illustrates both logical and physical flows?
  • What is a common financial impact of cyber extortion losses?
  • In which attack type do attackers use stolen credentials to gain access?
  • What does the term 'materiality' refer to in the context of SOC reports?
  • Which step in the Data Lifecycle involves analyzing and using the data?
  • What is a Race Condition in the context of system security?
  • Which characteristic is not associated with CIS Controls?
  • Which of the following presents a risk associated with outsourcing?
  • Which element in an audit involves determining the tolerable rate of deviation?
  • What is the purpose of port scanning in network security?
  • Which of the following is a primary component of the NIST Privacy Framework?
  • Which type of virus deletes or overwrites information on a file?
  • What method helps in classifying the severity of vulnerabilities?
  • What does the term 'managed security' imply in the context of the APO management objectives?
  • What type of backup involves copying all data items that have changed since the last backup?
  • What is a message digest or hash value created by?
  • What is one of the main goals of the PCI DSS?
  • Which type of attack is characterized by flooding a network with an overwhelming amount of traffic from multiple sources?
  • Which of the following is a disadvantage of ring topology?
  • Which component of COSO's framework involves analyzing the likelihood of cyber risks?
  • Which responsibility is unique to SOC 1 engagements during the planning stage?
  • What does the 'timing' aspect refer to in SOC audit procedures?
  • Which risk factor is associated with a lack of stakeholder support during a project?
  • In the COSO framework, what does 'CA' stand for in the context of existing control activities?
  • Which factor is NOT considered in determining materiality for SOC 1?
  • The Mean Time to Contain refers to:
  • What level of granularity is provided by Swim Lanes in BPMN?
  • What is the primary function of a vulnerability tool in an organization?
  • In a Type 1 SOC report, what is stated regarding operating effectiveness?
  • Which SOC report focuses specifically on internal control over financial reporting?
  • In what step of the Data Lifecycle is data created or captured from external sources?
  • What does purging data from the system signify?
  • What is the main focus of the "Information, Communication, and Reporting" component in COSO?
  • What element is NOT typically a part of the risk profile in COBIT?
  • What does STRIDE stand for in threat modeling?
  • What function does the Session Layer (Layer 5) perform in the OSI model?
  • What is the primary purpose of a disaster recovery plan?
  • What is the main function of mirroring in data management?
  • Which method of data protection is considered the highest form?
  • Which of the following is a goal of the APO management objective in the COBIT Core Model?
  • Which of the following methods can be categorized as a covert channel in data communication?
  • Which type of attack relies on creating false communications to impersonate legitimate users?
  • Which trust service is often analyzed during risk management planning?
  • Which type of report is restricted from certain potential users according to SOC regulations?
  • What type of incident response team is best suited for larger organizations with geographical dispersion?
  • What is a primary benefit of using an Application Software Provider (ASP) for ERP systems?
  • What type of report determines if security controls comply with established goals?
  • The NIST Cybersecurity Framework consists of how many categories?
  • Which of the following is an example of a corrective control?
  • In the context of a Relational Database, what are fields?
  • What distinguishes a Type 2 SOC report from a Type 1 SOC report?
  • What do Complementary User Entity Controls (CUECs) refer to?
  • Which of the following is a feature of Relational Databases?
  • What is the primary goal during the preparation phase of the data lifecycle?
  • Which of the following is considered a system availability control?
  • Which key AIS function involves approving or denying credit?
  • According to CIS Controls, what is the most important initial step for organizations?
  • Which control emphasizes the importance of security awareness and training programs?
  • What is a primary advantage of the Agile Method?
  • What is the primary focus of the BAI management objective?
  • What is passive data collection?
  • What does Tier 2 of the NIST Implementation Tiers suggest about cybersecurity awareness?
  • Which of the following best describes context-aware authentication?
  • What role does a gateway play in networking?
  • What does Network Hardening specifically focus on?
  • How do phishing simulations help employees?
  • What is the primary function of basic packet-filtering firewalls?
  • Which scoring system is used to assess vulnerabilities?
  • What is the final reporting action in the Revenue and Collections Cycle?
  • What is a characteristic of the publication phase in the data lifecycle?
  • Which phase of incident response focuses on the restoration of normal IT operations?
  • What is the goal of a buffer overflow attack?
  • What does purpose limitation require regarding data processing?
  • What is a potential risk associated with outsourcing?
  • What is one significant advantage of utilizing shared services in IT systems?
  • What aspect does the COSO Risk Assessment component emphasize when analyzing potential fraud?
  • During the Purchasing and Disbursements Cycle, what does the company submit after receiving a vendor's product?
  • What is a key activity included in the synthesis phase of the data lifecycle?
  • What does a post-incident review help organizations achieve?
  • Endpoint-Based DLP systems are responsible for which of the following?
  • What component provides temporary storage in a computer system?
  • What aspect of technology does robotic process automation utilize?
  • What must an auditor's test of controls include?
  • What does the term 'gap analysis' signify in the context of the NIST framework?
  • What type of organization is characterized by Tier 4 in the Implementation Tiers?
  • What aspect of database normalization does the Third Normal Form (3NF) require?
  • What is a common disadvantage of mesh topology?
  • What is the purpose of testing patches in a non-production environment?
  • In the context of application-based attacks, what does cross-site scripting (XSS) exploit?
  • Which attack occurs when a user’s legitimate request is captured and transmitted again by the attacker?
  • How do network address translation firewalls enhance privacy?
  • What is NOT one of the four key components of a SOC report?
  • Multi-Factor Authentication (MFA) uses what to validate identity?
  • What is the main purpose of Security Policies in an organization?
  • Which process involves evaluating third-party service providers with access to sensitive data?
  • How many controls and subcategories are defined in CIS Controls Version 8?
  • Which of the following is a form of security policy enforcement in DLP?
  • What tool helps in centralizing and assisting with log analysis in network security?
  • What is a key function of firewalls in cybersecurity?
  • Keystroke logging is designed to track what?
  • What principle of GDPR emphasizes data accuracy?
  • What does Mobile Code typically do?
  • Which component is responsible for data input in a computer system?
  • What is the purpose of enterprise log management?
  • When is the inclusive method typically required in auditing?
  • What is the first recommended step when implementing a Cloud Service Provider?
  • What is one of the main functions of general controls in an information system?
  • In data flow diagrams, what does an open-ended rectangle represent?
  • Which of the following is NOT one of the main components of the NIST Cybersecurity Framework?
  • What does the term 'Deficiency in Design' refer to in a SOC engagement?
  • What is the primary benefit of the 'Hybrid Control' approach in SP 800-53?
  • What is primarily assessed during a security assessment?
  • What does the 'current profile' refer to in the NIST framework?
  • Which layer of the OSI model is responsible for data encryption?
  • What is the primary basis for an adverse opinion in a SOC report?
  • What happens to the purchase order after the receiving department enters the quantity received?
  • Where in a SOC engagement report are CUECs usually identified?
  • Which of the following best describes Log Analysis in the context of access controls?
  • What should an auditor do regarding subsequent events?
  • How does System Hardening reduce risks for organizations?
  • What does a modem do in terms of internet connectivity?
  • What is the main objective of Network Segmentation or Isolation?
  • Which component of the COSO framework focuses on ethics and integrity?
  • Which change environment focuses on debugging code to identify errors?
  • What happens if an explanation of matters is added to a SOC report?
  • What does the term "sensitive personal information" refer to in the context of privacy?
  • What is the main benefit of using Software as a Service (SaaS)?
  • Which control involves updating software and systems regularly to mitigate risks?
  • What type of data do protocols like HTTP and FTP operate on?
  • Which of the following types of data is typically included in an ODS?
  • What do foreign-sourced attacks typically exploit?
  • What elements are part of the SOC system?
  • In SP 800-53, what is meant by 'System Specific Control'?
  • Which technology allows devices such as laptops and smartphones to connect to the internet wirelessly?
  • What does the 'Storage Limitation' principle in GDPR state?
  • Which cloud computing deployment model combines private and public elements?
  • Who is primarily responsible for carrying out governance policies according to the described framework?
  • What is the primary purpose of a Data Mart?
  • What is the purpose of an Access Control List (ACL)?
  • What is the primary focus of the Control Environment component in COSO's framework?
  • Which of the following describes a factory IT role?
  • Which fee might be considered in calculating cyber extortion losses?
  • What does the HR and Payroll Cycle allocate in its functions?
  • Which of the following is NOT a responsibility of network infrastructure hardware?
  • What is obfuscation in the context of data protection?
  • Which statement is true regarding compliance requirements?
  • What are Smart Cards primarily designed to do?
  • What is NOT a type of log utilized for network monitoring?
  • What defines Rule-Based Access Control?
  • What is a responsibility of management regarding CUECs?
  • Which trust service is primarily concerned with ensuring system availability?
  • What is a firewall designed to do?
  • What type of adjustments are made in the AIS process before generating financial reports?
  • Which additional requirement is specific to Type 2 SOC reports?
  • What is a Data Dictionary used for?
  • Which subsystem of an Accounting Information System is primarily responsible for processing daily financial transactions?
  • What is the primary focus of the monitoring component in the COSO framework?
  • What is the purpose of the HIPAA Security Rule?
  • Which of the following is a key characteristic of Cloud Service Providers?
  • What does the 'nature' aspect refer to in procedures of SOC audits?
  • Policy-Based Access Control combines which of the following?
  • Which type of firewall combines packet-filtering with network address translation?
  • What is considered a component of offshore operations?
  • How does a switch differ from a router?
  • What do compliance violations refer to in cloud computing risks?
  • What is one method to address risk material misstatement (RMM) in an audit?
  • Which of the following best describes a neural network?
  • What type of cipher involves replacing letters with symbols?
  • What does "embedded software code" in the context of cyber attacks mean?
  • What does PCI DSS stand for?
  • Which function of the NIST Cybersecurity Framework involves monitoring the network for active attacks?
  • Which function does a proxy serve in a network?
  • In the context of network attacks, what does "spoofing" refer to?
  • What is the focus of the COBIT 2019 Framework?
  • What is the first stage in a cyberattack?
  • What is typically a requirement upon hiring according to the Acceptable Use Policy?
  • Which type of malware is specifically designed to lock and deny access to files until a ransom is paid?
  • What is required for independence in SOC engagements?
  • What method can attackers use to obtain confidential data through technology?
  • What is one of the auditor's responsibilities when planning SOC engagements?
  • What must a Type 2 report include that a Type 1 report does not?
  • What type of DLP system is focused on preventing data transfer from cloud services?
  • Which of the following is one of the steps in a walkthrough?
  • What is NOT a basic policy or procedure to adopt for change management controls?
  • Which of the following provides guidance for translating desired behaviors into actionable practices in COBIT Governance System?
  • What is typically the focus of the "Responding" component in NIST risk management?
  • What describes the physical layout of nodes in a network?
  • What does the implementation of mitigation and contingency plans involve in business continuity planning?
  • What is the main purpose of the Application Layer (Layer 7) in the OSI model?
  • Which virus type uses multiple methods to infect files?
  • What does tokenization do to production data?
  • How are nodes arranged in a ring topology?
  • What does the "Review and Revision" component of COSO focus on?
  • What element plays a key role in influencing the technology adoption strategy in COBIT?
  • What is the primary benefit of edge-enabled devices?
  • What is the first step in the NIST Cybersecurity Framework regarding vulnerabilities?
  • What is the purpose of preparing a depreciation schedule in the Fixed Asset Cycle?
  • What does an end-to-end governance system consider?
  • What is key to successful testing during the change management process?
  • What principle does First Normal Form (1NF) enforce in database design?
  • Which phase in threat modeling involves quantifying the impact of an attack?
  • What characterizes a Star Schema in database design?
  • What is the focus of unit testing in software development?
  • What does vishing combine with to deceive individuals?
  • Why is it difficult to scale symmetric encryption?
  • In CIS Implementation Group 2, what is a primary characteristic?
  • In COBIT, what is the purpose of risk optimization within the EDM governance objective?
  • What is a primary disadvantage of asymmetric encryption?
  • Role-Based Access Control modifies user access based on what factor?
  • Which of the following is NOT a step in implementing a DLP program?
  • What aspect of access control do Risk-Based Access Controls mainly focus on?
  • Which management objective covers the organization of resources for effective technology use?
  • Which of the following describes a Start Event in BPMN?
  • What does a system requirement specify?
  • Which trust service focuses on the protection of sensitive information?
  • Which of the following is NOT a type of cyberattack?
  • In an Accounting Information System, which type of control helps to ensure that processing is accurate and complete?
  • What is the main focus of patch management as described in the process?
  • What is the main idea behind Complementary Subservice Organization Controls (CSOC)?
  • What is the primary function of Media Access Control (MAC) Filtering?
  • What is the intention behind malware?
  • Which category of data would be classified as "confidential" under CIS Control 3?
  • What is a common method used in brute-force attacks?
  • Which protocol is an example of the Data Link Layer (Layer 2)?
  • What aspect is NOT typically included in the description of test of controls?
  • In security assessments, what is often included in the security assessment findings?
  • In IG3, organizations typically have what level of cybersecurity?
  • According to COSO Principle 13, what type of information should organizations focus on acquiring?
  • What is a common strategy used in denial of service attacks to disrupt network operations?
  • What is the main benefit of conducting a Full Backup on a regular basis?
  • What are two common attacks on networks?
  • What is an example of acceptance criteria in document systems controls?
  • What is the primary function of a router in a network?
  • What is the objective of the "Internal Environment" component in the CRRIME OIE framework?
  • What does a circle or rectangle with rounded edges represent in a data flow diagram?
  • Which of the following is NOT a process driven by IT systems?
  • What does a LEFT JOIN do in SQL?
  • What is the main purpose of using a modem in a network?
  • What is the function of signal modifiers?
  • What does a 'Slow Adopter' strategy entail?
  • What does Maximum Tolerable Downtime (MTD) refer to?
  • What does ‘high’ classification in disruption impact signify in the BIA process?
  • Which control is focused on restricting user access to sensitive data?
  • What is one effect of moving from a SaaS model to an IaaS model in cloud services?
  • Filesystems use ACLs to:
  • What is the average cost of a data breach for an organization?
  • For SOC audits, what is a critical aspect when determining materiality?
  • What does the Bring Your Own Device (BYOD) Policy primarily focus on?
  • Which of the following is NOT typically a feature of whitelisting?
  • Which step is NOT part of the Change Management Process?
  • What language signals an adverse SOC 1 report?
  • What is the most common method for storing structured data?
  • Which organization developed COBIT in 1996?
  • What is a critical part of a data recovery strategy?
  • What does a Personal Identification Number (PIN) primarily consist of?
  • What is a common characteristic of a reverse shell attack?
  • Which concept restricts data access based on necessity in order to perform a job function?
  • What does Mean Time to Repair (MTTR) represent?
  • What is one aspect of Database Hardening?
  • Which of the following best describes a hub?
  • What is the primary purpose of the Center for Internet Security (CIS)?
  • What is firmware primarily responsible for?
  • What type of events do crisis management plans typically address?
  • What does the Exposure Factor (EF) represent in loss estimation?
  • In the context of security, what does the principle of Least Privilege primarily ensure?
  • What feature of next-generation firewalls allows for customization?
  • What does Infrastructure as a Service (IaaS) primarily provide?
  • What does availability ensure in an information system context?
  • What does a Fact Table contain in a database schema?
  • What additional criteria are required for confidentiality, availability, processing integrity, and privacy according to trust services?
  • Which of the following defines the Recovery Time Objective (RTO)?
  • What is the primary advantage of a star topology in network design?
  • What is the focus of the 'Recovery' phase in the NIST Privacy Framework?
  • What does EDM stand for within the COBIT Core Model Governance Objective?
  • In the context of database schemas, what is a Dimension Table?
  • Which of the following is NOT a type of Social Engineering Attack?
  • What is the purpose of estimating losses in the BIA process?
  • In the Revenue and Collections Cycle, what is the first step after a customer orders goods?
  • What distinguishes a qualified SOC 2 report from a SOC 1 report?
  • Which conversion method gradually adds volume to the new system while still operating the old system?
  • Which of the following does NOT fall under the SOC system?
  • What is a key feature of single sign-on (SSO) systems?
  • During the purging phase of the data lifecycle, what happens to the data?
  • What is the primary goal of cybersecurity?
  • What is the first step in a patch management program?
  • Which type of DLP system scans files on devices such as printers and USB drives?
  • Which SQL command is used to combine records from two or more tables based on a related column?
  • Which of the following is NOT one of the 11 design factors listed in COBIT 2019?
  • What aspect of DLP focuses on preventing unauthorized data transfers from a single computer or device?
  • What characterizes a 'First Mover' strategy in technology adoption?
  • How is the threat landscape categorized in COBIT?
  • Which type of scams does email protection primarily guard against?
  • In the context of risk response, which of the following options is NOT a valid approach?
  • How does the 'living off the land' (LotL) tactic relate to cybersecurity?
  • What is a significant impact on risk when moving from a private cloud to a public cloud?
  • Which conversion method involves implementing a new system while still using the old one?
  • What is crucial for maintaining the operational environment of data centers?
  • Which of the following is an example of a detective control?
  • What do Pools represent in BPMN diagrams?
  • How are disruption impacts classified in the BIA process?
  • Which cycle includes recording cash, interest, and investment activity?
  • Which operating system is commonly used on mobile devices?
  • What does encryption do to data at rest and in transit?
  • Which component of the CRRIME OIE framework involves risk assessment activities?
  • What does DTSPD stand for in the context of change environments?
  • Which is NOT a component of network infrastructure management?
  • Which strategy involves compromising a vendor to launch an attack on their clients?
  • Which type of attack involves an attacker who intercepts and potentially alters the communications between two parties?
  • What is a characteristic of the Private cloud deployment model?
  • What is a common challenge identified in the Information and Technology factor of COBIT?
  • What should be done to mitigate device mismanagement in the Internet of Things (IoT)?
  • What is emphasized by maintaining an information security policy in PCI DSS?
  • What is the significance of the 'People, Skills, Competencies' element in the COBIT Governance System?
  • In applying COSO to blockchain, which type of controls are emphasized?
  • A business continuity plan is considered more comprehensive than which of the following?
  • Which of the following is a potential risk associated with cloud computing?
  • At which OSI layer does error correction typically occur?
  • What defines active data collection in an organization?
  • What is the primary role of a Cloud Service Provider (CSP)?
  • Which of the following should be disabled to prevent malware installation?
  • Which regulation is considered the strictest privacy law in the world?
  • Which of the following SQL commands is considered the first clause in a SELECT statement?
  • What is the primary goal of conducting security interviews during assessments?
  • During the implementation of a CSP, what is a crucial step regarding governance?
  • What is the primary function of digital signatures?
  • What does CIS Control 3 emphasize regarding data?
  • What is essential for effective internal controls according to COSO Principle 14?
  • What is a key function of the Treasury Cycle?
  • What key feature does an Enterprise Resource Planning (ERP) system provide?
  • Which process represents the first step in the Extract, Transform, Load (ETL) method?
  • Which of the following is true about notifying individuals of subsequent events?
  • What should be evaluated in terms of materiality when forming an opinion?
  • What does COBIT stand for?
  • What type of logs is critical for testing and implementing change policies?
  • What does Single Sign-On (SSO) enable a user to do?
  • What is the purpose of masking in data protection?
  • Which protocol operates at the Transport Layer (Layer 4) of the OSI model?
  • What type of passcode generation does an asynchronous token rely on?
  • Which of the following best defines data minimization?
  • What does WiFi Protected Access primarily aim to achieve?
  • What role do Culture, Ethics, and Behavior play in the success of management and governance according to COBIT?
  • What encompasses the overall layout and topology of network resources?
  • What type of attack refers to altering existing network resources to gain unauthorized access?
  • Which tier indicates that an organization’s cybersecurity practices are integrated into planning?
  • According to SP800-63B, how often should passwords be changed?
  • Risk-Based Access Controls apply measures based on what aspect?
  • What do security program champions primarily do?
  • What does a Virtual Private Network (VPN) primarily offer?
  • Which scenario involves tampering with systems to add unauthorized devices?
  • Which aspect of COSO encompasses commitment to competence?
  • Which of the following would NOT be included in the auditor's test of controls?
  • What is the main purpose of the COBIT 2019 Implementation Guide?
  • In the context of accounting information systems, which control type is focused on ensuring data integrity during input?
  • Which aspect is essential for the COBIT Governance System to operate effectively?
  • What does Annualized Loss Expectancy (ALE) measure?
  • What is the main focus of IT infrastructure controls in relation to system availability?
  • Which layer is primarily responsible for the proper formatting of video and image data?
  • Natural Language Processing (NLP) software is primarily used for what purpose?
  • What does HITECH stand for?
  • Which technology is used to create secure communications over the internet?
  • What is the primary function of Antivirus Software Monitoring?
  • In an effective Incident Response Plan, what is meant by 'learning'?
  • What is the primary focus of the "Event ID" in the CRRIME OIE model?
  • In the COBIT framework, what type of IT role is considered critical for innovation and business operations?
  • Which of the following components is crucial for the delivery and support of services in the COBIT framework?
  • Which component of the COSO framework focuses on the efficiency of business operations?
  • What characteristic does biometrics use for identification?
  • What type of network architecture connects multiple offices over a large geographical area?
  • Which of the following is NOT a goal of PCI DSS?
  • Which of these factors is NOT typically associated with risks in outsourcing?
  • Which of the following is NOT a metric for assessing system availability?
  • Which CIS design principle emphasizes that controls should be measurable?
  • What does the "Recover" function in the NIST Cybersecurity Framework support?
  • Which of the following is NOT a function of COSO's Information and Communication component?
  • What does the DSS management objective focus on in the COBIT framework?
  • What is a misstatement description in a SOC engagement?
  • Which choice best describes a composite primary key?
  • What term describes the time taken to detect an incident?
  • What is a primary key in a relational database?
  • Which act is known for promoting healthcare privacy and security?
  • What is the consequence of a failure to disclose a significant subsequent event?
  • Which of the following is NOT a component of HIPAA safeguards?
  • What role does a Network Monitoring Tool play in access control?
  • What is a structured walkthrough?
  • Which technology is considered a common internet protocol?
  • What do timing channels utilize as a method for covert communication?
  • What is a key characteristic of the "Assessing" component in risk management?
  • What is a common vulnerability related to default application settings?
  • What is indicated by Intermediate Events in BPMN?
  • Which piece of hardware is necessary for connecting a computer to the Internet?
  • What is Tier 1 of the NIST Implementation Tiers characterized by?
  • What is meant by Recovery Time Actual (RTA)?
  • What must an organization regularly test as part of PCI DSS compliance?
  • What is an Operational Data Store (ODS) primarily used for?
  • What is the focus of risk assessment procedures in SOC 2 and 3 engagements?
  • What is one method used to test Incident Response Plans?
  • What is a key benefit of using an ERP system across different business functions?
  • Which of these is an example of an external peripheral device?
  • Which factor is crucial when approving and deploying patches?
  • What is one requirement under “Maintain a Vulnerability Management Program” in PCI DSS?
  • What does the term "VAACT" refer to in Processing Integrity?
  • Who is the intended primary audience for SP 800-53?
  • Which organization developed the Open Systems Interconnection (OSI) model?
  • What does a service auditor do when issuing a modified opinion?
  • Which of the following methods is NOT a type of conversion?
  • What is noted in a qualified SOC 1 opinion?
  • How is the 'Enterprise Strategy' characterized in the COBIT framework?
  • What is an adverse event in the field of cybersecurity?
  • What is one of the phases of threat modeling?
  • What does the Purchasing and Disbursement Cycle record in the GL?
  • What risk is associated with mobile technologies regarding application security?
  • What is the purpose of the Cloud Controls Matrix?
  • Which framework was improved by NIST in 1995 to include cybersecurity?
  • What does the HAVING clause do in SQL queries?
  • Which attack involves redirecting a user to a malicious website through altered URLs?
  • What does a Service Set Identifier (SSID) represent in a wireless network?
  • What does asymmetric encryption use to encrypt messages?
  • What does 'PHI' stand for in the context of HIPAA?
  • Under HIPAA, who qualifies as a covered entity?
  • Which of the following describes an event in the context of incident response?
  • What does a Deviation or Exception indicate in a SOC engagement?
  • What does the archival phase involve in the data lifecycle?
  • What role does Monitoring play in cyber security as per COSO's framework?
  • Which of the following best explains the focus of preventative controls in an internal control framework?
  • What is one purpose of a fire drill in a walkthrough context?
  • Which topology connects nodes in a linear or tree format?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy