An organization outsourced its IS functions to meet its responsibility for disaster recovery, the organization should:
Which of the following is the BEST way to prevent social engineering incidents?
A now regulation requires organizations to report significant security incidents to the regulator within 24 hours of identification. Which of the following is the IS auditor’s BEST recommendation to facilitate compliance with the regulation?
A network analyst is monitoring the network after hours and detects activity that appears to be a brute-force attempt to compromise a critical server. After reviewing the alerts to ensure their accuracy, what should be done NEXT?
Which of the following would MOST effectively ensure the integrity of data transmitted over a network?
Which of the following would be of GREATEST concern to an IS auditor reviewing the resiliency of an organizational network that has two internet connections?
An IS auditor is reviewing processes for importing market price data from external data providers. Which of the following findings should the auditor consider MOST critical?
Which of the following should be of GREATEST concern to an IS auditor when using data analytics?
Which of the following is the PRIMARY objective of a control self-assessment (CSA)?
Which of the following is MOST helpful in identifying system performance constraints?
A senior auditor is reviewing work papers prepared by a junior auditor indicating that a finding was removed after the auditee said they corrected the problem. Which of the following is the senior auditor s MOST appropriate course of action?
An organization has shifted from a bottom-up approach to a top-down approach in the development of IT policies. This should result in:
An IS auditor is verifying the adequacy of an organization ' s internal controls and is concerned about potential circumvention of regulations. Which of the following is the BEST sampling method to use?
An IS auditor finds the log management system is overwhelmed with false positive alerts. The auditor ' s BEST recommendation would be to:
Which of the following is the BEST source of information tor an IS auditor to use when determining whether an organization ' s information security policy is adequate?
Which of the following is the GREATEST concern associated with a high number of IT policy exceptions approved by management?
Which of the following would be the MOST useful metric for management to consider when reviewing a project portfolio?
Which of the following should be of GREATEST concern to an IS auditor reviewing an organization ' s mobile device policies and controls in its corporate environment?
Which of the following will MOST likely compromise the control provided By a digital signature created using RSA encryption?
Which of the following is the BEST way to help ensure new IT implementations align with enterprise architecture (EA) principles and requirements?
During an organization ' s implementation of a data loss prevention (DLP) solution, which of the following activities should be completed FIRST?
Which of the following is the PRIMARY benefit of effective implementation of appropriate data classification?
An IS auditor is asked to provide feedback on the systems options analysis for a new project. The BEST course of action for the IS auditor would be to:
Which of the following controls is MOST effective at preventing system failures when implementing a new web application?
An IS auditor is reviewing a bank’s service level agreement (SLA) with a third-party provider that hosts the bank’s secondary data center. Which of the following findings should be of GREATEST concern to the auditor?
Which of the following is an IS auditor ' s BEST course of action when the auditee indicates that a corrective action plan for a high-risk finding will take longer than expected?
Which of the following is MOST effective in keeping a database management system (DBMS) at maximum performance?
Which of the following should be done FIRST when planning a penetration test?
From a risk management perspective, which of the following is the BEST approach when implementing a large and complex data center IT infrastructure?
Which of the following is an IS auditor ' s BEST recommendation for mitigating risk associated with inadvertent disclosure of sensitive information by employees?
An employee approaches an IS auditor and expresses concern about a critical security issue in a newly installed application. Which of the following should the auditor do FIRST?
Which of the following BEST mitigates the risk associated with the deployment of a new production system?
An IS auditor notes the transaction processing times in an order processing system have significantly increased after a major release. Which of the following should the IS auditor review FIRST?
Which of the following is the PRIMARY purpose of conducting a control self-assessment (CSA)?
Which of the following is MOST important to consider when defining disaster recovery strategies?
Which of the following should be the PRIMARY basis for prioritizing follow-up audits?
An IS department is evaluated monthly on its cost-revenue ratio user satisfaction rate, and computer downtime This is BEST zed as an application of.
An organization establishes capacity utilization thresholds and monitors for instances when thresholds are exceeded. Which of the following is BEST supported by this activity?
Which of the following is the BEST recommendation to prevent fraudulent electronic funds transfers by accounts payable employees?
A system performance dashboard indicates several application servers are reaching the defined threshold for maximum CPU allocation. Which of the following would be the IS auditor ' s BEST recommendation for the IT department?
An IS auditor finds that a key Internet-facing system is vulnerable to attack and that patches are not available. What should the auditor recommend be done FIRST?
A new regulation in one country of a global organization has recently prohibited cross-border transfer of personal data. An IS auditor has been asked to determine the organization ' s level of exposure In the affected country. Which of the following would be MOST helpful in making this assessment?
Which of the following is an analytical review procedure for a payroll system?
A programmer has made unauthorized changes lo key fields in a payroll system report. Which of the following control weaknesses would have contributed MOST to this problem?
Which of the following is the BEST method to safeguard data on an organization ' s laptop computers?