Weekend Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

Isaca CISA Dumps

Page: 1 / 160
Total 1598 questions

Certified Information Systems Auditor Questions and Answers

Question 1

Which of the following findings should be an IS auditor’s GREATEST concern when reviewing a project to migrate confidential data backups to a cloud-based solution?

Options:

A.

Lack of chain of custody for retired backup media

B.

Insufficient scalability

C.

Insufficient due diligence performed on the vendor

D.

Increased storage cost

Question 2

Which of the following is the PRIMARY reason to perform a risk assessment?

Options:

A.

To determine the current risk profile

B.

To ensure alignment with the business impact analysis (BIA)

C.

To achieve compliance with regulatory requirements

D.

To help allocate budget for risk mitigation controls

Question 3

Which of the following metrics would BEST measure the agility of an organization ' s IT function?

Options:

A.

Average number of learning and training hours per IT staff member

B.

Frequency of security assessments against the most recent standards and guidelines

C.

Average time to turn strategic IT objectives into an agreed upon and approved initiative

D.

Percentage of staff with sufficient IT-related skills for the competency required of their roles

Question 4

Management receives information indicating a high level of risk associated with potential flooding near the organization ' s data center within the next few years. As a result, a decision has been made to move data center operations to another facility on higher ground. Which approach has been adopted?

Options:

A.

Risk avoidance

B.

Risk transfer

C.

Risk acceptance

D.

Risk reduction

Question 5

Which of the following should an IS auditor expect to see in a network vulnerability assessment?

Options:

A.

Misconfiguration and missing updates

B.

Malicious software and spyware

C.

Zero-day vulnerabilities

D.

Security design flaws

Question 6

The MOST important objective of a post-implementation audit is to:

Options:

A.

Address lessons learned from the project.

B.

Determine whether the required objectives were met.

C.

Develop a process for continuous improvement.

D.

Seek approval for the next implementation phase.

Question 7

An IS auditor is reviewing the backup procedures in an organization that has high volumes of data with frequent changes to transactions. Which of the following is the BEST backup scheme to recommend given the need for a shorter restoration time in the event of a disruption?

Options:

A.

Differential backup

B.

Full backup

C.

Incremental backup

D.

Mirror backup

Question 8

What is the FIRST step when creating a data classification program?

Options:

A.

Categorize and prioritize data.

B.

Develop data process maps.

C.

Categorize information by owner.

D.

Develop a policy.

Question 9

What is the BEST way to reduce the risk of inaccurate or misleading data proliferating through business intelligence systems?

Options:

A.

Establish rules for converting data from one format to another

B.

Implement data entry controls for new and existing applications

C.

Implement a consistent database indexing strategy

D.

Develop a metadata repository to store and access metadata

Question 10

An IS auditor is reviewing how password resets are performed for users working remotely. Which type of documentation should be requested to understand the detailed steps required for this activity?

Options:

A.

Standards

B.

Guidelines

C.

Policies

D.

Procedures

Question 11

Which of the following should an IS auditor consider the MOST significant risk associated with a new health records system that replaces a legacy system?

Options:

A.

Staff were not involved in the procurement process, creating user resistance to the new system.

B.

Data is not converted correctly, resulting in inaccurate patient records.

C.

The deployment project experienced significant overruns, exceeding budget projections.

D.

The new system has capacity issues, leading to slow response times for users.

Question 12

A staff accountant regularly uploads spreadsheets with inventory levels to the organization ' s financial reporting system. The transfers are executed through a customized interface created by an in-house developer. Which of the following is MOST important for the IS auditor to confirm during a review of the interface?

Options:

A.

The data in the spreadsheet is correctly recorded in the financial system.

B.

The financial system transfers are performed by the accountant at predefined intervals.

C.

The spreadsheets do not contain malware or malicious macros.

D.

The data transfer connection does not support full duplex communication.

Question 13

When auditing an organization ' s software acquisition process the BEST way for an IS auditor to understand the software benefits to the organization would be to review the

Options:

A.

feasibility study

B.

business case

C.

request for proposal (RFP)

D.

alignment with IT strategy

Question 14

An IS auditor discovers an option in a database that allows the administrator to directly modify any table. This option is necessary to overcome bugs in the software, but is rarely used. Changes to tables are automatically logged. The IS auditor ' s FIRST action should be to:

Options:

A.

recommend that the option to directly modify the database be removed immediately.

B.

recommend that the system require two persons to be involved in modifying the database.

C.

determine whether the log of changes to the tables is backed up.

D.

determine whether the audit trail is secured and reviewed.

Question 15

Which of the following is the PRIMARY reason for an organization to conduct a formal information security audit?

Options:

A.

To align information security strategies with business objectives.

B.

To identify material information security vulnerabilities.

C.

To reduce information security software licensing costs.

D.

To monitor information security team productivity.

Question 16

An IS auditor is reviewing an organization ' s information asset management process. Which of the following would be of GREATEST concern to the auditor?

Options:

A.

The process does not require specifying the physical locations of assets.

B.

Process ownership has not been established.

C.

The process does not include asset review.

D.

Identification of asset value is not included in the process.

Question 17

Which of the following concerns is MOST effectively addressed by implementing an IT framework for alignment between IT and business objectives?

Options:

A.

Inaccurate business impact analysis (BIA)

B.

Inadequate IT change management practices

C.

Lack of a benchmark analysis

D.

Inadequate IT portfolio management

Question 18

Which of the following is the BEST way for management to ensure the effectiveness of the cybersecurity incident response process?

Options:

A.

Periodic reporting of cybersecurity incidents to key stakeholders

B.

Periodic update of incident response process documentation

C.

Periodic cybersecurity training for staff involved in incident response

D.

Periodic tabletop exercises involving key stakeholders

Question 19

What is the Most critical finding when reviewing an organization’s information security management?

Options:

A.

No dedicated security officer

B.

No official charier for the information security management system

C.

No periodic assessments to identify threats and vulnerabilities

D.

No employee awareness training and education program

Question 20

Which of the following should be an IS auditor ' s GREATEST concern when an international organization intends to roll out a global data privacy policy?

Options:

A.

Requirements may become unreasonable.

B.

The policy may conflict with existing application requirements.

C.

Local regulations may contradict the policy.

D.

Local management may not accept the policy.

Question 21

While conducting a follow-up on an asset management audit, the IS auditor finds paid invoices for IT devices not recorded in the organization ' s inventory. Which of the following is the auditor ' s BEST course of action?

Options:

A.

Ask the asset management staff where the devices are.

B.

Alert both audit and operations management about the discrepancy.

C.

Ignore the invoices since they are not part of the follow-up.

D.

Make a note of the evidence to include it in the scope of a future audit.

Question 22

Which of the following provides the MOST reliable audit evidence on the validity of transactions in a financial application?

Options:

A.

Walk-through reviews

B.

Substantive testing

C.

Compliance testing

D.

Design documentation reviews

Question 23

Aligning IT strategy with business strategy PRIMARILY helps an organization to:

Options:

A.

optimize investments in IT.

B.

create risk awareness across business units.

C.

increase involvement of senior management in IT.

D.

monitor the effectiveness of IT.

Question 24

An IS auditor determines elevated administrator accounts for servers that are not properly checked out and then back in after each use. Which of the following is the MOST appropriate sampling technique to determine the scope of the problem?

Options:

A.

Haphazard sampling

B.

Random sampling

C.

Statistical sampling

D.

Stratified sampling

Question 25

Which of the following is MOST likely to be reduced when implementing optimal risk management strategies?

Options:

A.

Sampling risk

B.

Residual risk

C.

Inherent risk

D.

Detection risk

Question 26

Which of the following is MOST helpful for understanding an organization’s key driver to modernize application platforms?

Options:

A.

Vendor software inventories

B.

Network architecture diagrams

C.

System-wide incident reports

D.

Inventory of end-of-life software

Question 27

Following an IT audit, management has decided to accept the risk highlighted in the audit report. Which of the following would provide the MOST assurance to the IS auditor that management

is adequately balancing the needs of the business with the need to manage risk?

Options:

A.

A communication plan exists for informing parties impacted by the risk.

B.

Potential impact and likelihood are adequately documented.

C.

Identified risk is reported into the organization ' s risk committee.

D.

Established criteria exist for accepting and approving risk.

Question 28

Which of the following represents the HIGHEST level of maturity of an information security program?

Options:

A.

A training program is in place to promote information security awareness.

B.

A framework is in place to measure risks and track effectiveness.

C.

Information security policies and procedures are established.

D.

The program meets regulatory and compliance requirements.

Question 29

Which of the following is MOST helpful to an IS auditor reviewing the alignment of planned IT budget with the organization ' s goals and strategic objectives?

Options:

A.

Enterprise architecture (EA)

B.

Business impact analysis (BIA)

C.

Risk assessment report

D.

Audit recommendations

Question 30

Which of the following is the BEST reason to implement a data retention policy?

Options:

A.

To limit the liability associated with storing and protecting information

B.

To document business objectives for processing data within the organization

C.

To assign responsibility and ownership for data protection outside IT

D.

To establish a recovery point detective (RPO) for (toaster recovery procedures

Question 31

Which of the following is MOST important for an IS auditor to determine during the detailed design phase of a system development project?

Options:

A.

Program coding standards have been followed

B.

Acceptance test criteria have been developed

C.

Data conversion procedures have been established.

D.

The design has been approved by senior management.

Question 32

Which of the following is a challenge in developing a service level agreement (SLA) for network services?

Options:

A.

Establishing a well-designed framework for network servirces.

B.

Finding performance metrics that can be measured properly

C.

Ensuring that network components are not modified by the client

D.

Reducing the number of entry points into the network

Question 33

Which of the following methods will BEST reduce the risk associated with the transition to a new system using technologies that are not compatible with the old system?

Options:

A.

Parallel changeover

B.

Modular changeover

C.

Phased operation

D.

Pilot operation

Question 34

An IS auditor is reviewing job scheduling software and notes instances of delayed processing time, unexpected job interruption, and out-of-sequence job execution. Which of the following should the auditor examine FIRST to help determine the reasons for these instances?

Options:

A.

System schedule

B.

Job schedule

C.

Exception log

D.

Change log

Question 35

Which of the following would be MOST effective in detecting the presence of an unauthorized wireless access point on an internal network?

Options:

A.

Continuous network monitoring

B.

Periodic network vulnerability assessments

C.

Review of electronic access logs

D.

Physical security reviews

Question 36

An IS auditor noted a recent production incident in which a teller transaction system incorrectly charged fees to customers due to a defect from a recent release. Which of the following should be the auditor ' s NEXT step?

Options:

A.

Evaluate developer training.

B.

Evaluate the incident management process.

C.

Evaluate the change management process.

D.

Evaluate secure code practices.

Question 37

Which of the following is the BEST control to mitigate the malware risk associated with an instant messaging (IM) system?

Options:

A.

Blocking attachments in IM

B.

Blocking external IM traffic

C.

Allowing only corporate IM solutions

D.

Encrypting IM traffic

Question 38

Which of the following would provide the BEST evidence of an IT strategy corrections effectiveness?

Options:

A.

The minutes from the IT strategy committee meetings

B.

Synchronization of IT activities with corporate objectives

C.

The IT strategy committee charier

D.

Business unit satisfaction survey results

Question 39

In which of the following sampling methods is the entire sample considered to be irregular if a single error is found?

Options:

A.

Discovery sampling

B.

Variable sampling

C.

Stop-or-go sampling

D.

Judgmental sampling

Question 40

In reviewing the IT strategic plan, the IS auditor should consider whether it identifies the:

Options:

A.

allocation of IT staff.

B.

project management methodologies used.

C.

major IT initiatives.

D.

links to operational tactical plans.

Question 41

Which of the following is the MOST effective method of destroying sensitive data stored on electronic media?

Options:

A.

Degaussing

B.

Random character overwrite

C.

Physical destruction

D.

Low-level formatting

Question 42

which of the following is a core functionality of a configuration and release management system?

Options:

A.

Managing privileged access to databases servers and infrastructure

B.

Identifying vulnerabilities in configuration settings

C.

Deploying a configuration change to the sandbox environment

D.

Identifying other configuration items that will be impacted by a given change

Question 43

Which of the following is MOST important to include when developing a business continuity plan (BCP)?

Options:

A.

Criteria for triggering the plan

B.

Details of linked security policies

C.

Details of a comprehensive asset inventory

D.

Plans for addressing all types of threats

Question 44

Which of the following would be of MOST concern for an IS auditor evaluating the design of an organization ' s incident management processes?

Options:

A.

Service management standards are not followed.

B.

Expected time to resolve incidents is not specified.

C.

Metrics are not reported to senior management.

D.

Prioritization criteria are not defined.

Question 45

During a follow-up audit, an IS auditor finds that some critical recommendations have the IS auditor ' s BEST course of action?

Options:

A.

Require the auditee to address the recommendations in full.

B.

Adjust the annual risk assessment accordingly.

C.

Evaluate senior management ' s acceptance of the risk.

D.

Update the audit program based on management ' s acceptance of risk.

Question 46

Which of the following is MOST important to ensure that electronic evidence collected during a forensic investigation will be admissible in future legal proceedings?

Options:

A.

Restricting evidence access to professionally certified forensic investigators

B.

Documenting evidence handling by personnel throughout the forensic investigation

C.

Performing investigative procedures on the original hard drives rather than images of the hard drives

D.

Engaging an independent third party to perform the forensic investigation

Question 47

Which of the following provides the BEST evidence of the validity and integrity of logs in an organization ' s security information and event management (SIEM) system?

Options:

A.

Compliance testing

B.

Stop-or-go sampling

C.

Substantive testing

D.

Variable sampling

Question 48

When reviewing whether IT investments are meeting business objectives, which of the following evaluations would be MOST useful?

Options:

A.

A break-even analysis

B.

Realized return on investment (ROI) versus projected ROI

C.

Budgeted spend versus actual spend

D.

Actual return on investment (ROI) versus industry average ROI

Question 49

When reviewing the disaster recovery strategy, IT management identified an application that requires a short recovery point objective (RPO). Which of the following data restoration strategies would BEST enable the organization to meet this objective?

Options:

A.

Snapshots

B.

Mirroring

C.

Log shipping

D.

Data backups

Question 50

An internal audit team is deciding whether to use an audit management application hosted by a third party in a different country.

What should be the MOST important consideration related to the uploading of payroll audit documentation in the hosted

application?

Options:

A.

Financial regulations affecting the organization

B.

Data center physical access controls whore the application is hosted

C.

Privacy regulations affecting the organization

D.

Per-unit cost charged by the hosting services provider for storage

Question 51

Which of the following is the MOST effective method to identify new errors introduced as a result of program changes?

Options:

A.

Unit testing.

B.

Interface testing.

C.

Integration testing.

D.

Regression testing.

Question 52

An IS auditor notes that the previous year ' s disaster recovery test was not completed within the scheduled time frame due to insufficient hardware allocated by a third-party vendor. Which of the following provides the BEST evidence that adequate resources are now allocated to successfully recover the systems?

Options:

A.

Service level agreement (SLA)

B.

Hardware change management policy

C.

Vendor memo indicating problem correction

D.

An up-to-date RACI chart

Question 53

An organization ' s networking team wants to route data between two virtual local area networks (VLANs). Which type of device is the BEST recommendation for installation of the VLANs?

Options:

A.

Switch

B.

Firewall

C.

Bridge

D.

Hub

Question 54

Which of the following measures BEST mitigates the risk of data exfiltration during a cyberattack?

Options:

A.

Data loss prevention (DLP) system

B.

Network access controls (NAC)

C.

Perimeter firewall

D.

Hashing of sensitive data

Question 55

Which of the following is MOST important to consider when defining disaster recovery strategies?

Options:

A.

Maximum tolerable downtime (MTD)

B.

Mean time to restore (MTTR)

C.

Mean time to acknowledge

D.

Maximum time between failures (MTBF)

Question 56

Which of the following should an IS auditor recommend as a PRIMARY area of focus when an organization decides to outsource technical support for its external customers?

Options:

A.

Align service level agreements (SLAs) with current needs.

B.

Monitor customer satisfaction with the change.

C.

Minimize costs related to the third-party agreement.

D.

Ensure right to audit is included within the contract.

Question 57

Which of the following MOST effectively manages frequent program file changes where simultaneous code edits are used?

Options:

A.

Mandatory architecture reviews.

B.

Source code composition scanning.

C.

Source code version control.

D.

Change control self-assessments (CSAs).

Question 58

To develop meaningful recommendations ' or findings, which of the following is MOST important ' or an IS auditor to determine and understand?

Options:

A.

Root cause

B.

Responsible party

C.

impact

D.

Criteria

Question 59

Which of the following is an audit reviewer ' s PRIMARY role with regard to evidence?

Options:

A.

Ensuring unauthorized individuals do not tamper with evidence after it has been captured

B.

Ensuring evidence is sufficient to support audit conclusions

C.

Ensuring appropriate statistical sampling methods were used

D.

Ensuring evidence is labeled to show it was obtained from an approved source

Question 60

Which of the following is the MOST important area of focus for an IS auditor when developing a risk-based audit strategy?

Options:

A.

Critical business applications

B.

Business processes

C.

Existing IT controls

D.

Recent audit results

Question 61

Which of the following is the MOST important reason for an IS auditor to examine the results of a post-incident review performed after a security incident?

Options:

A.

To evaluate the effectiveness of continuous improvement efforts

B.

To compare incident response metrics with industry benchmarks

C.

To re-analyze the incident to identify any hidden backdoors planted by the attacker

D.

To evaluate the effectiveness of the network firewall against future security breaches

Question 62

During an incident management audit, an IS auditor finds that several similar incidents were logged during the audit period. Which of the following is the auditor ' s MOST important course of action?

Options:

A.

Document the finding and present it to management.

B.

Determine if a root cause analysis was conducted.

C.

Confirm the resolution time of the incidents.

D.

Validate whether all incidents have been actioned.

Question 63

An IS auditor would MOST likely recommend that IT management use a balanced scorecard to:

Options:

A.

indicate whether the organization meets quality standards.

B.

ensure that IT staff meet performance requirements.

C.

train and educate IT staff.

D.

assess IT functions and processes.

Question 64

An IS auditor notes that several employees are spending an excessive amount of time using social media sites for personal reasons. Which of the following should the auditor recommend be performed FIRST?

Options:

A.

Implement a process to actively monitor postings on social networking sites.

B.

Adjust budget for network usage to include social media usage.

C.

Use data loss prevention (DLP) tools on endpoints.

D.

implement policies addressing acceptable usage of social media during working hours.

Question 65

Which of the following is the MAJOR advantage of automating internal controls?

Options:

A.

To enable the review of large value transactions

B.

To efficiently test large volumes of data

C.

To help identity transactions with no segregation of duties

D.

To assist in performing analytical reviews

Question 66

UESTION NO: 210

An accounting department uses a spreadsheet to calculate sensitive financial transactions. Which of the following is the MOST important control for maintaining the security of data in the spreadsheet?

Options:

A.

There Is a reconciliation process between the spreadsheet and the finance system

B.

A separate copy of the spreadsheet is routinely backed up

C.

The spreadsheet is locked down to avoid inadvertent changes

D.

Access to the spreadsheet is given only to those who require access

Question 67

Which of the following is an IS auditor’s BEST approach when low-risk anomalies have been identified?

Options:

A.

Reprioritize further testing of the anomalies and refocus on issues with higher risk

B.

Update the audit plan to include the information collected during the audit

C.

Ask auditees to promptly remediate the anomalies

D.

Document the anomalies in audit workpapers

Question 68

Which of the following is the BEST way to ensure that business continuity plans (BCPs) will work effectively in the event of a major disaster?

Options:

A.

Prepare detailed plans for each business function.

B.

Involve staff at all levels in periodic paper walk-through exercises.

C.

Regularly update business impact assessments.

D.

Make senior managers responsible for their plan sections.

Question 69

In an environment where data virtualization is used, which of the following provides the BEST disaster recovery solution?

Options:

A.

Onsite disk-based backup systems

B.

Tape-based backup systems

C.

Virtual tape library

D.

Redundant array of independent disks (RAID)

Question 70

Which of the following is the MOST effective way to evaluate the physical security of a data center?

Options:

A.

Review data center access logs.

B.

Interview data center stakeholders.

C.

Review camera footage from the data center.

D.

Perform a data center tour.

Question 71

An IS auditor is reviewing a contract for the outsourcing of IT facilities. If missing, which of the following should present the GREATEST concern to the auditor?

Options:

A.

Hardware configurations

B.

Access control requirements

C.

Help desk availability

D.

Perimeter network security diagram

Question 72

Which of the following is a social engineering attack method?

Options:

A.

An employee is induced to reveal confidential IP addresses and passwords by answering questions over the phone.

B.

A hacker walks around an office building using scanning tools to search for a wireless network to gain access.

C.

An intruder eavesdrops and collects sensitive information flowing through the network and sells it to third parties.

D.

An unauthorized person attempts to gain access to secure premises by following an authorized person through a secure door.

Question 73

Which of the following will be the MOST effective method to verify that a service vendor keeps control levels as required by the client?

Options:

A.

Conduct periodic on-site assessments using agreed-upon criteria.

B.

Periodically review the service level agreement (SLA) with the vendor.

C.

Conduct an unannounced vulnerability assessment of vendor ' s IT systems.

D.

Obtain evidence of the vendor ' s control self-assessment (CSA).

Question 74

The GREATEST concern for an IS auditor reviewing vulnerability assessments by the auditee would be if the assessments are:

Options:

A.

Conducted once per year just before system audits are scheduled.

B.

Conducted by the internal technical team instead of external experts.

C.

Performed for critical systems, not for the entire infrastructure.

D.

Performed using open-source testing tools.

Question 75

An IS auditor has been tasked with analyzing an organization ' s capital expenditures against its repair and maintenance costs. Which of the following is the BEST reason to use a data analytics tool for this purpose?

Options:

A.

It reduces the error rate.

B.

It improves the reliability of the data.

C.

It enables the auditor to work with 100% of the transactions.

D.

It reduces the sample size required to perform the audit.

Question 76

An IS auditor is reviewing the system development practices of an organization that is about to move from a Waterfall to an Agile approach. Which of the following is MOST important for the auditor to focus on as a result of this move?

Options:

A.

Secure code review

B.

Release management

C.

Capacity planning

D.

Code documentation

Question 77

Which of the following is the PRIMARY objective of implementing privacy-related controls within an organization?

Options:

A.

To prevent confidential data loss

B.

To comply with legal and regulatory requirements

C.

To identify data at rest and data in transit for encryption

D.

To provide options to individuals regarding use of their data

Question 78

Which of the following should be an IS auditor’s PRIMARY focus when performing a post-implementation review for a critical IT project?

Options:

A.

Confirm the project steering committee included business representation.

B.

Determine if project goals were met as expected.

C.

Determine if project completion was on time and on budget.

D.

Confirm key stakeholders signed off on project closure.

Question 79

Which of the following observations should be of GREATEST concern to an IS auditor reviewing an organization ' s enterprise architecture (EA) program?

Options:

A.

IT application owners have sole responsibility for architecture approval.

B.

The architecture review board is chaired by the CIO.

C.

Information security requirements are reviewed by the EA program.

D.

The EA program governs projects that are not IT-related.

Question 80

Which of the following would MOST effectively help to reduce the number of repealed incidents in an organization?

Options:

A.

Testing incident response plans with a wide range of scenarios

B.

Prioritizing incidents after impact assessment.

C.

Linking incidents to problem management activities

D.

Training incident management teams on current incident trends

Question 81

During which phase of the software development life cycle is it BEST to initiate the discussion of application controls?

Options:

A.

Business case development phase when stakeholders are identified

B.

Application design phase process functionalities are finalized

C.

User acceptance testing (UAT) phase when test scenarios are designed

D.

Application coding phase when algorithms are developed to solve business problems

Question 82

An IS auditor observes that a large number of departed employees have not been removed from the accounts payable system. Which of the following is MOST important to determine in order to assess the risk1?

Options:

A.

The frequency of user access reviews performed by management

B.

The frequency of intrusion attempts associated with the accounts payable system

C.

The process for terminating access of departed employees

D.

The ability of departed employees to actually access the system

Question 83

An IS auditor is reviewing an organization ' s incident management processes and procedures. Which of the following observations should be the auditor ' s GREATEST concern?

Options:

A.

Ineffective post-incident review

B.

Ineffective incident prioritization

C.

Ineffective incident detection

D.

Ineffective incident classification

Question 84

An external audit firm was engaged to perform a validation and verification review for a systems implementation project. The IS auditor identifies that regression testing is not part of the project plan and was not performed by the systems implementation team. According to the team, the parallel testing being performed is sufficient, making regression testing unnecessary. What should be the auditor’s NEXT step?

Options:

A.

Evaluate the extent of the parallel testing being performed

B.

Recommend integration and stress testing be conducted by the systems implementation team

C.

Conclude that parallel testing is sufficient and regression testing is not needed

D.

Recommend regression testing be conducted by the systems implementation team

Question 85

Which of the following is the MOST efficient solution for a multi-location healthcare organization that wants to be able to access patient data wherever patients present themselves

for care?

Options:

A.

Infrastructure as a Service (laaS) provider

B.

Software as a Service (SaaS) provider

C.

Network segmentation

D.

Dynamic localization

Question 86

Which of the following controls is BEST implemented through system configuration?

Network user accounts for temporary workers expire after 90 days.

Application user access is reviewed every 180 days for appropriateness.

Financial data in key reports is traced to source systems for completeness and accuracy.

Options:

A.

Computer operations personnel initiate batch processing jobs daily.

Question 87

Which of the following technologies has the SMALLEST maximum range for data transmission between devices?

Options:

A.

Wi-Fi

B.

Bluetooth

C.

Long-term evolution (LTE)

D.

Near-field communication (NFC)

Question 88

Which of the following would be of GREATEST concern to an IS auditor reviewing an IT strategy document?

Options:

A.

Target architecture is defined at a technical level.

B.

The previous year ' s IT strategic goals were not achieved.

C.

Strategic IT goals are derived solely from the latest market trends.

D.

Financial estimates of new initiatives are disclosed within the document.

Question 89

Which of the following BEST enables alignment of IT with business objectives?

Options:

A.

Benchmarking against peer organizations

B.

Developing key performance indicators (KPIs)

C.

Completing an IT risk assessment

D.

Leveraging an IT governance framework

Question 90

Which of the following provides the BEST evidence that system requirements are met when evaluating a project before implementation?

Options:

A.

Integration testing results

B.

Sign-off from senior management

C.

User acceptance testing (UAT) results

D.

Regression testing results

Question 91

Which of the following is the BEST control to mitigate attacks that redirect internet traffic to an unauthorized website?

Options:

A.

Conduct regular user security awareness training.

B.

Enforce strong web browser security controls.

C.

Perform domain name system (DNS) server security hardening.

D.

Implement a web application firewall (WAF).

Question 92

During an information security review, an IS auditor learns an organizational policy requires all employ-ees to attend information security training during the first week of each new year. What is

the auditor ' s BEST recommendation to ensure employees hired after January receive adequate guid-ance regarding security awareness?

Options:

A.

Ensure new employees read and sign acknowledgment of the acceptable use policy.

B.

Revise the policy to include security training during onboarding.

C.

Revise the policy to require security training every six months for all employees.

D.

Require management of new employees to provide an overview of security awareness.

Question 93

Management has requested a post-implementation review of a newly implemented purchasing package to determine the extent that business requirements are being met. Which of the following

is MOST likely to be assessed?

Options:

A.

Acceptance testing results

B.

Results of live processing

C.

Implementation methodology

D.

Purchasing guidelines and policies

Question 94

Which of the following provides the BEST assurance that vendor-supported software remains up to date?

Options:

A.

Release and patch management

B.

Licensing agreement and escrow

C.

Software asset management

D.

Version management

Question 95

The PRIMARY reason to assign data ownership for protection of data is to establish:

Options:

A.

reliability.

B.

traceability.

C.

authority,

D.

accountability.

Question 96

Which type of testing is used to identify security vulnerabilities in source code in the development environment?

Options:

A.

Interactive application security testing (IAST)

B.

Runtime application self-protection (RASP)

C.

Dynamic analysis security testing (DAST)

D.

Static analysis security testing (SAST)

Question 97

Who is accountable for an organization ' s enterprise risk management (ERM) program?

Options:

A.

Board of directors

B.

Steering committee

C.

Chief risk officer (CRO)

D.

Executive management

Question 98

An IS auditor is conducting a post-implementation review of an enterprise resource planning (ERP) system. End users indicated concerns with the accuracy of critical automatic calculations made by the system. The auditor ' s FIRST course of action should be to:

Options:

A.

review recent changes to the system.

B.

verify completeness of user acceptance testing (UAT).

C.

verify results to determine validity of user concerns.

D.

review initial business requirements.

Question 99

Which of the following is the MOST significant risk when an application uses individual end-user accounts to access the underlying database?

Options:

A.

Multiple connects to the database are used and slow the process_

B.

User accounts may remain active after a termination.

C.

Users may be able to circumvent application controls.

D.

Application may not capture a complete audit trail.

Question 100

Which of the following BEST enables an organization to improve the effectiveness of its incident response team?

Options:

A.

Conducting periodic testing and incorporating lessons learned

B.

Increasing the mean resolution time and publishing key performance indicator (KPI) metrics

C.

Disseminating incident response procedures and requiring signed acknowledgment by team members

D.

Ensuring all team members understand information systems technology

Question 101

An organization that processes credit card information employs a remote workforce. Which of the following is the MOST effective way to mitigate risk associated with data exfiltration?

Options:

A.

Require employees to sign acknowledgment of the data security policy.

B.

Deploy a data loss prevention (DLP) system.

C.

Enable a web application firewall (WAF) along with an intrusion detection system (IDS).

D.

Implement a security information and event management (SIEM) solution.

Question 102

A small business unit is implementing a control self-assessment (CSA) program and leveraging the internal

audit function to test its internal controls annually. Which of the following is the MOST significant benefit of

this approach?

Options:

A.

Compliance costs are reduced.

B.

Risks are detected earlier.

C.

Business owners can focus more on their core roles.

D.

Line management is more motivated to avoid control exceptions.

Question 103

The waterfall life cycle model of software development is BEST suited for which of the following situations?

Options:

A.

The project will involve the use of new technology.

B.

The project intends to apply an object-oriented design approach.

C.

The project requirements are well understood.

D.

The project is subject to time pressures.

Question 104

An organization has decided to purchase a web-based email service from a third-party vendor and eliminate its own email server infrastructure. What type of cloud computing environment would BEST meet the organization ' s objective?

Options:

A.

Platform as a Service (PaaS)

B.

Software as a Service (SaaS)

C.

Database as a Service (DBaaS)

D.

Infrastructure as a Service (laaS)

Question 105

A new regulation in one country of a global organization has recently prohibited cross-border transfer of personal data. An IS auditor has been asked to determine the organization ' s level of exposure In the affected country. Which of the following would be MOST helpful in making this assessment?

Options:

A.

Developing an inventory of all business entities that exchange personal data with the affected jurisdiction

B.

Identifying data security threats in the affected jurisdiction

C.

Reviewing data classification procedures associated with the affected jurisdiction

D.

Identifying business processes associated with personal data exchange with the affected jurisdiction

Question 106

Which of the following is an IS auditor ' s BEST recommendation to protect an organization from attacks when its file server needs to be accessible to external users?

Options:

A.

Enforce a secure tunnel connection.

B.

Enhance internal firewalls.

C.

Set up a demilitarized zone (DMZ).

D.

Implement a secure protocol.

Question 107

An incident response team has been notified of a virus outbreak in a network subnet. Which of the following should be the NEXT step?

Options:

A.

Focus on limiting the damage.

B.

Remove and restore the affected systems.

C.

Verify that the compromised systems are fully functional.

D.

Document the incident.

Question 108

During an audit of payment services of a branch based in a foreign country, a large global bank ' s audit team identifies an opportunity to use data analytics techniques to identify abnormal payments. Which of the following is the team ' s MOST important course of action?

Options:

A.

Consult the legal department to understand the procedure for requesting data from a different jurisdiction.

B.

Conduct a walk through of the analytical strategy with stakeholders of the audited branch to obtain their buy-in.

C.

Request the data from the branch as the team audit charter covers the country where it is based.

D.

Agree on a data extraction and sharing strategy with the IT team of the audited branch.

Question 109

Which of the following BEST helps data loss prevention (DLP) tools detect movement of sensitive data m transit?

Options:

A.

Network traffic logs

B.

Deep packet inspection

C.

Data inventory

D.

Proprietary encryption

Question 110

A bank wants to outsource a system to a cloud provider residing in another country. Which of the following would be the MOST appropriate IS audit recommendation?

Options:

A.

Find an alternative provider in the bank ' s home country.

B.

Ensure the provider ' s internal control system meets bank requirements.

C.

Proceed as intended, as the provider has to observe all laws of the clients’ countries.

D.

Ensure the provider has disaster recovery capability.

Question 111

To ensure confidentiality through the use of asymmetric encryption, a message is encrypted with which of the following?

Options:

A.

Recipient ' s public key

B.

Sender ' s private key

C.

Sender ' s public key

D.

Recipient ' s private key

Question 112

Which of the following is the BEST method to prevent wire transfer fraud by bank employees?

Options:

A.

Independent reconciliation

B.

Re-keying of wire dollar amounts

C.

Two-factor authentication control

D.

System-enforced dual control

Question 113

An IS auditor is reviewing a bank’s service level agreement (SLA) with a third-party provider that hosts the bank’s secondary data center. Which of the following findings should be of GREATEST concern to the auditor?

Options:

A.

The recovery time objective (RTO) has a longer duration than documented in the disaster recovery plan (DRP).

B.

The SLA has not been reviewed in more than a year.

C.

The recovery point objective (RPO) has a shorter duration than documented in the disaster recovery plan (DRP).

D.

Backup data is hosted online only.

Question 114

Which of the following is the PRIMARY purpose of a rollback plan for a system change?

Options:

A.

To ensure steps exist to remove the change if necessary

B.

To ensure testing can be re-performed if required

C.

To ensure a backup exists before implementing a change

D.

To ensure the system change is effective

Question 115

A small organization is experiencing rapid growth and plans to create a new information security policy. Which of the following is MOST relevant to creating the policy?

Options:

A.

Business objectives

B.

Business impact analysis (BIA)

C.

Enterprise architecture (EA)

D.

Recent incident trends

Question 116

Which of the following is the MOST important course of action to ensure a cloud access security broker (CASB) effectively detects and responds to threats?

Options:

A.

Monitoring data movement

B.

Implementing a long-term CASB contract

C.

Reviewing the information security policy

D.

Evaluating firewall effectiveness

Question 117

During a physical security audit, an IS auditor was provided a proximity badge that granted access to three specific floors in a corporate office building. Which of the following issues should be of MOST concern?

Options:

A.

The proximity badge did not work for the first two days of audit fieldwork.

B.

There was no requirement for an escort during fieldwork.

C.

There was no follow-up for unsuccessful attempted access violations.

D.

The proximity badge incorrectly granted access to restricted areas.

Question 118

Which of the following is the BEST approach for determining the overall IT risk appetite of an organization when business units use different methods formanaging IT risks?

Options:

A.

Average the business units’ IT risk levels

B.

Identify the highest-rated IT risk level among the business units

C.

Prioritize the organization ' s IT risk scenarios

D.

Establish a global IT risk scoring criteria

Question 119

Which of the following is MOST important to include in a feasibility study when developing a business case for an IT investment?

Options:

A.

An analysis of costs and benefits associated with proposed solutions

B.

Availability of IT resources proposed for the project

C.

Evidence that all possible risk scenarios have been considered

D.

Key stakeholders responsible for review and approval of proposed solutions

Question 120

An externally facing system containing sensitive data is configured such that users have either read-only or administrator rights. Most users of the system have administrator access. Which of the following is the GREATEST risk associated with this situation?

Options:

A.

Users can export application logs.

B.

Users can view sensitive data.

C.

Users can make unauthorized changes.

D.

Users can install open-licensed software.

Question 121

Which of the following staff should an IS auditor interview FIRST to obtain a general overview of the various technologies used across different programs?

Options:

A.

Technical architect

B.

Enterprise architect

C.

Program manager

D.

Solution architect

Question 122

An organization is planning an acquisition and has engaged an IS auditor lo evaluate the IT governance framework of the target company. Which of the following would be MOST helpful In determining the effectiveness of the framework?

Options:

A.

Sell-assessment reports of IT capability and maturity

B.

IT performance benchmarking reports with competitors

C.

Recent third-party IS audit reports

D.

Current and previous internal IS audit reports

Question 123

An IS auditor is evaluating the risk associated with moving from one database management system (DBMS) to another. Which of the following would be MOST helpful to ensure the integrity of the system throughout the change?

Options:

A.

Preserving the same data classifications

B.

Preserving the same data inputs

C.

Preserving the same data structure

D.

Preserving the same data interfaces

Question 124

Which of the following is the BEST source of information for examining the classification of new data?

Options:

A.

Input by data custodians

B.

Security policy requirements

C.

Risk assessment results

D.

Current level of protection

Question 125

An IS auditor finds that irregularities have occurred and that auditee management has chosen to ignore them. If reporting to external authorities is required which of the following is the BEST action for the IS auditor to take?

Options:

A.

Submit the report to appropriate regulators immediately.

B.

Obtain approval from audit management to submit the report.

C.

Obtain approval from auditee management to release the report.

D.

Obtain approval from both audit and auditee management to release the report.

Question 126

Which of the following is the PRIMARY reason for an IS audit manager to review the work performed by a senior IS auditor prior to presentation of a report?

Options:

A.

To ensure the conclusions are adequately supported

B.

To ensure adequate sampling methods were used during fieldwork

C.

To ensure the work is properly documented and filed

D.

To ensure the work is conducted according to industry standards

Question 127

A white box testing method is applicable with which of the following testing processes?

Options:

A.

Integration testing

B.

Parallel testing

C.

Sociability testing

D.

User acceptance testing (UAT)

Question 128

Which of the following should be restricted from a network administrator ' s privileges in an adequately segregated IT environment?

Options:

A.

Monitoring network traffic

B.

Changing existing configurations for applications

C.

Hardening network ports

D.

Ensuring transmission protocols are functioning correctly

Question 129

An IS auditor has traced the source of a transaction fraud to the desktop system of an e-business staff member who is on leave. Which of the following is the BEST way for the auditor to ensure the success of the investigation?

Options:

A.

Create an image of the attacked system and dump the memory to a file for review.

B.

Immediately seal off the attacked system and block all access until after the investigation.

C.

Reboot the attacked system and promptly review log files and file timestamps.

D.

Interview the business staff and ask them to provide details of recent system activities.

Question 130

How does a continuous integration/continuous development (CI/CD) process help to reduce software failure risk?

Options:

A.

Easy software version rollback

B.

Smaller incremental changes

C.

Fewer manual milestones

D.

Automated software testing

Question 131

An IS auditor is verifying the adequacy of an organization ' s internal controls and is concerned about potential circumvention of regulations. Which of the following is the BEST sampling method to use?

Options:

A.

Variable sampling

B.

Random sampling

C.

Cluster sampling

D.

Attribute sampling

Question 132

Which of the following would be of GREATEST concern to an IS auditor evaluating an organization’s change management process?

Options:

A.

Change management meeting minutes are not available for several meetings.

B.

Change requests are not subject to prioritization.

C.

Changes are approved after being moved to production.

D.

A list of authorized requestors for emergency changes does not exist.

Question 133

An information systems security officer ' s PRIMARY responsibility for business process applications is to:

Options:

A.

authorize secured emergency access

B.

approve the organization ' s security policy

C.

ensure access rules agree with policies

D.

create role-based rules for each business process

Question 134

Which of the following issues associated with a data center ' s closed-circuit television (CCTV) surveillance cameras should be of MOST concern to an IS auditor?

Options:

A.

CCTV recordings are not regularly reviewed.

B.

CCTV cameras are not installed in break rooms

C.

CCTV records are deleted after one year.

D.

CCTV footage is not recorded 24 x 7.

Question 135

The BEST way to determine whether programmers have permission to alter data in the production environment is by reviewing:

Options:

A.

The access rights that have been granted.

B.

How the latest system changes were implemented.

C.

The access control system’s configuration.

D.

The access control system’s log settings.

Question 136

Which of the following is the BEST methodology to use for estimating the complexity of developing a large business application?

Options:

A.

Function point analysis

B.

Work breakdown structure

C.

Critical path analysts

D.

Software cost estimation

Question 137

An IS auditor is reviewing the disaster recovery plan (DRP) of an organization with offices across multiple regions. Which of the following should be the auditor ' s PRIMARY focus?

Options:

A.

Recovery point objective (RPO) monitoring

B.

Processes and system dependencies

C.

Disaster recovery training

D.

Data backup and storage changes

Question 138

An IS auditor discovers that backups of critical systems are not being performed in accordance with the recovery point objective (RPO) established in the business continuity plan (BCP). What should the auditor do NEXT?

Options:

A.

Request an immediate backup be performed.

B.

Expand the audit scope.

C.

Identify the root cause.

D.

Include the observation in the report.

Question 139

Which of the following documents should define roles and responsibilities within an IT audit organization?

Options:

A.

Audit charter

B.

Annual audit plan

C.

Engagement letter

D.

Audit scope letter

Question 140

Which of the following is the MOST efficient way to identify segregation of duties violations in a new system?

Options:

A.

Review a report of security rights in the system.

B.

Observe the performance of business processes.

C.

Develop a process to identify authorization conflicts.

D.

Examine recent system access rights violations.

Question 141

The PRIMARY purpose of an incident response plan is to:

Options:

A.

reduce the impact of an adverse event on information assets.

B.

increase the effectiveness of preventive controls.

C.

reduce the maximum tolerable downtime (MTD) of impacted systems.

D.

increase awareness of impacts from adverse events to IT systems.

Question 142

Effective separation of duties in an online environment can BEST be achieved by utilizing:

Options:

A.

appropriate supervision.

B.

transaction logging.

C.

written procedure manuals.

D.

access authorization tables.

Question 143

Which of the following would BEST demonstrate that an effective disaster recovery plan (DRP) is in place?

Options:

A.

Frequent testing of backups

B.

Annual walk-through testing

C.

Periodic risk assessment

D.

Full operational test

Question 144

Which of the following is the GREATEST risk when relying on reports generated by end-user computing (EUC)?

Options:

A.

Data may be inaccurate.

B.

Reports may not work efficiently.

C.

Reports may not be timely.

D.

Historical data may not be available.

Question 145

Which of the following is the BEST way to address segregation of duties issues in an organization with budget constraints?

Options:

A.

Rotate job duties periodically.

B.

Perform an independent audit.

C.

Hire temporary staff.

D.

Implement compensating controls.

Question 146

Which of the following should be done FIRST following an incident that has caused internal servers to be inaccessible, disrupting normal business operations?

Options:

A.

Document the servers ' dates, times, and locations, as well as the individual who last used them

B.

Make a bit-level copy of the affected servers and calculate the hash value of the copy.

C.

Copy all key directories and files on the affected servers and generate the hash value of the copy.

D.

Unplug all power cables immediately to prevent further actions of the attacker on the servers.

Question 147

Which of the following should an organization do FIRST when an employee is terminated for fraudulent activity?

Options:

A.

Review transactions approved by the employee.

B.

Escort the employee off the premises.

C.

Disable the employee’s logical access.

D.

Back up the employee’s hard drive.

Question 148

An organization with many desktop PCs is considering moving to a thin client architecture. Which of the following is the MAJOR advantage?

Options:

A.

The security of the desktop PC is enhanced.

B.

Administrative security can be provided for the client.

C.

Desktop application software will never have to be upgraded.

D.

System administration can be better managed

Question 149

An IS audit manager is preparing the staffing plan for an audit engagement of a cloud service provider. What should be the manager ' s PRIMARY concern when being made aware that a new

auditor in the department previously worked for this provider?

Options:

A.

Independence

B.

Professional conduct

C.

Subject matter expertise

D.

Resource availability

Question 150

An IS audit team is evaluating documentation of the most recent application user access review. It is determined that the user list was not system generated. Which of the following should be of

MOST concern?

Options:

A.

Confidentiality of the user list

B.

Timeliness of the user list review

C.

Completeness of the user list

D.

Availability of the user list

Question 151

Which of the following backup methods is MOST appropriate when storage space is limited?

Options:

A.

Incremental backups

B.

Mirror backups

C.

Full backups

D.

Annual backups

Question 152

During the audit of an enterprise resource planning (ERP) system, an IS auditor found an applicationpatch was applied to the production environment. It is MOST

important for the IS auditor to verify approval from the:

Options:

A.

information security officer.

B.

system administrator.

C.

information asset owner.

D.

project manager.

Question 153

A contract for outsourcing IS functions should always include:

Options:

A.

Full details of security procedures to be observed by the contractor.

B.

A provision for an independent audit of the contractor’s operations.

C.

The names and roles of staff to be employed in the operation.

D.

Data transfer protocols.

Question 154

Which of the following should be a concern to an IS auditor reviewing an organization’s use of a major cloud provider for Infrastructure as a Service (IaaS)?

Options:

A.

The IaaS service is connected to the organization’s network via a virtual private network (VPN).

B.

End users are able to create their own cloud server instances.

C.

The IaaS service relies on the organization’s active directory domain.

D.

The cloud governance policy was not reviewed within the last year by the IT department.

Question 155

In an IT organization where many responsibilities are shared which of the following is the BEST control for detecting unauthorized data changes?

Options:

A.

Users are required to periodically rotate responsibilities

B.

Segregation of duties conflicts are periodically reviewed

C.

Data changes are independently reviewed by another group

D.

Data changes are logged in an outside application

Question 156

Which of the following is the MOST important consideration to facilitate prosecution of a perpetrator after a cybercrime?

Options:

A.

An active intrusion detection system (IDS)

B.

Professional collection of unaltered evidence

C.

Reporting to the internal legal department

D.

Immediate law enforcement involvement

Question 157

An emergency power-off switch should:

Options:

A.

be protected.

B.

be remotely accessible.

C.

be under dual control.

D.

not be identified.

Question 158

An IS auditor finds the log management system is overwhelmed with false positive alerts. The auditor ' s BEST recommendation would be to:

Options:

A.

establish criteria for reviewing alerts.

B.

recruit more monitoring personnel.

C.

reduce the firewall rules.

D.

fine tune the intrusion detection system (IDS).

Question 159

Which of the following is the BEST source of information tor an IS auditor to use when determining whether an organization ' s information security policy is adequate?

Options:

A.

Information security program plans

B.

Penetration test results

C.

Risk assessment results

D.

Industry benchmarks

Question 160

An organization is enhancing the security of a client-facing web application following a proposal to acquire personal information for a business purpose. Which of the following is MOST important to review before implementing this initiative?

Options:

A.

Regulatory compliance requirements

B.

Data ownership assignments

C.

Encryption capabilities

D.

Customer notification procedures

Question 161

An organization is implementing a data loss prevention (DLP) system in response to a new regulatory requirement Reviewing. which of the following would be MOST helpful in evaluating the system ' s design?

Options:

A.

System manuals

B.

Enterprise architecture (EA)

C.

Historical record of data breaches

D.

Industry trends

Question 162

In an area susceptible to unexpected increases in electrical power, which of the following would MOST effectively protect the system?

Options:

A.

Generator

B.

Voltage regulator

C.

Circuit breaker

D.

Alternate power supply line

Question 163

An IS auditor learns that a business owner violated the organization ' s security policy by creating a web page with access to production data. The auditor ' s NEXT step should be to:

Options:

A.

determine if sufficient access controls exist.

B.

assess the sensitivity of the production data.

C.

shut down the web page.

D.

escalate to senior management.

Question 164

An organization plans to receive an automated data feed into its enterprise data warehouse from a third-party service provider. Which of the following would be the BEST way to prevent accepting bad data?

Options:

A.

Obtain error codes indicating failed data feeds.

B.

Purchase data cleansing tools from a reputable vendor.

C.

Appoint data quality champions across the organization.

D.

Implement business rules to reject invalid data.

Question 165

Which of the following BEST guards against the risk of attack by hackers?

Options:

A.

Tunneling

B.

Encryption

C.

Message validation

D.

Firewalls

Question 166

Which task should an IS auditor complete FIRST during the preliminary planning phase of a database security review?

Options:

A.

Perform a business impact analysis (BIA).

B.

Determine which databases will be in scope.

C.

Identify the most critical database controls.

D.

Evaluate the types of databases being used

Question 167

The PRIMARY purpose of a vulnerability assessment in a cybersecurity program is to:

Options:

A.

Enhance the security awareness of employees and other internal stakeholders.

B.

Identify known security exposures before attackers find them.

C.

Improve the overall security posture of the organization.

D.

Protect the organization’s IT assets against external cyberthreats.

Question 168

Which of the following is the MOST important consideration for a contingency facility?

Options:

A.

The contingency facility has the same badge access controls as the primary site.

B.

Both the contingency facility and the primary site have the same number of business assets in their inventory.

C.

The contingency facility is located a sufficient distance away from the primary site.

D.

Both the contingency facility and the primary site are easily identifiable.

Question 169

To improve efficiency, an organization has decided not to encrypt log files and plans to store the log data in native device formats. Which of the following is the GREATEST risk to the organization?

Options:

A.

Inability to automate data transfers.

B.

Inability to correlate security events in time.

C.

Increased cost of log data storage due to lack of compression.

D.

Unauthorized modification of log data.

Question 170

Which of the following BEST helps to determine an organization’s data availability approach in the event of a disaster?

Options:

A.

Maximum tolerable outage (MTO).

B.

Recovery point objective (RPO).

C.

Cost-benefit analysis.

D.

Service delivery objective (SDO).

Question 171

When reviewing an organization’s enterprise architecture (EA), which of the following is an IS auditor MOST likely to find within the EA documentation?

Options:

A.

Contact information for key resources within the IT department

B.

Detailed encryption standards

C.

Roadmaps showing the evolution from current state to future state

D.

Protocols used to communicate between systems

Question 172

Which of the following is the MOST important consideration for patching mission critical business application servers against known vulnerabilities?

Options:

A.

Patches are implemented in a test environment prior to rollout into production.

B.

Network vulnerability scans are conducted after patches are implemented.

C.

Vulnerability assessments are periodically conducted according to defined schedules.

D.

Roles and responsibilities for implementing patches are defined

Question 173

Which of the following should an IS auditor use when verifying a three-way match has occurred in an enterprise resource planning (ERR) system?

Options:

A.

Bank confirmation

B.

Goods delivery notification

C.

Purchase requisition

D.

Purchase order

Question 174

The PRIMARY objective of a privacy protection policy is to increase awareness of:

Options:

A.

Cybercrimes that target an organization’s computer network.

B.

The benefits of using encryption for personal data protection.

C.

The legal requirements for protecting personal information.

D.

System configuration procedures to protect privacy.

Question 175

One advantage of monetary unit sampling is the fact that

Options:

A.

results are stated m terms of the frequency of items in error

B.

it can easily be applied manually when computer resources are not available

C.

large-value population items are segregated and audited separately

D.

it increases the likelihood of selecting material items from the population

Question 176

An organization ' s strategy to source certain IT functions from a Software as a Service (SaaS) provider should be approved by the:

Options:

A.

chief financial officer (CFO).

B.

chief risk officer (CRO).

C.

IT steering committee.

D.

IT operations manager.

Question 177

How would an IS auditor BEST determine the effectiveness of a security awareness program?

Options:

A.

Review the results of social engineering tests.

B.

Evaluate management survey results.

C.

Interview employees to assess their security awareness.

D.

Review security awareness training quiz results.

Question 178

Which of the following is the PRIMARY benefit of performing periodic maturity model assessments?

Options:

A.

It acts as a measuring tool and progress indicator.

B.

It identifies and fixes attribute weaknesses.

C.

It facilitates the execution of an improvement plan.

D.

It ensures organizational consistency and improvement.

Question 179

An IS auditor found that a company executive is encouraging employee use of social networking sites for business purposes. Which of the following recommendations would BEST help to reduce the risk of data leakage?

Options:

A.

Requiring policy acknowledgment and nondisclosure agreements (NDAs) signed by employees

B.

Establishing strong access controls on confidential data

C.

Providing education and guidelines to employees on use of social networking sites

D.

Monitoring employees ' social networking usage

Question 180

What is BEST for an IS auditor to review when assessing the effectiveness of changes recently made to processes and tools related to an organization ' s business continuity plan (BCP)?

Options:

A.

Full test results

B.

Completed test plans

C.

Updated inventory of systems

D.

Change management processes

Question 181

Which of the following MOST effectively enables consistency across high-volume software changes ' ?

Options:

A.

The use of continuous integration and deployment pipelines

B.

Management reviews of detailed exception reports for released code

C.

Publication of a refreshed policy on development and release management

D.

An ongoing awareness campaign for software deployment best practices

Question 182

Which of the following is the BEST approach for determining the overall IT risk appetite of an organization when business units use different methods for managing IT risks?

Options:

A.

Establish a weighted score based on business unit criticality.

B.

Identify the highest-rated IT risk level among the business units.

C.

Average the business units’ IT risk levels.

D.

Establish a global IT risk scoring criteria.

Question 183

Which of the following should be the PRIMARY consideration when incorporating user training and awareness into a data loss prevention (DLP) strategy?

Options:

A.

Avoiding financial penalties and reputational risk

B.

Ensuring data availability

C.

Promoting secure data handling practices

D.

Adhering to data governance policies

Question 184

During an operational audit on the procurement department, the audit team encounters a key system that uses an artificial intelligence (Al) algorithm. The audit team does not have the necessary knowledge to proceed with the audit. Which of the following is the BEST way to handle this situation?

Options:

A.

Perform a skills assessment to identify members from other business units with knowledge of Al.

B.

Remove the Al portion from the audit scope and proceed with the audit.

C.

Delay the audit until the team receives training on Al.

D.

Engage external consultants who have audit experience and knowledge of Al.

Question 185

Which of the following is the MOST important factor when an organization is developing information security policies and procedures?

Options:

A.

Consultation with security staff

B.

Inclusion of mission and objectives

C.

Compliance with relevant regulations

D.

Alignment with an information security framework

Question 186

Which of the following network communication protocols is used by network devices such as routers to send error messages and operational information indicating success or failure when communicating with another IP address?

Options:

A.

Transmission Control Protocol/Internet Protocol (TCP/IP)

B.

Internet Control Message Protocol

C.

Multipurpose Transaction Protocol

D.

Point-to-Point Tunneling Protocol

Question 187

An organization allows programmers to change production systems in emergency situations without seeking prior approval. Which of the following controls should an IS auditor consider MOST

important?

Options:

A.

Programmers ' subsequent reports

B.

Limited number of super users

C.

Operator logs

D.

Automated log of changes

Question 188

Cross-site scripting (XSS) attacks are BEST prevented through:

Options:

A.

application firewall policy settings.

B.

a three-tier web architecture.

C.

secure coding practices.

D.

use of common industry frameworks.

Question 189

An IS auditor has been asked to perform a post-implementation review of a newly developed system. When reviewing the testing phase results, the auditor observed that separate modules of the system tested correctly in the user acceptance testing (UAT) phase, but some features did not work as expected when moved to production. Which of the following was MOST likely omitted prior to implementation?

Options:

A.

Integration testing

B.

End-user training

C.

Full unit testing

D.

Parallel testing

Question 190

Which of the following should an IS auditor be MOST concerned with when reviewing the IT asset disposal process?

Options:

A.

Monetary value of the asset.

B.

Certificate of destruction.

C.

Data migration to the new asset.

D.

Data stored on the asset.

Question 191

An IS auditor is evaluating an enterprise resource planning (ERP) migration from local systems to the cloud. Who should be responsible for the data

classification in this project?

Options:

A.

Information security officer

B.

Database administrator (DBA)

C.

Information owner

D.

Data architect

Question 192

An IS auditor finds that firewalls are outdated and not supported by vendors. Which of the following should be the auditor ' s NEXT course of action?

Options:

A.

Report the mitigating controls.

B.

Report the security posture of the organization.

C.

Determine the value of the firewall.

D.

Determine the risk of not replacing the firewall.

Question 193

Which of the following responses to risk associated with segregation of duties would incur the LOWEST initial cost?

Options:

A.

Risk acceptance

B.

Risk mitigation

C.

Risk transference

D.

Risk reduction

Question 194

Which of the following is the BEST recommendation to include in an organization ' s bring your own device (BYOD)

policy to help prevent data leakage?

Options:

A.

Require employees to waive privacy rights related to data on BYOD devices.

B.

Require multi-factor authentication on BYOD devices,

C.

Specify employee responsibilities for reporting lost or stolen BYOD devices.

D.

Allow only registered BYOD devices to access the network.

Question 195

Which of the following is the PRIMARY reason to follow a configuration management process to maintain application?

Options:

A.

To optimize system resources

B.

To follow system hardening standards

C.

To optimize asset management workflows

D.

To ensure proper change control

Question 196

Which of the following controls is MOST important for ensuring the integrity of system interfaces?

Options:

A.

Periodic audits

B.

File counts

C.

File checksums

D.

IT operator monitoring

Question 197

Which of the following BEST mitigates the risk of SQL injection attacks against applications exposed to the internet?

Options:

A.

Web application firewall (WAF)

B.

SQL server hardening

C.

Patch management program

D.

SQL server physical controls

Question 198

An IS auditor finds that capacity management for a key system is being performed by IT with no input from the business The auditor ' s PRIMARY concern would be:

Options:

A.

failure to maximize the use of equipment

B.

unanticipated increase in business s capacity needs.

C.

cost of excessive data center storage capacity

D.

impact to future business project funding.

Question 199

Which of the following key performance indicators (KPIs) provides stakeholders with the MOST useful information about whether information security risk is being managed?

Options:

A.

Time from identifying security threats to implementing solutions

B.

The number of security controls audited

C.

Time from security log capture to log analysis

D.

The number of entries in the security risk register

Question 200

Which of the following applications should an IS auditor consider to be the HIGHEST priority when reviewing disaster recovery planning (DRP) tests for an commerce company?

Options:

A.

An application for IT performance monitoring

B.

An application for HR management

C.

An application for financial management

D.

An application for traffic load balancing

Question 201

Which of the following is the MOST effective way to maintain network integrity when using mobile devices?

Options:

A.

Implement network access control.

B.

Implement outbound firewall rules.

C.

Perform network reviews.

D.

Review access control lists.

Question 202

Which of the following is BEST used for detailed testing of a business application ' s data and configuration files?

Options:

A.

Version control software

B.

Audit hooks

C.

Utility software

D.

Audit analytics tool

Question 203

A new system is being developed externally for an organization. Which of the following is the MOST important requirement to include in the vendor contract to ensure service continuity?

Options:

A.

Support documentation must be provided by the vendor.

B.

The vendor must have a documented disaster recovery plan (DRP) in place.

C.

Source code for the software must be placed in escrow.

D.

The vendor must train the organization’s staff to manage the new software.

Question 204

An IS auditor is reviewing an IT project and finds that an earned value analysis (EVA) is not regularly performed as part of project status reporting. Which of the following is the GREATEST risk resulting from this situation?

Options:

A.

Resources might not be assigned and prioritized in a timely manner.

B.

Time and budget overruns might not be identified in a timely manner.

C.

The project might not be compliant with project management standards.

D.

Business requirements may not be properly benchmarked.

Question 205

Due to a recent business divestiture, an organization has limited IT resources to deliver critical projects Reviewing the IT staffing plan against which of the following would BEST guide IT management when estimating resource requirements for future projects?

Options:

A.

Human resources (HR) sourcing strategy

B.

Records of actual time spent on projects

C.

Peer organization staffing benchmarks

D.

Budgeted forecast for the next financial year

Question 206

When an organization conducts business process improvements, the IS auditor should be MOST concerned with the:

Options:

A.

metrics used to evaluate key operating segments.

B.

adequacy of the controls in the redesigned process.

C.

adequacy of reporting to senior management.

D.

lack of version control over process documentation.

Question 207

Which of the following is the PRIMARY reason for using a digital signature?

Options:

A.

Provide availability to the transmission

B.

Authenticate the sender of a message

C.

Provide confidentiality to the transmission

D.

Verify the integrity of the data and the identity of the recipient

Question 208

An IS auditor reviewing a job scheduling tool notices performance and reliability problems. Which of the following is MOST likely affecting the tool?

Options:

A.

Administrator passwords do not meet organizational security and complexity requirements.

B.

The number of support staff responsible for job scheduling has been reduced.

C.

The scheduling tool was not classified as business-critical by the IT department.

D.

Maintenance patches and the latest enhancement upgrades are missing.

Question 209

Which of the following is MOST important for an IS auditor to consider when performing the risk assessment poor to an audit engagement?

Options:

A.

The design of controls

B.

Industry standards and best practices

C.

The results of the previous audit

D.

The amount of time since the previous audit

Question 210

An IS auditor follows up on a recent security incident and finds the incident response was not adequate. Which of the following findings should be considered MOST critical?

Options:

A.

The security weakness facilitating the attack was not identified.

B.

The attack was not automatically blocked by the intrusion detection system (IDS).

C.

The attack could not be traced back to the originating person.

D.

Appropriate response documentation was not maintained.

Question 211

Which of the following MUST be completed as part of the annual audit planning process?

Options:

A.

Business continuity analysis

B.

Industry benchmarking

C.

Risk assessment

D.

Risk control matrix

Question 212

During a database security audit, an IS auditor is reviewing the process used to input data. Which of the following is the MOST significant risk area for the auditor to focus on?

Options:

A.

Data resilience

B.

Data availability

C.

Data normalization

D.

Data integrity

Question 213

An organization is considering allowing users to connect personal devices to the corporate network. Which of the following should be done FIRST?

Options:

A.

Conduct security awareness training.

B.

Implement an acceptable use policy

C.

Create inventory records of personal devices

D.

Configure users on the mobile device management (MDM) solution

Question 214

Which of the following features of a library control software package would protect against unauthorized updating of source code?

Options:

A.

Required approvals at each life cycle step

B.

Date and time stamping of source and object code

C.

Access controls for source libraries

D.

Release-to-release comparison of source code

Question 215

Which of the following is an organization ' s BEST defense against malware?

Options:

A.

Documented security procedures

B.

Intrusion prevention system (IPS)

C.

Security awareness training

D.

Intrusion detection system (IDS)

Question 216

Which of the following should be of GREATEST concern to an IS auditor when using data analytics?

Options:

A.

The data source lacks integrity.

B.

The data analytics software is open source.

C.

The data set contains irrelevant fields.

D.

The data was not extracted by the auditor.

Question 217

Which of the following is the GREATEST benefit of an effective data classification process?

Options:

A.

Data custodians are identified.

B.

Data retention periods are well defined

C.

Data is protected according to its sensitivity

D.

Appropriate ownership over data is assigned

Question 218

Which of the following is MOST important to determine when conducting an audit Of an organization ' s data privacy practices?

Options:

A.

Whether a disciplinary process is established for data privacy violations

B.

Whether strong encryption algorithms are deployed for personal data protection

C.

Whether privacy technologies are implemented for personal data protection

D.

Whether the systems inventory containing personal data is maintained

Question 219

Which of the following provides the BEST evidence that all elements of a business continuity plan (BCP) are operating effectively?

Options:

A.

Walk-through test results

B.

Full operational test results

C.

Tabletop test results

D.

Simulation test results

Question 220

Which of the following is an example of a preventive control for physical access?

Options:

A.

Keeping log entries for all visitors to the building

B.

Implementing a fingerprint-based access control system for the building

C.

Installing closed-circuit television (CCTV) cameras for all ingress and egress points

D.

Implementing a centralized logging server to record instances of staff logging into workstations

Question 221

Which of the following is MOST important to ensure when planning a black-box penetration test?

Options:

A.

The tactics, techniques, and procedures have been determined.

B.

Diagrams of the organization’s network architecture are available.

C.

The test results will be documented and communicated to management.

D.

The management of the client organization has approved the scope of testing.

Question 222

A system development project is experiencing delays due to ongoing staff shortages. Which of the following strategies would provide the GREATEST assurance of system quality at implementation?

Options:

A.

Implement overtime pay and bonuses for all development staff.

B.

Utilize new system development tools to improve productivity.

C.

Recruit IS staff to expedite system development.

D.

Deliver only the core functionality on the initial target date.

Question 223

An organization used robotic process automation (RPA) technology to develop software bots that extract data from various sources for input into a legacy financial application. Which of the following should be of GREATEST concern to an IS auditor when reviewing the software bot job scheduling and production process automation?

Options:

A.

Minor overrides were not authorized by the business

B.

Software bots were incapable of learning from training data

C.

Software bots were programmed to record all user interactions, including mouse tracking

D.

Unauthorized modifications were made to the scripts to improve performance

Question 224

Which of the following should an IS auditor review when evaluating information systems governance for a large organization?

Options:

A.

Approval processes for new system implementations

B.

Procedures for adding a new user to the invoice processing system

C.

Approval processes for updating the corporate website

D.

Procedures for regression testing system changes

Question 225

The PRIMARY role of an IS auditor in the remediation of problems found during an audit engagement is to:

Options:

A.

help auditee management by providing the solution.

B.

explain the findings and provide general advice.

C.

present updated policies to management for approval.

D.

take ownership of the problems and oversee remediation efforts.

Question 226

Which of the following will provide the GREATEST assurance to IT management that a quality management system (QMS) is effective?

Options:

A.

A high percentage of stakeholders satisfied with the quality of IT

B.

Ahigh percentage of incidents being quickly resolved

C.

Ahigh percentage of IT processes reviewed by quality assurance (QA)

D.

Ahigh percentage of IT employees attending quality training

Question 227

Which of the following is the PRIMARY basis on which audit objectives are established?

Options:

A.

Audit risk

B.

Consideration of risks

C.

Assessment of prior audits

D.

Business strategy

Question 228

Which of the following is the BEST way to identify key areas for a risk-based audit plan?

Options:

A.

Review peer benchmarking results.

B.

Review open issues from recent audit reports.

C.

Interview relevant stakeholders in the business.

D.

Conduct a risk survey with the CIO.

Question 229

When an intrusion into an organization ' s network is detected, which of the following should be done FIRST?

Options:

A.

Notify senior management.

B.

Block all compromised network nodes.

C.

Identify nodes that have been compromised.

D.

Contact law enforcement.

Question 230

A new regulation requires organizations to report significant security incidents to the regulator within 24 hours of identification. Which of the following is the IS auditor ' s BEST recommendation to facilitate compliance with the regulation?

Options:

A.

Include the requirement in the incident management response plan.

B.

Establish key performance indicators (KPIs) for timely identification of security incidents.

C.

Enhance the alert functionality of the intrusion detection system (IDS).

D.

Engage an external security incident response expert for incident handling.

Question 231

Which of the following is the PRIMARY role of the IS auditor m an organization ' s information classification process?

Options:

A.

Securing information assets in accordance with the classification assigned

B.

Validating that assets are protected according to assigned classification

C.

Ensuring classification levels align with regulatory guidelines

D.

Defining classification levels for information assets within the organization

Question 232

During an audit of a reciprocal disaster recovery agreement between two companies, the IS auditor would be MOST concerned with the:

Options:

A.

allocation of resources during an emergency.

B.

frequency of system testing.

C.

differences in IS policies and procedures.

D.

maintenance of hardware and software compatibility.

Question 233

A hearth care organization utilizes Internet of Things (loT) devices to improve patient outcomes through real-time patient monitoring and advanced diagnostics. Which of the following would BEST assist in isolating these devices from corporate network traffic?

Options:

A.

Internal firewalls

B.

Blockchain technology

C.

Content filtering proxy

D.

Zero Trust architecture

Question 234

When auditing the feasibility study of a system development project, the IS auditor should:

Options:

A.

review qualifications of key members of the project team.

B.

review the request for proposal (RFP) to ensure that it covers the scope of work.

C.

review cost-benefit documentation for reasonableness.

D.

ensure that vendor contracts are reviewed by legal counsel.

Question 235

A small IT department has embraced DevOps, which allows members of this group to deploy code to production and maintain some development access to automate releases. Which of the following is the MOST effective control?

Options:

A.

Enforce approval prior to deployment by a member of the team who has not taken part in the development.

B.

The DevOps team provides an annual policy acknowledgment that they did not develop and deploy the same code.

C.

Annual training reinforces the need to maintain segregation between developers and deployers of code

D.

The IT compliance manager performs weekly reviews to ensure the same person did not develop and deploy code.

Question 236

In which phase of penetration testing would host detection and domain name system (DNS) interrogation be performed?

Options:

A.

Discovery

B.

Attacks

C.

Planning

D.

Reporting

Question 237

A web application is developed in-house by an organization. Which of the following would provide the BEST evidence to an IS auditor that the application is secure from external attack?

Options:

A.

Web application firewall (WAF) implementation

B.

Penetration test results

C.

Code review by a third party

D.

Database application monitoring logs

Question 238

An organization has shifted from a bottom-up approach to a top-down approach in the development of IT policies. This should result in:

Options:

A.

greater consistency across the organization.

B.

a synthesis of existing operational policies.

C.

a more comprehensive risk assessment plan.

D.

greater adherence to best practices.

Question 239

Which of the following would be the GREATEST concern during a financial statement audit?

Options:

A.

A backup has not been identified for key approvers.

B.

System capacity has not been tested.

C.

The procedures for generating key reports have not been approved.

D.

The financial management system is cloud based.

Question 240

A small organization has cut costs by reducing IT positions and consolidating a large number of critical responsibilities into the role of its most senior IT engineer. Which of the following is the PRIMARY risk in this situation?

Options:

A.

The consolidated role will result in a lack of resource optimization.

B.

The consolidation of the role creates limited authority.

C.

The consolidated responsibilities do not allow for appropriate separation of duties.

D.

The consolidation of the responsibilities will weaken succession planning.

Question 241

Which of the following is the PRIMARY function of a data loss prevention (DLP) policy when implemented in an organization ' s DLP solution?

Options:

A.

To encrypt sensitive data at rest and in transit

B.

To define rules for monitoring and protecting sensitive data

C.

To define rules and baselines for network performance

D.

To detect and block incoming network traffic

Question 242

Who should be the FIRST to evaluate an audit report prior to issuing it to the project steering committee?

Options:

A.

IS audit manager

B.

Audit committee

C.

Business owner

D.

Project sponsor

Question 243

Which of the following is the BEST way for an organization to mitigate the risk associated with third-party application performance?

Options:

A.

Ensure the third party allocates adequate resources to meet requirements.

B.

Use analytics within the internal audit function

C.

Conduct a capacity planning exercise

D.

Utilize performance monitoring tools to verify service level agreements (SLAs)

Question 244

An IS auditor is reviewing processes for importing market price data from external data providers. Which of the following findings should the auditor consider MOST critical?

Options:

A.

The transfer protocol does not require authentication.

B.

The quality of the data is not monitored.

C.

Imported data is not disposed of frequently.

D.

The transfer protocol is not encrypted.

Question 245

Management is concerned about sensitive information being intentionally or unintentionally emailed as attachments outside the organization by employees. What is the MOST important task before implementing any associated email controls?

Options:

A.

Require all employees to sign nondisclosure agreements (NDAs).

B.

Develop an acceptable use policy for end-user computing (EUC).

C.

Develop an information classification scheme.

D.

Provide notification to employees about possible email monitoring.

Question 246

Which of the following must be in place before an IS auditor initiates audit follow-up activities?

Options:

A.

Available resources for the activities included in the action plan

B.

A management response in the final report with a committed implementation date

C.

A heal map with the gaps and recommendations displayed in terms of risk

D.

Supporting evidence for the gaps and recommendations mentioned in the audit report

Question 247

An incorrect version of the source code was amended by a development team. This MOST likely indicates a weakness in:

Options:

A.

incident management.

B.

quality assurance (QA).

C.

change management.

D.

project management.

Question 248

An organization conducted an exercise to test the security awareness level of users by sending an email offering a cash reward 10 those who click on a link embedded in the body of the email. Which of the following metrics BEST indicates the effectiveness of awareness training?

Options:

A.

The number of users deleting the email without reporting because it is a phishing email

B.

The number of users clicking on the link to learn more about the sender of the email

C.

The number of users forwarding the email to their business unit managers

D.

The number of users reporting receipt of the email to the information security team

Question 249

Which of the following will MOST likely compromise the control provided By a digital signature created using RSA encryption?

Options:

A.

Reversing the hash function using the digest

B.

Altering the plaintext message

C.

Deciphering the receiver ' s public key

D.

Obtaining the sender ' s private key

Question 250

Which of the following is the BEST control to prevent the transfer of files to external parties through instant messaging (IM) applications?

Options:

A.

File level encryption

B.

File Transfer Protocol (FTP)

C.

Instant messaging policy

D.

Application-level firewalls

Question 251

An organization has recently acquired and implemented intelligent-agent software for granting loans to customers. During the post-implementation review, which of the following is the MOST important procedure for the IS auditor to perform?

Options:

A.

Review system and error logs to verify transaction accuracy.

B.

Review input and output control reports to verify the accuracy of the system decisions.

C.

Review signed approvals to ensure responsibilities for decisions of the system are well defined.

D.

Review system documentation to ensure completeness.

Question 252

Which of the following should be an IS auditor ' s GREATEST concern when evaluating an organization ' s ability to recover from system failures?

Options:

A.

Data backups being stored onsite

B.

Lack of documentation for data backup procedures

C.

Inadequate backup job monitoring

D.

Lack of periodic data backup restoration testing

Question 253

An IS auditor decides to review a data inventory list captured directly from a system instead of relying on an interview with the system owner. Which of the following provides the BEST justification for the auditor ' s decision?

Options:

A.

Independence of the evidence provider

B.

Qualification of the evidence provider

C.

Reliability of the evidence

D.

Timing of the evidence

Question 254

An internal audit department recently established a quality assurance (QA) program. Which of the following activities Is MOST important to include as part of the QA program requirements?

Options:

A.

Long-term Internal audit resource planning

B.

Ongoing monitoring of the audit activities

C.

Analysis of user satisfaction reports from business lines

D.

Feedback from Internal audit staff

Question 255

Which of the following is the BEST method to delete sensitive information from storage media that will be reused?

Options:

A.

Crypto-shredding

B.

Multiple overwriting

C.

Reformatting

D.

Re-partitioning

Question 256

Which of the following is the GREATEST risk related to the use of virtualized environments?

Options:

A.

The host may be a potential single point of failure within the system.

B.

There may be insufficient processing capacity to assign to guests.

C.

There may be increased potential for session hijacking.

D.

Ability to change operating systems may be limited.

Question 257

Which of the following is the PRIMARY reason for an organization to implement a configuration management database (CMDB)?

Options:

A.

To track configuration incidents and service requests

B.

To record and monitor performance metrics for configuration items

C.

To provide an organized view of configuration items and their relationships

D.

To store backup copies of software applications

Question 258

A global bank plans to use a cloud provider for backup of customer financial data. Which of the following should be the PRIMARY focus of this project?

Options:

A.

Backup testing schedule

B.

Data retention policy

C.

Transfer frequency

D.

Data confidentiality

Question 259

An organization ' s information security policies should be developed PRIMARILY on the basis of:

Options:

A.

enterprise architecture (EA).

B.

industry best practices.

C.

a risk management process.

D.

past information security incidents.

Question 260

When auditing the adequacy of a cooling system for a data center, which of the following is MOST important for the IS auditor to review?

Options:

A.

Environmental performance metrics

B.

Geographical location of the data center

C.

Disaster recovery plan (DRP) testing results

D.

Facilities maintenance records

Question 261

A global company has been using a publicly available AI tool to obtain information about global laws and regulations that could impact the business. Which of the following should be of MOST concern to an IS auditor?

Options:

A.

Accuracy and quality of the data provided by the AI tool

B.

Whether the organization is using a paid version of the AI tool

C.

Version and provider of the AI tool being utilized

D.

Whether the tool is utilized by competitors in the same industry

Question 262

An IS auditor is reviewing an industrial control system (ICS) that uses older unsupported technology in the scope of an upcoming audit. What should the auditor consider the MOST significant concern?

Options:

A.

Attack vectors are evolving for industrial control systems.

B.

There is a greater risk of system exploitation.

C.

Disaster recovery plans (DRPs) are not in place.

D.

Technical specifications are not documented.

Question 263

An external attacker spoofing an internal Internet Protocol (IP) address can BEST be detected by which of the following?

Options:

A.

Comparing the source address to the domain name server (DNS) entry

B.

Using static IP addresses for identification

C.

Comparing the source address to the interface used as the entry point

D.

Using a state table to compare the message states of each packet as it enters the system

Question 264

If a recent release of a program has to be backed out of production, the corresponding changes within the delta version of the code should be:

Options:

A.

filed in production for future reference in researching the problem.

B.

applied to the source code that reflects the version in production.

C.

eliminated from the source code that reflects the version in production.

D.

reinstalled when replacing the version back into production.

Question 265

Which of the following is the BEST detective control for a job scheduling process involving data transmission?

Options:

A.

Metrics denoting the volume of monthly job failures are reported and reviewed by senior management.

B.

Jobs are scheduled to be completed daily and data is transmitted using a Secure File Transfer Protocol (SFTP).

C.

Jobs are scheduled and a log of this activity is retained for subsequent review.

D.

Job failure alerts are automatically generated and routed to support personnel.

Question 266

Which of the following is the PRIMARY advantage of using virtualization technology for corporate applications?

Options:

A.

Stronger data security

B.

Better utilization of resources

C.

Increased application performance

D.

Improved disaster recovery

Question 267

An IS auditor finds that while an organization ' s IT strategy is heavily focused on research and development, the majority of protects n the IT portfolio focus on operations and maintenance. Which of the Mowing is the BEST recommendation?

Options:

A.

Align the IT strategy will business objectives

B.

Review priorities in the IT portfolio

C.

Change the IT strategy to focus on operational excellence.

D.

Align the IT portfolio with the IT strategy.

Question 268

An IS auditor has identified deficiencies within the organization ' s software development life cycle policies. Which of the following should be done NEXT?

Options:

A.

Document the findings in the audit report.

B.

Identify who approved the policies.

C.

Escalate the situation to the lead auditor.

D.

Communicate the observation to the auditee.

Question 269

During a review of an organization ' s IT capacity management process, an IS auditor should be MOST concerned if capacity planning:

Options:

A.

Was reviewed once during the previous six months.

B.

Omitted changes to key business systems.

C.

Lacked input from system administrators.

D.

Was based on input from IT service management only.

Question 270

A startup organization wants to develop a data loss prevention (DLP) program. The FIRST step should be to implement:

Options:

A.

Security awareness training

B.

Data encryption

C.

Data classification

D.

Access controls

Question 271

Which of the following poses the GREATEST risk to the use of active RFID tags?

Options:

A.

Session hijacking

B.

Eavesdropping

C.

Piggybacking

D.

Phishing attacks

Question 272

Which of the following responsibilities of an organization ' s quality assurance (QA) function should raise concern for an IS auditor?

Options:

A.

Ensuring standards are adhered to within the development process

B.

Ensuring the test work supports observations

C.

Updating development methodology

D.

Implementing solutions to correct defects

Question 273

Which of the following is MOST useful for determining whether the goals of IT are aligned with the organization ' s goals?

Options:

A.

Balanced scorecard

B.

Enterprise dashboard

C.

Enterprise architecture (EA)

D.

Key performance indicators (KPIs)

Question 274

A network analyst is monitoring the network after hours and detects activity that appears to be a brute-force attempt to compromise a critical server. After reviewing the alerts to ensure their accuracy, what should be done NEXT?

Options:

A.

Perform a root cause analysis.

B.

Document all steps taken in a written report.

C.

Isolate the affected system.

D.

Invoke the incident response plan.

Question 275

Which of the following is the BEST metric to measure the quality of software developed in an organization?

Options:

A.

Amount of successfully migrated software changes

B.

Reduction in the help desk budget

C.

Number of defects discovered in production

D.

Increase in quality assurance (QA) activities

Question 276

Which of the following is the MOST important consideration when establishing vulnerability scanning on critical IT infrastructure?

Options:

A.

The scanning will be performed during non-peak hours.

B.

The scanning will be followed by penetration testing.

C.

The scanning will be cost-effective.

D.

The scanning will not degrade system performance.

Question 277

Which of the following BEST indicates a need to review an organization ' s information security policy?

Options:

A.

High number of low-risk findings in the audit report

B.

Increasing exceptions approved by management

C.

Increasing complexity of business transactions

D.

Completion of annual IT risk assessment

Question 278

Which of the following controls is MOST crucial to ensure an organization will be able to recover its data from backup media in the event of a disaster?

Options:

A.

Encrypting data on backup media.

B.

Storing backup media at an offsite facility.

C.

Periodically restoring backup media for key databases.

D.

Keeping a current inventory of backup media.

Question 279

An external IS auditor is reviewing the continuous monitoring system for a large bank and notes several potential issues. Which of the following would present the GREATEST concern regarding the reliability of the monitoring system?

Options:

A.

The system results are not reviewed by senior management.

B.

The alert threshold is updated periodically.

C.

The monitoring thresholds are not subject to change management.

D.

The monitoring system was configured by a third party.

Question 280

Which of the following is the BEST control lo mitigate attacks that redirect Internet traffic to an unauthorized website?

Options:

A.

Utilize a network-based firewall.

B.

Conduct regular user security awareness training.

C.

Perform domain name system (DNS) server security hardening.

D.

Enforce a strong password policy meeting complexity requirement.

Question 281

When planning an audit, it is acceptable for an IS auditor to rely on a third-party provider’s external audit report on service level management when the

Options:

A.

scope and methodology meet audit requirements

B.

service provider is independently certified and accredited

C.

report confirms that service levels were not violated

D.

report was released within the last 12 months

Question 282

After areas have been appropriately scoped, what is the IS auditor ' s NEXT step in the selection for sampling?

Options:

A.

Define the population for sampling.

B.

Determine the sampling method.

C.

Calculate the sample size.

D.

Pull the sample.

Question 283

When designing a data analytics process, which of the following should be the stakeholder ' s role in automating data extraction and validation?

Options:

A.

Indicating which data elements are necessary to make informed decisions

B.

Allocating the resources necessary to purchase the appropriate software packages

C.

Performing the business case analysis for the data analytics initiative

D.

Designing the workflow necessary for the data analytics tool to evaluate the appropriate data

Question 284

During an audit, the IS auditor finds that in many cases excessive rights were not removed from a system. Which of the following is the auditor ' s BEST recommendation?

Options:

A.

System administrators should ensure consistency of assigned rights.

B.

IT security should regularly revoke excessive system rights.

C.

Human resources (HR) should delete access rights of terminated employees.

D.

Line management should regularly review and request modification of access rights

Question 285

Which of the following BEST describes an audit risk?

Options:

A.

The company is being sued for false accusations.

B.

The financial report may contain undetected material errors.

C.

Employees have been misappropriating funds.

D.

Key employees have not taken vacation for 2 years.

Question 286

Which of the following is the PRIMARY reason for an IS auditor to conduct post-implementation reviews?

Options:

A.

To determine whether project objectives in the business case have been achieved

B.

To ensure key stakeholder sign-off has been obtained

C.

To align project objectives with business needs

D.

To document lessons learned to improve future project delivery

Question 287

Which of the following BEST indicates the effectiveness of an organization ' s risk management program?

Options:

A.

Inherent risk is eliminated.

B.

Residual risk is minimized.

C.

Control risk is minimized.

D.

Overall risk is quantified.

Question 288

An IS auditor is auditing the operating effectiveness of weekly user access reviews. Of the five weekly reviews sampled, one has not been signed or dated. What is the MAIN reason to note this observation as a finding?

Options:

A.

The review may not be accurate.

B.

The review may not contain the appropriate content.

C.

The review may not be in compliance with industry standards.

D.

The review may not have been performed.

Question 289

An IS auditor is asked to review an organization ' s technology relationships, interfaces, and data. Which of the following enterprise architecture (EA) areas is MOST appropriate this review? (Choose Correct answer and give explanation from CISA Certification - Information Systems Auditor official book)

Options:

A.

Reference architecture

B.

Infrastructure architecture

C.

Information security architecture

D.

Application architecture

Question 290

Which of the following analytical methods would be MOST useful when trying to identify groups with similar behavior or characteristics in a large population?

Options:

A.

Deviation detection

B.

Cluster sampling

C.

Random sampling

D.

Classification

Question 291

IT governance should be driven by:

Options:

A.

business unit initiatives.

B.

balanced scorecards.

C.

policies and standards.

D.

organizational strategies.

Question 292

An IS auditor has found that an organization is unable to add new servers on demand in a cost-efficient manner. Which of the following is the auditor ' s BEST recommendation?

Options:

A.

Increase the capacity of existing systems.

B.

Upgrade hardware to newer technology.

C.

Hire temporary contract workers for the IT function.

D.

Build a virtual environment.

Question 293

An IS auditor is performing a follow-up audit for findings identified in an organization ' s user provisioning process Which of the following is the MOST appropriate population to sample from when testing for remediation?

Options:

A.

All users provisioned after the finding was originally identified

B.

All users provisioned after management resolved the audit issue

C.

All users provisioned after the final audit report was issued

D.

All users who have followed user provisioning processes provided by management

Question 294

An IS auditor is conducting an IT governance audit and notices many initiatives are managed informally by isolated project managers. Which of the following recommendations would have the GREATEST impact on improving the maturity of the IT team?

Options:

A.

Schedule a follow-up audit in the next year to confirm whether IT processes have matured.

B.

Create an interdisciplinary IT steering committee to oversee IT prioritization and spending.

C.

Document and track all IT decisions in a project management tool.

D.

Discontinue all current IT projects until formal approval is obtained and documented.

Question 295

Which of the following would be of GREATEST concern to an IS auditor reviewing the feasibility study for a new application system?

Options:

A.

Security requirements have not been defined.

B.

Conditions under which the system will operate are unclear.

C.

The business case does not include well-defined strategic benefits.

D.

System requirements and expectations have not been clarified.

Question 296

Which of the following is a social engineering attack method?

Options:

A.

An unauthorized person attempts to gam access to secure premises by following an authonzed person through a secure door.

B.

An employee is induced to reveal confidential IP addresses and passwords by answering questions over the phone.

C.

A hacker walks around an office building using scanning tools to search for a wireless network to gain access.

D.

An intruder eavesdrops and collects sensitive information flowing through the network and sells it to third parties.

Question 297

Which of the following is the BEST method to safeguard data on an organization ' s laptop computers?

Options:

A.

Disabled USB ports

B.

Full disk encryption

C.

Multi-factor authentication (MFA)

D.

Passkey phrases

Question 298

Which of the following would be of GREATEST concern when reviewing an organization ' s security information and event management (SIEM) solution?

Options:

A.

SIEM reporting is customized.

B.

SIEM configuration is reviewed annually

C.

The SIEM is decentralized.

D.

SIEM reporting is ad hoc.

Question 299

Which of the following observations would an IS auditor consider the GREATEST risk when conducting an audit of a virtual server farm tor potential software vulnerabilities?

Options:

A.

Guest operating systems are updated monthly

B.

The hypervisor is updated quarterly.

C.

A variety of guest operating systems operate on one virtual server

D.

Antivirus software has been implemented on the guest operating system only.

Question 300

An IS auditor should be MOST concerned if which of the following fire suppression systems is utilized to protect an asset storage closet?

Options:

A.

Deluge system

B.

Wet pipe system

C.

Preaction system

D.

CO2 system

Question 301

Which of the following technologies is BEST suited to fulfill a business requirement for nonrepudiation of business-to-business transactions with external parties without the need for a mutually trusted entity?

Options:

A.

Public key infrastructure (PKI)

B.

Blockchain distributed ledger

C.

Artificial intelligence (Al)

D.

Centralized ledger technology

Question 302

Which of the following management decisions presents the GREATEST risk associated with data leakage?

Options:

A.

There is no requirement for desktops to be encrypted

B.

Staff are allowed to work remotely

C.

Security awareness training is not provided to staff

D.

Security policies have not been updated in the past year

Question 303

Which of the following is the MOST significant impact to an organization that does not use an IT governance framework?

Options:

A.

adequate measurement of key risk indicators (KRIS)

B.

Inadequate alignment of IT plans and business objectives

C.

Inadequate business impact analysis (BIA) results and predictions

D.

Inadequate measurement of key performance indicators (KPls)

Question 304

Which of the following should be the IS auditor ' s PRIMARY focus, when evaluating an organization ' s offsite storage facility?

Options:

A.

Shared facilities

B.

Adequacy of physical and environmental controls

C.

Results of business continuity plan (BCP) test

D.

Retention policy and period

Question 305

An organization outsourced its IS functions to meet its responsibility for disaster recovery, the organization should:

Options:

A.

discontinue maintenance of the disaster recovery plan (DRP >

B.

coordinate disaster recovery administration with the outsourcing vendor

C.

delegate evaluation of disaster recovery to a third party

D.

delegate evaluation of disaster recovery to internal audit

Question 306

Which of the following is the BEST approach to validate whether a streaming site can continue to provide service during a period of live streaming with an anticipated high volume of viewers?

Options:

A.

Fuzzing

B.

Usability test

C.

Fault grading

D.

Load test

Question 307

Which of the following IT service management activities is MOST likely to help with identifying the root cause of repeated instances of network latency?

Options:

A.

Change management

B.

Problem management

C.

incident management

D.

Configuration management

Question 308

Which of the following provides the MOST comprehensive information about inherent risk within an organization?

Options:

A.

Risk assessments.

B.

Risk-based audit findings.

C.

Peer benchmarking.

D.

Business impact analysis (BIA).

Question 309

An IS auditor is reviewing an artificial intelligence (Al) and expert system application. The system has produced several critical errors with severe impact. Which of the following should the IS auditor do NEXT to understand the cause of the errors?

Options:

A.

Review the decision-making logic built into the system.

B.

Interview the system owner.

C.

Understand the purpose and functionality of the system.

D.

Verify system adherence to corporate policy.

Question 310

Following a security breach in which a hacker exploited a well-known vulnerability in the domain controller, an IS audit has been asked to conduct a control assessment. the auditor ' s BEST course of action would be to determine if:

Options:

A.

the patches were updated.

B.

The logs were monitored.

C.

The network traffic was being monitored.

D.

The domain controller was classified for high availability.

Question 311

Which of the following is the PRIMARY benefit of effective implementation of appropriate data classification?

Options:

A.

Ability to meet business requirements

B.

Assurance that sensitive data is encrypted

C.

Increased accuracy of sensitive data

D.

Management of business risk to sensitive data

Question 312

An organization has purchased a new cloud-based application from a vendor. Which of the following should be the FIRST consideration when implementing the system?

Options:

A.

Preventing alterations to the source code during implementation.

B.

Ensuring vendor default accounts and passwords have been disabled.

C.

Verifying that the vendor is meeting maintenance agreements.

D.

Deleting the old copies of the program from escrow to avoid wrong versions.

Question 313

Who is responsible for defining data access permissions?

Options:

A.

IT operations manager

B.

Data owner

C.

Database administrator (DBA)

D.

Information security manager

Question 314

Which of the following should be the MOST important consideration when conducting a review of IT portfolio management?

Options:

A.

Assignment of responsibility for each project to an IT team member

B.

Adherence to best practice and industry approved methodologies

C.

Controls to minimize risk and maximize value for the IT portfolio

D.

Frequency of meetings where the business discusses the IT portfolio

Question 315

Which of the following parameters reflects the risk threshold for an organization experiencing a service disruption?

Options:

A.

Maximum tolerable outage (MTO)

B.

Recovery point objective (RPO)

C.

Service delivery objective (SDO)

D.

Allowable interruption window (AIW)

Question 316

Which of the following is the BEST indicator for measuring performance of IT help desk function?

Options:

A.

Percentage of problems raised from incidents

B.

Mean time to categorize tickets

C.

Number 0t incidents reported

D.

Number of reopened tickets

Question 317

Which of the following is MOST appropriate to prevent unauthorized retrieval of confidential information stored in a business application system?

Options:

A.

Apply single sign-on for access control

B.

Implement segregation of duties.

C.

Enforce an internal data access policy.

D.

Enforce the use of digital signatures.

Question 318

Which of the following is the MOST important consideration when relying on the work of the prior auditor?

Options:

A.

Qualifications of the prior auditor

B.

Management agreement with recommendations

C.

Duration of the prior audit

D.

Number of findings identified by the prior auditor

Question 319

During an organization ' s implementation of a data loss prevention (DLP) solution, which of the following activities should be completed FIRST?

Options:

A.

Configuring reports

B.

Configuring rule sets

C.

Enabling detection points

D.

Establishing exceptions workflow

Question 320

What would be an IS auditor ' s BEST course of action when an auditee is unable to close all audit recommendations by the time of the follow-up audit?

Options:

A.

Ensure the open issues are retained in the audit results.

B.

Terminate the follow-up because open issues are not resolved

C.

Recommend compensating controls for open issues.

D.

Evaluate the residual risk due to open issues.

Question 321

In a large organization, IT deadlines on important projects have been missed because IT resources are not prioritized properly. Which of the following is the BEST recommendation to address this problem?

Options:

A.

Revisit the IT strategic plan.

B.

Implement project portfolio management.

C.

Implement an integrated resource management system.

D.

Implement a comprehensive project scorecard.

Question 322

Which of the following is the GREATEST risk of project dashboards being set without sufficiently defined criteria?

Options:

A.

Adverse findings from internal and external auditors

B.

Lack of project portfolio status oversight

C.

Lack of alignment of project status reports

D.

Inadequate decision-making and prioritization

Question 323

Which of the following is the MOST appropriate control to ensure integrity of online orders?

Options:

A.

Data Encryption Standard (DES)

B.

Digital signature

C.

Public key encryption

D.

Multi-factor authentication

Question 324

An organization is shifting to a remote workforce In preparation the IT department is performing stress and capacity testing of remote access infrastructure and systems What type of control is being implemented?

Options:

A.

Directive

B.

Detective

C.

Preventive

D.

Compensating

Question 325

An organization ' s enterprise architecture (EA) department decides to change a legacy system ' s components while maintaining its original functionality. Which of the following is MOST important for an IS auditor to understand when reviewing this decision?

Options:

A.

The current business capabilities delivered by the legacy system

B.

The proposed network topology to be used by the redesigned system

C.

The data flows between the components to be used by the redesigned system

D.

The database entity relationships within the legacy system

Question 326

Email required for business purposes is being stored on employees ' personal devices.

Which of the following is an IS auditor ' s BEST recommendation?

Options:

A.

Require employees to utilize passwords on personal devices

B.

Prohibit employees from storing company email on personal devices

C.

Ensure antivirus protection is installed on personal devices

D.

Implement an email containerization solution on personal devices

Question 327

Providing security certification for a new system should include which of the following prior to the system ' s implementation?

Options:

A.

End-user authorization to use the system in production

B.

External audit sign-off on financial controls

C.

Testing of the system within the production environment

D.

An evaluation of the configuration management practices

Question 328

in a post-implantation Nation review of a recently purchased system it is MOST important for the iS auditor to determine whether the:

Options:

A.

stakeholder expectations were identified

B.

vendor product offered a viable solution.

C.

user requirements were met.

D.

test scenarios reflected operating activities.

Question 329

What is the purpose of hashing a document?

Options:

A.

To prevent unauthorized disclosure of the contents

B.

To validate the integrity of the file contents

C.

To classify the file for internal use only

D.

To compress the size of the file

Question 330

Which of the following should be done FIRST when planning to conduct internal and external penetration testing for a client?

Options:

A.

Establish the timing of testing.

B.

Identify milestones.

C.

Determine the test reporting

D.

Establish the rules of engagement.

Question 331

Which of the following fire suppression systems needs to be combined with an automatic switch to shut down the electricity supply in the event of activation?

Options:

A.

Carbon dioxide

B.

FM-200

C.

Dry pipe

D.

Halon

Question 332

What is the PRIMARY benefit of using one-time passwords?

Options:

A.

An intercepted password cannot be reused

B.

Security for applications can be automated

C.

Users do not have to memorize complex passwords

D.

Users cannot be locked out of an account

Question 333

Which of the following BEST minimizes performance degradation of servers used to authenticate users of an e-commerce website?

Options:

A.

Configure a single server as a primary authentication server and a second server as a secondary authentication server.

B.

Configure each authentication server as belonging to a cluster of authentication servers.

C.

Configure each authentication server and ensure that each disk of its RAID is attached to the primary controller.

D.

Configure each authentication server and ensure that the disks of each server form part of a duplex.

Question 334

An IS auditor is evaluating the progress of a web-based customer service application development project. Which of the following would be MOST helpful for this evaluation?

Options:

A.

Backlog consumption reports

B.

Critical path analysis reports

C.

Developer status reports

D.

Change management logs

Question 335

An IS auditor finds a segregation of duties issue in an enterprise resource planning (ERP) system. Which of the following is the BEST way to prevent the misconfiguration from recurring?

Options:

A.

Monitoring access rights on a regular basis

B.

Referencing a standard user-access matrix

C.

Granting user access using a role-based model

D.

Correcting the segregation of duties conflicts

Question 336

Which of the following provides the MOST reliable method of preventing unauthonzed logon?

Options:

A.

issuing authentication tokens

B.

Reinforcing current security policies

C.

Limiting after-hours usage

D.

Installing an automatic password generator

Question 337

As part of business continuity planning, which of the following is MOST important to assess when conducting a business impact analysis (B1A)?

Options:

A.

Risk appetite

B.

Critical applications m the cloud

C.

Completeness of critical asset inventory

D.

Recovery scenarios

Question 338

An organization is disposing of removable onsite media which contains sensitive information. Which of the following is the MOST effective method to prevent disclosure of sensitive data?

Options:

A.

Encrypting and destroying keys

B.

Machine shredding

C.

Software formatting

D.

Wiping and rewriting three times

Question 339

A new system development project is running late against a critical implementation deadline. Which of the following is the MOST important activity?

Options:

A.

Ensure that code has been reviewed.

B.

Perform user acceptance testing (UAT).

C.

Document last-minute enhancements.

D.

Perform a pre-implementation audit.

Question 340

A manager Identifies active privileged accounts belonging to staff who have left the organization. Which of the following is the threat actor In this scenario?

Options:

A.

Terminated staff

B.

Unauthorized access

C.

Deleted log data

D.

Hacktivists

Question 341

The PRIMARY benefit of automating application testing is to:

Options:

A.

provide test consistency.

B.

provide more flexibility.

C.

replace all manual test processes.

D.

reduce the time to review code.

Question 342

An IS auditor is planning a review of an organizations cybersecurity incident response maturity Which of the following methodologies would provide the MOST reliable conclusions?

Options:

A.

Judgmental sampling

B.

Data analytics testing

C.

Variable sampling

D.

Compliance testing

Question 343

Which of the following controls is MOST crucial to ensure an organization will be able to recover its data from backup media in the event of a disaster?

Options:

A.

Storing backup media at an offsite facility

B.

Keeping a current inventory of backup media

C.

Periodically restoring backup media for key databases

D.

Encrypting data on backup media

Question 344

Backup procedures for an organization ' s critical data are considered to be which type of control?

Options:

A.

Directive

B.

Corrective

C.

Detective

D.

Compensating

Question 345

During an audit of a financial application, it was determined that many terminated users ' accounts were not disabled. Which of the following should be the IS auditor ' s NEXT step?

Options:

A.

Perform substantive testing of terminated users ' access rights.

B.

Perform a review of terminated users ' account activity

C.

Communicate risks to the application owner.

D.

Conclude that IT general controls ate ineffective.

Question 346

Which of the following should be of GREATEST concern to an IS auditor reviewing a terminated employee’s network access?

Options:

A.

The user account password is set to never expire.

B.

The last login to the user account was days after the last working date.

C.

The user account password was last changed more than 90 days ago.

D.

There is not a documented approval process to disable user accounts.

Question 347

Which of the following is the MOST effective way for an organization to project against data loss?

Options:

A.

Limit employee internet access.

B.

Implement data classification procedures.

C.

Review firewall logs for anomalies.

D.

Conduct periodic security awareness training.

Question 348

Which of the following system attack methods is executed by entering malicious code into the search box of a vulnerable website, causing the server to reveal restricted information?

Options:

A.

Man-m-the-middle

B.

Denial of service (DoS)

C.

SQL injection

D.

Cross-site scripting

Question 349

Which of the following application input controls would MOST likely detect data input errors in the customer account number field during the processing of an accounts receivable transaction?

Options:

A.

Limit check

B.

Parity check

C.

Reasonableness check

D.

Validity check

Question 350

While auditing a small organization ' s data classification processes and procedures, an IS auditor noticed that data is often classified at the incorrect level. What is the MOST effective way for the organization to improve this situation?

Options:

A.

Use automatic document classification based on content.

B.

Have IT security staff conduct targeted training for data owners.

C.

Publish the data classification policy on the corporate web portal.

D.

Conduct awareness presentations and seminars for information classification policies.

Question 351

During a pre-deployment assessment, what is the BEST indication that a business case will lead to the achievement of business objectives?

Options:

A.

The business case reflects stakeholder requirements.

B.

The business case is based on a proven methodology.

C.

The business case passed a quality review by an independent party.

D.

The business case identifies specific plans for cost allocation.

Question 352

Which of the following methods BEST enforces data leakage prevention in a multi-tenant cloud environment?

Options:

A.

Monitoring tools are configured to alert in case of downtime

B.

A comprehensive security review is performed every quarter.

C.

Data for different tenants is segregated by database schema

D.

Tenants are required to implement data classification polices

Question 353

An IS auditor wants to gain a better understanding of an organization’s selected IT operating system software. Which of the following would be MOST helpful to review?

Options:

A.

Service level agreements (SLAs)

B.

Project steering committee charter

C.

IT audit reports

D.

Enterprise architecture (EA)

Question 354

A steering committee established to oversee an organization’s digital transformation program is MOST likely to be involved with which of the following activities?

Options:

A.

Designing interface controls.

B.

Documenting requirements.

C.

Reviewing escalated project issues.

D.

Preparing project status reports.

Question 355

Which of the following is a detective control?

Options:

A.

Programmed edit checks for data entry

B.

Backup procedures

C.

Use of pass cards to gain access to physical facilities

D.

Verification of hash totals

Question 356

Which of the following BEST facilitates the legal process in the event of an incident?

Options:

A.

Right to perform e-discovery

B.

Advice from legal counsel

C.

Preserving the chain of custody

D.

Results of a root cause analysis

Question 357

Which of the following is MOST helpful for measuring benefits realization for a new system?

Options:

A.

Function point analysis

B.

Balanced scorecard review

C.

Post-implementation review

D.

Business impact analysis (BIA)

Question 358

An IS auditor is reviewing an organization ' s risk management program. Which of the following should be the PRIMARY driver of the enterprise IT risk appetite?

Options:

A.

Strategic objectives

B.

Return on investment (ROI)

C.

Cost of implementing controls

D.

Likelihood of risk events

Question 359

An organization is modernizing its technology policy framework to demonstrate compliance with external industry standards. Which of the following would be MOST useful to an IS auditor for validating the outcome?

Options:

A.

Benchmarking of internal standards against peer organizations

B.

Inventory of the organization ' s approved policy exceptions

C.

Policy recommendations from a leading external consulting agency

D.

Mapping of relevant standards against the organization ' s controls

Question 360

The MOST effective way to reduce sampling risk is to increase:

Options:

A.

confidence interval.

B.

population.

C.

audit sampling training.

D.

sample size.

Question 361

During a follow-up audit, an IS auditor finds that senior management has implemented a different remediation action plan than what was previously agreed upon. Which of the following is the auditor ' s BEST course of action?

Options:

A.

Report the deviation by the control owner in the audit report.

B.

Evaluate the implemented control to ensure it mitigates the risk to an acceptable level.

C.

Cancel the follow-up audit and reschedule for the next audit period.

D.

Request justification from management for not implementing the recommended control.

Question 362

Which of the following is the BEST indication of effective IT investment management?

Options:

A.

IT investments are implemented and monitored following a system development life cycle (SDLC)

B.

IT investments are mapped to specific business objectives

C.

Key performance indicators (KPIs) are defined for each business requiring IT Investment

D.

The IT Investment budget is significantly below industry benchmarks

Question 363

Which of the following should be of GREATEST concern to an IS auditor who is assessing an organization ' s configuration and release management process?

Options:

A.

The organization does not use an industry-recognized methodology

B.

Changes and change approvals are not documented

C.

All changes require middle and senior management approval

D.

There is no centralized configuration management database (CMDB)

Question 364

Which of the following activities would allow an IS auditor to maintain independence while facilitating a control sell-assessment (CSA)?

Options:

A.

Implementing the remediation plan

B.

Partially completing the CSA

C.

Developing the remediation plan

D.

Developing the CSA questionnaire

Question 365

An organization is ready to implement a new IT solution consisting of multiple modules. The last module updates the processed data into the database. Which of the following findings should be of MOST concern to the IS auditor?

Options:

A.

Absence of a formal change approval process

B.

Lack of input validation

C.

Use of weak encryption

D.

Lack of a data dictionary

Question 366

Which of the following tests is MOST likely to detect an error in one subroutine resulting from a recent change in another subroutine?

Options:

A.

User acceptance testing (UAT)

B.

Black-box testing

C.

Regression testing

D.

Stress testing

Question 367

Malicious program code was found in an application and corrected prior to release into production. After the release, the same issue was reported. Which of the following is the IS auditor ' s BEST recommendation?

Options:

A.

Ensure corrected program code is compiled in a dedicated server.

B.

Ensure change management reports are independently reviewed.

C.

Ensure programmers cannot access code after the completion of program edits.

D.

Ensure the business signs off on end-to-end user acceptance test (UAT) results.

Question 368

Which of the following should be the GREATEST concern for an IS auditor reviewing recent disaster recovery operations?

Options:

A.

The recovery point objective (RPO) was not defined.

B.

Test data was lost during a recovery operation.

C.

A warm site was used as a recovery strategy.

D.

A full backup was only performed once a week.

Question 369

What is the GREATEST concern for an IS auditor reviewing contracts for licensed software that executes a critical business process?

Options:

A.

The contract does not contain a right-to-audit clause.

B.

An operational level agreement (OLA) was not negotiated.

C.

Several vendor deliverables missed the commitment date.

D.

Software escrow was not negotiated.

Question 370

Which of the following is the MOST efficient control to reduce the risk associated with a systems administrator having network administrator responsibilities?

Options:

A.

The administrator must obtain temporary access to make critical changes.

B.

The administrator will need to request additional approval for critical changes.

C.

The administrator must sign a due diligence agreement.

D.

The administrator will be subject to unannounced audits.

Question 371

Which of the following should be the IS auditor ' s PRIMARY focus when evaluating an organizations offsite storage facility?

Options:

A.

Adequacy of physical and environmental controls

B.

Results of business continuity plan (BCP) tests

C.

Shared facilities

D.

Retention policy and period

Question 372

Which of the following MUST be completed as part of the annual audit planning process?

Options:

A.

Business impact analysis (BIA)

B.

Fieldwork

C.

Risk assessment

D.

Risk control matrix

Question 373

Which of the following would be the MOST significant finding when reviewing a data backup process?

Options:

A.

Recovery testing is not performed.

B.

The data backup process is not documented.

C.

Tapes are not consistently rotated offsite.

D.

The key to the data safe is kept by the backup administrator.

Question 374

Which of the following is the BEST indication that an information security awareness program is effective?

Options:

A.

A reduction in the number of reported information security incidents

B.

A reduction in the success rate of social engineering attacks

C.

A reduction in the cost of maintaining the information security program

D.

A reduction in the number of information security attacks

Question 375

Which of the following is the MOST important area of focus for an IS auditor assessing the management of cryptographic keys in a public key infrastructure (PKI)?

Options:

A.

Checking the subscription of the key management system

B.

Identifying unusual activities by the key processors

C.

Reviewing key compromise detection activities

D.

Reviewing PKI documentation

Question 376

Which of the following should be the PRIMARY basis for prioritizing follow-up audits?

Options:

A.

Audit cycle defined in the audit plan

B.

Complexity of management ' s action plans

C.

Recommendation from executive management

D.

Residual risk from the findings of previous audits

Question 377

Which of the following is the GREATEST advantage of maintaining an internal IS audit function within an organization?

Options:

A.

Increased independence and impartiality of recommendations

B.

Better understanding of the business and processes

C.

Ability to negotiate recommendations with management

D.

Increased IS audit staff visibility and availability throughout the year

Question 378

Which of the following is an effective way to ensure the integrity of file transfers in a peer-to-peer (P2P) computing environment?

Options:

A.

Associate a message authentication code with each file transferred.

B.

Ensure the files are transferred through an intrusion detection system (IDS).

C.

Encrypt the packets shared between peers within the environment.

D.

Connect the client computers in the environment to a jump server.

Question 379

An IS auditor has been asked to audit the proposed acquisition of new computer hardware. The auditor’s PRIMARY concern Is that:

Options:

A.

the implementation plan meets user requirements.

B.

a full, visible audit trail will be Included.

C.

a dear business case has been established.

D.

the new hardware meets established security standards

Question 380

When an IS auditor needs to confirm that an organization is encrypting sensitive information at a database level, which of the following would provide the BEST assurance?

Options:

A.

Reviewing the drive settings of the host server

B.

Checking network traffic for clear text transmissions

C.

Verifying a sample of critical fields

D.

Reviewing the organization’s encryption policy

Question 381

Which of the following is the PRIMARY benefit of operational log management?

Options:

A.

It enhances user experience via predictive analysis.

B.

It improves security with real-time monitoring of network data.

C.

It organizes data to identify performance issues.

D.

It supports data aggregation using unified storage.

Question 382

Which of the following should be performed FIRST before key performance indicators (KPIs) can be implemented?

Options:

A.

Analysis of industry benchmarks

B.

Identification of organizational goals

C.

Analysis of quantitative benefits

D.

Implementation of a balanced scorecard

Question 383

Which of the following should be used to evaluate an IT development project before an investment is committed?

Options:

A.

Earned value analysis (EVA)

B.

Rapid application development

C.

Function point analysis

D.

Feasibility study

Question 384

An organization is implementing a new data loss prevention (DLP) tool. Which of the following will BEST enable the organization to reduce false positive alerts?

Options:

A.

Using the default policy and tool rule sets

B.

Configuring a limited set of rules

C.

Deploying the tool in monitor mode

D.

Reducing the number of detection points

Question 385

A data breach has occurred due lo malware. Which of the following should be the FIRST course of action?

Options:

A.

Notify the cyber insurance company.

B.

Shut down the affected systems.

C.

Quarantine the impacted systems.

D.

Notify customers of the breach.

Question 386

The charging method that effectively encourages the MOST efficient use of IS resources is:

Options:

A.

specific charges that can be tied back to specific usage.

B.

total utilization to achieve full operating capacity.

C.

residual income in excess of actual incurred costs.

D.

allocations based on the ability to absorb charges.

Question 387

Which of the following BEST enables the timely identification of risk exposure?

Options:

A.

External audit review

B.

Internal audit review

C.

Control self-assessment (CSA)

D.

Stress testing

Question 388

During the planning phase of a data loss prevention (DLP) audit, management expresses a concern about mobile computing. Which of the following should the IS auditor identity as the associated risk?

Options:

A.

The use of the cloud negatively impacting IT availably

B.

Increased need for user awareness training

C.

Increased vulnerability due to anytime, anywhere accessibility

D.

Lack of governance and oversight for IT infrastructure and applications

Question 389

Which of the following is the PRIMARY purpose of batch processing monitoring?

Options:

A.

To comply with security standards

B.

To summarize the batch processing reporting

C.

To log error events in batch processing

D.

To prevent an incident that may result from batch failure

Question 390

Which of the following is the PRIMARY benefit of monitoring IT operational logs?

Options:

A.

Detecting processing errors in a timely manner

B.

Identifying configuration flaws in operating systems

C.

Managing the usability and capacity of IT resources

D.

Generating exception reports to assess security compliance

Question 391

An IS auditor is reviewing an organization ' s incident management processes. Which of the following observations should be the auditor ' s GREATEST concern?

Options:

A.

Ineffective incident detection

B.

Ineffective incident dashboard

C.

Ineffective incident classification

D.

Ineffective post-incident review

Question 392

External audits have identified recurring exceptions in the user termination process, despite similar internal audits having reported no exceptions in the past. Which of the following is the IS auditor ' s BEST course of action to improve the internal audit process in the future?

Options:

A.

Include the user termination process in all upcoming audits.

B.

Review user termination process changes.

C.

Review the internal audit sampling methodology.

D.

Review control self-assessment (CSA) results.

Question 393

Which of the following is MOST important to consider when evaluating a reciprocal arrangement as a recovery strategy?

Options:

A.

Differences in infrastructure capabilities.

B.

Differences in security policies and procedures.

C.

Differences in service level expectations.

D.

Differences in skills and resource competencies.

Question 394

How does the emergence of quantum computing impact traditional data encryption methods?

Options:

A.

Quantum computing may render classical encryption algorithms obsolete due to its ability to decrypt data with unprecedented efficiency.

B.

Quantum computing introduces new encryption techniques that are immune to decryption by classical and quantum computers alike.

C.

Quantum computing enhances the security of classical encryption algorithms by providing faster computation speeds.

D.

Quantum computing will require more frequent training on the application of classical data encryption methods.

Question 395

Which of the following should be of GREATEST concern to an IS auditor when auditing an organization ' s IT strategy development process?

Options:

A.

The IT strategy was developed before the business plan

B.

A business impact analysis (BIA) was not performed to support the IT strategy

C.

The IT strategy was developed based on the current IT capability

D.

Information security was not included as a key objective m the IT strategic plan.

Question 396

Which of the following BEST supports an organization ' s objective of restricting the use of removable storage devices by users?

Options:

A.

Data management policy

B.

Updated anti-malware solutions

C.

Data loss prevention (DLP)

D.

Online monitoring

Question 397

Which of the following applications has the MOST inherent risk and should be prioritized during audit planning?

Options:

A.

A decommissioned legacy application

B.

An onsite application that is unsupported

C.

An outsourced accounting application

D.

An internally developed application

Question 398

What should be the PRIMARY basis for selecting which IS audits to perform in the coming year?

Options:

A.

Senior management ' s request

B.

Prior year ' s audit findings

C.

Organizational risk assessment

D.

Previous audit coverage and scope

Question 399

Which of the following is the GREATEST concern associated with IS risk-based auditing when audit resources are limited?

Options:

A.

The audit schedule may become too predictable.

B.

Some business processes may not be audited.

C.

There may be significant delays in responding to management audit requests.

D.

Conducting risk assessments may reduce the time available for auditing.

Question 400

Which of the following would BEST indicate the effectiveness of a security awareness training program?

Options:

A.

Results of third-party social engineering tests

B.

Employee satisfaction with training

C.

Increased number of employees completing training

D.

Reduced unintentional violations

Question 401

Which of the following statements appearing in an organization ' s acceptable use policy BEST demonstrates alignment with data classification standards related to the protection of information assets?

Options:

A.

Any information assets transmitted over a public network must be approved by executive management.

B.

All information assets must be encrypted when stored on the organization ' s systems.

C.

Information assets should only be accessed by persons with a justified need.

D.

All information assets will be assigned a clearly defined level to facilitate proper employee handling.

Question 402

Which of the following is the BEST indication of effective governance over IT infrastructure?

Options:

A.

The ability to deliver continuous, reliable performance

B.

A requirement for annual security awareness programs

C.

An increase in the number of IT infrastructure servers

D.

A decrease in the number of information security incidents

Question 403

An IS auditor finds an IT manager recently changed a Software as a Service (SaaS) provider contract in an effort to cut costs. The new contract increases the time to resolve incidents. Which of the following should be the auditor’s GREATEST concern?

Options:

A.

The impact on business processes has not been evaluated.

B.

The new contract is not in compliance with IT security policy.

C.

The corresponding service level agreement (SLA) was not modified.

D.

Alternative cost-reduction methods were not considered.

Question 404

Which of the following is MOST helpful to an IS auditor when assessing the effectiveness of controls?

Options:

A.

A control self-assessment (CSA)

B.

Results of control testing

C.

Interviews with management

D.

A control matrix

Question 405

Which of the following is the BEST metric to measure the alignment of IT and business strategy?

Options:

A.

Level of stakeholder satisfaction with the scope of planned IT projects

B.

Percentage of enterprise risk assessments that include IT-related risk

C.

Percentage of stat satisfied with their IT-related roles

D.

Frequency of business process capability maturity assessments

Question 406

Which of the following is the BEST justification for deferring remediation testing until the next audit?

Options:

A.

The auditor who conducted the audit and agreed with the timeline has left the organization.

B.

Management ' s planned actions are sufficient given the relative importance of the observations.

C.

Auditee management has accepted all observations reported by the auditor.

D.

The audit environment has changed significantly.

Question 407

An organization has recently become aware of a pervasive chip-level security vulnerability that affects all of its processors. Which of the following is the BEST way to prevent this vulnerability from being exploited?

Options:

A.

Implement security awareness training.

B.

Install vendor patches

C.

Review hardware vendor contracts.

D.

Review security log incidents.

Question 408

Which of the following are used in a firewall to protect the entity ' s internal resources?

Options:

A.

Remote access servers

B.

Secure Sockets Layers (SSLs)

C.

Internet Protocol (IP) address restrictions

D.

Failover services

Question 409

Which of the following is the MOST effective way to identify exfiltration of sensitive data by a malicious insider?

Options:

A.

Implement data loss prevention (DLP) software

B.

Review perimeter firewall logs

C.

Provide ongoing information security awareness training

D.

Establish behavioral analytics monitoring

Question 410

Which of the following is the BEST review for an IS auditor to conduct when a vulnerability has been exploited by an employee?

Options:

A.

Compliance audit

B.

Application security testing

C.

Forensic audit

D.

Penetration testing

Question 411

What should an IS auditor evaluate FIRST when reviewing an organization ' s response to new privacy legislation?

Options:

A.

Implementation plan for restricting the collection of personal information

B.

Privacy legislation in other countries that may contain similar requirements

C.

Operational plan for achieving compliance with the legislation

D.

Analysis of systems that contain privacy components

Question 412

Which of the following methods would BEST help detect unauthorized disclosure of confidential documents sent over corporate email?

Options:

A.

Requiring all users to encrypt documents before sending

B.

Installing firewalls on the corporate network

C.

Reporting all outgoing emails that are marked as confidential

D.

Monitoring all emails based on pre-defined criteria

Question 413

To protect the organization from malware transmitted by physical media, IT administrators have disabled USB access for storage devices. Which of the following BEST describes this type of control?

Options:

A.

Corrective

B.

Administrative

C.

Preventive

D.

Physical

Question 414

Which of the following would be an appropriate role of internal audit in helping to establish an organization’s privacy program?

Options:

A.

Analyzing risks posed by new regulations

B.

Developing procedures to monitor the use of personal data

C.

Defining roles within the organization related to privacy

D.

Designing controls to protect personal data

Question 415

Which of the following is the MOST effective control over visitor access to highly secured areas?

Options:

A.

Visitors are required to be escorted by authorized personnel.

B.

Visitors are required to use biometric authentication.

C.

Visitors are monitored online by security cameras

D.

Visitors are required to enter through dead-man doors.

Question 416

During the design phase of a software development project, the PRIMARY responsibility of an IS auditor is to evaluate the:

Options:

A.

Future compatibility of the application.

B.

Proposed functionality of the application.

C.

Controls incorporated into the system specifications.

D.

Development methodology employed.

Question 417

When reviewing an organization ' s information security policies, an IS auditor should verify that the policies have been defined PRIMARILY on the basis of:

Options:

A.

a risk management process.

B.

an information security framework.

C.

past information security incidents.

D.

industry best practices.

Question 418

During a security audit, an IS auditor is tasked with reviewing log entries obtained from an enterprise intrusion prevention system (IPS). Which type of risk would be associated with the potential for the auditor to miss a sequence of logged events that could indicate an error in the IPS configuration?

Options:

A.

Sampling risk

B.

Detection risk

C.

Control risk

D.

Inherent risk

Question 419

Who is PRIMARILY responsible for the design of IT controls to meet control objectives?

Options:

A.

Business management

B.

Internal auditor

C.

Risk management

D.

ITC manager

Question 420

During a routine internal software licensing review, an IS auditor discovers instances where employees shared license keys to critical pieces of business software. Which of the following would be the auditor ' s BEST course of action?

Options:

A.

Recommend the utilization of software licensing monitoring tools

B.

Recommend the purchase of additional software license keys

C.

Validate user need for shared software licenses

D.

Verify whether the licensing agreement allows shared use

Question 421

An organization recently implemented a cloud document storage solution and removed the ability for end users to save data to their local workstation hard drives. Which of the following findings should be the IS auditor ' s GREATEST concern?

Options:

A.

Users are not required to sign updated acceptable use agreements.

B.

Users have not been trained on the new system.

C.

The business continuity plan (BCP) was not updated.

D.

Mobile devices are not encrypted.

Question 422

When reviewing the functionality of an intrusion detection system (IDS), the IS auditor should be MOST concerned if:

Options:

A.

legitimate packets blocked by the system have increased

B.

actual attacks have not been identified

C.

detected events have increased

D.

false positives have been reported

Question 423

An organization has recently become aware of a pervasive chip-level security vulnerability that affects all of its processors. Which of the following is the BEST way to prevent this vulnerability from being exploited?

Options:

A.

Review security log incidents.

B.

Review hardware vendor contracts.

C.

Install vendor patches.

D.

Implement security awareness training.

Question 424

During the planning stage of a compliance audit, an IS auditor discovers that a bank ' s inventory of compliance requirements does not include recent regulatory changes related to managing data risk. What should the auditor do FIRST?

Options:

A.

Ask management why the regulatory changes have not been Included.

B.

Discuss potential regulatory issues with the legal department

C.

Report the missing regulatory updates to the chief information officer (CIO).

D.

Exclude recent regulatory changes from the audit scope.

Question 425

The FIRST step in auditing a data communication system is to determine:

Options:

A.

traffic volumes and response-time criteria

B.

physical security for network equipment

C.

the level of redundancy in the various communication paths

D.

business use and types of messages to be transmitted

Question 426

Which of the following should be an IS auditor ' s GREATEST consideration when scheduling follow-up activities for agreed-upon management responses to remediate audit observations?

Options:

A.

Business interruption due to remediation

B.

IT budgeting constraints

C.

Availability of responsible IT personnel

D.

Risk rating of original findings

Question 427

During recent post-implementation reviews, an IS auditor has noted that several deployed applications are not being used by the business. The MOST likely cause would be the lack of:

Options:

A.

IT portfolio management.

B.

IT resource management.

C.

system support documentation.

D.

change management.

Question 428

Which of the following findings should be of GREATEST concern to an IS auditor performing a review of IT operations?

Options:

A.

The job scheduler application has not been designed to display pop-up error messages.

B.

Access to the job scheduler application has not been restricted to a maximum of two staff members

C.

Operations shift turnover logs are not utilized to coordinate and control the processing environment

D.

Changes to the job scheduler application ' s parameters are not approved and reviewed by an operations supervisor

Question 429

An IS auditor is reviewing security controls related to collaboration tools for a business unit responsible for intellectual property and patents. Which of the following observations should be of MOST concern to the auditor?

Options:

A.

Training was not provided to the department that handles intellectual property and patents

B.

Logging and monitoring for content filtering is not enabled.

C.

Employees can share files with users outside the company through collaboration tools.

D.

The collaboration tool is hosted and can only be accessed via an Internet browser

Question 430

Which of the following activities is MOST likely to increase internal audit quality?

Options:

A.

Increasing audit staff training

B.

Outsourcing the internal audit function

C.

Increasing the number of planned audits

D.

Conducting client surveys

Question 431

Which of the following is MOST important to include in forensic data collection and preservation procedures?

Options:

A.

Assuring the physical security of devices

B.

Preserving data integrity

C.

Maintaining chain of custody

D.

Determining tools to be used

Question 432

Which of the following presents the GREATEST risk of data leakage in the cloud environment?

Options:

A.

Lack of data retention policy

B.

Multi-tenancy within the same database

C.

Lack of role-based access

D.

Expiration of security certificate

Question 433

To confirm integrity for a hashed message, the receiver should use:

Options:

A.

the same hashing algorithm as the sender ' s to create a binary image of the file.

B.

a different hashing algorithm from the sender ' s to create a binary image of the file.

C.

the same hashing algorithm as the sender ' s to create a numerical representation of the file.

D.

a different hashing algorithm from the sender ' s to create a numerical representation of the file.

Question 434

Which of the following should an IS auditor review FIRST when planning a customer data privacy audit?

Options:

A.

Legal and compliance requirements

B.

Customer agreements

C.

Data classification

D.

Organizational policies and procedures

Question 435

A vendor requires privileged access to a key business application. Which of the following is the BEST recommendation to reduce the risk of data leakage?

Options:

A.

Implement real-time activity monitoring for privileged roles

B.

Include the right-to-audit in the vendor contract

C.

Perform a review of privileged roles and responsibilities

D.

Require the vendor to implement job rotation for privileged roles

Question 436

An IS auditor finds that application servers had inconsistent security settings leading to potential vulnerabilities. Which of the following is the BEST recommendation by the IS auditor?

Options:

A.

Improve the change management process

B.

Establish security metrics.

C.

Perform a penetration test

D.

Perform a configuration review

Question 437

Which of the following should be GREATEST concern to an IS auditor reviewing data conversion and migration during the implementation of a new application system?

Options:

A.

Data conversion was performed using manual processes.

B.

Backups of the old system and data are not available online.

C.

Unauthorized data modifications occurred during conversion.

D.

The change management process was not formally documented

Question 438

Which of the following should an IS auditor consider FIRST when evaluating firewall rules?

Options:

A.

The organization ' s security policy

B.

The number of remote nodes

C.

The firewalls ' default settings

D.

The physical location of the firewalls

Question 439

Recovery facilities providing a redundant combination of Internet connections to the local communications loop is an example of which type of telecommunications continuity?

Options:

A.

Voice recovery

B.

Alternative routing

C.

Long-haul network diversity

D.

Last-mile circuit protection

Question 440

An IS auditor concludes that logging and monitoring mechanisms within an organization are ineffective because critical servers are not included within the central log repository. Which of the following audit procedures would have MOST likely identified this exception?

Options:

A.

Inspecting a sample of alerts generated from the central log repository

B.

Comparing a list of all servers from the directory server against a list of all servers present in the central log repository

C.

Inspecting a sample of alert settings configured in the central log repository

D.

Comparing all servers included in the current central log repository with the listing used for the prior-year audit

Question 441

Which of the following biometric access controls has the HIGHEST rate of false negatives?

Options:

A.

Iris recognition

B.

Fingerprint scanning

C.

Face recognition

D.

Retina scanning

Question 442

During a follow-up audit, an IS auditor learns that some key management personnel have been replaced since the original audit, and current management has decided not to implement some previously accepted recommendations. What is the auditor ' s BEST course of action?

Options:

A.

Notify the chair of the audit committee.

B.

Notify the audit manager.

C.

Retest the control.

D.

Close the audit finding.

Question 443

A secure server room has a badge reader system that records name, date, and time information whenever a staff member uses a badge to enter or exit. When reviewing the system logs, an IS auditor notices records for some employees entering, but not exiting, the room. Which of the following would be the MOST effective compensating control to recommend?

Options:

A.

Installing security cameras at the doors

B.

Changing to a biometric access control system

C.

Implementing a monitored mantrap at entrance and exit points

D.

Requiring two-factor authentication at entrance and exit points

Question 444

Which of the following testing methods is MOST appropriate for assessing whether system integrity has been maintained after changes have been made?

Options:

A.

Regression testing

B.

Unit testing

C.

Integration testing

D.

Acceptance testing

Question 445

Which of the following would BEST ensure that a backup copy is available for restoration of mission critical data after a disaster ' '

Options:

A.

Use an electronic vault for incremental backups

B.

Deploy a fully automated backup maintenance system.

C.

Periodically test backups stored in a remote location

D.

Use both tape and disk backup systems

Question 446

Management has requested a post-implementation review of a newly implemented purchasing package to determine to what extent business requirements are being met. Which of the following is MOST likely to be assessed?

Options:

A.

Purchasing guidelines and policies

B.

Implementation methodology

C.

Results of line processing

D.

Test results

Question 447

An IS auditor is reviewing an organization ' s business continuity plan (BCP) following a change in organizational structure with significant impact to business processes. Which of the following findings should be the auditor ' s GREATEST concern?

Options:

A.

Key business process end users did not participate in the business impact " analysis (BIA)

B.

Copies of the BCP have not been distributed to new business unit end users sjnce the reorganization

C.

A test plan for the BCP has not been completed during the last two years

Question 448

Which of the following is a PRIMARY responsibility of an IT steering committee?

Options:

A.

Prioritizing IT projects in accordance with business requirements

B.

Reviewing periodic IT risk assessments

C.

Validating and monitoring the skill sets of IT department staff

D.

Establishing IT budgets for the business

Question 449

Who is PRIMARILY responsible for the design of IT controls to meet control objectives?

Options:

A.

Risk management

B.

Business management

C.

IT manager

D.

Internal auditor

Question 450

Which of the following is the BEST way to ensure that an application is performing according to its specifications?

Options:

A.

Unit testing

B.

Pilot testing

C.

System testing

D.

Integration testing

Question 451

Which of the following should be of GREATEST concern to an IS auditor performing a review of information security controls?

Options:

A.

The information security policy has not been approved by the chief audit executive (CAE).

B.

The information security policy does not include mobile device provisions

C.

The information security policy is not frequently reviewed

D.

The information security policy has not been approved by the policy owner

Question 452

Which of the following security testing techniques is MOST effective for confirming that inputs to a web application have been properly sanitized?

Options:

A.

SQL injection

B.

Fuzzing

C.

Brute force

D.

Password spraying

Question 453

Which of the following is MOST useful when planning to audit an organization ' s compliance with cybersecurity regulations in foreign countries?

Options:

A.

Prioritize the audit to focus on the country presenting the greatest amount of operational risk.

B.

Follow the cybersecurity regulations of the country with the most stringent requirements.

C.

Develop a template that standardizes the reporting of findings from each country ' s audit team

D.

Map the different regulatory requirements to the organization ' s IT governance framework

Question 454

The PRIMARY benefit lo using a dry-pipe fire-suppression system rather than a wet-pipe system is that a dry-pipe system:

Options:

A.

is more effective at suppressing flames.

B.

allows more time to abort release of the suppressant.

C.

has a decreased risk of leakage.

D.

disperses dry chemical suppressants exclusively.

Question 455

Which of the following groups is PRIMARILY accountable for establishing a culture that facilitates an effective and efficient internal control system?

Options:

A.

HR

B.

Senior management

C.

Line management

D.

Internal audit

Question 456

Which of the following is the BEST way to mitigate risk to an organization ' s network associated with devices permitted under a bring your own device (BYOD) policy?

Options:

A.

Require personal devices to be reviewed by IT staff.

B.

Enable port security on all network switches.

C.

Implement a network access control system.

D.

Ensure the policy requires antivirus software on devices.

Question 457

Which of the following is MOST important for an IS auditor to validate when auditing network device management?

Options:

A.

Devices cannot be accessed through service accounts.

B.

Backup policies include device configuration files.

C.

All devices have current security patches assessed.

D.

All devices are located within a protected network segment.

Question 458

In continuous delivery, the critical connector between development and production is:

Options:

A.

Release management.

B.

Log management.

C.

DevOps.

D.

Data management.

Question 459

An IS auditor finds that an IT manager recently changed a Software as a Service (SaaS) provider contract in an effort to cut costs. The new contract increases the time to resolve incidents. Which of the following should be the auditor’s GREATEST concern?

Options:

A.

The new contract is not in compliance with IT security policy.

B.

Alternative cost-reduction methods were not considered.

C.

The impact on business processes has not been evaluated.

D.

The corresponding service level agreement (SLA) was not modified.

Question 460

Which of the following is the BEST way to verify the effectiveness of a data restoration process?

Options:

A.

Performing periodic reviews of physical access to backup media

B.

Performing periodic complete data restorations

C.

Validating off ne backups using software utilities

D.

Reviewing and updating data restoration policies annually

Question 461

An organization has outsourced the development of a core application. However, the organization plans to bring the support and future maintenance of the application back in-house. Which of the following findings should be the IS auditor ' s GREATEST concern?

Options:

A.

The cost of outsourcing is lower than in-house development.

B.

The vendor development team is located overseas.

C.

A training plan for business users has not been developed.

D.

The data model is not clearly documented.

Question 462

Which of the following should be done FIRST to ensure the secure configuration of new IT assets in an organization?

Options:

A.

Identify and remediate vulnerabilities before deploying new IT assets.

B.

Define and implement hardening standards.

C.

Scan new IT assets for security vulnerabilities.

D.

Purchase security tools to configure new IT assets.

Question 463

Which of the following system redundancy configurations BEST improves system resiliency and reduces the possibility of a single cause of failure impacting system dependability?

Options:

A.

Active redundancy

B.

Homogeneous redundancy

C.

Diverse redundancy

D.

Passive redundancy

Question 464

An organization has initiated a project to migrate to a new accounts payable system. Which of the following responsibilities is MOST important to assign to the accounts payable business process owner working on this project?

Options:

A.

Identifying functional requirements the new system must meet.

B.

Ensuring the migration project is delivered on time and on budget.

C.

Monitoring resource utilization on the new system.

D.

Ensuring the supporting infrastructure is secure.

Question 465

During the evaluation of controls over a major application development project, the MOST effective use of an IS auditor ' s time would be to review and evaluate:

Options:

A.

application test cases.

B.

acceptance testing.

C.

cost-benefit analysis.

D.

project plans.

Question 466

Which of the following should an IS auditor ensure is classified at the HIGHEST level of sensitivity?

Options:

A.

Server room access history

B.

Emergency change records

C.

IT security incidents

D.

Penetration test results

Question 467

An IS auditor is reviewing the security of a banking system that uses hardware-based encryption. Which of the following is the PRIMARY objective for the adoption of this type of encryption?

Options:

A.

To simplify the key management process.

B.

To provide secure key management.

C.

To improve encryption algorithm efficiency.

D.

To increase encryption key length.

Question 468

Which of the following is the MOST appropriate and effective fire suppression method for an unstaffed computer room?

Options:

A.

Water sprinkler

B.

Fire extinguishers

C.

Carbon dioxide (CO2)

D.

Dry pipe

Question 469

The use of control totals satisfies which of the following control objectives?

Options:

A.

Transaction integrity

B.

Processing integrity

C.

Distribution control

D.

System recoverability

Question 470

Which of the following is the PRIMARY objective of cyber resiliency?

Options:

A.

To resume normal operations after service disruptions

B.

To prevent potential attacks or disruptions in operations

C.

To efficiently and effectively recover from an incident with limited operational impact

D.

To limit the severity of security breaches and maintain continuous operations

Question 471

Which of the following should be the FRST step when developing a data toes prevention (DIP) solution for a large organization?

Options:

A.

Identify approved data workflows across the enterprise.

B.

Conduct a threat analysis against sensitive data usage.

C.

Create the DLP pcJc.es and templates

D.

Conduct a data inventory and classification exercise

Question 472

Which of the following types of environmental equipment will MOST likely be deployed below the floor tiles of a data center?

Options:

A.

Temperature sensors

B.

Humidity sensors

C.

Water sensors

D.

Air pressure sensors

Question 473

A programmer has made unauthorized changes to key fields in a payroll system report. Which of the following control weaknesses would have contributed MOST to this

problem?

Options:

A.

The programmer did not involve the user in testing.

B.

The user requirements were not documented.

C.

Payroll files were not under the control of a librarian.

D.

The programmer has access to the production programs.

Question 474

Which of the following would BEST detect that a distributed denial of service (DDoS) attack is occurring?

Options:

A.

Customer service complaints

B.

Automated monitoring of logs

C.

Server crashes

D.

Penetration testing

Question 475

An organization has established hiring policies and procedures designed specifically to ensure network administrators are well qualified Which type of control is in place?

Options:

A.

Detective

B.

Compensating

C.

Corrective

D.

Directive

Question 476

Which of the following is the MOST important Issue for an IS auditor to consider with regard to Voice-over IP (VoIP) communications?

Options:

A.

Continuity of service

B.

Identity management

C.

Homogeneity of the network

D.

Nonrepudiation

Question 477

The waterfall life cycle model of software development is BEST suited for which of the following situations?

Options:

A.

The protect requirements are wall understood.

B.

The project is subject to time pressures.

C.

The project intends to apply an object-oriented design approach.

D.

The project will involve the use of new technology.

Question 478

When evaluating the design of controls related to network monitoring, which of the following is MOST important for an IS auditor to review?

Options:

A.

Incident monitoring togs

B.

The ISP service level agreement

C.

Reports of network traffic analysis

D.

Network topology diagrams

Question 479

Which of the following is the BEST approach to help organizations address risks associated with shadow IT?

Options:

A.

Implementing policies that prohibit the use of unauthorized systems and solutions

B.

Training employees on information security and conducting routine follow-ups

C.

Providing employees with access to necessary systems and unlimited software licenses

D.

Conducting regular security assessments to identify unauthorized systems and solutions

Page: 1 / 160
Total 1598 questions