🇺🇸 Certified Internal Auditor (CIA) · flashcards
Certified Internal Auditor (CIA) Business Acumen and Information Technology (Part 3) Flashcards
51 question-and-answer cards covering Business Acumen and Information Technology (Part 3) as it is examined in Certified Internal Auditor (CIA). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.
24 sample cards from the Business Acumen and Information Technology (Part 3) deck
Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.
In Kotter's 8-step change model, what is the first step?
Establishing a sense of urgency to motivate stakeholders and overcome complacency about the need for change.
What are the three stages of Lewin's change management model?
Unfreeze (prepare for change), Change/Move (implement the transition), and Refreeze (institutionalize and stabilize the new state).
What is the purpose of IT governance?
To ensure IT investments support business objectives, manage IT-related risks, and deliver value, while aligning IT with organizational strategy.
What does the COBIT framework provide?
A framework for IT governance and management that aligns IT with business goals, covering governance and management objectives, processes, and control practices.
What is ITIL and what does it focus on?
ITIL (Information Technology Infrastructure Library) is a framework of best practices for IT service management (ITSM), focusing on delivering and supporting IT services aligned with business needs.
What is the difference between IT governance and IT management?
IT governance sets direction, evaluates options, and monitors performance (board/executive responsibility); IT management plans, builds, runs, and monitors operations to execute that direction.
What three properties make up the CIA triad of information security?
Confidentiality (preventing unauthorized disclosure), Integrity (ensuring accuracy and preventing unauthorized modification), and Availability (ensuring authorized access when needed).
What is the difference between authentication and authorization?
Authentication verifies who a user is (identity); authorization determines what an authenticated user is permitted to access or do.
What are the three common factors used in multi-factor authentication?
Something you know (password/PIN), something you have (token/phone), and something you are (biometric).
What is the principle of least privilege?
Granting users the minimum access rights necessary to perform their job functions, reducing the risk of misuse or damage.
What is the difference between symmetric and asymmetric encryption?
Symmetric uses a single shared secret key for both encryption and decryption; asymmetric uses a public/private key pair where one key encrypts and the other decrypts.
What is the difference between authentication via a digital signature and encryption?
A digital signature uses the sender's private key to provide authentication, integrity, and non-repudiation; encryption uses the recipient's public key to provide confidentiality.
What is phishing and how does spear phishing differ?
Phishing uses fraudulent mass communications to trick users into revealing data; spear phishing is a targeted attack customized to a specific individual or organization.
What is a distributed denial-of-service (DDoS) attack?
An attack that overwhelms a system or network with traffic from many compromised sources, making services unavailable to legitimate users (attacks availability).
What is the difference between a vulnerability, a threat, and a risk?
A vulnerability is a weakness; a threat is a potential source of harm that could exploit it; risk is the likelihood and impact of a threat exploiting a vulnerability.
What is ransomware?
Malicious software that encrypts a victim's data or locks systems and demands payment (ransom) for restoration of access.
What is the difference between a firewall and an intrusion detection system (IDS)?
A firewall controls and filters network traffic based on rules to block unauthorized access; an IDS monitors traffic to detect and alert on suspicious activity (an IPS also blocks it).
What is the difference between penetration testing and vulnerability scanning?
Vulnerability scanning automatically identifies known weaknesses; penetration testing actively exploits weaknesses to simulate a real attack and assess actual impact.
What primary risks do cloud computing and third-party SaaS introduce?
Data security/privacy loss of control, vendor lock-in, availability/reliance on provider, compliance/jurisdiction issues, and weakened visibility over controls.
What governance risk does artificial intelligence/machine learning introduce that auditors should assess?
Algorithmic bias, lack of transparency/explainability ('black box'), data quality dependence, and accountability for automated decisions.
What are the three general categories of IT application controls?
Input controls (ensure accurate, complete, authorized data entry), processing controls (ensure correct processing), and output controls (ensure accurate, complete distribution of results).
What is the difference between general (IT) controls and application controls?
General controls apply broadly to the IT environment (access, change management, operations); application controls are specific to individual applications/transactions (input, processing, output).
What is the systems development life cycle (SDLC) and its typical phases?
A structured process for developing systems: planning/initiation, analysis (requirements), design, development/coding, testing, implementation, and maintenance.
What is the difference between RTO and RPO in business continuity planning?
Recovery Time Objective (RTO) is the maximum acceptable time to restore a system after disruption; Recovery Point Objective (RPO) is the maximum acceptable amount of data loss measured in time.
What this deck covers
The Business Acumen and Information Technology (Part 3) deck follows the Certified Internal Auditor (CIA) Business Acumen and Information Technology (Part 3) syllabus — 3 chapters and 11 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 17.0 cards per chapter.
Answers are written to be recallable, not just readable — averaging about 159 characters, which is long enough to carry the reasoning and short enough to say out loud.
A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.
Business Acumen and Information Technology (Part 3) flashcards FAQ
How many Business Acumen and Information Technology (Part 3) flashcards are in this Certified Internal Auditor (CIA) deck?
51 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.
Are these Certified Internal Auditor (CIA) flashcards free?
Yes. The preview here is free to read with no signup, and the full 51-card deck is free inside the Examius app.
What do the Business Acumen and Information Technology (Part 3) cards cover?
They follow the Certified Internal Auditor (CIA) Business Acumen and Information Technology (Part 3) syllabus — 3 chapters and 11 topics — so the questions track what is actually examinable.
How should I use these flashcards?
Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.