Which of the following is the BEST source of information for an IS auditor to use as a baseline to assess the adequacy of an organization ' s privacy policy?
An organization ' s security team created a simulated production environment with multiple vulnerable applications. What would be the PRIMARY purpose of creating such an environment?
Which of the following is the BEST control lo mitigate attacks that redirect Internet traffic to an unauthorized website?
Which of the following is an IS auditor’s BEST recommendation after identifying that HR staff create new employees in the payroll system as well as process payroll due to limited staffing?
Which of the following provides the BEST providence that outsourced provider services are being properly managed?
Which of the following is the MOST important action when populating a project risk register?
An organization that has suffered a cyber-attack is performing a forensic analysis of the affected users ' computers. Which of the following should be of GREATEST concern for the IS auditor reviewing this process?
When testing the accuracy of transaction data, which of the following situations BEST justifies the use of a smaller sample size?
Based on best practices, which types of accounts should be disabled for interactive login?
Which of the following should an IS auditor perform FIRST when auditing an outsourced human resource application?
Which of the following is the GREATEST benefit of adopting an Agile audit methodology?
Which of the following is the PRIMARY advantage of using visualization technology for corporate applications?
In an annual audit cycle, the audit of an organization ' s IT department resulted in many findings. Which of the following would be the MOST important consideration when planning the next audit?
Which of the following responses to risk associated with segregation of duties would incur the LOWEST initial cost?
Which of the following observations should be of GREATEST concern to an IS auditor reviewing an organization’s enterprise architecture (EA) program?
Which of the following BEST enables an organization to verify whether an encrypted message sent by a client has been altered?
To ensure confidentiality through the use of asymmetric encryption, a message is encrypted with which of the following?
During a review of an organization ' s IT capacity management process, an IS auditor should be MOST concerned if capacity planning:
An IS auditor has been asked to perform a post-implementation review of a newly developed system. When reviewing the testing phase results, the auditor observed that separate modules of the system tested correctly in the user acceptance testing (UAT) phase, but some features did not work as expected when moved to production. Which of the following was MOST likely omitted prior to implementation?
An organization has outsourced its data processing function to a service provider. Which of the following would BEST determine whether the service provider continues to meet the organization s objectives?
Which of the following is the BEST indicator that a third-party vendor adheres to the controls required by the organization?
A national tax administration agency with a distributed network experiences service disruptions due to a large influx of traffic to a regional office near the end of each year. Which of the following would BEST enable the agency to improve the performance of its servers during the busy period?
An IS auditor is reviewing desktop software profiles and notes that a user has downloaded and installed several games that are not approved by the company. Which of the following is the MOST significant risk that could result from this situation?
The PRIMARY reason to assign data ownership for protection of data is to establish:
Which of the following issues identified during a formal review of an organization ' s information security policies presents the GREATEST potential risk to the organization?
The PRIMARY reason to perform internal quality assurance (QA) for an internal audit function is to ensure:
An IS auditor plans to review all access attempts to a video-monitored and proximity card-controlled communications room. Which of the following would be MOST useful to the auditor?
Which of the following findings would be of GREATEST concern when auditing an organization ' s end-user computing (EUC)?
An externally facing system containing sensitive data is configured such that users have either read-only or administrator rights. Most users of the system have administrator access. Which of the following is the GREATEST risk associated with this situation?
Which of the following provides the BEST audit evidence that a firewall is configured in compliance with the organization ' s security policy?
Which of the following would be MOST useful when analyzing computer performance?
An organization offers an e-commerce platform that allows consumer-to-consumer transactions. The platform now uses blockchain technology to ensure the parties are unable to deny the transactions. Which of the following attributes BEST describes the risk element that this technology is addressing?
An IS auditor finds that capacity management for a key system is being performed by IT with no input from the business The auditor ' s PRIMARY concern would be:
Which of the following should be the FIRST step when developing a data loss prevention (DLP) solution for a large organization?
Which of the following audit evidence collection procedures is MOST reliable?
Which of the following is an IS auditor ' s BEST recommendation to mitigate the risk of eavesdropping
associated with an application programming interface (API) integration implementation?
An IS auditor finds that an IT manager recently changed a Software as a Service (SaaS) provider contract in an effort to cut costs. The new contract increases the time to resolve incidents. Which of the following should be the auditor’s GREATEST concern?
When assessing the overall effectiveness of an organization ' s disaster recovery planning process, which of the following is MOST important for the IS auditor to verify?
Which of the following should be identified FIRST during the risk assessment process?
Which of the following should be the GREATEST concern to an IS auditor reviewing the information security framework of an organization?
Which of the following is the MOST significant risk to an organization migrating its onsite application servers to a public cloud service provider?
Which of the following is the MAJOR advantage of automating internal controls?
What should an IS auditor ensure when a financial organization intends to utilize production data in the testing environment?
An IS auditor observes that a large number of departed employees have not been removed from the accounts payable system. Which of the following is MOST important to determine in order to assess the risk1?
Which of the following should be the IS auditor ' s PRIMARY focus, when evaluating an organization ' s offsite storage facility?
Which of the following is the BEST indication that an information security awareness program is effective?
An IS auditor is concerned that unauthorized access to a highly sensitive data center might be gained by piggybacking or tailgating. Which of the following is the BEST recommendation? (Choose Correct answer and give explanation from CISA Certification - Information Systems Auditor official book)
Which of the following is the BEST reason to implement a configuration management database (CMDB)?