Which of the following is the MOST effective control to mitigate against the risk of inappropriate activity by employees?
During the discussion of a draft audit report IT management provided suitable evidence that a process has been implemented for a control that had been concluded by the IS auditor as ineffective Which of the following is the auditor ' s BEST action?
Which of the following would provide the MOST important input during the planning phase for an audit on the implementation of a bring your own device (BYOD) program?
Which of the following should an IS auditor consider the MOST significant risk associated with a new health records system that replaces a legacy system?
Which of the following is MOST important for an IS auditor to verify when evaluating tne upgrade of an organization ' s enterprise resource planning (ERP) application?
Which of the following is the BEST indicator for measuring performance of IT help desk function?
The charging method that effectively encourages the MOST efficient use of IS resources is:
Which of the following is the PRIMARY advantage of using an automated security log monitoring tool over a manual review to monitor the use of privileged access?
An IS auditor finds that the cost of developing an application is now projected to significantly exceed the budget. Which of the following is the GREATEST risk to communicate to senior management?
Which of the following is the MOST important consideration when implementing a Zero Trust strategy for mobile, wireless, and Internet of Things (IoT) devices?
An organization wants to use virtual desktops to deliver corporate applications to its end users. Which of the following should an IS auditor recommend to prevent domain name system (DNS) poisoning in their cloud environment?
An organization has engaged a third party to implement an application to perform business-critical calculations. Which of the following is the MOST important process to help ensure the application provides accurate calculations?
An organization has purchased a new cloud-based application from a vendor. Which of the following should be the FIRST consideration when implementing the system?
Which of the following responses to risk associated with segregation of duties would incur the LOWEST initial cost?
When an intrusion into an organization network is deleted, which of the following should be done FIRST?
Which of the following is MOST likely to be a project deliverable of an agile software development methodology?
An IS auditor suspects an organization ' s computer may have been used to commit a crime. Which of the following is the auditor ' s BEST course of action?
Which of the following should be an IS auditor ' s PRIMARY focus when evaluating the response process for cybercrimes?
Which of the following BEST enables an organization to measure the current state of IT processes against leading practices?
An IS auditor learns a server administration team regularly applies workarounds to address repeated failures of critical data processing services Which of the following would BEST enable the organization to resolve this issue?
The FIRST step in an incident response plan is to:
Which of the following will MOST likely compromise the control provided By a digital signature created using RSA encryption?
Which of the following BEST guards against the risk of attack by hackers?
Backup procedures for an organization ' s critical data are considered to be which type of control?
Which of the following practices associated with capacity planning provides the GREATEST assurance that future incidents related to existing server performance will be prevented?
Which of the following is an IS auditor ' s BEST approach when prepanng to evaluate whether the IT strategy supports the organization ' s vision and mission?
During a follow-up audit, an IS auditor finds that senior management has implemented a different remediation action plan than what was previously agreed upon. Which of the following is the auditor ' s BEST course of action?
Which of the following BEST supports an organization ' s objective of restricting the use of removable storage devices by users?
Which of the following system redundancy configurations BEST improves system resiliency and reduces the possibility of a single cause of failure impacting system dependability?
Which of the following is the BEST methodology to use for estimating the complexity of developing a large business application?
An IS auditor is reviewing a contract for the outsourcing of IT facilities. If missing, which of the following should present the GREATEST concern to the auditor?
in a post-implantation Nation review of a recently purchased system it is MOST important for the iS auditor to determine whether the:
To improve efficiency, an organization has decided not to encrypt log files and plans to store the log data in native device formats. Which of the following is the GREATEST risk to the organization?
Which of the following is the MOST cost-effective way to determine the effectiveness of a business continuity plan (BCP)?
Which of the following would MOST effectively help to reduce the number of repealed incidents in an organization?
An internal audit department recently established a quality assurance (QA) program. Which of the following activities Is MOST important to include as part of the QA program requirements?
Which of the following controls helps to reduce fraud risk associated with robotic process automation (RPA)?
Which of the following would be MOST effective in detecting the presence of an unauthorized wireless access point on an internal network?
Which of the following is the PRIMARY role of the release plan?
Which of the following is an objective of IT project portfolio management?
Which type of attack poses the GREATEST risk to an organization ' s most sensitive data?
When auditing IT organizational structure, which of the following findings presents the GREATEST risk to an organization?
Which of the following should be of GREATEST concern to an IS auditor assessing the effectiveness of an organization ' s information security governance?
Which of the following MUST be completed as part of the annual audit planning process?
An organization has developed mature risk management practices that are followed across all departments What is the MOST effective way for the audit team to leverage this risk management maturity?
Who should be the FIRST to evaluate an audit report prior to issuing it to the project steering committee?
An IS auditor is conducting an IT governance audit and notices that many initiatives are managed informally by isolated project managers. Which of the following recommendations would have the GREATEST impact on improving the maturity of the IT team?
Which of the following system attack methods is executed by entering malicious code into the search box of a vulnerable website, causing the server to reveal restricted information?
Which of the following is MOST important for an IS auditor to review when evaluating the accuracy of a spreadsheet that contains several macros?
The use of which of the following is an inherent risk in the application container infrastructure?