Courseiva

CISA · domain

scenario questions

Practise Certified Information Systems Auditor CISA scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

995 questions257 easy433 medium305 hard

Focused practice

Practice scenario questions questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about scenario questions

scenario questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common scenario questions exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All scenario questions questions (995)

Click any question to see the full explanation, or start a practice session above.

1

During a build vs. buy analysis, the IS auditor observes that the organization decided to build a custom application because no vendor solution met all requirements. Which of the following risks should the auditor emphasize?

Medium
2

An organization is implementing a privacy program to comply with GDPR. Which THREE of the following are essential elements for managing cross-border data transfers?

Hard
3

A multinational company must comply with GDPR and local data protection laws when transferring personal data from the EU to a subsidiary in the US. Which transfer mechanism is most commonly accepted as providing adequate protection?

Hard
4

An online retail company runs its e-commerce platform on a virtualized infrastructure with 50 virtual servers. The platform experiences intermittent slowdowns during peak hours, and recent monitoring reports show that disk I/O latency on the storage area network (SAN) frequently exceeds 50 ms during these periods. The SAN has two fabric switches and a single storage array with 12 TB of usable capacity, currently at 80% utilization. The company’s disaster recovery plan requires recovery point objective (RPO) of 1 hour and recovery time objective (RTO) of 4 hours for the e-commerce platform. During a recent test failover to the disaster recovery site, the IT team discovered that the replication link between primary and DR sites is saturated, causing replication lag of up to 3 hours. The team also noted that the DR site storage has only 6 TB of usable capacity, now at 60% utilization. The IT manager is concerned about meeting the RPO and RTO. Which course of action should the IT team take first?

Hard
5

A company is using an agile development methodology for a critical business application. The IS auditor is concerned about the lack of formal documentation. What is the BEST approach to mitigate this risk?

Medium
6

A large organization is implementing a new HR management system to handle payroll and employee data. The project is currently in the build phase with a planned go-live in three months. Recently, the vendor notified the project team that a critical security patch will be released in two months that addresses a data leakage vulnerability present in the current version. The patch includes new features that are not in the contract. The project manager estimates that integrating the patch and re-testing will delay the project by at least four months. Business stakeholders insist on meeting the original go-live date because the legacy system is being decommissioned. The organization has a strict policy that all systems processing sensitive data must have the latest security patches within 30 days of release. What should the project team do?

Medium
7

An IS auditor is reviewing the audit follow-up process. The auditor notes that management has implemented corrective actions for 80% of previous audit findings. What should the auditor conclude?

Medium
8

A company is developing a mobile banking application. Which test phase is MOST critical to ensure that the application functions correctly from the end user's perspective?

Easy
9

An organization uses automated job scheduling for nightly batch processing. One job fails due to a missing dependency file. What is the most effective control to prevent recurrence?

Easy
10

An IS auditor is performing a walkthrough of a purchase-to-pay process. The auditor selects a sample of purchase orders and traces them through the system to verify that controls are properly designed and implemented. This is an example of:

Hard
11

During a review of firewall rule sets, an IS auditor finds a rule that allows any source IP to access any destination IP on TCP port 443. Which of the following should the auditor do FIRST?

Medium
12

Refer to the exhibit. A CISA is analyzing these logs. What is the MOST likely security incident?

Hard
13

An IS auditor finds that a control deficiency could lead to a material misstatement if combined with another deficiency. How should this be classified?

Hard
14

An IS auditor is evaluating the security of the architecture. Which of the following is the MOST critical finding?

Medium
15

An IT auditor is reviewing the policy hierarchy of an organization. Which of the following correctly describes the relationship between a policy and a procedure?

Hard
16

An organization is implementing a cloud resource management strategy to optimize costs and prevent waste. Which three practices should the auditor recommend?

Hard
17

Match each regulatory standard to its focus area.

Medium
18

An IS auditor is performing a compliance audit of data privacy regulations. The auditor finds that the organization's privacy policy is not fully aligned with regulatory requirements. Which of the following is the auditor's BEST course of action?

Hard
19

An IS auditor is conducting an audit of a small manufacturing company's IT operations. The company has 50 employees and uses a single server running Windows Server 2019 for file sharing and print services. There is no formal change management process. The IT manager, who also doubles as the system administrator, has full administrative rights and is the only person who can make changes to the server. During the audit, the auditor notices that the server's local security policy is configured to allow unlimited password attempts and no account lockout. The IT manager states that this is to avoid locking out users who forget their passwords. The auditor also finds that the guest account is enabled on the server. What should the auditor recommend as the HIGHEST priority action?

Easy
20

A financial institution operates a critical payment processing system that must maintain 99.999% availability. The system is deployed across two data centers in active-active mode with load balancing. During a routine maintenance window, a network misconfiguration caused all traffic to be directed to one data center, which then became overloaded and crashed, resulting in 30 minutes of downtime. The incident response team wants to prevent recurrence. Which of the following is the BEST action?

Medium
21

An organization uses a hot site for disaster recovery. During a recent test, the hot site did not have the latest version of the application software. What is the MOST likely cause?

Medium
22

Which is the MOST likely cause?

Easy
23

An organization's IT security policy requires that all employees complete annual security awareness training. An auditor notes that completion rate is only 60%. What is the MOST effective way to monitor compliance?

Medium
24

An IS auditor is reviewing the balanced scorecard for IT. Which of the following metrics BEST aligns with the 'customer perspective'?

Hard
25

What is the primary purpose of a chargeback model for IT services?

Medium
26

An IS auditor is planning an audit of an organization's IT infrastructure. Which of the following is the PRIMARY benefit of using a risk-based approach?

Easy
27

An IS auditor is reviewing the process for granting privileged access in a large organization. Which of the following findings should be of MOST concern?

Medium
28

During a business impact analysis (BIA), a department manager states that their process can be disrupted for up to 8 hours, but data loss cannot exceed 15 minutes. Which two metrics are defined by these statements?

Hard
29

An information systems auditor is evaluating user accounts in an organization's Linux environment. The accounts have the following properties: - The 'root' account has its password field set to '!!' (disabled). - The 'admin' account has its password field set to '!' (locked) and UID 0. - The 'test' account is a regular user with UID 1000. Based on this information, which user account poses the HIGHEST security risk?

Medium
30

An IS auditor reviews the log entry above. Which of the following is the MOST likely cause of the authentication failure?

Hard
31

An organization is implementing ITIL 4. Which TWO of the following are part of the four dimensions of service management? (Select TWO.)

Medium
32

Which TWO of the following are primary objectives of capacity management? (Select exactly 2.)

Medium
33

Which of the following is the PRIMARY purpose of conducting a penetration test?

Easy
34

An organization's business continuity plan (BCP) includes alternate facilities that can be operational within 24 hours. The maximum tolerable downtime (MTD) for a critical process is 12 hours. What is the most significant gap?

Medium
35

An organization uses a cloud-based CRM system. The asset management team has implemented tagging to track resource costs by department. During an audit, the IS auditor finds that several orphaned resources (e.g., virtual machines, storage volumes) exist that are not tagged and have been running for months. The cloud service provider's cost allocation report shows these resources under a default account. What is the most significant risk associated with this finding?

Hard
36

An organization has implemented a role-based access control (RBAC) system. A user complains that they cannot access a file needed to complete a critical task. The file's permission indicates that only the 'Manager' role has read access. The user is assigned to the 'Analyst' role. Which of the following is the BEST course of action?

Hard
37

A multinational manufacturing company with operations in 20 countries has historically allowed each regional division to manage its own IT systems independently. Recently, the company experienced a significant data breach originating from a region with weaker security controls, leading to financial losses and reputational damage. The board has mandated stronger IT governance to prevent future incidents. The CIO proposes implementing a global IT governance framework with centralized policy enforcement. However, regional directors argue that local regulations and business needs require autonomy. The governance committee must decide on a course of action that balances risk and business flexibility. Which of the following approaches is the MOST appropriate?

Hard
38

An IS auditor is reviewing a post-implementation review report for a new financial system. Which finding would most indicate that the project did not meet its objectives?

Medium
39

Which of the following is the BEST example of an analytical procedure used during an IS audit?

Medium
40

Given this configuration, which is the PRIMARY concern?

Medium
41

An organization is evaluating a cloud-based identity as a service (IDaaS) for single sign-on (SSO). Which of the following security concerns is MOST critical to address?

Hard
42

An organization's backup strategy includes taking full backups weekly and transactional log backups every 15 minutes. The auditor wants to verify that backup encryption is implemented for offsite storage. Which control is most relevant?

Hard
43

Which type of change in ITIL requires approval from the Change Advisory Board (CAB) before implementation?

Easy
44

A company has multiple business units with conflicting IT priorities. Which governance body should resolve this?

Medium
45

Based on the exhibit, what should the IS auditor MOST likely recommend?

Hard
46

Which TWO of the following are primary objectives of an information system audit?

Easy
47

Which of the following is the PRIMARY purpose of conducting a privacy impact assessment (PIA)?

Easy
48

Refer to the exhibit. A security administrator is troubleshooting why external users cannot reach the web server at 203.0.113.10 from the internet. Based on the configuration, what is the MOST likely issue?

Hard
49

A medium-sized retail company relies on an ERP system for order processing and inventory management. The system is hosted on-premises with daily backups stored on tape. The company's business continuity plan specifies an RTO of 4 hours and an RPO of 1 hour for the ERP system. During a recent fire drill, it was discovered that restoring the ERP system from tape took over 6 hours, and the most recent backup was from the previous day. Which of the following is the BEST course of action to meet the RTO and RPO goals?

Easy
50

An organization uses role-based access control (RBAC) for its enterprise resource planning (ERP) system. What is the greatest risk if user role assignments are not reviewed regularly?

Medium
51

An organization is selecting a key performance indicator (KPI) to measure the effectiveness of its patch management process. Which of the following is the MOST appropriate KPI?

Medium
52

During a security audit, it is discovered that a database containing customer credit card numbers is not encrypted at rest. The database is used by a legacy application that cannot be modified. Which compensating control most effectively reduces the risk?

Medium
53

An organization is planning a full interruption test of its disaster recovery plan. Which THREE of the following should the IS auditor recommend as best practices for this type of test? (Select three.)

Hard
54

Which TWO of the following are common objectives of an IT balanced scorecard? (Choose two.)

Easy
55

During the requirements gathering phase for a new financial system, stakeholders disagree on the priority of security controls versus user convenience. Which of the following is the BEST approach?

Medium
56

An organization has implemented role-based access control (RBAC). Which of the following is the PRIMARY benefit of RBAC?

Easy
57

A hospital is implementing a new electronic health records (EHR) system. The system will be used by doctors, nurses, and administrative staff. During the user acceptance testing (UAT) phase, the nursing staff reports that the interface for entering patient vitals is too slow and requires many clicks, which slows down their workflow. The project team has already completed system testing and is preparing for go-live in two weeks. The development team can make a quick fix to streamline the vital signs entry by adding a shortcut, but this change has not been tested. The IT director is concerned about patient safety and wants to ensure the system is usable. What is the BEST course of action?

Medium
58

When an organization uses an external provider to manage its IT help desk, this is an example of which sourcing model?

Medium
59

An organization is implementing a new customer relationship management (CRM) system using an agile methodology. Which THREE areas should the IS auditor focus on to assess the effectiveness of controls during the development process?

Medium
60

An organization is considering outsourcing its IT help desk. Which of the following is a key risk that should be addressed in the outsourcing contract?

Medium
61

Which TWO of the following are essential components of an effective incident response plan? (Select exactly 2.)

Medium
62

Which of the following is a key control in the deployment phase of the SDLC?

Easy
63

During an ERP implementation, the project team decides to disable segregation of duties (SoD) controls in the system to accelerate go-live. After go-live, the IS auditor identifies that a single user can perform incompatible functions. What is the BEST course of action?

Hard
64

A multinational corporation is deploying a data loss prevention (DLP) solution across its network. The DLP system must be configured to prevent the exfiltration of personally identifiable information (PII) while minimizing false positives. Which approach is most effective?

Hard
65

A large enterprise recently experienced a data breach due to an insider threat. The IT governance committee is reviewing the incident and considering measures to prevent recurrence. Which of the following is the BEST course of action to address the root cause?

Medium
66

An organization uses a standard change model for low-risk, pre-approved changes. Which of the following is an example of a standard change?

Medium
67

In a spiral SDLC model, what is the primary purpose of risk analysis in each iteration?

Easy
68

An organization is migrating from a legacy system to a new ERP. Which TWO of the following are the HIGHEST risks during data migration?

Medium
69

A systems analyst is gathering requirements for a new customer relationship management (CRM) system. Which of the following is the MOST important activity to ensure that the final system meets user needs?

Easy
70

Which TWO of the following are components of audit risk in the ISACA risk model? (Select TWO.)

Easy
71

According to ISACA IT Audit Standards, which of the following is the primary purpose of audit documentation (working papers)?

Easy
72

An organization plan to integrate a third-party payment gateway into its e-commerce platform. Which of the following is the MOST critical security control to implement before going live?

Hard
73

Arrange the steps to implement a password policy in the correct order.

Medium
74

During a third-party software vendor audit, the IS auditor discovers that the vendor uses a common shared database for multiple clients and relies on application-level access controls. Which of the following is the GREATEST concern?

Hard
75

An organization is implementing a public key infrastructure (PKI) to issue digital certificates for internal applications. Which THREE of the following are essential elements of PKI governance that an IS auditor should review?

Hard
76

An organization uses shared accounts for system administration. Which of the following is the MOST significant audit concern?

Medium
77

An IS auditor is reviewing the organization's incident management process. Which THREE of the following are essential components of an effective incident response plan?

Hard
78

Which of the following is an example of a detective control in the SDLC testing phase?

Medium
79

An IT auditor is reviewing the business continuity plan (BCP) testing schedule. The organization conducts a test where participants discuss their roles and responses to a scenario without any actual system activation. Which type of test is this?

Easy
80

An IS auditor reviews the exhibit during an audit of database controls. What is the most appropriate recommendation?

Medium
81

An organization is implementing a change management process. A change that requires approval from the Change Advisory Board (CAB) but is scheduled to be implemented during the next maintenance window is classified as which type of change?

Hard
82

Which TWO of the following are key components of an IT governance framework?

Medium
83

In a RACI matrix for the change management process, who is typically Accountable for the overall change process?

Hard
84

An IS auditor is reviewing a vendor's SOC 2 report as part of a systems acquisition. Which TWO aspects should the auditor verify to ensure the report is reliable?

Medium
85

An IT steering committee is reviewing a proposed project to migrate critical applications to the cloud. Which of the following is the PRIMARY role of the IT steering committee in this decision?

Medium
86

Which TWO of the following are key components of an IT governance framework? (Choose two.)

Easy
87

An organization is implementing COBIT 2019. Which TWO of the following are governance enablers? (Choose two.)

Medium
88

An IS auditor is reviewing change management procedures. Which of the following situations would be of GREATEST concern?

Medium
89

Which human resource control is PRIMARILY intended to detect fraud in IT operations?

Easy
90

In a RACI matrix for an IT change management process, who is responsible for performing the change?

Easy
91

A financial institution is evaluating its IT governance structure. Which of the following roles is BEST suited to ensure independent oversight of IT investments?

Medium
92

Based on the exhibit, what is the security risk of this bucket policy?

Easy
93

An IS auditor is evaluating the effectiveness of an organization's business continuity plan (BCP). Which of the following findings would be of GREATEST concern?

Easy
94

An organization wants to ensure that IT performance is measured against strategic goals. Which tool is BEST suited?

Easy
95

An IT auditor is reviewing the change management process for a financial application. The auditor finds that emergency changes are frequently implemented without post-implementation review. What is the MOST significant risk?

Medium
96

An organization's IT governance committee is reviewing a proposal to use a public cloud provider that does not meet the organization's data encryption standards. The board has set a low risk appetite for data privacy. What is the BEST action?

Hard
97

An auditor finds that access reviews have not been completed for two quarters. What is the MOST significant risk?

Hard
98

An IS auditor is selecting an appropriate audit sample. Which THREE of the following are factors that affect the sample size?

Medium
99

A company is implementing a new procurement system. The project team is considering using a rapid application development (RAD) methodology. Which of the following is a potential risk of using RAD?

Medium
100

Which THREE of the following are components of the COBIT 2019 governance system?

Hard
101

An IT auditor is reviewing the asset management process for hardware lifecycle. Which two controls should the auditor verify to ensure secure disposition of decommissioned servers?

Medium
102

An IS auditor is assessing the controls in an agile development environment. What is the MOST effective way to verify that security testing is performed iteratively?

Medium
103

Match each encryption key type to its usage.

Medium
104

An IS auditor is evaluating the effectiveness of a control. The auditor observes the control being performed and then independently performs the same control to confirm the result. Which combination of evidence types is being used?

Hard
105

An organization is negotiating a contract with a cloud service provider. Which clause is most important for the IS auditor to ensure is included?

Easy
106

During a change advisory board (CAB) meeting, a proposed change to the database server is discussed. The change involves implementing a security patch that requires a reboot. The change is categorized as 'normal' and has been risk-assessed as low impact. What is the most likely role of the CAB in this scenario?

Medium
107

An IS auditor is evaluating the capacity management process. The auditor notices that CPU utilization has been consistently above 90% for the past three months. The IT manager states that no proactive capacity planning has been performed. What is the primary risk?

Medium
108

An organization is deciding between building a custom application and purchasing a commercial off-the-shelf (COTS) product. The primary factor favoring the build option is:

Hard
109

A financial institution recently experienced a data breach where an attacker exfiltrated customer data through an SQL injection vulnerability in a web application. The IS auditor has been asked to review the application security controls. The web application is developed in-house and runs on an application server behind a web application firewall (WAF). The auditor reviews the WAF logs and finds that no SQL injection attacks were detected before the breach, but the logs show many blocked XSS attempts. The developer states that all input validation is performed on the client side using JavaScript. During the audit, the auditor also finds that the application uses a shared database account with DBA privileges for all connections. What is the MOST significant weakness that directly contributed to the breach?

Medium
110

Which of the following audit types is performed by an independent third-party auditor and is typically required for regulatory compliance?

Easy
111

An organization outsources its data center operations to a third-party provider. Which of the following is the MOST important clause to include in the contract to ensure the organization can verify the provider's controls?

Medium
112

An organization is deciding between developing a custom application and purchasing a commercial off-the-shelf (COTS) product. The project manager favors a COTS solution because it offers faster deployment. Which of the following is the MOST important consideration for the IS auditor to evaluate in this build vs. buy decision?

Hard
113

An organization is selecting a disaster recovery (DR) site. The primary data center is located in a region prone to earthquakes. The DR site should be at a sufficient distance to avoid the same disaster. Which type of alternate site provides the best balance of cost and recovery time for a medium-sized organization?

Hard
114

Which of the following is a key control during the deployment phase of a system development life cycle?

Easy
115

During the planning phase of an IS audit, which of the following is the PRIMARY purpose of conducting a risk assessment?

Easy
116

During an information systems audit, the IS auditor finds that data classification labels are not consistently applied across the organization. What is the most likely root cause of this issue?

Hard
117

During a disaster recovery test, the recovery time objective (RTO) for a critical application was not met. Which of the following is the MOST likely cause?

Easy
118

An IS auditor is assessing network security controls. Which TWO of the following are key elements of a firewall rule review?

Medium
119

A large financial institution is evaluating the effectiveness of its IT governance framework. The board has requested a review to ensure alignment with business objectives and regulatory requirements. Which of the following is the MOST important factor for the board to consider when assessing the IT governance framework?

Medium
120

Refer to the exhibit. An auditor finds that the file 'sensitive.txt' has world-writable permissions. Which of the following is the most appropriate remediation action?

Easy
121

An IT steering committee is evaluating a proposal to migrate critical applications to the cloud. Which factor is MOST important to ensure alignment with business strategy?

Medium
122

In business continuity planning, a company identifies a critical business process with a maximum tolerable downtime (MTD) of 4 hours. What is the primary purpose of this metric?

Easy
123

An organization is migrating data from a legacy system to a new ERP. What is the most critical data migration risk?

Medium
124

According to ISACA IT Audit Standards, which phase of the audit process includes the development of an audit programme?

Easy
125

Based on the exhibit, what is the MOST likely compliance issue requiring immediate remediation?

Hard
126

During a post-implementation review of a new accounting system, the IS auditor notes the following: the project was completed on time and within budget, but user satisfaction is low and there are several outstanding defect reports. Which THREE of the following are the MOST appropriate recommendations?

Hard
127

Refer to the exhibit. Based on the governance status report, which component should be addressed as a priority?

Easy
128

Which TWO of the following are components of audit risk in IS auditing?

Medium
129

An organization's online transaction processing system experienced a sudden performance degradation. The database administrator checked system resources and found excessive I/O wait time on the storage subsystem. Which of the following is the MOST likely root cause?

Medium
130

Which THREE of the following are common techniques for ensuring business resilience?

Hard
131

A compliance audit is primarily concerned with:

Easy
132

An organization uses automated job scheduling for batch processing. A critical job fails due to a dependency on another job that has not completed. Which of the following controls would BEST prevent this issue?

Medium
133

A healthcare organization must comply with HIPAA regulations regarding patient data privacy. The IT department has implemented technical controls, but the compliance officer discovers that some employees are sharing passwords. What is the BEST governance response?

Easy
134

Which TWO of the following are examples of IT governance frameworks? (Select TWO.)

Easy
135

During an audit of network security controls, the IS auditor reviews firewall rule sets and identifies a rule that allows any-to-any traffic from the internal network to the Internet. The rule has a business justification. What is the auditor's BEST recommendation?

Hard
136

A company is integrating a third-party payment gateway into its e-commerce platform. Which of the following is the MOST important security control to implement?

Medium
137

A medium-sized manufacturing company has recently deployed an ERP system to integrate its financial, supply chain, and HR processes. The IT department is small (5 staff) and reports to the CFO. The company has no formal IT governance committee; IT decisions are made by the CFO and CEO informally. During a recent audit, it was found that several critical security patches for the ERP system have not been applied, and there are no documented procedures for change management. The IT manager states that patches are applied when time permits, and changes are discussed via email. The CFO argues that the ERP is running fine and the audit findings are low risk. The IS auditor needs to recommend a course of action to improve IT governance. Which of the following is the MOST appropriate initial step?

Easy
138

Match each COBIT 5 domain to its description.

Medium
139

Refer to the exhibit. An IS auditor finds this bucket policy attached to an S3 bucket storing sensitive customer data. What should the auditor recommend?

Medium
140

Refer to the exhibit. An IS auditor is reviewing firewall logs and notices repeated denied SSH attempts from an internal host (10.0.1.50) to a server (172.16.0.1). After the denied attempts, the host initiates permitted HTTPS connections to another server (172.16.0.5). Which of the following is the BEST interpretation of this pattern?

Medium
141

A small e-commerce company uses a cloud-based e-commerce platform with automatic scaling. The company's business continuity plan relies on the cloud provider's promise of 99.99% uptime. During a regional outage affecting the cloud provider's primary availability zone, the company's website became unavailable for 2 hours, resulting in lost sales. The IT manager wants to improve resilience. Which of the following is the BEST action?

Easy
142

An organization is developing a business continuity strategy. According to best practices, which THREE of the following should be included in the strategy?

Medium
143

During an audit of a financial application, the IS auditor discovers that user access reviews are performed quarterly instead of monthly as required by policy. Which of the following is the BEST initial action for the auditor?

Medium
144

Which of the following is the BEST indicator that an organization's data security governance is effective?

Hard
145

An IS auditor is reviewing an emergency change that was implemented to fix a critical security vulnerability. What is the most important post-implementation step?

Hard
146

Which of the following are COBIT 2019 management objectives?

Hard
147

Which of the following is a key component of an IT balanced scorecard from the 'internal process' perspective?

Medium
148

An organization's IT governance framework includes a policy that all system access must be reviewed quarterly. The internal audit finds that reviews are incomplete. What is the BEST action?

Medium
149

A project manager is selecting a development methodology for a project with well-defined requirements and low uncertainty. Which methodology is most appropriate?

Easy
150

During an audit of a healthcare organization's information security program, the IS auditor finds that the security awareness training is conducted only at hire. Which of the following is the MOST significant risk associated with this practice?

Medium
151

An organization is implementing a custom ERP system. During user acceptance testing (UAT), critical bugs are found that affect core financial processing. The project sponsor suggests deploying the system on schedule and fixing bugs after go-live. What is the BEST course of action?

Medium
152

During a system deployment, the above error occurs. What is the MOST likely cause?

Medium
153

Which ITIL 4 guiding principle emphasizes understanding the current state and building on existing capabilities rather than starting from scratch?

Medium
154

Which TWO of the following are essential components of a disaster recovery plan (DRP)?

Easy
155

An organization is developing a business continuity strategy for its key customer-facing application. The BIA determined an RTO of 2 hours and an RPO of 30 minutes. Which TWO strategies are most appropriate to meet these objectives?

Medium
156

An IT department is structured with a central group that manages infrastructure and security, while business units have their own IT staff for application support. This is an example of which IT organizational structure?

Medium
157

Which type of disaster recovery test involves actually switching over to the alternate site and processing live transactions, but does not require the primary site to be shut down?

Easy
158

According to ISO/IEC 38500, a board member insists on approving all IT acquisitions above a certain threshold. Which principle of corporate governance of IT does this support?

Hard
159

During an audit of patch management, the IS auditor notes that several critical patches have not been applied within the defined SLA. Which of the following is the BEST approach to evaluate the risk acceptance of these unpatched vulnerabilities?

Hard
160

An organization is implementing a data loss prevention (DLP) solution. Which of the following is the BEST approach to minimize false positives while ensuring sensitive data is protected?

Medium
161

An organization is considering whether to build a custom application or purchase a commercial off-the-shelf (COTS) product. Which of the following factors would most strongly support a build decision?

Medium
162

An IS auditor is reviewing the process for granting access to a critical financial system. The auditor finds that access requests are approved by the system owner but there is no segregation between the request and approval functions for emergency access. Which of the following is the BEST control to mitigate this risk?

Medium
163

An organization uses shared accounts for system administration. Which of the following is the BEST control to mitigate the risk of non-repudiation?

Medium
164

Which TWO of the following are indicators that an IS auditor may need to adjust the audit approach during fieldwork? (Select TWO.)

Hard
165

An IS auditor is performing a compliance audit of a company's data privacy practices. Which type of evidence would be most appropriate to verify that employees have completed mandatory privacy training?

Medium
166

An organization is evaluating a vendor for a custom application development. The vendor states they are assessed at CMMI Level 2 (Managed). Which of the following best describes the implication of this rating?

Medium
167

An organization is adopting agile development methodology. Which control is MOST critical to ensure security is integrated?

Hard
168

A company is developing a custom application. During the requirements phase, the project manager documents that the system must encrypt all sensitive data at rest. Which of the following is the BEST control to ensure this requirement is met throughout the development lifecycle?

Easy
169

An organization has implemented a security awareness training program. Which of the following metrics would BEST indicate that the program is effective?

Easy
170

An IS auditor is assessing the risk of fraud in a financial system. Which combination of audit risk components is most directly relevant?

Hard
171

Which of the following is the BEST control to ensure that system changes are authorized?

Easy
172

An IS auditor is reviewing the logical access controls for a critical financial application. Which of the following is the MOST important control to ensure that user access rights remain appropriate over time?

Easy
173

An organization uses a public key infrastructure (PKI) to issue digital certificates. The IS auditor is reviewing the certificate lifecycle management. Which of the following is the GREATEST risk if certificate revocation lists (CRLs) are not updated in a timely manner?

Medium
174

An IT balanced scorecard for a retail company shows that the percentage of IT projects delivered on time has decreased from 85% to 70%. Which perspective of the balanced scorecard is MOST directly affected?

Medium
175

An organization is implementing a key management program to protect encryption keys. Which of the following is the MOST important control to ensure the security of cryptographic keys?

Easy
176

Based on the exhibit, what is the MOST likely security risk?

Medium
177

During a vendor audit, an IS auditor discovers that a cloud service provider uses subcontractors to manage data storage. The contract does not mention subcontracting. Which THREE risks should the auditor highlight to management?

Hard
178

During an IS audit, the auditor finds that a control deficiency could result in a material misstatement. According to ISACA standards, this should be classified as:

Medium
179

Scenario: A mid-sized manufacturing company has recently experienced a significant IT outage that halted production for 8 hours. The root cause was a failed firmware update on a core switch that was performed outside the change management process by a senior network engineer who claimed the update was urgent to patch a critical vulnerability. The company has a well-documented change management policy that requires all changes to be reviewed by the change advisory board (CAB) before implementation, except for emergency changes which require post-implementation review within 48 hours. The engineer did not follow the emergency change process; he implemented the update directly. The IT director wants to prevent such incidents in the future. Which of the following is the BEST action?

Hard
180

You are an IS auditor for a financial institution that processes credit card payments. The organization uses a key management system (KMS) to store encryption keys for point-of-sale (POS) data. The KMS is a hardware security module (HSM) located in a secured data center. The audit reveals that the HSM is administered by two individuals who both have full access to the HSM, including the ability to export keys. The organization has a policy requiring split knowledge and dual control for key management, but in practice, the two administrators often perform key ceremonies alone due to scheduling conflicts. The logs show that one administrator exported a key last month without the other present, and the export was approved via email by the other administrator after the fact. Which of the following is the BEST corrective action?

Medium
181

An IS auditor is reviewing problem management processes. Which TWO of the following are key outputs of effective problem management? (Select two.)

Easy
182

During a business impact analysis (BIA), the auditor identifies a critical process with a maximum tolerable downtime (MTD) of 4 hours. The IT department proposes a recovery time objective (RTO) of 2 hours and a recovery point objective (RPO) of 1 hour. Which statement is correct?

Medium
183

During an audit of a public key infrastructure (PKI), the IS auditor finds that certificate revocation lists (CRLs) are only updated weekly. Which of the following is the MOST significant risk?

Hard
184

Which TWO of the following are benefits of an iterative SDLC approach compared to waterfall? (Select two.)

Medium
185

A company is migrating its customer database to a public cloud provider. Which of the following encryption strategies best protects data while minimizing performance impact on queries?

Hard
186

A healthcare organization is required to comply with HIPAA regulations for protecting electronic protected health information (ePHI). The organization uses a cloud-based electronic health record (EHR) system. During a compliance audit, it is discovered that some employees are accessing patient records without a legitimate business need. The EHR system logs all access, but there is no automated process to review logs or detect anomalous behavior. The organization has implemented role-based access control (RBAC) and requires strong passwords, but unauthorized access continues. The IT manager proposes implementing a security information and event management (SIEM) system to collect and correlate logs. However, the budget is limited. Which additional control would be most cost-effective to reduce unauthorized access to patient records?

Medium
187

A company's security policy requires that all laptops have full disk encryption. During an audit, it is discovered that several laptops have encryption enabled but the recovery keys are stored on the local drive. What is the MOST significant risk?

Easy
188

During an audit of an organization's disaster recovery plan (DRP), the IS auditor finds that the plan was last tested 18 months ago and no test results were documented. What should the auditor recommend?

Medium
189

A multinational corporation has implemented a hot site disaster recovery solution for its critical financial applications. Which of the following is the MOST important consideration to ensure the effectiveness of the hot site?

Hard
190

During an audit, the auditor identifies a control deficiency that could result in a material misstatement. According to ISACA guidelines, this is classified as:

Medium
191

Which of the following is the PRIMARY objective of a post-implementation review of an information system?

Easy
192

Which of the following is the PRIMARY reason for an external IS audit to be more independent than an internal audit?

Easy
193

An IS auditor is assessing the data inventory of a financial institution to ensure compliance with privacy regulations. Which TWO of the following are essential elements that should be included in the data inventory?

Medium
194

Arrange the steps to set up a virtual private network (VPN) for remote access in the correct order.

Medium
195

According to ISACA IT Audit Standards, which of the following is a key requirement for audit documentation?

Easy
196

During a business impact analysis (BIA), which of the following is the MOST important metric to identify for each critical business process?

Medium
197

An IS auditor is evaluating the vendor selection process for a new system. Which of the following is the most important factor to include in the contract?

Medium
198

An organization is implementing a data loss prevention (DLP) solution. Which of the following is the MOST important step to ensure the DLP rules are effective?

Easy
199

According to ISACA IT Audit Standards, which of the following is the MOST important consideration when determining the scope of an IS audit?

Medium
200

An IS auditor is evaluating the effectiveness of controls over a critical financial application. Which TWO of the following are appropriate audit procedures to test the design and implementation of controls? (Select TWO.)

Medium
201

An IT governance framework has been implemented, but the board is not receiving regular reports on IT performance. Which of the following is the BEST course of action?

Medium
202

An organization uses a third-party vendor for application support. The vendor has subcontracted some support activities to another firm (fourth party). The contract with the vendor requires the vendor to ensure fourth-party compliance, but there is no direct oversight. What is the IS auditor's primary recommendation?

Hard
203

An IT steering committee is reviewing a proposed project to implement a new customer relationship management (CRM) system. The project has strong support from the sales department but is opposed by the finance department due to cost concerns. What is the primary role of the IT steering committee in this situation?

Medium
204

During a security audit, which rule poses the greatest risk?

Easy
205

A company is developing a new financial application. Which THREE of the following are valid reasons to involve internal audit during the development phase?

Hard
206

During the system development life cycle (SDLC), which THREE of the following are recognized benefits of involving internal audit early in the process?

Easy
207

An organization is implementing a public key infrastructure (PKI) to support digital certificates. Which of the following is the MOST critical control to ensure the integrity of the certificate lifecycle?

Medium
208

An IS auditor is reviewing the change management process and notices that several emergency changes were implemented without post-implementation review. What is the PRIMARY concern?

Hard
209

A company is designing its backup strategy for a critical database that must be available 24/7. The database experiences high transaction volumes. Which backup method minimizes data loss while allowing continuous operations?

Easy
210

During a post-implementation review of a new payroll system, the IS auditor identifies several outstanding issues. Which TWO issues should be considered most critical to address immediately? (Select TWO)

Medium
211

During an incident, the IT team identifies that a critical patch was not applied due to an expired software maintenance contract. Which of the following is the BEST long-term remediation?

Hard
212

Which TWO of the following are effective controls to prevent fraud in IT? (Select TWO)

Medium
213

An organization is implementing a business continuity plan (BCP) and needs to determine the maximum acceptable downtime for a critical system. Which metric should be defined FIRST?

Hard
214

A company's backup policy requires daily full backups to tape and offsite storage. After a ransomware attack, the IT team discovers that the latest backup set is corrupted. Which of the following controls would have BEST prevented this?

Medium
215

An organization has implemented a balanced scorecard (BSC) for IT performance measurement. Which of the following is the PRIMARY benefit of using a BSC?

Easy
216

Which TWO of the following are key activities in the system design phase of the SDLC?

Medium
217

An IS auditor is reviewing a post-implementation review report for a new ERP system. Which of the following findings would be of greatest concern to the auditor?

Hard
218

An organization uses automated job scheduling for batch processing. A critical payroll job fails due to a dependency on a prior job that did not complete. The job scheduler is configured to handle dependencies. What should the auditor verify regarding rerun procedures?

Hard
219

During a security audit, it was found that users in the finance department have unnecessary access to HR payroll data. Which access control principle has been violated?

Easy
220

A company decides to outsource the development of a customer portal. Which of the following is the MOST critical control to include in the contract?

Medium
221

A company is replacing its legacy on-premises ERP system with a cloud-based SaaS solution. The project manager is concerned about data migration risks. Which of the following is the BEST approach to mitigate data integrity issues during migration?

Medium
222

During an incident response exercise, the IT team discovers that the failover to the disaster recovery (DR) site failed because the DR site's storage area network (SAN) was not zoned correctly for the replicated data. Which of the following controls would BEST prevent this issue?

Hard
223

Refer to the exhibit. During a penetration test, a security analyst captures this SAML response. Which of the following security weaknesses is most evident?

Hard
224

Which TWO of the following are key controls for ensuring data privacy during system development?

Medium
225

An organization has implemented a key management program. Which of the following is the MOST critical control for ensuring the security of cryptographic keys?

Medium
226

An organization is implementing a data retention policy for personally identifiable information (PII) to comply with GDPR. Which of the following is the MOST appropriate approach?

Hard
227

An IS auditor is reviewing the process for granting access to a sensitive financial application. Which TWO of the following are the MOST important controls to ensure appropriate access?

Easy
228

Which TWO of the following are key components of an IT governance framework? (Choose two.)

Medium
229

During user acceptance testing, a user with the above permission set cannot execute a fund transfer. What is the MOST likely reason?

Easy
230

A large financial institution is developing a new online banking platform using an Agile methodology. The development team has implemented continuous integration and continuous deployment (CI/CD) pipeline. During a routine security scan, the IS auditor discovers that a developer accidentally committed a configuration file containing database credentials into the public-facing code repository. The credentials were exposed for 48 hours before being detected. Which of the following is the most critical control failure that allowed this incident to occur?

Hard
231

Which of the following is the PRIMARY purpose of audit working papers?

Medium
232

An IS auditor identifies a control deficiency that could result in a material misstatement in the financial statements. According to audit reporting standards, this should be classified as:

Hard
233

Which of the following is the best example of audit evidence obtained through re-performance?

Medium
234

An IS auditor is reviewing an organization's logical access control processes. Which of the following is the primary purpose of conducting regular user access recertifications?

Easy
235

An IS auditor is reviewing a third-party service provider's controls. Which of the following is the MOST important clause to include in the contract to ensure the auditor can assess the provider's controls?

Medium
236

A company is implementing IT governance based on COBIT 2019. Which of the following design factors would have the GREATEST impact on the governance system design?

Hard
237

An IS auditor is reviewing an agile software development project. Which of the following is the most important control to assess?

Medium
238

An organization is developing a critical application using an agile methodology. The project sponsor demands frequent deliveries but the development team is concerned about insufficient testing. Which of the following BEST mitigates this risk?

Hard
239

An IT auditor is evaluating the change management process for a financial trading system. Which of the following is the BEST indicator of a mature change management process?

Medium
240

An IS auditor is assessing the vulnerability management program of a financial services company. The auditor reviews the latest vulnerability scan report and finds that several critical vulnerabilities have not been patched within the defined SLA of 30 days. The IT manager explains that patches could not be applied due to compatibility issues with legacy applications, and risk acceptance has been documented for some but not all. Which THREE of the following are the MOST appropriate audit findings?

Medium
241

During an IT audit, the auditor observes that mandatory vacation policies are not enforced for IT staff with access to financial systems. What is the PRIMARY risk associated with this finding?

Hard
242

An organization is implementing a large ERP system. The project team plans to migrate legacy data to the new system. Which of the following is the MOST significant risk associated with data migration?

Hard
243

Which THREE of the following are required components of a SMART recommendation? (Select three.)

Hard
244

An IS auditor is reviewing physical access controls at a data center. Which of the following controls is MOST effective for preventing tailgating?

Easy
245

Which THREE of the following are responsibilities of the board of directors regarding IT governance? (Choose three.)

Hard
246

Which TWO are primary objectives of an identity and access management (IAM) program? (Select exactly 2.)

Hard
247

An IS auditor is reviewing the change management process for a critical financial application. Which of the following is the most important element to verify in an emergency change request?

Medium
248

Which THREE of the following are phases of the audit process as defined by ISACA? (Select THREE.)

Hard
249

A company is implementing a cloud-based identity and access management (IAM) system. Which of the following best describes the principle of least privilege in this context?

Medium
250

A large enterprise is assessing its IT governance maturity. Which THREE of the following are indicators of a mature governance process? (Select exactly three.)

Hard
251

An IS auditor is reviewing the incident response (IR) process. Which of the following is the MOST important characteristic of an effective tabletop exercise?

Medium
252

An organization is transitioning from a waterfall to an agile development methodology. Which of the following is a key risk that the IS auditor should highlight?

Medium
253

An IS auditor is reviewing a penetration test report that shows a critical vulnerability in a web application. The IT manager states that the vulnerability will not be fixed because it requires significant code changes and the application is being decommissioned in six months. What should the auditor do?

Hard
254

A database administrator accidentally deleted a critical table. The last full backup was taken 24 hours ago, and transaction logs are archived every 15 minutes. Which recovery method will minimize data loss?

Medium
255

Which of the following is the PRIMARY purpose of a service desk?

Easy
256

An IT manager wants to measure the effectiveness of the organization's patch management process. Which of the following KPIs would be most appropriate?

Medium
257

Which of the following is a permanent file item in an IS audit working paper?

Medium
258

Which of the following is the BEST indicator that an organization's incident management process is effective?

Easy
259

A company is outsourcing software development. What is the IS auditor's PRIMARY concern?

Medium
260

An organization uses continuous auditing techniques to monitor transactions. The IS auditor is evaluating the effectiveness of these techniques. Which of the following is the PRIMARY benefit of continuous auditing over traditional periodic auditing?

Medium
261

What is the primary control weakness in this IAM policy?

Medium
262

Which THREE are core components of a comprehensive identity and access management (IAM) system? (Choose three.)

Hard
263

An organization is considering outsourcing its IT infrastructure management. Which of the following is the MOST important factor to include in the service level agreement (SLA)?

Medium
264

An organization's mobile device management (MDM) policy requires that all corporate data on employee-owned smartphones be protected. Which control best ensures that corporate data can be remotely wiped without affecting personal data?

Easy
265

An IT governance framework should include which TWO key components? (Select exactly two.)

Easy
266

An organization experiences a ransomware attack that encrypts critical files. Which of the following is the BEST recovery strategy to minimize data loss?

Medium
267

Which of the following evidence types involves the auditor independently performing a control procedure to verify its effectiveness?

Easy
268

An IS auditor is testing a control that requires two approvals for purchase orders over $10,000. The auditor selects a sample of 50 purchase orders from the population of 500. Using statistical sampling, the auditor finds 2 deviations. The tolerable deviation rate is 5%. What should the auditor conclude?

Medium
269

An organization wants to ensure that data is not retained longer than necessary. Which of the following is the BEST control to implement?

Easy
270

An organization has a policy requiring all employees to complete annual information security awareness training. Which of the following is the BEST way to verify compliance with this policy?

Easy
271

An auditor is reviewing IT asset management processes. The auditor finds that several servers running an older operating system are still in production, even though the vendor has ended support. What is the primary risk associated with this finding?

Medium
272

An organization has implemented a clean desk policy. Which of the following is the BEST audit procedure to verify compliance?

Medium
273

During a review of firewall rule sets, an IS auditor identifies a rule that allows 'any-any' traffic from an internal subnet to the DMZ. The rule was implemented six months ago based on a business request that has since been completed. The firewall administrator explains that the rule was kept for convenience. Which of the following is the BEST audit recommendation?

Hard
274

An IS auditor is assessing the vendor management process. Which TWO are key controls for managing third-party risk?

Easy
275

A large financial institution is implementing a new core banking system to replace a legacy system. The project has been underway for 18 months and is behind schedule. User acceptance testing (UAT) has revealed significant data integrity issues, including missing customer records and incorrect interest calculations. The project manager, under pressure from senior management to meet a regulatory deadline, proposes going live with a promise to fix the issues in a post-implementation phase. The development team has been making ad hoc code changes directly in the test environment without version control or proper testing. Additionally, the IS auditor discovers that the business requirements were never formally signed off by the user community; only verbal approvals were obtained. The project has consumed 90% of the budget but only 60% of the functionality is tested. Which of the following is the BEST course of action for the IS auditor to recommend?

Hard
276

Which of the following is the BEST indicator of the effectiveness of a security awareness program?

Easy
277

Which TWO of the following are indicators of poor project governance that an IS auditor should identify?

Hard
278

An organization uses a cloud service provider (CSP) for critical applications. The IS auditor is reviewing the contract for vendor concentration risk. Which TWO clauses are MOST relevant to mitigating this risk?

Hard
279

Which TWO of the following are benefits of implementing an IT governance framework?

Easy
280

An IS auditor is reviewing the firewall rule base. Which of the following findings would be of MOST concern?

Medium
281

A company's endpoint protection solution alerts on a file that is digitally signed by a trusted software vendor but exhibits malicious behavior on execution. What type of threat does this scenario most likely depict?

Hard
282

Refer to the exhibit. An application log shows an error. What is the MOST likely cause of this error?

Medium
283

An IS auditor is assessing an ERP implementation. Which of the following control concerns is MOST likely to arise from segregation of duties conflicts?

Medium
284

An organization uses role-based access control (RBAC). An employee is transferred to a new department. According to best practices, what should be done regarding the employee's access rights?

Medium
285

A company is developing a mobile application that processes credit card payments. During the testing phase, which of the following types of testing is MOST critical to ensure security?

Medium
286

An IS auditor is assessing audit risk for a payroll system. The inherent risk is assessed as moderate, control risk as high due to weak segregation of duties, and detection risk is set at low because of extensive substantive testing. What is the impact on overall audit risk?

Hard
287

Which THREE of the following are key components of an effective information security awareness program? (Choose three.)

Hard
288

An organization is implementing a new incident management process aligned with ITIL. The IT team discovers a critical system is down, affecting all users. According to ITIL, what severity level should be assigned to this incident?

Easy
289

Which TWO of the following are important controls for managing cloud resources to prevent cost overruns? (Select TWO).

Medium
290

An IS auditor is reviewing the key management program for an organization's encryption systems. Which of the following is the MOST critical control to ensure the security of encryption keys?

Medium
291

A company is implementing a new IT governance framework. Which of the following is the PRIMARY benefit of aligning IT strategy with business strategy?

Easy
292

During a post-implementation review, an IS auditor identifies that the system's actual transaction processing time is significantly higher than the benchmark specified in the service level agreement (SLA). The vendor claims it is due to inadequate network bandwidth provided by the client. What should the auditor do first?

Hard
293

Which TWO of the following are recommended practices for aligning IT strategy with business goals, according to COBIT 2019?

Medium
294

An IS auditor is evaluating the release management process for a software application. Which TWO are essential components of a successful release plan?

Hard
295

Which of the following best describes audit risk in the context of an IS audit?

Hard
296

A multinational corporation is implementing a new enterprise resource planning (ERP) system across multiple regions. The project uses a phased roll-out. After the first phase in Asia, the system experiences intermittent synchronization errors between the central database and regional servers. The IT team suspects network latency but cannot reproduce the issue consistently. The project sponsor wants to proceed with the next phase in Europe to avoid further delays. The IS auditor is performing a post-implementation review. What is the MOST appropriate recommendation?

Hard
297

An organization has a policy that requires all employees to undergo annual security awareness training. This is an example of which type of document in the policy hierarchy?

Easy
298

A small business wants to protect customer data collected through its e-commerce website. Which control is most appropriate for protecting the data at rest and in transit?

Easy
299

During an audit of physical security, the IS auditor observes that employees frequently leave confidential documents on their desks overnight. Which TWO controls should the auditor recommend?

Easy
300

During the user acceptance testing (UAT) phase of a new financial application, the business users report that the system calculates interest incorrectly for certain loan types. The project manager wants to fix this quickly. Which of the following is the BEST course of action?

Hard
301

Which of the following is the PRIMARY purpose of a change advisory board (CAB) in the change management process?

Medium
302

An IS auditor is planning an audit of a decentralized organization with multiple business units. The auditor wants to use a risk-based approach. Which of the following is the MOST appropriate factor to prioritize audit coverage?

Hard
303

Which TWO of the following are key considerations when managing software licenses in an organization? (Select TWO).

Medium
304

Which TWO of the following are the MOST effective controls to prevent unauthorized changes to production data?

Medium
305

During which phase of the SDLC should security requirements be formally documented and approved?

Easy
306

Which THREE of the following are typical controls in the design phase of the SDLC?

Medium
307

An organization is implementing a new IT governance framework. Which of the following is the PRIMARY benefit of aligning IT strategy with business strategy?

Easy
308

An organization processes personal data of EU residents and has implemented pseudonymisation as a privacy control. The IS auditor is reviewing the effectiveness of this control in meeting GDPR requirements. Which of the following is the MOST important limitation of pseudonymisation?

Hard
309

An IS auditor is performing a risk assessment for an audit of a cloud service provider. Which THREE factors should be considered when assessing inherent risk? (Select THREE.)

Hard
310

An organization is implementing a new ERP system and is concerned about segregation of duties (SoD) conflicts. What is the BEST approach to address this during the implementation?

Medium
311

A multinational corporation is implementing a bring your own device (BYOD) policy. Which of the following is the most important security control to ensure corporate data is protected on employee devices?

Hard
312

A financial services organization recently experienced a data breach where customer financial records were exfiltrated. The investigation reveals that an attacker gained access through a compromised privileged account belonging to a database administrator. The attacker used valid credentials to log into the database server and then exported a large volume of data using native database tools. The security team notes that the organization has multi-factor authentication (MFA) enabled for all remote access, but the database server was accessed from an internal IP address. The organization also has a data loss prevention (DLP) system, but it did not alert on the export because the traffic was encrypted. The database activity monitoring (DAM) system did log the export, but alerts were not reviewed due to high volume and many false positives. Which of the following would have been most effective in preventing this breach?

Hard
313

What is the PRIMARY purpose of a post-implementation review?

Easy
314

An organization is implementing a privileged access management (PAM) solution. Which of the following is the PRIMARY benefit of using a PAM tool?

Medium
315

An organization is implementing a new IT policy. What is the MOST important step to ensure compliance?

Medium
316

Based on the exhibit, what is the default retention period for data?

Easy
317

Which testing phase is MOST effective for validating that the system meets business needs?

Easy
318

A company plans to outsource its data center operations to a cloud service provider. What is the MOST important governance consideration for the board before finalizing the contract?

Medium
319

Which TWO of the following are key performance indicators (KPIs) for IT operations?

Medium
320

An IS auditor is planning a risk-based audit of a financial system. Which TWO of the following factors should the auditor consider when assessing inherent risk? (Select two.)

Medium
321

An organization is implementing a new financial system. Which of the following is the MOST important control to ensure data integrity during the data migration phase?

Easy
322

Refer to the exhibit. An auditor finds that users are able to reuse previous passwords easily. Which setting should be modified to address this weakness?

Medium
323

What is the MOST significant weakness in the planned remediation?

Hard
324

A company uses a RAID 5 array for its file server. One disk fails, and the system continues to operate. However, during the rebuild process, a second disk fails. What is the likely consequence?

Hard
325

Which THREE of the following are characteristics of a SMART recommendation? (Select three.)

Hard
326

A multinational corporation is deploying a new cloud-based collaboration platform for its 5,000 employees. The platform will store sensitive project data and intellectual property. The CISO mandates that all data must be encrypted at rest and in transit, and that access must be controlled via the company's identity provider (IdP) using SAML 2.0. During a pilot with the R&D department, the security team discovers that the platform's audit logs do not record failed login attempts from the IdP. The platform vendor states that the IdP is responsible for authentication, so the platform only logs successful assertions. The CISO is concerned about the lack of visibility into brute-force attacks. The company already has a SIEM that receives logs from the IdP and other sources. What is the BEST course of action?

Medium
327

An IS auditor is reviewing the physical access controls at a data center. Which of the following is the MOST effective control to prevent tailgating?

Easy
328

An IS auditor is reviewing capacity management practices. Which TWO indicators suggest that proactive capacity management is being performed effectively?

Medium
329

An IS auditor is performing a compliance audit of a data privacy regulation. Which of the following is the PRIMARY source of audit criteria?

Medium
330

Based on the exhibit, which control deficiency is most critical for the IS auditor to address?

Hard
331

An IS auditor is reviewing the incident response (IR) process. Which of the following is the BEST way to test the effectiveness of the IR plan?

Easy
332

Refer to the exhibit. Which of the following is the most significant risk associated with the backup policy for critical data?

Hard
333

A multinational corporation is implementing a global IT governance framework. Which of the following challenges is MOST likely to arise?

Hard
334

During a software asset management (SAM) audit, it is discovered that the organization is using software that has reached end-of-life. Which of the following is the MOST significant risk associated with this situation?

Hard
335

An IS auditor finds that a project failed to meet its objectives because key stakeholders were not involved in the requirements definition phase. Which phase of the SDLC was most neglected?

Medium
336

Which of the following is the PRIMARY reason for implementing network segmentation?

Easy
337

An organization is designing an IT balanced scorecard to align IT performance with business goals. Which perspective would include metrics related to IT employee skills and training?

Hard
338

An organization uses a cloud-based ERP system to manage financial transactions. The system is accessed by employees in finance, procurement, and sales departments. The IS auditor is reviewing the user access review process. The access review is performed quarterly by the IT manager using a report generated by the ERP system. The report lists all users and their roles. The IT manager manually checks off users who are still employed and approves the report. The auditor notes that the IT manager does not have detailed knowledge of job functions in each department. Additionally, the ERP system allows role combinations that may create segregation of duties conflicts, such as a user having both 'create purchase order' and 'approve purchase order' roles. The company's policy requires segregation of duties reviews to be performed by business process owners. Which of the following is the BEST recommendation?

Medium
339

An organization has defined an SLA that requires critical incidents to be resolved within 4 hours. A P1 incident is reported at 10:00 AM. At what time must the incident be resolved to meet the SLA?

Easy
340

Which TWO of the following are typically included in the fieldwork phase of an IS audit? (Select two.)

Medium
341

An IS auditor is evaluating the encryption strategy for a healthcare organization subject to HIPAA. Which of the following is the MOST significant risk if the organization relies solely on encryption as a safe harbor?

Hard
342

An IS auditor is reviewing the backup process for a critical database. Which TWO of the following are essential controls to ensure data recoverability?

Easy
343

In a waterfall SDLC, which phase requires formal sign-off from the business owner before proceeding to the next phase?

Easy
344

An IS auditor is reviewing the design phase of a new procurement system. Which TWO of the following controls are MOST critical to include in the system design to prevent unauthorized purchases?

Medium
345

An IS auditor is reviewing an organization's data classification policy. Which of the following findings is MOST critical?

Medium
346

Refer to the exhibit. An IS auditor is reviewing an IAM policy for a cloud data platform. The auditor notices that user jdoe has READ_ONLY access to all tables matching 'sales_', but asmith has READ_WRITE access to the same set of tables. Which of the following is the MOST critical control issue?

Hard
347

Which control failure is MOST significant?

Hard
348

Order the steps for conducting an audit engagement from start to finish.

Medium
349

An IS auditor is reviewing the physical access controls at a data center. Which TWO of the following are the MOST effective controls to prevent unauthorized tailgating?

Medium
350

An IS auditor is reviewing the incident management process. Incidents are categorized as P1 (critical) through P4 (low). The SLA for P1 incidents requires initial response within 15 minutes and resolution within 4 hours. The auditor notes that the average time to respond to P1 incidents is 12 minutes, but the average resolution time is 6 hours. The root cause analysis shows that many P1 incidents are due to known errors documented in the known error database (KEDB). What is the most significant finding?

Hard
351

During an agile software development project, a sprint review meeting is conducted. What is the PRIMARY purpose of this meeting from an IS audit perspective?

Medium
352

An IS auditor is reviewing a request for proposal (RFP) for a new system. Which TWO elements should be included in the RFP?

Easy
353

Refer to the exhibit. Which of the following statements is TRUE regarding this S3 bucket policy?

Medium
354

During a post-implementation review of a financial system, an IS auditor finds that several critical reports are not being generated correctly. Which of the following should the auditor recommend FIRST?

Easy
355

An organization is implementing a data loss prevention (DLP) solution. Which TWO of the following are key considerations for effective DLP deployment?

Easy
356

An IS auditor is evaluating the effectiveness of an organization's change management process. Which of the following is the most important control to verify during the audit?

Easy
357

During an audit, the IS auditor discovers that the audit log for a critical server is overwritten every 24 hours. The auditor wants to ensure logs are preserved for a longer period. Which of the following recommendations is most appropriate?

Medium
358

Which testing type is performed by end-users to verify that the system meets their needs?

Easy
359

Which of the following is the BEST control to ensure that user acceptance testing (UAT) is effective?

Medium
360

An IS auditor is reviewing a change management process. Which TWO elements should be documented in a normal change request to ensure adequate governance? (Select TWO)

Medium
361

An organization is implementing a new financial system and has completed user acceptance testing (UAT). The project manager reports that all critical defects have been fixed and retested, but several low-severity issues remain unresolved. What is the BEST course of action?

Medium
362

An IS auditor is reviewing the organization's encryption key management program. Which of the following is the MOST critical control to ensure the confidentiality of encrypted data in the event of a key compromise?

Medium
363

An IS auditor is reviewing a vulnerability scan report and finds that a critical vulnerability on a web server has been open for 90 days beyond the remediation SLA. The system owner states that the vulnerability cannot be patched because it would break a legacy application. What should the auditor recommend?

Hard
364

An IS auditor uses statistical sampling to test a population of 10,000 transactions. The auditor discovers 5 errors in the sample of 200. Which of the following conclusions is most appropriate?

Hard
365

An IS auditor is evaluating the change management process. Which of the following is the BEST indicator that emergency changes are being properly controlled?

Medium
366

An IS auditor is assessing the effectiveness of access controls. Which TWO procedures provide the strongest evidence? (Select two.)

Medium
367

Based on the log, what is the MOST likely root cause of the backup failure?

Easy
368

Which THREE of the following are essential components of a data classification program?

Hard
369

A medium-sized e-commerce company recently suffered a ransomware attack that encrypted critical databases. The IT team restored systems from backups, but the incident exposed a lack of clear roles and responsibilities for incident response. The board has asked the IT governance committee to review and improve the incident response governance. The committee notes that while there is an incident response policy, it is not regularly tested, and staff are unsure of their roles. The company also lacks a formal communication protocol for notifying stakeholders. What should the committee prioritize to strengthen governance over incident response?

Easy
370

An organization is adopting an agile development methodology for a new financial application. During a sprint review, the product owner expresses concern that the system does not enforce segregation of duties (SoD). The development team argues that SoD will be addressed in a future sprint. As the IS auditor, what is the BEST recommendation?

Hard
371

A small business wants to protect customer data stored on a local file server. Which of the following is the MOST cost-effective control to prevent unauthorized access?

Easy
372

An organization is implementing a data loss prevention (DLP) solution. Which of the following is the BEST approach to reduce false positives during initial deployment?

Medium
373

An IS auditor is reviewing the user access recertification process. Which of the following findings would MOST concern the auditor regarding the effectiveness of access reviews?

Medium
374

An organization's backup strategy includes full backups every Sunday and incremental backups on other days. On Wednesday, a failure occurs. Which backups are needed to restore the data?

Medium
375

Refer to the exhibit. The IS auditor reviews the router's version output during an audit. What is the MOST significant finding?

Easy
376

A multinational corporation is evaluating its IT governance structure. The board wants to ensure that IT investments are prioritized based on risk and value. Which framework component is MOST critical?

Hard
377

A mid-sized company is implementing a new IT service management (ITSM) tool to improve incident management. The IT manager wants to ensure that the tool aligns with ITIL best practices. The company has a dedicated service desk team that handles about 200 incidents per week. The IT manager is considering whether to implement a self-service portal for users to submit incidents and check status, or to continue using email-based incident reporting. The service desk team is concerned that a self-service portal might reduce their direct interaction with users and potentially lead to less personalized support. However, the IT manager believes that a portal could improve efficiency and tracking. The company's IT governance framework requires that any major IT investment be approved by the steering committee and that there be a clear business case. The IT manager has prepared a business case but the steering committee wants to ensure that the solution is aligned with ITIL and that it addresses key incident management processes. Which of the following is the most appropriate next step for the IT manager?

Easy
378

An IS auditor is reviewing backup procedures for a critical database. Which THREE are key considerations for ensuring backup reliability and recoverability?

Medium
379

An IS auditor is reviewing the effectiveness of a control that requires dual approval for payments over $10,000. The auditor selects a sample of payments and independently verifies that two approvals were obtained. This audit procedure is:

Medium
380

During an operational audit of an IT department, the auditor finds that system uptime is 99.9% but the department missed two critical project deadlines. Which conclusion is most appropriate?

Medium
381

An IS auditor is reviewing a waterfall SDLC project that has completed the requirements phase. Which of the following is the greatest risk to the project?

Medium
382

An IS auditor is reviewing the change management process for a critical financial application. Which of the following findings would be of GREATEST concern?

Hard
383

Which TWO of the following are components of the IT balanced scorecard?

Easy
384

An IS auditor is reviewing the logical access controls for a cloud-based HR system. The system contains sensitive employee data. The auditor notes that user provisioning is performed by the HR department without IT involvement, and there is no formal access request or approval process. Which THREE of the following are the MOST significant risks?

Easy
385

Which TWO of the following are key elements of a change request document?

Medium
386

Which TWO of the following are key controls that an IS auditor should expect to find in a well-managed system development life cycle (SDLC)?

Medium
387

During an operational audit, the auditor wants to evaluate the efficiency of a data entry process. Which of the following audit procedures would be most appropriate?

Medium
388

An IS auditor is reviewing the physical access controls at a data center. Which of the following is the MOST effective control to prevent tailgating?

Medium
389

An organization is developing a policy on acceptable use of company IT resources. Which of the following should be included to support effective governance?

Medium
390

An IS auditor is testing the effectiveness of a control that requires dual authorization for all transactions over $10,000. The population consists of 5,000 transactions, of which 250 exceed the threshold. The auditor uses a sample of 50 transactions from the entire population and finds 3 exceptions. What type of sampling method did the auditor use?

Hard
391

A multinational corporation is implementing a global HR system. The project team decides to use a pilot implementation in one region before rolling out to others. What is the PRIMARY risk if the pilot region is not representative of the entire organization?

Hard
392

During a post-implementation review of a new financial system, the IS auditor finds that user acceptance testing (UAT) was completed with only 60% of test cases passed. Which of the following is the MOST significant risk?

Medium
393

An IS auditor reviews the change request. Which of the following is the most significant risk?

Hard
394

Which of the following is the PRIMARY purpose of a data classification scheme?

Easy
395

A system has a Mean Time Between Failures (MTBF) of 200 hours and a Mean Time To Repair (MTTR) of 20 hours. What is the availability of the system?

Medium
396

During which phase of the SDLC should security requirements be formally documented and approved by the business owner?

Easy
397

Order the steps for conducting a business impact analysis (BIA) in the correct sequence.

Medium
398

A multinational corporation has defined its risk appetite as 'moderate' for IT investments. The IT steering committee is evaluating a new project with potential high returns but also significant cybersecurity risks. The project's risk profile is assessed as 'high' by the risk management team. What should the committee do FIRST?

Hard
399

An organization wants to ensure that its backup tapes are protected from unauthorized access. Which of the following is the MOST effective control?

Easy
400

Refer to the exhibit. Which perspective shows the greatest deviation from target?

Hard
401

An organization has implemented a business continuity plan (BCP) and disaster recovery plan (DRP). During a recent full interruption test, the IT team discovered that the recovery time objective (RTO) for a critical application was not met. What is the MOST likely reason for this failure?

Medium
402

An IS auditor is reviewing the access recertification process for a financial application. The process requires users' managers to confirm access rights quarterly. Which of the following findings should MOST concern the auditor?

Medium
403

An IS auditor is reviewing an emergency change that was implemented to fix a critical security vulnerability. Which of the following post-implementation controls is MOST important to ensure the change was properly managed?

Hard
404

According to ISO/IEC 38500, which principle requires that IT investments are made for valid business reasons and with clear business outcomes?

Easy
405

An organization is acquiring a new financial system. The contract includes a clause that allows the organization to audit the vendor's controls. Which type of report would most efficiently provide assurance over the vendor's internal controls?

Medium
406

A university is implementing a new student information system. The project team uses an iterative development approach. During user acceptance testing, students report that the online course registration portal crashes when more than 100 users register simultaneously. The development team identifies a database connection pooling issue and estimates a fix will take three weeks. The project deadline is in two weeks. The project manager suggests deploying the system as is and fixing the issue after go-live, as the crash is rare. The IS auditor is consulted. What should the auditor recommend?

Medium
407

An IS auditor is reviewing a contract for a new software solution. Which of the following contract types poses the HIGHEST risk to the buyer if requirements are not well-defined?

Medium
408

A security auditor discovers that a server has been compromised due to an unpatched vulnerability. Which of the following would have most effectively prevented this incident?

Medium
409

During an audit of the incident response process, the IS auditor finds that the organization relies on shared accounts for system administration. Which TWO of the following are the MOST significant risks associated with shared accounts?

Medium
410

An organization is conducting a Business Impact Analysis (BIA). Which of the following metrics defines the maximum acceptable outage time for a critical business process?

Medium
411

During a spiral model SDLC project, an IS auditor is reviewing risk assessment documentation. Which of the following would be the GREATEST concern?

Hard
412

Refer to the exhibit. The organization is planning to achieve the target level. What is the MOST appropriate action?

Medium
413

Which of the following is the PRIMARY benefit of using a hardware security module (HSM) for key management?

Easy
414

An IS auditor is reviewing a systems acquisition project that involves purchasing an ERP system. Which of the following is the MOST significant risk related to data migration during implementation?

Medium
415

Order the steps for performing a data backup in the correct sequence.

Medium
416

Which of the following are key considerations when implementing a data classification policy? (Choose THREE.)

Medium
417

In a spiral model SDLC, risk analysis is performed at the beginning of each iteration. What is the PRIMARY benefit of this approach?

Hard
418

During the planning phase of an IS audit, the auditor identifies that the organization has recently implemented a new ERP system. Which of the following actions should the auditor prioritize?

Medium
419

Which TWO of the following are key objectives of a post-implementation review of a new system?

Medium
420

What is the FIRST step in implementing an identity and access management (IAM) program?

Easy
421

Scenario: A healthcare organization is implementing a new electronic health records (EHR) system. The project has been delayed due to scope creep and resource constraints. The project sponsor is pressuring the project manager to accelerate the timeline by skipping user acceptance testing (UAT) and going live immediately. The organization has a governance policy that requires all IT projects to complete UAT before deployment. The project manager is concerned about quality and patient safety. Which of the following is the BEST course of action?

Medium
422

An organization has an availability requirement of 99.99% for its online transaction processing system. The system's MTBF is 720 hours. What is the maximum allowable MTTR to meet this requirement?

Hard
423

An IT department uses a balanced scorecard (BSC) to measure performance. The financial perspective shows that IT costs are within budget, but customer satisfaction scores are declining. The learning and growth perspective indicates low employee engagement. Which action should the IT governance committee prioritize?

Hard
424

An IT auditor is reviewing the organization's policy hierarchy. Which of the following correctly represents the typical order from highest to lowest level?

Hard
425

An IS auditor is reviewing the business impact analysis (BIA) for a financial services company. Which THREE metrics are typically defined in a BIA?

Medium
426

An organization's IT strategy is developed by the IT department without input from business stakeholders. Which of the following is the MOST significant risk?

Hard
427

An organization is implementing a software asset management (SAM) program. Which of the following is the PRIMARY benefit of SAM?

Medium
428

An IS auditor is evaluating the incident response (IR) plan. Which of the following is the BEST indicator that the plan is effective?

Medium
429

A medium-sized manufacturing company has a decentralized IT structure where each business unit manages its own IT budget and projects. The CEO is concerned that IT investments are not aligned with corporate strategy and that there is duplication of effort. The IT department lacks a formal project portfolio management process. The company has experienced several project failures due to poor prioritization. The CEO has asked the newly hired IT auditor to recommend an initial step to improve IT governance. The auditor should recommend:

Easy
430

A company is migrating from a legacy system to a cloud-based ERP. Which of the following is the MOST important control to ensure data integrity during data conversion?

Easy
431

In an Agile software development project, who is primarily responsible for prioritizing the product backlog?

Easy
432

An IS auditor is reviewing the privileged access management (PAM) process. Which TWO of the following are the MOST effective controls to prevent misuse of privileged accounts?

Medium
433

Which of the following is the BEST indicator of IT performance from the customer perspective in an IT balanced scorecard?

Easy
434

During an audit, the IS auditor finds that the business continuity plan (BCP) was last updated two years ago and does not include new cloud-based applications. The organization has not conducted a BCP test in 18 months. What should the auditor recommend FIRST?

Hard
435

An organization has implemented a new IT service management (ITSM) tool. The IT manager wants to measure the effectiveness of incident management. Which metric is MOST appropriate?

Hard
436

An IS auditor is reviewing a backup strategy that includes daily full backups and weekly offsite storage. The recovery time objective (RTO) for a critical application is 4 hours. Which of the following findings would be of GREATEST concern?

Hard
437

An organization is adopting ITIL 4 for service management. Which guiding principle emphasizes starting from existing processes rather than building from scratch?

Medium
438

An IT steering committee is evaluating a major system upgrade. Which of the following is the PRIMARY benefit of using an IT balanced scorecard in this evaluation?

Medium
439

An organization is implementing a new IT governance framework. Which of the following is the PRIMARY benefit of using a framework like COBIT?

Easy
440

Which TWO of the following are components of the ITIL 4 four dimensions of service management? (Select TWO.)

Medium
441

An IS auditor is reviewing an agile project that uses Scrum. Which event provides the best opportunity for the auditor to assess whether completed user stories meet the defined acceptance criteria?

Medium
442

During a post-implementation review of a new HR system, the auditor finds that the system's disaster recovery plan (DRP) was not tested before go-live. Which of the following is the BEST recommendation?

Hard
443

During a review of the patch management process, the IS auditor finds that critical security patches are applied within 30 days, but the policy requires application within 7 days. The IT manager argues that the delay is due to testing requirements. What should the auditor recommend?

Medium
444

Which TWO of the following are key controls in the system development life cycle?

Medium
445

A company is updating its business continuity plan (BCP). Which THREE of the following should be included as key components?

Hard
446

Which of the following is a key difference between internal and external IS auditors?

Medium
447

An organization is developing a custom application. The project manager reports that the development team has implemented 80% of the features but only 50% of the budget is used. What is the MOST significant risk from an IS audit perspective?

Hard
448

During a risk-based audit, the IS auditor identifies a control deficiency that could lead to a material misstatement in financial reporting. According to standard classification, this is best described as a:

Medium
449

A bank is converting data from its legacy core banking system to a new platform. Which control is MOST critical to ensure the completeness and accuracy of data conversion?

Medium
450

Which THREE of the following are typical objectives of an IT governance framework for system acquisition?

Hard
451

During a privacy audit, the IS auditor discovers that the organization does not have a complete data inventory. What is the PRIMARY risk associated with this finding?

Medium
452

Which of the following audit types is MOST likely to be performed by an organization's own employees?

Easy
453

An IS auditor is reviewing a system development project to assess whether it is on schedule. Which of the following would provide the BEST evidence of project progress against the planned timeline?

Medium
454

A government agency has an IT governance framework that includes an IT strategy committee, an IT steering committee, and a project management office. Despite this, there is a lack of transparency regarding IT spending and resource allocation. The agency's annual audit found that several IT initiatives were not approved by the steering committee and were funded out of operational budgets. The CFO is frustrated because IT costs are unpredictable. The agency's chief information officer (CIO) reports to the CFO but the IT steering committee is chaired by the CIO. The auditor's best recommendation to improve governance is to:

Hard
455

Refer to the exhibit. During a security audit, an IS analyst identifies that a critical business application hosted on 192.168.1.100:443 is unreachable from the 10.0.1.0/24 subnet. Which of the following is the MOST likely cause?

Hard
456

During a business impact analysis (BIA), the IS auditor identifies that the maximum tolerable downtime (MTD) for an online payment system is 2 hours, and the recovery point objective (RPO) is 15 minutes. The current disaster recovery solution uses nightly backups (12-hour RPO) and can restore the system in 4 hours. Which risk is most critical?

Medium
457

During a change management board (CAB) meeting, a proposed change to the network firewall configuration is discussed. The change is considered low risk and pre-approved. Which type of change does this represent?

Easy
458

Which TWO of the following are effective controls to prevent unauthorized access to sensitive data in a database? (Choose two.)

Medium
459

You are the IT governance lead at a multinational corporation with a complex IT environment spanning multiple business units. The company has recently experienced a series of minor security incidents where unauthorized access was gained through unused user accounts that were not disabled after employees left the organization. Additionally, there have been delays in provisioning access for new hires, leading to productivity losses. The IT department currently uses a manual process for access management, with each business unit maintaining its own user lists. The company has a policy that requires access reviews every quarter, but these are often missed or performed superficially. The CIO has asked you to recommend a solution that addresses these issues while ensuring compliance with regulations such as GDPR and SOX. Which of the following is the BEST course of action?

Hard
460

During system development, which testing phase is performed by developers to verify that individual program units function correctly?

Medium
461

Which TWO of the following are indicators that a project is at risk of failure according to ISACA's project governance framework?

Hard
462

Refer to the exhibit. An auditor notices this log entry during a review. The user john.doe does not have a legitimate business need to access executive salaries. Which of the following is the MOST likely control failure?

Medium
463

Which THREE of the following are essential elements of an emergency change request? (Select three.)

Hard
464

An IS auditor is reviewing an organization's key management program. Which of the following is the GREATEST risk associated with using a single key for both encryption and decryption of sensitive data?

Hard
465

An IT steering committee is reviewing a proposal for a new customer relationship management (CRM) system. What is the committee's MOST important role?

Medium
466

Which of the following is the PRIMARY purpose of a business impact analysis (BIA)?

Easy
467

An auditor discovers that a financial institution's IT department uses a decentralized model, with each business unit managing its own applications. What is a PRIMARY risk of this structure?

Hard
468

An auditor is selecting a sample of purchase orders for testing. The auditor decides to select every 50th purchase order from a list. This is an example of:

Medium
469

Which TWO of the following are types of analytical procedures used in an IS audit? (Select two.)

Medium
470

Which THREE of the following are key performance indicators (KPIs) commonly used to measure IT performance? (Select THREE.)

Hard
471

Which THREE of the following are common challenges when integrating a software package with existing legacy systems? (Select exactly three.)

Hard
472

An organization is implementing a large ERP system. The project manager is concerned about segregation of duties conflicts. Which THREE controls should the IS auditor recommend to mitigate segregation of duties risks during implementation? (Select THREE)

Hard
473

An IS auditor is reviewing an agile software development project. Which of the following would be the BEST evidence that adequate controls are in place for user acceptance?

Medium
474

Match each log type to its typical content.

Medium
475

An IT manager needs to ensure that the organization's IT resources are used efficiently. Which of the following is the BEST metric to measure IT resource utilization?

Easy
476

Which TWO of the following are BEST indicators that a system development project is at risk of failure?

Hard
477

During a spiral SDLC project, the IS auditor should focus on which aspect as the primary risk?

Hard
478

During a firewall rule review, an IS auditor identifies several rules that allow any-to-any traffic. Which THREE of the following should the auditor recommend as the MOST appropriate actions?

Hard
479

An organization experiences a critical system failure during non-business hours. The IT team discovers that the last full backup was 48 hours ago, and the incremental backups for the past 24 hours are corrupted. The recovery time objective (RTO) for this system is 4 hours, and the recovery point objective (RPO) is 1 hour. Which of the following is the MOST immediate concern?

Medium
480

Which of the following is a key advantage of using an iterative SDLC model over a waterfall model?

Easy
481

An organization has a clean desk policy. Which of the following is the BEST audit procedure to test compliance with this policy?

Medium
482

A multinational organization operates a critical ERP system on a virtualized infrastructure across two data centers (primary and DR). The primary data center is located in Region A, and the DR site in Region B, 500 km away. The ERP database is 2 TB and changes at an average rate of 10 MB per second. The organization uses synchronous replication between the two sites over a dedicated 10 Gbps WAN link. During a recent disaster simulation, the IT team observed that the replication link experienced 15 ms latency, causing the primary database to slow down significantly under peak load, ultimately missing the defined RTO of 4 hours for full failover. The business has an RPO of 15 minutes. The CISO asks the IS auditor to recommend a solution that balances cost and performance while meeting both RTO and RPO. Which of the following is the BEST course of action?

Hard
483

A mid-sized company is upgrading its legacy financial system to a new cloud-based ERP. The project manager has decided to use a big-bang cutover approach to minimize costs and time. During the first week post-go-live, users report that several critical reports are generating incorrect totals. An initial investigation reveals that the data mapping from the old system to the new system was not fully validated. Which of the following should the IS auditor recommend as the most appropriate corrective action?

Easy
484

Which of the following is the PRIMARY benefit of using a prototype during system development?

Easy
485

An organization's IT department is considering a shift from insourcing to co-sourcing for application development. What is a PRIMARY advantage of co-sourcing?

Medium
486

An organization is implementing a data masking solution for a non-production database. Which of the following is the MOST important requirement?

Medium
487

An organization has a policy requiring annual information security awareness training for all employees. During a recent audit, it was found that 20% of employees had not completed the training. What is the BEST course of action for the IT governance committee?

Easy
488

An IT auditor is reviewing the problem management process. The IT team maintains a repository of known errors with documented workarounds. Which component of problem management is this?

Medium
489

Which THREE of the following are common challenges when implementing a bring-your-own-device (BYOD) policy that affect information systems operations? (Select exactly 3.)

Hard
490

Which TWO of the following are essential controls to ensure data integrity during a cloud migration project?

Medium
491

Which of the following are effective controls to protect sensitive data in use? (Choose TWO.)

Easy
492

A company outsources its data center operations to a third-party provider. Which of the following is the MOST important control to include in the outsourcing contract?

Medium
493

An organization is planning to implement a data loss prevention (DLP) solution to protect sensitive data. Which THREE of the following are essential steps to ensure the effectiveness of the DLP program?

Hard
494

Which THREE of the following are commonly used data encryption standards? (Choose three.)

Easy
495

An IS auditor is reviewing logical access controls for a critical application. Which of the following is the MOST important control to detect unauthorized access?

Medium
496

An IS auditor is reviewing change management for a financial application. Which TWO of the following findings would most likely indicate a control weakness?

Hard
497

A multinational corporation's IT audit reveals that the IT department uses a single instance of an ERP system for all subsidiaries. Which COBIT 2019 governance system component is MOST relevant to address the risks of this centralized approach?

Hard
498

An IS auditor is reviewing an agile software development project. Which TWO controls should the auditor expect to see in place?

Medium
499

Which of the following is the most important factor to consider when determining sample size for a compliance test?

Easy
500

An organization is implementing a data classification policy and needs to assign ownership for sensitive data. Which of the following is the most appropriate role to assign as the data owner?

Medium
501

A multinational corporation is replacing its legacy on-premises customer relationship management (CRM) system with a new cloud-based CRM solution. The project involves migrating data from the old system, customizing the new system to match business processes, and integrating with an existing enterprise resource planning (ERP) system. The project has a tight deadline of six months. During the planning phase, the project team decides to use a waterfall methodology because the requirements are well-defined. However, three months into the project, the business users request significant changes to the customer data fields, which were not originally specified. The project manager is concerned that accommodating these changes will delay the project. The integration with the ERP system is also proving more complex than anticipated, with data mapping errors causing delays. The go-live date is fixed due to the end-of-support for the legacy system. What is the BEST course of action for the project manager?

Hard
502

A company is in the process of acquiring a new customer relationship management (CRM) system. During which phase of the systems development life cycle (SDLC) should the business requirements be formally documented?

Easy
503

An organization uses risk-based authentication (RBA) for user access. Which of the following factors would MOST likely trigger a step-up authentication?

Medium
504

An IS auditor is evaluating the effectiveness of a security awareness program. Which of the following metrics would BEST indicate that the program is achieving its objectives?

Medium
505

An organization's IT policy review cycle is set to every two years. However, a new regulation requires immediate changes to data retention policies. What is the best course of action?

Medium
506

An IS auditor is auditing the user access management process for a large healthcare organization that uses an electronic health records (EHR) system. The organization has 5,000 users including doctors, nurses, and administrative staff. The auditor reviews a sample of access requests and finds that 20% of the requests were approved by the user's manager but the approval was not documented in the system. The auditor also finds that there is no periodic review of user access rights. The IT security manager states that users are automatically provisioned based on their role in the HR system, and that access reviews are performed manually by managers but not documented. What is the auditor's BEST recommendation to address the most significant risk?

Medium
507

Which TWO of the following are key responsibilities of an IT steering committee?

Medium
508

A project team is using a prototyping approach for a new system. Which of the following is the BEST control to ensure the prototype accurately reflects user needs?

Medium
509

Which of the following best describes the primary advantage of using statistical sampling over non-statistical sampling in an IS audit?

Hard
510

During a disaster recovery test, the IS auditor observes that the alternate site uses a warm site configuration. Which of the following is a characteristic of a warm site?

Hard
511

When implementing a data classification policy, which of the following roles is PRIMARILY responsible for assigning classification labels to data?

Easy
512

During a software asset management (SAM) audit, the IS auditor discovers that the organization is using software versions that are no longer supported by the vendor. What is the primary risk?

Medium
513

An IS auditor is reviewing the system development life cycle (SDLC) for a custom application. The project manager has decided to skip the design phase and proceed directly from requirements to coding. Which of the following risks are MOST likely to increase as a result? (Choose two.)

Hard
514

An organization is planning to deploy a web application firewall (WAF) to protect a critical application. Which deployment mode should be used to ensure that the WAF can block malicious traffic without introducing a single point of failure?

Medium
515

During a system development project, the IS auditor notes that code reviews are performed only after the code is unit tested. Which of the following is the MOST significant risk associated with this practice?

Medium
516

An IS auditor is assessing the risk of material misstatement in a financial system. The auditor determines that inherent risk is high, control risk is moderate, and detection risk is low. What is the overall audit risk?

Hard
517

An IS auditor is reviewing the password policy for a system that processes sensitive financial data. Which of the following is the MOST effective control to mitigate the risk of password cracking?

Hard
518

In a traditional waterfall SDLC, when should the test plan be developed?

Easy
519

During an incident response, the IT team isolates a compromised system from the network. Which of the following is the primary purpose of this action?

Easy
520

A nonprofit organization develops a small online donation platform using a third-party payment gateway. The project team skips formal security testing because of budget constraints. After launch, a security researcher discovers that the application fails to validate input on the donation amount field, allowing manipulation. The nonprofit loses several thousand dollars before the issue is patched. The IS auditor is asked to review the system development process. Which of the following is the PRIMARY finding?

Easy
521

An IS auditor reviews the exhibit. Which of the following is the most likely cause of the denied traffic?

Easy
522

Which of the following is an example of a compliance audit?

Easy
523

Which TWO of the following are HR controls that help mitigate the risk of insider fraud in IT? (Select TWO.)

Easy
524

An IS auditor is reviewing the change management process for a financial application. Which of the following findings would be of MOST concern?

Medium
525

A company stores sensitive customer data in a database. To comply with privacy regulations, the data must be anonymized for analytics. Which technique provides the strongest anonymization while preserving data utility?

Hard
526

Refer to the exhibit. This log entry MOST likely indicates:

Hard
527

An external auditor is conducting a compliance audit for a company subject to SOX. Which standard is most relevant for this engagement?

Medium
528

An organization has outsourced its IT help desk to a third-party provider. Which of the following is the MOST critical control to ensure service quality?

Hard
529

An IS auditor is performing a walkthrough of a purchase-to-pay process. Which of the following is the auditor most likely trying to achieve?

Medium
530

Refer to the exhibit. A security analyst notices that users on the INSIDE network (10.1.1.0/24) can browse HTTPS websites but cannot resolve domain names. What is the most likely cause?

Hard
531

An organization is implementing a new IT governance framework. Which of the following is a key component of the COBIT 2019 governance system?

Medium
532

A financial services company is migrating its core banking system to a public cloud to improve scalability and reduce costs. The project is high-risk due to regulatory compliance requirements (e.g., data residency, audit trails). The IT governance committee has reviewed the project plan and finds that the risk assessment is incomplete – it does not address the potential impact of a cloud provider outage on critical transactions. The committee must approve the project or request changes. The project manager argues that the cloud provider's SLA guarantees 99.99% uptime and that additional controls would delay the project. What should the governance committee do?

Medium
533

An organization is considering acquiring a commercial off-the-shelf (COTS) ERP system. Which of the following risks is most effectively mitigated by including a contractual clause for audit rights?

Hard
534

An organization wants to protect its intellectual property from unauthorized disclosure via email. Which control should be implemented?

Easy
535

Based on the exhibit, which control is most likely missing to prevent this type of event?

Hard
536

During a post-implementation review of a new customer relationship management (CRM) system, the IS auditor finds that the system is processing transactions slower than anticipated. What is the BEST initial course of action for the auditor?

Medium
537

An IT manager is reviewing the access control model for a financial application. The policy requires that no single person can approve a transaction. Which access control principle does this policy enforce?

Medium
538

An organization has recently implemented a cloud-based identity provider (IdP) for single sign-on (SSO) across all SaaS applications. Users authenticate using their corporate credentials via SAML 2.0. After a week, the IT security team notices a significant increase in failed login attempts from various IP addresses targeting a specific user account. The helpdesk reports that the user, a senior executive, has not complained about any issues. The security team investigates and finds that the account lockout policy is set to 5 failed attempts within 15 minutes, after which the account is locked for 30 minutes. The failed attempts are occurring in bursts of 4, then stopping, then resuming from different IPs. The organization uses conditional access policies that require MFA from unknown locations. However, the failed attempts appear to be stopped at the authentication prompt and never reach the MFA stage. What is the most likely explanation and the best course of action?

Hard
539

Based on the exhibit, what is the MOST appropriate action for IT management?

Easy
540

An IS auditor is assessing the effectiveness of network segmentation for a payment card processing environment. Which of the following is the PRIMARY benefit of network segmentation in meeting PCI DSS requirements?

Easy
541

Which TWO of the following are characteristics of the iterative SDLC model?

Easy
542

A hospital is implementing a new electronic health record (EHR) system. The project team includes clinicians and IT staff. During integration testing, the system fails to exchange lab results with the existing legacy system due to format mismatches. The IT team suggests developing a custom interface. The clinical team is concerned that any custom solution may not comply with health data privacy regulations. The project sponsor pressures the team to quickly fix the issue to avoid delays. The IS auditor is reviewing this situation. What is the MOST appropriate action for the auditor to recommend?

Medium
543

An IS auditor is reviewing the vulnerability management program. The auditor notes that a critical vulnerability was identified in a production system six months ago and has not been patched due to a business impact assessment. Which of the following should the auditor examine NEXT?

Medium
544

Order the steps for responding to a security incident in the correct sequence.

Medium
545

Which TWO of the following are essential components of a business case for a new system?

Easy
546

An organization is developing a new customer portal. The development team wants to use an agile methodology. Which of the following is a key benefit of using agile for this project?

Easy
547

In a RACI matrix for an IT process, which role should be assigned to the person who ultimately approves the outcome and is held accountable for its success?

Medium
548

An organization uses a chargeback model to allocate IT costs to business units. What is a PRIMARY benefit of this approach?

Easy
549

An IS auditor is reviewing firewall rule sets and discovers a rule that permits any source IP to access the internal database server on TCP port 1433 (Microsoft SQL). The rule was documented as a temporary measure but has been in place for 18 months. What is the auditor's BEST course of action?

Hard
550

An IS auditor is assessing the risk of a new financial application. The auditor determines that inherent risk is high due to complex transactions, but control risk is low because of strong automated controls. If detection risk is set at 5%, what is the audit risk?

Medium
551

Which TWO of the following are primary objectives of a data loss prevention (DLP) strategy?

Hard
552

Match each testing technique to its description.

Medium
553

Which of the following is the PRIMARY purpose of performing a walkthrough during the audit planning phase?

Medium
554

During a post-implementation review of a new ERP system, the IS auditor identified that the project was delivered within budget but user satisfaction scores are low. Which THREE areas should the auditor examine further?

Hard
555

An IS auditor is reviewing an organization's vulnerability management program. The auditor notes that a critical vulnerability in a key application has not been patched for 90 days, and there is no documented risk acceptance. What should the auditor do FIRST?

Hard
556

Which of the following is the PRIMARY purpose of a business impact analysis (BIA) in business continuity planning?

Easy
557

In an agile development environment, an IS auditor reviews the backlog and finds that security requirements are not explicitly included. What is the best recommendation?

Hard
558

During an audit of a privileged access management (PAM) system, the auditor finds that privileged sessions are recorded but not reviewed. What is the primary risk?

Hard
559

A security review of the above Apache configuration identifies a critical vulnerability. Which of the following is the MOST significant issue?

Hard
560

An organization uses the access list above on its perimeter firewall. Which of the following is a valid conclusion?

Easy
561

During an agile software development project, which of the following events provides the best opportunity for the IS auditor to assess the effectiveness of controls implemented in the current sprint?

Easy
562

An organization is migrating sensitive customer data to a public cloud. Which of the following encryption strategies provides the STRONGEST protection against data exposure to the cloud provider?

Medium
563

Refer to the exhibit. An administrator applied this ACL to a VLAN interface. The server at 10.0.0.100 hosts a web application. What is the effect of this ACL?

Hard
564

An organization's IT strategy is not aligned with business strategy due to lack of communication. Which of the following would BEST improve alignment?

Hard
565

An organization performs daily full backups of its critical database. The recovery time objective (RTO) is 4 hours. During a disaster, it takes 6 hours to restore the database. What is the most likely cause?

Easy
566

During an audit of privacy controls, the IS auditor discovers that the organization processes personal data of EU residents but has not appointed a Data Protection Officer (DPO). Which regulation is MOST likely being violated?

Hard
567

During a vendor evaluation for a critical system, the IS auditor notes that the vendor's SOC 2 report includes an adverse opinion. What should be the auditor's PRIMARY recommendation?

Medium
568

An organization is implementing a backup strategy for its critical database. The database is updated continuously during business hours, and the recovery point objective (RPO) is 15 minutes. Which backup method should be used to meet the RPO while minimizing backup storage and performance impact?

Medium
569

Which TWO of the following are guiding principles of ITIL 4? (Select TWO)

Medium
570

During the fieldwork phase, an IS auditor discovers that a control is not operating as designed. The auditor reperforms the control and finds that it is effective. Which of the following conclusions is MOST appropriate?

Hard
571

Which THREE of the following are commonly accepted practices for securing mobile devices in an enterprise environment?

Medium
572

A multinational corporation operates in a highly regulated industry. The IT governance framework includes a risk appetite statement approved by the board. Recently, the company suffered a significant data breach due to an unpatched vulnerability that had been identified three months earlier. The IT audit found that the vulnerability was reported to the IT department but was not prioritized for remediation because it was deemed low risk by the IT operations team. The incident response plan was not activated because the breach was not initially detected. The board wants to strengthen governance to prevent recurrence. The most effective course of action for the auditor to recommend is:

Hard
573

An organization is implementing a new identity management system. Which testing approach is MOST effective for verifying access controls?

Medium
574

An organization is considering whether to build a custom application or purchase a commercial off-the-shelf (COTS) product. Which of the following factors is MOST important when deciding to build rather than buy?

Medium
575

A security architect is designing a data classification schema for a multinational corporation. Which combination of factors is MOST critical for determining the classification level of a data asset?

Hard
576

An organization uses a risk-based audit approach. For a high-risk area, the auditor decides to perform 100% testing instead of sampling. Which of the following is a valid reason for this decision?

Hard
577

An IS auditor is planning an audit of a financial application. The auditor wants to ensure that audit effort is focused on areas with the highest risk. Which approach should the auditor adopt?

Medium
578

Which of the following is a key performance indicator (KPI) for IT service management?

Easy
579

An organization is implementing a new payroll system using an agile methodology. Which TWO of the following are the MOST important controls for the IS auditor to assess?

Medium
580

An organization is implementing a new identity management system. Which THREE of the following are essential requirements for the system?

Medium
581

An organization outsources its IT help desk to a third-party vendor. Which clause is MOST important for the IS auditor to verify in the contract to ensure the organization can assess the vendor's controls?

Medium
582

An IS auditor is reviewing the access recertification process for a financial institution. The process requires users and their managers to confirm access rights quarterly. During the review, the auditor finds that recertifications are consistently completed late, with an average delay of 45 days. Additionally, terminated employees' access is not always removed promptly, and there are no compensating controls. Which of the following is the MOST significant risk arising from these findings?

Medium
583

An IT manager submits a request to change the firewall configuration during business hours. According to best practices for change management, what should be done FIRST?

Easy
584

An IS auditor is reviewing the organization's data inventory process for privacy compliance. Which TWO of the following are the MOST important elements that should be included in the data inventory?

Medium
585

An IS auditor is reviewing an agile project. Which THREE of the following are controls the auditor should evaluate?

Hard
586

Which TWO of the following are types of statistical sampling methods? (Select TWO.)

Medium
587

An organization's IT department implemented a new change management process that requires all changes to be approved by a change advisory board (CAB). A critical security patch needs to be deployed within 2 hours to address an active zero-day vulnerability. The change request was submitted but the CAB is not scheduled to meet for another 24 hours. What is the BEST course of action?

Medium
588

Which TWO of the following are the MOST effective controls to prevent unauthorized access to a data center's server room? (Choose two.)

Hard
589

Which of the following is the PRIMARY purpose of conducting a privacy impact assessment (PIA) before implementing a new system that processes personal data?

Easy
590

An IS auditor is reviewing the logical access controls of an enterprise resource planning (ERP) system. The auditor finds that terminated employees' accounts are disabled but not deleted. What is the PRIMARY risk associated with this practice?

Easy
591

Which of the following is the PRIMARY purpose of an IT governance framework?

Easy
592

Arrange the steps to implement a patch management process in the correct order.

Medium
593

During an SDLC audit, the IS auditor finds that security requirements were not formally documented during the requirements phase. Which of the following is the BEST recommendation to mitigate the associated risk?

Medium
594

An organization is developing a business continuity strategy. Which THREE of the following are essential components of a comprehensive BC strategy?

Hard
595

Which of the following is the most reliable form of audit evidence?

Medium
596

Which THREE of the following are common risks associated with the prototyping methodology?

Hard
597

Which of the following is a primary advantage of fixed-price contracts in systems acquisition?

Easy
598

Which of the following is a key principle of corporate governance of IT according to ISO/IEC 38500?

Easy
599

In a large enterprise, the IT department uses a RACI matrix for its change management process. The change manager is responsible for executing the change, but which role is typically accountable for the success or failure of the change?

Hard
600

During which phase of the audit process does the auditor perform procedures such as inquiry, observation, and inspection?

Easy
601

An organization has a disaster recovery plan that includes a hot site. During a full interruption test, the recovery team discovers that the hot site's network configuration is incompatible with the production environment. What is the most likely root cause?

Hard
602

Which TWO of the following are common risks in the procurement of custom-developed software?

Medium
603

After a security incident, an organization discovers that an employee accessed sensitive files without authorization. Which of the following is the most effective preventive control to reduce the risk of such unauthorized access?

Medium
604

During an audit, the IS auditor identifies that a system access control deficiency could lead to unauthorized modification of financial data. The deficiency does not have a compensating control. How should the auditor classify this finding?

Medium
605

Which type of audit evidence involves the auditor independently performing a control procedure to verify its effectiveness?

Medium
606

Order the steps for performing a disaster recovery test in the correct sequence.

Medium
607

An organization is implementing a new cloud-based HR system. The project sponsor wants to skip regular project status meetings to speed up delivery. Which THREE of the following are the MOST significant risks of eliminating these meetings?

Hard
608

An IS auditor is assessing the organization's compliance with privacy regulations regarding cross-border data transfers. Which TWO of the following are acceptable mechanisms to legitimize such transfers under the GDPR?

Medium
609

Which THREE of the following are valid reasons for implementing a service level management process? (Select THREE.)

Hard
610

Which TWO of the following are physical security controls to prevent unauthorized access to a data center?

Medium
611

During a disaster recovery test, the team discovers that the backup server is unable to restore data because of incompatible software versions. Which TWO controls should have been implemented to prevent this?

Easy
612

An IS auditor is reviewing the physical access controls at a data center. Which of the following is the MOST effective control to prevent tailgating?

Easy
613

An IS auditor is reviewing the audit documentation from a prior year and finds that a material weakness was reported but not remediated. According to ISACA standards, which audit phase should address this?

Hard
614

Which of the following is a potential risk in this RACI matrix?

Medium
615

An IS auditor is reviewing the system development life cycle (SDLC) methodology. Which phase should include the development of detailed test plans?

Easy
616

During a post-implementation review of a system, an IS auditor finds that the actual transaction processing time is 30% slower than projected. What should the auditor recommend FIRST?

Medium
617

An organization is implementing a new financial system using the waterfall SDLC model. Which of the following is the MOST critical control to ensure that business requirements are met?

Easy
618

A government agency is developing a case management system for law enforcement. The project follows an agile approach, releasing iterations every two weeks. During a sprint demo, users discover that the system does not redact personally identifiable information (PII) in documents shared with external parties, violating privacy laws. The development team says they planned to add redaction in a future sprint. The product owner wants to prioritize PII redaction immediately. The project manager is concerned that this will disrupt the release schedule. The IS auditor is assessing the project's risk management. Which of the following is the BEST recommendation?

Hard
619

Which of the following BEST describes the role of threat modeling in the design phase of the SDLC?

Medium
620

An organization is deploying a major system upgrade. The change request has been approved by CAB, but the deployment plan does not include a rollback procedure. As an IS auditor, what should you recommend?

Hard
621

An IT manager notices that the CPU utilization of a critical server consistently exceeds 90% during peak hours. Which is the BEST course of action?

Medium
622

Which of the following is the PRIMARY objective of a penetration test?

Easy
623

An IS auditor is reviewing the human resources practices in the IT department. Which THREE of the following controls are most effective in reducing the risk of fraud?

Hard
624

A company performs daily full backups of its database and weekly incremental backups. The backup retention policy requires keeping full backups for 30 days and incremental backups for 7 days. An auditor reviews the backup schedule. Which backup type provides the fastest restore?

Medium
625

Which of the following is the PRIMARY purpose of an IT strategy committee?

Easy
626

During the follow-up phase of an audit, the auditor discovers that a previous finding has not been remediated. What is the auditor's BEST course of action?

Medium
627

In a waterfall SDLC, when should user acceptance testing (UAT) typically occur?

Easy
628

An auditor is evaluating the IT governance framework of a large bank. Which TWO of the following are components of COBIT 2019's governance system? (Select TWO.)

Medium
629

An IS auditor is evaluating the reliability of audit evidence. Which TWO of the following are characteristics of reliable audit evidence?

Easy
630

An organization is implementing a new release management process. Which TWO activities are essential components of a successful release?

Easy
631

An organization is planning to replace its legacy accounting system with a commercial off-the-shelf (COTS) software package. Which of the following is the PRIMARY risk of using a COTS solution?

Easy
632

A healthcare organization has implemented a data classification policy with three levels: Public, Internal, and Restricted. The IT department recently received a report of a potential data breach. An internal auditor discovered that a database containing Protected Health Information (PHI) classified as Restricted was accessible via a web application that did not enforce encryption in transit. The web application uses HTTPS, but the auditor found that the connection was downgraded to HTTP due to a misconfiguration in the load balancer. Additionally, the database logs show that an external IP address queried the database for thousands of patient records over a two-hour period. The database was configured to allow only specific internal application servers, but the firewall rule was incorrectly set to allow connections from any IP address. The security team needs to determine the most effective immediate action to prevent further unauthorized access and protect the data. Which course of action should the security team take FIRST?

Hard
633

An organization has outsourced its IT operations to a third-party provider. The IS auditor is planning an audit of the outsourced services. What is the most appropriate source of audit evidence?

Easy
634

Refer to the exhibit. A developer is inserting a new employee record. What is the cause of this error?

Easy
635

Which of the following is a key objective of the design phase in the SDLC?

Easy
636

Which TWO of the following are phases of the audit process? (Select two.)

Easy
637

An organization's IT service desk is the single point of contact for all incidents. The SLA for resolving P2 incidents is 8 hours. The auditor finds that the service desk frequently reassigns P2 incidents to second-level support without updating the incident record, causing delays in resolution. The average resolution time for P2 incidents is 10 hours. What is the primary control weakness?

Hard
638

An IS auditor is reviewing the data subject rights fulfillment process for GDPR compliance. Which TWO of the following are required to be completed within the one-month response period?

Medium
639

Which IT sourcing model involves using an external provider to manage some IT functions while retaining others in-house?

Easy
640

Based on the exhibit, the IS auditor is reviewing access to the payroll folder. Which of the following is the MOST significant finding?

Hard
641

An organization uses a third-party cloud service for data storage. Which of the following is the BEST way to ensure data confidentiality in the event of a cloud provider breach?

Hard
642

A company requires employees to use smart cards for facility access. Which additional control would BEST prevent tailgating?

Easy
643

During a change management audit, the IS auditor notes that an emergency change was implemented to fix a critical security vulnerability. Which of the following should the auditor expect to find in the change documentation?

Medium
644

An organization's IT security policy requires background checks for all IT staff handling sensitive data. Which of the following is the PRIMARY reason for this requirement?

Medium
645

A company has been developing a custom inventory management system using Scrum. In the current sprint, the team discovered that the integration module with the legacy ERP system has severe performance issues: under peak load, transactions time out and fail. The product owner is concerned because the release is scheduled in two weeks. The development team estimates that a proper fix will take three weeks. A similar issue occurred in a previous sprint and was temporarily resolved by reducing the number of concurrent transactions, which lowered performance but kept the system operational. The stakeholders are anxious about the deadline because the legacy ERP will be retired shortly after the planned go-live. What is the BEST action for the team to take?

Hard
646

The IT governance objective 'Evaluate-Direct-Monitor' in COBIT 2019 is primarily associated with which role?

Easy
647

A retail company is merging with a competitor. The IT departments of both organizations have different IT governance structures: Company A uses a centralized model with strict change management, while Company B uses a decentralized model with autonomous business unit IT. The CIO has been tasked with integrating the IT functions post-merger. The board expects cost synergies and improved service levels. The integration team is facing resistance from Company B's business heads who fear loss of agility. The CIO needs to propose a governance model for the merged entity. Which approach would BEST meet the board's expectations while addressing resistance?

Medium
648

An IS auditor is assessing the effectiveness of an organization's IT governance framework. Which THREE of the following are key indicators of a mature governance process?

Hard
649

The exhibit shows a log entry from a domain controller. The IS auditor is investigating account lockout issues. What is the MOST likely cause of this event?

Hard
650

An IS auditor is reviewing a system development project and notices that user acceptance testing (UAT) is being conducted in the production environment due to lack of a separate test environment. What is the primary risk?

Medium
651

An IS auditor is evaluating the effectiveness of a backup strategy for a critical database. Which TWO of the following are essential controls to ensure data recoverability?

Medium
652

An organization has decentralized IT management with each business unit making its own technology decisions. Which of the following is the BEST way to maintain enterprise-wide governance?

Hard
653

Which TWO of the following are examples of detective controls? (Choose two.)

Medium
654

A company's backup policy requires that backup media be stored offsite. Which of the following is the PRIMARY reason for this requirement?

Easy
655

An organization is disposing of old servers. The IS auditor reviews the asset disposition process and finds that hard drives are being erased using a standard format command. What is the auditor's primary concern?

Hard
656

During an audit of a cloud service provider, the IS auditor finds that the provider's datacenter access logs show multiple successful logins by an employee during non-business hours over several weeks. The employee works in the sales department. What should the auditor do first?

Medium
657

An organization is considering replacing its legacy financial system with a new ERP solution. Which of the following is the PRIMARY advantage of purchasing a commercial off-the-shelf (COTS) ERP package over building a custom system?

Easy
658

An e-commerce company stores customer payment card data in a tokenized database. The tokenization system replaces credit card numbers with tokens, and the actual card numbers are stored in a separate, highly restricted vault. The company is audited for Payment Card Industry Data Security Standard (PCI DSS) compliance. During the audit, it is discovered that the tokenization system sometimes fails due to high load, causing the application to fall back to storing actual card numbers temporarily. This fallback mechanism was not documented or approved. The company also uses the same encryption key for the vault as for other non-sensitive data. The auditor identifies several non-compliances. Which of the following should the company prioritize to remediate?

Medium
659

During an ERP implementation, the project team decides to customize the software to align with existing business processes. Which of the following risks is MOST likely to increase as a result of extensive customization?

Medium
660

Which of the following is a key difference between internal and external auditors?

Medium
661

An organization is implementing a disaster recovery plan. The DR team wants to test the plan with minimal risk and without impacting production operations. Which type of test is most appropriate?

Medium
662

An organization has defined an RTO of 4 hours for its critical financial system. During a disaster recovery test, the system was recovered in 3.5 hours, but data loss was 30 minutes. Which metric is most directly addressed by the recovery time?

Easy
663

During the planning phase of an IS audit, the auditor identifies that the organization has recently implemented a new ERP system. The audit team has limited experience with this ERP. Which of the following is the BEST course of action?

Medium
664

Which of the following is the PRIMARY benefit of conducting a tabletop exercise for disaster recovery?

Easy
665

You are an IS auditor reviewing the remote access configuration for a medium-sized enterprise. The company uses a VPN concentrator to allow employees to connect from home. The VPN is configured with IPsec using pre-shared keys (PSK) and requires no multi-factor authentication. Employees use company-issued laptops with full disk encryption. The VPN logs show that connections are coming from a wide range of IP addresses, including some from countries where the company has no business operations. The IT manager argues that the PSK is changed monthly and that full disk encryption mitigates any risk. However, during the audit, you find that the PSK is stored in a shared document on an internal file server accessible to all employees. Additionally, the VPN concentrator uses a single PSK for all users. Which of the following is the MOST critical finding?

Hard
666

An IS auditor is planning an audit of a newly implemented financial system. Which of the following is the PRIMARY consideration when determining the audit scope?

Easy
667

Refer to the exhibit. An IS auditor reviewing backup logs notices this error. Which of the following is the MOST likely root cause?

Medium
668

During an audit, an IS auditor finds that a system administrator has not taken mandatory vacation in three years. Which control is most likely being violated?

Hard
669

Which TWO of the following are essential elements of a business continuity plan (BCP) for a newly developed system?

Easy
670

An IT policy exception is requested to allow a legacy system that cannot be patched to remain in operation. What is the BEST way to manage this exception?

Medium
671

Refer to the exhibit. A cloud load balancer uses this JSON configuration. A request arrives from source IP 10.0.1.100 to port 80. Which backend pool will receive the request?

Medium
672

An organization is acquiring a third-party SaaS application. Which of the following should be included in the contract to ensure data protection?

Medium
673

Refer to the exhibit. An IT operator receives this error message from an automated backup job. What is the MOST likely cause of this failure?

Hard
674

An organization has the storage bucket policy shown. Which of the following is the MOST likely intent of this policy?

Medium
675

You are the lead IT auditor for a multinational corporation that recently completed a merger with another company. During the post-merger integration audit, you discover that the acquired company's legacy HR system contains sensitive personal data of 20,000 employees and has been directly accessible from the internet for the last 18 months. The system runs on an unsupported operating system (Windows Server 2008) and uses a custom-built application with no logging enabled. The acquired company's IT manager argues that the server is isolated behind a firewall and has never been compromised. However, your review of firewall logs shows numerous connection attempts from unknown IP addresses. The integration team plans to decommission this system in three months. You need to determine the appropriate audit response. Which of the following should you do NEXT?

Hard
676

An organization classifies IT incidents based on severity. A critical financial application is unavailable, impacting all users. According to ITIL best practices, which severity level should this incident be assigned?

Medium
677

Which type of disaster recovery test involves a full switch-over from the primary site to the alternate site, resulting in actual disruption of normal operations?

Easy
678

An IS auditor is reviewing the logical access controls for a financial application. The auditor notices that user access reviews are performed annually by the application owner, but there is no documentation indicating that managers confirm the continued need for access. Which of the following is the MOST significant risk associated with this finding?

Medium
679

During an audit of an organization's change management process, the IS auditor selects a sample of 50 change requests from a population of 500. The auditor finds that 3 of the 50 did not have proper approval. What is the estimated error rate in the population?

Medium
680

An organization is adopting ITIL 4 to improve its service management practices. Which guiding principle emphasizes understanding how different components work together to deliver value?

Hard
681

Refer to the exhibit. Which of the following services is accessible from the internet to host 10.1.1.100?

Medium
682

An organization is implementing a business continuity plan (BCP). Which of the following is the PRIMARY purpose of conducting a business impact analysis (BIA)?

Easy
683

An administrator sees the above error after a failed backup job. What is the MOST likely cause?

Medium
684

An organization has a policy requiring strong passwords. Which additional control is most effective at preventing credential stuffing attacks?

Easy
685

Which document is typically included in the permanent file of audit documentation?

Easy
686

An auditor is reviewing IT policy compliance and finds that a critical policy was last updated three years ago. The organization has undergone significant changes. What is the auditor's PRIMARY concern?

Hard
687

An IS auditor is reviewing a software development project that follows the waterfall model. Which of the following is the MAIN advantage of this methodology?

Easy
688

Which THREE of the following are responsibilities of the board of directors regarding IT governance? (Choose three.)

Hard
689

During a change management audit, an IS auditor finds that a critical system change was approved by the change manager without a CAB meeting. The change was categorized as a standard change. Which of the following should the auditor do FIRST?

Medium
690

An auditor is reviewing the encryption strategy for a healthcare application that stores protected health information (PHI) in a database. The database currently uses transparent data encryption (TDE). What is a key risk associated with TDE?

Medium
691

Refer to the exhibit. A tester executes test case TC-101 and records the result shown. What is the NEXT appropriate step in the testing process?

Medium
692

A small business lacks formal IT governance. What is the FIRST step to establish governance?

Easy
693

An organization is implementing a new IT governance framework. Which of the following is the BEST approach to ensure alignment between IT strategy and business goals?

Medium
694

When implementing a commercial off-the-shelf (COTS) software package, which of the following is the MOST important activity to ensure the software meets business requirements?

Easy
695

Which TWO of the following are examples of administrative controls for information security?

Easy
696

An organization uses the policy shown. Which of the following is an omission in the policy?

Hard
697

An IS auditor is evaluating the design of controls over a new financial system. Which of the following is the BEST approach to assess control design?

Hard
698

During a penetration test, a tester discovers that an application stores passwords using a reversible encryption algorithm. Which of the following is the BEST remediation?

Medium
699

According to ITIL 4, which guiding principle emphasizes understanding the current state before making improvements?

Medium
700

An IS auditor is reviewing the change management process for a financial institution. The auditor finds that emergency changes bypass normal approval but are documented and reviewed within 48 hours. Which of the following is the BEST recommendation?

Hard
701

A company is experiencing frequent server crashes due to memory leaks. The operations team has implemented a monitoring solution. Which of the following is the BEST indicator to trigger an automated failover to a standby server?

Easy
702

An organization is adopting COBIT 2019. Which TWO of the following are components of the governance system?

Medium
703

During system development, the project team discovers that the original requirements are incomplete. What is the BEST course of action?

Medium
704

An organization is implementing an automated job scheduling system. Which of the following is the PRIMARY benefit of using dependency management in job scheduling?

Medium
705

An IS auditor is reviewing a change management process. A developer made an emergency change directly to production without following the standard change approval process. The change was later documented as a normal change. Which control weakness is MOST indicated by this scenario?

Medium
706

A multinational corporation is adopting a hybrid cloud strategy. The IT governance board must decide on a framework to ensure alignment with business objectives and regulatory compliance. Which framework is MOST appropriate?

Hard
707

Based on the backup logs, the backup administrator notices that the incremental backup job failed due to insufficient storage. Which TWO actions should the administrator take to resolve the immediate issue and prevent recurrence?

Hard
708

An IT auditor is reviewing the alignment of IT with business strategy. Which THREE of the following are indicators of effective IT strategy alignment? (Select THREE.)

Hard
709

During an audit of a cloud service provider, the IS auditor discovers that the provider's data center access logs show an employee accessing the production environment outside of normal business hours without a change request. What should the auditor do FIRST?

Medium
710

During a spiral SDLC project, the project team has completed a risk analysis and created a prototype. What is the most likely next step in the spiral model?

Hard
711

Which TWO of the following are examples of analytical procedures used as audit evidence? (Select two.)

Medium
712

An IS auditor is reviewing the system design phase of a project. Which of the following activities is most important to ensure that security is adequately addressed?

Medium
713

Which of the following is a characteristic of non-statistical (judgmental) sampling?

Medium
714

An IS auditor is reviewing the logical access controls for a critical database. Which of the following findings should be considered the HIGHEST risk?

Medium
715

A company is implementing a new customer relationship management (CRM) system. The project team is currently defining user roles and permissions. Which of the following is the PRIMARY reason to enforce segregation of duties (SoD) within the CRM?

Easy
716

Which TWO of the following are primary objectives of IT governance as defined by COBIT 5?

Medium
717

A company's IT service desk receives multiple reports of users being unable to access a cloud-based CRM system. The network team confirms that internet connectivity is working. Which of the following should be the FIRST step in troubleshooting the issue?

Medium
718

A medium-sized financial services firm recently suffered a ransomware attack that encrypted critical servers and backups. The recovery process took three weeks because the backup tapes were stored in the same building (which was also infected) and the backup software had a vulnerability that allowed the ransomware to delete old backups. The firm's BCP did not account for simultaneous loss of primary and secondary data. As the IS auditor, you are asked to recommend the most effective improvement to the backup strategy to prevent recurrence and improve resilience. Which of the following actions should the firm implement?

Easy
719

A multinational corporation is implementing a disaster recovery plan for its critical financial systems. The plan includes off-site backups and redundant hardware. During a recent test, the recovery time objective (RTO) was met, but the recovery point objective (RPO) was exceeded by 30 minutes due to delayed data replication. Which of the following is the BEST action to address this issue?

Medium
720

Which of the following is the PRIMARY purpose of audit working papers?

Easy
721

During which phase of the waterfall SDLC should security requirements be formally documented and approved by the business owner?

Easy
722

Which of the following is the primary purpose of conducting a static application security test (SAST) during the development phase of the SDLC?

Easy
723

An IT auditor is reviewing the capacity management process. Which TWO of the following are key activities that should be performed?

Medium
724

A healthcare organization is required to comply with HIPAA regulations for data backup and disaster recovery. They operate a primary data center and a colocation facility for disaster recovery. The current backup strategy involves nightly full backups to tape, which are stored off-site monthly. The recovery time for the electronic health record (EHR) system is estimated at 8 hours, but the RTO required by the business is 2 hours. Additionally, the RPO requirement is 15 minutes. The IT manager proposes implementing a continuous data protection (CDP) solution. However, the CFO is concerned about the cost. Which of the following is the BEST argument to justify the CDP investment?

Hard
725

Refer to the exhibit. An IS auditor is reviewing the architecture. Which of the following is the MOST critical security weakness?

Hard
726

Match each CISA domain to its focus.

Medium
727

A company is implementing a new ERP system. The project team plans to use a parallel conversion strategy. What is the PRIMARY advantage of this approach?

Medium
728

What is the PRIMARY purpose of conducting a feasibility study before acquiring a new information system?

Easy
729

A company is implementing a privileged access management (PAM) system. Which of the following is the MOST important control to prevent lateral movement after a privileged account is compromised?

Hard
730

An organization is developing a web application using an Agile methodology. The security team wants to integrate security testing early in the development lifecycle. Which of the following is the BEST approach to achieve this?

Medium
731

An organization's business continuity plan includes a reciprocal agreement with another company. What is the PRIMARY risk of this arrangement?

Hard
732

Which TWO of the following are key components of an IT governance framework?

Easy
733

An IS auditor is preparing working papers. Which of the following items should be included in the permanent file rather than the current file?

Hard
734

In a RACI matrix, the person who is ultimately accountable for a process outcome is assigned which role?

Easy
735

In ITIL incident management, which severity level typically indicates a critical incident that severely impacts business operations and requires immediate resolution?

Easy
736

An IS auditor is using statistical sampling to test a population of 10,000 transactions. The desired confidence level is 95%, and the tolerable error rate is 5%. Which of the following factors would MOST likely increase the required sample size?

Easy
737

Which of the following disaster recovery test types involves a full switch-over to the alternate site, resulting in actual disruption to normal operations?

Easy
738

Which of the following is a key performance indicator (KPI) for IT service management?

Easy
739

An IS auditor is reviewing change management procedures and finds that standard changes are approved by the change manager without CAB review. What is the auditor's BEST conclusion?

Medium
740

Match each type of access control to its definition.

Medium
741

During an IT audit, the auditor discovers that the IT department has not conducted a business impact analysis (BIA) for three years. The organization's disaster recovery plan (DRP) is based on the previous BIA. The IT manager argues that the DRP is still valid because no major changes have occurred. What should the auditor recommend?

Hard
742

During an audit, the auditor uses a sampling method where the population is divided into subgroups, and samples are selected from each subgroup. This method is known as:

Hard
743

During a data migration from a legacy system to a new ERP, the following log entries were generated. Which TWO issues should the IS auditor flag as high risk?

Easy
744

A company is migrating its on-premises data center to a public cloud provider. Which of the following is the MOST important control to implement before migration to ensure data security?

Medium
745

During an ERP implementation, data migration is a critical activity. Which of the following controls would be most effective in ensuring the accuracy and completeness of migrated data?

Hard
746

Based on the exhibit, which of the following is the MOST likely result of the current firewall configuration?

Hard
747

A project uses a waterfall model. After design, the team discovers that the requirements have changed significantly. What is the BEST action?

Hard
748

During an audit of the incident management process, the IS auditor finds that tabletop exercises have not been conducted in the past two years. What is the MOST significant risk associated with this finding?

Medium
749

An organization has implemented a database activity monitoring (DAM) solution. Which of the following are BEST practices for tuning the DAM to reduce false positives? (Choose TWO.)

Hard
750

Which of the following backup types copies only data that has changed since the last full backup?

Easy
751

An IS auditor is evaluating the use of continuous auditing techniques. Which of the following is the most significant benefit of implementing continuous monitoring over traditional periodic audits?

Hard
752

An IS auditor is reviewing a post-implementation review of a new payroll system. Which TWO findings should most concern the auditor? (Select two.)

Medium
753

A large enterprise is implementing a backup strategy for a critical database that requires an RTO of 2 hours and an RPO of 15 minutes. The database is 2 TB in size. Which backup method would BEST meet these requirements while minimizing storage costs?

Hard
754

Which THREE are indicators of a possible data exfiltration attempt via the network? (Choose three.)

Hard
755

Which of the following is the PRIMARY reason an external audit is considered more independent than an internal audit?

Easy
756

Which policy hierarchy document provides detailed steps for performing a specific task, such as resetting a user password?

Medium
757

During the acquisition of a new software package, the procurement team evaluates two vendors. Vendor A offers a lower upfront cost but higher annual maintenance fees. Vendor B has a higher upfront cost but includes three years of maintenance. What is the MOST important factor for the IS auditor to consider?

Medium
758

Which TWO controls are most effective for protecting data at rest on a database server? (Choose two.)

Medium
759

An organization outsources its help desk to a third-party vendor. The contract includes a service level agreement (SLA) with response times. The auditor wants to ensure that the organization can monitor vendor performance. Which clause is most important?

Medium
760

Which of the following types of audit evidence provides the highest level of assurance?

Medium
761

During the implementation of a new ERP system, the project team discovers that the legacy system data cannot be directly migrated due to incompatible data formats. The project manager proposes building a custom script to extract, transform, and load (ETL) data. Which of the following is the BEST course of action?

Medium
762

A multinational corporation operates an e-commerce platform hosted in a private cloud environment. The platform consists of web servers, application servers, and a database cluster. The database cluster uses synchronous replication across two data centers (Primary and DR) located 500 km apart. The recovery time objective (RTO) for the platform is 2 hours, and the recovery point objective (RPO) is 15 minutes. During a recent disaster simulation, the primary data center lost power completely. The IT team initiated failover to the DR site. However, the failover process took 3 hours due to a misconfiguration in the DNS failover scripts, and the database was found to be inconsistent because the replication link was broken 30 minutes before the power loss. The team had to restore from a backup that was 4 hours old. After the incident, management requests a review of the disaster recovery plan. Which of the following is the BEST course of action to address the issues identified?

Hard
763

During the fieldwork phase, an IS auditor uses analytical procedures to compare current year IT expenses to prior year. A significant increase is noted. What should the auditor do next?

Medium
764

Which physical security control is most effective for preventing unauthorized individuals from tailgating into a data center?

Easy
765

Match each audit risk component to its definition.

Medium
766

You are an information security manager for a global financial services company. The organization maintains a hybrid infrastructure with critical customer data stored on an on-premises Oracle database server (DB-SRV-01) and in an AWS S3 bucket (customer-data-prod). At 10:00 AM, the security operations center (SOC) alerts you to an anomalous outbound data transfer from DB-SRV-01 to an unknown IP address in a high-risk country. The transfer started at 9:45 AM and involves 500 MB of data, likely including personally identifiable information (PII). The SOC has already quarantined the server's network egress by blocking all outbound traffic from DB-SRV-01, but the server remains connected to the internal production network. Meanwhile, a separate analysis indicates that the S3 bucket has been accessed via an IAM key that was stolen from a compromised developer workstation three days ago. The key has not been rotated. The incident response team is preparing to act. The primary objective is to protect information assets and minimize data exposure. Given this scenario, which of the following actions should the team take FIRST?

Medium
767

Refer to the exhibit. A CISA is reviewing this S3 bucket policy. What is the PRIMARY security concern?

Easy
768

An IS auditor reviews the disposal process of hard drives. Which of the following methods provides the HIGHEST assurance that data cannot be recovered?

Hard
769

An organization is implementing IT governance based on COBIT. Which THREE of the following are enablers? (Select exactly three.)

Medium
770

An IS auditor is selecting audit procedures to test controls over user access. Which of the following is an example of a re-performance procedure?

Easy
771

During a problem management meeting, the team identifies a recurring issue causing multiple incidents. The root cause is known, but a permanent fix is not yet available. Which of the following is the BEST approach to manage this situation until a permanent fix is implemented?

Medium
772

An IS auditor is testing the effectiveness of a control that involves a manual review of exception reports. The population of exceptions is 5,000 items. The auditor wants to achieve a 95% confidence level with a tolerable error rate of 2%. Which sampling method is MOST appropriate?

Hard
773

Which backup method copies all data that has changed since the last full backup, regardless of subsequent incremental backups, and is often used to reduce restore time?

Easy
774

An organization is selecting an alternate site for disaster recovery. The site must have sufficient equipment to resume operations within a few hours, and the organization is willing to share the site with another business. Which type of alternate site is MOST appropriate?

Hard
775

An IT auditor is reviewing capacity management. The server team monitors CPU utilization and disk space. They receive alerts when thresholds are exceeded. Which practice is most effective for proactive capacity planning?

Easy
776

An organization is implementing an IT governance framework to align IT with business objectives. Which TWO of the following are primary responsibilities of the IT steering committee?

Medium
777

Based on the exhibit, which metric would be LEAST relevant to the 'Customer' perspective?

Medium
778

A large financial institution has a well-defined IT governance framework with a clear organizational structure, policies, and processes. However, the internal audit department has identified that several IT projects are over budget and behind schedule. The project managers blame unclear requirements and scope creep. The IT governance committee meets monthly but reviews projects only at a high level. The auditor's best recommendation to improve project governance is to:

Medium
779

An IS auditor is evaluating the change management process for a critical financial application. The auditor finds that all standard changes are approved by the Change Advisory Board (CAB). However, emergency changes are approved by the IT manager and later ratified by the CAB. Which of the following is the greatest risk associated with this process?

Hard
780

An IS auditor selects a sample of 50 transactions from a population of 1,000 using a random number generator. This is an example of which sampling method?

Medium
781

Which COBIT 2019 governance objective describes the board's responsibility for overseeing IT?

Easy
782

What is the primary purpose of the planning phase in an IS audit?

Easy
783

Which TWO of the following are primary objectives of information classification? (Choose two.)

Easy
784

An IS auditor is reviewing the configuration for a web application. Which of the following is the MOST significant security weakness?

Medium
785

A small manufacturing company uses a network-attached storage (NAS) device to store design files, financial records, and employee data. The NAS is backed up weekly to an external hard drive that is stored in the same office. The company has no encryption on the NAS or the backup drive. One weekend, the office is burglarized, and both the NAS and the backup drive are stolen. The company had no remote backup. Which of the following would have best protected the data in this scenario?

Easy
786

During a risk assessment, an IS auditor identifies that the IT department has not performed a business impact analysis (BIA) for critical systems. Which of the following is the MOST significant risk?

Hard
787

An IS auditor is reviewing the software asset management (SAM) process. The organization uses a mix of commercial off-the-shelf (COTS) and open-source software. The auditor finds that several servers are running end-of-life (EOL) operating systems that are no longer patched. Which TWO risks are most directly associated with this finding?

Medium
788

An organization is evaluating two vendors for a critical cloud-based ERP system. Which TWO contractual clauses are most important to include to ensure the organization can monitor vendor performance and security? (Select TWO)

Medium
789

Based on the exhibit, what is the most likely control weakness that allowed this condition?

Medium
790

Which of the following is a key objective of the COBIT 2019 management objective 'Align, Plan, and Organize' (APO)?

Medium
791

An IS auditor is reviewing automated job scheduling controls. A critical batch job failed due to a dependency on a previous job that had not completed. The system did not alert operations staff. Which control weakness is most significant?

Hard
792

During user acceptance testing (UAT) of a new financial system, users report that the system fails to enforce a segregation of duties rule where the same user should not be able to create a purchase order and approve it. The requirement was documented in the functional specifications. Which of the following is the MOST likely cause of this issue?

Medium
793

Refer to the exhibit. An IS auditor is reviewing backup error logs. The error indicates a failed backup due to a missing file. What is the MOST likely cause?

Easy
794

During a review of the incident management process, the IS auditor finds that the incident response (IR) team conducts tabletop exercises annually, but the scenarios are limited to malware outbreaks. Which of the following should be the auditor's GREATEST concern?

Hard
795

An IS auditor is reviewing the incident management process. The organization has a policy that all security incidents must be reported within one hour. However, the average reporting time is four hours. Which is the BEST corrective action?

Hard
796

An organization is replacing its legacy customer relationship management (CRM) system. Which of the following is the MOST important control to ensure data integrity during the data conversion process?

Easy
797

Which of the following is a principle of ISO/IEC 38500 for corporate governance of IT?

Easy
798

An IS auditor is performing a walkthrough of the accounts payable process. Which audit procedure is the auditor primarily executing?

Medium
799

During data conversion from a legacy system to a new ERP, the project team decides to clean data during extraction but not during loading. What is the PRIMARY risk associated with this approach?

Hard
800

An organization is implementing an ERP system and is concerned about segregation of duties conflicts. What is the most effective control to address this risk during implementation?

Medium
801

An IS auditor is evaluating a system development project that uses an outsourced team. The contract allows the vendor to reuse some of the developed code in other projects. What is the auditor's PRIMARY concern?

Hard
802

When implementing a commercial off-the-shelf (COTS) system, what is the MOST important factor?

Easy
803

What is the primary security concern in this architecture?

Hard
804

Which THREE of the following are best practices for managing system testing in an IS development project?

Medium
805

An IS auditor is evaluating the design of controls over a critical financial application. The auditor performs a walkthrough and identifies that a control is missing but management has compensating controls. Which of the following is the auditor's BEST next step?

Hard
806

Which TWO of the following are benefits of using a version control system in software development?

Easy
807

A company outsources its data center operations. Which IT governance practice is MOST critical to ensure the outsourcing arrangement meets business requirements?

Hard
808

A financial institution is required by regulators to demonstrate that IT controls are effective. Which of the following provides the BEST evidence?

Hard
809

An IT department uses a balanced scorecard to measure performance. Which metric would BEST reflect the 'customer perspective'?

Easy
810

Which of the following is a key objective of a post-implementation review?

Easy
811

Refer to the exhibit. An auditor reviews the security log of a sensitive server. Which of the following is the MOST suspicious event?

Medium
812

Which THREE of the following are typical phases in the system development life cycle (SDLC)?

Easy
813

A multinational corporation's data center in the European Union (EU) stores personal data of EU citizens. The company must comply with the General Data Protection Regulation (GDPR), which requires that personal data be protected and that data subjects have the right to erasure ('right to be forgotten'). The company's IT team uses a centralized identity management system that stores user credentials and personal data in an active directory (AD) forest. The AD forest is replicated across multiple data centers worldwide, including a non-EU country. The data protection officer (DPO) is concerned that personal data might be inadvertently replicated to jurisdictions without adequate protection. Which of the following is the most effective way to address this concern?

Hard
814

An IS auditor is evaluating the controls over program changes. Which TWO of the following are essential controls?

Medium
815

An IS auditor is reviewing the end-of-life (EOL) software policy. Which THREE risks are associated with running unsupported software? (Select THREE).

Hard
816

During the design phase of an SDLC, which TWO activities should be performed to ensure security is integrated into the system? (Select TWO)

Easy
817

An organization's IT service desk categorizes incidents based on severity levels. A P1 incident is defined as a critical system outage affecting all users. Which of the following is the MOST appropriate target for the initial response time for a P1 incident?

Easy
818

An IT manager is reviewing the service level agreements (SLAs) for a cloud-based email service. The SLA guarantees 99.9% uptime per month. The service experienced an outage of 45 minutes in a 30-day month. Did the service meet the SLA?

Medium
819

You are the IT audit manager for a multinational corporation. The company recently implemented a new enterprise resource planning (ERP) system using a phased rollout approach. The first phase (finance module) was deployed to three regional offices six months ago. During a post-implementation review, you discovered that the user acceptance testing (UAT) for the finance module was completed in only two days instead of the planned two weeks. The UAT was performed by a small group of power users selected by the project manager, and they reported no critical issues. However, after go-live, several finance staff in one region found that the system does not support a statutory reporting requirement specific to that country, which was not tested. The project manager argues that the requirement was never documented in the business requirements specification. The system has been live for six months, and the missing functionality requires a significant customization that will take three months and cost $200,000. Management is reluctant to fund the customization because the budget is exhausted. As the IT auditor, what is the BEST course of action?

Hard
820

An IS auditor is testing the effectiveness of a preventive control that rejects invalid transactions. The auditor uses a computer-assisted audit technique (CAAT) to create a set of test transactions. What is the primary risk associated with this approach?

Hard
821

During the feasibility study for a new inventory system, the project team identifies that the expected benefits are significantly lower than the initial estimates. What is the MOST appropriate action for the IS auditor to recommend?

Easy
822

An IS auditor is planning an audit of a small organization with limited IT staff. Which approach is most appropriate?

Medium
823

An organization is adopting ISO/IEC 38500 to govern IT. Which of the following best illustrates the application of the 'Human Behaviour' principle?

Hard
824

An IT audit revealed that the organization's IT steering committee has not met in the past six months. Which of the following is the MOST likely consequence of this situation?

Medium
825

Which THREE of the following are components of the ITIL 4 service value system? (Select THREE)

Hard
826

Which TWO of the following are benefits of establishing an IT steering committee?

Easy
827

An organization's availability management team reports that a critical server has an MTBF of 720 hours and an MTTR of 4 hours. What is the availability percentage for this server?

Medium
828

Which TWO of the following are components of an IT balanced scorecard? (Select TWO)

Easy
829

During which phase of the IS audit process does the auditor perform walkthroughs and test controls?

Easy
830

Which TWO of the following are primary objectives of the audit planning phase? (Select TWO.)

Easy
831

Which of the following is the PRIMARY objective of an operational audit?

Easy
832

An organization uses automated job scheduling with dependency management. A critical nightly batch job failed because a prerequisite job did not complete successfully. The job scheduler automatically attempted to rerun the failed job three times, each time failing due to the same dependency. The operations team was not alerted until the next morning. What control should the auditor recommend to improve this process?

Medium
833

A system has a Mean Time Between Failures (MTBF) of 500 hours and a Mean Time To Repair (MTTR) of 20 hours. What is the availability of the system?

Hard
834

An organization is planning to outsource its data center operations. Which of the following governance practices should be implemented to ensure proper oversight?

Medium
835

During an operational audit, the auditor uses ratio analysis to compare current year expenses to prior years and industry benchmarks. This is an example of which type of audit evidence?

Medium
836

Which TWO of the following are key elements of an effective incident response plan? (Select exactly 2.)

Medium
837

Which of the following is the BEST method to ensure that a system development project is completed on time?

Medium
838

An organization is implementing an enterprise resource planning (ERP) system. The project team plans to migrate legacy data without performing a full reconciliation between source and target systems. As an IS auditor, which of the following should be your PRIMARY concern?

Hard
839

An organization is performing software asset management (SAM) to ensure license compliance. Which two activities should the auditor verify?

Medium
840

An organization is developing a mobile app that will handle personal health information (PHI). The security team mandates that data must be encrypted both in transit and at rest. Which of the following implementation strategies BEST ensures compliance?

Hard
841

Which THREE of the following are common risks associated with outsourcing software development?

Hard
842

During a review of encryption practices, the IS auditor finds that an organization uses the same encryption key for all customer data at rest. What is the PRIMARY concern?

Medium
843

An organization uses a hot site as its disaster recovery alternative. Which of the following is the MOST critical consideration when selecting a hot site?

Medium
844

In the context of IT governance, what is the PRIMARY purpose of an exception management process for IT policies?

Hard
845

Which THREE of the following are commonly recognized benefits of implementing a formal IT service management (ITSM) framework such as ITIL?

Hard
846

During an audit of an organization's information security programme, the IS auditor finds that the security awareness training completion rate is 95% but phishing simulation tests show a 30% failure rate. What should the auditor recommend?

Medium
847

An IT manager is developing a governance policy for change management. Which element is MOST important to include?

Easy
848

An organization uses a chargeback model for IT services. What is the PRIMARY benefit of this approach?

Easy
849

Which TWO of the following are key components of an effective information security awareness program?

Easy
850

In a risk-based audit approach, which of the following BEST describes how an IS auditor should prioritize audit coverage?

Hard
851

In a DevOps environment, which practice BEST supports auditability?

Hard
852

An IS auditor is planning an audit of a small organization with limited IT staff. Which of the following is a key consideration for the audit approach?

Hard
853

An organization is implementing a new IT governance framework to align IT with business objectives. Which framework focuses on the principles of evaluate-direct-monitor?

Easy
854

Which of the following is a key difference between an internal audit and an external audit?

Medium
855

An IS auditor is reviewing the availability management process. The auditor calculates that the mean time between failures (MTBF) is 200 hours and the mean time to repair (MTTR) is 20 hours. What is the availability percentage?

Medium
856

Which THREE of the following are components of a typical IT governance framework?

Hard
857

During the design phase of a waterfall project, the development team discovers that a key security requirement was omitted from the functional specification. The design has already been partially completed based on the flawed specification. What is the MOST appropriate action?

Hard
858

An IT auditor is reviewing the release management process. Which of the following is the MOST important control to ensure that new releases do not negatively impact production systems?

Medium
859

Which TWO of the following are types of audit evidence recognized in IS audit practice?

Easy
860

An IS auditor is reviewing the disaster recovery plan (DRP) for an e-commerce company that generates 90% of its revenue online. The DRP states that the recovery time objective (RTO) for the transactional database is 4 hours, and the recovery point objective (RPO) is 1 hour. The current backup strategy includes nightly full backups and hourly transaction log backups stored on a local disk array. The backups are then copied to a remote datacenter via a WAN link with an average transfer speed of 10 Mbps. The database size is 500 GB. The auditor calculates that the time to transfer the full backup over the WAN is approximately 12 hours. The organization's management is confident that the DRP is adequate because they have never had to invoke it. What is the auditor's MOST critical finding?

Hard
861

An IS auditor is reviewing a contract with a vendor for a new financial system. Which of the following clauses is MOST critical to ensure auditability?

Hard
862

An IS auditor is evaluating the privacy controls of an e-commerce company that collects and processes personal data from customers in multiple jurisdictions, including the European Union (GDPR). The company has a data inventory but has not conducted a privacy impact assessment (PIA) for a new customer analytics platform that processes sensitive data. Which THREE of the following are the MOST critical deficiencies that the auditor should report?

Medium
863

During an audit, an IS auditor finds that the organization uses a cloud-based identity provider (IdP) for single sign-on (SSO) but does not enforce multi-factor authentication (MFA) for all users. Which of the following is the BEST recommendation to reduce risk?

Hard
864

Which THREE of the following are characteristics of SMART recommendations in an audit report? (Select three.)

Hard
865

An IS auditor is reviewing the vendor management program for a critical outsourced service. The vendor has recently been acquired by another company. Which TWO factors should the auditor be most concerned about regarding the acquisition?

Medium
866

During system implementation, a critical defect is found in the production environment. The project manager wants to apply an emergency patch without full testing. Which of the following is the BEST course of action?

Hard
867

Which type of audit is primarily concerned with evaluating the efficiency and effectiveness of operations?

Easy
868

A company is designing a public cloud-based application that processes highly sensitive personal data. Which of the following data protection strategies provides the STRONGEST assurance that data remains confidential even if the cloud provider's infrastructure is compromised?

Hard
869

An organization uses RAID 5 for its database server. Which of the following is the PRIMARY advantage of RAID 5?

Medium
870

An IS auditor is reviewing an organization's change management process. The auditor notes that all emergency changes are approved post-implementation by the change advisory board (CAB) within 48 hours. Which of the following is the auditor's BEST course of action?

Hard
871

During a change management review, an IS auditor discovers that a recent database upgrade was implemented without prior approval from the Change Advisory Board (CAB) because it was classified as a 'standard change.' However, the change involved migrating to a new database version that required application code modifications. What should concern the auditor most?

Medium
872

During a system development project, the project manager notices that the actual cost is significantly higher than the planned cost at the 50% completion point. The earned value (EV) is $500,000, the actual cost (AC) is $600,000, and the planned value (PV) is $550,000. Which of the following is the MOST appropriate action?

Hard
873

Which of the following is the MOST important objective of system testing?

Easy
874

A financial institution is implementing a data classification policy. Which of the following is the most important factor in determining the classification level of a data asset?

Easy
875

In the audit follow-up phase, which TWO actions are essential? (Select two.)

Medium
876

An organization is implementing a new CRM system using an iterative development methodology. The IS auditor wants to verify that appropriate controls are in place. Which THREE of the following are essential controls for iterative development? (Select THREE.)

Hard
877

Which TWO of the following are primary objectives of a business continuity plan (BCP)?

Medium
878

An IS auditor is reviewing the logical access controls of a system. Which of the following is the BEST evidence that access rights are appropriately assigned?

Easy
879

A company outsources its IT help desk to a third-party vendor. The service level agreement (SLA) specifies that all P1 incidents must be resolved within 2 hours. During an audit, the auditor finds that the vendor’s average resolution time for P1 incidents is 3 hours. What is the most appropriate recommendation?

Medium
880

A company's IT governance policy requires that all critical systems have a documented business continuity plan (BCP). During an audit, an IT auditor finds that the BCP for a critical financial system has not been updated in three years. Which of the following is the BEST recommendation?

Medium
881

An IS auditor is reviewing physical security controls at a data center. The data center hosts critical servers and uses a badge access system with PINs, CCTV cameras, and a mantrap entry. The auditor observes that employees sometimes hold the door open for others without badging. Which TWO of the following are the MOST effective controls to address this tailgating risk?

Easy
882

During an IT audit, the auditor finds that a system administrator has local administrator rights on multiple production servers and uses a shared service account for routine maintenance. What is the PRIMARY risk associated with this practice?

Easy
883

During a change management process review, an IS auditor finds that the change advisory board (CAB) approved a change that subsequently caused a major service outage. The change was classified as 'normal' with no emergency. What is the auditor's primary concern?

Medium
884

An organization is implementing a new IT service management system based on ITIL 4. Which TWO of the following are guiding principles of ITIL 4?

Medium
885

According to COBIT 2019, which design factor is MOST critical for tailoring a governance system?

Medium
886

An organization's IT strategy must be aligned with business strategy. Which of the following is the PRIMARY benefit of this alignment?

Easy
887

During an audit of IT asset management, the IS auditor finds that several servers are running an operating system that has reached end-of-life (EOL). The organization has not deployed any compensating controls. Which of the following is the GREATEST risk?

Hard
888

Which of the following audit types is most likely to be conducted by an employee of the organization being audited, potentially raising independence concerns?

Easy
889

Arrange the steps to configure a firewall rule in the correct order.

Medium
890

Which TWO of the following are examples of administrative controls for information security? (Choose two.)

Easy
891

During an audit, the IS auditor identifies that the audit team lacks the technical expertise to evaluate a specific system. According to ISACA standards, the auditor should:

Easy
892

An organization is planning to purchase a cloud-based HR system. Which THREE of the following should be included in the vendor contract to ensure adequate control and oversight? (Select three.)

Hard
893

A company is migrating its applications to a public IaaS cloud. What is the primary concern for protecting data in this environment?

Medium
894

What is the PRIMARY purpose of conducting a static application security testing (SAST) during the development phase?

Easy
895

An organization is implementing a new ERP system. The project sponsor requests a change that will significantly increase project scope without additional budget. Which of the following is the BEST action for the project manager?

Hard
896

An IT auditor is reviewing backup procedures. The organization performs daily full backups and retains them for 30 days. Additionally, weekly backups are retained for 12 months. Which of the following is the MOST likely risk associated with this backup strategy?

Medium
897

An organization stores sensitive research data in a cloud storage service. The data must be encrypted at rest and in transit, and the organization wants to maintain control over encryption keys. Which solution best meets these requirements?

Hard
898

An organization wants to implement an exception management process for IT policies. Which of the following is the most important step to ensure effective control?

Hard
899

An IS auditor is evaluating the encryption key management program of a healthcare organization that processes protected health information (PHI). The organization uses a mix of symmetric and asymmetric keys. Which TWO of the following are key management practices that should be addressed to ensure effective protection of PHI?

Medium
900

An IS auditor is reviewing an agile software development project. Which of the following practices would BEST help ensure that security controls are adequately addressed?

Medium
901

Which of the following is a requirement for effective segregation of duties in IT?

Easy
902

An IS auditor is reviewing a project that uses an iterative SDLC approach. Which THREE controls should the auditor expect to see in place during the development iterations? (Select THREE)

Hard
903

An organization's data classification policy defines 'Confidential' data as requiring encryption at rest. An IS auditor discovers that a database containing customer personal information is not encrypted. What is the auditor's BEST course of action?

Hard
904

An IS auditor is planning an audit of a newly implemented ERP system. The auditor wants to ensure that the audit covers critical controls. Which of the following is the most appropriate first step in the audit planning process?

Easy
905

Which THREE of the following are essential components of a change management process?

Easy
906

Match each disaster recovery site type to its description.

Medium
907

An organization is adopting a DevOps approach for system development. Which THREE controls should an IS auditor expect to see in place to maintain security and compliance?

Hard
908

An organization uses a COTS (commercial off-the-shelf) ERP system with significant customizations. The IS auditor is reviewing the system's configuration management. Which of the following findings would MOST indicate a weakness?

Hard
909

An IS auditor is performing a review of an organization's IT governance framework. Which of the following findings would be of MOST concern?

Hard
910

An organization's IT department is structured with a central unit that provides infrastructure and support, while individual business units have their own application development teams. This structure is BEST described as:

Medium
911

An IT auditor is reviewing the system development life cycle (SDLC) process for a critical application. Which of the following findings would be of MOST concern?

Medium
912

An IS auditor is reviewing the privileged access management (PAM) process. The auditor finds that shared administrative accounts are used for critical system maintenance and that passwords are changed quarterly. Which of the following is the BEST recommendation to mitigate the risk of audit trail loss?

Hard
913

A company's backup policy requires that backup tapes be stored offsite for at least one year. During an audit, the auditor finds that the offsite storage facility is not access-controlled and backup tapes are not encrypted. Which of the following is the auditor's BEST recommendation?

Medium
914

A company is deciding whether to centralize or decentralize its IT function. Which of the following is an advantage of a centralized IT structure?

Medium
915

During an IT audit, the auditor discovers that the IT strategy is not formally documented. Which of the following is the MOST significant risk associated with this finding?

Easy
916

During a disaster recovery planning audit, the IS auditor notes that the organization's plan includes a hot standby site. However, the plan has not been updated in two years, and the last test was a tabletop exercise 18 months ago. The organization has recently implemented a new ERP system. Which THREE findings should the auditor report as most significant?

Hard
917

An organization's backup strategy includes daily incremental backups and weekly full backups. During a disaster recovery test, the restoration of a critical server fails because a required incremental backup is corrupt. Which control should the organization implement to verify the integrity of backups?

Hard
918

During a change management audit, which TWO of the following are essential elements of a normal change request? (Select two.)

Medium
919

A company's security policy requires that all laptops have full-disk encryption. During an audit, 10% of laptops are found without encryption. Which of the following is the MOST effective corrective action?

Medium
920

An organization is implementing a new CRM system using an agile methodology. The IS auditor wants to assess whether security requirements are being addressed. What is the best evidence for the auditor to review?

Medium
921

A company uses role-based access control (RBAC). An employee moves from one department to another but retains some previous access due to overlapping role permissions. This condition is known as:

Hard
922

Which THREE factors should an IS auditor consider when determining the sample size for a compliance test? (Select three.)

Hard
923

During a nightly batch job, the above error appears in the application logs. The transaction table ACCT_TRANS has a unique constraint on the REF_NUM column. Which of the following is the MOST likely root cause?

Hard
924

An organization is using a spiral model for a high-risk project. The IS auditor wants to ensure that risk assessment is performed at each iteration. Which of the following is the BEST evidence that this control is effective?

Hard
925

During a security assessment, an auditor discovers that employees are sharing passwords to access a critical system. Which of the following controls would BEST mitigate this risk?

Easy
926

An IS auditor is planning an audit of a financial system. The auditor identifies that the inherent risk is high due to the complexity of transactions, but control risk is low because of strong automated controls. Which component of audit risk will be MOST affected by the auditor's testing strategy?

Medium
927

A small manufacturing company decides to acquire an off-the-shelf inventory management system. The purchasing manager selects a vendor based solely on the lowest price, ignoring the vendor's financial stability and support history. After purchase, the vendor declares bankruptcy, leaving the company without support. The system has a critical bug that halts inventory tracking. The IT manager considers hiring a consultant to fix the bug. As an IS auditor, what should the auditor's PRIMARY concern be?

Easy
928

Which TWO of the following are key responsibilities of an IT steering committee?

Medium
929

Which THREE are commonly used techniques to protect sensitive data in a cloud environment? (Select exactly 3.)

Medium
930

During an audit of incident management processes, the IS auditor reviews past incident reports and conducts interviews. The organization recently experienced a ransomware attack that encrypted critical systems. The incident response team was able to contain the attack but struggled with forensic collection due to lack of pre-defined procedures. Which TWO of the following should the auditor recommend as the HIGHEST priority improvements?

Hard
931

An organization is implementing a new incident management process based on ITIL. An incident classified as P1 (Priority 1) occurs. According to ITIL best practices, what is the most appropriate initial action?

Easy
932

Refer to the exhibit. An auditor reviews the log shipping configuration for a critical database. Based on the information provided, what is the MOST significant finding?

Easy
933

An organization outsources its data center operations to a third-party vendor. The contract includes a right-to-audit clause. During a scheduled audit, the vendor refuses to provide access to logs from a subcontractor managing network security. What is the IS auditor's best course of action?

Medium
934

After issuing the final audit report, the IS auditor should perform follow-up procedures. What is the PRIMARY purpose of follow-up?

Medium
935

An organization is evaluating its business continuity plan (BCP) to ensure alignment with the IT disaster recovery plan. Which TWO of the following are critical elements that should be included in the BCP to support effective business resilience?

Hard
936

Which THREE of the following are indicators of mature IT governance?

Hard
937

An organization is implementing an agile methodology for a new software project. Which of the following is the MOST effective control to ensure that security requirements are addressed?

Hard
938

An IS auditor is reviewing the termination procedure for IT employees. Which of the following is the most critical control to ensure immediate effectiveness?

Hard
939

An organization implemented a business continuity plan (BCP) that includes manual workarounds. Which of the following is the PRIMARY risk of relying on manual processes during a disruption?

Medium
940

A university's research department stores sensitive research data on a file server that is shared among faculty and graduate students. The server is accessible from the campus network and via VPN for remote access. Recently, a student downloaded a large dataset containing personally identifiable information (PII) of research subjects to a personal laptop. The laptop was later stolen. The university's incident response team determines that the student had legitimate access to the data for research purposes. Which control would have most effectively prevented the data exposure?

Easy
941

Which THREE of the following are key elements that should be included in a risk assessment report for information systems?

Hard
942

During a recent audit, the IT auditor found that the problem management process does not include a known error database (KEDB). Which of the following is the MOST significant risk associated with this finding?

Medium
943

An organization is implementing COBIT 2019 to improve IT governance. Which of the following is a key component of the governance system according to COBIT 2019?

Medium
944

An organization is evaluating its business continuity plan (BCP) for a critical application with a recovery time objective (RTO) of 4 hours and a recovery point objective (RPO) of 1 hour. The current backup strategy involves daily full backups and hourly transaction log backups. Which of the following is the MOST significant risk?

Hard
945

An organization is implementing a new CRM system and has chosen a build (in-house development) approach over buying a COTS product. Which of the following is the most significant risk of this decision?

Medium
946

An IS auditor is evaluating the effectiveness of an organization's information security awareness program. Which of the following is the BEST indicator of program effectiveness?

Hard
947

In the context of ITIL change management, which change type requires approval from the Change Advisory Board (CAB)?

Medium
948

Which THREE of the following are key considerations when selecting a software development methodology for a project?

Hard
949

Which TWO are primary criteria for classifying information assets within an organization? (Choose two.)

Easy
950

An IT department is struggling with project delays and budget overruns. Which governance practice would be MOST effective?

Medium
951

Which TWO of the following are typical controls in the testing phase of the SDLC? (Select two.)

Medium
952

Which THREE of the following are key metrics to include in a disaster recovery test report? (Select exactly 3.)

Hard
953

During a systems audit, the auditor finds that the project did not follow the organization's systems development methodology. What should the auditor do FIRST?

Hard
954

An organization is selecting a vendor for a new enterprise resource planning (ERP) system. Which of the following is the MOST critical factor in the vendor selection process?

Easy
955

Match each security control to its category.

Medium
956

A financial services company is developing a new customer-facing web application for account management. The project is using a waterfall methodology. The initial requirements were gathered six months ago, and the coding phase is nearly complete. The business sponsor now requests a new feature that allows customers to view transaction receipts online. The project manager is concerned that this change will delay the project by two months and exceed the budget. The sponsor insists that the feature is critical for customer satisfaction and that the project must adapt. The development team estimates it will take 200 hours to implement. The steering committee is divided. As an IS auditor, what would be the BEST recommendation to resolve this?

Hard
957

An IS auditor is reviewing the release management process for a critical application. The release strategy includes a phased rollout to 10% of users initially, then 50%, then 100%. The first phase revealed a data integrity issue that affected a subset of transactions. The release manager decided to continue with the next phase while a patch was being developed. What should the auditor most recommend?

Hard
958

A multinational corporation is designing its disaster recovery strategy to meet a recovery point objective (RPO) of 15 minutes for its critical database. Which replication method is MOST appropriate?

Hard
959

An IS auditor is reviewing vendor management practices for a cloud-based SaaS solution. Which TWO of the following are critical elements to include in the contract's service level agreement (SLA)? (Select TWO.)

Medium
960

An organization has configured HSRP as shown. During a failover test, the primary router (G0/1) is shut down, but the DR site router does not become active. What is the MOST likely reason?

Hard
961

An IS auditor is evaluating an organization's SDLC controls for a new system. Which TWO of the following are key controls that should be in place during the design phase? (Select TWO.)

Medium
962

Arrange the steps to perform a risk assessment in the correct order.

Medium
963

An organization is selecting a vendor for a new procurement system. Which of the following is the MOST important factor to include in the contract?

Medium
964

During an audit of the information security program, the IS auditor reviews the organization's information security policy. Which of the following is the PRIMARY purpose of an information security policy?

Easy
965

Which of the following is the MOST effective control to prevent unauthorized USB devices from connecting to corporate workstations?

Medium
966

An IS auditor is reviewing a business continuity plan (BCP). Which TWO of the following are key components of the business continuity strategy? (Select two.)

Medium
967

An IS auditor is assessing the backup and recovery procedures for a critical database. Which TWO of the following are the MOST important controls to ensure recoverability?

Hard
968

Which THREE of the following are acceptable methods for gathering audit evidence? (Select THREE.)

Medium
969

An IS auditor is assessing the effectiveness of controls over a critical financial system. Which TWO types of evidence provide the highest level of assurance? (Select TWO.)

Medium
970

An IS auditor is using analytical procedures during the planning phase. Which of the following is an example of an analytical procedure?

Medium
971

An organization's backup strategy involves weekly full backups and daily incremental backups. After a system failure, the restoration takes longer than expected. What is the most likely cause?

Easy
972

According to ISACA audit standards, which TWO of the following are phases of the audit process? (Select two.)

Easy
973

An IS auditor is reviewing the logical access controls of a financial application. Which of the following is the BEST way to verify that user access rights are appropriate?

Medium
974

An organization is developing its IT strategy to align with the overall business strategy. The business strategy emphasizes rapid market expansion through digital products. Which of the following IT strategies would BEST support this business goal?

Easy
975

An IS auditor is preparing the audit report. According to ISACA standards, which of the following should be included in the final audit report?

Easy
976

A company is considering restructuring its IT department from a centralized to a decentralized model to give business units more autonomy. What is a PRIMARY governance risk associated with this move?

Medium
977

Refer to the exhibit. An auditor reviews the ACL and notes that it allows traffic from a specific host while blocking other IPs in the same subnet. What is the most likely security issue?

Easy
978

An organization has experienced several security incidents due to unauthorized changes to production systems. Which governance mechanism should be strengthened?

Medium
979

Refer to the exhibit. The IAM policy is intended to allow only requests originating from account 123456789012 to perform any S3 actions. Why does the policy NOT achieve this objective?

Medium
980

An IT steering committee is reviewing a proposal for a new customer relationship management (CRM) system. Which of the following BEST demonstrates that the proposal aligns with the organization's strategic goals?

Easy
981

An IS auditor is reviewing the capacity management process for a server hosting a critical application. The server's CPU utilization has been consistently above 90% for the past three months, and memory usage is at 85%. There are no threshold alerts configured. The capacity plan shows that additional resources are scheduled to be added in six months. What should the auditor most recommend?

Medium
982

An IT auditor is reviewing the business continuity plan (BCP) for a financial services firm. The plan includes a hot site that is shared with another organization under a reciprocal agreement. Which of the following findings should be of MOST concern to the auditor?

Hard
983

An organization is implementing a COTS application. The project team plans to heavily customize the application to meet unique business processes. Which of the following is the most significant risk?

Hard
984

A software development company uses a cloud-based source code repository (e.g., GitHub) to store proprietary code. The company has two-factor authentication (2FA) enabled for all accounts. A developer's personal computer was infected with malware that stole the developer's session cookies and local credentials. The attacker used the stolen session to access the code repository and exfiltrated the entire codebase. The company's security team reviews the incident and notes that the repository has audit logging, but the logs were not monitored in real time. The team wants to implement additional controls to prevent a similar incident. Which control would have been most effective in preventing the exfiltration?

Medium
985

An IS auditor is evaluating the patch management process. The auditor notes that critical security patches are applied within 30 days, but the policy requires 7 days. The IT manager states that the delay is due to testing requirements. What should the auditor recommend?

Hard
986

Which TWO of the following are considered essential components of an information security policy framework? (Choose two.)

Medium
987

An organization is adopting a decentralized IT structure to better meet the needs of its business units. Which of the following is a potential risk of this approach?

Medium
988

An IT auditor is reviewing the change management process for a financial institution. The auditor finds that emergency changes are frequently approved by the change manager without CAB review. Which risk is most associated with this practice?

Medium
989

A company plans to implement a commercial off-the-shelf (COTS) application and requires significant customization to match its unique business processes. The vendor advises against extensive customization because it may complicate future upgrades. What is the BEST course of action?

Hard
990

A financial institution is deploying a data loss prevention (DLP) solution. Which of the following is the MOST important prerequisite to ensure the DLP can effectively detect sensitive data?

Easy
991

An IT auditor is evaluating the capacity management process. Which of the following findings would be of MOST concern?

Hard
992

An organization is implementing a change management process based on ITIL. Which THREE change types should be included in the policy?

Hard
993

Which of the following is a key performance indicator (KPI) for IT service management?

Easy
994

A company's availability monitoring shows that a critical application has an average MTBF of 720 hours and an average MTTR of 4 hours. What is the availability percentage?

Hard
995

Which TWO of the following are key benefits of using a system development life cycle (SDLC) methodology? (Select exactly two.)

Medium

Frequently asked questions

What does the scenario questions domain cover on the CISA exam?
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 995 scenario questions questions in the CISA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only scenario questions questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.