SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CISA Certified Information Systems Auditor Vocab
Start Test
Study First
Subjects
:
certifications
,
cisa
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Self-governance and freedom from conflict of interest and undue influence. The IS auditor should be free to make his/her own decisions; not influenced by the organization being audited and its people (managers and employers).
legal risk
Hash total
Point-of-presence (POP)
Independence
2. A system's level of resilience to seamlessly react from hardware and/or software failure
Fault tolerance
Password cracker
Public key infrastructure
Whitebox testing
3. An exchange rate; which can be used optionally to perform foreign currency conversion. The corporate exchange rate is generally a standard market rate determined by senior financial management for use throughout the organization.
Applet
Corporate exchange rate
Netware
Monetary unit sampling
4. The individual responsible for the safeguard and maintenance of all program and data files
Broadband
Whitebox testing
Librarian
Coaxial cable
5. The method used to identify the location of a participant in a network. Ideally; addressing specifies where the participant is located rather than who they are (name) or how to get there (routing).
Public key
Database replication
Performance testing
Addressing
6. A popular network protocol and cabling scheme that uses a bus topology and CSMA/CD (carrier sense multiple access/collision detection) to prevent network failures or collisions when two devices try to access the network at the same time
Test generators
Automated teller machine (ATM)
Ethernet
Value-added network (VAN)
7. Computer hardware that houses the electronic circuits that control/direct all operations of the computer system
Scure socket layer (SSL)
Central processing unit (CPU)
IDS (intrusion detection system)
ASCII (American Standard Code for Information Interchange)
8. Data unit that is routed from source to destination in a packet-switched network. A packet contains both routing information and data. Transmission control protocol/Internet protocol (TCP/IP) is such a packet-switched network.
Packet
Network
Hexadecimal
Control weakness
9. To apply a variable; alternating current (AC) field for the purpose of demagnetizing magnetic recording media. The process involves increasing the AC field gradually from zero to some maximum value and back to zero; which leaves a very low residue of
Multiplexor
Degauss
Noise
Encryption
10. Analysis that is performed on a continuous basis; with results gained in time to alter the run-time system
Compiler
Real-time analysis
ACK (acknowledgement)
Remote job entry (RJE)
11. A named collection of related records
File
Bandwidth
COCO
Audit evidence
12. A hierarchical database that is distributed across the Internet that allows names to be resolved into IP addresses (and vice versa) to locate services such as web and e-mail servers
Statistical sampling
DNS (domain name system)
Log
Intrusion
13. Defined minimum performance measures at or above which the service delivered is considered acceptable
Digital certificate
Service level agreement (SLA)
Scheduling
Object code
14. A project management technique used in the planning and control of system projects
Fault tolerance
Batch processing
Program evaluation and review technique (PERT)
Assembly language
15. Is the risk to earnings or capital arising from changes in the value of portfolios of financial instruments. Price risk arises from market making; dealing and position taking in interest rate; foreign exchange; equity and commodities markets. Banks m
Internet packet (IP) spoofing
Database replication
price risk
Brute force
16. Detection on the basis of whether the system activity matches that defined as bad
Table look-ups
Data flow
Misuse detection
Computer-assisted audit technique (CAATs)
17. Describes the design properties of a computer system that allow it to resist active attempts to attack or bypass it
Fail-safe
Function point analysis
Automated teller machine (ATM)
browser
18. A system of interconnected computers and the communications equipment used to connect them
Project team
Continuity
Network
Hypertext
19. The proportion of known attacks detected by an intrusion detection system
Dumb terminal
Base case
UDDI
Coverage
20. Diagramming data that are to be exchanged electronically; including how it is to be used and what business management systems need it. It is a preliminary step for developing an applications link. (Also see application tracing and mapping.)
False negative
Uninterruptible power supply (UPS)
Mapping
Terms of reference
21. Applications that detect; prevent and possibly remove all known viruses from files located in a microcomputer hard drive
Antivirus software
Embedded audit module
Content filtering
Internal penetrators
22. Processing is achieved by entering information into the computer via a video display terminal. The computer immediately accepts or rejects the information; as it is entered.
Job control language (JCL)
Online data processing
Hypertext
Monetary unit sampling
23. A device for sending and receiving computerized data over transmission lines
Terminal
Database
Spoofing
Monitoring policy
24. The act of copying raw data from one place to another with little or no formatting for readability. Usually; dump refers to copying data from main memory to a display screen or a printer. Dumps are useful for diagnosing bugs. After a program fails; o
Computer-aided software engineering (CASE)
Symmetric key encryption
Memory dump
Intrusion
25. The accuracy and completeness of information as well as to its validity in accordance with business values and expectations
Mutual takeover
Application programming interface (API)
Integrity
Auditability
26. A protocol used for transmitting data between two ends of a connection
DMZ (demilitarized zone)
Modem (modulator-demodulator)
Judgment sampling
PPP (point-to-point protocol)
27. A process involving the extraction of components from existing systems and restructuring these components to develop new systems or to enhance the efficiency of existing systems. Existing software systems thus can be modernized to prolong their funct
Spool (simultaneous peripheral operations online)
Evidence
Independence
Reengineering
28. Files maintained by a system; primarily a database management system; for the purposed of reapplying changes following an error or outage recovery
Combined Code on Corporate Governance
Audit plan
Redo logs
Audit expert systems
29. The rate of transmission for telecommunication data. It is expressed in bits per second (bps).
Rulebase
Frame relay
Baud rate
Controls (Control procedures)
30. A layer within the International Organization for Standardization (ISO)/Open Systems Interconnection (OSI) model. It is used in information transfers between users through application programs and other devices. In this layer various protocols are ne
Program evaluation and review technique (PERT)
Relevant audit evidence
Application layer
price risk
31. Used to electronically scan and input written information from a source document
RS-232 interface
Mapping
Control Objectives for Enterprise Governance
Optical character recognition
32. Programs and supporting documentation that enable and facilitate use of the computer. Software controls the operation of the hardware.
File
Permanent virtual circuit (PVC)
Table look-ups
Software
33. Any technique designed to provide the electronic equivalent of a handwritten signature to demonstrate the origin and integrity of specific data. Digital signatures are an example of electronic signatures.
Electronic signature
Transaction protection
Windows NT
Exposure
34. An individual using a terminal; PC or an application can access a network to send an unstructured message to another individual or group of people.
E-mail/interpersonal messaging
Fault tolerance
Screening routers
Privacy
35. A phone number that represents the area in which the communications provider or Internet service provider (ISP) provides service
Point-of-presence (POP)
Criteria
Data custodian
Test programs
36. An edit check designed to ensure the data in a particular field is numeric
Sniff
Numeric check
Fault tolerance
Degauss
37. An empowering method/process by which management and staff of all levels collectively identify and evaluate IS related risks and controls under the guidance of a facilitator who could be an IS auditor. The IS auditor can utilise CRSA for gathering re
Anomaly
Data structure
Control risk self-assessment
Link editor (linkage editor)
38. A network monitoring and data acquisition tool that performs filter translation; packet acquisition and packet display
Authorization
Output analyzer
Real-time processing
Tcpdump
39. With respect to security; a special type of virus that does not attach itself to programs; but rather spreads via other methods such as e-mail (also see virus)
Worm
Web Services Description Language (WSDL)
Misuse detection
Sniff
40. Transactions that cannot be denied after the fact
Nonrepudiable trnasactions
Topology
Fault tolerance
Registration authority (RA)
41. A document distributed to software vendors requesting them to submit a proposal to develop or provide a software product
X.500
Top-level management
Hub
Request for proposal (RFP)
42. A report on Internal Control--An Integrated Framework sponsored by the Committee of Sponsoring Organizations of the Treadway Commission in 1992. It provides guidance and a comprehensive framework of internal control for all organizations.'
Security administrator
COSO
Application acquisition review
Anomaly detection
43. An extension to PPP to facilitate the creation of VPNs. L2TP merges the best features of PPTP (from Microsoft) and L2F (from Cisco).
World Wide Web Consortium (W3C)
L2TP (Layer 2 tunneling protocol)
Value-added network (VAN)
Database
44. System flowcharts are graphical representations of the sequence of operations in an information system or program. Information system flowcharts show how data from source documents flow through the computer to final distribution to users. Symbols use
Surge suppressor
Run instructions
System flowcharts
Object Management Group (OMG)
45. Any intentional violation of the security policy of a system
Application program
Private key cryptosystems
Data security
Intrusion
46. Software packages that sequentially dial telephone numbers; recording any numbers that answer
War dialler
Sniff
Worm
Application security
47. An entity (department; cost center; division or other group) responsible for entering and maintaining budget data.
Budget organization
Application controls
Systems development life cycle (SDLC)
IPSec (Internet protocol security)
48. The computer room and support areas
Proxy server
Editing
Information processing facility (IPF)
Polymorphism (objects)
49. The consolidation in 1998 of the ''Cadbury;'' ''Greenbury'' and ''Hampel'' Reports. Named after the Committee Chairs; these reports were sponsored by the UK Financial Reporting Council; the London Stock Exchange; the Confederation of British Industry
Combined Code on Corporate Governance
Executable code
Access rights
Audit expert systems
50. Audit evidence is relevant if it pertains to the audit objectives and has a logical relationship to the findings and conclusions it is used to support.
Relevant audit evidence
Bus topology
Embedded audit module
Monetary unit sampling