Courseiva

CCNA Assessment And Audit Questions

32 questions · Assessment And Audit · All types, answers revealed

1
MCQeasy

What is the primary function of an assessor's 'working papers'?

A.To list the audit team members
B.To document evidence and support the findings
C.To submit to the regulator
D.To replace the need for an audit
AnswerB

They provide traceability for audit conclusions.

Why this answer

Working papers document the evidence gathered, testing performed, and observations made, which serve as the foundation for the final assessment report.

2
MCQhard

During an audit of an IAM system, the auditor notices that inactive accounts are not being disabled. Which control is failing?

A.Audit log retention
B.Account management lifecycle
C.Role-based access control
D.Multi-factor authentication
AnswerB

Lifecycle includes onboarding, maintenance, and offboarding/disabling.

Why this answer

Disabled account management is a critical detective and preventive control to ensure that only authorized, active users have access.

3
Multi-Selecteasy

Which THREE activities are part of the 'Assessment Execution' phase?

Select 3 answers
A.Developing the final risk strategy
B.Purchasing new hardware
C.Reviewing system documentation
D.Testing system configuration
E.Interviewing key personnel
AnswersC, D, E

Method of assessment.

Why this answer

Execution involves interviewing staff, reviewing documentation, and testing technical configuration settings.

4
Multi-Selectmedium

Which THREE types of findings might appear in an audit report?

Select 3 answers
A.Employee performance pay
B.Operational observations
C.Documentation deficiencies
D.Critical vulnerabilities
E.Office furniture inventory
AnswersB, C, D

Informational findings.

Why this answer

Findings range from critical (immediate risk), to moderate (needs attention), to minor (observational), all of which appear in the report.

5
Multi-Selectmedium

Which TWO factors contribute to the 'scope' of an information security audit?

Select 2 answers
A.External stock prices
B.Competitor market analysis
C.Network boundaries
D.Employee home addresses
E.System components and assets
AnswersC, E

Defines where the audit stops.

Why this answer

The audit scope is driven by the physical and logical boundaries of the system being reviewed.

6
MCQmedium

You are auditing a backup solution. Which metric is most critical for the Availability audit?

A.Encryption key rotation
B.Tape rotation schedule
C.Backup storage capacity
D.Recovery Time Objective (RTO)
AnswerD

RTO measures availability requirements.

Why this answer

Recovery Time Objective (RTO) dictates how quickly a system must be available after an outage, which is the primary metric for availability testing.

7
MCQhard

You are assessing an organization's compliance with SOC 2. The auditor requests evidence of 'Trust Services Criteria'. Which evidence is most relevant for the Availability criterion?

A.Privacy policy publication
B.Encryption of data at rest
C.Disaster recovery plan test results
D.User access review logs
AnswerC

DR tests demonstrate that systems can be recovered.

Why this answer

Availability requires that systems be available for operation as agreed. Business continuity and disaster recovery testing provide evidence of this.

8
MCQmedium

When conducting an audit, what is 'sampling'?

A.Randomly selecting records without criteria
B.Testing only the most recent data
C.Testing every single record in a database
D.Selecting a representative subset for testing
AnswerD

Sampling makes auditing scalable.

Why this answer

Sampling is the process of selecting a subset of data (e.g., user accounts) to represent the entire population to make an inference about the effectiveness of a control.

9
MCQhard

Which technique is best to detect 'false negatives' during a security control assessment?

A.Reviewing security log correlation
B.Interviewing developers
C.Checking server physical locks
D.Single tool vulnerability scanning
AnswerA

Cross-log analysis reveals missed threats.

Why this answer

Correlation of logs from multiple sources (e.g., firewall, IPS, host logs) allows an auditor to see if a threat was missed by a single control.

10
MCQhard

During an assessment, you identify that an organization is not logging administrative access. What is the most appropriate recommendation in the final report?

A.Increase complexity of passwords
B.Change the audit team
C.Configure audit logging for administrative actions
D.Remove administrative access
AnswerC

This addresses the specific control gap.

Why this answer

A clear, actionable recommendation would be to implement and configure centralized logging (like Syslog or SIEM) for all administrative accounts.

11
Multi-Selectmedium

Which TWO methods are commonly used to gather assessment evidence?

Select 2 answers
A.Budget approval
B.Marketing collateral review
C.Interview
D.Observation
E.System retirement
AnswersC, D

Gathering expert input.

Why this answer

Assessment methods commonly include observing processes and interviewing personnel to understand implementation.

12
Multi-Selecteasy

Which TWO types of controls are specifically examined during an audit?

Select 2 answers
A.Physical building aesthetics
B.HR hiring policies
C.Administrative controls
D.Technical controls
E.Marketing controls
AnswersC, D

Verified via documentation review.

Why this answer

Audits assess both technical controls (logical) and administrative controls (policies/procedures).

13
Multi-Selecthard

Which THREE actions are essential for maintaining 'integrity' of audit evidence?

Select 3 answers
A.Publishing evidence to the company website
B.Chain of custody documentation
C.Use of cryptographic hashes for log files
D.Printing all evidence on paper
E.Restricting access to the audit evidence folder
AnswersB, C, E

Proves the evidence hasn't been altered.

Why this answer

Evidence must be protected from unauthorized changes, be verifiable, and be stored securely to maintain its chain of custody.

14
Multi-Selecthard

Which THREE items are critical when verifying an organization's Compliance with NIST SP 800-53?

Select 3 answers
A.System Security Plan (SSP)
B.Annual report of stock performance
C.Security Assessment Report (SAR)
D.Internal marketing strategy
E.POA&M
AnswersA, C, E

Baseline requirement.

Why this answer

NIST compliance requires a review of the SSP, the assessment of the controls, and the documentation of any deficiencies in a POA&M.

15
MCQeasy

A security auditor needs to verify that the principle of least privilege is applied to a Linux server. Which audit activity is most appropriate?

A.Running a Nessus vulnerability scan
B.Verifying user account permissions and group assignments
C.Checking for physical server room access
D.Reviewing system logs for failed login attempts
AnswerB

This directly maps access to roles.

Why this answer

Reviewing /etc/passwd and /etc/group files and comparing user permissions against assigned roles is a direct method to verify least privilege.

16
Multi-Selectmedium

Which THREE roles are typically involved in a security assessment?

Select 3 answers
A.Customer support agents
B.External public relations firm
C.Assessor / Auditor
D.Chief Information Security Officer (CISO)
E.System Owner
AnswersC, D, E

Performs the evaluation.

Why this answer

The assessor (auditor), the system owner (responsible party), and the security officer (compliance expert) are key participants.

17
Multi-Selecthard

Which TWO elements are required to be included in a Plan of Action and Milestones (POA&M)?

Select 2 answers
A.Target completion date
B.Personnel salary data
C.Historical audit logs
D.Description of the vulnerability
E.Software licensing keys
AnswersA, D

The 'Milestones' part of POA&M.

Why this answer

A POA&M must define the vulnerability/weakness and the specific milestone/date for remediation.

18
MCQmedium

You are performing a gap analysis. What is the correct order of operations for a professional assessment?

A.Current state, Target state, Gap identification
B.Gap identification, Target state, Current state
C.Current state, Gap identification, Target state
D.Target state, Current state, Gap identification
AnswerD

The target must be established before measuring the current state.

Why this answer

You must define the target (what good looks like), determine the current state (as-is), and then identify the delta (gap).

19
MCQmedium

You are preparing a NIST SP 800-53A security control assessment. Which methodology step is performed immediately after the 'Prepare for Assessment' phase?

A.Analyze Security Assessment Results
B.Develop the Plan of Action and Milestones (POA&M)
C.Assess Security Controls
D.Authorize the Information System
AnswerC

The assessment phase follows preparation.

Why this answer

According to NIST SP 800-53A, the assessment process is a linear flow where the 'Prepare for Assessment' phase leads directly into the 'Assess Security Controls' phase to execute the test procedures.

20
MCQhard

An organization is moving to a cloud-native infrastructure. What is the most significant change in the assessment of 'inherited' controls?

A.POA&M is prohibited for cloud providers
B.Greater reliance on third-party audit reports
C.Physical security is no longer assessed
D.Manual testing is mandated for all controls
AnswerB

The assessor relies on the provider's third-party attestations.

Why this answer

In a cloud environment, the provider manages the physical and infrastructure controls (inherited), meaning the assessor focuses on verifying the provider's attestations (like SOC 2 reports).

21
MCQeasy

Which document defines the specific security controls that an organization must implement based on its risk assessment?

A.Incident Response Plan
B.Risk Management Plan
C.Security Assessment Report (SAR)
D.System Security Plan (SSP)
AnswerD

The SSP identifies applied controls.

Why this answer

The System Security Plan (SSP) describes the system and the controls that have been selected (tailored) to meet security requirements.

22
MCQeasy

What is the purpose of a 'pre-assessment' meeting?

A.To set expectations and coordinate logistics
B.To conduct penetration testing
C.To finalize the POA&M
D.To perform hardware inventory
AnswerA

Logistics are vital for assessment success.

Why this answer

A pre-assessment or kickoff meeting ensures alignment on scope, timeline, logistics, and points of contact between the auditor and the client.

23
MCQeasy

Which type of audit is performed by an internal department to assess the effectiveness of security controls without external pressure?

A.Third-party assessment
B.Penetration test
C.Self-assessment
D.Regulatory inspection
AnswerC

Self-assessments are internal exercises.

Why this answer

Internal audits are conducted by the organization's own staff to improve internal processes and compliance before formal external audits occur.

24
MCQeasy

Which document serves as the primary agreement between an assessor and the target organization outlining the scope of an audit?

A.Interconnection Security Agreement
B.Rules of Engagement
C.Security Assessment Plan
D.Risk Assessment Report
E.System Security Plan
AnswerB

ROE serves as the governance agreement.

Why this answer

The Rules of Engagement (ROE) define the boundaries, scope, and procedures for an assessment, ensuring both parties understand the limitations.

25
MCQmedium

When an assessment report indicates a 'High' risk finding, what is the primary responsibility of the system owner regarding the POA&M?

A.Delete the finding from the report
B.Transfer the risk to the IT staff
C.Update the POA&M with a remediation plan
D.Accept the risk without documentation
AnswerC

High findings require immediate planning and tracking.

Why this answer

The system owner is responsible for prioritizing the remediation of high-risk items and ensuring the POA&M reflects the timeline and resource allocation for fixing them.

26
Multi-Selecteasy

Which TWO of the following are primary components of an effective security control assessment report?

Select 2 answers
A.Detailed Findings and Supporting Evidence
B.Executive Summary
C.Employee performance reviews
D.List of all vendor contracts
E.Company financial statements
AnswersA, B

This is a standard section.

Why this answer

An assessment report must detail the findings/weaknesses and the evidence that supports those findings.

27
MCQmedium

During a control assessment, you use the 'examine, interview, and test' methods. Which of these is classified as an 'objective' evidence gathering technique?

A.Reviewing policies
B.Interviewing the IT manager
C.Observing physical access
D.Testing technical controls
AnswerD

Testing provides verifiable technical evidence.

Why this answer

Testing is considered objective because it involves hands-on verification of a system's configuration or behavior, rather than relying on subjective human input (interview).

28
MCQeasy

What is the primary goal of the 'Assessment Reporting' phase?

A.To terminate the contract
B.To communicate findings to stakeholders
C.To select new security controls
D.To patch all identified vulnerabilities
AnswerB

Reporting is the communication phase.

Why this answer

Reporting provides stakeholders with an accurate picture of the security posture, identified risks, and the evidence supporting the findings.

29
MCQmedium

When conducting an assessment using the SCAP protocol, what is the primary purpose of the OVAL component?

A.To provide a language for checking system configuration state
B.To standardize the transfer of vulnerability data
C.To define the severity of a vulnerability
D.To manage the lifecycle of a POA&M
AnswerA

OVAL defines checks to identify configuration issues.

Why this answer

OVAL (Open Vulnerability and Assessment Language) is used to verify the state of a system's security configuration, such as registry keys or file permissions.

30
MCQhard

During a FedRAMP audit, you discover that a customer's cloud environment does not meet a required control. What is the mandatory next step to track this non-compliance?

A.Document the weakness in a Plan of Action and Milestones (POA&M)
B.Immediately terminate the cloud service
C.Perform a penetration test
D.Request a waiver from the JAB
E.Update the System Security Plan (SSP) to reflect compliance
AnswerA

POA&M is the standard artifact for tracking identified gaps.

Why this answer

FedRAMP requires that all open vulnerabilities and control weaknesses identified during an assessment be documented in a POA&M for tracking and remediation.

31
MCQmedium

Which standard provides the framework for conducting information security audits?

A.ISO/IEC 27007
B.NIST SP 800-37
C.PCI DSS
D.ISO/IEC 27001
AnswerA

This is the specific standard for ISMS auditing.

Why this answer

ISO/IEC 27007 provides guidance on managing an information security management system (ISMS) audit program.

32
MCQhard

You are assessing a system for compliance with FIPS 140-3. Which evidence provides the strongest validation?

A.CMVP validation certificate
B.Manufacturer's technical specification document
C.Internal configuration audit report
D.Email from the vendor
AnswerA

This is the industry standard for proof of compliance.

Why this answer

A NIST Cryptographic Module Validation Program (CMVP) certificate provides formal verification that a product has met the FIPS 140 requirements.

Ready to test yourself?

Try a timed practice session using only Assessment And Audit questions.