F1 Flashcards

1
Q

Difference between Public and Community?

A

Public does not allow for redundancy and data sharing with industry peers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Who would not be part of the intended audience for NIST SP 800-53?

A

Individuals with marketing and advertising responsibilities

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is NIST SP 800-53?

A

Protects information systems against sophisticated threats.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

When would independence be needed by an auditor for a subservice.

A

When the organizations management used the inclusive method.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

When do service auditors report on subsequent events.

A

Auditors don’t have to perform any procedures after the date of service but must appropriately respond to any subsequently discovered event.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is an SQL injection attack?

A

Application based attack in which an attacker injects malicious SQL code into existing SQL code on a company’s website to gain unauthorized access to a company’s data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a Network based attach>

A

Target the infrastructure of a network including switches, routers, servers, and cabling with the intent to gain unauthorized access or disrupt operations for users.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Supply chain attack?

A

Target the production and distribution of goods within a supply chain so that there are larger disruptions in the normal operations of a company, government, or other entity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Host based attack?

A

Target a single host such as a laptop, mobile device, or a server to disrupt functionality or obtain unauthorized access. SQL injections do not target a single host but rather the website’s database.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What cycle do these fall into voucher, production schedule, receipt, earnings statement?

A

Purchasing and disbursement cycle.
Production cycle.
Revenue cycle.
payroll cycle.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is not a disadvantage of outsourcing?

A

Risk Mitigation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

SOC 1 enagemnt would not focus on?

A

Applicable trust SOC 2 and 3 would.
Also only SOC 2 focuses on effective operations of controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

SQL?

A

Is the most likely used when running queries to retrieve specific subsets within a data when performing data extraction.
JavaScript is more focused on Web programming and a host of other applications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a Software-defined wide-area network (SD-WAN) devices?

A

Networks that are optimized using software that is integrated into the hardware, rather than solely physical connections.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is application network gateway?

A

Resource-intensive devices that inspect packets but do not assign IP addresses to other devices on the same network as their primary function.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a circuit-level gateway?

A

Is a form of firewall that verifies the source of data packets that traverse its network, but its primary purpose is not to share IP addresses with other machines.

17
Q

What is sampling risk?

A

The risk that a sample is not representative of the population.

18
Q

Detection risk?

A

The risk that the service auditor will fail to find material misstatements or deviations that are present.

19
Q

Who uses SOC 1 reports.

A

The independent auditors of the user entity?

20
Q

The trust services categories include:

A

Availability, confidentiality, privacy, processing integrity, and security.

21
Q

Service commitments?

A

Are declarations that may result in specific system requirements.