A secure server room has a badge reader system that records name, date, and time information whenever a staff member uses a badge to enter or exit. When reviewing the system logs, an IS auditor notices records for some employees entering, but not exiting, the room. Which of the following would be the MOST effective compensating control to recommend?
Management has requested a post-implementation review of a newly implemented purchasing package to determine the extent that business requirements are being met. Which of the following
is MOST likely to be assessed?
A now regulation requires organizations to report significant security incidents to the regulator within 24 hours of identification. Which of the following is the IS auditor’s BEST recommendation to facilitate compliance with the regulation?
An IS audit reveals that an organization operating in business continuity mode during a pandemic situation has not performed a simulation test of the
business continuity plan (BCP). Which of the following is the auditor ' s BEST course of action?
Which of the following is the BEST way to ensure an organization ' s data classification policies are preserved during the process of data transformation?
Management has requested a post-implementation review of a newly implemented purchasing package to determine to what extent business requirements are being met. Which of the following is MOST likely to be assessed?
What should an IS auditor do FIRST upon discovering that a service provider did not notify its customers of a security breach?
An IS auditor is reviewing how password resets are performed for users working remotely. Which type of documentation should be requested to understand the detailed steps required for this activity?
What would be an IS auditor ' s BEST recommendation upon finding that a third-party IT service provider hosts the organization ' s human resources (HR) system in a foreign country?
In order for a firewall to effectively protect a network against external attacks, what fundamental practice must be followed?
Which of the following issues associated with a data center ' s closed-circuit television (CCTV) surveillance cameras should be of MOST concern to an IS auditor?
Which of the following should be of GREATEST concern to an IS auditor assessing an organization ' s patch management program?
The waterfall life cycle model of software development is BEST suited for which of the following situations?
An IS auditor is reviewing logical access controls for an organization ' s financial business application Which of the following findings should be of GREATEST concern to the auditor?
The PRIMARY advantage of using open-source-based solutions is that they:
Which of the following should an IS auditor use when verifying a three-way match has occurred in an enterprise resource planning (ERR) system?
During a pre-implementation review, an IS auditor notes that some scenarios have not been tested. Management has indicated that the project is critical and cannot be postponed. Which of the following is the auditor ' s BEST course of action?
Which of the following is the BEST recommendation to drive accountability for achieving the desired outcomes specified in a benefits realization plan for an IT project?
Which of the following is the MOST appropriate indicator of change management effectiveness?
The PRIMARY objective of a control self-assessment (CSA) is to:
Which type of attack targets security vulnerabilities in web applications to gain access to data sets?
Which of the following would BEST reduce the risk of application programming interface (API) unavailability?
Which of the following provides IS audit professionals with the BEST source of direction for performing audit functions?
An organization offers an e-commerce platform that allows consumer-to-consumer transactions. The platform now uses blockchain technology to ensure the parties are unable to deny the transactions. Which of the following attributes BEST describes the risk element that this technology is addressing?
Which of the following is the BEST detective control for a job scheduling process involving data transmission?
A data center ' s physical access log system captures each visitor ' s identification document numbers along with the visitor ' s photo. Which of the following sampling methods would be MOST useful to an IS auditor conducting compliance testing for the effectiveness of the system?
Which of the following is the MOST important area of focus for an IS auditor assessing the management of cryptographic keys in a public key infrastructure (PKI)?
An IS auditor noted a recent production incident in which a teller transaction system incorrectly charged fees to customers due to a defect from a recent release. Which of the following should be the auditor ' s NEXT step?
In which phase of the audit life cycle process should an IS auditor initially discuss observations with management?
Which of the following should be of GREATEST concern to an IS auditor performing a review of information security controls?
An IS auditor finds that irregularities have occurred and that auditee management has chosen to ignore them. If reporting to external authorities is required which of the following is the BEST action for the IS auditor to take?
Which of the following security measures is MOST important for protecting Internet of Things (IoT) devices from potential cyberattacks?
Which of the following presents the GREATEST risk of data leakage in the cloud environment?
Which of the following should be given GREATEST consideration when implementing the use of an open-source product?
Following a discussion on the results of a recent audit engagement, the process owner of the audited area has provided an action plan addressing the gaps and recommendations. The auditor disagrees with some of the responses where the process owner is accepting a level of residual risk that is not within the organization ' s risk appetite. What is the auditor ' s BEST course of action?
An organization is considering allowing users to connect personal devices to the corporate network. Which of the following should be done FIRST?
Which of the following documents should define roles and responsibilities within an IT audit organization?
When auditing the feasibility study of a system development project, the IS auditor should:
An IS auditor is reviewing job scheduling software and notes instances of delayed processing time, unexpected job interruption, and out-of-sequence job execution. Which of the following should the auditor examine FIRST to help determine the reasons for these instances?
A bank wants to outsource a system to a cloud provider residing in another country. Which of the following would be the MOST appropriate IS audit recommendation?
A programmer has made unauthorized changes lo key fields in a payroll system report. Which of the following control weaknesses would have contributed MOST to this problem?
An organization is planning an acquisition and has engaged an IS auditor lo evaluate the IT governance framework of the target company. Which of the following would be MOST helpful In determining the effectiveness of the framework?
Which of the following is an IS auditor’s MOST important step in a privacy audit?
Which of the following findings from an IT governance review should be of GREATEST concern?
An IS auditor reviewing the threat assessment tor a data center would be MOST concerned if:
Which of the following should be the PRIMARY consideration when validating a data analytic algorithm that has never been used before?
Which of the following should be of GREATEST concern to an IS auditor reviewing an organization’s IT process performance reports over the last quarter?
Of the following who should be responsible for cataloging and inventorying robotic process automation (RPA) processes?
When testing the adequacy of tape backup procedures, which step BEST verifies that regularly scheduled Backups are timely and run to completion?
An IS auditor learns that an organization ' s business continuity plan (BCP) has not been updated in the last 18 months and that the organization recently closed a production plant. Which of the following is the auditor ' s BEST course of action?