Security Auditing, Monitoring, and Digital
Forensics Overview Exam Questions and
Answers with Verified Solutions | Latest
Updated 2026
What is the purpose of a security To evaluate a computer system's
audit? operations against
security goals and avoid data breaches.
What are the two types of audit Manual and automated.
tests?
What is the first step in Define how the system is supposed to
determining if work.
a system has worked as intended?
What does monitoring in security Reviewing and measuring all controls to
auditing involve? capture
actions and changes in the environment.
What is the role of security To address and mitigate risks associated
controls with
in risk management? security policies.
What should a security policy Acceptable and unacceptable actions
define? within the
organization.
, What are the four permission Promiscuous, Permissive, Prudent,
levels Paranoid.
in security policies?
What is the purpose of conducting To ensure appropriate security levels,
security audits? correct
installation of controls, and effectiveness of
controls.
How do security audits affect Consistent auditing increases trust, making
customer confidence? customers more willing to share sensitive
information.
What are the three levels of SOC SOC 1, SOC 2, SOC 3.
reports?
What is an audit plan? A document that defines objectives,
systems to
review, and areas of assurance to check.
What is included in defining the Surveying sites, reviewing documentation,
scope of an audit plan? and
checking logs.
What is a benchmark in auditing? The standard to which a system is
compared to
determine secure configuration.
Name one auditing benchmark. ISO 27002.
Forensics Overview Exam Questions and
Answers with Verified Solutions | Latest
Updated 2026
What is the purpose of a security To evaluate a computer system's
audit? operations against
security goals and avoid data breaches.
What are the two types of audit Manual and automated.
tests?
What is the first step in Define how the system is supposed to
determining if work.
a system has worked as intended?
What does monitoring in security Reviewing and measuring all controls to
auditing involve? capture
actions and changes in the environment.
What is the role of security To address and mitigate risks associated
controls with
in risk management? security policies.
What should a security policy Acceptable and unacceptable actions
define? within the
organization.
, What are the four permission Promiscuous, Permissive, Prudent,
levels Paranoid.
in security policies?
What is the purpose of conducting To ensure appropriate security levels,
security audits? correct
installation of controls, and effectiveness of
controls.
How do security audits affect Consistent auditing increases trust, making
customer confidence? customers more willing to share sensitive
information.
What are the three levels of SOC SOC 1, SOC 2, SOC 3.
reports?
What is an audit plan? A document that defines objectives,
systems to
review, and areas of assurance to check.
What is included in defining the Surveying sites, reviewing documentation,
scope of an audit plan? and
checking logs.
What is a benchmark in auditing? The standard to which a system is
compared to
determine secure configuration.
Name one auditing benchmark. ISO 27002.