An IS auditor has traced the source of a transaction fraud to the desktop system of an e-business staff member who is on leave. Which of the following is the BEST way for the auditor to ensure the success of the investigation?
An IS auditor reviewing the throat assessment for a data cantor would be MOST concerned if:
A sample for testing must include the 80 largest client balances and a random sample of the rest. What should the IS auditor recommend?
Which of the following would present the GREATEST concern during a review of internal audit quality assurance (QA) and continuous improvement processes?
Which of the following is the MOST cost-effective way to determine the effectiveness of a business continuity plan (BCP)?
The PRIMARY benefit lo using a dry-pipe fire-suppression system rather than a wet-pipe system is that a dry-pipe system:
An IS auditor learns that an in-house system development life cycle (SDLC) project has not met user specifications. The auditor should FIRST examine requirements from which of the following phases?
Which of the following is the GREATEST impact as a result of the ongoing deterioration of a detective control?
An IS auditor is reviewing the backup procedures in an organization that has high volumes of data with frequent changes to transactions. Which of the following is the BEST backup scheme to recommend given the need for a shorter restoration time in the event of a disruption?
Which of the following is the BEST data integrity check?
Which of the following controls is MOST crucial to ensure an organization will be able to recover its data from backup media in the event of a disaster?
Which of the following be of GREATEST concern to an IS auditor reviewing on-site preventive maintenance for an organization’s business-critical server hardware?
Which of the following is the GREATEST advantage of maintaining an internal IS audit function within an organization?
Which of the following should be an IS auditor ' s GREATEST concern when a data owner assigns an incorrect classification level to data?
Which of the following is the GREATEST concern related to an organization ' s data classification processes?
An IS auditor finds that an organization ' s data loss prevention (DLP) system is configured to use vendor default settings to identify violations. The auditor ' s MAIN concern should be that:
An IT governance body wants to determine whether IT service delivery is based on consistently effective processes. Which of the following is the BEST approach?
Job scheduling impacts system availability and reliability by:
Which of the following should be an IS auditor ' s GREATEST concern when evaluating an organization ' s ability to recover from system failures?
Which of the following is the MOST important consideration when evaluating the data retention policy for a global organization with regional offices in multiple countries?
An IS auditor Is renewing the deployment of a new automated system Which of the following findings presents the MOST significant risk?
Which of the following BEST ensures the quality and integrity of test procedures used in audit analytics?
When classifying information, it is MOST important to align the classification to:
An IS auditor is assessing backup performance and observes that the system administrator manually initiates backups during unexpected peak usage. Which of the following is the auditor ' s BEST course of action?
The PRIMARY objective of value delivery in reference to IT governance is to:
When reviewing a project to replace multiple manual data entry systems with an artificial intelligence (Al) system, the IS auditor should be MOST concerned with the impact Al will have on
Controls related to authorized modifications to production programs are BEST tested by:
Who is accountable for an organization ' s enterprise risk management (ERM) program?
Which of the following is MOST likely to be reduced when implementing optimal risk management strategies?
Which of the following is MOST important for an effective control self-assessment (CSA) program?
Using swipe cards to limit employee access to restricted areas requires implementing which additional control?
The decision to accept an IT control risk related to data quality should be the responsibility of the:
A financial accounting system audit determined that audit logging of transactions had been disabled by a finance employee. The IS auditor recommended that finance personnel no longer have the capability to change audit logging settings. Which of the following is MOST important to verify during the follow-up?
An IS auditor discovers that due to resource constraints a database administrator (DBA) is responsible for developing and executing changes into the production environment Which ot the following should the auditor do FIRSTS
Which of the following security testing techniques is MOST effective for confirming that inputs to a web application have been properly sanitized?
What would be an IS auditor ' s BEST course of action when an auditee is unable to close all audit recommendations by the time of the follow-up audit?
An organization has recently become aware of a pervasive chip-level security vulnerability that affects all of its processors. Which of the following is the BEST way to prevent this vulnerability from being exploited?
Which of the following provides the BE ST method for maintaining the security of corporate applications pushed to employee-owned mobile devices?
An IS auditor wants to determine who has oversight of staff performing a specific task and is referencing the organization ' s RACI chart. Which of the following roles within the chart would provide this information?
How is nonrepudiation supported within a public key infrastructure (PKI) environment?
Which of the following is MOST important to consider when defining disaster recovery strategies?
Which of the following is an executive management concern that could be addressed by the implementation of a security metrics dashboard?
Which of the following environments is BEST used for copying data and transformation into a compatible data warehouse format?
An organization has outsourced its data processing function to a service provider. Which of the following would BEST determine whether the service provider continues to meet the organization s objectives?
Which of the following is an IS auditor ' s BEST recommendation to protect an organization from attacks when its file server needs to be accessible to external users?
The PRIMARY goal of capacity management is to:
An organization is establishing a steering committee for the implementation of a new enterprise resource planning (ERP) system that uses Agile project management methodology. What is the MOST important criterion for the makeup of this committee?
When planning an internal penetration test, which of the following is the MOST important step prior to finalizing the scope of testing?
Retention periods and conditions for the destruction of personal data should be determined by the.
An organization is disposing of a system containing sensitive data and has deleted all files from the hard disk. An IS auditor should be concerned because:
TESTED 10 Sep 2026