A senior IS auditor suspects that a PC may have been used to perpetrate fraud in a finance department. The auditor should FIRST report this suspicion to:
When protecting the confidentiality of information assets, the MOST effective control practice is the:
Which of the following concerns is MOST effectively addressed by implementing an IT framework for alignment between IT and business objectives?
Which of the following is the BEST way to ensure that an application is performing according to its specifications?
Which of the following is me GREATE ST impact as a result of the ongoing deterioration of a detective control?
Which of the following poses the GREATEST risk to an organization related to system interfaces?
Which of the following is the PRIMARY reason to follow a configuration management process to maintain application?
Which of the following should be of GREATEST concern to an IS auditor reviewing a network printer disposal process?
Which type of testing is used to identify security vulnerabilities in source code in the development environment?
Which of the following should be an IS auditor ' s PRIMARY focus when auditing the implementation of a new IT operations performance monitoring system?
An IS auditor is reviewing the operational database management of an organization that uses cloud systems for hosting. Which of the following should be the auditor ' s PRIMARY area of focus?
Which of the following is the PRIMARY advantage of using an automated security log monitoring tool instead of conducting a manual review to monitor the use of privileged access?
Which of the following should be of GREATEST concern to an IS auditor who is assessing an organization ' s configuration and release management process?
Which of the following is the MOST important success factor for implementing a data loss prevention (DLP) tool?
At the conclusion of an audit, but before issuing the final report, the auditor should:
What should be the PRIMARY basis for selecting which IS audits to perform in the coming year?
Due to advancements in technology and electronic records, an IS auditor has completed an engagement by email only. Which of the following did the IS auditor potentially compromise?
The implementation of an IT governance framework requires that the board of directors of an organization:
Which of the following would be MOST effective to protect information assets in a data center from theft by a vendor?
Which of the following is the BEST way to determine the adequacy of controls for detecting inappropriate network activity in an organization?
During a review of a production schedule, an IS auditor observes that a staff member is not complying with mandatory operational procedures. The auditor ' s NEXT step should be to:
Which of the following is the PRIMARY reason to involve IS auditors in the software acquisition process?
Which of the following should be the FIRST step m managing the impact of a recently discovered zero-day attack?
Which of the following is MOST effective for controlling visitor access to a data center?
A data breach has occurred due lo malware. Which of the following should be the FIRST course of action?
Which of the following is the MOST appropriate indicator of change management effectiveness?
An organization has established hiring policies and procedures designed specifically to ensure network administrators are well qualified Which type of control is in place?
Which of the following is the PRIMARY concern when negotiating a contract for a hot site?
Which of the following BEST indicates that an incident management process is effective?
An IS auditor is reviewing an organizations release management practices and observes inconsistent and inaccurate estimation of the size and complexity of business application development projects. Which of the following should the auditor recommend to address this issue?
Which of the following physical controls provides the GREATEST assurance that only authorized individuals can access a data center?
An organization has replaced all of the storage devices at its primary data center with new higher-capacity units The replaced devices have been installed at the disaster recovery site to replace older units An IS auditor s PRIMARY concern would be whether
Which of the following is the MOST important course of action to ensure a cloud access security broker (CASB) effectively detects and responds to threats?
An administrator performs firewall configuration changes for a small organization. Which of the following is the BEST compensating control to mitigate the risk of unauthorized changes in this situation?
An organization has an acceptable use policy in place, but users do not formally acknowledge the policy. Which of the following is the MOST significant risk from this finding?
A month after a company purchased and implemented system and performance monitoring software, reports were too large and therefore were not reviewed or acted upon The MOST effective plan of action would be to:
Which of the following represents the GREATEST risk to virtualized environments?
When an intrusion into an organization ' s network is detected, which of the following should be done FIRST?
Which of the following is the MOST important consideration for an IS auditor when assessing the adequacy of an organization ' s information security policy?
An IS auditor discovers that backups of critical systems are not being performed in accordance with the recovery point objective (RPO) established in the business continuity plan (BCP). What should the auditor do NEXT?
Which of the following is the BEST justification for deferring remediation testing until the next audit?
Which of the following is the BEST way to determine whether a test of a disaster recovery plan (DRP) was successful?
An IS auditor is planning an audit of an organization ' s risk management practices. Which of the following would provide the MOST useful information about
risk appetite?
Which of the following is the BEST indication of effective IT investment management?
What is the GREATEST concern for an IS auditor reviewing contracts for licensed software that executes a critical business process?
Which of the following provides the BEST evidence that system requirements are met when evaluating a project before implementation?