Summer Sale - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dm70dm

CISA Certified Information Systems Auditor Questions and Answers

Questions 4

Which of the following weaknesses would have the GREATEST impact on the effective operation of a perimeter firewall?

Options:

A.

Use of stateful firewalls with default configuration

B.

Ad hoc monitoring of firewall activity

C.

Misconfiguration of the firewall rules

D.

Potential back doors to the firewall software

Buy Now
Questions 5

Using swipe cards to limit employee access to restricted areas requires implementing which additional control?

Options:

A.

Physical sign-in of all employees for access to restricted areas

B.

Implementation of additional PIN pads

C.

Periodic review of access profiles by management

D.

Installation of closed-circuit television (CCTV)

Buy Now

CISA Report Card

Questions 6

Which of the following BEST indicates that an incident management process is effective?

Options:

A.

Decreased number of calls to the help desk

B.

Decreased time for incident resolution

C.

Increased number of incidents reviewed by IT management

D.

Increased number of reported critical incidents

Buy Now
Questions 7

Which of the following is the MOST appropriate indicator of change management effectiveness?

Options:

A.

Time lag between changes to the configuration and the update of records

B.

Number of system software changes

C.

Time lag between changes and updates of documentation materials

D.

Number of incidents resulting from changes

Buy Now
Questions 8

An IS auditor assessing the controls within a newly implemented call center would First

Options:

A.

gather information from the customers regarding response times and quality of service.

B.

review the manual and automated controls in the call center.

C.

test the technical infrastructure at the call center.

D.

evaluate the operational risk associated with the call center.

Buy Now
Questions 9

An IS auditor has learned that access privileges are not periodically reviewed or updated. Which of the following would provide the BEST evidence to determine whether transactions have been executed by authorized employees?

Options:

A.

Audit trails

B.

Control totals

C.

Reconciliations

D.

Change logs

Buy Now
Questions 10

Which of the following business continuity activities prioritizes the recovery of critical functions?

Options:

A.

Business continuity plan (BCP) testing

B.

Business impact analysis (BIA)

C.

Disaster recovery plan (DRP) testing

D.

Risk assessment

Buy Now
Questions 11

An IS auditor learns the organization has experienced several server failures in its distributed environment. Which of the following is the BEST recommendation to limit the potential impact of server failures in the future?

Options:

A.

Redundant pathways

B.

Clustering

C.

Failover power

D.

Parallel testing

Buy Now
Questions 12

Which of the following would present the GREATEST concern during a review of internal audit quality assurance (QA) and continuous improvement processes?

Options:

A.

Improvement opportunities are not centrally tracked.

B.

The audit function is not subject to independent periodic external review.

C.

Substantive testing is not performed during the assessment phase of some audits.

D.

Quarterly reports are not distributed to the audit committee.

Buy Now
Questions 13

Which of the following physical controls provides the GREATEST assurance that only authorized individuals can access a data center?

Options:

A.

The data center is patrolled by a security guard.

B.

Access to the data center is monitored by video cameras.

C.

ID badges must be displayed before access is granted

D.

Access to the data center is controlled by a mantrap.

Buy Now
Questions 14

Which of the following is MOST important for an IS auditor to verify when evaluating an organization ' s firewall?

Options:

A.

Logs are being collected in a separate protected host

B.

Automated alerts are being sent when a risk is detected

C.

Insider attacks are being controlled

D.

Access to configuration files Is restricted.

Buy Now
Questions 15

To protect the organization from malware transmitted by physical media, IT administrators have disabled USB access for storage devices. Which of the following BEST describes this type of control?

Options:

A.

Corrective

B.

Administrative

C.

Preventive

D.

Physical

Buy Now
Questions 16

Which of the following would BEST indicate the effectiveness of a security awareness training program?

Options:

A.

Results of third-party social engineering tests

B.

Employee satisfaction with training

C.

Increased number of employees completing training

D.

Reduced unintentional violations

Buy Now
Questions 17

Which of the following provides the BEST assurance that a new database management system (DBMS) meets the requirements of local privacy regulations?

Options:

A.

Compliance audit

B.

Administrative audit

C.

General IT controls review

D.

Forensic audit

Buy Now
Questions 18

An organization has an acceptable use policy in place, but users do not formally acknowledge the policy. Which of the following is the MOST significant risk from this finding?

Options:

A.

Lack of data for measuring compliance

B.

Violation of industry standards

C.

Noncompliance with documentation requirements

D.

Lack of user accountability

Buy Now
Questions 19

Which of the following is the BEST way to determine the adequacy of controls for detecting inappropriate network activity in an organization?

Options:

A.

Reviewing SIEM reports of suspicious events in a timely manner

B.

Reviewing business application logs on a regular basis

C.

Troubleshooting connectivity issues routinely

D.

Installing a packet filtering firewall to block malicious traffic

Buy Now
Questions 20

An organization is permanently transitioning from onsite to fully remote business operations. When should the existing business impact analysis (BIA) be reviewed?

Options:

A.

During the next scheduled review

B.

At least one year after the transition

C.

As soon as the decision about the transition is announced

D.

As soon as the new operating model is in place

Buy Now
Questions 21

Which of the following controls BEST provides confidentiality and nonrepudiation for an online business looking for digital payment data security?

Options:

A.

Data Encryption Standard (DES)

B.

Advanced Encryption Standard (AES)

C.

Public Key Infrastructure (PKI)

D.

Virtual Private Network (VPN)

Buy Now
Questions 22

Which of the following is the BEST recommendation to drive accountability for achieving the desired outcomes specified in a benefits realization plan for an IT project?

Options:

A.

Document the dependencies between the project and other projects within the same program.

B.

Ensure that IT takes ownership for the delivery and tracking of all aspects of the benefits realization plan.

C.

Ensure that the project manager has formal authority for managing the benefits realization plan.

D.

Assign responsibilities, measures, and timelines for each identified benefit within the plan.

Buy Now
Questions 23

Cross-site scripting (XSS) attacks are BEST prevented through:

Options:

A.

application firewall policy settings.

B.

a three-tier web architecture.

C.

secure coding practices.

D.

use of common industry frameworks.

Buy Now
Questions 24

Capacity management enables organizations to:

Options:

A.

forecast technology trends

B.

establish the capacity of network communication links

C.

identify the extent to which components need to be upgraded

D.

determine business transaction volumes.

Buy Now
Questions 25

Which of the following is the BEST reason to implement a data retention policy?

Options:

A.

To establish a recovery point objective (RPO) for disaster recovery procedures

B.

To limit the liability associated with storing and protecting information

C.

To document business objectives for processing data within the organization

D.

To assign responsibility and ownership for data protection outside IT

Buy Now
Questions 26

Which of the following is the BEST control to mitigate the malware risk associated with an instant messaging (IM) system?

Options:

A.

Blocking attachments in IM

B.

Blocking external IM traffic

C.

Allowing only corporate IM solutions

D.

Encrypting IM traffic

Buy Now
Questions 27

An IS auditor reviewing an information processing environment decides to conduct external penetration testing. Which of the following is MOST appropriate to include in the audit scope for the organization to distinguish between the auditor ' s penetration attacks and actual attacks?

Options:

A.

Restricted host IP addresses of simulated attacks

B.

Testing techniques of simulated attacks

C.

Source IP addresses of simulated attacks

D.

Timing of simulated attacks

Buy Now
Questions 28

Which of the following is the BEST review for an IS auditor to conduct when a vulnerability has been exploited by an employee?

Options:

A.

Compliance audit

B.

Application security testing

C.

Forensic audit

D.

Penetration testing

Buy Now
Questions 29

Which of the following BEST helps monitor and manage operational logs to create value for an organization?

Options:

A.

Using automated tools to collect logs and raise alerts based on use cases

B.

Reporting results of log analyses to senior management for review

C.

Selecting logs only from critical operational systems and devices for monitoring

D.

Encrypting logs processed before archiving for defined retention periods

Buy Now
Questions 30

An IS auditor Is renewing the deployment of a new automated system Which of the following findings presents the MOST significant risk?

Options:

A.

The new system has resulted m layoffs of key experienced personnel.

B.

Users have not been trained on the new system.

C.

Data from the legacy system is not migrated correctly to the new system.

D.

The new system is not platform agnostic

Buy Now
Questions 31

An IS auditor is analyzing a sample of accesses recorded on the system log of an application. The auditor intends to launch an intensive investigation if one exception is found Which sampling method would be appropriate?

Options:

A.

Discovery sampling

B.

Judgmental sampling

C.

Variable sampling

D.

Stratified sampling

Buy Now
Questions 32

A small organization is experiencing rapid growth and plans to create a new information security policy. Which of the following is MOST relevant to creating the policy?

Options:

A.

Business objectives

B.

Business impact analysis (BIA)

C.

Enterprise architecture (EA)

D.

Recent incident trends

Buy Now
Questions 33

Which of the following would be the MOST significant finding when reviewing a data backup process?

Options:

A.

Recovery testing is not performed.

B.

The data backup process is not documented.

C.

Tapes are not consistently rotated offsite.

D.

The key to the data safe is kept by the backup administrator.

Buy Now
Questions 34

Which of the following is the BEST preventive control to protect the confidentiality of data on a corporate smartphone in the event it is lost?

Options:

A.

Biometric authentication for the device

B.

Remote data wipe program

C.

Encryption of the data stored on the device

D.

Password for device authentication

Buy Now
Questions 35

An IS auditor is reviewing an IT project and finds that an earned value analysis (EVA) is not regularly performed as part of project status reporting. Which of the following is the GREATEST risk resulting from this situation?

Options:

A.

Resources might not be assigned and prioritized in a timely manner.

B.

Time and budget overruns might not be identified in a timely manner.

C.

The project might not be compliant with project management standards.

D.

Business requirements may not be properly benchmarked.

Buy Now
Questions 36

Which of the following would be MOST effective in detecting the presence of an unauthorized wireless access point on an internal network?

Options:

A.

Continuous network monitoring

B.

Periodic network vulnerability assessments

C.

Review of electronic access logs

D.

Physical security reviews

Buy Now
Questions 37

An organization is planning to implement a work-from-home policy that allows users to work remotely as needed. Which of the following is the BEST solution for ensuring secure remote access to corporate resources?

Options:

A.

Additional firewall rules

B.

Multi-factor authentication

C.

Virtual private network (VPN)

D.

Virtual desktop

Buy Now
Questions 38

Which of the following is the PRIMARY purpose of a rollback plan for a system change?

Options:

A.

To ensure steps exist to remove the change if necessary

B.

To ensure testing can be re-performed if required

C.

To ensure a backup exists before implementing a change

D.

To ensure the system change is effective

Buy Now
Questions 39

Which of the following is MOST helpful for measuring benefits realization for a new system?

Options:

A.

Function point analysis

B.

Balanced scorecard review

C.

Post-implementation review

D.

Business impact analysis (BIA)

Buy Now
Questions 40

Upon completion of a penetration test with findings for an IT system, the NEXT step should be:

Options:

A.

analyzing all changes made to the system.

B.

vulnerability scanning and reconfirmation.

C.

remediation and retesting.

D.

maintaining the confidentiality of the testing report.

Buy Now
Questions 41

An IS auditor believes that management has accepted a level of residual risk that is not appropriate for the organization. Which of the following is the auditor’s MOST appropriate course of action?

Options:

A.

Submit a report informing the board of management’s decision to accept the risk.

B.

Discuss the matter with IS audit management and executive management.

C.

Include management’s response to accept the risk in the audit report and take no further action.

D.

Include the risk as a finding in the audit report but do not note management’s risk acceptance.

Buy Now
Questions 42

An organization is implementing a new system that supports a month-end business process. Which of the following implementation strategies would be MOST efficient to decrease business downtime?

Options:

A.

Big bang

B.

Phased

C.

Cutover

D.

Parallel

Buy Now
Questions 43

What is the MOST effective way to detect installation of unauthorized software packages by employees?

Options:

A.

Regular scanning of hard drives

B.

Communicating the policy to employees

C.

Logging of activity on the network

D.

Maintaining current antivirus software

Buy Now
Questions 44

What is MOST important to verify during an external assessment of network vulnerability?

Options:

A.

Update of security information event management (SIEM) rules

B.

Regular review of the network security policy

C.

Completeness of network asset inventory

D.

Location of intrusion detection systems (IDS)

Buy Now
Questions 45

An organization has decided to build a data warehouse using source data from several disparate systems to support strategic decision-making.

Which of the following is the BEST way to ensure the accuracy and completeness of the data used to support business decisions?

Options:

A.

The source data is pre-selected so that it already supports senior management ' s desired business decision outcome.

B.

The source data is from the current year of operations so that irrelevant data from prior years is not included.

C.

The source data is modified in the data warehouse to remove confidential or sensitive information.

D.

The source data is standardized and cleansed before loading into the data warehouse.

Buy Now
Questions 46

During planning for a cloud service audit, audit management becomes aware that the assigned IS auditor is unfamiliar with the technologies in use and their associated risks to the business. To ensure audit quality, which of the following actions should audit management consider FIRST?

Options:

A.

Conduct a follow-up audit after a suitable period has elapsed.

B.

Reschedule the audit assignment for the next financial year.

C.

Reassign the audit to an internal audit subject matter expert.

D.

Extend the duration of the audit to give the auditor more time.

Buy Now
Questions 47

The decision to accept an IT control risk related to data quality should be the responsibility of the:

Options:

A.

information security team.

B.

IS audit manager.

C.

chief information officer (CIO).

D.

business owner.

Buy Now
Questions 48

Users are complaining that a newly released enterprise resource planning (ERP) system is functioning too slowly. Which of the following tests during the quality assurance (QA) phase would have identified this concern?

Options:

A.

Stress

B.

Parallel

C.

Regression

D.

Interface

Buy Now
Questions 49

Which of the following should an IS auditor be MOST concerned with when a system uses RFID?

Options:

A.

Scalability

B.

Maintainability

C.

Nonrepudiation

D.

Privacy

Buy Now
Questions 50

Which of the following MUST be completed as part of the annual audit planning process?

Options:

A.

Business impact analysis (BIA)

B.

Fieldwork

C.

Risk assessment

D.

Risk control matrix

Buy Now
Questions 51

In an environment where data virtualization is used, which of the following provides the BEST disaster recovery solution?

Options:

A.

Onsite disk-based backup systems

B.

Tape-based backup systems

C.

Virtual tape library

D.

Redundant array of independent disks (RAID)

Buy Now
Questions 52

The PRIMARY reason to perform a capacity management review of technology resources is to ensure that:

Options:

A.

infrastructure and processes can meet current and future business needs.

B.

available capacity is operated in a secure and compliant manner.

C.

technology resource acquisitions align with current needed capacity.

D.

technology resource capacity requirements are properly defined.

Buy Now
Questions 53

Which of the following should an IS auditor recommend be done FIRST when an organization is planning to implement an IT compliance program?

Options:

A.

Identify staff training needs related to compliance requirements.

B.

Analyze historical compliance-related audit findings.

C.

Research and purchase an industry-recognized IT compliance tool

D.

Identify applicable laws, regulations, and standards.

Buy Now
Questions 54

Which of the following is the MOST important prerequisite for implementing a data loss prevention (DLP) tool?

Options:

A.

Requiring users to save files in secured folders instead of a company-wide shared drive

B.

Reviewing data transfer logs to determine historical patterns of data flow

C.

Developing a DLP policy and requiring signed acknowledgment by users

D.

Identifying where existing data resides and establishing a data classification matrix

Buy Now
Questions 55

A senior auditor is reviewing work papers prepared by a junior auditor indicating that a finding was removed after the auditee said they corrected the problem. Which of the following is the senior auditor s MOST appropriate course of action?

Options:

A.

Ask the auditee to retest

B.

Approve the work papers as written

C.

Have the finding reinstated

D.

Refer the issue to the audit director

Buy Now
Questions 56

Which of the following is MOST important to ensure when planning a black box penetration test?

Options:

A.

The management of the client organization is aware of the testing.

B.

The test results will be documented and communicated to management.

C.

The environment and penetration test scope have been determined.

D.

Diagrams of the organization ' s network architecture are available.

Buy Now
Questions 57

During an incident management audit, an IS auditor finds that several similar incidents were logged during the audit period. Which of the following is the auditor ' s MOST important course of action?

Options:

A.

Document the finding and present it to management.

B.

Determine if a root cause analysis was conducted.

C.

Confirm the resolution time of the incidents.

D.

Validate whether all incidents have been actioned.

Buy Now
Questions 58

Which of the following should be the PRIMARY objective of conducting an audit follow-up of management action plans?

Options:

A.

To verify that risks listed in the audit report have been properly mitigated

B.

To identify new risks and controls for the organizationTo ensure senior management is aware of the audit findingsTo align the management action plans with business requirements

Buy Now
Questions 59

An IS auditor has been asked to review the quality of data in a general ledger system. Which of the following would provide the auditor with the MOST meaningful results?

Options:

A.

Discussion of the largest account values with business owners

B.

Integrity checks against source documentation

C.

System vulnerability assessment

D.

Interviews with system owners and operators

Buy Now
Questions 60

An organization ' s networking team wants to route data between two virtual local area networks (VLANs). Which type of device is the BEST recommendation for installation of the VLANs?

Options:

A.

Switch

B.

Firewall

C.

Bridge

D.

Hub

Buy Now
Questions 61

An organization has implemented a distributed security administration system to replace the previous centralized one. Which of the following presents the GREATEST potential concern?

Options:

A.

Security procedures may be inadequate to support the change

B.

A distributed security system is inherently a weak security system

C.

End-user acceptance of the new system may be difficult to obtain

D.

The new system will require additional resources

Buy Now
Questions 62

Which of the following is the MOST appropriate control to ensure integrity of online orders?

Options:

A.

Data Encryption Standard (DES)

B.

Digital signature

C.

Public key encryption

D.

Multi-factor authentication

Buy Now
Questions 63

Recovery facilities providing a redundant combination of Internet connections to the local communications loop is an example of which type of telecommunications continuity?

Options:

A.

Voice recovery

B.

Alternative routing

C.

Long-haul network diversity

D.

Last-mile circuit protection

Buy Now
Questions 64

Which of the following MOST effectively minimizes downtime during system conversions?

Options:

A.

Phased approach

B.

Direct cutover

C.

Pilot study

D.

Parallel run

Buy Now
Questions 65

Which of the following is an audit reviewer ' s PRIMARY role with regard to evidence?

Options:

A.

Ensuring unauthorized individuals do not tamper with evidence after it has been captured

B.

Ensuring evidence is sufficient to support audit conclusions

C.

Ensuring appropriate statistical sampling methods were used

D.

Ensuring evidence is labeled to show it was obtained from an approved source

Buy Now
Questions 66

An organization is concerned with meeting new regulations for protecting data confidentiality and asks an IS auditor to evaluate their procedures for transporting data. Which of the

following would BEST support the organization ' s objectives?

Options:

A.

Cryptographic hashes

B.

Virtual local area network (VLAN)

C.

Encryption

D.

Dedicated lines

Buy Now
Questions 67

During the implementation of a new system, an IS auditor must assess whether certain automated calculations comply with the regulatory requirements Which of the following is the BEST way to obtain this assurance?

Options:

A.

Review sign-off documentation

B.

Review the source code related to the calculation

C.

Re-perform the calculation with audit software

D.

Inspect user acceptance lest (UAT) results

Buy Now
Questions 68

Which of the following is the MAIN objective of enterprise architecture (EA) governance?

Options:

A.

To ensure new processes and technologies harmonize with existing processes

B.

To ensure the EA can adapt to emerging technology trends

C.

To ensure the EA is compliant with local laws and regulations

D.

To ensure new initiatives produce an acceptable return on investment (ROI)

Buy Now
Questions 69

At the end of each business day, a business-critical application generates a report of financial transac-tions greater than a certain value, and an employee

then checks these transactions for errors. What type of control is in place?

Options:

A.

Detective

B.

Preventive

C.

Corrective

D.

Deterrent

Buy Now
Questions 70

Who is PRIMARILY responsible for the design of IT controls to meet control objectives?

Options:

A.

Risk management

B.

Business management

C.

IT manager

D.

Internal auditor

Buy Now
Questions 71

An IS auditor is reviewing the operational database management of an organization that uses cloud systems for hosting. Which of the following should be the auditor ' s PRIMARY area of focus?

Options:

A.

Cloud vendor security certifications

B.

Auto-scaling of provisioning costs

C.

Security settings configuration

D.

Large-scale data transfers

Buy Now
Questions 72

Which of the following observations should be of GREATEST concern to an IS auditor reviewing an organization’s enterprise architecture (EA) program?

Options:

A.

The architecture review board is chaired by the CIO

B.

IT application owners have sole responsibility for architecture approval

C.

The EA program governs projects that are not IT-related

D.

Information security requirements are reviewed by the EA program

Buy Now
Questions 73

Which of the following is the GREATEST risk related to the use of virtualized environments?

Options:

A.

The host may be a potential single point of failure within the system.

B.

There may be insufficient processing capacity to assign to guests.

C.

There may be increased potential for session hijacking.

D.

Ability to change operating systems may be limited.

Buy Now
Questions 74

Which of the following should be an IS auditor ' s PRIMARY focus when developing a risk-based IS audit program?

Options:

A.

Portfolio management

B.

Business plans

C.

Business processes

D.

IT strategic plans

Buy Now
Questions 75

An IS auditor is conducting an IT governance audit and notices many initiatives are managed informally by isolated project managers. Which of the following recommendations would have the GREATEST impact on improving the maturity of the IT team?

Options:

A.

Schedule a follow-up audit in the next year to confirm whether IT processes have matured.

B.

Create an interdisciplinary IT steering committee to oversee IT prioritization and spending.

C.

Document and track all IT decisions in a project management tool.

D.

Discontinue all current IT projects until formal approval is obtained and documented.

Buy Now
Questions 76

Which of the following is the BEST indicator of the effectiveness of an organization ' s incident response program?

Options:

A.

Number of successful penetration tests

B.

Percentage of protected business applications

C.

Financial impact per security event

D.

Number of security vulnerability patches

Buy Now
Questions 77

Which of the following is the BEST control to mitigate the risk of shadow IT?

Options:

A.

Intrusion detection system (IDS)

B.

Vendor management reviews

C.

Vulnerability scanning

D.

Security awareness training

Buy Now
Questions 78

Which of the following is MOST important to ensure when planning a black-box penetration test?

Options:

A.

The tactics, techniques, and procedures have been determined.

B.

Diagrams of the organization’s network architecture are available.

C.

The test results will be documented and communicated to management.

D.

The management of the client organization has approved the scope of testing.

Buy Now
Questions 79

Which of the following is the MAIN purpose of an information security management system?

Options:

A.

To identify and eliminate the root causes of information security incidents

B.

To enhance the impact of reports used to monitor information security incidents

C.

To keep information security policies and procedures up-to-date

D.

To reduce the frequency and impact of information security incidents

Buy Now
Questions 80

For security awareness training to be MOST effective, management should ensure the training:

Options:

A.

covers all aspects of the IT environment.

B.

is conducted by IT personnel.

C.

is tailored to specific groups.

D.

occurs annually.

Buy Now
Questions 81

A review of IT interface controls finds an organization does not have a process to identify and correct records that do not get transferred to the receiving system Which of the following is the IS auditors BEST recommendation?

Options:

A.

Enable automatic encryption decryption and electronic signing of data files

B.

implement software to perform automatic reconciliations of data between systems

C.

Have coders perform manual reconciliation of data between systems

D.

Automate the transfer of data between systems as much as feasible

Buy Now
Questions 82

An organization ' s IT risk assessment should include the identification of:

Options:

A.

vulnerabilities

B.

compensating controls

C.

business needs

D.

business process owners

Buy Now
Questions 83

Which of the following should be done FIRST to ensure the secure configuration of new IT assets in an organization?

Options:

A.

Identify and remediate vulnerabilities before deploying new IT assets.

B.

Define and implement hardening standards.

C.

Scan new IT assets for security vulnerabilities.

D.

Purchase security tools to configure new IT assets.

Buy Now
Questions 84

Which of the following network communication protocols is used by network devices such as routers to send error messages and operational information indicating success or failure when communicating with another IP address?

Options:

A.

Transmission Control Protocol/Internet Protocol (TCP/IP)

B.

Internet Control Message Protocol

C.

Multipurpose Transaction Protocol

D.

Point-to-Point Tunneling Protocol

Buy Now
Questions 85

Backup procedures for an organization ' s critical data are considered to be which type of control?

Options:

A.

Directive

B.

Corrective

C.

Detective

D.

Compensating

Buy Now
Questions 86

Which of the following network topologies will provide the GREATEST fault tolerance?

Options:

A.

Star configuration

B.

Ring configuration

C.

Bus configuration

D.

Mesh configuration

Buy Now
Questions 87

Which of the following is the GREATEST benefit of an effective data classification process?

Options:

A.

Data custodians are identified.

B.

Data retention periods are well defined

C.

Data is protected according to its sensitivity

D.

Appropriate ownership over data is assigned

Buy Now
Questions 88

Due to limited storage capacity, an organization has decided to reduce the actual retention period for media containing completed low-value transactions. Which of the following is MOST important for the organization to ensure?

Options:

A.

The policy includes a strong risk-based approach.

B.

The retention period allows for review during the year-end audit.

C.

The total transaction amount has no impact on financial reporting.

D.

The retention period complies with data owner responsibilities.

Buy Now
Questions 89

Which of the following BEST facilitates the successful implementation of IT performance monitoring?

Options:

A.

Determining goals for IT resources and processes

B.

Identifying tools to automate performance measurement

C.

Establishing templates for periodic reporting to management

D.

Adopting global standards and measurement norms

Buy Now
Questions 90

Which of the following is the MOST important area of focus for an IS auditor when developing a risk-based audit strategy?

Options:

A.

Critical business applications

B.

Business processes

C.

Existing IT controls

D.

Recent audit results

Buy Now
Questions 91

Attribute sampling is BEST suited to estimate:

Options:

A.

the true monetary value of a population.

B.

the total error amount in the population.

C.

the degree of compliance with approved procedures

D.

standard deviation from the mean.

Buy Now
Questions 92

Which of the following would present the GREATEST risk within a release management process for a new application?

Options:

A.

Procedures are not updated to coincide with the production release schedule.

B.

Code is deployed to production without authorization.

C.

A newly added program may overwrite existing production files.

D.

An identified bug was not resolved.

Buy Now
Questions 93

Which of the following would be of MOST concern for an IS auditor evaluating the design of an organization ' s incident management processes?

Options:

A.

Service management standards are not followed.

B.

Expected time to resolve incidents is not specified.

C.

Metrics are not reported to senior management.

D.

Prioritization criteria are not defined.

Buy Now
Questions 94

Which of the following is the BEST way to mitigate the impact of ransomware attacks?

Options:

A.

Invoking the disaster recovery plan (DRP)

B.

Backing up data frequently

C.

Paying the ransom

D.

Requiring password changes for administrative accounts

Buy Now
Questions 95

An IS auditor is conducting a post-implementation review of an enterprise resource planning (ERP) system. End users indicated concerns with the accuracy of critical automatic calculations made by the system. The auditor ' s FIRST course of action should be to:

Options:

A.

review recent changes to the system.

B.

verify completeness of user acceptance testing (UAT).

C.

verify results to determine validity of user concerns.

D.

review initial business requirements.

Buy Now
Questions 96

What should an IS auditor ensure when a financial organization intends to utilize production data in the testing environment?

Options:

A.

The data utilized is de-identified.

B.

The data utilized is accurate.

C.

The data utilized is complete.

D.

The data utilized is current.

Buy Now
Questions 97

During the design phase of a software development project, the PRIMARY responsibility of an IS auditor is to evaluate the:

Options:

A.

Future compatibility of the application.

B.

Proposed functionality of the application.

C.

Controls incorporated into the system specifications.

D.

Development methodology employed.

Buy Now
Questions 98

Which of the following will be the MOST effective method to verify that a service vendor keeps control levels as required by the client?

Options:

A.

Conduct periodic on-site assessments using agreed-upon criteria.

B.

Periodically review the service level agreement (SLA) with the vendor.

C.

Conduct an unannounced vulnerability assessment of vendor ' s IT systems.

D.

Obtain evidence of the vendor ' s control self-assessment (CSA).

Buy Now
Questions 99

Which of the following is an IS auditor ' s BEST recommendation to mitigate the risk of eavesdropping

associated with an application programming interface (API) integration implementation?

Options:

A.

Encrypt the extensible markup language (XML) file.

B.

Implement Transport Layer Security (TLS).

C.

Implement Simple Object Access Protocol (SOAP).

D.

Mask the API endpoints.

Buy Now
Questions 100

Which of the following is the MOST important course of action to ensure a cloud access security broker (CASB) effectively detects and responds to threats?

Options:

A.

Monitoring data movement

B.

Implementing a long-term CASB contract

C.

Reviewing the information security policy

D.

Evaluating firewall effectiveness

Buy Now
Questions 101

Which of the following would MOST effectively help to reduce the number of repealed incidents in an organization?

Options:

A.

Testing incident response plans with a wide range of scenarios

B.

Prioritizing incidents after impact assessment.

C.

Linking incidents to problem management activities

D.

Training incident management teams on current incident trends

Buy Now
Questions 102

Which of the following is the MOST effective way for an organization to project against data loss?

Options:

A.

Limit employee internet access.

B.

Implement data classification procedures.

C.

Review firewall logs for anomalies.

D.

Conduct periodic security awareness training.

Buy Now
Questions 103

Which of the following BEST supports the effectiveness of a compliance program?

Options:

A.

Implementing an awareness plan regarding compliance regulation requirements

B.

Implementing a governance, risk, and compliance (GRC) tool to track compliance to regulations

C.

Assessing and tracking all compliance audit findings

D.

Monitoring which compliance regulations apply to the organization

Buy Now
Questions 104

Which of the following are used in a firewall to protect the entity ' s internal resources?

Options:

A.

Remote access servers

B.

Secure Sockets Layers (SSLs)

C.

Internet Protocol (IP) address restrictions

D.

Failover services

Buy Now
Questions 105

Which of the following helps to ensure the integrity of data for a system interface?

Options:

A.

System interface testing

B.

user acceptance testing (IJAT)

C.

Validation checks

D.

Audit logs

Buy Now
Questions 106

Malicious program code was found in an application and corrected prior to release into production. After the release, the same issue was reported. Which of the following is the IS auditor ' s BEST recommendation?

Options:

A.

Ensure corrected program code is compiled in a dedicated server.

B.

Ensure change management reports are independently reviewed.

C.

Ensure programmers cannot access code after the completion of program edits.

D.

Ensure the business signs off on end-to-end user acceptance test (UAT) results.

Buy Now
Questions 107

Which of the following is the MOST significant risk when an application uses individual end-user accounts to access the underlying database?

Options:

A.

Multiple connects to the database are used and slow the process_

B.

User accounts may remain active after a termination.

C.

Users may be able to circumvent application controls.

D.

Application may not capture a complete audit trail.

Buy Now
Questions 108

Which of the following is the MOST important consideration to facilitate prosecution of a perpetrator after a cybercrime?

Options:

A.

An active intrusion detection system (IDS)

B.

Professional collection of unaltered evidence

C.

Reporting to the internal legal department

D.

Immediate law enforcement involvement

Buy Now
Questions 109

IS management has recently disabled certain referential integrity controls in the database management system (DBMS) software to provide users increased query performance. Which of the following controls will MOST effectively compensate for the lack of referential integrity?

Options:

A.

More frequent data backups

B.

Periodic table link checks

C.

Concurrent access controls

D.

Performance monitoring tools

Buy Now
Questions 110

Which of the following risks is BEST mitigated by implementing an automated three-way match?

Options:

A.

Inaccurate customer records

B.

Purchase order delays

C.

lnaccurate customer discounts

D.

Invalid payment processing

Buy Now
Questions 111

Which of the following should be of GREATEST concern to an IS auditor reviewing controls around an AI system in an organization?

Options:

A.

Development of the knowledge base was outsourced to vendors.

B.

The policy and procedure guide and its decision logic were reviewed once annually.

C.

Contracted developers have access to the knowledge base for maintenance purposes.

D.

Basic assumptions and formulas used to develop the decision logic were not documented.

Buy Now
Questions 112

Which of the following is the PRIMARY role of the IS auditor m an organization ' s information classification process?

Options:

A.

Securing information assets in accordance with the classification assigned

B.

Validating that assets are protected according to assigned classification

C.

Ensuring classification levels align with regulatory guidelines

D.

Defining classification levels for information assets within the organization

Buy Now
Questions 113

Which type of review is MOST important to conduct when an IS auditor is informed that a recent internal exploitation of a bug has been discovered in a business application?

Options:

A.

Penetration testing

B.

Application security testing

C.

Forensic audit

D.

Server security audit

Buy Now
Questions 114

Which of the following is MOST important to consider when reviewing an organization ' s defined data backup and restoration procedures?

Options:

A.

Business continuity plan (BCP)

B.

Recovery point objective (RPO)

C.

Mean time to restore (MTTR)

D.

Mean time between failures (MTBF)

Buy Now
Questions 115

An IS auditor finds that an organization ' s data loss prevention (DLP) system is configured to use vendor default settings to identify violations. The auditor ' s MAIN concern should be that:

Options:

A.

violation reports may not be reviewed in a timely manner.

B.

a significant number of false positive violations may be reported.

C.

violations may not be categorized according to the organization ' s risk profile.

D.

violation reports may not be retained according to the organization ' s risk profile.

Buy Now
Questions 116

During an audit of a reciprocal disaster recovery agreement between two companies, the IS auditor would be MOST concerned with the:

Options:

A.

allocation of resources during an emergency.

B.

frequency of system testing.

C.

differences in IS policies and procedures.

D.

maintenance of hardware and software compatibility.

Buy Now
Questions 117

Which of following is MOST important to determine when conducting a post-implementation review?

Options:

A.

Whether the solution architecture compiles with IT standards

B.

Whether success criteria have been achieved

C.

Whether the project has been delivered within the approved budget

D.

Whether lessons teamed have been documented

Buy Now
Questions 118

An IS auditor finds a high-risk vulnerability in a public-facing web server used to process online customer payments. The IS auditor should FIRST

Options:

A.

document the exception in an audit report.

B.

review security incident reports.

C.

identify compensating controls.

D.

notify the audit committee.

Buy Now
Questions 119

Which of the following is the PRIMARY advantage of using visualization technology for corporate applications?

Options:

A.

Improved disaster recovery

B.

Better utilization of resources

C.

Stronger data security

D.

Increased application performance

Buy Now
Questions 120

Which of the following is the BEST reason for an IS auditor to emphasize to management the importance of using an IT governance framework?

Options:

A.

Frameworks enable IT benchmarks against competitors

B.

Frameworks can be tailored and optimized for different organizations

C.

Frameworks help facilitate control self-assessments (CSAs)

D.

Frameworks help organizations understand and manage IT risk

Buy Now
Questions 121

The IS auditor has recommended that management test a new system before using it in production mode. The BEST approach for management in developing a test plan is to use processing parameters that are:

Options:

A.

randomly selected by a test generator.

B.

provided by the vendor of the application.

C.

randomly selected by the user.

D.

simulated by production entities and customers.

Buy Now
Questions 122

Which of the following management decisions presents the GREATEST risk associated with data leakage?

Options:

A.

There is no requirement for desktops to be encrypted

B.

Staff are allowed to work remotely

C.

Security awareness training is not provided to staff

D.

Security policies have not been updated in the past year

Buy Now
Questions 123

Which of the following MUST be performed by senior audit leadership prior to starting an IS audit project?

Options:

A.

Signoff on the audit scope.

B.

Attend planning walk-throughs.

C.

Review audit planning documents.

D.

Meet with auditee leadership.

Buy Now
Questions 124

An organization used robotic process automation (RPA) technology to develop software bots that extract data from various sources for input into a legacy financial application. Which of the following should be of GREATEST concern to an IS auditor when reviewing the software bot job scheduling and production process automation?

Options:

A.

Minor overrides were not authorized by the business

B.

Software bots were incapable of learning from training data

C.

Software bots were programmed to record all user interactions, including mouse tracking

D.

Unauthorized modifications were made to the scripts to improve performance

Buy Now
Questions 125

A senior IS auditor suspects that a PC may have been used to perpetrate fraud in a finance department. The auditor should FIRST report this suspicion to:

Options:

A.

audit management.

B.

the police.

C.

the audit committee.

D.

auditee line management.

Buy Now
Questions 126

Which of the following is MOST important when creating a forensic image of a hard drive?

Options:

A.

Requiring an independent third party be present while imaging

B.

Securing a backup copy of the hard drive

C.

Generating a content hash of the hard drive

D.

Choosing an industry-leading forensics software tool

Buy Now
Questions 127

When testing the adequacy of tape backup procedures, which step BEST verifies that regularly scheduled Backups are timely and run to completion?

Options:

A.

Observing the execution of a daily backup run

B.

Evaluating the backup policies and procedures

C.

Interviewing key personnel evolved In the backup process

D.

Reviewing a sample of system-generated backup logs

Buy Now
Questions 128

While evaluating the data classification process of an organization, an IS auditor ' s PRIMARY focus should be on whether:

Options:

A.

data classifications are automated.

B.

a data dictionary is maintained.

C.

data retention requirements are clearly defined.

D.

data is correctly classified.

Buy Now
Questions 129

An organization produces control reports with a desktop application that accesses data in the central production database. Which of the following would give an IS auditor concern about the reliability of these reports?

Options:

A.

The reports are printed by the same person who reviews them.

B.

The reports are available to all end users.

C.

The report definitions file is not included in routine backups.

D.

The report definitions can be modified by end users.

Buy Now
Questions 130

A computer forensic audit is MOST relevant in which of the following situations?

Options:

A.

Inadequate controls in the IT environment

B.

Mismatches in transaction data

C.

Missing server patches

D.

Data loss due to hacking of servers

Buy Now
Questions 131

When conducting an audit of an organization ' s use of AI in its customer service chatbots, an IS auditor should PRIMARILY focus on the:

Options:

A.

Safeguarding of personal data processing by the AI system.

B.

AI system ' s compliance with industry security standards.

C.

Speed and accuracy of chatbot responses to customer queries.

D.

AI system ' s ability to handle multiple customer queries at once.

Buy Now
Questions 132

In which of the following sampling methods is the entire sample considered to be irregular if a single error is found?

Options:

A.

Discovery sampling

B.

Variable sampling

C.

Stop-or-go sampling

D.

Judgmental sampling

Buy Now
Questions 133

Which of the following is the BEST recommendation by an IS auditor to prevent unauthorized access to Internet of Things (loT) devices ' ?

Options:

A.

loT devices should only be accessible from the host network.

B.

loT devices should log and alert on access attempts.

C.

IoT devices should require identification and authentication.

D.

loT devices should monitor the use of device system accounts.

Buy Now
Questions 134

Which of the following is the BEST compensating control when segregation of duties is lacking in a small IS department?

Options:

A.

Background checks

B.

User awareness training

C.

Transaction log review

D.

Mandatory holidays

Buy Now
Questions 135

Which of the following is the MOST important area of focus for an IS auditor assessing the management of cryptographic keys in a public key infrastructure (PKI)?

Options:

A.

Checking the subscription of the key management system

B.

Identifying unusual activities by the key processors

C.

Reviewing key compromise detection activities

D.

Reviewing PKI documentation

Buy Now
Questions 136

Which of the following is an IS auditor ' s BEST recommendation to protect an organization from attacks when its file server needs to be accessible to external users?

Options:

A.

Enforce a secure tunnel connection.

B.

Enhance internal firewalls.

C.

Set up a demilitarized zone (DMZ).

D.

Implement a secure protocol.

Buy Now
Questions 137

Which of the following is the MOST important consideration of any disaster response plan?

Options:

A.

Lost revenue

B.

Personnel safety

C.

IT asset protection

D.

Adequate resource capacity

Buy Now
Questions 138

Which of the following user actions poses the GREATEST risk for inadvertently introducing malware into a local network?

Options:

A.

Uploading a file onto an internal server

B.

Viewing a hypertext markup language (HTML) document

C.

Downloading a file from an enterprise file share

D.

Opening an email attachment from an external account

Buy Now
Questions 139

An IS auditor is reviewing an organization ' s system development life cycle (SDLC) Which of the following MUST be included in the review?

Options:

A.

Ownership of the system quality management plan

B.

Utilization of standards in the system development processes and procedures

C.

Validation that system development processes adhere to quality standards

D.

Definition of quality attributes to be associated with the system

Buy Now
Questions 140

Which of the following is the BEST justification for deferring remediation testing until the next audit?

Options:

A.

The auditor who conducted the audit and agreed with the timeline has left the organization.

B.

Management ' s planned actions are sufficient given the relative importance of the observations.

C.

Auditee management has accepted all observations reported by the auditor.

D.

The audit environment has changed significantly.

Buy Now
Questions 141

An IS audit learn is evaluating the documentation related to the most recent application user-access review performed by IT and business management It is determined that the user list was not system-generated. Which of the following should be the GREATEST concern?

Options:

A.

Availability of the user list reviewed

B.

Confidentiality of the user list reviewed

C.

Source of the user list reviewed

D.

Completeness of the user list reviewed

Buy Now
Questions 142

A new regulation requires organizations to report significant security incidents to the regulator within 24 hours of identification. Which of the following is the IS auditor ' s BEST recommendation to facilitate compliance with the regulation?

Options:

A.

Include the requirement in the incident management response plan.

B.

Establish key performance indicators (KPIs) for timely identification of security incidents.

C.

Enhance the alert functionality of the intrusion detection system (IDS).

D.

Engage an external security incident response expert for incident handling.

Buy Now
Questions 143

A sample for testing must include the 80 largest client balances and a random sample of the rest. What should the IS auditor recommend?

Options:

A.

Query the database.

B.

Develop an integrated test facility (ITF).

C.

Use generalized audit software.

D.

Leverage a random number generator.

Buy Now
Questions 144

To ensure confidentiality through the use of asymmetric encryption, a message is encrypted with which of the following?

Options:

A.

Recipient ' s public key

B.

Sender ' s private key

C.

Sender ' s public key

D.

Recipient ' s private key

Buy Now
Questions 145

In an environment that automatically reports all program changes, which of the following is the MOST efficient way to detect unauthorized changes to production programs?

Options:

A.

Reviewing the last compile date of production programs

B.

Manually comparing code in production programs to controlled copies

C.

Periodically running and reviewing test data against production programs

D.

Verifying user management approval of modifications

Buy Now
Questions 146

What should be the PRIMARY basis for selecting which IS audits to perform in the coming year?

Options:

A.

Senior management ' s request

B.

Prior year ' s audit findings

C.

Organizational risk assessment

D.

Previous audit coverage and scope

Buy Now
Questions 147

Which of the following BEST enables an organization to verify whether an encrypted message sent by a client has been altered?

Options:

A.

The digital signature

B.

The message header

C.

The date and time stamp of the received message

D.

The sender ' s private key

Buy Now
Questions 148

Which of the following is the PRIMARY reason for an organization to conduct a formal information security audit?

Options:

A.

To align information security strategies with business objectives.

B.

To identify material information security vulnerabilities.

C.

To reduce information security software licensing costs.

D.

To monitor information security team productivity.

Buy Now
Questions 149

An IS auditor is auditing the operating effectiveness of weekly user access reviews. Of the five weekly reviews sampled, one has not been signed or dated. What is the MAIN reason to note this observation as a finding?

Options:

A.

The review may not be accurate.

B.

The review may not contain the appropriate content.

C.

The review may not be in compliance with industry standards.

D.

The review may not have been performed.

Buy Now
Questions 150

Which of the following responses to risk associated with separation of duties would incur the LOWEST initial cost?

Options:

A.

Risk mitigation

B.

Risk acceptance

C.

Risk transference

D.

Risk reduction

Buy Now
Questions 151

Management has requested a post-implementation review of a newly implemented purchasing package to determine to what extent business requirements are being met. Which of the following is MOST likely to be assessed?

Options:

A.

Purchasing guidelines and policies

B.

Implementation methodology

C.

Results of line processing

D.

Test results

Buy Now
Questions 152

Which of the following represents the HIGHEST level of maturity of an information security program?

Options:

A.

A training program is in place to promote information security awareness.

B.

A framework is in place to measure risks and track effectiveness.

C.

Information security policies and procedures are established.

D.

The program meets regulatory and compliance requirements.

Buy Now
Questions 153

Due to system limitations, segregation of duties (SoD) cannot be enforced in an accounts payable system. Which of the following is the IS auditor ' s BEST recommendation for a compensating control?

Options:

A.

Require written authorization for all payment transactions

B.

Restrict payment authorization to senior staff members.

C.

Reconcile payment transactions with invoices.

D.

Review payment transaction history

Buy Now
Questions 154

One advantage of managing an entire collection of projects as a portfolio is that it highlights the need to:

Options:

A.

Inform users about all ongoing projects.

B.

Manage the quality of each project.

C.

Identify dependencies between projects.

D.

Manage the risk of each individual project.

Buy Now
Questions 155

Which of the following would be the GREATEST concern to an IS auditor when reviewing the outsourcing contract for an organization ' s cloud service provider?

Options:

A.

There is no change management process defined in the contract.

B.

There are no procedures for incident escalation.

C.

There is no dispute resolution process defined in the contract.

D.

There is no right-to-audit clause defined in the contract.

Buy Now
Questions 156

Which of the following is the GREATEST risk that could result from a contracted penetration tester attempting SQL injection techniques on the production system?

Options:

A.

The tester ' s access could be elevated.

B.

Events could be improperly logged.

C.

Sensitive data could be exfiltrated.

D.

Production data could be altered.

Buy Now
Questions 157

Which of the following should be an IS auditor ' s PRIMARY consideration when determining which issues to include in an audit report?

Options:

A.

Professional skepticism

B.

Management ' s agreement

C.

Materiality

D.

Inherent risk

Buy Now
Questions 158

A small IT department has embraced DevOps, which allows members of this group to deploy code to production and maintain some development access to automate releases. Which of the following is the MOST effective control?

Options:

A.

Enforce approval prior to deployment by a member of the team who has not taken part in the development.

B.

The DevOps team provides an annual policy acknowledgment that they did not develop and deploy the same code.

C.

Annual training reinforces the need to maintain segregation between developers and deployers of code

D.

The IT compliance manager performs weekly reviews to ensure the same person did not develop and deploy code.

Buy Now
Questions 159

Following a discussion on the results of a recent audit engagement, the process owner of the audited area has provided an action plan addressing the gaps and recommendations. The auditor disagrees with some of the responses where the process owner is accepting a level of residual risk that is not within the organization ' s risk appetite. What is the auditor ' s BEST course of action?

Options:

A.

Include the issue in the next report to the audit committee.

B.

Inform executive management of the residual risk.

C.

Accept the action plan proposed by the process owner.

D.

Escalate the situation to audit management.

Buy Now
Questions 160

An online retailer is receiving customer complaints about receiving different items from what they ordered on the organization ' s website. The root cause has been traced to poor data quality. Despite efforts to clean erroneous data from the system, multiple data quality issues continue to occur. Which of the following recommendations would be the BEST way to reduce the likelihood of future occurrences?

Options:

A.

Assign responsibility for improving data quality.

B.

Invest in additional employee training for data entry.

C.

Outsource data cleansing activities to reliable third parties.

D.

Implement business rules to validate employee data entry.

Buy Now
Questions 161

Which of the following is the MOST efficient control to reduce the risk associated with a systems administrator having network administrator responsibilities?

Options:

A.

The administrator must obtain temporary access to make critical changes.

B.

The administrator will need to request additional approval for critical changes.

C.

The administrator must sign a due diligence agreement.

D.

The administrator will be subject to unannounced audits.

Buy Now
Questions 162

When protecting the confidentiality of information assets, the MOST effective control practice is the:

Options:

A.

Awareness training of personnel on regulatory requirements

B.

Utilization of a dual-factor authentication mechanism

C.

Configuration of read-only access to all users

D.

Enforcement of a need-to-know access control philosophy

Buy Now
Questions 163

Which of the following is the BEST way to mitigate risk to an organization ' s network associated with devices permitted under a bring your own device (BYOD) policy?

Options:

A.

Require personal devices to be reviewed by IT staff.

B.

Enable port security on all network switches.

C.

Implement a network access control system.

D.

Ensure the policy requires antivirus software on devices.

Buy Now
Questions 164

Which of the following environments is BEST used for copying data and transformation into a compatible data warehouse format?

Options:

A.

Testing

B.

Replication

C.

Staging

D.

Development

Buy Now
Questions 165

How does a continuous integration/continuous development (CI/CD) process help to reduce software failure risk?

Options:

A.

Easy software version rollback

B.

Smaller incremental changes

C.

Fewer manual milestones

D.

Automated software testing

Buy Now
Questions 166

Which of the following would BEST manage the risk of changes in requirements after the analysis phase of a business application development project?

Options:

A.

Expected deliverables meeting project deadlines

B.

Sign-off from the IT team

C.

Ongoing participation by relevant stakeholders

D.

Quality assurance (OA) review

Buy Now
Questions 167

An IS auditor is evaluating an organization ' s IT strategy and plans. Which of the following would be of GREATEST concern?

Options:

A.

There is not a defined IT security policy.

B.

The business strategy meeting minutes are not distributed.

C.

IT is not engaged in business strategic planning.

D.

There is inadequate documentation of IT strategic planning.

Buy Now
Questions 168

During an information security review, an IS auditor learns an organizational policy requires all employ-ees to attend information security training during the first week of each new year. What is

the auditor ' s BEST recommendation to ensure employees hired after January receive adequate guid-ance regarding security awareness?

Options:

A.

Ensure new employees read and sign acknowledgment of the acceptable use policy.

B.

Revise the policy to include security training during onboarding.

C.

Revise the policy to require security training every six months for all employees.

D.

Require management of new employees to provide an overview of security awareness.

Buy Now
Questions 169

Which of the following should be the FIRST step when conducting an IT risk assessment?

Options:

A.

Identify potential threats.

B.

Assess vulnerabilities.

C.

Identify assets to be protected.

D.

Evaluate controls in place.

Buy Now
Questions 170

Which of the following performance management tools BEST helps an IS auditor evaluate the success of an organization’s IT strategy implementation and execution?

Options:

A.

IT benchmarking

B.

Capability maturity model

C.

Six Sigma

D.

IT metrics dashboard

Buy Now
Questions 171

Which of the following roles is PRIMARILY responsible for mitigating the risk of benefits not being realized in an IT project?

Options:

A.

Project sponsor

B.

Project manager

C.

Quality assurance (QA) manager

D.

Chief risk officer (CRO)

Buy Now
Questions 172

When an IS audit reveals that a firewall was unable to recognize a number of attack attempts, the auditor ' s BEST recommendation is to place an intrusion detection system (IDS) between the firewall and:

Options:

A.

the Internet.

B.

the demilitarized zone (DMZ).

C.

the organization ' s web server.

D.

the organization ' s network.

Buy Now
Questions 173

Which of the following methods BEST enforces data leakage prevention in a multi-tenant cloud environment?

Options:

A.

Monitoring tools are configured to alert in case of downtime

B.

A comprehensive security review is performed every quarter.

C.

Data for different tenants is segregated by database schema

D.

Tenants are required to implement data classification polices

Buy Now
Questions 174

Which of the following is the BEST indication of effective IT investment management?

Options:

A.

IT investments are implemented and monitored following a system development life cycle (SDLC)

B.

IT investments are mapped to specific business objectives

C.

Key performance indicators (KPIs) are defined for each business requiring IT Investment

D.

The IT Investment budget is significantly below industry benchmarks

Buy Now
Questions 175

An IS auditor is reviewing an organization ' s cloud access security broker (CASB) solution. Which ofthe following is MOST important for the auditor to verify?

Options:

A.

Cloud services are classified.

B.

Users are centrally managed.

C.

Cloud processes are resilient.

D.

Users are periodically recertified.

Buy Now
Questions 176

An IS auditor learns that an organization ' s business continuity plan (BCP) has not been updated in the last 18 months and that the organization recently closed a production plant. Which of the following is the auditor ' s BEST course of action?

Options:

A.

Determine whether the business impact analysis (BIA) is current with the organization ' s structure and context.

B.

Determine the types of technologies used at the plant and how they may affect the BCP.

C.

Perform testing to determine the impact to the recovery time objective (R TO).

D.

Assess the risk to operations from the closing of the plant.

Buy Now
Questions 177

Which of the following should an IS auditor perform FIRST when auditing an outsourced human resource application?

Options:

A.

Verify that fees billed for the service are appropriate to the work performed.

B.

Review the terms and provisions in the contract.

C.

Implement data access rights consistent with the organization’s security policy.

D.

Verify that security incident reports are issued in a timely manner.

Buy Now
Questions 178

During the walk-through procedures for an upcoming audit, an IS auditor notes that the key application in scope is part of a Software as a Service (SaaS)

agreement. What should the auditor do NEXT?

Options:

A.

Verify whether IT management monitors the effectiveness of the environment.

B.

Verify whether a right-to-audit clause exists.

C.

Verify whether a third-party security attestation exists.

D.

Verify whether service level agreements (SLAs) are defined and monitored.

Buy Now
Questions 179

An organization conducted an exercise to test the security awareness level of users by sending an email offering a cash reward 10 those who click on a link embedded in the body of the email. Which of the following metrics BEST indicates the effectiveness of awareness training?

Options:

A.

The number of users deleting the email without reporting because it is a phishing email

B.

The number of users clicking on the link to learn more about the sender of the email

C.

The number of users forwarding the email to their business unit managers

D.

The number of users reporting receipt of the email to the information security team

Buy Now
Questions 180

An IS auditor has been tasked with auditing the inventory control process for a large organization that processes millions of data transactions. Which of the following is the BEST testing strategy to adopt?

Options:

A.

Continuous monitoring

B.

Control self-assessments (CSAs)

C.

Risk assessments

D.

Stop-or-go sampling

Buy Now
Questions 181

Which of the following is the PRIMARY reason an IS auditor should recommend that management create an IT risk register?

Options:

A.

To document root causes of IT-related risk events and lessons learned

B.

To ensure there is appropriate funding for IT risk mitigation efforts

C.

To ensure an inventory of potential IT risks is maintained and reported

D.

To facilitate internal audit ' s testing of IT-risk-related controls

Buy Now
Questions 182

Which of following areas is MOST important for an IS auditor to focus on when reviewing the maturity model for a technology organization?

Options:

A.

Standard operating procedures

B.

Service level agreements (SLAs)

C.

Roles and responsibility matrix

D.

Business resiliency

Buy Now
Questions 183

A financial organization has learned that one of its business partners utilizes a cloud solution extending servers to several foreign countries. Which of the following should be of GREATEST concern to the organization?

Options:

A.

Data process outsourcing under the current scheme may violate regulations.

B.

Data integrity may be harmed as the result of distributed server deployment.

C.

Data classification may become invalid once data is stored in overseas servers.

D.

Data ownership between the bank and business partner may become unclear.

Buy Now
Questions 184

Which of the following protocols should be used when transferring data via the internet?

Options:

A.

User Datagram Protocol (UDP)

B.

Hypertext Transfer Protocol (HTTP)

C.

Secure File Transfer Protocol (SFTP)

D.

Remote Desktop Protocol (RDP)

Buy Now
Questions 185

Which of the following is a PRIMARY purpose of a privacy notice?

Options:

A.

To indemnify the organization against litigation by users for the appropriation of personal information

B.

To establish the organization’s accountability for the use and protection of personal information

C.

To obtain approval for the sale of personal information to third-party organizations

D.

To ensure that the organization’s privacy controls comply with the privacy laws of the user’s region

Buy Now
Questions 186

Which of the following should an IS auditor expect to see in a network vulnerability assessment?

Options:

A.

Misconfiguration and missing updates

B.

Malicious software and spyware

C.

Zero-day vulnerabilities

D.

Security design flaws

Buy Now
Questions 187

During a review of system access, an IS auditor notes that an employee who has recently changed roles within the organization still has previous access rights. The auditor ' s NEXT step should be to:

Options:

A.

recommend a control to automatically update access rights.

B.

determine the reason why access rights have not been revoked.

C.

direct management to revoke current access rights.

D.

determine if access rights are in violation of software licenses.

Buy Now
Questions 188

Which type of control has been established when an organization implements a security information and event management (SIEM) system?

Options:

A.

Preventive

B.

Detective

C.

Directive

D.

Corrective

Buy Now
Questions 189

Which of the following should be given GREATEST consideration when implementing the use of an open-source product?

Options:

A.

Support

B.

Performance

C.

Confidentiality

D.

Usability

Buy Now
Questions 190

An organization allows programmers to change production systems in emergency situations without seeking prior approval. Which of the following controls should an IS auditor consider MOST

important?

Options:

A.

Programmers ' subsequent reports

B.

Limited number of super users

C.

Operator logs

D.

Automated log of changes

Buy Now
Questions 191

Which of the following would be of GREATEST concern when reviewing an organization ' s security information and event management (SIEM) solution?

Options:

A.

SIEM reporting is customized.

B.

SIEM configuration is reviewed annually

C.

The SIEM is decentralized.

D.

SIEM reporting is ad hoc.

Buy Now
Questions 192

When reviewing a project to replace multiple manual data entry systems with an artificial intelligence (Al) system, the IS auditor should be MOST concerned with the impact Al will have on

Options:

A.

employee retention

B.

enterprise architecture (EA)

C.

future task updates

D.

task capacity output

Buy Now
Questions 193

Which of the following is the BEST way to ensure email confidentiality in transit?

Options:

A.

Encryption of corporate network traffic

B.

Complex user passwords

C.

End-to-end encryption

D.

Digital signatures

Buy Now
Questions 194

Which of the following BEST ensures that effective change management is in place in an IS environment?

Options:

A.

User authorization procedures for application access are well established.

B.

User-prepared detailed test criteria for acceptance testing of the software.

C.

Adequate testing was carried out by the development team.

D.

Access to production source and object programs is well controlled.

Buy Now
Questions 195

During a routine internal software licensing review, an IS auditor discovers instances where employees shared license keys to critical pieces of business software. Which of the following would be the auditor ' s BEST course of action?

Options:

A.

Recommend the utilization of software licensing monitoring tools

B.

Recommend the purchase of additional software license keys

C.

Validate user need for shared software licenses

D.

Verify whether the licensing agreement allows shared use

Buy Now
Questions 196

Which of the following should be of GREATEST concern to an IS auditor assessing the effectiveness of an organization ' s vulnerability scanning program ' '

Options:

A.

Steps taken to address identified vulnerabilities are not formally documented

B.

Results are not reported to individuals with authority to ensure resolution

C.

Scans are performed less frequently than required by the organization ' s vulnerability scanning schedule

D.

Results are not approved by senior management

Buy Now
Questions 197

When auditing the adequacy of a cooling system for a data center, which of the following is MOST important for the IS auditor to review?

Options:

A.

Environmental performance metrics

B.

Geographical location of the data center

C.

Disaster recovery plan (DRP) testing results

D.

Facilities maintenance records

Buy Now
Questions 198

Which of the following should be the FIRST step when developing a data loss prevention (DLP) solution for a large organization?

Options:

A.

Conduct a data inventory and classification exercise.

B.

Identify approved data workflows across the enterprise_

C.

Conduct a threat analysis against sensitive data usage.

D.

Create the DLP policies and templates

Buy Now
Questions 199

Which of the following is the PRIMARY benefit of implementing an IT capacity management process?

Options:

A.

Ensuring infrastructure meets current performance requirements

B.

Enabling rapid deployment of new software applications

C.

Helping resolve significant security concerns

D.

Reducing the cost and time to implement IT services

Buy Now
Questions 200

An IS auditor is examining a front-end subledger and a main ledger. Which of the following would be the GREATEST concern if there are flaws in the mapping of accounts between the two systems?

Options:

A.

Double-posting of a single journal entry

B.

Inability to support new business transactions

C.

Unauthorized alteration of account attributes

D.

Inaccuracy of financial reporting

Buy Now
Questions 201

An internal audit department recently established a quality assurance (QA) program. Which of the following activities Is MOST important to include as part of the QA program requirements?

Options:

A.

Long-term Internal audit resource planning

B.

Ongoing monitoring of the audit activities

C.

Analysis of user satisfaction reports from business lines

D.

Feedback from Internal audit staff

Buy Now
Questions 202

A disaster recovery plan (DRP) should include steps for:

Options:

A.

assessing and quantifying risk.

B.

negotiating contracts with disaster planning consultants.

C.

identifying application control requirements.

D.

obtaining replacement supplies.

Buy Now
Questions 203

An organization was recently notified by its regulatory body of significant discrepancies in its reporting data. A preliminary investigation revealed that the discrepancies were caused by problems with the organization ' s data quality Management has directed the data quality team to enhance their program. The audit committee has asked internal audit to be advisors to the process. To ensure that management concerns are addressed, which data set should internal audit recommend be reviewed FIRST?

Options:

A.

Data with customer personal information

B.

Data reported to the regulatory body

C.

Data supporting financial statements

D.

Data impacting business objectives

Buy Now
Questions 204

Which of the following should an IS auditor recommend as a PRIMARY area of focus when an organization decides to outsource technical support for its external customers?

Options:

A.

Align service level agreements (SLAs) with current needs.

B.

Monitor customer satisfaction with the change.

C.

Minimize costs related to the third-party agreement.

D.

Ensure right to audit is included within the contract.

Buy Now
Questions 205

Which of the following is MOST important for an IS auditor to verify when evaluating an organization ' s data conversion andinfrastructure migration plan?

Options:

A.

Strategic: goals have been considered.

B.

A rollback plan is included.

C.

A code check review is included.

D.

A migration steering committee has been formed.

Buy Now
Questions 206

An IS auditor has found that an organization is unable to add new servers on demand in a cost-efficient manner. Which of the following is the auditor ' s BEST recommendation?

Options:

A.

Increase the capacity of existing systems.

B.

Upgrade hardware to newer technology.

C.

Hire temporary contract workers for the IT function.

D.

Build a virtual environment.

Buy Now
Questions 207

An IS auditor is reviewing the perimeter security design of a network. Which of the following provides the GREATEST assurance outgoing Internet traffic is controlled?

Options:

A.

Intrusion detection system (IDS)

B.

Security information and event management (SIEM) system

C.

Stateful firewall

D.

Load balancer

Buy Now
Questions 208

If a recent release of a program has to be backed out of production, the corresponding changes within the delta version of the code should be:

Options:

A.

filed in production for future reference in researching the problem.

B.

applied to the source code that reflects the version in production.

C.

eliminated from the source code that reflects the version in production.

D.

reinstalled when replacing the version back into production.

Buy Now
Questions 209

An IS auditor has discovered that a software system still in regular use is years out of date and no longer supported the auditee has stated that it will take six months until the software is running on the current version. Which of the following is the BEST way to reduce the immediate risk associated with using an unsupported version of the software?

Options:

A.

Verify all patches have been applied to the software system ' s outdated version

B.

Close all unused ports on the outdated software system.

C.

Segregate the outdated software system from the main network.

D.

Monitor network traffic attempting to reach the outdated software system.

Buy Now
Questions 210

Which of the following methods provides the MOST reliable audit evidence?

Options:

A.

Inquiry

B.

Management attestation

C.

Re-performance of controls

D.

Observation

Buy Now
Questions 211

A job is scheduled to transfer data from a transactional system database to a data lake for reporting purposes. Which of the following would be of GREATEST concern to an IS auditor?

Options:

A.

The inventory of scheduled jobs is not periodically reviewed

B.

Automated support ticket creation has not been implemented for job failures and errors

C.

Access to scheduling changes is restricted to job operators

D.

Notification alerts are configured to be sent to a support distribution group

Buy Now
Questions 212

Which of the following controls BEST ensures appropriate segregation of duties within an accounts payable department?

Options:

A.

Restricting program functionality according to user security profiles

B.

Restricting access to update programs to accounts payable staff only

C.

Including the creator’s user ID as a field in every transaction record created

D.

Ensuring that audit trails exist for transactions

Buy Now
Questions 213

Which of the following BEST enables an IS auditor to combine and compare access control lists from various applications and devices?

Options:

A.

Integrated test facility (ITF)

B.

Snapshots

C.

Data analytics

D.

Audit hooks

Buy Now
Questions 214

Which of the following should be of GREATEST concern to an IS auditor reviewing hardware maintenance practices in an organization whose primary business is e-commerce?

Options:

A.

Hardware maintenance costs exceeded budget by 5%.

B.

The hardware maintenance plan was not approved by the risk manager.

C.

Resource utilization was 5% above the average target range.

D.

System uptime was 5% below the average target range.

Buy Now
Questions 215

An IS auditor found that a company executive is encouraging employee use of social networking sites for business purposes. Which of the following recommendations would BEST help to reduce the risk of data leakage?

Options:

A.

Requiring policy acknowledgment and nondisclosure agreements signed by employees

B.

Providing education and guidelines to employees on use of social networking sites

C.

Establishing strong access controls on confidential data

D.

Monitoring employees ' social networking usage

Buy Now
Questions 216

An IS auditor has completed the fieldwork phase of a network security review and is preparing the initial following findings should be ranked as the HIGHEST risk?

Options:

A.

Network penetration tests are not performed

B.

The network firewall policy has not been approved by the information security officer.

C.

Network firewall rules have not been documented.

D.

The network device inventory is incomplete.

Buy Now
Questions 217

Demonstrated support from which of the following roles in an organization has the MOST influence over information security governance?

Options:

A.

Chief information security officer (CISO)

B.

Information security steering committee

C.

Board of directors

D.

Chief information officer (CIO)

Buy Now
Questions 218

Which of the following BEST facilitates the legal process in the event of an incident?

Options:

A.

Right to perform e-discovery

B.

Advice from legal counsel

C.

Preserving the chain of custody

D.

Results of a root cause analysis

Buy Now
Questions 219

An organization has implemented a new data classification scheme and asks the IS auditor to evaluate its effectiveness. Which of the following would be of

GREATEST concern to the auditor?

Options:

A.

End-user managers determine who should access what information.

B.

The organization has created a dozen different classification categories.

C.

The compliance manager decides how the information should be classified.

D.

The organization classifies most of its information as confidential.

Buy Now
Questions 220

An organization establishes capacity utilization thresholds and monitors for instances when thresholds are exceeded. Which of the following is BEST supported by this activity?

Options:

A.

Integrity

B.

Availability

C.

Confidentiality

D.

Nonrepudiation

Buy Now
Questions 221

Which of the following is a challenge in developing a service level agreement (SLA) for network services?

Options:

A.

Establishing a well-designed framework for network servirces.

B.

Finding performance metrics that can be measured properly

C.

Ensuring that network components are not modified by the client

D.

Reducing the number of entry points into the network

Buy Now
Questions 222

An IS auditor is preparing for a review of controls associated with a manufacturing plant ' s implementation of industrial Internet of Things (loT) infrastructure Which of the following vulnerabilities would present the GREATEST security risk to the organization?

Options:

A.

Insufficient physical security around the lo I devices for theft prevention

B.

Use of open-source software components within the loT devices

C.

Constraints in loT device firmware storage space for code upgrades

D.

loT devices that are not using wireless network connectivity

Buy Now
Questions 223

A system experiences multiple recurring processing errors. Which of the following is the PRIMARY concern for an IS auditor?

Options:

A.

Inefficient incident management

B.

Lack of problem management

C.

Lack of change management

D.

Inefficient project management

Buy Now
Questions 224

The use of which of the following would BEST enhance a process improvement program?

Options:

A.

Model-based design notations

B.

Balanced scorecard

C.

Capability maturity models

D.

Project management methodologies

Buy Now
Questions 225

What is the BEST way to reduce the risk of inaccurate or misleading data proliferating through business intelligence systems?

Options:

A.

Establish rules for converting data from one format to another

B.

Implement data entry controls for new and existing applications

C.

Implement a consistent database indexing strategy

D.

Develop a metadata repository to store and access metadata

Buy Now
Questions 226

Which of the following is the BEST way to strengthen the security of smart devices to prevent data leakage?

Options:

A.

Enforce strong security settings on smart devices.

B.

Require employees to formally acknowledge security procedures.

C.

Review access logs to the organization ' s sensitive data in a timely manner.

D.

Include usage restrictions in bring your own device (BYOD) security procedures.

Buy Now
Questions 227

Which of the following is the BEST metric to measure the alignment of IT and business strategy?

Options:

A.

Level of stakeholder satisfaction with the scope of planned IT projects

B.

Percentage of enterprise risk assessments that include IT-related risk

C.

Percentage of stat satisfied with their IT-related roles

D.

Frequency of business process capability maturity assessments

Buy Now
Questions 228

Which of the following is the GREATEST advantage of outsourcing the development of an e-banking solution when in-house technical expertise is not available?

Options:

A.

Lower start-up costs

B.

Reduced risk of system downtime

C.

Direct oversight of risks

D.

Increased ability to adapt the system

Buy Now
Questions 229

The PRIMARY role of a control self-assessment (CSA) facilitator is to:

Options:

A.

conduct interviews to gain background information.

B.

focus the team on internal controls.

C.

report on the internal control weaknesses.

D.

provide solutions for control weaknesses.

Buy Now
Questions 230

In reviewing the IT strategic plan, the IS auditor should consider whether it identifies the:

Options:

A.

allocation of IT staff.

B.

project management methodologies used.

C.

major IT initiatives.

D.

links to operational tactical plans.

Buy Now
Questions 231

In an annual audit cycle, the audit of an organization ' s IT department resulted in many findings. Which of the following would be the MOST important consideration when planning the next audit?

Options:

A.

Postponing the review until all of the findings have been rectified

B.

Limiting the review to the deficient areas

C.

Verifying that all recommendations have been implemented

D.

Following up on the status of all recommendations

Buy Now
Questions 232

An IT balanced scorecard is PRIMARILY used for:

Options:

A.

evaluating the IT project portfolio

B.

measuring IT strategic performance

C.

allocating IT budget and resources

D.

monitoring risk in lT-related processes

Buy Now
Questions 233

Which of the following is the MOST effective way to identify exfiltration of sensitive data by a malicious insider?

Options:

A.

Implement data loss prevention (DLP) software

B.

Review perimeter firewall logs

C.

Provide ongoing information security awareness training

D.

Establish behavioral analytics monitoring

Buy Now
Questions 234

When building or upgrading enterprise cryptographic infrastructure, which of the following is the MOST critical requirement for growing business environments?

Options:

A.

Service discovery

B.

Backup and restoration capabilities

C.

Network throttling

D.

Scalable architectures and systems

Buy Now
Questions 235

Which of the following is the BEST control to minimize the risk of unauthorized access to lost company-owned mobile devices?

Options:

A.

Password/PIN protection

B.

Device tracking software

C.

Device encryption

D.

Periodic backup

Buy Now
Questions 236

Which of the following should be of MOST concern to an IS auditor when reviewing an intrusion detection system (IDS)?

Options:

A.

High false-positive rate

B.

Delay in signature updates

C.

High false-negative rate

D.

Decrease in processing speed

Buy Now
Questions 237

Which of the following is MOST important for an IS auditor to do during an exit meeting with an auditee?

Options:

A.

Ensure that the facts presented in the report are correct

B.

Communicate the recommendations lo senior management

C.

Specify implementation dates for the recommendations.

D.

Request input in determining corrective action.

Buy Now
Questions 238

Which of the following is MOST important when planning a network audit?

Options:

A.

Determination of IP range in use

B.

Analysis of traffic content

C.

Isolation of rogue access points

D.

Identification of existing nodes

Buy Now
Questions 239

In a RAO model, which of the following roles must be assigned to only one individual?

Options:

A.

Responsible

B.

Informed

C.

Consulted

D.

Accountable

Buy Now
Questions 240

When drafting a disaster recovery strategy, what should be the MOST important outcome of a business impact analysis (BIA)?

Options:

A.

Establishing recovery point objectives (RPOs)

B.

Determining recovery priorities

C.

Establishing recovery time objectives (RTOs)

D.

Determining recovery costs

Buy Now
Questions 241

Which of the following would BEST detect that a distributed denial of service (DDoS) attack is occurring?

Options:

A.

Customer service complaints

B.

Automated monitoring of logs

C.

Server crashes

D.

Penetration testing

Buy Now
Questions 242

Which of the following is the BEST evidence that an organization ' s IT strategy is aligned lo its business objectives?

Options:

A.

The IT strategy is modified in response to organizational change.

B.

The IT strategy is approved by executive management.

C.

The IT strategy is based on IT operational best practices.

D.

The IT strategy has significant impact on the business strategy

Buy Now
Questions 243

A CFO has requested an audit of IT capacity management due to a series of finance system slowdowns during month-end reporting. What would be MOST important to consider before including this audit in the program?

Options:

A.

Whether system delays result in more frequent use of manual processing

B.

Whether the system ' s performance poses a significant risk to the organization

C.

Whether stakeholders are committed to assisting with the audit

D.

Whether internal auditors have the required skills to perform the audit

Buy Now
Questions 244

An IS auditor discovers a box of hard drives in a secured location that are overdue for physical destruction. The vendor responsible for this task was never made aware of these hard drives.

Which of the following is the BEST course of action to address this issue?

Options:

A.

Examine the workflow to identify gaps in asset-handling responsibilities.

B.

Escalate the finding to the asset owner for remediation.

C.

Recommend the drives be sent to the vendor for destruction.

D.

Evaluate the corporate asset-handling policy for potential gaps.

Buy Now
Questions 245

Which of the following provides the BEST evidence that all elements of a business continuity plan (BCP) are operating effectively?

Options:

A.

Walk-through test results

B.

Full operational test results

C.

Tabletop test results

D.

Simulation test results

Buy Now
Questions 246

Which of the following is the BEST security control to validate the integrity of data communicated between production databases and a big data analytics

system?

Options:

A.

Hashing in-scope data sets

B.

Encrypting in-scope data sets

C.

Running and comparing the count function within the in-scope data sets

D.

Hosting a digital certificate for in-scope data sets

Buy Now
Questions 247

An organization is implementing a new data loss prevention (DLP) tool. Which of the following will BEST enable the organization to reduce false positive alerts?

Options:

A.

Using the default policy and tool rule sets

B.

Configuring a limited set of rules

C.

Deploying the tool in monitor mode

D.

Reducing the number of detection points

Buy Now
Questions 248

An IS auditor performs a follow-up audit and learns the approach taken by the auditee to fix the findings differs from the agreed-upon approach confirmed during the last audit. Which of the following should be the auditor ' s NEXT course of action?

Options:

A.

Evaluate the appropriateness of the remedial action taken.

B.

Conduct a risk analysis incorporating the change.

C.

Report results of the follow-up to the audit committee.

D.

Inform senior management of the change in approach.

Buy Now
Questions 249

Which of the following is an IS auditor’s BEST recommendation for conducting a forensic investigation of the contents on a hard drive?

Options:

A.

Make an image of the hard drive for investigation and save the original drive in a secure place.

B.

Investigate the original hard drive to ensure it has not been tampered with.

C.

Ask the user of the endpoint to make a copy of the hard drive and provide it to the auditor for investigation.

D.

Shut down the computer in order to preserve the evidence, disconnect it from the network, and restart.

Buy Now
Questions 250

Which of the following should be an IS auditor’s PRIMARY focus when performing a post-implementation review for a critical IT project?

Options:

A.

Confirm the project steering committee included business representation.

B.

Determine if project goals were met as expected.

C.

Determine if project completion was on time and on budget.

D.

Confirm key stakeholders signed off on project closure.

Buy Now
Questions 251

An IS auditor learns of a new regulation which imposes penalties based on the number of individuals whose personally identifiable information (PII) is exposed by a security breach. What would be the BEST recommendation to help the organization limit the liability associated with a breach to its customer information database?

Options:

A.

Database segmentation

B.

Database normalization

C.

Database harmonization

D.

Database optimization

Buy Now
Questions 252

Which of the following access rights presents the GREATEST risk when granted to a new member of the system development staff?

Options:

A.

Write access to production program libraries

B.

Write access to development data libraries

C.

Execute access to production program libraries

D.

Execute access to development program libraries

Buy Now
Questions 253

What is the PRIMARY purpose of documenting audit objectives when preparing for an engagement?

Options:

A.

To address the overall risk associated with the activity under review

B.

To identify areas with relatively high probability of material problems

C.

To help ensure maximum use of audit resources during the engagement

D.

To help prioritize and schedule auditee meetings

Buy Now
Questions 254

An organization is modernizing its technology policy framework to demonstrate compliance with external industry standards. Which of the following would be MOST useful to an IS auditor for validating the outcome?

Options:

A.

Benchmarking of internal standards against peer organizations

B.

Inventory of the organization ' s approved policy exceptions

C.

Policy recommendations from a leading external consulting agency

D.

Mapping of relevant standards against the organization ' s controls

Buy Now
Questions 255

Which of the following is the PRIMARY benefit of performing periodic maturity model assessments?

Options:

A.

It acts as a measuring tool and progress indicator.

B.

It identifies and fixes attribute weaknesses.

C.

It facilitates the execution of an improvement plan.

D.

It ensures organizational consistency and improvement.

Buy Now
Questions 256

An information systems security officer ' s PRIMARY responsibility for business process applications is to:

Options:

A.

authorize secured emergency access

B.

approve the organization ' s security policy

C.

ensure access rules agree with policies

D.

create role-based rules for each business process

Buy Now
Questions 257

The record-locking option of a database management system (DBMS) serves to.

Options:

A.

eliminate the risk of concurrent updates to a record

B.

allow database administrators (DBAs) to record the activities of users.

C.

restrict users from changing certain values within records.

D.

allow users to lock others out of their files.

Buy Now
Questions 258

Which of the following is the BEST approach for determining the overall IT risk appetite of an organization when business units use different methods for managing IT risks?

Options:

A.

Establish a weighted score based on business unit criticality.

B.

Identify the highest-rated IT risk level among the business units.

C.

Average the business units’ IT risk levels.

D.

Establish a global IT risk scoring criteria.

Buy Now
Questions 259

Which of the following provides the MOST reliable method of preventing unauthonzed logon?

Options:

A.

issuing authentication tokens

B.

Reinforcing current security policies

C.

Limiting after-hours usage

D.

Installing an automatic password generator

Buy Now
Questions 260

In an organization ' s feasibility study to acquire hardware to support a new web server, omission of which of the following would be of MOST concern?

Options:

A.

Alternatives for financing the acquisition

B.

Financial stability of potential vendors

C.

Reputation of potential vendors

D.

Cost-benefit analysis of available products

Buy Now
Questions 261

What would be an IS auditor ' s BEST course of action when an auditee is unable to close all audit recommendations by the time of the follow-up audit?

Options:

A.

Ensure the open issues are retained in the audit results.

B.

Terminate the follow-up because open issues are not resolved

C.

Recommend compensating controls for open issues.

D.

Evaluate the residual risk due to open issues.

Buy Now
Questions 262

If enabled within firewall rules, which of the following services would present the GREATEST risk?

Options:

A.

Simple mail transfer protocol (SMTP)

B.

Simple object access protocol (SOAP)

C.

Hypertext transfer protocol (HTTP)

D.

File transfer protocol (FTP)

Buy Now
Questions 263

A current project to develop IT-based solutions will need additional funding to meet changes in business requirements. Who is BEST suited to obtain this additional funding?

Options:

A.

Project sponsor

B.

Project manager

C.

IT strategy committee

D.

Board of directors

Buy Now
Questions 264

An IS auditor has validated that an organization ' s IT department runs several low-priority automated tasks Which of the following is the BEST recommendation for an automated job schedule?

Options:

A.

Low-priority jobs should be avoided.

B.

Low-priority jobs should include the major functions.

C.

Low-priority jobs should be provided with optimal resources.

D.

Low-priority jobs should be scheduled subject to resource availability.

Buy Now
Questions 265

Which of the following data would be used when performing a business impact analysis (BIA)?

Options:

A.

Projected impact of current business on future business

B.

Cost-benefit analysis of running the current business

C.

Cost of regulatory compliance

D.

Expected costs for recovering the business

Buy Now
Questions 266

Capacity management tools are PRIMARILY used to ensure that:

Options:

A.

available resources are used efficiently and effectively

B.

computer systems are used to their maximum capacity most of the time

C.

concurrent use by a large number of users is enabled

D.

proposed hardware acquisitions meet capacity requirements

Buy Now
Questions 267

Which of the following is MOST important to include when developing a business continuity plan (BCP)?

Options:

A.

Criteria for triggering the plan

B.

Details of linked security policies

C.

Details of a comprehensive asset inventory

D.

Plans for addressing all types of threats

Buy Now
Questions 268

Which of the following is the BEST way to help ensure new IT implementations align with enterprise architecture (EA) principles and requirements?

Options:

A.

Document the security view as part of the EA

B.

Consider stakeholder concerns when defining the EA

C.

Perform mandatory post-implementation reviews of IT implementations

D.

Conduct EA reviews as part of the change advisory board

Buy Now
Questions 269

Following a security breach in which a hacker exploited a well-known vulnerability in the domain controller, an IS audit has been asked to conduct a control assessment. the auditor ' s BEST course of action would be to determine if:

Options:

A.

the patches were updated.

B.

The logs were monitored.

C.

The network traffic was being monitored.

D.

The domain controller was classified for high availability.

Buy Now
Questions 270

Which of the following is the PRIMARY purpose of batch processing monitoring?

Options:

A.

To comply with security standards

B.

To summarize the batch processing reporting

C.

To log error events in batch processing

D.

To prevent an incident that may result from batch failure

Buy Now
Questions 271

An organization is considering allowing users to connect personal devices to the corporate network. Which of the following should be done FIRST?

Options:

A.

Conduct security awareness training.

B.

Implement an acceptable use policy

C.

Create inventory records of personal devices

D.

Configure users on the mobile device management (MDM) solution

Buy Now
Questions 272

Which of the following groups is PRIMARILY accountable for establishing a culture that facilitates an effective and efficient internal control system?

Options:

A.

Board of directors.

B.

Senior management.

C.

Line management.

D.

Internal audit.

Buy Now
Questions 273

Which of the following should be of MOST concern to an IS auditor reviewing an organization’s business impact analysis (BIA)?

Options:

A.

A risk assessment was not conducted prior to completing the BIA.

B.

System criticality information was only provided by the IT manager.

C.

A questionnaire was used to gather information as opposed to in-person interviews.

D.

The BIA was not signed off by executive management.

Buy Now
Questions 274

Which of the following encryption methods offers the BEST wireless security?

Options:

A.

Wi-Fi Protected Access 3 (WPA3)

B.

Data Encryption Standard (DES)

C.

Wired Equivalent Privacy (WEP)

D.

Secure Sockets Layer (SSL)

Buy Now
Questions 275

During a follow-up audit, an IS auditor finds that some critical recommendations have the IS auditor ' s BEST course of action?

Options:

A.

Require the auditee to address the recommendations in full.

B.

Adjust the annual risk assessment accordingly.

C.

Evaluate senior management ' s acceptance of the risk.

D.

Update the audit program based on management ' s acceptance of risk.

Buy Now
Questions 276

Which of the following is the GREATEST concern associated with IS risk-based auditing when audit resources are limited?

Options:

A.

The audit schedule may become too predictable.

B.

Some business processes may not be audited.

C.

There may be significant delays in responding to management audit requests.

D.

Conducting risk assessments may reduce the time available for auditing.

Buy Now
Questions 277

Which of the following is the BEST example of continuous auditing?

Options:

A.

Periodic confirmation that controls are operating effectively.

B.

Periodic touchpoints to identify emerging risks.

C.

Continuous feedback provided to management on controls.

D.

Ongoing assessments that evaluate the fulfillment of service level objectives.

Buy Now
Questions 278

An organization has both an IT strategy committee and an IT steering committee. When reviewing the minutes of the IT steering committee, an IS auditor would expect to find that the

committee:

Options:

A.

assessed the contribution of IT to the business.

B.

acquired and assigned appropriate resources for projects.

C.

compared the risk and return of IT investments.

D.

reviewed the achievement of the strategic IT objective.

Buy Now
Questions 279

The charging method that effectively encourages the MOST efficient use of IS resources is:

Options:

A.

specific charges that can be tied back to specific usage.

B.

total utilization to achieve full operating capacity.

C.

residual income in excess of actual incurred costs.

D.

allocations based on the ability to absorb charges.

Buy Now
Questions 280

An organization has shifted from a bottom-up approach to a top-down approach in the development of IT policies. This should result in:

Options:

A.

greater consistency across the organization.

B.

a synthesis of existing operational policies.

C.

a more comprehensive risk assessment plan.

D.

greater adherence to best practices.

Buy Now
Questions 281

A proper audit trail of changes to server start-up procedures would include evidence of:

Options:

A.

subsystem structure.

B.

program execution.

C.

security control options.

D.

operator overrides.

Buy Now
Questions 282

Which of the following is the BEST detective control for a job scheduling process involving data transmission?

Options:

A.

Metrics denoting the volume of monthly job failures are reported and reviewed by senior management.

B.

Jobs are scheduled to be completed daily and data is transmitted using a Secure File Transfer Protocol (SFTP).

C.

Jobs are scheduled and a log of this activity is retained for subsequent review.

D.

Job failure alerts are automatically generated and routed to support personnel.

Buy Now
Questions 283

Which task should an IS auditor complete FIRST during the preliminary planning phase of a database security review?

Options:

A.

Perform a business impact analysis (BIA).

B.

Determine which databases will be in scope.

C.

Identify the most critical database controls.

D.

Evaluate the types of databases being used

Buy Now
Questions 284

The PRIMARY purpose of an incident response plan is to:

Options:

A.

reduce the impact of an adverse event on information assets.

B.

increase the effectiveness of preventive controls.

C.

reduce the maximum tolerable downtime (MTD) of impacted systems.

D.

increase awareness of impacts from adverse events to IT systems.

Buy Now
Questions 285

Which of the following backup methods is MOST appropriate when storage space is limited?

Options:

A.

Incremental backups

B.

Mirror backups

C.

Full backups

D.

Annual backups

Buy Now
Questions 286

Which of the following is the PRIMARY advantage of establishing a control self-assessment (CSA) program?

Options:

A.

Early detection of risk.

B.

Reduction in control cost.

C.

Improvement in audit rating processes.

D.

Engagement of senior management.

Buy Now
Questions 287

Which of the following is MOST important for an IS auditor to confirm when reviewing an organization ' s plans to implement robotic process automation (RPA > to automate routine business tasks?

Options:

A.

The end-to-end process is understood and documented.

B.

Roles and responsibilities are defined for the business processes in scope.

C.

A benchmarking exercise of industry peers who use RPA has been completed.

D.

A request for proposal (RFP) has been issued to qualified vendors.

Buy Now
Questions 288

Which of the following would be MOST useful when analyzing computer performance?

Options:

A.

Statistical metrics measuring capacity utilization

B.

Operations report of user dissatisfaction with response time

C.

Tuning of system software to optimize resource usage

D.

Report of off-peak utilization and response time

Buy Now
Questions 289

Which of the following should an IS auditor review when evaluating information systems governance for a large organization?

Options:

A.

Approval processes for new system implementations

B.

Procedures for adding a new user to the invoice processing system

C.

Approval processes for updating the corporate website

D.

Procedures for regression testing system changes

Buy Now
Questions 290

Which of the following is the MOST important privacy consideration for an organization that uses a cloud service provider to process customer data?

Options:

A.

Data privacy must be managed in accordance with the regulations applicable to the organization.

B.

Data privacy must be monitored in accordance with industry standards and best practices.

C.

No personal information may be transferred to the service provider without notifying the customer.

D.

Customer data transferred to the service provider must be reported to the regulatory authority.

Buy Now
Questions 291

The GREATEST concern for an IS auditor reviewing vulnerability assessments by the auditee would be if the assessments are:

Options:

A.

Conducted once per year just before system audits are scheduled.

B.

Conducted by the internal technical team instead of external experts.

C.

Performed for critical systems, not for the entire infrastructure.

D.

Performed using open-source testing tools.

Buy Now
Questions 292

An IS auditor notes that the previous year ' s disaster recovery test was not completed within the scheduled time frame due to insufficient hardware allocated by a third-party vendor. Which of the following provides the BEST evidence that adequate resources are now allocated to successfully recover the systems?

Options:

A.

Service level agreement (SLA)

B.

Hardware change management policy

C.

Vendor memo indicating problem correction

D.

An up-to-date RACI chart

Buy Now
Questions 293

Which of the following activities would allow an IS auditor to maintain independence while facilitating a control sell-assessment (CSA)?

Options:

A.

Implementing the remediation plan

B.

Partially completing the CSA

C.

Developing the remediation plan

D.

Developing the CSA questionnaire

Buy Now
Questions 294

Which of the following is MOST important to include in forensic data collection and preservation procedures?

Options:

A.

Assuring the physical security of devices

B.

Preserving data integrity

C.

Maintaining chain of custody

D.

Determining tools to be used

Buy Now
Questions 295

An IS auditor is evaluating the progress of a web-based customer service application development project. Which of the following would be MOST helpful for this evaluation?

Options:

A.

Backlog consumption reports

B.

Critical path analysis reports

C.

Developer status reports

D.

Change management logs

Buy Now
Questions 296

Which of the following is the MOST effective way for an organization to help ensure agreed-upon action plans from an IS audit will be implemented?

Options:

A.

Ensure sufficient audit resources are allocated,

B.

Communicate audit results organization-wide.

C.

Ensure ownership is assigned.

D.

Test corrective actions upon completion.

Buy Now
Questions 297

Which of the following is the BEST source of information for an IS auditor to use as a baseline to assess the adequacy of an organization ' s privacy policy?

Options:

A.

Historical privacy breaches and related root causes

B.

Globally accepted privacy best practices

C.

Local privacy standards and regulations

D.

Benchmark studies of similar organizations

Buy Now
Questions 298

Which of the following is the MOST effective control to mitigate against the risk of inappropriate activity by employees?

Options:

A.

User activity monitoring

B.

Two-factor authentication

C.

Network segmentation

D.

Access recertification

Buy Now
Questions 299

In a review of the organization standards and guidelines for IT management, which of the following should be included in an IS development methodology?

Options:

A.

Value-added activity analysis

B.

Risk management techniques

C.

Access control rules

D.

Incident management techniques

Buy Now
Questions 300

Which of the following is the MOST important consideration when implementing a Zero Trust strategy for mobile, wireless, and Internet of Things (IoT) devices?

Options:

A.

Ensuring the latest firmware updates are applied regularly to all devices

B.

Validating the identity of all devices and users before granting access to resources

C.

Focusing on user training and awareness to prevent phishing attacks

D.

Implementing strong encryption protocols for data in transit and at rest

Buy Now
Questions 301

Due to a recent business divestiture, an organization has limited IT resources to deliver critical projects Reviewing the IT staffing plan against which of the following would BEST guide IT management when estimating resource requirements for future projects?

Options:

A.

Human resources (HR) sourcing strategy

B.

Records of actual time spent on projects

C.

Peer organization staffing benchmarks

D.

Budgeted forecast for the next financial year

Buy Now
Questions 302

Which of the following would be an appropriate rote of internal audit in helping to establish an organization ' s privacy program?

Options:

A.

Analyzing risks posed by new regulations

B.

Designing controls to protect personal data

C.

Defining roles within the organization related to privacy

D.

Developing procedures to monitor the use of personal data

Buy Now
Questions 303

The FIRST step in an incident response plan is to:

Options:

A.

validate the incident.

B.

notify the head of the IT department.

C.

isolate systems impacted by the incident.

D.

initiate root cause analysis.

Buy Now
Questions 304

An IS auditor finds ad hoc vulnerability scanning is in place with no clear alignment to the organization ' s wider security threat and vulnerability management program.

Which of the following would BEST enable the organization to work toward improvement in this area?

Options:

A.

Implementing security logging to enhance threat and vulnerability management

B.

Maintaining a catalog of vulnerabilities that may impact mission-critical systems

C.

Using a capability maturity model to identify a path to an optimized program

D.

Outsourcing the threat and vulnerability management function to a third party

Buy Now
Questions 305

Which of the following is MOST important to ensure when developing an effective security awareness program?

Options:

A.

Training personnel are information security professionals.

B.

Outcome metrics for the program are established.

C.

Security threat scenarios are included in the program content.

D.

Phishing exercises are conducted post-training

Buy Now
Questions 306

Audit frameworks cart assist the IS audit function by:

Options:

A.

defining the authority and responsibility of the IS audit function.

B.

providing details on how to execute the audit program.

C.

providing direction and information regarding the performance of audits.

D.

outlining the specific steps needed to complete audits

Buy Now
Questions 307

Which of the following is BEST used for detailed testing of a business application ' s data and configuration files?

Options:

A.

Version control software

B.

Audit hooks

C.

Utility software

D.

Audit analytics tool

Buy Now
Questions 308

An IS auditor is reviewing a bank’s service level agreement (SLA) with a third-party provider that hosts the bank’s secondary data center. Which of the following findings should be of GREATEST concern to the auditor?

Options:

A.

The recovery time objective (RTO) has a longer duration than documented in the disaster recovery plan (DRP).

B.

The SLA has not been reviewed in more than a year.

C.

The recovery point objective (RPO) has a shorter duration than documented in the disaster recovery plan (DRP).

D.

Backup data is hosted online only.

Buy Now
Questions 309

What should an IS auditor do FIRST when a follow-up audit reveals some management action plans have not been initiated?

Options:

A.

Confirm whether the identified risks are still valid.

B.

Provide a report to the audit committee.

C.

Escalate the lack of plan completion to executive management.

D.

Request an additional action plan review to confirm the findings.

Buy Now
Questions 310

Which of the following provides the BEST assurance of data integrity after file transfers?

Options:

A.

Check digits

B.

Monetary unit sampling

C.

Hash values

D.

Reasonableness check

Buy Now
Questions 311

Which of the following is the BEST sampling method to use when relatively few errors are expected to be found in a population?

Options:

A.

Variable sampling

B.

Judgmental sampling

C.

Stop-or-go sampling

D.

Discovery sampling

Buy Now
Questions 312

Management has learned the implementation of a new IT system will not be completed on time and has requested an audit. Which of the following audit findings should be of GREATEST concern?

Options:

A.

The actual start times of some activities were later than originally scheduled.

B.

Tasks defined on the critical path do not have resources allocated.

C.

The project manager lacks formal certification.

D.

Milestones have not been defined for all project products.

Buy Now
Questions 313

An IS auditor reviewing the system development life cycle (SDLC) finds there is no requirement for business cases. Which of the following should be offGREATEST concern to the organization?

Options:

A.

Vendor selection criteria are not sufficiently evaluated.

B.

Business resources have not been optimally assigned.

C.

Business impacts of projects are not adequately analyzed.

D.

Project costs exceed established budgets.

Buy Now
Questions 314

Which of the following should be an IS auditor ' s PRIMARY focus when evaluating the response process for cybercrimes?

Options:

A.

Communication with law enforcement

B.

Notification to regulators

C.

Root cause analysis

D.

Evidence collection

Buy Now
Questions 315

To help determine whether a controls-reliant approach to auditing financial systems in a company should be used, which sequence of IS audit work is MOST appropriate?

Options:

A.

Review of the general IS controls followed by a review of the application controls

B.

Detailed examination of financial transactions followed by review of the general ledger

C.

Review of major financial applications followed by a review of IT governance processes

D.

Review of application controls followed by a test of key business process controls

Buy Now
Questions 316

An IS auditor concludes that logging and monitoring mechanisms within an organization are ineffective because critical servers are not included within the central log repository. Which of the following audit procedures would have MOST likely identified this exception?

Options:

A.

Inspecting a sample of alerts generated from the central log repository

B.

Comparing a list of all servers from the directory server against a list of all servers present in the central log repository

C.

Inspecting a sample of alert settings configured in the central log repository

D.

Comparing all servers included in the current central log repository with the listing used for the prior-year audit

Buy Now
Questions 317

Some control activities have been found to be only partially compliant with the design of the control. Which of the following is an IS auditor’s PRIMARY course of action?

Options:

A.

Recommend redesigning control activities to ensure acceptance by users.

B.

Evaluate the impact of the partial compliance.

C.

Discuss partial compliance with control owners.

D.

Include each instance of partial compliance as a finding in the final audit report.

Buy Now
Questions 318

Which of the following should be an IS auditor ' s GREATEST concern when assessing an IT service configuration database?

Options:

A.

The database is read-accessible for all users.

B.

The database is write-accessible for all users.

C.

The database is not encrypted at rest.

D.

The database is executable for all users.

Buy Now
Questions 319

When designing a data analytics process, which of the following should be the stakeholder ' s role in automating data extraction and validation?

Options:

A.

Indicating which data elements are necessary to make informed decisions

B.

Allocating the resources necessary to purchase the appropriate software packages

C.

Performing the business case analysis for the data analytics initiative

D.

Designing the workflow necessary for the data analytics tool to evaluate the appropriate data

Buy Now
Questions 320

To mitigate the risk of exposing data through application programming interface (API) queries. which of the following design considerations is MOST important?

Options:

A.

Data retention

B.

Data minimization

C.

Data quality

D.

Data integrity

Buy Now
Questions 321

Which of the following should be the IS auditor ' s PRIMARY focus when evaluating an organizations offsite storage facility?

Options:

A.

Adequacy of physical and environmental controls

B.

Results of business continuity plan (BCP) tests

C.

Shared facilities

D.

Retention policy and period

Buy Now
Questions 322

An organization ' s enterprise architecture (EA) department decides to change a legacy system ' s components while maintaining its original functionality. Which of the following is MOST important for an IS auditor to understand when reviewing this decision?

Options:

A.

The current business capabilities delivered by the legacy system

B.

The proposed network topology to be used by the redesigned system

C.

The data flows between the components to be used by the redesigned system

D.

The database entity relationships within the legacy system

Buy Now
Questions 323

An IS auditor observes that a large number of departed employees have not been removed from the accounts payable system. Which of the following is MOST important to determine in order to assess the risk1?

Options:

A.

The frequency of user access reviews performed by management

B.

The frequency of intrusion attempts associated with the accounts payable system

C.

The process for terminating access of departed employees

D.

The ability of departed employees to actually access the system

Buy Now
Questions 324

Which of the following is an example of a preventive control for physical access?

Options:

A.

Keeping log entries for all visitors to the building

B.

Implementing a fingerprint-based access control system for the building

C.

Installing closed-circuit television (CCTV) cameras for all ingress and egress points

D.

Implementing a centralized logging server to record instances of staff logging into workstations

Buy Now
Questions 325

An IS auditor has been asked to audit the proposed acquisition of new computer hardware. The auditor’s PRIMARY concern Is that:

Options:

A.

the implementation plan meets user requirements.

B.

a full, visible audit trail will be Included.

C.

a dear business case has been established.

D.

the new hardware meets established security standards

Buy Now
Questions 326

An IS auditor reviewing an organization’s IT systems finds that the organization frequently purchases systems that are incompatible with the technologies already in the organization. Which of the following is the MOST likely reason?

Options:

A.

Ineffective risk management policy

B.

Lack of enterprise architecture (EA)

C.

Lack of a maturity model

D.

Outdated enterprise resource planning (ERP) system

Buy Now
Questions 327

Which of the following should be of GREATEST concern to an IS auditor reviewing a terminated employee’s network access?

Options:

A.

The user account password is set to never expire.

B.

The last login to the user account was days after the last working date.

C.

The user account password was last changed more than 90 days ago.

D.

There is not a documented approval process to disable user accounts.

Buy Now
Questions 328

An IS auditor notes that several employees are spending an excessive amount of time using social media sites for personal reasons. Which of the following should the auditor recommend be performed FIRST?

Options:

A.

Implement a process to actively monitor postings on social networking sites.

B.

Adjust budget for network usage to include social media usage.

C.

Use data loss prevention (DLP) tools on endpoints.

D.

implement policies addressing acceptable usage of social media during working hours.

Buy Now
Questions 329

The use of control totals reduces the risk of:

Options:

A.

posting to the wrong record.

B.

incomplete processing.

C.

improper backup.

D.

improper authorization.

Buy Now
Questions 330

Secure code reviews as part of a continuous deployment program are which type of control?

Options:

A.

Detective

B.

Logical

C.

Preventive

D.

Corrective

Buy Now
Questions 331

An IS auditor will be testing accounts payable controls by performing data analytics on the entire population of transactions. Which of the following is MOST important for the auditor to confirm when sourcing the population data?

Options:

A.

The data is taken directly from the system.

B.

There is no privacy information in the data.

C.

The data can be obtained in a timely manner.

D.

The data analysis tools have been recently updated.

Buy Now
Questions 332

During a database management evaluation an IS auditor discovers that some accounts with database administrator (DBA) privileges have been assigned a default password with an unlimited number of failed login attempts Which of the following is the auditor ' s BEST course of action?

Options:

A.

Identify accounts that have had excessive failed login attempts and request they be disabled

B.

Request the IT manager to change administrator security parameters and update the finding

C.

Document the finding and explain the risk of having administrator accounts with inappropriate security settings

Buy Now
Questions 333

In order for a firewall to effectively protect a network against external attacks, what fundamental practice must be followed?

Options:

A.

The firewall must be placed in the demilitarized zone (DMZ).

B.

Only essential external services should be permitted.

C.

Filters for external information must be defined.

D.

All external communication must be via the firewall.

Buy Now
Questions 334

An IS auditor is reviewing the security of a web-based customer relationship management (CRM) system that is directly accessed by customers via the Internet, which of the following should be a concern for the auditor?

Options:

A.

The system is hosted on an external third-party service provider’s server.

B.

The system is hosted in a hybrid-cloud platform managed by a service provider.

C.

The system is hosted within a demilitarized zone (DMZ) of a corporate network.

D.

The system is hosted within an internal segment of a corporate network.

Buy Now
Questions 335

Which of the following is the BEST recommendation to prevent fraudulent electronic funds transfers by accounts payable employees?

Options:

A.

Periodic vendor reviews

B.

Dual control

C.

Independent reconciliation

D.

Re-keying of monetary amounts

E.

Engage an external security incident response expert for incident handling.

Buy Now
Questions 336

A bank wants to outsource a system to a cloud provider residing in another country. Which of the following would be the MOST appropriate IS audit recommendation?

Options:

A.

Find an alternative provider in the bank ' s home country.

B.

Ensure the provider ' s internal control system meets bank requirements.

C.

Proceed as intended, as the provider has to observe all laws of the clients’ countries.

D.

Ensure the provider has disaster recovery capability.

Buy Now
Questions 337

The BEST way for an IS auditor to validate that separation of duties has been implemented is to perform:

Options:

A.

A review of personnel files.

B.

An analysis of documented job descriptions.

C.

A review of the organizational chart.

D.

A walk-through of job functions.

Buy Now
Questions 338

Which of the following is the MOST appropriate and effective fire suppression method for an unstaffed computer room?

Options:

A.

Water sprinkler

B.

Fire extinguishers

C.

Carbon dioxide (CO2)

D.

Dry pipe

Buy Now
Questions 339

A KEY benefit of integrated auditing is that it:

Options:

A.

Facilitates the business in reviewing its control environment.

B.

Enables continuous auditing and monitoring.

C.

Improves the review of audit work by team leaders.

D.

Combines skill sets from operational, functional, and IS auditors.

Buy Now
Questions 340

During the audit of an enterprise resource planning (ERP) system, an IS auditor found an applicationpatch was applied to the production environment. It is MOST

important for the IS auditor to verify approval from the:

Options:

A.

information security officer.

B.

system administrator.

C.

information asset owner.

D.

project manager.

Buy Now
Questions 341

Which of the following controls helps to reduce fraud risk associated with robotic process automation (RPA)?

Options:

A.

Inclusion of robots in business impact assessments (BIAs)

B.

Password rotation

C.

Recertification process for robots

D.

Common RPA testing framework

Buy Now
Questions 342

Which of the following is the BEST way to ensure that business continuity plans (BCPs) will work effectively in the event of a major disaster?

Options:

A.

Prepare detailed plans for each business function.

B.

Involve staff at all levels in periodic paper walk-through exercises.

C.

Regularly update business impact assessments.

D.

Make senior managers responsible for their plan sections.

Buy Now
Questions 343

Which of the following documents should specify roles and responsibilities within an IT audit organization?

Options:

A.

Organizational chart

B.

Audit charier

C.

Engagement letter

D.

Annual audit plan

Buy Now
Questions 344

How does public key infrastructure (PKI) help to verify that a digitally signed document is not a forgery?

Options:

A.

By decrypting the signature with the signer’s public key

B.

By verifying the signature with the signer’s private key

C.

By checking the signature against the receiver’s public key

D.

By checking the signed document’s audit history

Buy Now
Questions 345

Which of the following is MOST important to consider when assessing the scope of privacy concerns for an IT project?

Options:

A.

Data ownership

B.

Applicable laws and regulations

C.

Business requirements and data flows

D.

End-user access rights

Buy Now
Questions 346

An IS audit reveals that an organization is not proactively addressing known vulnerabilities. Which of the following should the IS auditor recommend the organization do FIRST?

Options:

A.

Verify the disaster recovery plan (DRP) has been tested.

B.

Ensure the intrusion prevention system (IPS) is effective.

C.

Assess the security risks to the business.

D.

Confirm the incident response team understands the issue.

Buy Now
Questions 347

Which of the following is the BEST source of information tor an IS auditor to use when determining whether an organization ' s information security policy is adequate?

Options:

A.

Information security program plans

B.

Penetration test results

C.

Risk assessment results

D.

Industry benchmarks

Buy Now
Questions 348

The operations team of an organization has reported an IS security attack Which of the following should be the FIRST step for the security incident response team?

Options:

A.

Report results to management

B.

Document lessons learned

C.

Perform a damage assessment

D.

Prioritize resources for corrective action

Buy Now
Questions 349

During a follow-up audit, an IS auditor learns that some key management personnel have been replaced since the original audit, and current management has decided not to implement some previously accepted recommendations. What is the auditor ' s BEST course of action?

Options:

A.

Notify the chair of the audit committee.

B.

Notify the audit manager.

C.

Retest the control.

D.

Close the audit finding.

Buy Now
Questions 350

Which of the following is the BEST source of information for assessing the effectiveness of IT process monitoring?

Options:

A.

Real-time audit software

B.

Performance data

C.

Quality assurance (QA) reviews

D.

Participative management techniques

Buy Now
Questions 351

Which of the following should be the PRIMARY objective of a disaster recovery plan (DRP)?

Options:

A.

Minimizing loss of information

B.

Assessing the risk of key applications

C.

Identifying key business processes

D.

Documenting all IT assets

Buy Now
Questions 352

An IS auditor finds the log management system is overwhelmed with false positive alerts. The auditor ' s BEST recommendation would be to:

Options:

A.

establish criteria for reviewing alerts.

B.

recruit more monitoring personnel.

C.

reduce the firewall rules.

D.

fine tune the intrusion detection system (IDS).

Buy Now
Questions 353

An IS auditor is reviewing a decision to consolidate processing for multiple applications onto a single large server. Which of the following is the MOST significant impact from this decision?

Options:

A.

Higher operating system license fees

B.

More applications affected by a server outage

C.

Simplified asset management

D.

Fewer application servers requiring vulnerability scans

Buy Now
Questions 354

An organization has made a strategic decision to split into separate operating entities to improve profitability. However, the IT infrastructure remains shared between the entities. Which of the following would BEST help to ensure that IS audit still covers key risk areas within the IT environment as part of its annual plan?

Options:

A.

Increasing the frequency of risk-based IS audits for each business entity

B.

Developing a risk-based plan considering each entity ' s business processes

C.

Conducting an audit of newly introduced IT policies and procedures

D.

Revising IS audit plans to focus on IT changes introduced after the split

Buy Now
Questions 355

An organization has virtualized its server environment without making any other changes to the network or security infrastructure. Which of the following is the MOST significant risk?

Options:

A.

Inability of the network intrusion detection system (IDS) to monitor virtual server-lo-server communications

B.

Vulnerability in the virtualization platform affecting multiple hosts

C.

Data center environmental controls not aligning with new configuration

D.

System documentation not being updated to reflect changes in the environment

Buy Now
Questions 356

Which of the following BEST facilitates strategic program management?

Options:

A.

Implementing stage gates

B.

Establishing a quality assurance (QA) process

C.

Aligning projects with business portfolios

D.

Tracking key project milestones

Buy Now
Questions 357

Which of the following BEST demonstrates to senior management and the board that an audit function is compliant with standards and the code of ethics?

Options:

A.

Audit staff interviews

B.

Quality control reviews

C.

Control self-assessments (CSAs)

D.

Corrective action plans

Buy Now
Questions 358

Data Loss Prevention (DLP) tools provide the MOST protection against:

Options:

A.

The installation of unknown malware.

B.

Malicious programs running on organizational systems.

C.

The downloading of sensitive information to devices by employees.

D.

The sending of corrupt data files to external parties via email.

Buy Now
Questions 359

Which of the following is MOST important for an IS auditor to determine when reviewing the design and implementation of controls?

Options:

A.

Whether there is a proper balance between the magnitude of the risk and the control measures implemented

B.

Whether the implemented controls closely align with domestic and international industry best practices

C.

Whether identified risks are being completely mitigated through the proper application of control mechanisms

D.

Whether adequate resources are available for frequent and stringent control monitoring

Buy Now
Questions 360

Which of the following should be an IS auditor ' s GREATEST concern when a data owner assigns an incorrect classification level to data?

Options:

A.

Controls to adequately safeguard the data may not be applied.

B.

Data may not be encrypted by the system administrator.

C.

Competitors may be able to view the data.

D.

Control costs may exceed the intrinsic value of the IT asset.

Buy Now
Questions 361

Which of the following should be the GREATEST concern to an IS auditor reviewing an organization ' s method to transport sensitive data between offices?

Options:

A.

The method relies exclusively on the use of public key infrastructure (PKI).

B.

The method relies exclusively on the use of digital signatures.

C.

The method relies exclusively on the use of asymmetric encryption algorithms.

D.

The method relies exclusively on the use of 128-bit encryption.

Buy Now
Questions 362

A review of an organization’s IT portfolio revealed several applications that are not in use. The BEST way to prevent this situation from recurring would be to implement.

Options:

A.

A formal request for proposal (RFP) process

B.

Business case development procedures

C.

An information asset acquisition policy

D.

Asset life cycle management.

Buy Now
Questions 363

Which of the following MOST effectively reduces the risk of emails containing personally identifiable information (PII) being sent to unauthorized recipients?

Options:

A.

Multi-factor authentication (MFA)

B.

Intrusion detection system (IDS)

C.

Email audit trails

D.

Regular security awareness training

Buy Now
Questions 364

Which of the following metrics would BEST measure the agility of an organization ' s IT function?

Options:

A.

Average number of learning and training hours per IT staff member

B.

Frequency of security assessments against the most recent standards and guidelines

C.

Average time to turn strategic IT objectives into an agreed upon and approved initiative

D.

Percentage of staff with sufficient IT-related skills for the competency required of their roles

Buy Now
Questions 365

Which of the following provides the MOST assurance of the integrity of a firewall log?

Options:

A.

The log is reviewed on a monthly basis.

B.

Authorized access is required to view the log.

C.

The log cannot be modified.

D.

The log is retained per policy.

Buy Now
Questions 366

A manager Identifies active privileged accounts belonging to staff who have left the organization. Which of the following is the threat actor In this scenario?

Options:

A.

Terminated staff

B.

Unauthorized access

C.

Deleted log data

D.

Hacktivists

Buy Now
Questions 367

An organization’s information security department has recently created a centralized governance model to ensure that network-related findings are remediated within the service level agreement (SLA). What should the IS auditor use to assess the capability of this governance model?

Options:

A.

Key process controls.

B.

Key performance indicators (KPIs).

C.

Key risk indicators (KRIs).

D.

Key data elements.

Buy Now
Questions 368

An organization ' s payroll department recently implemented a new Software as a Service (SaaS) tool for payment processing. Which of the following audits is MOST appropriate for an IS auditor to validate that the new tool is configured as expected to meet performance requirements?

Options:

A.

Financial audit

B.

Administrative audit

C.

Functional audit

D.

Compliance audit

Buy Now
Questions 369

Which of the following findings from an IT governance review should be of GREATEST concern?

Options:

A.

The IT budget is not monitored

B.

All IT services are provided by third parties.

C.

IT value analysis has not been completed.

D.

IT supports two different operating systems.

Buy Now
Questions 370

An organization has developed mature risk management practices that are followed across all departments What is the MOST effective way for the audit team to leverage this risk management maturity?

Options:

A.

Implementing risk responses on management ' s behalf

B.

Integrating the risk register for audit planning purposes

C.

Providing assurances to management regarding risk

D.

Facilitating audit risk identification and evaluation workshops

Buy Now
Questions 371

Which of the following would be an IS auditor ' s GREATEST concern when reviewing the organization ' s business continuity plan (BCP)?

Options:

A.

The recovery plan does not contain the process and application dependencies.

B.

The duration of tabletop exercises is longer than the recovery point objective (RPO).

C.

The duration of tabletop exercises is longer than the recovery time objective (RTO).

D.

The recovery point objective (RPO) and recovery time objective (R TO) are not the same.

Buy Now
Questions 372

Which of the following is the MOST important factor when an organization is developing information security policies and procedures?

Options:

A.

Consultation with security staff

B.

Inclusion of mission and objectives

C.

Compliance with relevant regulations

D.

Alignment with an information security framework

Buy Now
Questions 373

In a high-volume, real-time system, the MOST effective technique by which to continuously monitor and analyze transaction processing is:

Options:

A.

integrated test facility (ITF).

B.

parallel simulation.

C.

transaction tagging.

D.

embedded audit modules.

Buy Now
Questions 374

Which of the following findings would be of GREATEST concern to an IS auditor reviewing the security architecture of an organization that has just implemented a Zero Trust solution?

Options:

A.

An increase in security-related costs

B.

User complaints about the new mode of working

C.

An increase in user identification errors

D.

A noticeable drop in the performance of IT systems

Buy Now
Questions 375

The IS quality assurance (OA) group is responsible for:

Options:

A.

ensuring that program changes adhere to established standards.

B.

designing procedures to protect data against accidental disclosure.

C.

ensuring that the output received from system processing is complete.

D.

monitoring the execution of computer processing tasks.

Buy Now
Questions 376

Which of the following are BEST suited for continuous auditing?

Options:

A.

Low-value transactions

B.

Real-lime transactions

C.

Irregular transactions

D.

Manual transactions

Buy Now
Questions 377

A new system is being developed externally for an organization. Which of the following is the MOST important requirement to include in the vendor contract to ensure service continuity?

Options:

A.

Support documentation must be provided by the vendor.

B.

The vendor must have a documented disaster recovery plan (DRP) in place.

C.

Source code for the software must be placed in escrow.

D.

The vendor must train the organization’s staff to manage the new software.

Buy Now
Questions 378

The PRIMARY advantage of object-oriented technology is enhanced:

Options:

A.

efficiency due to the re-use of elements of logic.

B.

management of sequential program execution for data access.

C.

grouping of objects into methods for data access.

D.

management of a restricted variety of data types for a data object.

Buy Now
Questions 379

Which of the following should be performed FIRST before key performance indicators (KPIs) can be implemented?

Options:

A.

Analysis of industry benchmarks

B.

Identification of organizational goals

C.

Analysis of quantitative benefits

D.

Implementation of a balanced scorecard

Buy Now
Questions 380

Which of the following is a principle of the Agile software development process?

Options:

A.

Clear documentation should be seen as the primary measure of progress.

B.

Development phases should be isolated from each other.

C.

A linear approach should be used that requires phase completion before continuing.

D.

Changing requirements should be welcomed, even late in the development process.

Buy Now
Questions 381

Which of the following technologies BEST assists in protection of digital evidence as part of forensic investigation acquisition?

Options:

A.

Hardware-based media write blocker

B.

Data encryption

C.

Differential backups

D.

Source media sanitization

Buy Now
Questions 382

Which of the following approaches would utilize data analytics to facilitate the testing of a new account creation process?

Options:

A.

Attempt to submit new account applications with invalid dates of birth.

B.

Review the business requirements document for date of birth field requirements.

C.

Review new account applications submitted in the past month for invalid dates of birth.

D.

Evaluate configuration settings for the date of birth field requirements

Buy Now
Questions 383

Which of the following BEST indicates to an IS auditor that an organization handles emergency changes appropriately and transparently?

Options:

A.

The application operations manual contains procedures to ensure emergency fixes do not compromise system integrity.

B.

Special logon IDs are used to grant programmers permanent access to the production environment.

C.

Change management controls are retroactively applied.

D.

Emergency changes are applied to production libraries immediately.

Buy Now
Questions 384

An organization is concerned about duplicate vendor payments on a complex system with a high volume of transactions. Which of the following would be MOST helpful to an IS auditor to determine whether duplicate vendor payments exist?

Options:

A.

Computer-assisted audit technique (CAAT)

B.

Stratified sampling

C.

Statistical sampling

D.

Process walk-through

Buy Now
Questions 385

Which of the following is the BEST way to minimize sampling risk?

Options:

A.

Use a larger sample size

B.

Perform statistical sampling

C.

Perform judgmental sampling

D.

Enhance audit testing procedures

Buy Now
Questions 386

Which of the following establishes the PRIMARY difference between a business continuity plan (BCP) and a disaster recovery plan (DRP)?

Options:

A.

The annual testing requirements

B.

The focus on system recovery

C.

The timeframe for plan activation

D.

The involvement of senior management

Buy Now
Questions 387

To develop meaningful recommendations ' or findings, which of the following is MOST important ' or an IS auditor to determine and understand?

Options:

A.

Root cause

B.

Responsible party

C.

impact

D.

Criteria

Buy Now
Questions 388

Which of the following is MOST important to consider when determining the usefulness of audit evidence?

Options:

A.

Timing of the evidence

B.

Nature of evidence gathered

C.

Overall objectives of the review

D.

Competence of the IS auditor

Buy Now
Questions 389

Which of the following provides IS audit professionals with the BEST source of direction for performing audit functions?

Options:

A.

Audit charter

B.

IT steering committee

C.

Information security policy

D.

Audit best practices

Buy Now
Questions 390

Which of the following should be the GREATEST concern for an IS auditor reviewing recent disaster recovery operations?

Options:

A.

The recovery point objective (RPO) was not defined.

B.

Test data was lost during a recovery operation.

C.

A warm site was used as a recovery strategy.

D.

A full backup was only performed once a week.

Buy Now
Questions 391

An IS auditor has been asked to review an event log aggregation system to ensure risk management practices have been applied. Which of the following should be of MOST concern to the auditor?

Options:

A.

The log data is not normalized.

B.

Log feeds are uploaded via batch process.

C.

Data Encryption Standards (DESs) have not been considered.

D.

Completeness testing has not been performed on the log data.

Buy Now
Questions 392

Which of the following MUST be completed as part of the annual audit planning process?

Options:

A.

Business continuity analysis

B.

Industry benchmarking

C.

Risk assessment

D.

Risk control matrix

Buy Now
Questions 393

When a data center is attempting to restore computing facilities at an alternative site following a disaster, which of the following should be restored FIRST?

Options:

A.

Data backups

B.

Decision support system

C.

Operating system

D.

Applications

Buy Now
Questions 394

During a follow-up audit, an IS auditor finds that some critical recommendations have not been addressed, as management has decided to accept the risk. Which of the following is the IS auditors BEST course of action?

Options:

A.

Require the auditee to address the recommendations in full.

B.

Update the audit program based on management ' s acceptance of risk.

C.

Evaluate senior management ' s acceptance of the risk.

D.

Adjust the annual risk assessment accordingly.

Buy Now
Questions 395

What type of control has been implemented when secure code reviews are conducted as part of a deployment program?

Options:

A.

Detective

B.

Corrective

C.

Monitoring

D.

Deterrent

Buy Now
Questions 396

Which of the following should be done FIRST following an incident that has caused internal servers to be inaccessible, disrupting normal business operations?

Options:

A.

Document the servers ' dates, times, and locations, as well as the individual who last used them

B.

Make a bit-level copy of the affected servers and calculate the hash value of the copy.

C.

Copy all key directories and files on the affected servers and generate the hash value of the copy.

D.

Unplug all power cables immediately to prevent further actions of the attacker on the servers.

Buy Now
Questions 397

An IS auditor reviewing database security should be MOST concerned if the database administrator (DBA):

Options:

A.

approves access roles.

B.

resolves database locks.

C.

executes recovery procedures.

D.

assesses database performance.

Buy Now
Questions 398

During an audit of a financial application, it was determined that many terminated users ' accounts were not disabled. Which of the following should be the IS auditor ' s NEXT step?

Options:

A.

Perform substantive testing of terminated users ' access rights.

B.

Perform a review of terminated users ' account activity

C.

Communicate risks to the application owner.

D.

Conclude that IT general controls ate ineffective.

Buy Now
Questions 399

When reviewing the disaster recovery strategy, IT management identified an application that requires a short recovery point objective (RPO). Which of the following data restoration strategies would BEST enable the organization to meet this objective?

Options:

A.

Snapshots

B.

Mirroring

C.

Log shipping

D.

Data backups

Buy Now
Questions 400

Which of the following activities provides an IS auditor with the MOST insight regarding potential single person dependencies that might exist within the organization?

Options:

A.

Reviewing vacation patterns

B.

Reviewing user activity logs

C.

Interviewing senior IT management

D.

Mapping IT processes to roles

Buy Now
Questions 401

An IS auditor discovers that backups of critical systems are not being performed in accordance with the recovery point objective (RPO) established in the business continuity plan (BCP). What should the auditor do NEXT?

Options:

A.

Request an immediate backup be performed.

B.

Expand the audit scope.

C.

Identify the root cause.

D.

Include the observation in the report.

Buy Now
Questions 402

Which of the following will BEST ensure that a proper cutoff has been established to reinstate transactions and records to their condition just prior to a computer system failure?

Options:

A.

Rotating backup copies of transaction files offsite

B.

Using a database management system (DBMS) to dynamically back-out partially processed transactions

C.

Maintaining system console logs in electronic formal

D.

Ensuring bisynchronous capabilities on all transmission lines

Buy Now
Questions 403

An IT balanced scorecard is the MOST effective means of monitoring:

Options:

A.

governance of enterprise IT.

B.

control effectiveness.

C.

return on investment (ROI).

D.

change management effectiveness.

Buy Now
Questions 404

An organization ' s security team created a simulated production environment with multiple vulnerable applications. What would be the PRIMARY purpose of creating such an environment?

Options:

A.

To collect digital evidence of cyberattacks

B.

To attract attackers in order to study their behavior

C.

To provide training to security managers

D.

To test the intrusion detection system (IDS)

Buy Now
Questions 405

Which of the following is the BEST method to delete sensitive information from storage media that will be reused?

Options:

A.

Cross-cut shredding.

B.

Multiple overwriting.

C.

Repartitioning.

D.

Reformatting.

Buy Now
Questions 406

Which of the following applications has the MOST inherent risk and should be prioritized during audit planning?

Options:

A.

A decommissioned legacy application

B.

An onsite application that is unsupported

C.

An outsourced accounting application

D.

An internally developed application

Buy Now
Questions 407

Which of the following should an IS auditor do FIRST when auditing a robotics process automation (RPA) implementation?

Options:

A.

Evaluate the overall solution architecture.

B.

Analyze the sequence of activities performed by the robot.

C.

Understand the business processes automated by the robot.

D.

Identity the credentials used by the robot and where they are stored.

Buy Now
Questions 408

Which of the following fire suppression systems needs to be combined with an automatic switch to shut down the electricity supply in the event of activation?

Options:

A.

Carbon dioxide

B.

FM-200

C.

Dry pipe

D.

Halon

Buy Now
Questions 409

Which of the following is MOST critical for the effective implementation of IT governance?

Options:

A.

Strong risk management practices

B.

Internal auditor commitment

C.

Supportive corporate culture

D.

Documented policies

Buy Now
Questions 410

Which of the following is MOST effective in keeping a database management system (DBMS) at maximum performance?

Options:

A.

Periodic database maintenance.

B.

Data consistency control.

C.

Database logging.

D.

Data model normalization.

Buy Now
Questions 411

When reviewing hard disk utilization reports, an IS auditor observes that utilization is routinely above 95%. Which of the following should be the GREATEST concern to the IS auditor?

Options:

A.

Availability

B.

Consistency

C.

Denial of service (DoS) attacks

D.

Data security

Buy Now
Questions 412

Which of the following scenarios would MOST likely raise a concern about auditor independence?

Options:

A.

The auditor was on the implementation team of a project currently being audited.

B.

The auditor has not completed annual business ethics training.

C.

The auditor used to manage the same business process at a different organization.

D.

The auditor attended design and development meetings to monitor progress.

Buy Now
Questions 413

An IS auditor reviewing an organization’s online payment system finds that the system sometimes duplicates payments. Which control will BEST compensate for this weakness?

Options:

A.

Using hash totals

B.

Performing a bank reconciliation

C.

Manually receipting payments

D.

Using control totals

Buy Now
Questions 414

A characteristic of a digital signature is that it

Options:

A.

is under control of the receiver

B.

is unique to the message

C.

is validated when data are changed

D.

has a reproducible hashing algorithm

Buy Now
Questions 415

An externally facing system containing sensitive data is configured such that users have either read-only or administrator rights. Most users of the system have administrator access. Which of the following is the GREATEST risk associated with this situation?

Options:

A.

Users can export application logs.

B.

Users can view sensitive data.

C.

Users can make unauthorized changes.

D.

Users can install open-licensed software.

Buy Now
Questions 416

Management receives information indicating a high level of risk associated with potential flooding near the organization ' s data center within the next few years. As a result, a decision has been made to move data center operations to another facility on higher ground. Which approach has been adopted?

Options:

A.

Risk avoidance

B.

Risk transfer

C.

Risk acceptance

D.

Risk reduction

Buy Now
Questions 417

Which of the following activities should be separated in an organization’s incident management processes?

Options:

A.

Recording and classifying incidents.

B.

Collecting and analyzing logs from devices.

C.

Identifying root causes and recommending workarounds.

D.

Initiating and closing error logs.

Buy Now
Questions 418

A post-implementation audit has been completed for the deployment of a sophisticated job scheduling tool Which of the following observations would be of GREATEST concern?

Options:

A.

The IT learn customized tool settings without seeking approval from the provider.

B.

The overall project took longer to complete than planned.

C.

The data encryption setting is not enabled in the scheduling tool.

D.

The IT team accesses the scheduler admin panel via a generic account.

Buy Now
Questions 419

Which of the following would BEST help lo support an auditor’s conclusion about the effectiveness of an implemented data classification program?

Options:

A.

Purchase of information management tools

B.

Business use cases and scenarios

C.

Access rights provisioned according to scheme

D.

Detailed data classification scheme

Buy Now
Questions 420

An IS auditor discovers that an IT organization serving several business units assigns equal priority to all initiatives, creating a risk of delays in securing project funding Which of the following would be MOST helpful in matching demand for projects and services with available resources in a way that supports business objectives?

Options:

A.

Project management

B.

Risk assessment results

C.

IT governance framework

D.

Portfolio management

Buy Now
Questions 421

Which of the following statements appearing in an organization ' s acceptable use policy BEST demonstrates alignment with data classification standards related to the protection of information assets?

Options:

A.

Any information assets transmitted over a public network must be approved by executive management.

B.

All information assets must be encrypted when stored on the organization ' s systems.

C.

Information assets should only be accessed by persons with a justified need.

D.

All information assets will be assigned a clearly defined level to facilitate proper employee handling.

Buy Now
Questions 422

Which of the following should be of GREATEST concern to an |$ auditor reviewing data conversion and migration during the implementation of a newapplication system?

Options:

A.

The change management process was not formally documented

B.

Backups of the old system and data are not available online

C.

Unauthorized data modifications occurred during conversion,

D.

Data conversion was performed using manual processes

Buy Now
Questions 423

After delivering an audit report, the audit manager discovers that evidence was overlooked during the audit This evidence indicates that a procedural control may have failed and could contradict a conclusion of the audit Which of the following risks is MOST affected by this oversight?

Options:

A.

Inherent

B.

Operational

C.

Audit

D.

Financial

Buy Now
Questions 424

Data from a system of sensors located outside of a network is received by the open ports on a server. Which of the following is the BEST way to ensure the integrity of the data being collected from the sensor system?

Options:

A.

Route the traffic from the sensor system through a proxy server.

B.

Hash the data that is transmitted from the sensor system.

C.

Implement network address translation on the sensor system.

D.

Transmit the sensor data via a virtual private network (VPN) to the server.

Buy Now
Questions 425

Which of the following BEST enables an IS auditor to prioritize financial reporting spreadsheets for an end-user computing (EUC) audit?

Options:

A.

Understanding the purpose of each spreadsheet

B.

Identifying the spreadsheets with built-in macros

C.

Reviewing spreadsheets based on file size

D.

Ascertaining which spreadsheets are most frequently used

Buy Now
Questions 426

Which of the following is the PRIMARY reason to follow a configuration management process to maintain application?

Options:

A.

To optimize system resources

B.

To follow system hardening standards

C.

To optimize asset management workflows

D.

To ensure proper change control

Buy Now
Questions 427

Which of the following is MOST appropriate to review when determining if the work completed on an IT project is in alignment with budgeted costs?

Options:

A.

Return on investment (ROI) analysis

B.

Earned value analysis (EVA)

C.

Financial value analysis

D.

Business impact analysis (BIA)

Buy Now
Questions 428

Which of the following methods will BEST reduce the risk associated with the transition to a new system using technologies that are not compatible with the old system?

Options:

A.

Parallel changeover

B.

Modular changeover

C.

Phased operation

D.

Pilot operation

Buy Now
Questions 429

Which of the following should be the GREATEST concern to an IS auditor reviewing the information security framework of an organization?

Options:

A.

The information security policy has not been updated in the last two years.

B.

Senior management was not involved in the development of the information security policy.

C.

A list of critical information assets was not included in the information security policy.

D.

The information security policy is not aligned with regulatory requirements.

Buy Now
Questions 430

Which of the following observations should be of GREATEST concern to an IS auditor reviewing an organization ' s enterprise architecture (EA) program?

Options:

A.

IT application owners have sole responsibility for architecture approval.

B.

The architecture review board is chaired by the CIO.

C.

Information security requirements are reviewed by the EA program.

D.

The EA program governs projects that are not IT-related.

Buy Now
Questions 431

Which of the following is the PRIMARY benefit of effective implementation of appropriate data classification?

Options:

A.

Ability to meet business requirements

B.

Assurance that sensitive data is encrypted

C.

Increased accuracy of sensitive data

D.

Management of business risk to sensitive data

Buy Now
Questions 432

An IS auditor is reviewing a data conversion project Which of the following is the auditor ' s BEST recommendation prior to go-live?

Options:

A.

Review test procedures and scenarios

B.

Conduct a mock conversion test

C.

Establish a configuration baseline

D.

Automate the test scripts

Buy Now
Questions 433

An IS auditor finds an IT manager recently changed a Software as a Service (SaaS) provider contract in an effort to cut costs. The new contract increases the time to resolve incidents. Which of the following should be the auditor’s GREATEST concern?

Options:

A.

The impact on business processes has not been evaluated.

B.

The new contract is not in compliance with IT security policy.

C.

The corresponding service level agreement (SLA) was not modified.

D.

Alternative cost-reduction methods were not considered.

Buy Now
Questions 434

Coding standards provide which of the following?

Options:

A.

Program documentation

B.

Access control tables

C.

Data flow diagrams

D.

Field naming conventions

Buy Now
Questions 435

Which of the following is a method to prevent disclosure of classified documents printed on a shared printer?

Options:

A.

Using passwords to allow authorized users to send documents to the printer

B.

Requiring a key code to be entered on the printer to produce hard copy

C.

Encrypting the data stream between the user ' s computer and the printer

D.

Producing a header page with classification level for printed documents

Buy Now
Questions 436

The BEST way to evaluate the effectiveness of a newly developed application is to:

Options:

A.

perform a post-implementation review-

B.

analyze load testing results.

C.

perform a secure code review.

D.

review acceptance testing results.

Buy Now
Questions 437

An IS auditor learns that an in-house system development life cycle (SDLC) project has not met user specifications. The auditor should FIRST examine requirements from which of the following phases?

Options:

A.

Configuration phase

B.

User training phase

C.

Quality assurance (QA) phase

D.

Development phase

Buy Now
Questions 438

During an IT governance audit, an IS auditor notes that IT policies and procedures are not regularly reviewed and updated. The GREATEST concern to the IS auditor is that policies and procedures might not:

Options:

A.

reflect current practices.

B.

include new systems and corresponding process changes.

C.

incorporate changes to relevant laws.

D.

be subject to adequate quality assurance (QA).

Buy Now
Questions 439

Which of the following is the MOST important responsibility of user departments associated with program changes?

Options:

A.

Providing unit test data

B.

Analyzing change requests

C.

Updating documentation lo reflect latest changes

D.

Approving changes before implementation

Buy Now
Questions 440

What is the purpose of hashing a document?

Options:

A.

To prevent unauthorized disclosure of the contents

B.

To validate the integrity of the file contents

C.

To classify the file for internal use only

D.

To compress the size of the file

Buy Now
Questions 441

Which of the following is the MAIN risk associated with adding a new system functionality during the development phase without following a project change

management process?

Options:

A.

The added functionality has not been documented.

B.

The new functionality may not meet requirements.

C.

The project may fail to meet the established deadline.

D.

The project may go over budget.

Buy Now
Questions 442

Which of the following is the GREATEST security risk associated with data migration from a legacy human resources (HR) system to a cloud-based system?

Options:

A.

Data from the source and target system may be intercepted.

B.

Data from the source and target system may have different data formats.

C.

Records past their retention period may not be migrated to the new system.

D.

System performance may be impacted by the migration

Buy Now
Questions 443

Which of the following is found in an audit charter?

Options:

A.

The process of developing the annual audit plan

B.

The authority given to the audit function

C.

Required training for audit staff

D.

Audit objectives and scope

Buy Now
Questions 444

During the course of an IS audit, management verbally agreed with an issue identified by the IS auditor. However, when presented in a draft report, management disagreed with the finding. What should the auditor do NEXT?

Options:

A.

Rewrite the finding according to management’s suggestion.

B.

Discontinue further consultation and issue a final report as written.

C.

Provide evidence for the finding and request a follow-up meeting.

D.

Report the matter immediately to the chair of the audit committee.

Buy Now
Questions 445

Which of the following techniques BEST mitigates the risk of pervasive network attacks?

Options:

A.

Segmentation

B.

Configuration assessment

C.

Encryption

D.

Demilitarized zone (DMZ)

Buy Now
Questions 446

Which of the following presents the GREATEST risk associated with end-user computing (EUC) applica-tions over financial reporting?

Options:

A.

Inability to quickly modify and deploy a solution

B.

Lack of portability for users

C.

Loss of time due to manual processes

D.

Calculation errors in spreadsheets

Buy Now
Questions 447

Which of the following is MOST important for an IS auditor to verify when evaluating tne upgrade of an organization ' s enterprise resource planning (ERP) application?

Options:

A.

Application related documentation was updated to reflect the changes in the new version

B.

Security configurations were appropriately applied to the new version

C.

Users were provided security training on the new version

D.

Lessons teamed analysis was documented after the upgrade

Buy Now
Questions 448

Which of the following is the PRIMARY reason for an IS auditor to perform a risk assessment?

Options:

A.

It helps to identify areas with a relatively high probability of material problems.

B.

It provides a basis for the formulation of corrective action plans.

C.

It increases awareness of the types of management actions that may be inappropriate

D.

It helps to identify areas that are most sensitive to fraudulent or inaccurate practices

Buy Now
Questions 449

During the planning stage of a compliance audit, an IS auditor discovers that a bank ' s inventory of compliance requirements does not include recent regulatory changes related to managing data risk. What should the auditor do FIRST?

Options:

A.

Ask management why the regulatory changes have not been Included.

B.

Discuss potential regulatory issues with the legal department

C.

Report the missing regulatory updates to the chief information officer (CIO).

D.

Exclude recent regulatory changes from the audit scope.

Buy Now
Questions 450

Which of the following BEST describes the concept of fault tolerance in system resiliency?

Options:

A.

It enables switching to redundant systems in case of faults.

B.

It minimizes downtime and ensures continuous operations.

C.

It allows systems to continue operating in the presence of faults.

D.

It distributes workloads across multiple servers to prevent overload.

Buy Now
Questions 451

An IS auditor reviewing the threat assessment tor a data center would be MOST concerned if:

Options:

A.

some of the identified throats are unlikely to occur.

B.

all identified throats relate to external entities.

C.

the exercise was completed by local management.

D.

neighboring organizations operations have been included.

Buy Now
Questions 452

When an organization conducts business process improvements, the IS auditor should be MOST concerned with the:

Options:

A.

metrics used to evaluate key operating segments.

B.

adequacy of the controls in the redesigned process.

C.

adequacy of reporting to senior management.

D.

lack of version control over process documentation.

Buy Now
Questions 453

A global bank plans to use a cloud provider for backup of customer financial data. Which of the following should be the PRIMARY focus of this project?

Options:

A.

Backup testing schedule

B.

Data retention policy

C.

Transfer frequency

D.

Data confidentiality

Buy Now
Questions 454

Which of the following observations should be of GREATEST concern to an IS auditor assessing access controls for the accounts payable module of a finance system?

Options:

A.

Payment files are stored on a shared drive in a writable format prior to processing.

B.

Accounts payable staff have access to update vendor bank account details.

C.

The IS auditor was granted access to create purchase orders.

D.

Configured delegation limits do not align to the organization ' s delegation’s policy.

Buy Now
Questions 455

Which of the following is MOST important for an IS auditor to confirm when reviewing an organization ' s incident response management program?

Options:

A.

All incidents have a severity level assigned.

B.

All identified incidents are escalated to the CEO and the CISO.

C.

Incident response is within defined service level agreements (SLAs).

D.

The alerting tools and incident response team can detect incidents.

Buy Now
Questions 456

Which of the following would be an auditor ' s GREATEST concern when reviewing data inputs from spreadsheets into the core finance system?

Options:

A.

Undocumented code formats data and transmits directly to the database.

B.

There is not a complete inventory of spreadsheets, and file naming is inconsistent.

C.

The department data protection policy has not been reviewed or updated for two years.

D.

Spreadsheets are accessible by all members of the finance department.

Buy Now
Questions 457

Which of the following Is the BEST way to ensure payment transaction data is restricted to the appropriate users?

Options:

A.

Implementing two-factor authentication

B.

Restricting access to transactions using network security software

C.

implementing role-based access at the application level

D.

Using a single menu tor sensitive application transactions

Buy Now
Questions 458

Which of the following BEST indicates that the effectiveness of an organization ' s security awareness program has improved?

Options:

A.

A decrease in the number of information security audit findings

B.

An increase in the number of staff who complete awareness training

C.

An increase in the number of phishing emails reported by employees

D.

A decrease in the number of malware outbreaks

Buy Now
Questions 459

Which of the following would BEST assist an IS auditor in understanding the inputs and outputs of a microservice-oriented application?

Options:

A.

Data flow diagrams

B.

Network architecture diagrams

C.

Business requirements documentation

D.

Entity-relationship diagrams

Buy Now
Questions 460

An IS auditor should ensure that an application ' s audit trail:

Options:

A.

has adequate security.

B.

logs ail database records.

C.

Is accessible online

D.

does not impact operational efficiency

Buy Now
Questions 461

Afire alarm system has been installed in the computer room The MOST effective location for the fire alarm control panel would be inside the

Options:

A.

computer room closest to the uninterruptible power supply (UPS) module

B.

computer room closest to the server computers

C.

system administrators’ office

D.

booth used by the building security personnel

Buy Now
Questions 462

Which of the following would be of GREATEST concern to an IS auditor reviewing an IT-related customer service project?

Options:

A.

The project risk exceeds the organization ' s risk appetite.

B.

Executing the project will require additional investments.

C.

Expected business value is expressed in qualitative terms.

D.

The organization will be the first to offer the proposed services.

Buy Now
Questions 463

An IS auditor is reviewing the disaster recovery plan (DRP) of an organization with offices across multiple regions. Which of the following should be the auditor ' s PRIMARY focus?

Options:

A.

Recovery point objective (RPO) monitoring

B.

Processes and system dependencies

C.

Disaster recovery training

D.

Data backup and storage changes

Buy Now
Questions 464

Which of the following is MOST important for an IS auditor to validate when reviewing the controls for an organization ' s quality management system (QMS)?

Options:

A.

Whether root cause analysis is performed on all failed and rejected changes

B.

Whether critical services are delivered in a timely and sustainable manner

C.

Whether there is a process to monitor continuous improvement areas and necessary targets

D.

Whether the organization follows an industry-recognized service management framework

Buy Now
Questions 465

An IS auditor discovers that validation controls m a web application have been moved from the server side into the browser to boost performance This would MOST likely increase the risk of a successful attack by.

Options:

A.

phishing.

B.

denial of service (DoS)

C.

structured query language (SQL) injection

D.

buffer overflow

Buy Now
Questions 466

An organization is disposing of removable onsite media which contains sensitive information. Which of the following is the MOST effective method to prevent disclosure of sensitive data?

Options:

A.

Encrypting and destroying keys

B.

Machine shredding

C.

Software formatting

D.

Wiping and rewriting three times

Buy Now
Questions 467

Which of the following features of a library control software package would protect against unauthorized updating of source code?

Options:

A.

Required approvals at each life cycle step

B.

Date and time stamping of source and object code

C.

Access controls for source libraries

D.

Release-to-release comparison of source code

Buy Now
Questions 468

An organization has partnered with a third party to transport backup drives to an offsite storage facility. Which of the following is MOST important before sending the drives?

Options:

A.

Creating a chain of custody to accompany the drive in transit

B.

Ensuring data protection is aligned with the data classification policy

C.

Encrypting the drive with strong protection standards

D.

Ensuring the drive is placed in a tamper-evident mechanism

Buy Now
Questions 469

An organization has decided to reengineer business processes to improve the performance of overall IT service delivery. Which of the following recommendations from the project team should be the GREATEST concern to the IS auditor?

Options:

A.

Disable operational logging to enhance the processing speed and save storage.

B.

Adopt a service delivery model based on insights from peer organizations.

C.

Delegate business decisions to the chief risk officer (CRO).

D.

Eliminate certain reports and key performance indicators (KPIs)

Buy Now
Questions 470

An organization is migrating its HR application to an Infrastructure as a Service (laaS) model in a private cloud. Who is PRIMARILY responsible for the security configurations of the deployed application ' s operating system?

Options:

A.

The cloud provider ' s external auditor

B.

The cloud provider

C.

The operating system vendor

D.

The organization

Buy Now
Questions 471

An IS auditor is evaluating the access controls for a shared customer relationship management (CRM) system. Which of the following would be the GREATEST concern?

Options:

A.

Single sign-on is not enabled

B.

Audit logging is not enabled

C.

Security baseline is not consistently applied

D.

Complex passwords are not required

Buy Now
Questions 472

An IS auditor suspects an organization ' s computer may have been used to commit a crime. Which of the following is the auditor ' s BEST course of action?

Options:

A.

Examine the computer to search for evidence supporting the suspicions.

B.

Advise management of the crime after the investigation.

C.

Contact the incident response team to conduct an investigation.

D.

Notify local law enforcement of the potential crime before further investigation.

Buy Now
Questions 473

An IS auditor is reviewing a contract for the outsourcing of IT facilities. If missing, which of the following should present the GREATEST concern to the auditor?

Options:

A.

Hardware configurations

B.

Access control requirements

C.

Help desk availability

D.

Perimeter network security diagram

Buy Now
Questions 474

An IS auditor is planning a review of an organizations robotic process automation (RPA) technology. Which of the following MUST be included in the audit work plan?

Options:

A.

Integration architecture

B.

Change management

C.

Cost-benefit analysis

D.

Employee training content

Buy Now
Questions 475

Which of the following provides the MOST useful information regarding an organization ' s risk appetite and tolerance?

Options:

A.

Gap analysis

B.

Audit reports

C.

Risk profile

D.

Risk register

Buy Now
Questions 476

An IS auditor is reviewing the installation of a new server. The IS auditor ' s PRIMARY objective is to ensure that

Options:

A.

security parameters are set in accordance with the manufacturer s standards.

B.

a detailed business case was formally approved prior to the purchase.

C.

security parameters are set in accordance with the organization ' s policies.

D.

the procurement project invited lenders from at least three different suppliers.

Buy Now
Questions 477

Which of the following is the MOST effective control to mitigate unintentional misuse of authorized access?

Options:

A.

Annual sign-off of acceptable use policy

B.

Regular monitoring of user access logs

C.

Security awareness training

D.

Formalized disciplinary action

Buy Now
Questions 478

Following the complete corruption of a database, an organization recovered its customer data from the most recent available backup. However, the organization has started receiving many complaints about discrepancies in customer data. Which of the following is MOST important for an IS auditor to review in this situation?

Options:

A.

Service level agreement (SLA)

B.

Maximum tolerable outage (MTO)

C.

Recovery time objective (RTO)

D.

Recovery point objective (RPO)

Buy Now
Questions 479

Which of the following should be done FIRST when creating a data protection program?

Options:

A.

Implement data loss prevention (DLP) controls.

B.

Perform classification based on standards.

C.

Deploy intrusion detection systems (IDS).

D.

Test logical access controls for effectiveness.

Buy Now
Exam Code: CISA
Exam Name: Certified Information Systems Auditor
Last Update: Aug 4, 2026
Questions: 1598

PDF + Testing Engine

$74.7  $249

Testing Engine

$67.5  $225
buy now CISA testing engine

PDF (Q&A)

$59.7  $199
buy now CISA pdf
dumpsmate guaranteed to pass

24/7 Customer Support

DumpsMate's team of experts is always available to respond your queries on exam preparation. Get professional answers on any topic of the certification syllabus. Our experts will thoroughly satisfy you.

Site Secure

mcafee secure

TESTED 04 Aug 2026