Which of the following is the MOST effective way to evaluate the physical security of a data center?
When a data center is attempting to restore computing facilities at an alternative site following a disaster, which of the following should be restored FIRST?
Which of the following metrics would BEST measure the agility of an organization ' s IT function?
An IS auditor is following up on prior period items and finds management did not address an audit finding. Which of the following should be the IS auditor ' s NEXT course of action?
Which of the following would BEST detect that a distributed denial of service (DDoS) attack is occurring?
An organization that operates an e-commerce website wants to provide continuous service to its customers and is planning to invest in a hot site due to service criticality. Which of the following is the MOST important consideration when making this decision?
Which of the following is the MOST important reason to implement version control for an end-user computing (EUC) application?
Which of the following should be the FIRST step in the incident response process for a suspected breach?
Which of the following is BEST used for detailed testing of a business application ' s data and configuration files?
Which of the following protocols should be used when transferring data via the internet?
Which of the following would BEST enable an organization to address the security risks associated with a recently implemented bring your own device (BYOD) strategy?
An IS auditor has validated that an organization ' s IT department runs several low-priority automated tasks Which of the following is the BEST recommendation for an automated job schedule?
An IS auditor has found that an organization is unable to add new servers on demand in a cost-efficient manner. Which of the following is the auditor ' s BEST recommendation?
Which of the following issues associated with a data center ' s closed-circuit television (CCTV) surveillance cameras should be of MOST concern to an IS auditor?
Which of the following is the MOST effective way for an organization to project against data loss?
An IS audit reveals that an organization is not proactively addressing known vulnerabilities. Which of the following should the IS auditor recommend the organization do FIRST?
Which of the following should be of GREATEST concern to an IS auditor reviewing an organization ' s IT process performance reports over the last quarter?
Which of the following responsibilities associated with a disaster recovery plan (DRP) can be outsourced to a Disaster Recovery as a Service (DRaaS) provider?
Which of the following would provide management with the MOST reasonable assurance that a new data warehouse will meet the needs of the
organization?
Which of the following is the MOST important consideration when establishing vulnerability scanning on critical IT infrastructure?
Which of the following application input controls would MOST likely detect data input errors in the customer account number field during the processing of an accounts receivable transaction?
What should an IS auditor evaluate FIRST when reviewing an organization ' s response to new privacy legislation?
Which of the following is the MOST important privacy consideration for an organization that uses a cloud service provider to process customer data?
Which of the following is the MOST appropriate and effective fire suppression method for an unstaffed computer room?
Which of the following is the PRIMARY reason for an IS auditor to conduct post-implementation reviews?
A small business unit is implementing a control self-assessment (CSA) program and leveraging the internal
audit function to test its internal controls annually. Which of the following is the MOST significant benefit of
this approach?
Which of the following is MOST important to include when developing a business continuity plan (BCP)?
Which of the following is MOST important for an IS auditor to look
for in a project feasibility study?
When an IS auditor needs to confirm that an organization is encrypting sensitive information at a database level, which of the following would provide the BEST assurance?
Which of the following risk scenarios is BEST addressed by implementing policies and procedures related to full disk encryption?
An organization ' s payroll department recently implemented a new Software as a Service (SaaS) tool for payment processing. Which of the following audits is MOST appropriate for an IS auditor to validate that the new tool is configured as expected to meet performance requirements?
Recovery facilities providing a redundant combination of Internet connections to the local communications loop is an example of which type of telecommunications continuity?
An IS audit reveals an IT application is experiencing poor performance including data inconsistency and integrity issues. What is the MOST likely cause?
Which of the following is the MOST reliable way for an IS auditor to evaluate the operational effectiveness of an organization ' s data loss prevention (DLP) controls?
An organization ' s enterprise architecture (EA) department decides to change a legacy system ' s components while maintaining its original functionality. Which of the following is MOST important for an IS auditor to understand when reviewing this decision?
A new system development project is running late against a critical implementation deadline Which of the following is the MOST important activity?
Which of the following is MOST important for an IS auditor to confirm when reviewing an organization ' s incident response management program?
Compared to developing a system in-house, acquiring a software package means that the need for testing by end users is:
An IS auditor is reviewing a data conversion project Which of the following is the auditor ' s BEST recommendation prior to go-live?
Upon completion of a penetration test with findings for an IT system, the NEXT step should be:
The BEST way to provide assurance that a project is adhering to the project plan is to:
During the course of fieldwork, an internal IS auditor observes a critical vulnerability within a newly deployed application. What is the auditor ' s BEST course of action?
An IS auditor is asked to review an organization ' s technology relationships, interfaces, and data. Which of the following enterprise architecture (EA) areas is MOST appropriate this review? (Choose Correct answer and give explanation from CISA Certification - Information Systems Auditor official book)
Which of the following is the GREATEST risk when relying on reports generated by end-user computing (EUC)?
What would be the PRIMARY reason an IS auditor would recommend replacing universal PIN codes with an RFID access card system at a data center?
Which audit approach is MOST helpful in optimizing the use of IS audit resources?