ISA 305 Exam 1 Chapter 4 Exam #1 Questions with correct
answers
The Internet is inherently insecure. It was built initially for military purposes over
50 years ago when computer technology was extremely basic and limited.
Another reason why it is insecure is because it is built on TCP/IP which is a
nonproprietary open standard, built for communication and connectivity, not
security. Also, there is no global entity with true governance over the Internet.
Many companies address their Internet security vulnerabilities using the Defense
in Depth approach. This approach involves intentional redundant defense
mechanisms (i.e., multiple firewalls) in order to protect their valuable data from
unauthorized access. This approach is also known as the castle approach because
it is similar to the type of redundant defense mechanisms used to guard a castle
(i.e., massive doors and deep moats). The objective is that even if one of the
defense layers fail, the others will back it up and keep o - ✔✔Chapter 4 Sample
Short Answer/Essay Questions: The Internet (with a capital I) is inherently
_______! Explain why.
Why and how does a typical organization address security vulnerabilities using the
concept of defend-in-depth (DiD)? (e.g., is the redundancy "bad?")
Accounting Information System - ✔✔_________ ___________ ________ collects,
processes, stores, and reports accounting information.
1. IT General Controls (ITGCs)
2. Application Controls - ✔✔What are the 2 major types of internal controls for
computer-based systems?
,Entity Level (Aka Management control system) - ✔✔What is the highest level of
controls in the typical organizational IT Controls hierarchy?
Entity - ✔✔Having an IT Audit Function is a __________ level control.
General - ✔✔_________ controls apply overall to the IT systems.
Application - ✔✔__________ controls used to control inputs, processing, and
output.
1. Authentication of users and limiting unauthorized access
2. Hacking and other Network Break-ins
3. Organizational Structure
4. Physical Environment and Physical Security of the system
5. Business Continuity/DRP - ✔✔What are the 5 categories of IT General
Controls?
Unauthenticated - ✔✔If access is unauthorized, then by default it is
____________.
Authentication - ✔✔___________ comes before authorization.
, know; have; are - ✔✔Factors of Authentication can be something you ________,
something you ___________ and/or something you _______.
Multi-Factor Authentication - ✔✔What is the use of more than one factors of
authentication called?
Because they have the opposite effect than that what was intended - ✔✔Why are
passwords sometimes called Contra-Security?
Information Security Objectives - ✔✔What does the CIAANA represent?
Confidentiality
Information Integrity
Authentication
Systems Availability
Nonrepudiation
Authorization - ✔✔What does the CIAANA mnemonic stand for?
The AICPA Trust Principles - ✔✔What does the SAPiOpC mnemonic represent?
Security
Availability
Processing Integrity
Online Privacy
answers
The Internet is inherently insecure. It was built initially for military purposes over
50 years ago when computer technology was extremely basic and limited.
Another reason why it is insecure is because it is built on TCP/IP which is a
nonproprietary open standard, built for communication and connectivity, not
security. Also, there is no global entity with true governance over the Internet.
Many companies address their Internet security vulnerabilities using the Defense
in Depth approach. This approach involves intentional redundant defense
mechanisms (i.e., multiple firewalls) in order to protect their valuable data from
unauthorized access. This approach is also known as the castle approach because
it is similar to the type of redundant defense mechanisms used to guard a castle
(i.e., massive doors and deep moats). The objective is that even if one of the
defense layers fail, the others will back it up and keep o - ✔✔Chapter 4 Sample
Short Answer/Essay Questions: The Internet (with a capital I) is inherently
_______! Explain why.
Why and how does a typical organization address security vulnerabilities using the
concept of defend-in-depth (DiD)? (e.g., is the redundancy "bad?")
Accounting Information System - ✔✔_________ ___________ ________ collects,
processes, stores, and reports accounting information.
1. IT General Controls (ITGCs)
2. Application Controls - ✔✔What are the 2 major types of internal controls for
computer-based systems?
,Entity Level (Aka Management control system) - ✔✔What is the highest level of
controls in the typical organizational IT Controls hierarchy?
Entity - ✔✔Having an IT Audit Function is a __________ level control.
General - ✔✔_________ controls apply overall to the IT systems.
Application - ✔✔__________ controls used to control inputs, processing, and
output.
1. Authentication of users and limiting unauthorized access
2. Hacking and other Network Break-ins
3. Organizational Structure
4. Physical Environment and Physical Security of the system
5. Business Continuity/DRP - ✔✔What are the 5 categories of IT General
Controls?
Unauthenticated - ✔✔If access is unauthorized, then by default it is
____________.
Authentication - ✔✔___________ comes before authorization.
, know; have; are - ✔✔Factors of Authentication can be something you ________,
something you ___________ and/or something you _______.
Multi-Factor Authentication - ✔✔What is the use of more than one factors of
authentication called?
Because they have the opposite effect than that what was intended - ✔✔Why are
passwords sometimes called Contra-Security?
Information Security Objectives - ✔✔What does the CIAANA represent?
Confidentiality
Information Integrity
Authentication
Systems Availability
Nonrepudiation
Authorization - ✔✔What does the CIAANA mnemonic stand for?
The AICPA Trust Principles - ✔✔What does the SAPiOpC mnemonic represent?
Security
Availability
Processing Integrity
Online Privacy