Certified Information Systems Auditor Questions and Answers
Which of the following findings should be an IS auditor’s GREATEST concern when reviewing a project to migrate confidential data backups to a cloud-based solution?
Which of the following is the PRIMARY reason to perform a risk assessment?
Which of the following metrics would BEST measure the agility of an organization ' s IT function?
Management receives information indicating a high level of risk associated with potential flooding near the organization ' s data center within the next few years. As a result, a decision has been made to move data center operations to another facility on higher ground. Which approach has been adopted?
Which of the following should an IS auditor expect to see in a network vulnerability assessment?
The MOST important objective of a post-implementation audit is to:
An IS auditor is reviewing the backup procedures in an organization that has high volumes of data with frequent changes to transactions. Which of the following is the BEST backup scheme to recommend given the need for a shorter restoration time in the event of a disruption?
What is the FIRST step when creating a data classification program?
What is the BEST way to reduce the risk of inaccurate or misleading data proliferating through business intelligence systems?
An IS auditor is reviewing how password resets are performed for users working remotely. Which type of documentation should be requested to understand the detailed steps required for this activity?
Which of the following should an IS auditor consider the MOST significant risk associated with a new health records system that replaces a legacy system?
A staff accountant regularly uploads spreadsheets with inventory levels to the organization ' s financial reporting system. The transfers are executed through a customized interface created by an in-house developer. Which of the following is MOST important for the IS auditor to confirm during a review of the interface?
When auditing an organization ' s software acquisition process the BEST way for an IS auditor to understand the software benefits to the organization would be to review the
An IS auditor discovers an option in a database that allows the administrator to directly modify any table. This option is necessary to overcome bugs in the software, but is rarely used. Changes to tables are automatically logged. The IS auditor ' s FIRST action should be to:
Which of the following is the PRIMARY reason for an organization to conduct a formal information security audit?
An IS auditor is reviewing an organization ' s information asset management process. Which of the following would be of GREATEST concern to the auditor?
Which of the following concerns is MOST effectively addressed by implementing an IT framework for alignment between IT and business objectives?
Which of the following is the BEST way for management to ensure the effectiveness of the cybersecurity incident response process?
What is the Most critical finding when reviewing an organization’s information security management?
Which of the following should be an IS auditor ' s GREATEST concern when an international organization intends to roll out a global data privacy policy?
While conducting a follow-up on an asset management audit, the IS auditor finds paid invoices for IT devices not recorded in the organization ' s inventory. Which of the following is the auditor ' s BEST course of action?
Which of the following provides the MOST reliable audit evidence on the validity of transactions in a financial application?
Aligning IT strategy with business strategy PRIMARILY helps an organization to:
An IS auditor determines elevated administrator accounts for servers that are not properly checked out and then back in after each use. Which of the following is the MOST appropriate sampling technique to determine the scope of the problem?
Which of the following is MOST likely to be reduced when implementing optimal risk management strategies?
Which of the following is MOST helpful for understanding an organization’s key driver to modernize application platforms?
Following an IT audit, management has decided to accept the risk highlighted in the audit report. Which of the following would provide the MOST assurance to the IS auditor that management
is adequately balancing the needs of the business with the need to manage risk?
Which of the following represents the HIGHEST level of maturity of an information security program?
Which of the following is MOST helpful to an IS auditor reviewing the alignment of planned IT budget with the organization ' s goals and strategic objectives?
Which of the following is the BEST reason to implement a data retention policy?
Which of the following is MOST important for an IS auditor to determine during the detailed design phase of a system development project?
Which of the following is a challenge in developing a service level agreement (SLA) for network services?
Which of the following methods will BEST reduce the risk associated with the transition to a new system using technologies that are not compatible with the old system?
An IS auditor is reviewing job scheduling software and notes instances of delayed processing time, unexpected job interruption, and out-of-sequence job execution. Which of the following should the auditor examine FIRST to help determine the reasons for these instances?
Which of the following would be MOST effective in detecting the presence of an unauthorized wireless access point on an internal network?
An IS auditor noted a recent production incident in which a teller transaction system incorrectly charged fees to customers due to a defect from a recent release. Which of the following should be the auditor ' s NEXT step?
Which of the following is the BEST control to mitigate the malware risk associated with an instant messaging (IM) system?
Which of the following would provide the BEST evidence of an IT strategy corrections effectiveness?
In which of the following sampling methods is the entire sample considered to be irregular if a single error is found?
In reviewing the IT strategic plan, the IS auditor should consider whether it identifies the:
Which of the following is the MOST effective method of destroying sensitive data stored on electronic media?
which of the following is a core functionality of a configuration and release management system?
Which of the following is MOST important to include when developing a business continuity plan (BCP)?
Which of the following would be of MOST concern for an IS auditor evaluating the design of an organization ' s incident management processes?
During a follow-up audit, an IS auditor finds that some critical recommendations have the IS auditor ' s BEST course of action?
Which of the following is MOST important to ensure that electronic evidence collected during a forensic investigation will be admissible in future legal proceedings?
Which of the following provides the BEST evidence of the validity and integrity of logs in an organization ' s security information and event management (SIEM) system?
When reviewing whether IT investments are meeting business objectives, which of the following evaluations would be MOST useful?
When reviewing the disaster recovery strategy, IT management identified an application that requires a short recovery point objective (RPO). Which of the following data restoration strategies would BEST enable the organization to meet this objective?
An internal audit team is deciding whether to use an audit management application hosted by a third party in a different country.
What should be the MOST important consideration related to the uploading of payroll audit documentation in the hosted
application?
Which of the following is the MOST effective method to identify new errors introduced as a result of program changes?
An IS auditor notes that the previous year ' s disaster recovery test was not completed within the scheduled time frame due to insufficient hardware allocated by a third-party vendor. Which of the following provides the BEST evidence that adequate resources are now allocated to successfully recover the systems?
An organization ' s networking team wants to route data between two virtual local area networks (VLANs). Which type of device is the BEST recommendation for installation of the VLANs?
Which of the following measures BEST mitigates the risk of data exfiltration during a cyberattack?
Which of the following is MOST important to consider when defining disaster recovery strategies?
Which of the following should an IS auditor recommend as a PRIMARY area of focus when an organization decides to outsource technical support for its external customers?
Which of the following MOST effectively manages frequent program file changes where simultaneous code edits are used?
To develop meaningful recommendations ' or findings, which of the following is MOST important ' or an IS auditor to determine and understand?
Which of the following is an audit reviewer ' s PRIMARY role with regard to evidence?
Which of the following is the MOST important area of focus for an IS auditor when developing a risk-based audit strategy?
Which of the following is the MOST important reason for an IS auditor to examine the results of a post-incident review performed after a security incident?
During an incident management audit, an IS auditor finds that several similar incidents were logged during the audit period. Which of the following is the auditor ' s MOST important course of action?
An IS auditor would MOST likely recommend that IT management use a balanced scorecard to:
An IS auditor notes that several employees are spending an excessive amount of time using social media sites for personal reasons. Which of the following should the auditor recommend be performed FIRST?
Which of the following is the MAJOR advantage of automating internal controls?
UESTION NO: 210
An accounting department uses a spreadsheet to calculate sensitive financial transactions. Which of the following is the MOST important control for maintaining the security of data in the spreadsheet?
Which of the following is an IS auditor’s BEST approach when low-risk anomalies have been identified?
Which of the following is the BEST way to ensure that business continuity plans (BCPs) will work effectively in the event of a major disaster?
In an environment where data virtualization is used, which of the following provides the BEST disaster recovery solution?
Which of the following is the MOST effective way to evaluate the physical security of a data center?
An IS auditor is reviewing a contract for the outsourcing of IT facilities. If missing, which of the following should present the GREATEST concern to the auditor?
Which of the following is a social engineering attack method?
Which of the following will be the MOST effective method to verify that a service vendor keeps control levels as required by the client?
The GREATEST concern for an IS auditor reviewing vulnerability assessments by the auditee would be if the assessments are:
An IS auditor has been tasked with analyzing an organization ' s capital expenditures against its repair and maintenance costs. Which of the following is the BEST reason to use a data analytics tool for this purpose?
An IS auditor is reviewing the system development practices of an organization that is about to move from a Waterfall to an Agile approach. Which of the following is MOST important for the auditor to focus on as a result of this move?
Which of the following is the PRIMARY objective of implementing privacy-related controls within an organization?
Which of the following should be an IS auditor’s PRIMARY focus when performing a post-implementation review for a critical IT project?
Which of the following observations should be of GREATEST concern to an IS auditor reviewing an organization ' s enterprise architecture (EA) program?
Which of the following would MOST effectively help to reduce the number of repealed incidents in an organization?
During which phase of the software development life cycle is it BEST to initiate the discussion of application controls?
An IS auditor observes that a large number of departed employees have not been removed from the accounts payable system. Which of the following is MOST important to determine in order to assess the risk1?
An IS auditor is reviewing an organization ' s incident management processes and procedures. Which of the following observations should be the auditor ' s GREATEST concern?
An external audit firm was engaged to perform a validation and verification review for a systems implementation project. The IS auditor identifies that regression testing is not part of the project plan and was not performed by the systems implementation team. According to the team, the parallel testing being performed is sufficient, making regression testing unnecessary. What should be the auditor’s NEXT step?
Which of the following is the MOST efficient solution for a multi-location healthcare organization that wants to be able to access patient data wherever patients present themselves
for care?
Which of the following controls is BEST implemented through system configuration?
Network user accounts for temporary workers expire after 90 days.
Application user access is reviewed every 180 days for appropriateness.
Financial data in key reports is traced to source systems for completeness and accuracy.
Which of the following technologies has the SMALLEST maximum range for data transmission between devices?
Which of the following would be of GREATEST concern to an IS auditor reviewing an IT strategy document?
Which of the following BEST enables alignment of IT with business objectives?
Which of the following provides the BEST evidence that system requirements are met when evaluating a project before implementation?
Which of the following is the BEST control to mitigate attacks that redirect internet traffic to an unauthorized website?
During an information security review, an IS auditor learns an organizational policy requires all employ-ees to attend information security training during the first week of each new year. What is
the auditor ' s BEST recommendation to ensure employees hired after January receive adequate guid-ance regarding security awareness?
Management has requested a post-implementation review of a newly implemented purchasing package to determine the extent that business requirements are being met. Which of the following
is MOST likely to be assessed?
Which of the following provides the BEST assurance that vendor-supported software remains up to date?
The PRIMARY reason to assign data ownership for protection of data is to establish:
Which type of testing is used to identify security vulnerabilities in source code in the development environment?
Who is accountable for an organization ' s enterprise risk management (ERM) program?
An IS auditor is conducting a post-implementation review of an enterprise resource planning (ERP) system. End users indicated concerns with the accuracy of critical automatic calculations made by the system. The auditor ' s FIRST course of action should be to:
Which of the following is the MOST significant risk when an application uses individual end-user accounts to access the underlying database?
Which of the following BEST enables an organization to improve the effectiveness of its incident response team?
An organization that processes credit card information employs a remote workforce. Which of the following is the MOST effective way to mitigate risk associated with data exfiltration?
A small business unit is implementing a control self-assessment (CSA) program and leveraging the internal
audit function to test its internal controls annually. Which of the following is the MOST significant benefit of
this approach?
The waterfall life cycle model of software development is BEST suited for which of the following situations?
An organization has decided to purchase a web-based email service from a third-party vendor and eliminate its own email server infrastructure. What type of cloud computing environment would BEST meet the organization ' s objective?
A new regulation in one country of a global organization has recently prohibited cross-border transfer of personal data. An IS auditor has been asked to determine the organization ' s level of exposure In the affected country. Which of the following would be MOST helpful in making this assessment?
Which of the following is an IS auditor ' s BEST recommendation to protect an organization from attacks when its file server needs to be accessible to external users?
An incident response team has been notified of a virus outbreak in a network subnet. Which of the following should be the NEXT step?
During an audit of payment services of a branch based in a foreign country, a large global bank ' s audit team identifies an opportunity to use data analytics techniques to identify abnormal payments. Which of the following is the team ' s MOST important course of action?
Which of the following BEST helps data loss prevention (DLP) tools detect movement of sensitive data m transit?
A bank wants to outsource a system to a cloud provider residing in another country. Which of the following would be the MOST appropriate IS audit recommendation?
To ensure confidentiality through the use of asymmetric encryption, a message is encrypted with which of the following?
Which of the following is the BEST method to prevent wire transfer fraud by bank employees?
An IS auditor is reviewing a bank’s service level agreement (SLA) with a third-party provider that hosts the bank’s secondary data center. Which of the following findings should be of GREATEST concern to the auditor?
Which of the following is the PRIMARY purpose of a rollback plan for a system change?
A small organization is experiencing rapid growth and plans to create a new information security policy. Which of the following is MOST relevant to creating the policy?
Which of the following is the MOST important course of action to ensure a cloud access security broker (CASB) effectively detects and responds to threats?
During a physical security audit, an IS auditor was provided a proximity badge that granted access to three specific floors in a corporate office building. Which of the following issues should be of MOST concern?
Which of the following is the BEST approach for determining the overall IT risk appetite of an organization when business units use different methods formanaging IT risks?
Which of the following is MOST important to include in a feasibility study when developing a business case for an IT investment?
An externally facing system containing sensitive data is configured such that users have either read-only or administrator rights. Most users of the system have administrator access. Which of the following is the GREATEST risk associated with this situation?
Which of the following staff should an IS auditor interview FIRST to obtain a general overview of the various technologies used across different programs?
An organization is planning an acquisition and has engaged an IS auditor lo evaluate the IT governance framework of the target company. Which of the following would be MOST helpful In determining the effectiveness of the framework?
An IS auditor is evaluating the risk associated with moving from one database management system (DBMS) to another. Which of the following would be MOST helpful to ensure the integrity of the system throughout the change?
Which of the following is the BEST source of information for examining the classification of new data?
An IS auditor finds that irregularities have occurred and that auditee management has chosen to ignore them. If reporting to external authorities is required which of the following is the BEST action for the IS auditor to take?
Which of the following is the PRIMARY reason for an IS audit manager to review the work performed by a senior IS auditor prior to presentation of a report?
A white box testing method is applicable with which of the following testing processes?
Which of the following should be restricted from a network administrator ' s privileges in an adequately segregated IT environment?
An IS auditor has traced the source of a transaction fraud to the desktop system of an e-business staff member who is on leave. Which of the following is the BEST way for the auditor to ensure the success of the investigation?
How does a continuous integration/continuous development (CI/CD) process help to reduce software failure risk?
An IS auditor is verifying the adequacy of an organization ' s internal controls and is concerned about potential circumvention of regulations. Which of the following is the BEST sampling method to use?
Which of the following would be of GREATEST concern to an IS auditor evaluating an organization’s change management process?
An information systems security officer ' s PRIMARY responsibility for business process applications is to:
Which of the following issues associated with a data center ' s closed-circuit television (CCTV) surveillance cameras should be of MOST concern to an IS auditor?
The BEST way to determine whether programmers have permission to alter data in the production environment is by reviewing:
Which of the following is the BEST methodology to use for estimating the complexity of developing a large business application?
An IS auditor is reviewing the disaster recovery plan (DRP) of an organization with offices across multiple regions. Which of the following should be the auditor ' s PRIMARY focus?
An IS auditor discovers that backups of critical systems are not being performed in accordance with the recovery point objective (RPO) established in the business continuity plan (BCP). What should the auditor do NEXT?
Which of the following documents should define roles and responsibilities within an IT audit organization?
Which of the following is the MOST efficient way to identify segregation of duties violations in a new system?
The PRIMARY purpose of an incident response plan is to:
Effective separation of duties in an online environment can BEST be achieved by utilizing:
Which of the following would BEST demonstrate that an effective disaster recovery plan (DRP) is in place?
Which of the following is the GREATEST risk when relying on reports generated by end-user computing (EUC)?
Which of the following is the BEST way to address segregation of duties issues in an organization with budget constraints?
Which of the following should be done FIRST following an incident that has caused internal servers to be inaccessible, disrupting normal business operations?
Which of the following should an organization do FIRST when an employee is terminated for fraudulent activity?
An organization with many desktop PCs is considering moving to a thin client architecture. Which of the following is the MAJOR advantage?
An IS audit manager is preparing the staffing plan for an audit engagement of a cloud service provider. What should be the manager ' s PRIMARY concern when being made aware that a new
auditor in the department previously worked for this provider?
An IS audit team is evaluating documentation of the most recent application user access review. It is determined that the user list was not system generated. Which of the following should be of
MOST concern?
Which of the following backup methods is MOST appropriate when storage space is limited?
During the audit of an enterprise resource planning (ERP) system, an IS auditor found an applicationpatch was applied to the production environment. It is MOST
important for the IS auditor to verify approval from the:
A contract for outsourcing IS functions should always include:
Which of the following should be a concern to an IS auditor reviewing an organization’s use of a major cloud provider for Infrastructure as a Service (IaaS)?
In an IT organization where many responsibilities are shared which of the following is the BEST control for detecting unauthorized data changes?
Which of the following is the MOST important consideration to facilitate prosecution of a perpetrator after a cybercrime?
An emergency power-off switch should:
An IS auditor finds the log management system is overwhelmed with false positive alerts. The auditor ' s BEST recommendation would be to:
Which of the following is the BEST source of information tor an IS auditor to use when determining whether an organization ' s information security policy is adequate?
An organization is enhancing the security of a client-facing web application following a proposal to acquire personal information for a business purpose. Which of the following is MOST important to review before implementing this initiative?
An organization is implementing a data loss prevention (DLP) system in response to a new regulatory requirement Reviewing. which of the following would be MOST helpful in evaluating the system ' s design?
In an area susceptible to unexpected increases in electrical power, which of the following would MOST effectively protect the system?
An IS auditor learns that a business owner violated the organization ' s security policy by creating a web page with access to production data. The auditor ' s NEXT step should be to:
An organization plans to receive an automated data feed into its enterprise data warehouse from a third-party service provider. Which of the following would be the BEST way to prevent accepting bad data?
Which of the following BEST guards against the risk of attack by hackers?
Which task should an IS auditor complete FIRST during the preliminary planning phase of a database security review?
The PRIMARY purpose of a vulnerability assessment in a cybersecurity program is to:
Which of the following is the MOST important consideration for a contingency facility?
To improve efficiency, an organization has decided not to encrypt log files and plans to store the log data in native device formats. Which of the following is the GREATEST risk to the organization?
Which of the following BEST helps to determine an organization’s data availability approach in the event of a disaster?
When reviewing an organization’s enterprise architecture (EA), which of the following is an IS auditor MOST likely to find within the EA documentation?
Which of the following is the MOST important consideration for patching mission critical business application servers against known vulnerabilities?
Which of the following should an IS auditor use when verifying a three-way match has occurred in an enterprise resource planning (ERR) system?
The PRIMARY objective of a privacy protection policy is to increase awareness of:
One advantage of monetary unit sampling is the fact that
An organization ' s strategy to source certain IT functions from a Software as a Service (SaaS) provider should be approved by the:
How would an IS auditor BEST determine the effectiveness of a security awareness program?
Which of the following is the PRIMARY benefit of performing periodic maturity model assessments?
An IS auditor found that a company executive is encouraging employee use of social networking sites for business purposes. Which of the following recommendations would BEST help to reduce the risk of data leakage?
What is BEST for an IS auditor to review when assessing the effectiveness of changes recently made to processes and tools related to an organization ' s business continuity plan (BCP)?
Which of the following MOST effectively enables consistency across high-volume software changes ' ?
Which of the following is the BEST approach for determining the overall IT risk appetite of an organization when business units use different methods for managing IT risks?
Which of the following should be the PRIMARY consideration when incorporating user training and awareness into a data loss prevention (DLP) strategy?
During an operational audit on the procurement department, the audit team encounters a key system that uses an artificial intelligence (Al) algorithm. The audit team does not have the necessary knowledge to proceed with the audit. Which of the following is the BEST way to handle this situation?
Which of the following is the MOST important factor when an organization is developing information security policies and procedures?
Which of the following network communication protocols is used by network devices such as routers to send error messages and operational information indicating success or failure when communicating with another IP address?
An organization allows programmers to change production systems in emergency situations without seeking prior approval. Which of the following controls should an IS auditor consider MOST
important?
Cross-site scripting (XSS) attacks are BEST prevented through:
An IS auditor has been asked to perform a post-implementation review of a newly developed system. When reviewing the testing phase results, the auditor observed that separate modules of the system tested correctly in the user acceptance testing (UAT) phase, but some features did not work as expected when moved to production. Which of the following was MOST likely omitted prior to implementation?
Which of the following should an IS auditor be MOST concerned with when reviewing the IT asset disposal process?
An IS auditor is evaluating an enterprise resource planning (ERP) migration from local systems to the cloud. Who should be responsible for the data
classification in this project?
An IS auditor finds that firewalls are outdated and not supported by vendors. Which of the following should be the auditor ' s NEXT course of action?
Which of the following responses to risk associated with segregation of duties would incur the LOWEST initial cost?
Which of the following is the BEST recommendation to include in an organization ' s bring your own device (BYOD)
policy to help prevent data leakage?
Which of the following is the PRIMARY reason to follow a configuration management process to maintain application?
Which of the following controls is MOST important for ensuring the integrity of system interfaces?
Which of the following BEST mitigates the risk of SQL injection attacks against applications exposed to the internet?
An IS auditor finds that capacity management for a key system is being performed by IT with no input from the business The auditor ' s PRIMARY concern would be:
Which of the following key performance indicators (KPIs) provides stakeholders with the MOST useful information about whether information security risk is being managed?
Which of the following applications should an IS auditor consider to be the HIGHEST priority when reviewing disaster recovery planning (DRP) tests for an commerce company?
Which of the following is the MOST effective way to maintain network integrity when using mobile devices?
Which of the following is BEST used for detailed testing of a business application ' s data and configuration files?
A new system is being developed externally for an organization. Which of the following is the MOST important requirement to include in the vendor contract to ensure service continuity?
An IS auditor is reviewing an IT project and finds that an earned value analysis (EVA) is not regularly performed as part of project status reporting. Which of the following is the GREATEST risk resulting from this situation?
Due to a recent business divestiture, an organization has limited IT resources to deliver critical projects Reviewing the IT staffing plan against which of the following would BEST guide IT management when estimating resource requirements for future projects?
When an organization conducts business process improvements, the IS auditor should be MOST concerned with the:
Which of the following is the PRIMARY reason for using a digital signature?
An IS auditor reviewing a job scheduling tool notices performance and reliability problems. Which of the following is MOST likely affecting the tool?
Which of the following is MOST important for an IS auditor to consider when performing the risk assessment poor to an audit engagement?
An IS auditor follows up on a recent security incident and finds the incident response was not adequate. Which of the following findings should be considered MOST critical?
Which of the following MUST be completed as part of the annual audit planning process?
During a database security audit, an IS auditor is reviewing the process used to input data. Which of the following is the MOST significant risk area for the auditor to focus on?
An organization is considering allowing users to connect personal devices to the corporate network. Which of the following should be done FIRST?
Which of the following features of a library control software package would protect against unauthorized updating of source code?
Which of the following is an organization ' s BEST defense against malware?
Which of the following should be of GREATEST concern to an IS auditor when using data analytics?
Which of the following is the GREATEST benefit of an effective data classification process?
Which of the following is MOST important to determine when conducting an audit Of an organization ' s data privacy practices?
Which of the following provides the BEST evidence that all elements of a business continuity plan (BCP) are operating effectively?
Which of the following is an example of a preventive control for physical access?
Which of the following is MOST important to ensure when planning a black-box penetration test?
A system development project is experiencing delays due to ongoing staff shortages. Which of the following strategies would provide the GREATEST assurance of system quality at implementation?
An organization used robotic process automation (RPA) technology to develop software bots that extract data from various sources for input into a legacy financial application. Which of the following should be of GREATEST concern to an IS auditor when reviewing the software bot job scheduling and production process automation?
Which of the following should an IS auditor review when evaluating information systems governance for a large organization?
The PRIMARY role of an IS auditor in the remediation of problems found during an audit engagement is to:
Which of the following will provide the GREATEST assurance to IT management that a quality management system (QMS) is effective?
Which of the following is the PRIMARY basis on which audit objectives are established?
Which of the following is the BEST way to identify key areas for a risk-based audit plan?
When an intrusion into an organization ' s network is detected, which of the following should be done FIRST?
A new regulation requires organizations to report significant security incidents to the regulator within 24 hours of identification. Which of the following is the IS auditor ' s BEST recommendation to facilitate compliance with the regulation?
Which of the following is the PRIMARY role of the IS auditor m an organization ' s information classification process?
During an audit of a reciprocal disaster recovery agreement between two companies, the IS auditor would be MOST concerned with the:
A hearth care organization utilizes Internet of Things (loT) devices to improve patient outcomes through real-time patient monitoring and advanced diagnostics. Which of the following would BEST assist in isolating these devices from corporate network traffic?
When auditing the feasibility study of a system development project, the IS auditor should:
A small IT department has embraced DevOps, which allows members of this group to deploy code to production and maintain some development access to automate releases. Which of the following is the MOST effective control?
In which phase of penetration testing would host detection and domain name system (DNS) interrogation be performed?
A web application is developed in-house by an organization. Which of the following would provide the BEST evidence to an IS auditor that the application is secure from external attack?
An organization has shifted from a bottom-up approach to a top-down approach in the development of IT policies. This should result in:
Which of the following would be the GREATEST concern during a financial statement audit?
A small organization has cut costs by reducing IT positions and consolidating a large number of critical responsibilities into the role of its most senior IT engineer. Which of the following is the PRIMARY risk in this situation?
Which of the following is the PRIMARY function of a data loss prevention (DLP) policy when implemented in an organization ' s DLP solution?
Who should be the FIRST to evaluate an audit report prior to issuing it to the project steering committee?
Which of the following is the BEST way for an organization to mitigate the risk associated with third-party application performance?
An IS auditor is reviewing processes for importing market price data from external data providers. Which of the following findings should the auditor consider MOST critical?
Management is concerned about sensitive information being intentionally or unintentionally emailed as attachments outside the organization by employees. What is the MOST important task before implementing any associated email controls?
Which of the following must be in place before an IS auditor initiates audit follow-up activities?
An incorrect version of the source code was amended by a development team. This MOST likely indicates a weakness in:
An organization conducted an exercise to test the security awareness level of users by sending an email offering a cash reward 10 those who click on a link embedded in the body of the email. Which of the following metrics BEST indicates the effectiveness of awareness training?
Which of the following will MOST likely compromise the control provided By a digital signature created using RSA encryption?
Which of the following is the BEST control to prevent the transfer of files to external parties through instant messaging (IM) applications?
An organization has recently acquired and implemented intelligent-agent software for granting loans to customers. During the post-implementation review, which of the following is the MOST important procedure for the IS auditor to perform?
Which of the following should be an IS auditor ' s GREATEST concern when evaluating an organization ' s ability to recover from system failures?
An IS auditor decides to review a data inventory list captured directly from a system instead of relying on an interview with the system owner. Which of the following provides the BEST justification for the auditor ' s decision?
An internal audit department recently established a quality assurance (QA) program. Which of the following activities Is MOST important to include as part of the QA program requirements?
Which of the following is the BEST method to delete sensitive information from storage media that will be reused?
Which of the following is the GREATEST risk related to the use of virtualized environments?
Which of the following is the PRIMARY reason for an organization to implement a configuration management database (CMDB)?
A global bank plans to use a cloud provider for backup of customer financial data. Which of the following should be the PRIMARY focus of this project?
An organization ' s information security policies should be developed PRIMARILY on the basis of:
When auditing the adequacy of a cooling system for a data center, which of the following is MOST important for the IS auditor to review?
A global company has been using a publicly available AI tool to obtain information about global laws and regulations that could impact the business. Which of the following should be of MOST concern to an IS auditor?
An IS auditor is reviewing an industrial control system (ICS) that uses older unsupported technology in the scope of an upcoming audit. What should the auditor consider the MOST significant concern?
An external attacker spoofing an internal Internet Protocol (IP) address can BEST be detected by which of the following?
If a recent release of a program has to be backed out of production, the corresponding changes within the delta version of the code should be:
Which of the following is the BEST detective control for a job scheduling process involving data transmission?
Which of the following is the PRIMARY advantage of using virtualization technology for corporate applications?
An IS auditor finds that while an organization ' s IT strategy is heavily focused on research and development, the majority of protects n the IT portfolio focus on operations and maintenance. Which of the Mowing is the BEST recommendation?
An IS auditor has identified deficiencies within the organization ' s software development life cycle policies. Which of the following should be done NEXT?
During a review of an organization ' s IT capacity management process, an IS auditor should be MOST concerned if capacity planning:
A startup organization wants to develop a data loss prevention (DLP) program. The FIRST step should be to implement:
Which of the following poses the GREATEST risk to the use of active RFID tags?
Which of the following responsibilities of an organization ' s quality assurance (QA) function should raise concern for an IS auditor?
Which of the following is MOST useful for determining whether the goals of IT are aligned with the organization ' s goals?
A network analyst is monitoring the network after hours and detects activity that appears to be a brute-force attempt to compromise a critical server. After reviewing the alerts to ensure their accuracy, what should be done NEXT?
Which of the following is the BEST metric to measure the quality of software developed in an organization?
Which of the following is the MOST important consideration when establishing vulnerability scanning on critical IT infrastructure?
Which of the following BEST indicates a need to review an organization ' s information security policy?
Which of the following controls is MOST crucial to ensure an organization will be able to recover its data from backup media in the event of a disaster?
An external IS auditor is reviewing the continuous monitoring system for a large bank and notes several potential issues. Which of the following would present the GREATEST concern regarding the reliability of the monitoring system?
Which of the following is the BEST control lo mitigate attacks that redirect Internet traffic to an unauthorized website?
When planning an audit, it is acceptable for an IS auditor to rely on a third-party provider’s external audit report on service level management when the
After areas have been appropriately scoped, what is the IS auditor ' s NEXT step in the selection for sampling?
When designing a data analytics process, which of the following should be the stakeholder ' s role in automating data extraction and validation?
During an audit, the IS auditor finds that in many cases excessive rights were not removed from a system. Which of the following is the auditor ' s BEST recommendation?
Which of the following BEST describes an audit risk?
Which of the following is the PRIMARY reason for an IS auditor to conduct post-implementation reviews?
Which of the following BEST indicates the effectiveness of an organization ' s risk management program?
An IS auditor is auditing the operating effectiveness of weekly user access reviews. Of the five weekly reviews sampled, one has not been signed or dated. What is the MAIN reason to note this observation as a finding?
An IS auditor is asked to review an organization ' s technology relationships, interfaces, and data. Which of the following enterprise architecture (EA) areas is MOST appropriate this review? (Choose Correct answer and give explanation from CISA Certification - Information Systems Auditor official book)
Which of the following analytical methods would be MOST useful when trying to identify groups with similar behavior or characteristics in a large population?
IT governance should be driven by:
An IS auditor has found that an organization is unable to add new servers on demand in a cost-efficient manner. Which of the following is the auditor ' s BEST recommendation?
An IS auditor is performing a follow-up audit for findings identified in an organization ' s user provisioning process Which of the following is the MOST appropriate population to sample from when testing for remediation?
An IS auditor is conducting an IT governance audit and notices many initiatives are managed informally by isolated project managers. Which of the following recommendations would have the GREATEST impact on improving the maturity of the IT team?
Which of the following would be of GREATEST concern to an IS auditor reviewing the feasibility study for a new application system?
Which of the following is a social engineering attack method?
Which of the following is the BEST method to safeguard data on an organization ' s laptop computers?
Which of the following would be of GREATEST concern when reviewing an organization ' s security information and event management (SIEM) solution?
Which of the following observations would an IS auditor consider the GREATEST risk when conducting an audit of a virtual server farm tor potential software vulnerabilities?
An IS auditor should be MOST concerned if which of the following fire suppression systems is utilized to protect an asset storage closet?
Which of the following technologies is BEST suited to fulfill a business requirement for nonrepudiation of business-to-business transactions with external parties without the need for a mutually trusted entity?
Which of the following management decisions presents the GREATEST risk associated with data leakage?
Which of the following is the MOST significant impact to an organization that does not use an IT governance framework?
Which of the following should be the IS auditor ' s PRIMARY focus, when evaluating an organization ' s offsite storage facility?
An organization outsourced its IS functions to meet its responsibility for disaster recovery, the organization should:
Which of the following is the BEST approach to validate whether a streaming site can continue to provide service during a period of live streaming with an anticipated high volume of viewers?
Which of the following IT service management activities is MOST likely to help with identifying the root cause of repeated instances of network latency?
Which of the following provides the MOST comprehensive information about inherent risk within an organization?
An IS auditor is reviewing an artificial intelligence (Al) and expert system application. The system has produced several critical errors with severe impact. Which of the following should the IS auditor do NEXT to understand the cause of the errors?
Following a security breach in which a hacker exploited a well-known vulnerability in the domain controller, an IS audit has been asked to conduct a control assessment. the auditor ' s BEST course of action would be to determine if:
Which of the following is the PRIMARY benefit of effective implementation of appropriate data classification?
An organization has purchased a new cloud-based application from a vendor. Which of the following should be the FIRST consideration when implementing the system?
Who is responsible for defining data access permissions?
Which of the following should be the MOST important consideration when conducting a review of IT portfolio management?
Which of the following parameters reflects the risk threshold for an organization experiencing a service disruption?
Which of the following is the BEST indicator for measuring performance of IT help desk function?
Which of the following is MOST appropriate to prevent unauthorized retrieval of confidential information stored in a business application system?
Which of the following is the MOST important consideration when relying on the work of the prior auditor?
During an organization ' s implementation of a data loss prevention (DLP) solution, which of the following activities should be completed FIRST?
What would be an IS auditor ' s BEST course of action when an auditee is unable to close all audit recommendations by the time of the follow-up audit?
In a large organization, IT deadlines on important projects have been missed because IT resources are not prioritized properly. Which of the following is the BEST recommendation to address this problem?
Which of the following is the GREATEST risk of project dashboards being set without sufficiently defined criteria?
Which of the following is the MOST appropriate control to ensure integrity of online orders?
An organization is shifting to a remote workforce In preparation the IT department is performing stress and capacity testing of remote access infrastructure and systems What type of control is being implemented?
An organization ' s enterprise architecture (EA) department decides to change a legacy system ' s components while maintaining its original functionality. Which of the following is MOST important for an IS auditor to understand when reviewing this decision?
Email required for business purposes is being stored on employees ' personal devices.
Which of the following is an IS auditor ' s BEST recommendation?
Providing security certification for a new system should include which of the following prior to the system ' s implementation?
in a post-implantation Nation review of a recently purchased system it is MOST important for the iS auditor to determine whether the:
What is the purpose of hashing a document?
Which of the following should be done FIRST when planning to conduct internal and external penetration testing for a client?
Which of the following fire suppression systems needs to be combined with an automatic switch to shut down the electricity supply in the event of activation?
What is the PRIMARY benefit of using one-time passwords?
Which of the following BEST minimizes performance degradation of servers used to authenticate users of an e-commerce website?
An IS auditor is evaluating the progress of a web-based customer service application development project. Which of the following would be MOST helpful for this evaluation?
An IS auditor finds a segregation of duties issue in an enterprise resource planning (ERP) system. Which of the following is the BEST way to prevent the misconfiguration from recurring?
Which of the following provides the MOST reliable method of preventing unauthonzed logon?
As part of business continuity planning, which of the following is MOST important to assess when conducting a business impact analysis (B1A)?
An organization is disposing of removable onsite media which contains sensitive information. Which of the following is the MOST effective method to prevent disclosure of sensitive data?
A new system development project is running late against a critical implementation deadline. Which of the following is the MOST important activity?
A manager Identifies active privileged accounts belonging to staff who have left the organization. Which of the following is the threat actor In this scenario?
The PRIMARY benefit of automating application testing is to:
An IS auditor is planning a review of an organizations cybersecurity incident response maturity Which of the following methodologies would provide the MOST reliable conclusions?
Which of the following controls is MOST crucial to ensure an organization will be able to recover its data from backup media in the event of a disaster?
Backup procedures for an organization ' s critical data are considered to be which type of control?
During an audit of a financial application, it was determined that many terminated users ' accounts were not disabled. Which of the following should be the IS auditor ' s NEXT step?
Which of the following should be of GREATEST concern to an IS auditor reviewing a terminated employee’s network access?
Which of the following is the MOST effective way for an organization to project against data loss?
Which of the following system attack methods is executed by entering malicious code into the search box of a vulnerable website, causing the server to reveal restricted information?
Which of the following application input controls would MOST likely detect data input errors in the customer account number field during the processing of an accounts receivable transaction?
While auditing a small organization ' s data classification processes and procedures, an IS auditor noticed that data is often classified at the incorrect level. What is the MOST effective way for the organization to improve this situation?
During a pre-deployment assessment, what is the BEST indication that a business case will lead to the achievement of business objectives?
Which of the following methods BEST enforces data leakage prevention in a multi-tenant cloud environment?
An IS auditor wants to gain a better understanding of an organization’s selected IT operating system software. Which of the following would be MOST helpful to review?
A steering committee established to oversee an organization’s digital transformation program is MOST likely to be involved with which of the following activities?
Which of the following is a detective control?
Which of the following BEST facilitates the legal process in the event of an incident?
Which of the following is MOST helpful for measuring benefits realization for a new system?
An IS auditor is reviewing an organization ' s risk management program. Which of the following should be the PRIMARY driver of the enterprise IT risk appetite?
An organization is modernizing its technology policy framework to demonstrate compliance with external industry standards. Which of the following would be MOST useful to an IS auditor for validating the outcome?
The MOST effective way to reduce sampling risk is to increase:
During a follow-up audit, an IS auditor finds that senior management has implemented a different remediation action plan than what was previously agreed upon. Which of the following is the auditor ' s BEST course of action?
Which of the following is the BEST indication of effective IT investment management?
Which of the following should be of GREATEST concern to an IS auditor who is assessing an organization ' s configuration and release management process?
Which of the following activities would allow an IS auditor to maintain independence while facilitating a control sell-assessment (CSA)?
An organization is ready to implement a new IT solution consisting of multiple modules. The last module updates the processed data into the database. Which of the following findings should be of MOST concern to the IS auditor?
Which of the following tests is MOST likely to detect an error in one subroutine resulting from a recent change in another subroutine?
Malicious program code was found in an application and corrected prior to release into production. After the release, the same issue was reported. Which of the following is the IS auditor ' s BEST recommendation?
Which of the following should be the GREATEST concern for an IS auditor reviewing recent disaster recovery operations?
What is the GREATEST concern for an IS auditor reviewing contracts for licensed software that executes a critical business process?
Which of the following is the MOST efficient control to reduce the risk associated with a systems administrator having network administrator responsibilities?
Which of the following should be the IS auditor ' s PRIMARY focus when evaluating an organizations offsite storage facility?
Which of the following MUST be completed as part of the annual audit planning process?
Which of the following would be the MOST significant finding when reviewing a data backup process?
Which of the following is the BEST indication that an information security awareness program is effective?
Which of the following is the MOST important area of focus for an IS auditor assessing the management of cryptographic keys in a public key infrastructure (PKI)?
Which of the following should be the PRIMARY basis for prioritizing follow-up audits?
Which of the following is the GREATEST advantage of maintaining an internal IS audit function within an organization?
Which of the following is an effective way to ensure the integrity of file transfers in a peer-to-peer (P2P) computing environment?
An IS auditor has been asked to audit the proposed acquisition of new computer hardware. The auditor’s PRIMARY concern Is that:
When an IS auditor needs to confirm that an organization is encrypting sensitive information at a database level, which of the following would provide the BEST assurance?
Which of the following is the PRIMARY benefit of operational log management?
Which of the following should be performed FIRST before key performance indicators (KPIs) can be implemented?
Which of the following should be used to evaluate an IT development project before an investment is committed?
An organization is implementing a new data loss prevention (DLP) tool. Which of the following will BEST enable the organization to reduce false positive alerts?
A data breach has occurred due lo malware. Which of the following should be the FIRST course of action?
The charging method that effectively encourages the MOST efficient use of IS resources is:
Which of the following BEST enables the timely identification of risk exposure?
During the planning phase of a data loss prevention (DLP) audit, management expresses a concern about mobile computing. Which of the following should the IS auditor identity as the associated risk?
Which of the following is the PRIMARY purpose of batch processing monitoring?
Which of the following is the PRIMARY benefit of monitoring IT operational logs?
An IS auditor is reviewing an organization ' s incident management processes. Which of the following observations should be the auditor ' s GREATEST concern?
External audits have identified recurring exceptions in the user termination process, despite similar internal audits having reported no exceptions in the past. Which of the following is the IS auditor ' s BEST course of action to improve the internal audit process in the future?
Which of the following is MOST important to consider when evaluating a reciprocal arrangement as a recovery strategy?
How does the emergence of quantum computing impact traditional data encryption methods?
Which of the following should be of GREATEST concern to an IS auditor when auditing an organization ' s IT strategy development process?
Which of the following BEST supports an organization ' s objective of restricting the use of removable storage devices by users?
Which of the following applications has the MOST inherent risk and should be prioritized during audit planning?
What should be the PRIMARY basis for selecting which IS audits to perform in the coming year?
Which of the following is the GREATEST concern associated with IS risk-based auditing when audit resources are limited?
Which of the following would BEST indicate the effectiveness of a security awareness training program?
Which of the following statements appearing in an organization ' s acceptable use policy BEST demonstrates alignment with data classification standards related to the protection of information assets?
Which of the following is the BEST indication of effective governance over IT infrastructure?
An IS auditor finds an IT manager recently changed a Software as a Service (SaaS) provider contract in an effort to cut costs. The new contract increases the time to resolve incidents. Which of the following should be the auditor’s GREATEST concern?
Which of the following is MOST helpful to an IS auditor when assessing the effectiveness of controls?
Which of the following is the BEST metric to measure the alignment of IT and business strategy?
Which of the following is the BEST justification for deferring remediation testing until the next audit?
An organization has recently become aware of a pervasive chip-level security vulnerability that affects all of its processors. Which of the following is the BEST way to prevent this vulnerability from being exploited?
Which of the following are used in a firewall to protect the entity ' s internal resources?
Which of the following is the MOST effective way to identify exfiltration of sensitive data by a malicious insider?
Which of the following is the BEST review for an IS auditor to conduct when a vulnerability has been exploited by an employee?
What should an IS auditor evaluate FIRST when reviewing an organization ' s response to new privacy legislation?
Which of the following methods would BEST help detect unauthorized disclosure of confidential documents sent over corporate email?
To protect the organization from malware transmitted by physical media, IT administrators have disabled USB access for storage devices. Which of the following BEST describes this type of control?
Which of the following would be an appropriate role of internal audit in helping to establish an organization’s privacy program?
Which of the following is the MOST effective control over visitor access to highly secured areas?
During the design phase of a software development project, the PRIMARY responsibility of an IS auditor is to evaluate the:
When reviewing an organization ' s information security policies, an IS auditor should verify that the policies have been defined PRIMARILY on the basis of:
During a security audit, an IS auditor is tasked with reviewing log entries obtained from an enterprise intrusion prevention system (IPS). Which type of risk would be associated with the potential for the auditor to miss a sequence of logged events that could indicate an error in the IPS configuration?
Who is PRIMARILY responsible for the design of IT controls to meet control objectives?
During a routine internal software licensing review, an IS auditor discovers instances where employees shared license keys to critical pieces of business software. Which of the following would be the auditor ' s BEST course of action?
An organization recently implemented a cloud document storage solution and removed the ability for end users to save data to their local workstation hard drives. Which of the following findings should be the IS auditor ' s GREATEST concern?
When reviewing the functionality of an intrusion detection system (IDS), the IS auditor should be MOST concerned if:
An organization has recently become aware of a pervasive chip-level security vulnerability that affects all of its processors. Which of the following is the BEST way to prevent this vulnerability from being exploited?
During the planning stage of a compliance audit, an IS auditor discovers that a bank ' s inventory of compliance requirements does not include recent regulatory changes related to managing data risk. What should the auditor do FIRST?
The FIRST step in auditing a data communication system is to determine:
Which of the following should be an IS auditor ' s GREATEST consideration when scheduling follow-up activities for agreed-upon management responses to remediate audit observations?
During recent post-implementation reviews, an IS auditor has noted that several deployed applications are not being used by the business. The MOST likely cause would be the lack of:
Which of the following findings should be of GREATEST concern to an IS auditor performing a review of IT operations?
An IS auditor is reviewing security controls related to collaboration tools for a business unit responsible for intellectual property and patents. Which of the following observations should be of MOST concern to the auditor?
Which of the following activities is MOST likely to increase internal audit quality?
Which of the following is MOST important to include in forensic data collection and preservation procedures?
Which of the following presents the GREATEST risk of data leakage in the cloud environment?
To confirm integrity for a hashed message, the receiver should use:
Which of the following should an IS auditor review FIRST when planning a customer data privacy audit?
A vendor requires privileged access to a key business application. Which of the following is the BEST recommendation to reduce the risk of data leakage?
An IS auditor finds that application servers had inconsistent security settings leading to potential vulnerabilities. Which of the following is the BEST recommendation by the IS auditor?
Which of the following should be GREATEST concern to an IS auditor reviewing data conversion and migration during the implementation of a new application system?
Which of the following should an IS auditor consider FIRST when evaluating firewall rules?
Recovery facilities providing a redundant combination of Internet connections to the local communications loop is an example of which type of telecommunications continuity?
An IS auditor concludes that logging and monitoring mechanisms within an organization are ineffective because critical servers are not included within the central log repository. Which of the following audit procedures would have MOST likely identified this exception?
Which of the following biometric access controls has the HIGHEST rate of false negatives?
During a follow-up audit, an IS auditor learns that some key management personnel have been replaced since the original audit, and current management has decided not to implement some previously accepted recommendations. What is the auditor ' s BEST course of action?
A secure server room has a badge reader system that records name, date, and time information whenever a staff member uses a badge to enter or exit. When reviewing the system logs, an IS auditor notices records for some employees entering, but not exiting, the room. Which of the following would be the MOST effective compensating control to recommend?
Which of the following testing methods is MOST appropriate for assessing whether system integrity has been maintained after changes have been made?
Which of the following would BEST ensure that a backup copy is available for restoration of mission critical data after a disaster ' '
Management has requested a post-implementation review of a newly implemented purchasing package to determine to what extent business requirements are being met. Which of the following is MOST likely to be assessed?
An IS auditor is reviewing an organization ' s business continuity plan (BCP) following a change in organizational structure with significant impact to business processes. Which of the following findings should be the auditor ' s GREATEST concern?
Which of the following is a PRIMARY responsibility of an IT steering committee?
Who is PRIMARILY responsible for the design of IT controls to meet control objectives?
Which of the following is the BEST way to ensure that an application is performing according to its specifications?
Which of the following should be of GREATEST concern to an IS auditor performing a review of information security controls?
Which of the following security testing techniques is MOST effective for confirming that inputs to a web application have been properly sanitized?
Which of the following is MOST useful when planning to audit an organization ' s compliance with cybersecurity regulations in foreign countries?
The PRIMARY benefit lo using a dry-pipe fire-suppression system rather than a wet-pipe system is that a dry-pipe system:
Which of the following groups is PRIMARILY accountable for establishing a culture that facilitates an effective and efficient internal control system?
Which of the following is the BEST way to mitigate risk to an organization ' s network associated with devices permitted under a bring your own device (BYOD) policy?
Which of the following is MOST important for an IS auditor to validate when auditing network device management?
In continuous delivery, the critical connector between development and production is:
An IS auditor finds that an IT manager recently changed a Software as a Service (SaaS) provider contract in an effort to cut costs. The new contract increases the time to resolve incidents. Which of the following should be the auditor’s GREATEST concern?
Which of the following is the BEST way to verify the effectiveness of a data restoration process?
An organization has outsourced the development of a core application. However, the organization plans to bring the support and future maintenance of the application back in-house. Which of the following findings should be the IS auditor ' s GREATEST concern?
Which of the following should be done FIRST to ensure the secure configuration of new IT assets in an organization?
Which of the following system redundancy configurations BEST improves system resiliency and reduces the possibility of a single cause of failure impacting system dependability?
An organization has initiated a project to migrate to a new accounts payable system. Which of the following responsibilities is MOST important to assign to the accounts payable business process owner working on this project?
During the evaluation of controls over a major application development project, the MOST effective use of an IS auditor ' s time would be to review and evaluate:
Which of the following should an IS auditor ensure is classified at the HIGHEST level of sensitivity?
An IS auditor is reviewing the security of a banking system that uses hardware-based encryption. Which of the following is the PRIMARY objective for the adoption of this type of encryption?
Which of the following is the MOST appropriate and effective fire suppression method for an unstaffed computer room?
The use of control totals satisfies which of the following control objectives?
Which of the following is the PRIMARY objective of cyber resiliency?
Which of the following should be the FRST step when developing a data toes prevention (DIP) solution for a large organization?
Which of the following types of environmental equipment will MOST likely be deployed below the floor tiles of a data center?
A programmer has made unauthorized changes to key fields in a payroll system report. Which of the following control weaknesses would have contributed MOST to this
problem?
Which of the following would BEST detect that a distributed denial of service (DDoS) attack is occurring?
An organization has established hiring policies and procedures designed specifically to ensure network administrators are well qualified Which type of control is in place?
Which of the following is the MOST important Issue for an IS auditor to consider with regard to Voice-over IP (VoIP) communications?
The waterfall life cycle model of software development is BEST suited for which of the following situations?
When evaluating the design of controls related to network monitoring, which of the following is MOST important for an IS auditor to review?
Which of the following is the BEST approach to help organizations address risks associated with shadow IT?