Which of the following strategies BEST optimizes data storage without compromising data retention practices?
Which of the following BEST mitigates the risk of SQL injection attacks against applications exposed to the internet?
Which of the following would be the BEST criteria for monitoring an IT vendor ' s service levels?
Which of the following observations should be of GREATEST concern to an IS auditor reviewing an organization ' s enterprise architecture (EA) program?
An IS auditor is reviewing security controls related to collaboration tools for a business unit responsible for intellectual property and patents. Which of the following observations should be of MOST concern to the auditor?
Which of the following is the GREATEST risk of project dashboards being set without sufficiently defined criteria?
Which of the following would BEST determine whether a post-implementation review (PIR) performed by the project management office (PMO) was effective?
During an information security review, an IS auditor learns an organizational policy requires all employ-ees to attend information security training during the first week of each new year. What is
the auditor ' s BEST recommendation to ensure employees hired after January receive adequate guid-ance regarding security awareness?
Which of the following is MOST important to consider when developing a service level agreement (SLAP)?
Which of the following recommendations would BEST prevent the implementation of IT projects without collaborating with the business?
Which of the following provides an IS auditor the BEST evidence that a third-party service provider ' s information security controls are effective?
Which of the following should be done FIRST when planning to conduct internal and external penetration testing for a client?
During an audit of a reciprocal disaster recovery agreement between two companies, the IS auditor would be MOST concerned with the:
Which of the following groups is PRIMARILY accountable for establishing a culture that facilitates an effective and efficient internal control system?
During a follow-up audit, an IS auditor finds that senior management has implemented a different remediation action plan than what was previously agreed upon. Which of the following is the auditor ' s BEST course of action?
The PRIMARY purpose of a vulnerability assessment in a cybersecurity program is to:
Which of the following should an IS auditor use when verifying a three-way match has occurred in an enterprise resource planning (ERR) system?
Which of the following is the BEST approach for determining the overall IT risk appetite of an organization when business units use different methods for managing IT risks?
Which of the following should an IS auditor expect to find when reviewing an IT metrics dashboard?
In which phase of the audit life cycle process should an IS auditor initially discuss observations with management?
An IS auditor finds that a recently deployed application has a number of developers with inappropriate update access left over from the testing environment. Which of the following would have BEST prevented the update access from being migrated?
Which of the following BEST demonstrates alignment of the IT department with the corporate mission?
An organization performs virtual machine (VM) replication instead of daily backups of its critical servers. Which of the following is MOST important to validate when evaluating the adequacy of recovery procedures?
Visitors to a data center are required to present an ID and pre-approved documents. Which type of control has been implemented?
Which of the following is the GREATEST risk related to the use of virtualized environments?
Which of the following provides the MOST useful information for performing a business impact analysis (B1A)?
Which of the following MUST be completed as part of the annual audit planning process?
Which of the following is the BEST method to delete sensitive information from storage media that will be reused?
Which of the following BEST helps to establish that digital evidence is in its original form and has not been tampered with?
Following a breach, what is the BEST source to determine the maximum amount of time before customers must be notified that their personal information may have been compromised?
An IS auditor reviewing an organization’s online payment system finds that the system sometimes duplicates payments. Which control will BEST compensate for this weakness?
An IS auditor reviewing security incident processes realizes incidents are resolved and closed, but root causes are not investigated. Which of the following should be the MAJOR concern with this situation?
If a source code is not recompiled when program changes are implemented, which of the following is a compensating control to ensure synchronization of source and object?
When reviewing an organization ' s information security policies, an IS auditor should verify that the policies have been defined PRIMARILY on the basis of:
The charging method that effectively encourages the MOST efficient use of IS resources is:
What is MOST important to verify during an external assessment of network vulnerability?
Which of the following BEST ensures that effective change management is in place in an IS environment?
Which of the following BEST helps to ensure data integrity across system interfaces?
Which type of review is MOST important to conduct when an IS auditor is informed that a recent internal exploitation of a bug has been discovered in a business application?
An organization using a cloud provider for its online billing system requires the website to be accessible to customers at all times. What is the BEST way to verify the organization ' s business requirements are met?
Which of the following activities is MOST likely to increase internal audit quality?
Which of the following is MOST important for an IS auditor to verify when evaluating an organization ' s firewall?
An IS auditor reviewing a job scheduling tool notices performance and reliability problems. Which of the following is MOST likely affecting the tool?
Which of the following should be used as the PRIMARY basis for prioritizing IT projects and initiatives?
An IS auditor reviewing an information processing environment decides to conduct external penetration testing. Which of the following is MOST appropriate to include in the audit scope for the organization to distinguish between the auditor ' s penetration attacks and actual attacks?