When auditing the adequacy of a cooling system for a data center, which of the following is MOST important for the IS auditor to review?
An IS auditor requests direct access to data required to perform audit procedures instead of asking management to provide the data Which of the following is the PRIMARY advantage of this approach?
Which of the following is an effective way to ensure the integrity of file transfers in a peer-to-peer (P2P) computing environment?
Which of the following is MOST important with regard to an application development acceptance test?
An IS auditor is reviewing an organization that performs backups on local database servers every two weeks and does not have a formal policy to govern data backup and restoration procedures. Which of the following findings presents the GREATEST risk to the organization?
Which of the following is MOST important to include in a business case for an IT-enabled investment?
in a controlled application development environment, the MOST important segregation of duties should be between the person who implements changes into the production environment and the:
Which of the following controls is the BEST recommendation to prevent the skimming of debit or credit card data in point of sale (POS) systems?
Which of the following is the PRIMARY reason for an IS auditor to conduct post-implementation reviews?
Which of the following BEST facilitates strategic program management?
When reviewing past results of a recurring annual audit, an IS auditor notes that findings may not have been reported and independence may not have been maintained. Which of the following is the auditor ' s BEST course of action?
An organization ' s enterprise architecture (EA) department decides to change a legacy system ' s components while maintaining its original functionality. Which of the following is MOST important for an IS auditor to understand when reviewing this decision?
Which of the following should an IS auditor expect to see in a network vulnerability assessment?
Which of the following methods BEST enforces data leakage prevention in a multi-tenant cloud environment?
Which of the following findings related to segregation of duties should be of GREATEST concern to an IS auditor?
Which of the following is MOST important to consider when defining disaster recovery strategies?
Which of the following is PRIMARILY used in blockchain technology to create a distributed immutable ledger?
Which of the following application input controls would MOST likely detect data input errors in the customer account number field during the processing of an accounts receivable transaction?
An IS auditor believes that management has accepted a level of residual risk that is not appropriate for the organization. Which of the following is the auditor’s MOST appropriate course of action?
Which of the following would a digital signature MOST likely prevent?
Which of the following IT service management activities is MOST likely to help with identifying the root cause of repeated instances of network latency?
When processing speed is the highest priority, which cryptographic algorithm should be used to verify the integrity of a bit-for-bit copy from digital evidence?
Which of the following would be the BEST process for continuous auditing to a large financial Institution?
Which of the following is the PRIMARY advantage of using an automated security log monitoring tool instead of conducting a manual review to monitor the use of privileged access?
Which of the following is the PRIMARY reason an IS auditor should discuss observations with management before delivering a final report?
When auditing the alignment of IT to the business strategy, it is MOST Important for the IS auditor to:
Providing security certification for a new system should include which of the following prior to the system ' s implementation?
A month after a company purchased and implemented system and performance monitoring software, reports were too large and therefore were not reviewed or acted upon The MOST effective plan of action would be to:
Which type of testing is used to identify security vulnerabilities in source code in the development environment?
Which of following areas is MOST important for an IS auditor to focus on when reviewing the maturity model for a technology organization?
An IS auditor observes that a business-critical application does not currently have any level of fault tolerance. Which of the following is the GREATEST concern with this situation?
Which of the following would be of GREATEST concern to an IS auditor evaluating an organization’s change management process?
What is the BEST way to reduce the risk of inaccurate or misleading data proliferating through business intelligence systems?
Which of the following should be of GREATEST concern to an IS auditor when auditing an organization ' s IT strategy development process?
Which of the following would BEST enable an organization to address the security risks associated with a recently implemented bring your own device (BYOD) strategy?
An organizations audit charier PRIMARILY:
An organization has moved all of its infrastructure to the cloud. Which of the following would be an IS auditor’s GREATEST concern related to the organization’s ability to continue operations in case of a disaster?
Which of the following is a PRIMARY responsibility of a quality assurance (QA) team?
Which of the following is the GREATEST benefit of an effective data classification process?
To help determine whether a controls-reliant approach to auditing financial systems in a company should be used, which sequence of IS audit work is MOST appropriate?
Which of the following is the BEST way to strengthen the security of smart devices to prevent data leakage?
An IS auditor finds that some employees are using public cloud-based AI tools. Which of the following presents the GREATEST concern?
Which of the following would be of GREATEST concern to an IS auditor reviewing an IT strategy document?
An emergency power-off switch should:
An IS auditor is reviewing an organization ' s business continuity plan (BCP) following a change in organizational structure with significant impact to business processes. Which of the following findings should be the auditor ' s GREATEST concern?
An IS auditor finds that periodic reviews of read-only users for a reporting system are not being performed. Which of the following should be the IS auditor ' s NEXT course of action?
A security review focused on data loss prevention (DLP) revealed the organization has no visibility to data stored in the cloud. What is the IS auditor ' s BEST recommendation to address this
issue?
A review of an organization’s IT portfolio revealed several applications that are not in use. The BEST way to prevent this situation from recurring would be to implement.
Which of the following is the MOST likely root cause of shadow IT in an organization?
Which of the following access rights presents the GREATEST risk when granted to a new member of the system development staff?