Question 1
An auditor identifies business objectives, critical systems, and related threats before selecting audit procedures. Which approach is being used?
Show answer & explanation
Correct answer: B - Risk-based auditing
10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.
The C)CSSA exam has 100 questions and runs 2 hours.
These 10 free C)CSSA questions are organized by exam domain, so you can see how each part of the Certified Cybersecurity Systems Auditor blueprint is tested. Reveal the answer and explanation under each question.
An auditor identifies business objectives, critical systems, and related threats before selecting audit procedures. Which approach is being used?
Correct answer: B - Risk-based auditing
An audit finding states that a control weakness could expose sensitive information assets. What is the auditor's most appropriate action?
Correct answer: A - Document evidence, assess impact, and report the finding
IT projects are selected without considering business goals or available resources. Which governance area has a weakness?
Correct answer: B - Strategic planning and alignment
A risk exposure formula is likelihood multiplied by impact. A vulnerability has likelihood 4 and impact 5. Scores above 15 require priority remediation. What should the auditor conclude?
Correct answer: B - The score is 20 and requires priority remediation
An auditor reviews a new application before deployment. Which area should be examined to determine whether controls were incorporated during creation?
Correct answer: A - System acquisition, development, and implementation
An application accepts unexpected input that could alter database commands. Which control area requires review?
Correct answer: A - Input validation controls
Firewall changes are made directly in production without approval records. What is the primary concern?
Correct answer: A - Unauthorized access from uncontrolled configuration changes
A company maintains backups but has never tested restoration. What is the auditor's main concern?
Correct answer: A - Recovery capability has not been demonstrated
Employees have access permissions beyond their job responsibilities. Which security principle is violated?
Correct answer: A - Least privilege
An organization encrypts sensitive data but stores encryption keys with the same administrators who manage the data. What should the auditor evaluate?
Correct answer: A - Key management practices
The full bank has 1,020 more C)CSSA questions with explanations.
Continue in the free practice test →
View plans