An external attacker spoofing an internal Internet Protocol (IP) address can BEST be detected by which of the following?
Which of the following would BEST facilitate the successful implementation of an IT-related framework?
Which of the following is an example of a passive attack method?
During a follow-up audit, an IS auditor finds that some critical recommendations have the IS auditor ' s BEST course of action?
Which of the following provides the BE ST method for maintaining the security of corporate applications pushed to employee-owned mobile devices?
Which of the following provides the MOST assurance over the completeness and accuracy ol loan application processing with respect to the implementation of a new system?
Which of the following is the BEST indication that a software development project is on track to meet its completion deadline?
Which of the following is found in an audit charter?
Malicious program code was found in an application and corrected prior to release into production. After the release, the same issue was reported. Which of the following is the IS auditor ' s BEST recommendation?
Some control activities have been found to be only partially compliant with the design of the control. Which of the following is an IS auditor’s PRIMARY course of action?
Which of the following is MOST helpful in identifying system performance constraints?
An IS auditor is assigned to perform a post-implementation review of an application system. Which of the following would impair the auditor’s independence?
The following findings are the result of an IS auditor’s post-implementation review of a newly implemented system. Which of the following findings is of GREATEST significance?
An IS auditor should ensure that an application ' s audit trail:
An incident response team has been notified of a virus outbreak in a network subnet. Which of the following should be the NEXT step?
Which of the following is the MOST important course of action to ensure a cloud access security broker (CASB) effectively detects and responds to threats?
What would be an IS auditor ' s BEST course of action when an auditee is unable to close all audit recommendations by the time of the follow-up audit?
Which of the following is MOST helpful to an IS auditor reviewing the alignment of planned IT budget with the organization ' s goals and strategic objectives?
The BEST way to determine whether programmers have permission to alter data in the production environment is by reviewing:
Which of the following findings from a network security review presents the GREATEST risk to the organization?
An organization implemented a cybersecurity policy last year Which of the following is the GREATE ST indicator that the policy may need to be revised?
An IS auditor is reviewing the installation of a new server. The IS auditor ' s PRIMARY objective is to ensure that
Which of the following is the GREATEST concern associated with a high number of IT policy exceptions approved by management?
An IS auditor has discovered that a software system still in regular use is years out of date and no longer supported. The auditee has stated that it will take six months until the software is running on the current version. Which of the following is the BEST way to reduce the immediate risk associated with using an unsupported version of the software?
Using swipe cards to limit employee access to restricted areas requires implementing which additional control?
Which of the following is a threat to IS auditor independence?
Which of the following should be of MOST concern to an IS auditor reviewing the information systems acquisition, development, and implementation process?
An organization is implementing a new system that supports a month-end business process. Which of the following implementation strategies would be MOST efficient to decrease business downtime?
Which of the following would be of GREATEST concern to an IS auditor reviewing the resiliency of an organizational network that has two internet connections?
Which of the following is the GREATEST risk associated with utilizing spreadsheets for financial reporting in end-user computing (EUC)?
Which of the following issues identified during a formal review of an organization ' s information security policies presents the GREATEST potential risk to the organization?
Which of the following is MOST important to ensure successful implementation when an organization decides to purchase software from available products on the market?
An IS auditor wants to gain a better understanding of an organization’s selected IT operating system software. Which of the following would be MOST helpful to review?
An IS auditor is reviewing processes for importing market price data from external data providers. Which of the following findings should the auditor consider MOST critical?
Which of the following is MOST helpful to an IS auditor when assessing the effectiveness of controls?
An IS auditor is assigned to perform a post-implementation review of an application system. Which of the following would impair the auditor ' s independence?
Which of the following should be the role of internal audit in an organization’s move to the cloud?
When an organization conducts business process improvements, the IS auditor should be MOST concerned with the:
An IS auditor is assessing an organization ' s DevSecOps approach. Which of the following BEST indicates a proactive approach to identifying vulnerabilities?
What is the BEST control to address SQL injection vulnerabilities?
An organization is implementing a data loss prevention (DLP) system in response to a new regulatory requirement Reviewing. which of the following would be MOST helpful in evaluating the system ' s design?
The business case for an information system investment should be available for review until the:
An IS auditor has been asked to review the integrity of data transfer between two business-critical systems that have not been tested since implementation. Which of the following would provide the MOST useful information to plan an audit?
Which of the following observations should be of GREATEST concern to an IS auditor performing an audit of change and release management controls for a new complex system developed by a small in-house IT team?
Which of the following is the PRIMARY purpose of enterprise architecture (EA) within an organization?
Which of the following BEST demonstrates that IT strategy Is aligned with organizational goals and objectives?
A source code repository should be designed to:
An IS auditor discovers that due to resource constraints a database administrator (DBA) is responsible for developing and executing changes into the production environment Which ot the following should the auditor do FIRSTS
Which of the following is the MOST effective control over visitor access to highly secured areas?
Following a discussion on the results of a recent audit engagement, the process owner of the audited area has provided an action plan addressing the gaps and recommendations. The auditor disagrees with some of the responses where the process owner is accepting a level of residual risk that is not within the organization’s risk appetite. What is the auditor’s BEST course of action?