An IS auditor will be testing accounts payable controls by performing data analytics on the entire population of transactions. Which of the following is MOST important for the auditor to confirm when sourcing the population data?
Which of the following user actions poses the GREATEST risk for inadvertently introducing malware into a local network?
Which of the following network topologies will provide the GREATEST fault tolerance?
An audit has identified that business units have purchased cloud-based applications without IPs support. What is the GREATEST risk associated with this situation?
Compared to developing a system in-house, acquiring a software package means that the need for testing by end users is:
An IS auditor discovers that validation controls m a web application have been moved from the server side into the browser to boost performance This would MOST likely increase the risk of a successful attack by.
What is the PRIMARY benefit of an audit approach which requires reported findings to be issued together with related action plans, owners, and target dates?
An internal audit team is deciding whether to use an audit management application hosted by a third party in a different country.
What should be the MOST important consideration related to the uploading of payroll audit documentation in the hosted
application?
Prior to a follow-up engagement, an IS auditor learns that management has decided to accept a level of residual risk related to an audit finding without remediation. The IS auditor is concerned about management ' s decision. Which of the following should be the IS auditor ' s NEXT course of action?
A disaster recovery plan (DRP) should include steps for:
Which of the following is the MOST important factor when an organization is developing information security policies and procedures?
Following a breach, what is the BEST source to determine the maximum amount of time before customers must be notified that their personal information may have been compromised?
Which of the following is the BEST indication of effective governance over IT infrastructure?
Which of the following should be of GREATEST concern for an IS auditor reviewing an organization ' s disaster recovery plan (DRP)?
Which of the following would BEST indicate the effectiveness of a security awareness training program?
What is the FIRST step when creating a data classification program?
Which of the following is MOST important when planning a network audit?
An IS auditor is reviewing a machine learning (ML) model that predicts the likelihood that a user will watch a certain movie. Which of the following would be of GREATEST concern to the auditor?
During an audit, an IT finding is agreed upon by all IT teams involved, but no team wants to be responsible for remediation or considers the finding within Its area of responsibility Which of the following is the IS auditor ' s BEST course of action?
An IS audit review identifies inconsistencies in privacy requirements across third-party service provider contracts. Which of the following is the BEST
recommendation to address this situation?
A post-implementation review was conducted by issuing a survey to users. Which of the following should be of GREATEST concern to an IS auditor?
Which of the following is the BEST performance indicator for the effectiveness of an incident management program?
Which of the following would BEST demonstrate that an effective disaster recovery plan (DRP) is in place?
Which of the following is necessary for effective risk management in IT governance?
An IS auditor is conducting a review of a data center. Which of the following observations could indicate an access control Issue?
Which of the following is an audit reviewer ' s PRIMARY role with regard to evidence?
An IS auditor is verifying the adequacy of an organization ' s internal controls and is concerned about potential circumvention of regulations. Which of the following is the BEST sampling method to use?
Which of the following would present the GREATEST concern during a review of internal audit quality assurance (QA) and continuous improvement processes?
What should an IS auditor do FIRST when management responses
to an in-person internal control questionnaire indicate a key internal
control is no longer effective?
The performance, risks, and capabilities of an IT infrastructure are BEST measured using a:
Which of the following findings would be of GREATEST concern to an IS auditor reviewing the security architecture of an organization that has just implemented a Zero Trust solution?
Which of the following would present the GREATEST concern during a review of internal audit quality assurance (QA) and continuous improvement processes?
Which of the following is the MOST reliable way for an IS auditor to evaluate the operational effectiveness of an organization ' s data loss prevention (DLP) controls?
An IS auditor has been asked to perform a post-implementation review of a newly developed system. When reviewing the testing phase results, the auditor observed that separate modules of the system tested correctly in the user acceptance testing (UAT) phase, but some features did not work as expected when moved to production. Which of the following was MOST likely omitted prior to implementation?
An IS auditor finds a segregation of duties issue in an enterprise resource planning (ERP) system. Which of the following is the BEST way to prevent the misconfiguration from recurring?
During an audit of a financial application, it was determined that many terminated users ' accounts were not disabled. Which of the following should be the IS auditor ' s NEXT step?
Which of the following is the PRIMARY benefit of implementing an IT capacity management process?
Which of the following provides the MOST reliable method of preventing unauthonzed logon?
When evaluating the design of controls related to network monitoring, which of the following is MOST important for an IS auditor to review?
An IS auditor is reviewing an organization ' s incident management processes and procedures. Which of the following observations should be the auditor ' s GREATEST concern?
While conducting a follow-up on an asset management audit, the IS auditor finds paid invoices for IT devices not recorded in the organization ' s inventory. Which of the following is the auditor ' s BEST course of action?
When evaluating information security governance within an organization, which of the following findings should be of MOST concern to an IS auditor?
The PRIMARY benefit of information asset classification is that it:
A configuration management audit identified that predefined automated procedures are used when deploying and configuring application infrastructure in a cloud-based
environment. Which of the following is MOST important for the IS auditor to review?
An IS auditor has been asked to provide support to the control self-assessment (CSA) program. Which of the following BEST represents the scope of the auditor’s role in the program?
Which of the following would be of MOST concern to an IS auditor reviewing a data loss prevention (DLP) solution implementation for endpoints?
Which of the following is the MOST important consideration when developing tabletop exercises within a cybersecurity incident response plan?
Which of the following is MOST important to ensure that electronic evidence collected during a forensic investigation will be admissible in future legal proceedings?
Which of the following is the MOST important responsibility of data owners when implementing a data classification process?
If a source code is not recompiled when program changes are implemented, which of the following is a compensating control to ensure synchronization of source and object?