SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CISA Certified Information Systems Auditor Vocab
Start Test
Study First
Subjects
:
certifications
,
cisa
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. A mathematical key (kept secret by the holder) used to create digital signatures and; depending upon the algorithm; to decrypt messages or files encrypted (for confidentiality) with the corresponding public key
Adjusting period
Distributed data processing network
Private key
File server
2. The risk that activities will include deliberate circumvention of controls with the intent to conceal the perpetuation of irregularities. The unauthorized use of assets or services and abetting or helping to conceal.
Batch control
Risk
Screening routers
Fraud risk
3. A file format in which records are organized and can be accessed; according to a preestablished key that is part of the record
Program flowcharts
Distributed data processing network
Indexed sequential file
Star topology
4. A set of communications protocols that encompasses media access; packet transport; session communications; file transfer; electronic mail; terminal emulation; remote file access and network management. TCP/IP provides the basis for the Internet.
Synchronous transmission
Operating system audit trails
TCP/IP protocol (Transmission Control Protocol/Internet Protocol)
Repudiation
5. The process of actually entering transactions into computerized or manual files. Such transactions might immediately update the master files or may result in memo posting; in which the transactions are accumulated over a period of time; then applied
Intranet
Decentralization
Posting
Computer-assisted audit technique (CAATs)
6. Electronic communications by special devices over distances or around devices that preclude direct interpersonal exchange
Telecommunications
Appearance
Audit expert systems
Librarian
7. A condition in which each of an organization's regional locations maintains its own financial and operational data while sharing processing with an organizationwide; centralized database. This permits easy sharing of data while maintaining a certain
Split data systems
Manual journal entry
Backup
Parallel simulation
8. (remote authentication dial-in user service)
Compliance testing
Central processing unit (CPU)
RADIUS
Evidence
9. A row or record consisting of a set of attribute value pairs (column or field) in a relational data structure
Tuple
Control group
External router
Hot site
10. An interactive online system capability that immediately updates computer files when transactions are initiated through a terminal
Real-time processing
e-commerce
Token
Network administrator
11. Any situation or event that has the potential to harm a system
Anonymity
Recovery point objective (RPO)—
Threat
Third-party review
12. The main memory of the computer's central processing unit
Internal storage
DDoS (distributed denial-of-service) attack
Brouters
Switch
13. A phone number that represents the area in which the communications provider or Internet service provider (ISP) provides service
Downtime report
Point-of-presence (POP)
Information processing facility (IPF)
Components (as in component-based development)
14. Techniques and procedures used to verify; validate and edit data; to ensure that only correct data are entered into the computer
Input controls
Preventive controls
Arithmetic-logic unit (ALU)
Test data
15. Freedom from unauthorized intrusion
Privacy
Data communications
X.500
Residual risk
16. The process of taking an unencrypted message (plaintext); applying a mathematical function to it (encryption algorithm with a key) and producing an encrypted message (ciphertext)
Default deny policy
Sufficient audit evidence
Variable sampling
Encryption
17. Interface between data terminal equipment and data communications equipment employing serial binary data interchange
Buffer
Audit objective
RS-232 interface
Asynchronous Transfer Mode (ATM)
18. A set of protocols that allow systems to communicate information about the state of services on other systems. It is used; for example; in determining whether systems are up; maximum packet sizes on links; whether a destination host/network/port is a
ICMP (internet control message protocol)
End-user computing
Integrated services digital network (ISDN)
Default deny policy
19. Processing is achieved by entering information into the computer via a video display terminal. The computer immediately accepts or rejects the information; as it is entered.
Online data processing
Sampling risk
Cohesion
War dialler
20. Specifies the format of packets and the addressing scheme
Decentralization
Monitoring policy
IP (Internet protocol)
Console log
21. The process of monitoring the events occurring in a computer system or network; detecting signs of security problems
Dial-in access controls
Intrusion detection
RFC (request for comments)
End-user computing
22. An attack strategy in which the attacker intercepts the communications stream between two parts of the victim system and then replaces the traffic between the two components with the intruder's own; eventually assuming control of the communication
Authorization
Man-in-the-middle attack
Topology
Service provider
23. Impartial point of view which allows the IS auditor to act objectively and with fairness
FIN (final)
Independent attitude
Cryptography
Business impact analysis (BIA)
24. Wiring devices that may be inserted into communication links for use with analysis probes; LAN analyzers and intrusion detection security systems
Database administrator (DBA)
Piggy backing
Taps
Coaxial cable
25. A series of steps to complete an audit objective
Audit program
Decision support systems (DSS)
Privacy
Blackbox testing
26. A programmed edit or routine that detects transposition and transcription errors by calculating and checking the check digit
Port
Object Management Group (OMG)
Security policy
Check digit verification (self-checking digit)
27. An exception report is generated by a program that identifies transactions or data that appear to be incorrect. These items may be outside a predetermined range or may not conform to specified criteria.
Virus
Dial-back
Exception reports
liquidity risk
28. An audit technique used to select items from a population for audit testing purposes based on selecting all those items that have certain attributes or characteristics (such as all items over a certain size)
Virtual private network (VPN)
Attribute sampling
Intrusive monitoring
Segregation/separation of duties
29. A stored collection of related data needed by organizations and individuals to meet their information processing and retrieval requirements
Optical scanner
Detective controls
Dumb terminal
Database
30. Any technique designed to provide the electronic equivalent of a handwritten signature to demonstrate the origin and integrity of specific data. Digital signatures are an example of electronic signatures.
Audit expert systems
Electronic signature
Project sponsor
Machine language
31. A project management technique used in the planning and control of system projects
Point-of-presence (POP)
Program evaluation and review technique (PERT)
Mapping
Data diddling
32. An intrusion detection system (IDS) inspects network activity to identify suspicious patterns that may indicate a network or system attack from someone attempting to break into or compromise a system
IDS (intrusion detection system)
Budget
Telnet
Whitebox testing
33. Disconnecting from the computer
Virus
Distributed data processing network
Data Encryption Standard (DES)
Logoff
34. An approach used to plan; design; develop; test and implement an application system or a major modification to an application system. Typical phases include the feasibility study; requirements study; requirements definition; detailed design; programm
Systems development life cycle (SDLC)
Statistical sampling
File
Baud rate
35. A process involving the extraction of components from existing systems and restructuring these components to develop new systems or to enhance the efficiency of existing systems. Existing software systems thus can be modernized to prolong their funct
Business-to-consumer e-commerce (B2C)
Private key cryptosystems
Error risk
Reengineering
36. The number of distinct locations that may be referred to with the machine address. For most binary machines; it is equal to 2n; where n is the number of bits in the machine address.
Remote job entry (RJE)
Sniff
Hardware
Address space
37. A top-down technique of designing programs and systems. It makes programs more readable; more reliable and more easily maintained.
System software
Interface testing
Structured programming
Arithmetic-logic unit (ALU)
38. Record layouts provide information regarding the type of record; its size and the type of data contained in the record. Screen and report layouts describe what information is provided and necessary for input.
Reasonable assurance
Compensating control
Record; screen and report layouts
Private key cryptosystems
39. Controls over the business processes that are supported by the ERP
business process integrity
Utility programs
Trust
price risk
40. A fail-over process in which the primary node owns the resource group. The backup node runs a non-critical application (e.g.; a development or test environment) and takes over the critical resource group but not vice versa.
Check digit verification (self-checking digit)
Extended Binary-coded Decimal Interchange Code (EBCDIC)
Anomaly
Simple fail-over
41. ATM is a high-bandwidth low-delay switching and multiplexing technology. It is a data link layer protocol. This means that it is a protocol-independent transport mechanism. ATM allows integration of real-time voice and video as well as data. ATM allo
Token ring topology
Asynchronous Transfer Mode (ATM)
Discovery sampling
Internal penetrators
42. A sub-network of the Internet through which information is exchanged by text; graphics; audio and video.
Financial audit
world wide web (WWW)
Operating system audit trails
Information engineering
43. The act of transferring computerized information from one computer to another computer
Source documents
Decision support systems (DSS)
Downloading
Compensating control
44. The application of audit procedures to less than 100 percent of the items within a population to obtain audit evidence about a particular characteristic of the population
Scure socket layer (SSL)
Analog
Fail-over
Audit sampling
45. Systems that employ sufficient hardware and software assurance measures to allow their use for processing of a range of sensitive or classified information
Due professional care
Trusted systems
Internal storage
System narratives
46. A web-based version of the traditional phone book's yellow and white pages enabling businesses to be publicly listed in promoting greater e-commerce activities.
Topology
Universal Description; Discovery and Integration (UDDI)
Queue
Salami technique
47. Glass fibers that transmit binary signals over a telecommunications network. Fiber optic systems have low transmission losses as compared to twisted-pair cables. They do not radiate energy or conduct electricity. They are free from corruption and lig
Brute force
Rulebase
Table look-ups
Fiber optic cable
48. Is the risk to earnings or capital arising from a bank's inability to meet its obligations when they come due; without incurring unacceptable losses. Internet banking may increase deposit volatility from customers who maintain accounts solely on the
Application proxy
Bulk data transfer
Centralized data processing
liquidity risk
49. A flag set in a packet to indicate that this packet is the final data packet of the transmission
RFC (request for comments)
Blackbox testing
Sniff
FIN (final)
50. Self-governance and freedom from conflict of interest and undue influence. The IS auditor should be free to make his/her own decisions; not influenced by the organization being audited and its people (managers and employers).
Backup
RADIUS
Downtime report
Independence