When reviewing whether IT investments are meeting business objectives, which of the following evaluations would be MOST useful?
An IS auditor is reviewing the service management of an outsourced help desk. Which of the following is the BEST indicator of how effectively the service provider is performing this function?
A steering committee established to oversee an organization’s digital transformation program is MOST likely to be involved with which of the following activities?
What should an IS auditor do FIRST when a follow-up audit reveals some management action plans have not been initiated?
A financial accounting system audit determined that audit logging of transactions had been disabled by a finance employee. The IS auditor recommended that finance personnel no longer have the capability to change audit logging settings. Which of the following is MOST important to verify during the follow-up?
An organization has implemented a distributed security administration system to replace the previous centralized one. Which of the following presents the GREATEST potential concern?
Which of the following provides the GREATEST assurance that an organization has effective controls preventing connection of unauthorized Internet of Things (IoT) devices to the corporate network?
Which of the following security risks can be reduced by a property configured network firewall?
Which of the following documents should specify roles and responsibilities within an IT audit organization?
An organization has recently moved to an agile model for deploying custom code to its in-house accounting software system. When reviewing the procedures in place for production code deployment, which of the following is the MOST significant security concern to address?
Which of the following should be an IS auditor ' s GREATEST concern when an international organization intends to roll out a global data privacy policy?
Which of the following provides the BEST evidence that a third-party service provider ' s information security controls
are effective?
Which of the following tasks would cause the GREATEST segregation of duties (SoD) concern if performed by the person who reconciles the organization ' s device inventory?
An organization has assigned two now IS auditors to audit a now system implementation. One of the auditors has an IT-related degree, and one has a business degree. Which ol the following is MOST important to meet the IS audit standard for proficiency?
An IS auditor should be MOST concerned if which of the following fire suppression systems is utilized to protect an asset storage closet?
Which of the following should be performed FIRST before key performance indicators (KPIs) can be implemented?
An IS auditor reviewing the system development life cycle (SDLC) finds there is no requirement for business cases. Which of the following should be offGREATEST concern to the organization?
Which of the following controls is the BEST recommendation to prevent the skimming of debit or credit card data in point of sale (POS) systems?
Which of the following is the PRIMARY advantage of parallel processing for a new system implementation?
Which of the following is the BEST approach for determining the overall IT risk appetite of an organization when business units use different methods formanaging IT risks?
Data centers that want to prevent unauthorized personnel from entering during a power outage should ensure external access doors:
An IS auditor is reviewing the disaster recovery plan (DRP) of an organization with offices across multiple regions. Which of the following should be the auditor ' s PRIMARY focus?
An IS auditor found that operations personnel failed to run a script contributing to year-end financial statements. Which of the following is the BEST recommendation?
An IS auditor is reviewing a machine learning model that predicts the likelihood that a user will watch a certain movie. Which of the following would be of GREATEST concern to the auditor?
A job is scheduled to transfer data from a transactional system database to a data lake for reporting purposes. Which of the following would be of GREATEST concern to an IS auditor?
Which of the following BEST describes the role of a document owner when implementing a data classification policy in an organization?
Which of the following BEST describes the concept of fault tolerance in system resiliency?