ARM 400 TEST PAPER CORRECT QUESTIONS AND
ANSWERS SURE A+
✔✔Internal data entry processes that capture accounting transactions, customer data or
other operational transactions are called
A. Data capture.
B. Data quality.
C. Data integration.
D. Data governance. - ✔✔A
✔✔Which one of the following provides the frame of reference needed so data can be
used appropriately for analysis and decision-making?
A. Metadata
B. Data lineage
C. Data custodian
D. Data virtualization - ✔✔A
✔✔Under the General Data Protection Regulation (GDPR), a data controller's role is to
A. Represent the business aspects of data governance.
B. Define the metrics used to measure an organization's overall data quality.
C. Define how and for what purpose personal data should be processed.
D. Manage the flow of data for the rest of the organization. - ✔✔C
,✔✔Encrypting data to block its use if stolen is an example of a
A. Software-based security solution.
B. Cyber-threat inventory approach.
C. Incident response plan.
D. Hardware-based security solution. - ✔✔A
✔✔Data governance provides
A. Definitions, standards and procedures for how data is used.
B. The internal data entry processes needed to capture accounting transactions.
C. A road map that details where data is located.
D. A dynamic view of data without needing to move it between systems. - ✔✔A
✔✔In terms of data quality principles, validity is defined as
A. The accuracy of data within predefined and accepted parameters or values.
B. The process of tracing data from its source to its destination.
C. The true value of data relative to the business information being analyzed.
D. The extent that each dataset contains all elements necessary for business needs. -
✔✔A
✔✔Encrypting data is an example of
A. An enterprise risk management program
B. A regulatory compliance program.
C. A data governance program.
D. A data security program. - ✔✔D
✔✔Cyber extortion is another name for
A. Phishing.
B. Bitcoin
C. Ransomware.
D. Social engineering. - ✔✔C
✔✔Donna's Dog Treats has been very successful in the Boston area and would like to
expand to new cities. Donna knows that she cannot make this decision based on
customer advice and blind faith. She has collected internal financial and operational
data as well as external data from reliable sources. Donna has hired an analyst to
review the data quality. The analyst is reviewing the data to see if it includes the
demographics for each target city that Donna is considering. Which one of the following
- ✔✔A
✔✔To gain a competitive advantage, maintain profitability, and satisfy customers an
organization must
A. Be able to trust its data.
B. Pay attention to the marketplace.
C. Adopt current accounting rules.
, D. Have an effective risk management program. - ✔✔A
✔✔Malware is defined as
A. Software designed to cause damage.
B. Software technology used to encrypt data.
C. A hardware-based security breach.
D. A tool for managing data security. - ✔✔A
✔✔Which one of the following is an example of a data governance tool?
A. Metadata
B. Risk Management
C. Data integration
D. External Policy - ✔✔D
✔✔A data governance committee (DGC)
A. Is cross-functional.
B. Cleanses big data.
C. Reports to risk management.
D. Is comprised of IT architects. - ✔✔A
✔✔In accordance with the Three Lines of Defense Model, how does risk management
act as the second line of defense?
A. Risk management alerts internal audit of potential threats within a department and
works with internal audit to neutralize the threat.
B. Risk management supports and monitors operational management's implementation
of risk management practices.
C. Risk management provides oversight to the operational management's assessment
of risk and internal controls.
D. Risk management has aut - ✔✔B
✔✔Which one of the following best describes why many purchasers require an ISO
9001 certification prior to buying a business?
A. To have an outside audit company attest to its conclusive audit.
B. To ensure that internal standards and controls are in place.
C. To transfer liability should the financial statements prove erroneous.
D. To obligate the seller to perform audits for conformance prior to the sale. - ✔✔B
✔✔It is necessary to define functions that should be performed by internal audit rather
than the enterprise risk management (ERM) team because
A. Internal audit and risk managers share responsibilities for governance and
compliance for the organization.
B. ERM is all encompassing and if not controlled will absorb internal audit functions.
C. The Institute of Internal Auditors (IIA) guidelines are used to avoid confusion in an
organization and clarify financial compliance issues.
ANSWERS SURE A+
✔✔Internal data entry processes that capture accounting transactions, customer data or
other operational transactions are called
A. Data capture.
B. Data quality.
C. Data integration.
D. Data governance. - ✔✔A
✔✔Which one of the following provides the frame of reference needed so data can be
used appropriately for analysis and decision-making?
A. Metadata
B. Data lineage
C. Data custodian
D. Data virtualization - ✔✔A
✔✔Under the General Data Protection Regulation (GDPR), a data controller's role is to
A. Represent the business aspects of data governance.
B. Define the metrics used to measure an organization's overall data quality.
C. Define how and for what purpose personal data should be processed.
D. Manage the flow of data for the rest of the organization. - ✔✔C
,✔✔Encrypting data to block its use if stolen is an example of a
A. Software-based security solution.
B. Cyber-threat inventory approach.
C. Incident response plan.
D. Hardware-based security solution. - ✔✔A
✔✔Data governance provides
A. Definitions, standards and procedures for how data is used.
B. The internal data entry processes needed to capture accounting transactions.
C. A road map that details where data is located.
D. A dynamic view of data without needing to move it between systems. - ✔✔A
✔✔In terms of data quality principles, validity is defined as
A. The accuracy of data within predefined and accepted parameters or values.
B. The process of tracing data from its source to its destination.
C. The true value of data relative to the business information being analyzed.
D. The extent that each dataset contains all elements necessary for business needs. -
✔✔A
✔✔Encrypting data is an example of
A. An enterprise risk management program
B. A regulatory compliance program.
C. A data governance program.
D. A data security program. - ✔✔D
✔✔Cyber extortion is another name for
A. Phishing.
B. Bitcoin
C. Ransomware.
D. Social engineering. - ✔✔C
✔✔Donna's Dog Treats has been very successful in the Boston area and would like to
expand to new cities. Donna knows that she cannot make this decision based on
customer advice and blind faith. She has collected internal financial and operational
data as well as external data from reliable sources. Donna has hired an analyst to
review the data quality. The analyst is reviewing the data to see if it includes the
demographics for each target city that Donna is considering. Which one of the following
- ✔✔A
✔✔To gain a competitive advantage, maintain profitability, and satisfy customers an
organization must
A. Be able to trust its data.
B. Pay attention to the marketplace.
C. Adopt current accounting rules.
, D. Have an effective risk management program. - ✔✔A
✔✔Malware is defined as
A. Software designed to cause damage.
B. Software technology used to encrypt data.
C. A hardware-based security breach.
D. A tool for managing data security. - ✔✔A
✔✔Which one of the following is an example of a data governance tool?
A. Metadata
B. Risk Management
C. Data integration
D. External Policy - ✔✔D
✔✔A data governance committee (DGC)
A. Is cross-functional.
B. Cleanses big data.
C. Reports to risk management.
D. Is comprised of IT architects. - ✔✔A
✔✔In accordance with the Three Lines of Defense Model, how does risk management
act as the second line of defense?
A. Risk management alerts internal audit of potential threats within a department and
works with internal audit to neutralize the threat.
B. Risk management supports and monitors operational management's implementation
of risk management practices.
C. Risk management provides oversight to the operational management's assessment
of risk and internal controls.
D. Risk management has aut - ✔✔B
✔✔Which one of the following best describes why many purchasers require an ISO
9001 certification prior to buying a business?
A. To have an outside audit company attest to its conclusive audit.
B. To ensure that internal standards and controls are in place.
C. To transfer liability should the financial statements prove erroneous.
D. To obligate the seller to perform audits for conformance prior to the sale. - ✔✔B
✔✔It is necessary to define functions that should be performed by internal audit rather
than the enterprise risk management (ERM) team because
A. Internal audit and risk managers share responsibilities for governance and
compliance for the organization.
B. ERM is all encompassing and if not controlled will absorb internal audit functions.
C. The Institute of Internal Auditors (IIA) guidelines are used to avoid confusion in an
organization and clarify financial compliance issues.