Which of the following is the GREATEST benefit of adopting an international IT governance framework rather than establishing a new framework based on the actual situation of a specific organization1?
Which of the following features of a library control software package would protect against unauthorized updating of source code?
Which of the following should be the PRIMARY purpose of conducting tabletop exercises when re-viewing a security incident response plan?
Which of the following is the BEST way to mitigate the impact of ransomware attacks?
When planning an audit, it is acceptable for an IS auditor to rely on a third-party provider’s external audit report on service level management when the
Which of the following is the MOST effective method to identify new errors introduced as a result of program changes?
In a small IT web development company where developers must have write access to production, the BEST recommendation of an IS auditor would be to:
An IS auditor is reviewing an organization ' s primary router access control list. Which of the following should result in a finding?
An IS auditor Is reviewing a recent security incident and is seeking information about me approval of a recent modification to a database system ' s security settings Where would the auditor MOST likely find this information?
The BEST way to evaluate the effectiveness of a newly developed application is to:
Which of the following network communication protocols is used by network devices such as routers to send error messages and operational information indicating success or failure when communicating with another IP address?
A new regulation has been enacted that mandates specific information security practices for the protection of customer data. Which of the following is MOST useful for an IS auditor to review when auditing against the regulation?
During the review of a system disruption incident, an IS auditor notes that IT support staff were put in a position to make decisions beyond their level of authority.
Which of the following is the BEST recommendation to help prevent this situation in the future?
A transaction processing system interfaces with the general ledger. Data analytics has identified that some transactions are being recorded twice in the general ledger. While management states a system fix has been implemented, what should the IS auditor recommend to validate the interface is working in the future?
The business case for an information system investment should be available for review until the:
Which of the following provides the MOST useful information regarding an organization ' s risk appetite and tolerance?
Which type of threat can utilize a large group of automated social media accounts to steal data, send spam, or launch distributed denial of service (DDoS) attacks?
During the implementation of an enterprise resource planning (ERP) system, an IS auditor is reviewing the results of user acceptance testing (UAT). Which of the following should be the auditor’s PRIMARY focus?
Which of the following provides IS audit professionals with the BEST source of direction for performing audit functions?
When planning an audit to assess application controls of a cloud-based system, it is MOST important tor the IS auditor to understand the.
An IS auditor is performing a follow-up audit and notes that some critical deficiencies have not been addressed. The auditor ' s BEST course of action is to:
Which of the following is the MOST important consideration when relying on the work of the prior auditor?
An IS auditor finds that a new network connection allows communication between the Internet and the internal enterprise resource planning (ERP) system. Which of the following is the PRIMARY business impact to include when presenting this observation to management?
Which of the following would be of MOST concern to an IS auditor reviewing a data loss prevention (DLP) solution implementation for endpoints?
An IS auditor reviewing the database controls for a new e-commerce system discovers a security weakness in the database configuration. Which of the following should be the IS auditor ' s NEXT course of action?
A project team has decided to switch to an agile approach to develop a replacement for an existing business application. Which of the following should an IS auditor do FIRST to ensure the effectiveness of the protect audit?
An IS auditor identifies that a legacy application to be decommissioned in three months cannot meet the security requirements established by the current policy. What is the BEST way (or the auditor to address this issue?
An organization has partnered with a third party to transport backup drives to an offsite storage facility. Which of the following is MOST important before sending the drives?
Which of the following is the PRIMARY reason an IS auditor should discuss observations with management before delivering a final report?
Which of the following is MOST important to define within a disaster recovery plan (DRP)?
Which of the following MUST be performed by senior audit leadership prior to starting an IS audit project?
An IS auditor has been asked to review an event log aggregation system to ensure risk management practices have been applied. Which of the following should be of MOST concern to the auditor?
Which of the following indicates that an internal audit organization is structured to support the independence and clarity of the reporting process?
Which of the following is MOST important to consider when evaluating a reciprocal arrangement as a recovery strategy?
Which of the following findings from a database security audit presents the GREATEST risk of critical security exposures?
Which of the following is the BEST way to detect unauthorized copies of licensed software on systems?
Due to a recent business divestiture, an organization has limited IT resources to deliver critical projects Reviewing the IT staffing plan against which of the following would BEST guide IT management when estimating resource requirements for future projects?
During a pre-implementation review, an IS auditor notes that some scenarios have not been tested. Management has indicated that the project is critical and cannot be postponed. Which of the following is the auditor ' s BEST course of action?
Which of the following is the MOST effective control over visitor access to highly secured areas?
Management has learned the implementation of a new IT system will not be completed on time and has requested an audit. Which of the following audit findings should be of GREATEST concern?
Which of the following is the STRONGEST indication of a mature risk management program?
The BEST way for an IS auditor to validate that separation of duties has been implemented is to perform:
Which of the following should be an IS auditor ' s PRIMARY focus when developing a risk-based IS audit program?
An IS auditor is reviewing job scheduling software and notes instances of delayed processing time, unexpected job interruption, and out-of-sequence job execution. Which of the following should the auditor examine FIRST to help determine the reasons for these instances?
A web proxy server for corporate connections to external resources reduces organizational risk by:
Which type of risk would MOST influence the selection of a sampling methodology?