During the walk-through procedures for an upcoming audit, an IS auditor notes that the key application in scope is part of a Software as a Service (SaaS)
agreement. What should the auditor do NEXT?
Which of the following is the MOST appropriate testing approach when auditing a daily data flow between two systems via an automated interface to confirm that it is complete and accurate?
An organization has virtualized its server environment without making any other changes to the network or security infrastructure. Which of the following is the MOST significant risk?
Which of the following BEST supports an organization ' s objective of restricting the use of removable storage devices by users?
Which of the following is the BEST way to mitigate the risk associated with unintentional modifications of complex calculations in end-user computing (EUC)?
In continuous delivery, the critical connector between development and production is:
Which of the following methods would MOST effectively provide positive authentication for physical access?
Which of the following is the BEST methodology to use for estimating the complexity of developing a large business application?
While auditing a small organization ' s data classification processes and procedures, an IS auditor noticed that data is often classified at the incorrect level. What is the MOST effective way for the organization to improve this situation?
While evaluating the data classification process of an organization, an IS auditor ' s PRIMARY focus should be on whether:
An information systems security officer ' s PRIMARY responsibility for business process applications is to:
When reviewing past results of a recurring annual audit, an IS auditor notes that findings may not have been reported and independence may not have been maintained. Which of the following is the auditor ' s BEST course of action?
An organization is implementing a new data loss prevention (DLP) tool. Which of the following will BEST enable the organization to reduce false positive alerts?
Which of the following methods will BEST reduce the risk associated with the transition to a new system using technologies that are not compatible with the old system?
An organization is concerned about duplicate vendor payments on a complex system with a high volume of transactions. Which of the following would be MOST helpful to an IS auditor to determine whether duplicate vendor payments exist?
An organization is planning to implement a work-from-home policy that allows users to work remotely as needed. Which of the following is the BEST solution for ensuring secure remote access to corporate resources?
Which of the following is MOST likely to be a project deliverable of an agile software development methodology?
Which of the following is the BEST detective control for a job scheduling process involving data transmission?
Which of the following is the PRIMARY benefit of adopting an industry-level standard when developing an organization’s cybersecurity program?
Which of the following provides the MOST assurance over the completeness and accuracy ol loan application processing with respect to the implementation of a new system?
Which of the following findings related to segregation of duties should be of GREATEST concern to an IS auditor?
Which of the following approaches BEST enables an IS auditor to detect security vulnerabilities within an application?
Which of the following types of firewalls provide the GREATEST degree of control against hacker intrusion?
Secure code reviews as part of a continuous deployment program are which type of control?
Which of the following would be of GREATEST concern to an IS auditor reviewing the feasibility study for a new application system?
Which of the following controls is MOST important for ensuring the integrity of system interfaces?
An IS auditor learns that an organization ' s business continuity plan (BCP) has not been updated in the last 18 months and that the organization recently closed a production plant. Which of the following is the auditor ' s BEST course of action?
Which of the following would BEST help to ensure that potential security issues are considered by the development team as part of incremental changes to agile-developed software?
A secure server room has a badge reader system that records name, date, and time information whenever a staff member uses a badge to enter or exit. When reviewing the system logs, an IS auditor notices records for some employees entering, but not exiting, the room. Which of the following would be the MOST effective compensating control to recommend?
Which of the following cloud capabilities BEST enables an organization to meet unexpectedly high service demand?
An IS auditor finds that irregularities have occurred and that auditee management has chosen to ignore them. If reporting to external authorities is required which of the following is the BEST action for the IS auditor to take?
Which of the following roles is PRIMARILY responsible for mitigating the risk of benefits not being realized in an IT project?
Which of the following presents the GREATEST risk of data leakage in the cloud environment?
When auditing an organization ' s software acquisition process the BEST way for an IS auditor to understand the software benefits to the organization would be to review the
Which of the following approaches would utilize data analytics to facilitate the testing of a new account creation process?
Which of the following is the BEST evidence that an organization ' s IT strategy is aligned lo its business objectives?
Which of the following would be of GREATEST concern when reviewing an organization ' s security information and event management (SIEM) solution?
An IS auditor wants to gain a better understanding of an organization’s selected IT operating system software. Which of the following would be MOST helpful to review?
Which of the following findings would be of GREATEST concern when reviewing project risk management practices?
Which of the following will provide the GREATEST assurance to IT management that a quality management system (QMS) is effective?
A small organization is experiencing rapid growth and plans to create a new information security policy. Which of the following is MOST relevant to creating the policy?
Which of the following is MOST important for an IS auditor to review when evaluating the accuracy of a spreadsheet that contains several macros?
Which of the following is the GREATEST risk associated with hypervisors in virtual environments?
Which of the following findings should be of GREATEST concern for an IS auditor when auditing the effectiveness of a phishing simu-lation test administered for staff members?
Which of the following provides the BEST evidence of effective IT portfolio managements?
Which of the following analytical methods would be MOST useful when trying to identify groups with similar behavior or characteristics in a large population?