During the planning stage of a compliance audit, an IS auditor discovers that a bank ' s inventory of compliance requirements does not include recent regulatory changes related to managing data risk. What should the auditor do FIRST?
Which of the following controls would BEST help a forensic investigator prevent modifications in digital evidence?
Which of the following is MOST useful for determining the strategy for IT portfolio management?
Which of the following should an IS auditor consider the MOST significant risk associated with a new health records system that replaces a legacy system?
Which of the following is the MOST effective control to mitigate against the risk of inappropriate activity by employees?
During a routine internal software licensing review, an IS auditor discovers instances where employees shared license keys to critical pieces of business software. Which of the following would be the auditor ' s BEST course of action?
Which of the following is MOST appropriate to review when determining if the work completed on an IT project is in alignment with budgeted costs?
Which of the following management decisions presents the GREATEST risk associated with data leakage?
Which of the following presents the GREATEST risk to an organization ' s ability to manage quality control (QC) processes?
Due to system limitations, segregation of duties (SoD) cannot be enforced in an accounts payable system. Which of the following is the IS auditor ' s BEST recommendation for a compensating control?
An IS auditor extracts data from a travel and expenses system to determine whether employees are using the organization’s car for personal use. What type of audit is being performed?
Which of the following is the MOST likely root cause of shadow IT in an organization?
An organization uses an automated continuous integration/continuous deployment (CI/CD) tool to deploy changes to production. Which of the following would be an IS auditor ' s GREATEST concern in this situation?
Which of the following should be of GREATEST concern to an IS auditor when auditing an organization ' s IT strategy development process?
Who is PRIMARILY responsible for the design of IT controls to meet control objectives?
Which type of attack poses the GREATEST risk to an organization ' s most sensitive data?
Email required for business purposes is being stored on employees ' personal devices.
Which of the following is an IS auditor ' s BEST recommendation?
Which of the following should be of GREATEST concern to an IS auditor reviewing data conversion and migration during the implementation of a new application system?
A current project to develop IT-based solutions will need additional funding to meet changes in business requirements. Who is BEST suited to obtain this additional funding?
An organization ' s security policy mandates that all new employees must receive appropriate security awareness training. Which of the following metrics would BEST assure compliance with this policy?
An external IS auditor is reviewing the continuous monitoring system for a large bank and notes several potential issues. Which of the following would present the GREATEST concern regarding the reliability of the monitoring system?
An IS auditor is reviewing the installation of a new server. The IS auditor ' s PRIMARY objective is to ensure that
Which of the following would BEST indicate the effectiveness of a security awareness training program?
The use of access control lists (ACLs) is the MOST effective method to mitigate security risk for routers because they: (Identify Correct answer and related explanation/references from CISA Certification - Information Systems Auditor official Manual or book)
Which of the following is the BEST indication to an IS auditor that management ' s post-implementation review was effective?
Which of the following is the BEST approach to validate whether a streaming site can continue to provide service during a period of live streaming with an anticipated high volume of viewers?
A bank wants to outsource a system to a cloud provider residing in another country. Which of the following would be the MOST appropriate IS audit recommendation?
What is the BEST way to reduce the risk of inaccurate or misleading data proliferating through business intelligence systems?
Which of the following is the MOST important reason for an IS auditor to examine the results of a post-incident review performed after a security incident?
Which of the following BEST enables a governing body to monitor IT performance based on metrics?
A CFO has requested an audit of IT capacity management due to a series of finance system slowdowns during month-end reporting. What would be MOST important to consider before including this audit in the program?
In a 24/7 processing environment, a database contains several privileged application accounts with passwords set to never expire. Which of the following recommendations would BEST address the risk with minimal disruption to the business?
Which of the following MUST be completed as part of the annual audit planning process?
Which of the following user actions poses the GREATEST risk for inadvertently introducing malware into a local network?
A PRIMARY objective of risk management is to keep the total cost of risks below the:
Which of the following should be of GREATEST concern to an IS auditor reviewing hardware maintenance practices in an organization whose primary business is e-commerce?
An IS auditor suspects an organization ' s computer may have been used to commit a crime. Which of the following is the auditor ' s BEST course of action?
An IS auditor has found that a vendor has gone out of business and the escrow has an older version of the source code. What is the auditor ' s BEST recommendation for the organization?
If concurrent update transactions to an account are not processed properly, which of the following will be affected?
Which of the following establishes the PRIMARY difference between a business continuity plan (BCP) and a disaster recovery plan (DRP)?
Which of the following observations should be of GREATEST concern to an IS auditor performing an audit of change and release management controls for a new complex system developed by a small in-house IT team?
A global bank plans to use a cloud provider for backup of customer financial data. Which of the following should be the PRIMARY focus of this project?
Which of the following controls BEST ensures appropriate segregation of duties within an accounts payable department?
An IS auditor finds that the process for removing access for terminated employees is not documented What is the MOST significant risk from this observation?
Which of the following is the MOST important determining factor when establishing appropriate timeframes for follow-up activities related to audit findings?
In reviewing the IT strategic plan, the IS auditor should consider whether it identifies the:
An organization is disposing of a system containing sensitive data and has deleted all files from the hard disk. An IS auditor should be concerned because:
Which of the following provides the BEST assurance of data integrity after file transfers?