Which of the following should be of GREATEST concern to an IS auditor reviewing an organization's business continuity plan (BCP)?
A. The BCP's contact information needs to be updated
B. The BCP is not version controlled.
C. The BCP has not been approved by senior management.
D. The BCP has not been tested since it was first issued.
An IS auditor is evaluating the progress of a web-based customer service application development project. Which of the following would be MOST helpful for this evaluation?
A. Backlog consumption reports
B. Critical path analysis reports
C. Developer status reports
D. Change management logs
Which of the following is the BEST way for management to ensure the effectiveness of the cybersecurity incident response process?
A. Periodic reporting of cybersecurity incidents to key stakeholders
B. Periodic update of incident response process documentation
C. Periodic cybersecurity training for staff involved in incident response
D. Periodic tabletop exercises involving key stakeholders
Which of the following areas of responsibility would cause the GREATEST segregation of duties conflict if the individual who performs the related tasks also has approval authority?
A. Purchase requisitions and purchase orders
B. Invoices and reconciliations
C. Vendor selection and statements of work
D. Good receipts and payments
Which of the following is the MOST important prerequisite for implementing a data loss prevention (DLP) tool?
A. Requiring users to save files in secured folders instead of a company-wide shared drive
B. Reviewing data transfer logs to determine historical patterns of data flow
C. Developing a DLP policy and requiring signed acknowledgment by users
D. Identifying where existing data resides and establishing a data classification matrix
An IS auditor reviewing a job scheduling tool notices performance and reliability problems. Which of the following is MOST likely affecting the tool?
A. Administrator passwords do not meet organizational security and complexity requirements.
B. The number of support staff responsible for job scheduling has been reduced.
C. The scheduling tool was not classified as business-critical by the IT department.
D. Maintenance patches and the latest enhancement upgrades are missing.
Which of the following is the BEST recommendation to drive accountability for achieving the desired outcomes specified in a benefits realization plan for an IT project?
A. Document the dependencies between the project and other projects within the same program.
B. Ensure that IT takes ownership for the delivery and tracking of all aspects of the benefits realization plan.
C. Ensure that the project manager has formal authority for managing the benefits realization plan.
D. Assign responsibilities, measures, and timelines for each identified benefit within the plan.
When planning a review of IT governance, an IS auditor is MOST likely to:
A. assess whether business process owner responsibilities are consistent.
B. obtain information about the control framework adopted by management.
C. examine audit committee minutes for IT-related controls.
D. define key performance indicators (KPIs).
Which of the following would be MOST useful to an IS auditor when making recommendations to enable continual improvement of IT processes over time?
A. Benchmarking studies
B. Maturity model
C. IT risk register
D. IT incident log
Which of the following findings should be an IS auditor's GREATEST concern when reviewing an organization's purchase of new IT infrastructure hardware?
A. The new infrastructure arrived with default system settings.
B. The new infrastructure has residual risk within the organization's risk tolerance.
C. The new infrastructure's hardening requirements are stronger than required by policy.
D. The new infrastructure has compatibility issues with existing systems.