When planning an audit to assess controls for an application in the cloud environment, it is MOST important for an IS auditor to understand:
Which of the following is MOST important when implementing a data classification program?
Results from which of the following would BEST provide assurance to a governing body that an organization’s information system controls have been reviewed objectively?
An organization ' s IT risk assessment should include the identification of:
Which of the following is the BEST control lo mitigate attacks that redirect Internet traffic to an unauthorized website?
An organization is enhancing the security of a client-facing web application following a proposal to acquire personal information for a business purpose. Which of the following is MOST important to review before implementing this initiative?
Which of the following is the BEST reason for software developers to use automated testing versus manual testing?
When building or upgrading enterprise cryptographic infrastructure, which of the following is the MOST critical requirement for growing business environments?
Which of the following BEST reflects a mature strategic planning process?
Which audit approach is MOST helpful in optimizing the use of IS audit resources?
An IS auditor has traced the source of a transaction fraud to the desktop system of an e-business staff member who is on leave. Which of the following is the BEST way for the auditor to ensure the success of the investigation?
Which of the following MOST effectively manages frequent program file changes where simultaneous code edits are used?
While executing follow-up activities, an IS auditor is concerned that management has implemented corrective actions that are different from those originally discussed and agreed with the audit function. In order to resolve the situation, the IS auditor ' s BEST course of action would be to:
Following an IT audit, management has decided to accept the risk highlighted in the audit report. Which of the following would provide the MOST assurance to the IS auditor that management
is adequately balancing the needs of the business with the need to manage risk?
Which of the following is the BEST control to mitigate the malware risk associated with an instant messaging (IM) system?
Which of the following is the PRIMARY objective of performing quality assurance (QA) in a system development process?
Which of the following physical controls provides the GREATEST assurance that only authorized individuals can access a data center?
What is the PRIMARY purpose of documenting audit objectives when preparing for an engagement?
Which of the following is an example of a preventative control in an accounts payable system?
An IS auditor is conducting a post-implementation review of an enterprise resource planning (ERP) system. End users indicated concerns with the accuracy of critical automatic calculations made by the system. The auditor ' s FIRST course of action should be to:
Which of the following is the MOST important determining factor when establishing appropriate timeframes for follow-up activities related to audit findings?
Which of the following performance management tools BEST helps an IS auditor evaluate the success of an organization’s IT strategy implementation and execution?
Which of the following is the MOST important consideration when relying on the work of the prior auditor?
When an IS auditor needs to confirm that an organization is encrypting sensitive information at a database level, which of the following would provide the BEST assurance?
An external audit firm was engaged to perform a validation and verification review for a systems implementation project. The IS auditor identifies that regression testing is not part of the project plan and was not performed by the systems implementation team. According to the team, the parallel testing being performed is sufficient, making regression testing unnecessary. What should be the auditor’s NEXT step?
An IT governance body wants to determine whether IT service delivery is based on consistently effective processes. Which of the following is the BEST approach?
Which of the following operational log management considerations is MOST important for an organization undergoing a digital transformation?
An organization is concerned about duplicate vendor payments on a complex system with a high volume of transactions. Which of the following would be MOST helpful to an IS auditor to determine whether duplicate vendor payments exist?
Which of the following is MOST important to include in a feasibility study when developing a business case for an IT investment?
Which of the following is a corrective control?
Which of the following will provide the GREATEST assurance to IT management that a quality management system (QMS) is effective?
During a security audit, an IS auditor is tasked with reviewing log entries obtained from an enterprise intrusion prevention system (IPS). Which type of risk would be associated with the potential for the auditor to miss a sequence of logged events that could indicate an error in the IPS configuration?
A system performance dashboard indicates several application servers are reaching the defined threshold for maximum CPU allocation. Which of the following would be the IS auditor ' s BEST recommendation for the IT department?
An organization is disposing of a system containing sensitive data and has deleted all files from the hard disk. An IS auditor should be concerned because:
Which of the following should be an IS auditor ' s GREATEST concern when an international organization intends to roll out a global data privacy policy?
Which of the following presents the GREATEST challenge to the alignment of business and IT?
Which of the following findings would be of GREATEST concern to an IS auditor assessing an organization ' s patch management process?
A finance department has a multi-year project to upgrade the enterprise resource planning (ERP) system hosting the general ledger. and in year one, the system version upgrade will be applied. Which of the following should be the PRIMARY focus of the IS auditor reviewing the first year of the project?
To mitigate the risk of exposing data through application programming interface (API) queries. which of the following design considerations is MOST important?
Which of the following is the BEST reason for an IS auditor to emphasize to management the importance of using an IT governance framework?
The following findings are the result of an IS auditor ' s post-implementation review of a newly implemented system. Which of the following findings is of GREATEST significance?
Which of the following risk scenarios is BEST mitigated through the use of a data loss prevention (DLP) tool?
Which of the following is the GREATEST benefit of adopting an Agile audit methodology?
Which of the following is the MOST important benefit of involving IS audit when implementing governance of enterprise IT?
Which of the following are examples of corrective controls?
An organization has decided to purchase a web-based email service from a third-party vendor and eliminate its own email server infrastructure. What type of cloud computing environment would BEST meet the organization ' s objective?
Which of the following would an IS auditor recommend as the MOST effective preventive control to reduce the risk of data leakage?
An IS auditor is reviewing a data conversion project Which of the following is the auditor ' s BEST recommendation prior to go-live?
Which of the following risks is BEST mitigated by implementing an automated three-way match?
An IS audit team is evaluating documentation of the most recent application user access review. It is determined that the user list was not system generated. Which of the following should be of
MOST concern?