ECCouncil 712-50 Question Answer
Which of the following provides an audit framework?
Control Objectives for IT (COBIT)
Payment Card Industry-Data Security Standard (PCI-DSS)
International Organization Standard (ISO) 27002
National Institute of Standards and Technology (NIST) SP 800-30
COBIT as an Audit Framework:
COBIT provides a comprehensive framework for governance, management, and audit of IT processes, aligning IT goals with business objectives.
Why This is Correct:
COBIT includes guidelines for auditors to evaluate IT controls and their effectiveness in achieving organizational objectives.
Why Other Options Are Incorrect:
B. PCI-DSS: Focuses on cardholder data security, not a comprehensive audit framework.
C. ISO 27002: Provides best practices for information security but not an audit framework.
D. NIST SP 800-30: Focuses on risk assessments, not audits.
References:
EC-Council references COBIT as the preferred framework for conducting IT governance and audit activities.
TESTED 19 Dec 2025
Copyright © 2014-2025 ACE4Sure. All Rights Reserved