Which of the following is an IS auditor ' s BEST recommendation to protect an organization from attacks when its file server needs to be accessible to external users?
An organization uses an automated continuous integration/continuous deployment (CI/CD) tool to deploy changes to production. Which of the following would be an IS auditor ' s GREATEST concern in this situation?
An IS auditor reviewing an organization’s online payment system finds that the system sometimes duplicates payments. Which control will BEST compensate for this weakness?
What is the MOST effective way to detect installation of unauthorized software packages by employees?
In an environment that automatically reports all program changes, which of the following is the MOST efficient way to detect unauthorized changes to production programs?
In a 24/7 processing environment, a database contains several privileged application accounts with passwords set to never expire. Which of the following recommendations would BEST address the risk with minimal disruption to the business?
The GREATEST benefit of using a polo typing approach in software development is that it helps to:
In a high-volume, real-time system, the MOST effective technique by which to continuously monitor and analyze transaction processing is:
An IS audit manager is preparing the staffing plan for an audit engagement of a cloud service provider. What should be the manager ' s PRIMARY concern when being made aware that a new
auditor in the department previously worked for this provider?
The BEST way to provide assurance that a project is adhering to the project plan is to:
During a review of a production schedule, an IS auditor observes that a staff member is not complying with mandatory operational procedures. The auditor ' s NEXT step should be to:
Which of the following should an IS auditor be MOST concerned with during a post-implementation review?
During a disaster recovery audit, an IS auditor finds that a business impact analysis (BIA) has not been performed. The auditor should FIRST
An IS auditor is asked to review an organization ' s technology relationships, interfaces, and data. Which of the following enterprise architecture (EA) areas is MOST appropriate this review? (Choose Correct answer and give explanation from CISA Certification - Information Systems Auditor official book)
Which of the following approaches will ensure recovery time objectives (RTOs) are met for an organization ' s disaster recovery plan (DRP)?
Which of the following should be the IS auditor ' s PRIMARY focus when evaluating an organizations offsite storage facility?
Which of the following is the BEST review for an IS auditor to conduct when a vulnerability has been exploited by an employee?
Which of the following is the MOST appropriate testing approach when auditing a daily data flow between two systems via an automated interface to confirm that it is complete and accurate?
Which of the following is the GREATEST risk associated with hypervisors in virtual environments?
Which of the following provides the GREATEST assurance that a middleware application compiling data from multiple sales transaction databases for forecasting is operating effectively?
An IS audit manager was temporarily tasked with supervising a project manager assigned to the organization ' s payroll application upgrade. Upon returning to the audit department, the audit manager has been asked to perform an audit to validate the implementation of the payroll application. The audit manager is the only one in the audit department with IT project management
experience. What is the BEST course of action?
Which of the following is the PRIMARY role of the IS auditor m an organization ' s information classification process?
Which of the following provides the BEST providence that outsourced provider services are being properly managed?
Which of the following is the PRIMARY reason for implementing continuous auditing?
A manager Identifies active privileged accounts belonging to staff who have left the organization. Which of the following is the threat actor In this scenario?
Which of the following should be the GREATEST concern to an IS auditor reviewing an organization ' s job scheduling practices?
Which of the following must be in place before an IS auditor initiates audit follow-up activities?
In order to be useful, a key performance indicator (KPI) MUST
Audit observations should be FIRST communicated with the auditee:
During the design phase of a software development project, the PRIMARY responsibility of an IS auditor is to evaluate the:
Which of the following should be the FIRST consideration when deciding whether data should be moved to a cloud provider for storage?
A company has implemented an IT segregation of duties policy. In a role-based environment, which of the following roles may be assigned to an application developer?
An organization has recently acquired and implemented intelligent-agent software for granting loans to customers. During the post-implementation review, which of the following is the MOST important procedure for the IS auditor to perform?
Which of the following would an IS auditor find to be the GREATEST risk associated with the server room in a remote office location?
Which of the following is the GREATEST risk when relying on reports generated by end-user computing (EUC)?
Which of the following will be the MOST effective method to verify that a service vendor keeps control levels as required by the client?
Which of the following is the BEST way to prevent social engineering incidents?
An IS auditor is evaluating the access controls for a shared customer relationship management (CRM) system. Which of the following would be the GREATEST concern?
An IS auditor has been asked to advise on measures to improve IT governance within the organization. Which of the following IS the BEST recommendation?
Which of the following provides the MOST useful information to an IS auditor when selecting projects for inclusion in an IT audit plan?
During an exit interview, senior management disagrees with some of me facts presented m the draft audit report and wants them removed from the report. Which of the following would be the auditor ' s BEST course of action?
Which of the following is MOST important to ensure when developing an effective security awareness program?
Which of the following would be of GREATEST concern to an IS auditor reviewing an IT-related customer service project?
During audit framework. an IS auditor teams that employees are allowed to connect their personal devices to company-owned computers. How can the auditor BEST validate that appropriate security controls are in place to prevent data loss?
An IS auditor reviewing an organization’s online payment system finds that the system sometimes duplicates payments. Which control will BEST compensate for this weakness?
With regard to resilience, which of the following is the GREATEST risk to an organization that has implemented a new critical system?
The PRIMARY objective of a privacy protection policy is to increase awareness of:
A KEY benefit of integrated auditing is that it:
Which of the following audit procedures would provide the BEST assurance that an application program is functioning as designed?
An organization has decided to reengineer business processes to improve the performance of overall IT service delivery. Which of the following recommendations from the project team should be the GREATEST concern to the IS auditor?