Information Systems and Controls ISC Becker Supplemental Course
-
WELCOME. PLEASE START HERE!
1. Welcome to Farhat Lectures -
2. How to Use This Course & Resources
-
3. Choosing the Right CPA Discipline
-
4. CPA Exam Study Tips & Common Questions
-
🚀Introduce Yourself1 Topic
-
🚨🚨🚨2026 AICPA Released Questions1 Topic
-
ISC1 : M1 : National Institute of Standards and Technology Frameworks📖NIST Cybersecurity Framework: Govern Function 12 Topics|1 Quiz
-
📖NIST Cybersecurity Framework Identify Function 22 Topics|1 Quiz
-
📖NIST Cybersecurity Framework Protect Function 32 Topics|1 Quiz
-
📖NIST Cybersecurity Framework Detect Function 42 Topics|1 Quiz
-
📖NIST Cybersecurity Framework Respond Function 52 Topics|1 Quiz
-
📖NIST Cybersecurity Framework Recover Function 62 Topics|1 Quiz
-
📖NIST Cybersecurity Framework Profile2 Topics|1 Quiz
-
📖NIST: 4 Tiers2 Topics|1 Quiz
-
📖NIST Privacy Framework2 Topics|1 Quiz
-
📖NIST SP 800-532 Topics|1 Quiz
-
🚨🚨HOW TO SOLVE SIMULATIONS (TUTORIAL + VIDEO EXAMPLES)✅ CPA Exam Simulation Tutorial + 2024 and 2025 AICPA Video Questions.5 Topics|2 Quizzes
-
ISC1 : M2 : Privacy and Data Security Standards📖Intro to Data Privacy laws and Data breaches4 Topics|1 Quiz
-
📖Health Insurance Portability and Accountability Act (HIPAA)2 Topics|1 Quiz
-
📖PCIDSS2 Topics|1 Quiz
-
📖GDPR2 Topics|1 Quiz
-
ISC1 : M3 : Center for Internet Security Critical Security Controls: Part 1📖Intro to Center for Internet Security and Implementation Groups 1, 2 and 34 Topics|1 Quiz
-
📖Center for Internet Security (CIS) 1 to 96 Topics|1 Quiz
-
ISC1 : M4 : Center for Internet Security Critical Security Controls: Part 2📖CIS Controls 10 to 122 Topics
-
📖CIS Controls 13 to 152 Topics
-
📖CIS Controls 16 to 182 Topics
-
ISC1 : M5 : COBIT 2019 Framework📖The 6 principles of COBIT2 Topics
-
📖COBIT 7 Information Criteria2 Topics|2 Quizzes
-
ISC2 : M1 : IT Infrastructure📖IT Architectures: operating systems, servers etc.2 Topics|1 Quiz
-
📖Introduction to Cloud Computing2 Topics
-
📖Cloud Computing Deployment, Risks and Benefits2 Topics|1 Quiz
-
🎯AICPA Questions: Cloud Computing1 Quiz
-
📖Role and responsibilities of cloud service providers2 Topics|1 Quiz
-
📖How COSO Frameworks Address Cloud Computing Governance2 Topics|1 Quiz
-
ISC2 : M2 : Enterprise and Accounting Information Systems📖Enterprise Resource Planning / ERP Architecture4 Topics|1 Quiz
-
🎯AICPA Questions: Enterprise and Accounting Information Systems1 Quiz
-
📖Introduction to Accounting Information System (Business Cycles)2 Topics
-
📖Revenue Cycle2 Topics|1 Quiz
-
📖Expenditure Cycle2 Topics|1 Quiz
-
📖Payroll and H/R cycle2 Topics|1 Quiz
-
📖Manufacturing/production Cycle2 Topics|1 Quiz
-
📖Financing, Reporting and General Ledger Cycle2 Topics
-
📖Shared Services, Outsourcing & Offshoring2 Topics|1 Quiz
-
ISC2 : M3 : Availability, Resiliency, and Disaster Recovery📖Introduction to Business Resiliency2 Topics|1 Quiz
-
📖Business Resiliency Crisis Management2 Topics|1 Quiz
-
📖Business Resiliency: Disaster Recovery Plan DRP2 Topics|1 Quiz
-
📖Business Resiliency System Controls2 Topics|1 Quiz
-
🎯AICPA Questions: Business Continuity Plan1 Quiz
-
ISC2 : M4 : Change Management📖Change Management and Process of Change Management2 Topics|1 Quiz
-
🎯AICPA Questions: Change Management1 Quiz
-
📖Risks and Mitigations to Change Management2 Topics
-
📖System Development Life Cycle (SDLC)2 Topics|1 Quiz
-
📖Waterfall and Agile Methodology2 Topics|1 Quiz
-
📖Purpose Of Testing Change Management2 Topics|1 Quiz
-
📖Software System Testing2 Topics|1 Quiz
-
ISC2: M5: INTRODUCTION TO DATA COLLECTION & THE DATA LIFE CYCLE📖Data Life Cycle2 Topics|1 Quiz
-
ISC2: M6: DATA STORAGE & DATABASE DESIGN📖Database Systems2 Topics|1 Quiz
-
📖Flat Files Vs Structured Data2 Topics|1 Quiz
-
📖Business Intelligence Tools For Databases2 Topics|1 Quiz
-
📖Primary & Foreign Key3 Topics|1 Quiz
-
🎯AICPA Previously Released Questions1 Quiz
-
ISC2: M7: DATA EXTRACTION, INTEGRATION, & PROCESS DOCUMENTATION📖Data Definition Language: Create & Alter2 Topics
-
📖Data Definition Language: Drop, Truncate, Rename2 Topics
-
📖Data Manipulation Language: Insert, Update & Delete2 Topics
-
📖Data Control Language: Grant & Revoke2 Topics
-
📖Transaction Control Language: Commit Rollback & Save Point2 Topics|1 Quiz
-
📖1 To 1 Relationship In SQL Database2 Topics
-
📖1 To Many Relationship In SQL Database2 Topics
-
📖Many To Many Relationship In SQL Databasse2 Topics|1 Quiz
-
📖Business Process Modeling Notation2 Topics
-
📖Data Normalization8 Topics|1 Quiz
-
ISC3: M1: THREATS & ATTACKS📖Cyber Security2 Topics|1 Quiz
-
📖Threat Actors2 Topics|1 Quiz
-
📖Network Based Attacks2 Topics|1 Quiz
-
📖Host Based Attacked2 Topics|1 Quiz
-
📖Malware Attacks2 Topics|1 Quiz
-
📖Social Engineering Attacks2 Topics|1 Quiz
-
📖Application Based Attacks2 Topics|1 Quiz
-
📖Phishing Attacks2 Topics|1 Quiz
-
📖Physical Attacks2 Topics|1 Quiz
-
📖Supply Chain Attacks2 Topics|1 Quiz
-
📖Stages Of Cyber Attacks2 Topics|1 Quiz
-
📖Risks Related To Cloud Computing2 Topics|1 Quiz
-
📖Risks Related To Mobile Technology2 Topics|1 Quiz
-
📖Risks Related To Internet Of Things2 Topics|1 Quiz
-
📖Threat Modeling2 Topics|1 Quiz
-
ISC3: M2: MITIGATION OF THREATS & ATTACKS📖COSO & Cybersecurity2 Topics|1 Quiz
-
📖ERM: Cybersecurity2 Topics
-
📖Security Policies (Cybersecurity)2 Topics|1 Quiz
-
📖Security Policies: Acceptable Use Policies2 Topics|1 Quiz
-
📖Bring Your Own Device Policies2 Topics|1 Quiz
-
📖Network Components2 Topics|1 Quiz
-
📖Network Security2 Topics|1 Quiz
-
📖Authorization & Authentication2 Topics|1 Quiz
-
📖Identification & Authentication2 Topics|1 Quiz
-
📖Vulnerability Management2 Topics|1 Quiz
-
📖Vulnerability Scanning2 Topics|1 Quiz
-
📖Defense In Depth2 Topics
-
📖Redundancy & Diversification2 Topics
-
📖Preventive Controls2 Topics
-
📖Access Controls2 Topics|1 Quiz
-
📖Detective Controls2 Topics|1 Quiz
-
📖Corrective Controls2 Topics|1 Quiz
-
ISC3: M3: SECURITY TESTING📖Risk Management Framework2 Topics
-
📖Security Assessment Reports2 Topics|1 Quiz
-
📖Security Assessment Evaluators, Process & Evidence2 Topics|1 Quiz
-
📖Security Awareness2 Topics|1 Quiz
-
📖Evaluating Security Awareness2 Topics|1 Quiz
-
ISC3: M4: CONFIDENTIALITY & PRIVACY📖Confidentiality & Privacy2 Topics|1 Quiz
-
📖Protecting Confidential Data2 Topics|1 Quiz
-
📖Data Obfuscation SDLC2 Topics|1 Quiz
-
📖Data Encryption2 Topics
-
📖Hashing & Cipher Techniques2 Topics
-
📖Data Loss Prevention2 Topics|1 Quiz
-
📖Data At Rest & Data Deletion2 Topics
-
📖Walkthrough Of Org. Security, Confidentiality & Privacy2 Topics|1 Quiz
-
📖SOC 2 Engagement2 Topics|1 Quiz
-
ISC3: M5: INCIDENT RESPONSE📖Incident Respond Plan2 Topics|1 Quiz
-
📖Incident Response Plan (IRP): People2 Topics|1 Quiz
-
📖Events & Incidents2 Topics
-
📖7 Steps Responding To An Incident2 Topics|1 Quiz
-
📖Test IRP2 Topics|1 Quiz
-
📖Cyber Insurance2 Topics|1 Quiz
-
ISC4: M1: SOC ENGAGEMENT CATEGORIES & TYPES📖SOC 1, 2 & 32 Topics
-
📖Type 1 & Type 2 Opinion2 Topics|1 Quiz
-
📖Trust Service Criteria2 Topics
-
📖Attestation Engagements ISC2 Topics
-
📖COSO & TSC2 Topics|1 Quiz
-
📖TSC Additional Criteria2 Topics|1 Quiz
-
ISC4: M2: REPORTING ON SOC ENGAGEMENTS: PART 1📖Service Organization Control (SOC) Engagement2 Topics|1 Quiz
-
📖Unqualified Opinion2 Topics
-
📖Types Of Opinion In A SOC Engagement2 Topics|1 Quiz
-
📖Description Of SOC 12 Topics|1 Quiz
-
📖Description Of SOC 22 Topics|1 Quiz
-
📖Description Of Cybersecurity2 Topics
-
📖Management Assertions In A SOC Engagement2 Topics|1 Quiz
-
📖SOC 1 Type 1 Report2 Topics
-
📖SOC 1 Type 2 Report2 Topics
-
📖SOC 2 Type 2 Report2 Topics
-
ISC4: M3: REPORTING ON SOC ENGAGEMENTS: PART 2📖Carve-Out & Include Method2 Topics|1 Quiz
-
📖CUECs2 Topics|1 Quiz
-
📖SOC Reports: Complementary Subservice & User Controls2 Topics
-
📖SOC Reports: Qualified Or Adverse2 Topics
-
📖SOC Reports: Qualified Or Disclaimer2 Topics
-
ISC4: M4: PLANNING & RISK ASSESSMENT IN A SOC ENGAGEMENT📖SOC 1 Management Responsibilities2 Topics
-
📖SOC 2 Management Responsibilities2 Topics|1 Quiz
-
📖Service Auditor’s Responsibilities2 Topics|1 Quiz
-
📖Independence & SOC Engagements2 Topics|1 Quiz
-
📖Materiality In SOC Engagement2 Topics|1 Quiz
-
📖System Requirements2 Topics
-
📖Service Commitments2 Topics|1 Quiz
-
📖SOC Risk Assessment2 Topics|1 Quiz
-
ISC4: M5: PERFORMING SOC ENGAGEMENTS📖SOC Engagement: Response To The Assessed Level Of Risk2 Topics|1 Quiz
-
📖SOC Description 12 Topics|1 Quiz
-
📖SOC Description 22 Topics|1 Quiz
-
📖Control Design2 Topics
-
📖Test Of Effectiveness2 Topics
-
📖Evaluate The Procedures2 Topics|1 Quiz
-
📖Subsequent Events In A SOC Engagement2 Topics|1 Quiz
-
📖Presentation Letter (SOC Engagement)2 Topics|1 Quiz
Participants 2344
Instructions on how to complete the quiz
- Click on “Start Quiz” to start.
- “Check” to submit your answer and reveal the solution.
- “Skip Question” to skip the question for now.
- “Review” to mark question for review later.
- “Feedback” to inquire about the question or provide us your feedback.
- Please make sure to reference the number of the question in your inquiry such as # 4
- Quiz Summary” to finish/submit the whole quiz
Quiz Summary
0 of 10 Questions completed
Questions:
Information
You have already completed the quiz before. Hence you can not start it again.
Quiz is loading…
You must sign in or sign up to start the quiz.
You must first complete the following:
Results
Results
0 of 10 Questions answered correctly
Your time:
Time has elapsed
You have reached 0 of 0 point(s), (0)
Earned Point(s): 0 of 0, (0)
0 Essay(s) Pending (Possible Point(s): 0)
| Average score |
|
| Your score |
|
Categories
- Not categorized 0%
- Review / Skip
- Answered
- Correct
- Incorrect
-
Question 1 of 10
1. Question
A financial services firm observes its database server sending an unusually high volume of data at 3:00 AM, far exceeding normal baseline levels for that time. This anomalous activity triggers an internal alert.
CorrectIncorrect -
Question 2 of 10
2. Question
A large retail company’s security team is receiving a series of minor security alerts from various systems. Which approach best ensures these related events are recognized as a potential attack?
CorrectIncorrect -
Question 3 of 10
3. Question
An international bank receives threat intelligence reports containing new Indicators of Compromise (IoCs) – such as malicious IP addresses, domain names, and file hashes – associated with a cyber-attack campaign targeting financial institutions. The bank wants to leverage this information to strengthen its security monitoring. According to the NIST CSF “Detect” function, how should the bank use these IoCs?
CorrectIncorrect -
Question 4 of 10
4. Question
A tech company suspects that after an employee fell for a phishing email, an attacker has obtained the employee’s credentials and is now attempting lateral movement within the corporate network. The attacker is using the stolen login to try accessing several internal servers that the employee account would not normally use, in an effort to expand their foothold. Which control aligned with the NIST CSF “Detect” function would best help the company identify this lateral movement activity quickly?
CorrectIncorrect -
Question 5 of 10
5. Question
An insurance firm experienced a prolonged malware infection unnoticed for weeks. Which measure best helps identify malware infections promptly in the future?
CorrectIncorrect -
Question 6 of 10
6. Question
A mid-sized manufacturing company wants to shift from reactive to proactive security monitoring. What’s the most appropriate step?
CorrectIncorrect -
Question 7 of 10
7. Question
During an IT audit of a retail company, auditors discover that the organization has deployed several security monitoring tools (an intrusion detection system, a SIEM, etc.), but no formal process or personnel are assigned to review the alerts consistently or to respond to potential security events. In practice, alerts are sometimes ignored or handled ad hoc by whoever notices them. Which aspect of the NIST CSF “Detect” function is lacking at this company, and what improvement is needed?
CorrectIncorrect -
Question 8 of 10
8. Question
A financial technology startup has set up basic security monitoring: they collect logs in a SIEM and have one analyst responsible for watching alerts. However, the team has never tested whether their detection setup truly works against real threats. The CISO is concerned that the team might not recognize or properly handle a sophisticated attack, since they’ve only dealt with benign alerts so far. What practice related to the NIST CSF “Detect” function should the company implement to gain confidence that its detection capabilities work as intended?
CorrectIncorrect -
Question 9 of 10
9. Question
A multinational corporation is expanding its security monitoring capabilities by logging more user activities and network traffic across all its regional offices. However, the Chief Privacy Officer warns that in some countries, data privacy laws restrict how user data can be monitored or stored. When enhancing detection capabilities in line with the NIST CSF “Detect” function, what must the corporation ensure?
CorrectIncorrect -
Question 10 of 10
10. Question
A logistics company suffered a cyber incident where an attacker managed to breach a system undetected. The security team eventually discovered the attack when an employee noticed files being transferred abnormally, not because of an automated alert. Upon investigation, they found that the attacker’s activities did not trigger the existing detection rules, exposing a gap in their monitoring setup. After containing the incident, management wants to improve the company’s detection capabilities. What should the company do, in alignment with the NIST CSF “Detect” function, to learn from this incident and strengthen its future detection?
CorrectIncorrect
Responses