Information Systems and Controls ISC Gleim Supplemental Course
-
WELCOME. PLEASE START HERE!
1. Welcome to Farhat Lectures -
2. How to Use This Course & Resources
-
3. Choosing the Right CPA Discipline
-
4. CPA Exam Study Tips & Common Questions
-
🚀Introduce Yourself1 Topic
-
🚨🚨🚨2026 AICPA Released Questions1 Topic
-
2. IT Infrastructure📖IT Architectures: operating systems, servers2 Topics|1 Quiz
-
📖Cloud Computing6 Topics|2 Quizzes
-
📖How COSO Frameworks Address Cloud Computing Governance2 Topics|1 Quiz
-
🚨🚨HOW TO SOLVE SIMULATIONS (TUTORIAL + VIDEO EXAMPLES)✅ ISC CPA Exam Simulation Tutorial + 2024 and 2025 AICPA Video Questions. Gleim5 Topics|2 Quizzes
-
3. Accounting Systems and Blockchain📖Enterprise Resource Planning (ERP)4 Topics|1 Quiz
-
4. Information Systems Management📖Introduction to Business Resiliency2 Topics|1 Quiz
-
📖Business Resiliency Crisis Management2 Topics|1 Quiz
-
📖Business Resiliency System Controls2 Topics|1 Quiz
-
📖Business Resiliency: Disaster Recovery Plan DRP2 Topics|1 Quiz
-
📖Change Management and Process of Change Management4 Topics|1 Quiz
-
📖System Development Life Cycle (SDLC)2 Topics|1 Quiz
-
📖Waterfall and Agile Methodology2 Topics
-
📖Purpose of testing change management2 Topics|1 Quiz
-
📖Data Life Cycle2 Topics|1 Quiz
-
🎯AICPA Questions: Business Continuity Plan1 Quiz
-
5. Data Management📖Database Systems2 Topics|1 Quiz
-
📖Flat Files Versus Structured Data2 Topics|1 Quiz
-
📖Business Intelligence Tools for Databases2 Topics|1 Quiz
-
📖Data Life Cycle2 Topics|1 Quiz
-
📖Primary and Foreign Key3 Topics|1 Quiz
-
📖Data Definition language4 Topics
-
📖Data Manipulation & control language4 Topics
-
📖Transaction Control language: Commit Rollback and Save point2 Topics|1 Quiz
-
📖Relationships in SQL Database6 Topics|1 Quiz
-
✏️+🎥One-to-One Relationships in SQL Databases + PPT Slides🟢
-
🎙️1 to 1 Relationship in SQL Database
-
✏️+🎥1 to Many Relationship in SQL Database + PPT Slides🟢
-
🎙️1 to Many Relationship in SQL Database
-
✏️+🎥Many-to-Many Relationships in SQL Databases + PPT Slides🟢
-
🎙️Many to Many Relationship in SQL Database
-
✏️+🎥One-to-One Relationships in SQL Databases + PPT Slides🟢
-
📖Data Normalizaton8 Topics|1 Quiz
-
📖Business Process Modeling Notation2 Topics
-
6. Regulations, Standards, and Frameworks📖Introduction to CIS and Its Design Principles4 Topics|1 Quiz
-
📖The 6 principles of COBIT2 Topics|1 Quiz
-
📖COBIT 7 Information Criteria2 Topics|1 Quiz
-
📖NIST Cybersecurity Framework- Function 1,2&36 Topics|3 Quizzes
-
🎥+✏️NIST Cybersecurity Framework: Govern Function 1🟢
-
🎙️NIST Cybersecurity Framework: Govern Function 1
-
✏️+🎥NIST Cybersecurity Framework Identify Function 2🟢
-
🎙️NIST Cybersecurity Framework Identify Function 2
-
✏️+🎥NIST Cybersecurity Framework Protect Function 3🟢
-
🎙️NIST Cybersecurity Framework Protect Function 3
-
🎥+✏️NIST Cybersecurity Framework: Govern Function 1🟢
-
📖NIST Cybersecurity Framework- Function 4,5&66 Topics|3 Quizzes
-
✏️+🎥NIST Cybersecurity Framework Detect Function 4🟢
-
🎙️NIST Cybersecurity Framework Detect Function 4
-
✏️+🎥NIST Cybersecurity Framework Respond Function 5🟢
-
🎙️NIST Cybersecurity Framework Respond Function 5
-
✏️+🎥NIST Cybersecurity Framework Recover Function 6🟢
-
🎙️NIST Cybersecurity Framework Recover Function 6
-
✏️+🎥NIST Cybersecurity Framework Detect Function 4🟢
-
📖NIST Cybersecurity Framework & tiers4 Topics|2 Quizzes
-
📖NIST Privacy Framework4 Topics|2 Quizzes
-
📖CIS Controls 1 to 3 /4 to 64 Topics
-
📖CIS Controls 7 to 9 /10 to 124 Topics|1 Quiz
-
📖CIS Controls 13 to 15 /16 to 184 Topics
-
📖Introduction to Data Privacy Laws4 Topics|1 Quiz
-
📖Health Insurance Portability and Accountability Act (HIPAA)2 Topics|1 Quiz
-
📖GDPR2 Topics|1 Quiz
-
📖PCIDSS2 Topics|1 Quiz
-
7. Security: Threats and Attacks📖Cyber Security2 Topics|1 Quiz
-
📖Threat Actors2 Topics|1 Quiz
-
📖Network & Host Based Attacks4 Topics|2 Quizzes
-
📖Malware Attacks2 Topics|1 Quiz
-
📖Social Engineering Attacks2 Topics|1 Quiz
-
📖Application Based Attacks2 Topics|1 Quiz
-
📖Phishing Attacks1 Topic|1 Quiz
-
📖Physical Attacks2 Topics|1 Quiz
-
📖Supply Chain Attacks2 Topics|1 Quiz
-
📖Stages of Cyber Attacks2 Topics|1 Quiz
-
📖Risks Related to Cloud Computing2 Topics|1 Quiz
-
📖Risks Related to Mobile Technology & Internet of Things4 Topics|2 Quizzes
-
📖Threat Modeling2 Topics|1 Quiz
-
8. Mitigation and Testing: 8.1: Mitigation Concepts📖Security Policies (Cybersecurity)4 Topics|2 Quizzes
-
📖Bring your own Device Policies2 Topics|1 Quiz
-
📖Network Components & Security4 Topics|2 Quizzes
-
📖Authorization, Identification and Authentication4 Topics|2 Quizzes
-
📖Vulnerability Management & Scanning4 Topics|2 Quizzes
-
📖Defense in Depth2 Topics
-
📖Redundancy and Diversification2 Topics
-
📖COSO and Cybersecurity2 Topics
-
📖ERM: Cybersecurity2 Topics|1 Quiz
-
📖Mitigation Cyber Risks8 Topics|3 Quizzes
-
📖Risk Management Framework2 Topics
-
📖Security Assessment Reports2 Topics|1 Quiz
-
📖Security Assessment Evaluators, Process and evidence2 Topics|1 Quiz
-
📖Security Awareness4 Topics|2 Quizzes
-
9. Confidentiality and Privacy📖Confidentiality and Privacy2 Topics|1 Quiz
-
📖Protecting Confidential Data2 Topics|1 Quiz
-
📖Data Obfuscation & Encryption4 Topics|1 Quiz
-
📖Hashing and Cipher Techniques2 Topics
-
📖Data Loss Prevention2 Topics|1 Quiz
-
📖Data at rest and Data Deletion2 Topics
-
📖WalkThrough of Org. Security, Confidentiality and Privacy2 Topics|1 Quiz
-
📖SOC 2 Engagement2 Topics|1 Quiz
-
Study Unit 10: Incident Response📖Incident Respond Plan2 Topics|1 Quiz
-
📖Incident Response Plan (IRP): People4 Topics|1 Quiz
-
📖7 Steps Responding to an Incident2 Topics|1 Quiz
-
📖Cyber Insurance2 Topics|1 Quiz
-
📖Test IRP2 Topics|1 Quiz
-
📖Introduction to Accounting Information System (Business Cycles)2 Topics
-
📖Revenue & Expenditure Cycle4 Topics|2 Quizzes
-
📖Payroll and H/R cycle2 Topics|1 Quiz
-
📖Manufacturing/production Cycle2 Topics|1 Quiz
-
📖Financing, Reporting and General Ledger Cycle2 Topics
-
📖Shared Services, Outsourcing & Offshoring2 Topics|1 Quiz
-
11. Nature of SOC 1, SOC 2, and SOC 3 Engagements📖SOC 1, 2 and 32 Topics
-
📖Type 1 and Type 2 Opinion2 Topics|1 Quiz
-
📖Trust Services Criteria2 Topics
-
📖Attestation Engagements ISC2 Topics
-
📖COSO and TSC4 Topics|2 Quizzes
-
📖SOC 1 & 2 :Management Responsibilities4 Topics|1 Quiz
-
📖Service Auditor’s Responsibilities2 Topics|1 Quiz
-
📖Independence and SOC Engagement2 Topics|1 Quiz
-
📖Materiality in SOC Engagement2 Topics|1 Quiz
-
📖System Requirements2 Topics
-
📖Service Commitments2 Topics|1 Quiz
-
📖SOC Risk Assessment2 Topics|1 Quiz
-
13 & 14: SOC 1 and SOC 2 engagements📖Unqualified Opinion2 Topics
-
📖Types of Opinion in a SOC Engagement2 Topics|1 Quiz
-
📖Description of SOC 1 & 24 Topics|2 Quizzes
-
📖Descrtion of Cybersecurity2 Topics
-
📖Management Assertions in a SOC Engagement2 Topics
-
📖SOC 1 Type 1 & 2 Report4 Topics
-
📖SOC 2 Type 2 Report2 Topics
-
📖Carve-out and Include Method2 Topics|1 Quiz
-
📖CUECs2 Topics|1 Quiz
-
📖SOC Reports6 Topics
-
📖SOC Engagement: Response to the Assessed Level of Risk2 Topics|1 Quiz
-
📖SOC Description 1 & 24 Topics|2 Quizzes
-
📖Control Design2 Topics
-
📖Test of Effectiveness2 Topics
-
📖Evaluate the Procedures2 Topics|1 Quiz
-
📖Subsequent Events in a SOC Engagement2 Topics|1 Quiz
-
📖Representation Letter (SOC Engagement)2 Topics|1 Quiz
Participants 2340
Instructions on how to complete the quiz:
- Click on “Start Quiz” to start.
- “Check” to submit your answer and reveal the solution.
- “Skip Question” to skip the question for now.
- “Review” to mark question for review later.
- “Feedback” to inquire about the question or provide us your feedback.
- Please make sure to reference the number of the question in your inquiry such as # 4
- “Quiz Summary” to finish/submit the whole quiz.
Quiz Summary
0 of 6 Questions completed
Questions:
Information
You have already completed the quiz before. Hence you can not start it again.
Quiz is loading…
You must sign in or sign up to start the quiz.
You must first complete the following:
Results
Results
0 of 6 Questions answered correctly
Your time:
Time has elapsed
You have reached 0 of 0 point(s), (0)
Earned Point(s): 0 of 0, (0)
0 Essay(s) Pending (Possible Point(s): 0)
| Average score |
|
| Your score |
|
Categories
- Not categorized 0%
- Review / Skip
- Answered
- Correct
- Incorrect
-
Question 1 of 6
1. Question
Which of the following is a common risk in outsourcing IT change management?
CorrectIncorrect -
Question 2 of 6
2. Question
What is the best way to manage technical risks in IT change management?
CorrectIncorrect -
Question 3 of 6
3. Question
What is the best way to manage user adoption risks in IT change management?
CorrectIncorrect -
Question 4 of 6
4. Question
What is the best way to manage security risks in IT change management?
CorrectIncorrect -
Question 5 of 6
5. Question
What is the best way to manage compliance risks in IT change management?
CorrectIncorrect -
Question 6 of 6
6. Question
What is the best way to manage quality risks in IT change management?
CorrectIncorrect
Responses
You must be logged in to post a comment.
QUIZ 154 OF 177 (Becker BEC), “System Development Life Cycle”: i’m a bit confused. In the SDLC, “Testing” follows “Implementation”; however, this seems to suggest the contrary ¯\_(ツ)_/¯ Is there any clarity you can offer? NBD if not
Sorry… this is with regard to Question 2.
Hello Evan,
Let’s clarify the relationship between testing and implementation in the System Development Life Cycle (SDLC).
In the traditional SDLC model, testing typically follows implementation. This means that after the software or system has been developed (implementation), it undergoes testing to ensure that it meets the specified requirements, functions as intended, and is free of errors or bugs. This is a standard practice to catch any issues that may have arisen during the development process.
Now, let’s address why “Conduct thorough testing and validation before implementation” is considered correct:
Identification of Issues Early: Conducting testing before implementation allows for the early identification and resolution of potential technical issues. This can include bugs, system crashes, data corruption, or incompatibility with other software.
Risk Mitigation: By identifying and addressing issues before implementation, the organization can mitigate the risk of deploying faulty or problematic systems into a live environment. This helps ensure a smoother transition to the new system.
Cost Savings: Fixing issues post-implementation can be more costly and time-consuming. Thorough testing before implementation can save resources by preventing the need for extensive post-implementation troubleshooting and fixes.
In summary, while testing traditionally follows implementation in the SDLC, the idea behind conducting thorough testing before implementation is to catch and address issues as early as possible in the development process, reducing risks and ensuring a more successful implementation. This approach aligns with the principle of proactive.
Hope this helps
Farhat Lectures support team
Hello Evan,
In the System Development Life Cycle (SDLC), the typical sequence is as follows:
Planning: This is the initial phase where project goals, scope, timelines, and resources are defined.
System Design: In this phase, the system architecture is designed based on the requirements specified in the planning phase.
Implementation: This is where the actual coding and development of the system take place. The designed system is translated into a working system.
Testing: Once the system is developed, it undergoes testing to ensure that it functions according to the requirements. This phase helps identify and fix any bugs or issues.
Deployment (or Installation): The system is deployed to a production environment for end-users.
Maintenance: After deployment, the system requires ongoing maintenance to address any issues, updates, or enhancements.
Can you please specify which question are your referring to under this test bank ?
Farhat Lectures support team