AFC-CERT Sample Questions

AFC-CERT Sample Questions & Answers

Preventive controls grounded in the COSO framework make up nearly half the test, ahead of assessing and reporting on how well anti-fraud controls actually work, with the smallest share on controls that keep data itself secure.

Launch the full AFC-CERT simulator →

Showing 6 of 12 free samples.

  1. Question 1Beginner

    Internal Controls for Data Security · Current Data Threats

    An organization detects a spear-phishing campaign targeting its accounts payable department. The emails appear to come from the CFO and request urgent wire transfers. This attack vector leverages information likely gathered from:

    Show answer & explanation

    Correct answer: B

    Attackers often use professional social media sites (OSINT) to identify organizational hierarchies, reporting lines (who reports to the CFO), and specific roles (AP clerks). This allows them to craft highly targeted spear-phishing emails (Business Email Compromise) that appear authentic.

  2. Question 2AdvancedSelect 2

    Internal Controls for Data Security · Data Security Risks

    Which of the following are primary components of a comprehensive Data Loss Prevention (DLP) strategy? (Select TWO)

    Show answer & explanation

    Correct answers: B, C

    DLP agents on endpoints (laptops/desktops) monitor and block unauthorized data transfers (e.g., to USB drives or personal email), which is a critical enforcement mechanism.

    You cannot protect what you cannot find or define. Discovering where sensitive data resides and classifying it (e.g., Confidential, Public) is the foundational step of DLP.

  3. Question 3Beginner

    Internal Controls for Data Security · Introduction to Internal Data Controls

    True or False: In a high-security data center, biometric access controls (such as fingerprint or retina scanners) are considered a 'what you have' authentication factor.

    Show answer & explanation

    Correct answer: B

    Biometrics are classified as 'what you are' (inherent characteristics). 'What you have' refers to physical tokens like smart cards or keys. 'What you know' refers to passwords or PINs.

  4. Question 4Intermediate

    Internal Controls for Data Security · Introduction to Internal Data Controls

    A healthcare organization is decommissioning a server that stored Patient Health Information (PHI). Standard deletion of files is insufficient because data remanence allows recovery. Which method provides the highest level of assurance that data is unrecoverable on the hard drives while allowing the physical drive to be reused if necessary?

    Show answer & explanation

    Correct answer: B

    Crypto-shredding involves encrypting the data and then deliberately destroying the decryption keys. This renders the data unreadable. Unlike physical destruction or degaussing (which render the drive unusable), crypto-shredding allows the hardware to be reused while ensuring data confidentiality.

  5. Question 5Intermediate

    Internal Controls for Data Security · Introduction to Internal Data Controls

    Case Study:

    GlobalTech Solutions has transitioned 40% of its workforce to full-time remote work. Remote employees access the corporate network via VPN. Recently, the security team noticed anomalous traffic patterns originating from the VPN account of a sales director, accessing engineering source code repositories at 3 AM local time. The sales director denies this activity.

    Upon investigation, the security team discovered the sales director's password was 'Sales2024!'. The account did not require a second factor for authentication. The engineering repository contained trade secrets.

    Based on this scenario, which control failure was the PRIMARY enabler of this security breach?

    Show answer & explanation

    Correct answer: B

    While weak passwords are an issue, the primary control failure that enabled the breach was the lack of Multi-Factor Authentication (MFA). Even with a compromised password, MFA would have prevented the attacker from successfully logging into the VPN. This is a critical logical access control for remote access.

  6. Question 6Intermediate

    Internal Controls for Data Security · Data Security Risks

    Behavioral analytics tools are increasingly used to detect insider threats. Which of the following employee behaviors would most likely flag a high-risk event in a User Behavior Analytics (UBA) system?

    Show answer & explanation

    Correct answer: B

    This is a classic 'flight risk' indicator. Employees leaving an organization often attempt to take intellectual property or client lists with them. UBA systems specifically baseline normal data transfer volumes and flag significant deviations, especially when correlated with HR status changes like resignation.

Ready for the real thing?

The full AFC-CERT simulator has every exam-style question, timed mode, and instant scoring.