SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CISA Certified Information Systems Auditor Vocab
Start Test
Study First
Subjects
:
certifications
,
cisa
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. A communications terminal control hardware unit that controls a number of computer terminals. All messages are buffered by the controller and then transmitted to the receiver.
Cluster controller
PPTP (point-to-point tunneling protocol)
Budget organization
Application maintenance review
2. Used to enable remote access to a server computer. Commands typed are run on the remote server.
Trust
Telnet
Terminal
Structured programming
3. Audit evidence is relevant if it pertains to the audit objectives and has a logical relationship to the findings and conclusions it is used to support.
Relevant audit evidence
Address space
Application program
Monetary unit sampling
4. 1)A computer dedicated to servicing requests for resources from other computers on a network. Servers typically run network operating systems. 2)A computer that provides services to another computer (the client).
Scheduling
Tape management system (TMS)
Computer server
System flowcharts
5. A program that translates programming language (source code) into machine executable instructions (object code)
Black box testing
IDS (intrusion detection system)
Diskless workstations
Compiler
6. A device that forwards packets between LAN devices or segments. LANs that use switches are called switched LANs.
Project sponsor
Wide area network (WAN)
HTTPS (hyper text transfer protocol secure)
Switch
7. A recurring journal entry used to allocate revenues or costs. For example; an allocation entry could be defined to allocate costs to each department based on headcount.
ASCII (American Standard Code for Information Interchange)
Allocation entry
Security management
Computationally greedy
8. Techniques and procedures used to verify; validate and edit data; to ensure that only correct data are entered into the computer
Fault tolerance
Machine language
Transaction
Input controls
9. A layer within the International Organization for Standardization (ISO)/Open Systems Interconnection (OSI) model. It is used in information transfers between users through application programs and other devices. In this layer various protocols are ne
Content filtering
Ethernet
Audit
Application layer
10. The amount of time allowed for the recovery of a business function or resource after a disaster occurs
Dumb terminal
Sufficient audit evidence
Peripherals
Recovery time objective (RTO)
11. Computer file storage media not physically connected to the computer; typically tapes or tape cartridges used for backup purposes
Offline files
Librarian
Utility software
Cleartext
12. A high-capacity disk storage device or a computer that stores data centrally for network users and manages access to that data. File servers can be dedicated so that no process other than network management can be executed while the network is availa
Operator console
Availability
Initial program load (IPL)
File server
13. A biometric device that is used to authenticate a user through palm scans
Handprint scanner
Journal entry
Application development review
System testing
14. An engagement where management does not make a written assertion about the effectiveness of their control procedures; and the IS auditor provides an opinion about subject matter directly; such as the effectiveness of the control procedures
Challenge/response token
Active response
Direct reporting engagement
Verification
15. The transmission of job control language (JCL) and batches of transactions from a remote terminal location
Multiplexing
Remote job entry (RJE)
Demodulation
Pervasive IS controls
16. A file format in which records are organized and can be accessed; according to a preestablished key that is part of the record
TCP (transmission control protocol)
Indexed sequential file
Hash function
File layout
17. An electronic form functionally equivalent to cash in order to make and receive payments in cyberbanking
Concurrent access
Request for proposal (RFP)
Controls (Control procedures)
Electronic cash
18. Another term for an application programmer interface (API). It refers to the interfaces that allow programmers to access lower- or higher-level services by providing an intermediary layer that includes function calls to the services.
Coupling
Concurrent access
Middleware
Discovery sampling
19. A display terminal without processing capability. Dumb terminals are dependent upon the main computer for processing. All entered data are accepted without further editing or validation.
Memory dump
Node
Dumb terminal
Foreign exchange risk
20. The current and prospective effect on earnings and capital arising from negative public opinion. This affects the bank's ability to establish new relationships or services or continue servicing existing relationships. Reputation risk may expose the b
Rapid application development
Reputational risk
UNIX
Shell
21. The process of generating; recording and reviewing a chronological record of system events to ascertain their accuracy
Audit
Microwave transmission
Personal identification number (PIN)
Reputational risk
22. A debit or credit to a general ledger account. See also manual journal entry.
Internet Engineering Task Force (IETF)
Content filtering
Noise
Journal entry
23. The Committee on the Financial Aspects of Corporate Governance; set up in May 1991 by the UK Financial Reporting Council; the London Stock Exchange and the UK accountancy profession; was chaired by Sir Adrian Cadbury and produced a report on the subj
DMZ (demilitarized zone)
Combined Code on Corporate Governance
Cadbury
Data dictionary
24. To the basic border firewall; add a host that resides on an untrusted network where the firewall cannot protect it. That host is minimally configured and carefully managed to be as secure as possible. The firewall is configured to require incoming an
Spoofing
Real-time processing
Untrustworthy host
Certificate authority (CA)
25. The portion of a security policy that states the general process that will be performed to accomplish a security goal
Wiretapping
Offsite storage
Operational control
Procedure
26. A fail-over process; which is basically a two-way idle standby: two servers are configured so that both can take over the other node's resource group. Both must have enough CPU power to run both applications with sufficient speed; or performance loss
Prototyping
Table look-ups
Mutual takeover
Logical access controls
27. A testing approach which focuses on the functionality of the application or product and does not require knowledge of the code intervals.
Black box testing
UDDI
Blackbox testing
Substantive testing
28. A version of the Windows operating system that supports preemptive multitasking
Computationally greedy
Windows NT
Control risk self-assessment
COBIT
29. This approach allows IS auditors to monitor system reliability on a continuous basis and to gather selective audit evidence through the computer.
Output analyzer
DMZ (demilitarized zone)
Blackbox testing
Continuous auditing approach
30. A port configured on a network switch to receive copies of traffic from one or more other ports on the switch
Error risk
Bar code
Spanning port
Control risk self-assessment
31. Auxiliary computer hardware equipment used for input; output and data storage. Examples include disk drives and printers.
Comparison program
Untrustworthy host
Procedure
Peripherals
32. Simulated transactions that can be used to test processing logic; computations and controls actually programmed in computer applications. Individual programs or an entire system can be tested. This technique includes Integrated Test Facilities (ITFs)
Request for proposal (RFP)
Test data
Rounding down
Peripherals
33. The structure through which the objectives of an organization are set; and the means of attaining those objectives; and determines monitoring performance guidelines. Good corporate governance should provide proper incentives for board and management
Default password
Static analysis
Corporate governance
Budget formula
34. The process that limits and controls access to resources of a computer system; a logical or physical control designed to protect against unauthorized entry or use. Access control can be defined by the system (mandatory access control; or MAC) or defi
Control weakness
IP (Internet protocol)
Security perimeter
Access control
35. Self-governance and freedom from conflict of interest and undue influence. The IS auditor should be free to make his/her own decisions; not influenced by the organization being audited and its people (managers and employers).
Independence
Electronic cash
Monitoring policy
Accountability
36. Criteria Of Control; published by the Canadian Institute of Chartered Accountants in 1995
COCO
price risk
Audit authority
DMZ (demilitarized zone)
37. A sub-network of the Internet through which information is exchanged by text; graphics; audio and video.
Latency
Reengineering
world wide web (WWW)
Service user
38. A master control program that runs the computer and acts as a scheduler and traffic controller. It is the first program copied into the computer's memory after the computer is turned on and must reside in memory at all times. It is the software that
Peripherals
Electronic data interchange (EDI)
Input controls
Operating system
39. ATM is a high-bandwidth low-delay switching and multiplexing technology. It is a data link layer protocol. This means that it is a protocol-independent transport mechanism. ATM allows integration of real-time voice and video as well as data. ATM allo
E-mail/interpersonal messaging
Integrated test facilities (ITF)
Operating system audit trails
Asynchronous Transfer Mode (ATM)
40. A numbering system that uses a base of 16 and uses 16 digits: 0; 1; 2; 3; 4; 5; 6; 7; 8; 9; A; B; C; D; E and F. Programmers use hexadecimal numbers as a convenient way of representing binary numbers.
Hexadecimal
Object orientation
Downtime report
Independent attitude
41. Defined minimum performance measures at or above which the service delivered is considered acceptable
Service level agreement (SLA)
Memory dump
Indexed sequential access method (ISAM)
Redundancy check
42. A method for downloading public files using the File Transfer Protocol (FTP). Anonymous FTP is called anonymous because users do not need to identify themselves before accessing files from a particular server. In general; users enter the word anonymo
vulnerability
Spoofing
Anonymous File Transfer Protocol (FTP)
Input controls
43. The most important types of operational risk involve breakdowns in internal controls and corporate governance. Such breakdowns can lead to financial losses through error; fraud or failure to perform in a timely manner or cause the interests of the ba
Financial audit
Operational risk
Packet switching
Assembler
44. A communication network that serves several users within a specified geographic area. It is made up of servers; workstations; a network operating system and a communications link. Personal computer LANs function as distributed processing systems in w
Local area network (LAN)
Protocol
Administrative controls
Reverse engineering
45. A workstation or PC on a network that does not have its own disk. Instead; it stores files on a network file server.
Diskless workstations
Subject matter (Area of activity)
Corporate exchange rate
Black box testing
46. A testing technique used to retest earlier program abends or logical errors that occurred during the initial testing phase
Trojan horse
Plaintext
Regression testing
Audit plan
47. A third party that provides organizations with a variety of Internet; and Internet-related services
ISP (Internet service provider)
Compiler
Audit objective
Digital certificate
48. Unusual or statistically rare
Piggy backing
Anomaly
Uploading
Encapsulation (objects)
49. A fully operational offsite data processing facility equipped with both hardware and system software to be used in the event of a disaster
Untrustworthy host
ACK (acknowledgement)
Hot site
Logon
50. The computer room and support areas
Extended Binary-coded Decimal Interchange Code (EBCDIC)
Worm
Information processing facility (IPF)
Internet