Test your basic knowledge |

CISA Certified Information Systems Auditor Vocab

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Self-governance and freedom from conflict of interest and undue influence. The IS auditor should be free to make his/her own decisions; not influenced by the organization being audited and its people (managers and employers).






2. A system's level of resilience to seamlessly react from hardware and/or software failure






3. An exchange rate; which can be used optionally to perform foreign currency conversion. The corporate exchange rate is generally a standard market rate determined by senior financial management for use throughout the organization.






4. The individual responsible for the safeguard and maintenance of all program and data files






5. The method used to identify the location of a participant in a network. Ideally; addressing specifies where the participant is located rather than who they are (name) or how to get there (routing).






6. A popular network protocol and cabling scheme that uses a bus topology and CSMA/CD (carrier sense multiple access/collision detection) to prevent network failures or collisions when two devices try to access the network at the same time






7. Computer hardware that houses the electronic circuits that control/direct all operations of the computer system






8. Data unit that is routed from source to destination in a packet-switched network. A packet contains both routing information and data. Transmission control protocol/Internet protocol (TCP/IP) is such a packet-switched network.






9. To apply a variable; alternating current (AC) field for the purpose of demagnetizing magnetic recording media. The process involves increasing the AC field gradually from zero to some maximum value and back to zero; which leaves a very low residue of






10. Analysis that is performed on a continuous basis; with results gained in time to alter the run-time system






11. A named collection of related records






12. A hierarchical database that is distributed across the Internet that allows names to be resolved into IP addresses (and vice versa) to locate services such as web and e-mail servers






13. Defined minimum performance measures at or above which the service delivered is considered acceptable






14. A project management technique used in the planning and control of system projects






15. Is the risk to earnings or capital arising from changes in the value of portfolios of financial instruments. Price risk arises from market making; dealing and position taking in interest rate; foreign exchange; equity and commodities markets. Banks m






16. Detection on the basis of whether the system activity matches that defined as bad






17. Describes the design properties of a computer system that allow it to resist active attempts to attack or bypass it






18. A system of interconnected computers and the communications equipment used to connect them






19. The proportion of known attacks detected by an intrusion detection system






20. Diagramming data that are to be exchanged electronically; including how it is to be used and what business management systems need it. It is a preliminary step for developing an applications link. (Also see application tracing and mapping.)






21. Applications that detect; prevent and possibly remove all known viruses from files located in a microcomputer hard drive






22. Processing is achieved by entering information into the computer via a video display terminal. The computer immediately accepts or rejects the information; as it is entered.






23. A device for sending and receiving computerized data over transmission lines






24. The act of copying raw data from one place to another with little or no formatting for readability. Usually; dump refers to copying data from main memory to a display screen or a printer. Dumps are useful for diagnosing bugs. After a program fails; o






25. The accuracy and completeness of information as well as to its validity in accordance with business values and expectations






26. A protocol used for transmitting data between two ends of a connection






27. A process involving the extraction of components from existing systems and restructuring these components to develop new systems or to enhance the efficiency of existing systems. Existing software systems thus can be modernized to prolong their funct






28. Files maintained by a system; primarily a database management system; for the purposed of reapplying changes following an error or outage recovery






29. The rate of transmission for telecommunication data. It is expressed in bits per second (bps).






30. A layer within the International Organization for Standardization (ISO)/Open Systems Interconnection (OSI) model. It is used in information transfers between users through application programs and other devices. In this layer various protocols are ne






31. Used to electronically scan and input written information from a source document






32. Programs and supporting documentation that enable and facilitate use of the computer. Software controls the operation of the hardware.






33. Any technique designed to provide the electronic equivalent of a handwritten signature to demonstrate the origin and integrity of specific data. Digital signatures are an example of electronic signatures.






34. An individual using a terminal; PC or an application can access a network to send an unstructured message to another individual or group of people.






35. A phone number that represents the area in which the communications provider or Internet service provider (ISP) provides service






36. An edit check designed to ensure the data in a particular field is numeric






37. An empowering method/process by which management and staff of all levels collectively identify and evaluate IS related risks and controls under the guidance of a facilitator who could be an IS auditor. The IS auditor can utilise CRSA for gathering re






38. A network monitoring and data acquisition tool that performs filter translation; packet acquisition and packet display






39. With respect to security; a special type of virus that does not attach itself to programs; but rather spreads via other methods such as e-mail (also see virus)






40. Transactions that cannot be denied after the fact






41. A document distributed to software vendors requesting them to submit a proposal to develop or provide a software product






42. A report on Internal Control--An Integrated Framework sponsored by the Committee of Sponsoring Organizations of the Treadway Commission in 1992. It provides guidance and a comprehensive framework of internal control for all organizations.'






43. An extension to PPP to facilitate the creation of VPNs. L2TP merges the best features of PPTP (from Microsoft) and L2F (from Cisco).






44. System flowcharts are graphical representations of the sequence of operations in an information system or program. Information system flowcharts show how data from source documents flow through the computer to final distribution to users. Symbols use






45. Any intentional violation of the security policy of a system






46. Software packages that sequentially dial telephone numbers; recording any numbers that answer






47. An entity (department; cost center; division or other group) responsible for entering and maintaining budget data.






48. The computer room and support areas






49. The consolidation in 1998 of the ''Cadbury;'' ''Greenbury'' and ''Hampel'' Reports. Named after the Committee Chairs; these reports were sponsored by the UK Financial Reporting Council; the London Stock Exchange; the Confederation of British Industry






50. Audit evidence is relevant if it pertains to the audit objectives and has a logical relationship to the findings and conclusions it is used to support.