Which of the following staff should an IS auditor interview FIRST to obtain a general overview of the various technologies used across different programs?
Which of the following is the MOST important Issue for an IS auditor to consider with regard to Voice-over IP (VoIP) communications?
Having knowledge in which of the following areas is MOST relevant for an IS auditor reviewing public key infrastructure (PKI)?
The use of which of the following is an inherent risk in the application container infrastructure?
The purpose of a checksum on an amount field in an electronic data interchange (EDI) communication of financial transactions is to ensure:
Which of the following should be used to evaluate an IT development project before an investment is committed?
In which phase of penetration testing would host detection and domain name system (DNS) interrogation be performed?
Which of the following is MOST important for an IS auditor to verify when reviewing the planned use of Benford ' s law as a data analytics technique to detect fraud in a set of credit card transactions?
Following a discussion on the results of a recent audit engagement, the process owner of the audited area has provided an action plan addressing the gaps and recommendations. The auditor disagrees with some of the responses where the process owner is accepting a level of residual risk that is not within the organization ' s risk appetite. What is the auditor ' s BEST course of action?
Which of the following BEST supports the effectiveness of a compliance program?
In an IT organization where many responsibilities are shared which of the following is the BEST control for detecting unauthorized data changes?
An IS audit manager was temporarily tasked with supervising a project manager assigned to the organization ' s payroll application upgrade. Upon returning to the audit department, the audit manager has been asked to perform an audit to validate the implementation of the payroll application. The audit manager is the only one in the audit department with IT project management
experience. What is the BEST course of action?
Which of the following risks is BEST mitigated by implementing an automated three-way match?
Which type of control is being implemented when a biometric access device is installed at the entrance to a facility?
Who should be the FIRST to evaluate an audit report prior to issuing it to the project steering committee?
An IS auditor is reviewing how password resets are performed for users working remotely. Which type of documentation should be requested to understand the detailed steps required for this activity?
When classifying information, it is MOST important to align the classification to:
An IS auditor has been asked to review the integrity of data transfer between two business-critical systems that have not been tested since implementation. Which of the following would provide the MOST useful information to plan an audit?
Which of the following should be GREATEST concern to an IS auditor reviewing data conversion and migration during the implementation of a new application system?
Following an IT audit, management has decided to accept the risk highlighted in the audit report. Which of the following would provide the MOST assurance to the IS auditor that management
is adequately balancing the needs of the business with the need to manage risk?
Which task should an IS auditor complete FIRST during the preliminary planning phase of a database security review?
When selecting a new data loss prevention (DLP) solution, the MOST important consideration is that the solution:
Which of the following is the BEST recommendation to include in an organization ' s bring your own device (BYOD)
policy to help prevent data leakage?
During an IS audit of a data center, it was found that programmers are allowed to make emergency fixes to operational programs. Which of the following should be the IS auditor ' s PRIMARY recommendation?
Which of the following is the MOST important consideration when an organization is performing a business impact analysis (BIA)?
Which of the following should an organization do FIRST when an employee is terminated for fraudulent activity?
Which of the following provides an IS auditor assurance that the interface between a point-of-sale (POS) system and the general ledger is transferring sales data completely and accurately?
Which of the following observations should be of GREATEST concern to an IS auditor assessing access controls for the accounts payable module of a finance system?
Which of the following should be of GREATEST concern to an IS auditor assessing the effectiveness of an organization ' s vulnerability scanning program ' '
During an audit of a financial application, it was determined that many terminated users ' accounts were not disabled. Which of the following should be the IS auditor ' s NEXT step?
In the case of a disaster where the data center is no longer available, which of the following tasks should be done FIRST?
An IS auditor finds that a number of key patches have not been applied in a timely manner due to re-source constraints. Which of the following is the GREATEST risk to the organization in this
situation?
Which of the following should be the GREATEST concern to an IS auditor reviewing an organization ' s method to transport sensitive data between offices?
Which of the following is the BEST sampling method to use when relatively few errors are expected to be found in a population?
Which of the following security measures will reduce the risk of propagation when a cyberattack occurs?
Which of the following documents would be MOST useful in detecting a weakness in segregation of duties?
In an environment where data virtualization is used, which of the following provides the BEST disaster recovery solution?
During a security audit, an IS auditor is tasked with reviewing log entries obtained from an enterprise intrusion prevention system (IPS). Which type of risk would be associated with the potential for the auditor to miss a sequence of logged events that could indicate an error in the IPS configuration?
Which of the following should be the GREATEST concern for an IS auditor reviewing recent disaster recovery operations?
Which of the following is the MOST effective way to detect as many abnormalities as possible during an IS audit?
The due date of an audit project is approaching, and the audit manager has determined that only 60% of the audit has been completed. Which of the following should the audit manager do FIRST?
Which of the following is MOST useful when planning to audit an organization ' s compliance with cybersecurity regulations in foreign countries?
Which type of attack targets security vulnerabilities in web applications to gain access to data sets?
Who is PRIMARILY responsible for the design of IT controls to meet control objectives?