Which of the following should an IS auditor be MOST concerned with when a system uses RFID?
Which of the following would the IS auditor MOST likely review to determine whether modifications to the operating system parameters were authorized?
A national bank recently migrated a large number of business-critical applications to the cloud. Which of the following is MOST important to ensuring the resiliency of the applications?
An organization’s information security department has recently created a centralized governance model to ensure that network-related findings are remediated within the service level agreement (SLA). What should the IS auditor use to assess the capability of this governance model?
If enabled within firewall rules, which of the following services would present the GREATEST risk?
An IS auditor discovers from patch logs that some in-scope systems are not compliant with the regular patching schedule. What should the auditor do NEXT?
Which of the following is the MOST efficient control to reduce the risk associated with a systems administrator having network administrator responsibilities?
Which of the following is the PRIMARY reason to follow a configuration management process to maintain application?
Which of the following should be of GREATEST concern to an IS auditor reviewing an organization ' s business continuity plan (BCP)?
Which of the following is MOST important for an effective control self-assessment (CSA) program?
Which of the following provides the BEST assurance that a new database management system (DBMS) meets the requirements of local privacy regulations?
Which of the following metrics BEST demonstrates the effectiveness of an organization’s privacy program?
Before the release of a new application into an organization’s production environment, which of the following should be in place to ensure that proper testing has occurred and rollback plans are in place?
Which of following is MOST important to determine when conducting a post-implementation review?
A finance department has a two-year project to upgrade the enterprise resource planning (ERP) system hosting the general ledger in year one the system version upgrade will be applied and in year two business processes will be updated to implement new system functionality. Which of the following should be the PRIMARY focus of an IS auditor reviewing the second year of the implementation ' ?
The MOST effective way to reduce sampling risk is to increase:
During the implementation of an upgraded enterprise resource planning (ERP) system, which of the following is the MOST important consideration for a go-live decision?
Which of the following is the PRIMARY benefit of operational log management?
Which of the following is the MOST significant impact to an organization that does not use an IT governance framework?
Which of the following should be of MOST concern to an IS auditor reviewing the public key infrastructure (PKI) for enterprise email?
An IS auditor is planning an audit of an organization ' s accounts payable processes. Which of the following controls is MOST important to assess in the audit?
Which of the following is the GREATEST risk related to the use of virtualized environments?
During an IT governance audit, an IS auditor notes that IT policies and procedures are not regularly reviewed and updated. The GREATEST concern to the IS auditor is that policies and procedures might not:
Which of the following should be an IS auditor ' s PRIMARY consideration when determining which issues to include in an audit report?
Which of the following control measures is the MOST effective against unauthorized access of confidential information on stolen or lost laptops?
An IS auditor has been asked to assess the security of a recently migrated database system that contains personal and financial data for a bank ' s customers. Which of the following controls is MOST important for the auditor to confirm is in place?
Which of the following is the PRIMARY benefit of a tabletop exercise for an incident response plan?
Which of the following is the BEST way to mitigate the risk associated with unintentional modifications of complex calculations in end-user computing (EUC)?
Which of the following is the PRIMARY advantage of using virtualization technology for corporate applications?
Which of the following is MOST important for an IS auditor to confirm when reviewing an organization ' s incident response management program?
Which of the following is the BEST evidence that an organization ' s IT strategy is aligned lo its business objectives?
Which of the following methods provides the MOST reliable audit evidence?
Which of the following is the MOST important consideration when establishing vulnerability scanning on critical IT infrastructure?
Which type of review is MOST important to conduct when an IS auditor is informed that a recent internal exploitation of a bug has been discovered in a business application?
Which of the following is the MOST important consideration for a contingency facility?
Which of the following is the BEST way for an IS auditor to assess the design of an automated application control?
When drafting a disaster recovery strategy, what should be the MOST important outcome of a business impact analysis (BIA)?
Which of the following MUST be performed by senior audit leadership prior to starting an IS audit project?
When physical destruction IS not practical, which of the following is the MOST effective means of disposing of sensitive data on a hard disk?
When conducting an audit of an organization ' s use of AI in its customer service chatbots, an IS auditor should PRIMARILY focus on the:
The implementation of an IT governance framework requires that the board of directors of an organization:
Which of the following staff should an IS auditor interview FIRST to obtain a general overview of the various technologies used across different programs?
Which of the following is MOST important for an IS auditor to confirm when reviewing an organization ' s plans to implement robotic process automation (RPA > to automate routine business tasks?
Which of the following findings from a database security audit presents the GREATEST risk of critical security exposures?
In a review of the organization standards and guidelines for IT management, which of the following should be included in an IS development methodology?
The due date of an audit project is approaching, and the audit manager has determined that only 60% of the audit has been completed. Which of the following should the audit manager do FIRST?
Which of the following is the MOST effective control to mitigate unintentional misuse of authorized access?
Which of the following findings should be of GREATEST concern to an IS auditor assessing the risk associated with end-user computing (EUC) in an organization?
The PRIMARY purpose of a configuration management system is to:
An organization has established hiring policies and procedures designed specifically to ensure network administrators are well qualified Which type of control is in place?