TechNuggets Academy

Information Technology and Security

Free Certified in Risk and Information Systems Control practice — 6 questions on Information Technology and Security, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Domain 4: Information Technology and Security
A financial institution's core trading platform has a mandated Recovery Point Objective (RPO) of 15 minutes and Recovery Time Objective (RTO) of 4 hours. The risk practitioner is reviewing the current backup strategy, which consists of a full backup every Sunday night and incremental backups every 24 hours. Which change to the strategy is required to meet the stated RPO?
RPO defines the maximum tolerable amount of data loss measured in time. A 15-minute RPO means the maximum data loss window between the last recoverable copy and the point of failure cannot exceed 15 minutes. Only continuous replication or near-real-time log shipping can achieve this; any batch-based backup, no matter how frequent, leaves a data-loss gap larger than the interval between jobs plus processing time.
Question 2 of 6 · Domain 4: Information Technology and Security
Using the TOGAF Architecture Development Method as a reference, a risk practitioner is assessing which enterprise architecture domain documents the portfolio of applications, their interdependencies, and their mapping to core business processes, in order to identify concentration risk from a single point of application failure.
Application architecture in TOGAF describes the individual application systems, their logical grouping, interactions, and relationships to core business processes. This is the layer a risk practitioner reviews to identify single points of failure or concentration risk among interdependent applications supporting a business function.
Question 3 of 6 · Domain 4: Information Technology and Security
A risk practitioner is advising a development team adopting a shift-left security approach for a new customer-facing application. At which phase of the system development life cycle should security requirements first be formally defined and embedded to minimize the cost and risk associated with rework?
The shift-left principle, and general SDLC risk economics, hold that defects and control gaps found earlier in the life cycle are exponentially cheaper to remediate than those found later. Security requirements should be elicited and embedded during requirements gathering and design, alongside functional requirements, so that architecture and code are built to satisfy them from the outset.
Question 4 of 6 · Domain 4: Information Technology and Security
Employees at a professional services firm are pasting excerpts of confidential client contracts into a public generative AI chatbot to get quick summaries, creating risk of unauthorized data disclosure to a third-party AI provider. Which response BEST reduces this risk while preserving the productivity benefit employees are seeking?
The risk driver is uncontrolled use of public AI tools (shadow AI) with sensitive data. The most effective and proportionate response combines a technical control — an enterprise AI gateway or approved enterprise AI service with DLP/content inspection to prevent sensitive data from leaving the organization's boundary — with an administrative control (updated policy and targeted training) that channels the underlying business need into a governed alternative, rather than simply prohibiting it.
Question 5 of 6 · Domain 4: Information Technology and Security
A regulation requires an organization to retain financial transaction records for 7 years, but analytics shows the records are actively queried by the business only during the first 90 days after creation. From a risk and cost standpoint, which data lifecycle management approach is MOST appropriate?
A defensible data lifecycle strategy balances regulatory retention obligations, cost, and business access needs. Tiered storage — hot storage while actively accessed, then migration to lower-cost archive tiers for the remainder of the mandated retention period, followed by defensible destruction — satisfies the 7-year regulatory requirement at the lowest reasonable cost while meeting the actual access pattern.
Question 6 of 6 · Domain 4: Information Technology and Security
An internal audit finding notes that the same employee in the treasury department can both initiate a wire transfer request and approve it for release, with no independent second approver involved. Which control principle has been violated?
Segregation of duties (SoD) requires that no single individual have end-to-end control over a critical or sensitive transaction, such as both initiating and approving a wire transfer, so that fraud or error would require collusion between at least two people. The finding describes a classic SoD violation in a financial process.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →