<< Prev Question Next Question >>

Question 171/791

An IS auditor discovers that validation controls m a web application have been moved from the server side into the browser to boost performance This would MOST likely increase the risk of a successful attack by.

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (791q)
Question 1: When selecting a new data loss prevention (DLP) solution, th...
Question 2: While conducting a follow-up on an asset management audit, t...
Question 3: Which of the following should be the GREATEST concern for an...
Question 4: Which of the following is MOST important to determine when c...
Question 5: If concurrent update transactions to an account are not proc...
Question 6: A checksum is classified as which type of control?...
Question 7: Which task should an IS auditor complete FIRST during the pr...
Question 8: An IS auditor is analyzing a sample of accounts payable tran...
Question 9: Which of the following is the BEST indication of effective I...
Question 10: Email required for business purposes is being stored on empl...
Question 11: Which of the following provides the MOST reliable audit evid...
Question 12: An IS auditor has been asked to assess the security of a rec...
Question 13: An organization is permanently transitioning from onsite to ...
Question 14: Which of the following presents the GREATEST risk associated...
Question 15: Which of the following is the MOST reliable way for an IS au...
Question 16: Which of the following is MOST important to ensure when plan...
Question 17: Which of the following BEST describes the role of the IS aud...
Question 18: An incident response team has been notified of a virus outbr...
Question 19: Stress testing should ideally be earned out under a:...
Question 20: Which of the following is the BEST reason for an IS auditor ...
Question 21: Which of the following types of firewalls provide the GREATE...
Question 22: Which of the following is the MOST important prerequisite fo...
Question 23: Which of the following should be the FIRST step to successfu...
Question 24: Which of the following statements appearing in an organizati...
Question 25: Which of the following activities should be separated in an ...
Question 26: Which of the following would present the GREATEST concern du...
Question 27: Which of the following is MOST important for an IS auditor t...
Question 28: Management has decided to accept a risk in response to a dra...
Question 29: From an IS auditor ' s perspective, which of the following w...
Question 30: Which of the following provides the GREATEST assurance that ...
Question 31: Which of the following BEST addresses the availability of an...
Question 32: What should an IS auditor do FIRST upon discovering that a s...
Question 33: An IS auditor is reviewing the operational database manageme...
Question 34: The PRIMARY objective of a privacy protection policy is to i...
Question 35: If a source code is not recompiled when program changes are ...
Question 36: Which of the following is MOST important when creating a for...
Question 37: Which of the following is MOST important to consider when de...
Question 38: An organization is concerned about duplicate vendor payments...
Question 39: Which of the following should be the IS auditor ' s PRIMARY ...
Question 40: Which of the following is the BEST indication that a softwar...
Question 41: Which of the following BEST supports an organization ' s obj...
Question 42: An organization has outsourced the development of a core app...
Question 43: A configuration management audit identified that predefined ...
Question 44: Which of the following is the GREATEST advantage of vulnerab...
Question 45: Which of the following criteria is MOST important for the su...
Question 46: An organization considering the outsourcing of a business ap...
Question 47: External audits have identified recurring exceptions in the ...
Question 48: Which of the following would be the BEST criteria for monito...
Question 49: Which of the following application input controls would MOST...
Question 50: When implementing Internet Protocol security (IPsec) archite...
Question 51: When an IS audit reveals that a firewall was unable to recog...
Question 52: Which of the following user actions poses the GREATEST risk ...
Question 53: The FIRST step in auditing a data communication system is to...
Question 54: Which of the following provides the BEST evidence that IT po...
Question 55: An IS auditor plans to review all access attempts to a video...
Question 56: Which of the following types of firewalls provides the GREAT...
Question 57: Which of the following risks is BEST mitigated by implementi...
Question 58: Which of the following is an example of a preventative contr...
Question 59: An IS auditor is reviewing a data conversion project Which o...
Question 60: The GREATEST concern for an IS auditor reviewing vulnerabili...
Question 61: In a high-volume, real-time system, the MOST effective techn...
Question 62: A database administrator (DBA) should be prevented from havi...
Question 63: The purpose of a checksum on an amount field in an electroni...
Question 64: A startup organization wants to develop a data loss preventi...
Question 65: Which of the following provides the BEST evidence that a thi...
Question 66: In an environment that automatically reports all program cha...
Question 67: Which of the following is the BEST way to determine whether ...
Question 68: What is the Most critical finding when reviewing an organiza...
Question 69: An IS auditor would MOST likely recommend that IT management...
Question 70: An IS auditor has been asked to advise on measures to improv...
Question 71: Which of the following is the BEST method to safeguard data ...
Question 72: Which of the following is the MOST important consideration w...
Question 73: An emergency power-off switch should:...
Question 74: An IS auditor is providing input to an RFP to acquire a fina...
Question 75: Which of the following responses to risk associated with sep...
Question 76: When verifying the accuracy and completeness of migrated dat...
Question 77: Which of the following is the PRIMARY purpose of obtaining a...
Question 78: Which of the following documents should define roles and res...
Question 79: An IS auditor is reviewing processes for importing market pr...
Question 80: Which of the following is the MOST efficient control to redu...
Question 81: Which of the following BEST enables the timely identificatio...
Question 82: Which of the following analytical methods would be MOST usef...
Question 83: An organization allows employees to retain confidential data...
Question 84: Which of the following is the MOST effective way to evaluate...
Question 85: Which of the following should an IS auditor be MOST concerne...
Question 86: Which of the following should be of GREATEST concern to an I...
Question 87: An organization with many desktop PCs is considering moving ...
Question 88: An IS auditor is reviewing a decision to consolidate process...
Question 89: During an IT general controls audit of a high-risk area wher...
Question 90: During a database management evaluation an IS auditor discov...
Question 91: Which of the following should be an IS auditor ' s PRIMARY f...
Question 92: Which of the following would be the GREATEST concern to an I...
Question 93: Which of the following is the BEST method to prevent wire tr...
Question 94: Which of the following is the PRIMARY role of the IS auditor...
Question 95: Which of the following is the GREATEST concern when applying...
Question 96: When reviewing whether IT investments are meeting business o...
Question 97: Which of the following is the BEST indicator that a third-pa...
Question 98: An IS auditor is asked to review an organization ' s technol...
Question 99: The PRIMARY purpose of requiring source code escrow in a con...
Question 100: Of the following who should be responsible for cataloging an...
Question 101: An IS auditor is asked to provide feedback on the systems op...
Question 102: Which of the following is the PRIMARY reason to follow a con...
Question 103: When processing speed is the highest priority, which cryptog...
Question 104: Which of the following would an IS auditor recommend as the ...
Question 105: Which of the following techniques BEST mitigates the risk of...
Question 106: Which of the following is the MOST important reason for an o...
Question 107: For security awareness training to be MOST effective, manage...
Question 108: A proper audit trail of changes to server start-up procedure...
Question 109: Which of the following is the MOST effective way for an orga...
Question 110: An IT strategic plan that BEST leverages IT in achieving org...
Question 111: Which of the following BEST describes the process of creatin...
Question 112: Which of the following controls would BEST help a forensic i...
Question 113: When reviewing hard disk utilization reports, an IS auditor ...
Question 114: Which of the following BEST mitigates the risk of SQL inject...
Question 115: When determining whether a project in the design phase will ...
Question 116: An IS auditor has learned that access privileges are not per...
Question 117: Which of the following is the BEST indicator for measuring p...
Question 118: Which of the following should be the PRIMARY basis for prior...
Question 119: Which of the following BEST indicates that an incident manag...
Question 120: An organization has decided to purchase a web-based email se...
Question 121: Which of the following provides the BEST evidence that syste...
Question 122: A review of Internet security disclosed that users have indi...
Question 123: In a small IT web development company where developers must ...
Question 124: A transaction processing system interfaces with the general ...
Question 125: An organization has introduced a capability maturity model t...
Question 126: When auditing an organization ' s software acquisition proce...
Question 127: Which of the following is the BEST reason to implement a con...
Question 128: Which of the following is the BEST reason to implement a dat...
Question 129: Which of the following recommendations would BEST prevent th...
Question 130: Which of the following should an IS auditor do FIRST when au...
Question 131: Which of the following performance management tools BEST hel...
Question 132: A telecommunications company has recently created a new frau...
Question 133: An IS auditor discovers that backups of critical systems are...
Question 134: In which phase of the internal audit process is contact esta...
Question 135: An IS auditor observes that an organization ' s systems are ...
Question 136: The PRIMARY reason for an IS auditor to use data analytics t...
Question 137: During an operational audit on the procurement department, t...
Question 138: Which of the following would provide the BEST evidence of an...
Question 139: An organization has moved all of its infrastructure to the c...
Question 140: Which of the following can BEST reduce the impact of a long-...
Question 141: Which of the following is the MOST important consideration w...
Question 142: Which of the following is the PRIMARY reason for an airline ...
Question 143: During an internal audit of project governance, which of the...
Question 144: Which of the following is the PRIMARY reason for an IS audit...
Question 145: An IS auditor has found that an organization is unable to ad...
Question 146: Which of the following represents the HIGHEST level of matur...
Question 147: Which of the following would be of GREATEST concern to an IS...
Question 148: Which of the following is an IS auditor ' s BEST approach wh...
Question 149: During the course of an IS audit, management verbally agreed...
Question 150: An organization has shifted from a bottom-up approach to a t...
Question 151: An IS auditor has discovered that a software system still in...
Question 152: An IS auditor is reviewing a bank's service level agreement ...
Question 153: Upon completion of a penetration test with findings for an I...
Question 154: The use of access control lists (ACLs) is the MOST effective...
Question 155: Which of the following will provide the GREATEST assurance t...
Question 156: An IS auditor is planning a review of an organizations robot...
Question 157: Which of the following should be done FIRST to ensure the se...
Question 158: An IS auditor notes that not all security tests were complet...
Question 159: What is the GREATEST concern for an IS auditor reviewing con...
Question 160: A financial organization has learned that one of its busines...
Question 161: Which of the following poses the GREATEST risk to an organiz...
Question 162: Which of the following is MOST helpful for measuring benefit...
Question 163: Which of the following is a method to prevent disclosure of ...
Question 164: Which of the following should be of MOST concern to an IS au...
Question 165: Which of the following should be done FIRST when creating a ...
Question 166: Which of the following is the BEST justification for deferri...
Question 167: Which of the following is an executive management concern th...
Question 168: Which of the following MOST effectively minimizes downtime d...
Question 169: Which of the following is the BEST way to mitigate risk to a...
Question 170: Which of the following is the BEST recommendation to prevent...
Question 171: An IS auditor discovers that validation controls m a web app...
Question 172: An organization has recently become aware of a pervasive chi...
Question 173: Which of the following is the MOST appropriate responsibilit...
Question 174: Which of the following should be the GREATEST concern to an ...
Question 175: Which of the following is MOST important for an IS auditor t...
Question 176: Who should be the FIRST to evaluate an audit report prior to...
Question 177: An IS auditor is conducting a post-implementation review of ...
Question 178: IT disaster recovery time objectives (RTOs) should be based ...
Question 179: Which of the following would be of GREATEST concern when rev...
Question 180: A manager Identifies active privileged accounts belonging to...
Question 181: A national bank recently migrated a large number of business...
Question 182: Which of the following would BEST indicate the effectiveness...
Question 183: Which of the following BEST helps to determine an organizati...
Question 184: IT management has accepted the risk associated with an IS au...
Question 185: An IS auditor wants to verify alignment of the organization ...
Question 186: An organization uses public key infrastructure (PKI) to prov...
Question 187: Which of the following is necessary for effective risk manag...
Question 188: Which of the following should be the PRIMARY objective of a ...
Question 189: Which of the following is the BEST way to address segregatio...
Question 190: Which of the following is MOST important for the successful ...
Question 191: Upon completion of a penetration test with findings for an I...
Question 192: In which phase of the audit life cycle process should an IS ...
Question 193: Which of the following BEST describes the concept of fault t...
Question 194: Which of the following MOST effectively detects transpositio...
Question 195: An IS auditor is reviewing an organizations release manageme...
Question 196: Which of the following should be of MOST concern to an IS au...
Question 197: An IS audit manager was temporarily tasked with supervising ...
Question 198: Which of the following is the BEST reason for an organizatio...
Question 199: The PRIMARY role of an IS auditor in the remediation of prob...
Question 200: During audit framework. an IS auditor teams that employees a...
Question 201: Which of the following is the MOST appropriate testing appro...
Question 202: Aligning IT strategy with business strategy PRIMARILY helps ...
Question 203: Which of the following biometric access controls has the HIG...
Question 204: Which of the following is the PRIMARY advantage of using an ...
Question 205: An IS auditor is reviewing processes for importing market pr...
Question 206: Which of the following is MOST important when defining the I...
Question 207: During a review, an IS auditor discovers that corporate user...
Question 208: Which of the following is MOST helpful in identifying system...
Question 209: Which of the following metrics would BEST measure the agilit...
Question 210: Which of the following is the PRIMARY reason for implementin...
Question 211: An IS department is evaluated monthly on its cost-revenue ra...
Question 212: A data breach has occurred due lo malware. Which of the foll...
Question 213: Which of the following responsibilities associated with a di...
Question 214: Coding standards provide which of the following?...
Question 215: An IS auditor finds that an organization ' s data loss preve...
Question 216: What should be the PRIMARY basis for selecting which IS audi...
Question 217: Which of the following observations should be of GREATEST co...
Question 218: Which of the following should an IS auditor expect to find w...
Question 219: Which of the following would be of MOST concern for an IS au...
Question 220: An organization has made a strategic decision to split into ...
Question 221: Following the sale of a business division, employees will be...
Question 222: An IS auditor should ensure that an application ' s audit tr...
Question 223: A CFO has requested an audit of IT capacity management due t...
Question 224: An organization has established hiring policies and procedur...
Question 225: Which of the following is the BEST indication that there are...
Question 226: Which of the following is the GREATEST advantage of outsourc...
Question 227: In a large organization, IT deadlines on important projects ...
Question 228: An IS auditor is reviewing an IT project and finds that an e...
Question 229: Which of the following should be of GREATEST concern to an I...
Question 230: An employee approaches an IS auditor and expresses concern a...
Question 231: Which of the following should be of GREATEST concern to an I...
Question 232: Which of the following would be an IS auditor ' s GREATEST c...
Question 233: Which of the following is an example of a preventive control...
Question 234: In which data loss prevention (DLP) deployment model is data...
Question 235: Providing security certification for a new system should inc...
Question 236: Which of the following is MOST important to ensure when plan...
Question 237: Which of the following observations should be of GREATEST co...
Question 238: During an exit interview, senior management disagrees with s...
Question 239: Which of the following BEST indicates an effective internal ...
Question 240: When auditing the closing stages of a system development pro...
Question 241: An organization uses an automated continuous integration/con...
Question 242: To mitigate the risk of exposing data through application pr...
Question 243: Which of the following should be the PRIMARY role of an inte...
Question 244: Which of the following would an IS auditor find to be the GR...
Question 245: The BEST way for an IS auditor to validate that separation o...
Question 246: Which of the following controls is MOST crucial to ensure an...
Question 247: Which of the following is the MOST significant risk when an ...
Question 248: An online retailer is receiving customer complaints about re...
Question 249: An internal audit department recently established a quality ...
Question 250: An IS audit reveals that an organization operating in busine...
Question 251: A now regulation requires organizations to report significan...
Question 252: A senior auditor is reviewing work papers prepared by a juni...
Question 253: An IS auditor reviewing the system development life cycle (S...
Question 254: Which of the following should be of MOST concern to an IS au...
Question 255: When reviewing an IT strategic plan, the GREATEST concern wo...
Question 256: An IS auditor is reviewing database fields updated in real-t...
Question 257: During an audit, an IT finding is agreed upon by all IT team...
Question 258: Which of the following BEST demonstrates to senior managemen...
Question 259: Which of the following is the MOST important action when pop...
Question 260: An IS auditor wants to gain a better understanding of an org...
Question 261: An organization is modernizing its technology policy framewo...
Question 262: Which of the following should an IS auditor consider the MOS...
Question 263: A programmer has made unauthorized changes to key fields in ...
Question 264: To ensure confidentiality through the use of asymmetric encr...
Question 265: Which of the following should be the FRST step when developi...
Question 266: The PRIMARY advantage of object-oriented technology is enhan...
Question 267: An organization performs virtual machine (VM) replication in...
Question 268: Which of the following is the BEST method for converting sys...
Question 269: When auditing the feasibility study of a system development ...
Question 270: Which of the following MUST be completed as part of the annu...
Question 271: Which of the following is the PRIMARY concern when negotiati...
Question 272: Which of the following is the MOST effective control over vi...
Question 273: An IS audit learn is evaluating the documentation related to...
Question 274: An IT governance body wants to determine whether IT service ...
Question 275: Which of the following should be an IS auditor ' s PRIMARY f...
Question 276: An IS auditor is reviewing enterprise governance and finds t...
Question 277: Which of the following would provide the BEST evidence that ...
Question 278: Which of the following BEST protects an organization ' s pro...
Question 279: A PRIMARY objective of risk management is to keep the total ...
Question 280: An organization has alternative links in its wide area netwo...
Question 281: Which of the following is the BEST control to prevent the tr...
Question 282: An IS auditor is assessing backup performance and observes t...
Question 283: An organization that processes credit card information emplo...
Question 284: Retention periods and conditions for the destruction of pers...
Question 285: Which of the following protocols should be used when transfe...
Question 286: Which of the following is the BEST evidence that an organiza...
Question 287: The PRIMARY purpose of an incident response plan is to:...
Question 288: Which of the following is the MOST important consideration w...
Question 289: Which of the following is MOST appropriate to review when de...
Question 290: While reviewing the effectiveness of an incident response pr...
Question 291: Which of the following poses the GREATEST risk to the use of...
Question 292: Effective separation of duties in an online environment can ...
Question 293: An IS auditor is planning a review of an organizations cyber...
Question 294: Which of the following is the BEST way to address separation...
Question 295: The process of applying a hash function to a message and obt...
Question 296: Which of the following would BEST manage the risk of changes...
Question 297: A business has requested an audit to determine whether infor...
Question 298: In order for a firewall to effectively protect a network aga...
Question 299: Which of the following BEST enables alignment of IT with bus...
Question 300: An IS auditor is reviewing a machine learning algorithm-base...
Question 301: Which of the following is the MOST important advantage of pa...
Question 302: Which of the following tests is MOST likely to detect an err...
Question 303: Which of the following responsibilities of an organization '...
Question 304: Which of the following should an IS auditor ensure is classi...
Question 305: An IS auditor noted a recent production incident in which a ...
Question 306: An organization has recently become aware of a pervasive chi...
Question 307: An organization has virtualized its server environment witho...
Question 308: Which of the following is the PRIMARY reason for an organiza...
Question 309: In reviewing the IT strategic plan, the IS auditor should co...
Question 310: Which of the following is the MOST important activity in the...
Question 311: The FIRST step in an incident response plan is to:...
Question 312: A financial accounting system audit determined that audit lo...
Question 313: What is the PRIMARY benefit of using one-time passwords?...
Question 314: Which of the following controls is BEST implemented through ...
Question 315: Which of the following security risks can be reduced by a pr...
Question 316: An organization produces control reports with a desktop appl...
Question 317: An IS auditor is reviewing an organization ' s risk manageme...
Question 318: During a follow-up engagement, an IS auditor confirms eviden...
Question 319: A global organization ' s policy states that all workstation...
Question 320: When evaluating whether the expected benefits of a project h...
Question 321: Which of the following is the BEST testing approach to facil...
Question 322: Which of the following is the BEST indication to an IS audit...
Question 323: Which of the following audit evidence collection procedures ...
Question 324: Which of the following is the BEST compensating control agai...
Question 325: An IS auditor finds that one employee has unauthorized acces...
Question 326: What should an IS auditor ensure when a financial organizati...
Question 327: A bank performed minor changes to the interest calculation c...
Question 328: Which of the following is MOST important to include when dev...
Question 329: An IS auditor finds that the process for removing access for...
Question 330: Which of the following is the PRIMARY benefit of implementin...
Question 331: When is it MOST important for an IS auditor to apply the con...
Question 332: Which of the following is the MOST important course of actio...
Question 333: Which of the following practices associated with capacity pl...
Question 334: An IS auditor finds that while an organization ' s IT strate...
Question 335: Which of the following is MOST important for an IS auditor t...
Question 336: Who is PRIMARILY responsible for the design of IT controls t...
Question 337: To confirm integrity for a hashed message, the receiver shou...
Question 338: Which of the following is the MOST important consideration o...
Question 339: Which of the following is the MOST cost-effective way to det...
Question 340: During an audit of a multinational bank ' s disposal process...
Question 341: Which of the following findings from an IT governance review...
Question 342: An IS auditor is evaluating the access controls for a shared...
Question 343: An IS auditor is assigned to perform a post-implementation r...
Question 344: A vendor requires privileged access to a key business applic...
Question 345: An IS auditor finds that a key Internet-facing system is vul...
Question 346: An IS auditor is reviewing desktop software profiles and not...
Question 347: Which of the following is the PRIMARY benefit of introducing...
Question 348: Management receives information indicating a high level of r...
Question 349: Which of the following would BEST determine whether a post-i...
Question 350: Which of the following should be an IS auditor's PRIMARY foc...
Question 351: Which of the following would BEST prevent an arbitrary appli...
Question 352: Which of the following is the PRIMARY reason to perform a ri...
Question 353: Which of the following should be of GREATEST concern to an I...
Question 354: Which of the following is MOST important for an IS auditor t...
Question 355: During a follow-up audit, an IS auditor finds that some crit...
Question 356: Which of the following is the GREATEST benefit of adopting a...
Question 357: Which of the following are BEST suited for continuous auditi...
Question 358: Which of the following is the PRIMARY purpose of enterprise ...
Question 359: Which of the following is a principle of the Agile software ...
Question 360: Which of the following is the BEST approach for determining ...
Question 361: Which of the following is the BEST way to ensure that an app...
Question 362: What should an IS auditor do FIRST when management responses...
Question 363: Which of the following should be of GREATEST concern to an I...
Question 364: Which of the following should be of GREATEST concern for an ...
Question 365: Which of the following is the BEST methodology to use for es...
Question 366: Which of the following is the MOST effective method to ident...
Question 367: Which of the following is the BEST method to delete sensitiv...
Question 368: Which of the following would provide the MOST important inpu...
Question 369: An IS auditor reviewing the threat assessment tor a data cen...
Question 370: Which of the following controls helps to reduce fraud risk a...
Question 371: Which of the following poses the GREATEST potential concern ...
Question 372: Which of the following measures BEST mitigates the risk of d...
Question 373: Which of the following is an IS auditor ' s BEST recommendat...
Question 374: Which of the following should be the FIRST step in the incid...
Question 375: Based on best practices, which types of accounts should be d...
Question 376: An organization outsourced its IS functions to meet its resp...
Question 377: Which of the following provides the BEST evidence that all e...
Question 378: An IS auditor discovers a box of hard drives in a secured lo...
Question 379: Which of the following tests would provide the BEST assuranc...
Question 380: Which of the following methods would BEST help detect unauth...
Question 381: Which of the following provides IS audit professionals with ...
Question 382: Which of the following is the MOST important consideration w...
Question 383: During the planning phase of a data loss prevention (DLP) au...
Question 384: Which of the following findings would be of GREATEST concern...
Question 385: Which of the following is the PRIMARY objective of enterpris...
Question 386: How does public key infrastructure (PKI) help to verify that...
Question 387: An IS auditor is reviewing the release management process fo...
Question 388: Which of the following is the GREATEST risk related to the u...
Question 389: What should be the PRIMARY focus during a review of a busine...
Question 390: When evaluating information security governance within an or...
Question 391: An IS auditor is reviewing an organization ' s cloud access ...
Question 392: Which of the following would present the GREATEST concern du...
Question 393: Which of the following is the PRIMARY advantage of using vir...
Question 394: What is the FIRST step when creating a data classification p...
Question 395: Attribute sampling is BEST suited to estimate:...
Question 396: After delivering an audit report, the audit manager discover...
Question 397: Which of the following is an IS auditor ' s BEST recommendat...
Question 398: Capacity management enables organizations to:...
Question 399: Which of the following would be MOST important to include in...
Question 400: The PRIMARY responsibility of a project steering committee i...
Question 401: An organization has engaged a third party to implement an ap...
Question 402: While evaluating the data classification process of an organ...
Question 403: Which of the following security measures will reduce the ris...
Question 404: Which of the following security measures is MOST important f...
Question 405: While reviewing transactions, an IS auditor discovers incons...
Question 406: An IS auditor reviewing database security should be MOST con...
Question 407: An IS auditor discovers that a developer has used the same k...
Question 408: In which phase of penetration testing would host detection a...
Question 409: Which of the following should an IS auditor expect to see in...
Question 410: Which of the following should be an IS auditor ' s PRIMARY c...
Question 411: An IS auditor observes that a business-critical application ...
Question 412: Which of the following is the MAIN responsibility of the IT ...
Question 413: Which of the following activities would allow an IS auditor ...
Question 414: Which of the following MOST effectively reduces the probabil...
Question 415: An external attacker spoofing an internal Internet Protocol ...
Question 416: How is nonrepudiation supported within a public key infrastr...
Question 417: An organization is concerned with meeting new regulations fo...
Question 418: An organization has an acceptable use policy in place, but u...
Question 419: An IS auditor is reviewing a client ' s outsourced payroll s...
Question 420: Data is being transferred from an application database to a ...
Question 421: Which of the following is MOST helpful for an IS auditor to ...
Question 422: An IS auditor found that a company executive is encouraging ...
Question 423: Which of the following BEST facilitates the successful imple...
Question 424: A data center ' s physical access log system captures each v...
Question 425: An organization has both an IT strategy committee and an IT ...
Question 426: Who is PRIMARILY responsible for the design of IT controls t...
Question 427: A new system is being developed externally for an organizati...
Question 428: Having knowledge in which of the following areas is MOST rel...
Question 429: When auditing IT organizational structure, which of the foll...
Question 430: Which of the following would be MOST impacted if an IS audit...
Question 431: An IS auditor is reviewing an organization ' s incident mana...
Question 432: Which of the following is MOST effective in keeping a databa...
Question 433: An IS auditor is assessing the adequacy of management ' s re...
Question 434: Which of the following would be of GREATEST concern to an IS...
Question 435: Which of the following will be the MOST effective method to ...
Question 436: Which of the following provides re BEST evidence that outsou...
Question 437: Which of the following is the BEST control to mitigate the m...
Question 438: Which of the following audit procedures would be MOST conclu...
Question 439: Which of the following is MOST important to consider when as...
Question 440: During an IT governance audit, an IS auditor notes that IT p...
Question 441: Which of the following should be of GREATEST concern to an I...
Question 442: Which of the following should be of GREATEST concern to an I...
Question 443: How would an IS auditor BEST determine the effectiveness of ...
Question 444: Which of the following is MOST important to define within a ...
Question 445: Which of the following is the BEST data integrity check?...
Question 446: A staff accountant regularly uploads spreadsheets with inven...
Question 447: During a project audit, an IS auditor notes that project rep...
Question 448: The due date of an audit project is approaching, and the aud...
Question 449: Which of the following would be of GREATEST concern to an IS...
Question 450: Which of the following would BEST help to ensure that an inc...
Question 451: An IS auditor is reviewing the perimeter security design of ...
Question 452: A security administrator is called in the middle of the nigh...
Question 453: Which of the following is a PRIMARY function of an intrusion...
Question 454: An IS auditor is reviewing a data conversion project. Which ...
Question 455: Which of the following is the BEST disposal method for flash...
Question 456: Which of the following IT service management activities is M...
Question 457: When evaluating the design of controls related to network mo...
Question 458: During a follow-up audit, an IS auditor learns that some key...
Question 459: An IS auditor discovers that validation controls in a web ap...
Question 460: Which of the following BEST guards against the risk of attac...
Question 461: An IS auditor extracts data from a travel and expenses syste...
Question 462: Which of the following would present the GREATEST risk withi...
Question 463: Which of the following is the PRIMARY basis on which audit o...
Question 464: An IS auditor is assigned to review the IS department s qual...
Question 465: Which type of control is being implemented when a biometric ...
Question 466: Which of the following should be restricted from a network a...
Question 467: An IS auditor found that operations personnel failed to run ...
Question 468: To develop meaningful recommendations ' or findings, which o...
Question 469: When classifying information, it is MOST important to align ...
Question 470: Which of the following are examples of corrective controls?...
Question 471: An organization is establishing a steering committee for the...
Question 472: A white box testing method is applicable with which of the f...
Question 473: Which of the following would BEST help to ensure that potent...
Question 474: Which of the following is the BEST review for an IS auditor ...
Question 475: The PRIMARY reason to perform internal quality assurance (QA...
Question 476: An IS auditor should be MOST concerned if which of the follo...
Question 477: Which of the following would be the GREATEST concern for an ...
Question 478: An IS auditor wants to determine who has oversight of staff ...
Question 479: A security review focused on data loss prevention (DLP) reve...
Question 480: Which of the following would be of GREATEST concern to an IS...
Question 481: Which of the following is the MOST important reason to class...
Question 482: Which of the following MUST be completed as part of the annu...
Question 483: An organization saves confidential information in a file wit...
Question 484: Which of the following is an IS auditor's BEST recommendatio...
Question 485: Which of the following is MOST useful for determining whethe...
Question 486: Which of the following should be the FIRST consideration whe...
Question 487: At the conclusion of an audit, but before issuing the final ...
Question 488: Which of the following BEST helps monitor and manage operati...
Question 489: The waterfall life cycle model of software development is BE...
Question 490: An IS auditor has been asked to review an event log aggregat...
Question 491: Which of the following approaches will ensure recovery time ...
Question 492: An IS auditor finds an IT manager recently changed a Softwar...
Question 493: in a controlled application development environment, the MOS...
Question 494: When auditing the security architecture of an online applica...
Question 495: An IS auditor believes that management has accepted a level ...
Question 496: Which of the following management decisions presents the GRE...
Question 497: Which of the following establishes the PRIMARY difference be...
Question 498: Which of the following is the MOST likely root cause of shad...
Question 499: An IS auditor is reviewing a bank ' s service level agreemen...
Question 500: An IS auditor is assessing an organization ' s DevSecOps app...
Question 501: Which of the following is the PRIMARY reason an IS auditor s...
Question 502: An IS auditor is reviewing security controls related to coll...
Question 503: An organization using a cloud provider for its online billin...
Question 504: Which of following areas is MOST important for an IS auditor...
Question 505: Which of the following is the GREATEST risk of project dashb...
Question 506: Which of the following is the BEST control to help ensure th...
Question 507: Backup procedures for an organization ' s critical data are ...
Question 508: In an annual audit cycle, the audit of an organization ' s I...
Question 509: Which of the following MOST effectively manages frequent pro...
Question 510: An organizations audit charier PRIMARILY:...
Question 511: Which of the following groups is PRIMARILY accountable for e...
Question 512: Which of the following should be of GREATEST concern to an I...
Question 513: An IS auditor is reviewing an organization ' s system develo...
Question 514: Which of the following represents the GREATEST risk to virtu...
Question 515: Which of the following observations should be of GREATEST co...
Question 516: Which of the following is the MOST effective way to detect a...
Question 517: An organization is planning an acquisition and has engaged a...
Question 518: Which of the following is an effective way to ensure the int...
Question 519: Which of the following is the BEST way to determine the adeq...
Question 520: An organization is ready to implement a new IT solution cons...
Question 521: During an audit which of the following would be MOST helpful...
Question 522: Which of the following is MOST important to consider when sc...
Question 523: An IS auditor is reviewing documentation from a change that ...
Question 524: An IS auditor finds ad hoc vulnerability scanning is in plac...
Question 525: Internal audit is evaluating an organization's IT portfolio ...
Question 526: Which of the following should be an IS auditor ' s PRIMARY f...
Question 527: Which of the following is the PRIMARY benefit of performing ...
Question 528: An IS auditor finds that a new network connection allows com...
Question 529: Which of the following is a PRIMARY purpose of a privacy not...
Question 530: Which of the following would be the MOST useful metric for m...
Question 531: In a 24/7 processing environment, a database contains severa...
Question 532: Which of the following is the MOST effective way for an IS a...
Question 533: Which of the following approaches would utilize data analyti...
Question 534: Which of the following should be of MOST concern to an IS au...
Question 535: An IS auditor is preparing for a review of controls associat...
Question 536: During the implementation of an enterprise resource planning...
Question 537: During a physical security audit, an IS auditor was provided...
Question 538: The PRIMARY advantage of using open-source-based solutions i...
Question 539: With regard to resilience, which of the following is the GRE...
Question 540: During a new system implementation, an IS auditor has been a...
Question 541: Which of the following would provide an IS auditor with the ...
Question 542: During the planning phase of a data loss prevention (DLP) au...
Question 543: Which of the following system attack methods is executed by ...
Question 544: An organization used robotic process automation (RPA) techno...
Question 545: A steering committee established to oversee an organization'...
Question 546: A small organization is experiencing rapid growth and plans ...
Question 547: Which of the following controls helps to ensure that data ex...
Question 548: A core system fails a week after a scheduled update, causing...
Question 549: Which of the following should be GREATEST concern to an IS a...
Question 550: Which of the following is the MOST important benefit of invo...
Question 551: Which of the following should an IS auditor perform FIRST wh...
Question 552: An organization that has suffered a cyber-attack is performi...
Question 553: Which of the following is MOST likely to be reduced when imp...
Question 554: Which of the following is the PRIMARY role of an IS auditor ...
Question 555: Following a security breach in which a hacker exploited a we...
Question 556: Which of the following should an IS auditor review when eval...
Question 557: During a review of an organization ' s IT capacity managemen...
Question 558: An IT balanced scorecard is PRIMARILY used for:...
Question 559: Spreadsheets are used to calculate project cost estimates. T...
Question 560: An IS audit reveals an IT application is experiencing poor p...
Question 561: As part of business continuity planning, which of the follow...
Question 562: Which of the following should be done FIRST following an inc...
Question 563: If enabled within firewall rules, which of the following ser...
Question 564: Which of the following BEST contributes to the quality of an...
Question 565: To enable the alignment of IT staff development plans with I...
Question 566: Secure code reviews as part of a continuous deployment progr...
Question 567: Which of the following is MOST effective for controlling vis...
Question 568: Which of the following conditions would be of MOST concern t...
Question 569: Which of the following controls is MOST crucial to ensure an...
Question 570: Several unattended laptops containing sensitive customer dat...
Question 571: Following the complete corruption of a database, an organiza...
Question 572: Which of the following should be an IS auditor ' s GREATEST ...
Question 573: Which of the following is MOST important during software lic...
Question 574: An organization recently implemented a cloud document storag...
Question 575: Which of the following is the BEST way to identify key areas...
Question 576: An organization ' s security policy mandates that all new em...
Question 577: Which of the following is an IS auditor's BEST recommendatio...
Question 578: Which of the following will MOST likely compromise the contr...
Question 579: Which of the following is me GREATE ST impact as a result of...
Question 580: Which of the following would BEST reduce the risk of applica...
Question 581: Which of the following is the MOST important consideration w...
Question 582: Which of the following should be the FIRST step when plannin...
Question 583: Which of the following should be an IS auditor ' s GREATEST ...
Question 584: The following findings are the result of an IS auditor's pos...
Question 585: What would be an IS auditor ' s BEST course of action when a...
Question 586: What would be an IS auditor ' s BEST recommendation upon fin...
Question 587: Which of the following would be a result of utilizing a top-...
Question 588: Which of the following is MOST important to consider when re...
Question 589: Which of the following is MOST important for an IS auditor t...
Question 590: Which of the following should be the GREATEST concern to an ...
Question 591: Which of the following is MOST important for an IS auditor t...
Question 592: Which of the following should an IS auditor consider FIRST w...
Question 593: Which of the following is MOST important to include in secur...
Question 594: Which of the following MUST be performed by senior audit lea...
Question 595: An organization has decided to reengineer business processes...
Question 596: The use of which of the following would BEST enhance a proce...
Question 597: Which of the following provides the BEST evidence of the val...
Question 598: Which of the following responses to risk associated with seg...
Question 599: An IS auditor reviewing an organization's IT systems finds t...
Question 600: Which of the following is the BEST way to verify the effecti...
Question 601: An IS auditor is concerned that unauthorized access to a hig...
Question 602: Which of the following should be of GREATEST concern to an I...
Question 603: An IS auditor learns the organization has experienced severa...
Question 604: Documentation of workaround processes to keep a business fun...
Question 605: Which of the following would minimize the risk of losing tra...
Question 606: An IS auditor learns that a business owner violated the orga...
Question 607: Which of the following provides the MOST useful information ...
Question 608: Which of the following BEST enables an IS auditor to priorit...
Question 609: The PRIMARY role of a control self-assessment (CSA) facilita...
Question 610: Which of the following MOST effectively reduces the risk of ...
Question 611: Which of the following procedures for testing a disaster rec...
Question 612: Which of the following is the PRIMARY function of an interna...
Question 613: During recent post-implementation reviews, an IS auditor has...
Question 614: An IS auditor notes that IT and the business have different ...
Question 615: An IS auditor determines that the vendor ' s deliverables do...
Question 616: An IS auditor reviewing a job scheduling tool notices perfor...
Question 617: An outsourced recruitment vendor processes personally identi...
Question 618: Which of the following issues identified during a formal rev...
Question 619: Which of the following is the BEST way to ensure an organiza...
Question 620: Which of the following presents the GREATEST risk of data le...
Question 621: Which of the following is the PRIMARY objective of a control...
Question 622: When testing the accuracy of transaction data, which of the ...
Question 623: An IS auditor finds that a recently deployed application has...
Question 624: Which of the following is the PRIMARY purpose of conducting ...
Question 625: Which of the following is the MOST appropriate and effective...
Question 626: An IS auditor identifies that a legacy application to be dec...
Question 627: Which of the following is the BEST way for an IS auditor to ...
Question 628: Which of the following provides an IS auditor assurance that...
Question 629: When assessing the overall effectiveness of an organization ...
Question 630: An IS auditor is following up on prior period items and find...
Question 631: Which of the following BEST facilitates strategic program ma...
Question 632: The BEST way to evaluate the effectiveness of a newly develo...
Question 633: A firewall between internal network segments improves securi...
Question 634: An organization is planning to implement a work-from-home po...
Question 635: An organization has outsourced its data processing function ...
Question 636: Aligning IT strategy with business strategy PRIMARILY helps ...
Question 637: Which of the following is the BEST point in time to conduct ...
Question 638: Which of the following findings would be of GREATEST concern...
Question 639: Which of the following BEST indicates a need to review an or...
Question 640: During an information security review, an IS auditor learns ...
Question 641: Which of the following is the BEST metric to measure the qua...
Question 642: Which of the following is MOST important to ensure successfu...
Question 643: The PRIMARY purpose of a vulnerability assessment in a cyber...
Question 644: Which of the following findings should be of GREATEST concer...
Question 645: Due to system limitations, segregation of duties (SoD) canno...
Question 646: Which of the following technologies BEST assists in protecti...
Question 647: In an environment where data virtualization is used, which o...
Question 648: Which of the following is the PRIMARY reason for using a dig...
Question 649: Which of the following is the MOST important privacy conside...
Question 650: Visitors to a data center are required to present an ID and ...
Question 651: Management has requested a post-implementation review of a n...
Question 652: Which of the following is the PRIMARY reason to involve IS a...
Question 653: Which of the following will BEST ensure that a proper cutoff...
Question 654: The BEST way to provide assurance that a project is adhering...
Question 655: Which of the following is BEST supported by enforcing data d...
Question 656: Which of the following would BEST ensure that a backup copy ...
Question 657: Which of the following would the IS auditor MOST likely revi...
Question 658: Which of the following is the MOST important consideration w...
Question 659: Which of the following areas of responsibility would cause t...
Question 660: Which of the following provides the BEST assurance that a ne...
Question 661: Which of the following provides the BE ST method for maintai...
Question 662: Which of the following is MOST useful for determining the st...
Question 663: Which type of attack targets security vulnerabilities in web...
Question 664: Which of the following operational log management considerat...
Question 665: Which of the following is the BEST control to help ensure th...
Question 666: A new regulation in one country of a global organization has...
Question 667: Which of the following metrics BEST demonstrates the effecti...
Question 668: Which of the following is the MOST important regulatory cons...
Question 669: Which of the following is the BEST indication that an inform...
Question 670: Which of the following would be an IS auditor's GREATEST con...
Question 671: Which of the following is MOST important for an IS auditor t...
Question 672: Which of the following is MOST helpful to an IS auditor revi...
Question 673: Which of the following should be used as the PRIMARY basis f...
Question 674: Which of the following is the MOST important reason to imple...
Question 675: Which of the following is the BEST way to minimize sampling ...
Question 676: Which of the following is a PRIMARY benefit of using risk as...
Question 677: A characteristic of a digital signature is that it...
Question 678: When reviewing a business case for a proposed implementation...
Question 679: Which of the following indicates that an internal audit orga...
Question 680: Which of the following is MOST important for an IS auditor t...
Question 681: Which of the following BEST enables an IS auditor to confirm...
Question 682: Which of the following is the BEST source of information to ...
Question 683: Which of the following is the GREATEST benefit of adopting a...
Question 684: Management has learned the implementation of a new IT system...
Question 685: Which of the following is the PRIMARY function of a data los...
Question 686: Which of the following is the MOST important area of focus f...
Question 687: Which of the following should be the IS auditor ' s PRIMARY ...
Question 688: An IS auditor is conducting a physical security audit of a h...
Question 689: An IS auditor finds that application servers had inconsisten...
Question 690: Which of the following is the MOST effective way to maintain...
Question 691: Which of the following backup schemes is the BEST option whe...
Question 692: What should an IS auditor do FIRST when a follow-up audit re...
Question 693: In the development of a new financial application, the IS au...
Question 694: Which of the following presents the GREATEST risk to an orga...
Question 695: What should an IS auditor recommend to management as the MOS...
Question 696: One benefit of return on investment (ROI) analysts in IT dec...
Question 697: Which of the following provides the MOST useful information ...
Question 698: Which of the following would be an IS auditor ' s GREATEST c...
Question 699: When testing the adequacy of tape backup procedures, which s...
Question 700: An organization is concerned about duplicate vendor payments...
Question 701: Which of the following should be of GREATEST concern to an I...
Question 702: Which of the following should be the PRIMARY consideration w...
Question 703: An IS auditor is evaluating an enterprise resource planning ...
Question 704: A disaster recovery plan (DRP) should include steps for:...
Question 705: In order to be useful, a key performance indicator (KPI) MUS...
Question 706: Following a merger, a review of an international organizatio...
Question 707: Which of the following methods will BEST reduce the risk ass...
Question 708: Which of the following provides a new IS auditor with the MO...
Question 709: An IS auditor is evaluating the risk associated with moving ...
Question 710: Which of the following is the MOST appropriate indicator of ...
Question 711: When determining the quality of evidence collected during an...
Question 712: The operations team of an organization has reported an IS se...
Question 713: During an audit, the IS auditor finds that in many cases exc...
Question 714: An IS auditor discovers an option in a database that allows ...
Question 715: An organization has assigned two new IS auditors to audit a ...
Question 716: The BEST way to determine whether programmers have permissio...
Question 717: In a public key cryptographic system, which of the following...
Question 718: Which of the following is MOST important for an effective co...
Question 719: Which type of review is MOST important to conduct when an IS...
Question 720: An IS auditor performs a follow-up audit and learns the appr...
Question 721: Which of the following provides the BEST audit evidence that...
Question 722: Recovery facilities providing a redundant combination of Int...
Question 723: An organization has developed mature risk management practic...
Question 724: During the development of a business case for a new applicat...
Question 725: Which of the following provides the BEST providence that out...
Question 726: Which of the following backup methods is MOST appropriate wh...
Question 727: An IS auditor has identified deficiencies within the organiz...
Question 728: An IS auditor is reviewing a network diagram. Which of the f...
Question 729: Which of the following is a challenge in developing a servic...
Question 730: Which of the following should an IS auditor review FIRST whe...
Question 731: Which of the following is the MAJOR advantage of automating ...
Question 732: When assessing a proposed project for the two-way replicatio...
Question 733: Which of the following is the PRIMARY objective of performin...
Question 734: What is the PRIMARY benefit of an audit approach which requi...
Question 735: Which of the following is the MOST important success factor ...
Question 736: When information processing has been outsourced to another o...
Question 737: Which of the following job scheduling schemes for operating ...
Question 738: Audit frameworks cart assist the IS audit function by:...
Question 739: Which of the following should be done FIRST when planning a ...
Question 740: An IS auditor observes that a large number of departed emplo...
Question 741: A finance department has a two-year project to upgrade the e...
Question 742: Which of the following is the GREATEST risk associated with ...
Question 743: Which of the following is the PRIMARY reason that asset clas...
Question 744: Which of the following is the MOST important consideration w...
Question 745: Audit observations should be FIRST communicated with the aud...
Question 746: Which of the following documents should specify roles and re...
Question 747: Which of the following is MOST critical to the success of an...
Question 748: An organization is shifting to a remote workforce In prepara...
Question 749: Upon completion of audit work, an IS auditor should:...
Question 750: Transaction records from a business database were inadverten...
Question 751: Which of the following is the PRIMARY advantage of parallel ...
Question 752: Which type of attack poses the GREATEST risk to an organizat...
Question 753: Which of the following is a PRIMARY objective of incident ma...
Question 754: An IS auditor evaluating the change management process must ...
Question 755: What is the purpose of hashing a document?...
Question 756: An organization has developed processes to recover critical ...
Question 757: Which of the following is MOST important to ensure that elec...
Question 758: One advantage of managing an entire collection of projects a...
Question 759: An emergency power-off switch should:...
Question 760: An IS auditor is performing a follow-up audit and notes that...
Question 761: During planning for a cloud service audit, audit management ...
Question 762: Which of the following would be an appropriate role of inter...
Question 763: Which of the following BEST enables an organization to measu...
Question 764: What should an IS auditor evaluate FIRST when reviewing an o...
Question 765: Which of the following threats is mitigated by a firewall?...
Question 766: For an organization that has plans to implement web-based tr...
Question 767: Which of the following is the BEST indicator of the effectiv...
Question 768: An organization ' s IT risk assessment should include the id...
Question 769: Which of the following is the GREATEST advantage of maintain...
Question 770: The record-locking option of a database management system (D...
Question 771: Which of the following is the PRIMARY purpose of enterprise ...
Question 772: Which of the following would be the BEST process for continu...
Question 773: Which of the following is an example of shadow IT?...
Question 774: Which of the following is the BEST source of organizational ...
Question 775: An IS auditor learns that an organization did not conduct an...
Question 776: Which of the following is the MOST effective method of destr...
Question 777: Which of the following approaches BEST enables an IS auditor...
Question 778: Due to limited storage capacity, an organization has decided...
Question 779: Which of the following areas is MOST likely to be overlooked...
Question 780: Which of the following should be of MOST concern to an IS au...
Question 781: In which of the following system development life cycle (SDL...
Question 782: When designing a data analytics process, which of the follow...
Question 783: The implementation of an IT governance framework requires th...
Question 784: Which of the following BEST indicates the effectiveness of a...
Question 785: The IS quality assurance (OA) group is responsible for:...
Question 786: During the review of a system disruption incident, an IS aud...
Question 787: Which of the following is the PRIMARY objective of cyber res...
Question 788: An organization allows its employees lo use personal mobile ...
Question 789: Which of the following BEST demonstrates that IT strategy Is...
Question 790: Which of the following is the MAIN objective of enterprise a...
Question 791: An organization is implementing a new system that supports a...