Which of the following activities should be separated in an organization’s incident management processes?
During a follow-up audit, an IS auditor learns that management has deferred the implementation of a previously agreed-upon recommendation. What is the responsibility of the auditor?
Which of the following is the BEST data integrity check?
What is the PRIMARY benefit of using one-time passwords?
An organization plans to centrally decommission end-of-life databases and migrate the data to the latest model of hardware. Which of the following BEST ensures data integrity is preserved during the migration?
An organization is concerned with meeting new regulations for protecting data confidentiality and asks an IS auditor to evaluate their procedures for transporting data. Which of the
following would BEST support the organization ' s objectives?
Which of the following is the PRIMARY reason to involve IS auditors in the software acquisition process?
Which of the following is MOST important to include when developing a business continuity plan (BCP)?
Which of the following should be of MOST concern to an IS auditor reviewing an organization ' s operational log management?
Data centers that want to prevent unauthorized personnel from entering during a power outage should ensure external access doors:
Which of the following controls BEST provides confidentiality and nonrepudiation for an online business looking for digital payment data security?
Which of the following is the MOST important consideration when evaluating the data retention policy for a global organization with regional offices in multiple countries?
Which of the following applications should an IS auditor consider to be the HIGHEST priority when reviewing disaster recovery planning (DRP) tests for an commerce company?
Which of the following is the PRIMARY basis on which audit objectives are established?
A web proxy server for corporate connections to external resources reduces organizational risk by:
Which of the following is the PRIMARY benefit of performing periodic maturity model assessments?
Which type of control has been established when an organization implements a security information and event management (SIEM) system?
Which of the following should be the PRIMARY objective of a disaster recovery plan (DRP)?
While auditing a small organization ' s data classification processes and procedures, an IS auditor noticed that data is often classified at the incorrect level. What is the MOST effective way for the organization to improve this situation?
Which of the following BEST ensures that effective change management is in place in an IS environment?
Which of the following is the BEST method to delete sensitive information from storage media that will be reused?
An IS auditor discovers that validation controls in a web application have been moved from the server side into the browser to boost performance. This would MOST likely increase the risk of a successful attack by:
Which of the following concerns is MOST effectively addressed by implementing an IT framework for alignment between IT and business objectives?
An IS auditor wants to inspect recent events in a system to observe failed authentications and password changes. Which of the following is the MOST appropriate method to use for this purpose?
Which of the following is MOST important to ensure when planning a black box penetration test?
Which of the following is an IS auditor ' s BEST recommendation to mitigate the risk of eavesdropping
associated with an application programming interface (API) integration implementation?
Which of the following approaches BEST enables an IS auditor to detect security vulnerabilities within an application?
Which of the following provides an IS auditor the BEST evidence that a third-party service provider ' s information security controls are effective?
Which of the following is the MOST important consideration for patching mission critical business application servers against known vulnerabilities?
A system development project is experiencing delays due to ongoing staff shortages. Which of the following strategies would provide the GREATEST assurance of system quality at implementation?
An IS auditor learns the organization has experienced several server failures in its distributed environment. Which of the following is the BEST recommendation to limit the potential impact of server failures in the future?
Which of the following is an example of shadow IT?
A database administrator (DBA) should be prevented from having end user responsibilities:
An IS auditor is reviewing an organization ' s primary router access control list. Which of the following should result in a finding?
Which of the following would provide management with the MOST reasonable assurance that a new data warehouse will meet the needs of the
organization?
In response to an audit finding regarding a payroll application, management implemented a new automated control. Which of the following would be MOST helpful to the IS auditor when evaluating the effectiveness of the new control?
Which of the following technologies has the SMALLEST maximum range for data transmission between devices?
Which of the following is the BEST control to mitigate the risk of shadow IT?
An organization ' s security policy mandates that all new employees must receive appropriate security awareness training. Which of the following metrics would BEST assure compliance with this policy?
Which of the following areas is MOST likely to be overlooked when implementing a new data classification process?
An IS auditor is reviewing an organization ' s cloud access security broker (CASB) solution. Which ofthe following is MOST important for the auditor to verify?
Which of the following risk scenarios is BEST addressed by implementing policies and procedures related to full disk encryption?
Which of the following is the BEST way to detect unauthorized copies of licensed software on systems?
Coding standards provide which of the following?
An IS auditor is reviewing desktop software profiles and notes that a user has downloaded and installed several games that are not approved by the company. Which of the following is the MOST significant risk that could result from this situation?
Which of the following should be of GREATEST concern to an IS auditor reviewing a network printer disposal process?
Which of the following should be the PRIMARY purpose of conducting tabletop exercises when re-viewing a security incident response plan?
An organization ' s strategy to source certain IT functions from a Software as a Service (SaaS) provider should be approved by the:
Which of the following is an executive management concern that could be addressed by the implementation of a security metrics dashboard?
Stress testing should ideally be earned out under a: