CISA · domain
scenario questions
Practise Certified Information Systems Auditor CISA scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice scenario questions questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about scenario questions
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common scenario questions exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All scenario questions questions (934)
Click any question to see the full explanation, or start a practice session above.
During a build vs. buy analysis, the IS auditor observes that the organization decided to build a custom application because no vendor solution met all requirements. Which of the following risks should the auditor emphasize?
Medium2An organization is implementing a privacy program to comply with GDPR. Which THREE of the following are essential elements for managing cross-border data transfers?
Hard3An online retail company runs its e-commerce platform on a virtualized infrastructure with 50 virtual servers. The platform experiences intermittent slowdowns during peak hours, and recent monitoring reports show that disk I/O latency on the storage area network (SAN) frequently exceeds 50 ms during these periods. The SAN has two fabric switches and a single storage array with 12 TB of usable capacity, currently at 80% utilization. The company’s disaster recovery plan requires recovery point objective (RPO) of 1 hour and recovery time objective (RTO) of 4 hours for the e-commerce platform. During a recent test failover to the disaster recovery site, the IT team discovered that the replication link between primary and DR sites is saturated, causing replication lag of up to 3 hours. The team also noted that the DR site storage has only 6 TB of usable capacity, now at 60% utilization. The IT manager is concerned about meeting the RPO and RTO. Which course of action should the IT team take first?
Hard4A company is using an agile development methodology for a critical business application. The IS auditor is concerned about the lack of formal documentation. What is the BEST approach to mitigate this risk?
Medium5An IS auditor is reviewing the audit follow-up process. The auditor notes that management has implemented corrective actions for 80% of previous audit findings. What should the auditor conclude?
Medium6A company is developing a mobile banking application. Which test phase is MOST critical to ensure that the application functions correctly from the end user's perspective?
Easy7An organization uses automated job scheduling for nightly batch processing. One job fails due to a missing dependency file. What is the most effective control to prevent recurrence?
Easy8An IS auditor is conducting a preliminary review of a newly acquired subsidiary and needs to understand the organizational structure, key business processes, and the technology environment before drafting the engagement plan. Which of the following techniques is MOST appropriate for gathering this broad understanding?
Easy9During a review of firewall rule sets, an IS auditor finds a rule that allows any source IP to access any destination IP on TCP port 443. Which of the following should the auditor do FIRST?
Medium10An IS auditor is planning the use of computer-assisted audit techniques (CAATs) to test a large transaction population for duplicate payments. Which of the following is the MOST important consideration before relying on the CAAT results?
Hard11An IS auditor is evaluating the security of the architecture. Which of the following is the MOST critical finding?
Medium12An IT auditor is reviewing the policy hierarchy of an organization. Which of the following correctly describes the relationship between a policy and a procedure?
Hard13An IS auditor is performing a compliance audit of data privacy regulations. The auditor finds that the organization's privacy policy is not fully aligned with regulatory requirements. Which of the following is the auditor's BEST course of action?
Hard14An IS auditor is conducting an audit of a small manufacturing company's IT operations. The company has 50 employees and uses a single server running Windows Server 2019 for file sharing and print services. There is no formal change management process. The IT manager, who also doubles as the system administrator, has full administrative rights and is the only person who can make changes to the server. During the audit, the auditor notices that the server's local security policy is configured to allow unlimited password attempts and no account lockout. The IT manager states that this is to avoid locking out users who forget their passwords. The auditor also finds that the guest account is enabled on the server. What should the auditor recommend as the HIGHEST priority action?
Easy15An organization uses a hot site for disaster recovery. During a recent test, the hot site did not have the latest version of the application software. What is the MOST likely cause?
Medium16An organization's IT security policy requires that all employees complete annual security awareness training. An auditor notes that completion rate is only 60%. What is the MOST effective way to monitor compliance?
Medium17A hospital is implementing a new electronic health record (EHR) system to replace a legacy system. During the implementation phase, the project manager proposes using a parallel changeover strategy. Which of the following is the MOST significant risk associated with this approach?
Medium18What is the primary purpose of a chargeback model for IT services?
Medium19An IS auditor is planning an audit of an organization's IT infrastructure. Which of the following is the PRIMARY benefit of using a risk-based approach?
Easy20An IS auditor is reviewing the process for granting privileged access in a large organization. Which of the following findings should be of MOST concern?
Medium21During a business impact analysis (BIA), a department manager states that their process can be disrupted for up to 8 hours, but data loss cannot exceed 15 minutes. Which two metrics are defined by these statements?
Hard22An information systems auditor is evaluating user accounts in an organization's Linux environment. The accounts have the following properties: - The 'root' account has its password field set to '!!' (disabled). - The 'admin' account has its password field set to '!' (locked) and UID 0. - The 'test' account is a regular user with UID 1000. Based on this information, which user account poses the HIGHEST security risk?
Medium23An organization is implementing ITIL 4. Which TWO of the following are part of the four dimensions of service management? (Select TWO.)
Medium24Which TWO of the following are primary objectives of capacity management? (Select exactly 2.)
Medium25Which of the following is the PRIMARY purpose of conducting a penetration test?
Easy26An IS auditor is designing test procedures for an audit of an organization's network perimeter. The auditor plans to use computer-assisted audit techniques (CAATs) to analyze firewall log data covering six months. Which TWO of the following are the MOST important considerations when using CAATs in this engagement? (Choose two.)
Hard27An organization's business continuity plan (BCP) includes alternate facilities that can be operational within 24 hours. The maximum tolerable downtime (MTD) for a critical process is 12 hours. What is the most significant gap?
Medium28A multinational manufacturing company with operations in 20 countries has historically allowed each regional division to manage its own IT systems independently. Recently, the company experienced a significant data breach originating from a region with weaker security controls, leading to financial losses and reputational damage. The board has mandated stronger IT governance to prevent future incidents. The CIO proposes implementing a global IT governance framework with centralized policy enforcement. However, regional directors argue that local regulations and business needs require autonomy. The governance committee must decide on a course of action that balances risk and business flexibility. Which of the following approaches is the MOST appropriate?
Hard29An IS auditor is reviewing a post-implementation review report for a new financial system. Which finding would most indicate that the project did not meet its objectives?
Medium30Which of the following is the BEST example of an analytical procedure used during an IS audit?
Medium31Given this configuration, which is the PRIMARY concern?
Medium32An organization is evaluating a cloud-based identity as a service (IDaaS) for single sign-on (SSO). Which of the following security concerns is MOST critical to address?
Hard33An organization's backup strategy includes taking full backups weekly and transactional log backups every 15 minutes. The auditor wants to verify that backup encryption is implemented for offsite storage. Which control is most relevant?
Hard34Which type of change in ITIL requires approval from the Change Advisory Board (CAB) before implementation?
Easy35A company has multiple business units with conflicting IT priorities. Which governance body should resolve this?
Medium36Based on the exhibit, what should the IS auditor MOST likely recommend?
Hard37Which TWO of the following are primary objectives of an information system audit?
Easy38Which of the following is the PRIMARY purpose of conducting a privacy impact assessment (PIA)?
Easy39An IS auditor is reviewing the physical security controls at a data center that hosts the organization's primary transaction processing systems. The auditor observes that the data center uses a single-factor proximity card reader at the main entrance, the server room door is propped open during a vendor maintenance visit, and CCTV cameras record continuously but recordings are retained for only seven days. Which of the following should the auditor identify as the MOST significant control weakness?
Medium40A medium-sized retail company relies on an ERP system for order processing and inventory management. The system is hosted on-premises with daily backups stored on tape. The company's business continuity plan specifies an RTO of 4 hours and an RPO of 1 hour for the ERP system. During a recent fire drill, it was discovered that restoring the ERP system from tape took over 6 hours, and the most recent backup was from the previous day. Which of the following is the BEST course of action to meet the RTO and RPO goals?
Easy41An organization uses role-based access control (RBAC) for its enterprise resource planning (ERP) system. What is the greatest risk if user role assignments are not reviewed regularly?
Medium42An IS auditor is reviewing an organization's network segmentation design. The organization states that its cardholder data environment is isolated from the corporate network. During testing, the auditor discovers that a management VLAN can reach both environments and that the firewall permits administrative protocols from the management VLAN to any host. Which of the following is the auditor's BEST conclusion?
Medium43An organization is planning a full interruption test of its disaster recovery plan. Which THREE of the following should the IS auditor recommend as best practices for this type of test? (Select three.)
Hard44An IS auditor is reviewing the physical security controls at a data center that hosts the organization's core banking platform. During the walkthrough, the auditor notes that the mantrap entrance functions correctly, but the loading dock door is propped open for ventilation and the CCTV system records only the main corridor. Which TWO of the following findings should the auditor report as control weaknesses? (Choose two.)
Medium45Which TWO of the following are common objectives of an IT balanced scorecard? (Choose two.)
Easy46During the requirements gathering phase for a new financial system, stakeholders disagree on the priority of security controls versus user convenience. Which of the following is the BEST approach?
Medium47An organization has implemented role-based access control (RBAC). Which of the following is the PRIMARY benefit of RBAC?
Easy48A hospital is implementing a new electronic health records (EHR) system. The system will be used by doctors, nurses, and administrative staff. During the user acceptance testing (UAT) phase, the nursing staff reports that the interface for entering patient vitals is too slow and requires many clicks, which slows down their workflow. The project team has already completed system testing and is preparing for go-live in two weeks. The development team can make a quick fix to streamline the vital signs entry by adding a shortcut, but this change has not been tested. The IT director is concerned about patient safety and wants to ensure the system is usable. What is the BEST course of action?
Medium49When an organization uses an external provider to manage its IT help desk, this is an example of which sourcing model?
Medium50An organization is implementing a new customer relationship management (CRM) system using an agile methodology. Which THREE areas should the IS auditor focus on to assess the effectiveness of controls during the development process?
Medium51An organization is considering outsourcing its IT help desk. Which of the following is a key risk that should be addressed in the outsourcing contract?
Medium52Which TWO of the following are essential components of an effective incident response plan? (Select exactly 2.)
Medium53Which of the following is a key control in the deployment phase of the SDLC?
Easy54A multinational corporation is deploying a data loss prevention (DLP) solution across its network. The DLP system must be configured to prevent the exfiltration of personally identifiable information (PII) while minimizing false positives. Which approach is most effective?
Hard55A large enterprise recently experienced a data breach due to an insider threat. The IT governance committee is reviewing the incident and considering measures to prevent recurrence. Which of the following is the BEST course of action to address the root cause?
Medium56An organization uses a standard change model for low-risk, pre-approved changes. Which of the following is an example of a standard change?
Medium57In a spiral SDLC model, what is the primary purpose of risk analysis in each iteration?
Easy58An organization is migrating from a legacy system to a new ERP. Which TWO of the following are the HIGHEST risks during data migration?
Medium59A systems analyst is gathering requirements for a new customer relationship management (CRM) system. Which of the following is the MOST important activity to ensure that the final system meets user needs?
Easy60According to ISACA IT Audit Standards, which of the following is the primary purpose of audit documentation (working papers)?
Easy61Arrange the steps to implement a password policy in the correct order.
Medium62During a third-party software vendor audit, the IS auditor discovers that the vendor uses a common shared database for multiple clients and relies on application-level access controls. Which of the following is the GREATEST concern?
Hard63An organization uses shared accounts for system administration. Which of the following is the MOST significant audit concern?
Medium64An IS auditor is reviewing the organization's incident management process. Which THREE of the following are essential components of an effective incident response plan?
Hard65An IT auditor is reviewing the business continuity plan (BCP) testing schedule. The organization conducts a test where participants discuss their roles and responses to a scenario without any actual system activation. Which type of test is this?
Easy66An organization is implementing a change management process. A change that requires approval from the Change Advisory Board (CAB) but is scheduled to be implemented during the next maintenance window is classified as which type of change?
Hard67In a RACI matrix for the change management process, who is typically Accountable for the overall change process?
Hard68An IT steering committee is reviewing a proposed project to migrate critical applications to the cloud. Which of the following is the PRIMARY role of the IT steering committee in this decision?
Medium69Which TWO of the following are key components of an IT governance framework? (Choose two.)
Easy70An organization is implementing COBIT 2019. Which TWO of the following are governance enablers? (Choose two.)
Medium71An IS auditor is reviewing change management procedures. Which of the following situations would be of GREATEST concern?
Medium72In a RACI matrix for an IT change management process, who is responsible for performing the change?
Easy73An IS auditor is reviewing the post-implementation review (PIR) of a newly deployed human resources (HR) system. Which of the following should be the PRIMARY focus of the PIR?
Easy74A financial institution is evaluating its IT governance structure. Which of the following roles is BEST suited to ensure independent oversight of IT investments?
Medium75An IS auditor is reviewing the physical security controls at a data center. The auditor observes that the data center has a single entrance with a biometric scanner, but the door is propped open by a cleaning cart while the cleaning staff works inside. Which of the following is the MOST appropriate action for the auditor to take?
Easy76Based on the exhibit, what is the security risk of this bucket policy?
Easy77An IS auditor is evaluating the effectiveness of an organization's business continuity plan (BCP). Which of the following findings would be of GREATEST concern?
Easy78An organization wants to ensure that IT performance is measured against strategic goals. Which tool is BEST suited?
Easy79An IT auditor is reviewing the change management process for a financial application. The auditor finds that emergency changes are frequently implemented without post-implementation review. What is the MOST significant risk?
Medium80An organization's IT governance committee is reviewing a proposal to use a public cloud provider that does not meet the organization's data encryption standards. The board has set a low risk appetite for data privacy. What is the BEST action?
Hard81An IS auditor is reviewing an organization's implementation of a security information and event management (SIEM) system. The auditor wants to assess whether the SIEM is effectively supporting incident detection and response. Which TWO of the following are the MOST important factors for the auditor to evaluate? (Choose two.)
Hard82An auditor finds that access reviews have not been completed for two quarters. What is the MOST significant risk?
Hard83An IS auditor is selecting an appropriate audit sample. Which THREE of the following are factors that affect the sample size?
Medium84A company is implementing a new procurement system. The project team is considering using a rapid application development (RAD) methodology. Which of the following is a potential risk of using RAD?
Medium85Which THREE of the following are components of the COBIT 2019 governance system?
Hard86An IT auditor is reviewing the asset management process for hardware lifecycle. Which two controls should the auditor verify to ensure secure disposition of decommissioned servers?
Medium87An IS auditor is reviewing a network access control list and finds that a rule permits traffic from any source to a database server on port 1521. Management states the rule is required for a legacy application. Which of the following is the MOST appropriate audit response?
Hard88An IS auditor is reviewing the audit committee's oversight of the IT audit function. Which of the following is the MOST important factor for the auditor to consider when assessing the committee's effectiveness?
Easy89An IS auditor is assessing the controls in an agile development environment. What is the MOST effective way to verify that security testing is performed iteratively?
Medium90An IS auditor is reviewing a project to implement a new loan origination system. The project manager has produced a detailed work breakdown structure (WBS), a critical path schedule, and a resource-loaded plan. Which of the following should the auditor verify FIRST to assess whether the project schedule is realistic?
Medium91An IS auditor is evaluating the effectiveness of a control. The auditor observes the control being performed and then independently performs the same control to confirm the result. Which combination of evidence types is being used?
Hard92An organization is negotiating a contract with a cloud service provider. Which clause is most important for the IS auditor to ensure is included?
Easy93During a change advisory board (CAB) meeting, a proposed change to the database server is discussed. The change involves implementing a security patch that requires a reboot. The change is categorized as 'normal' and has been risk-assessed as low impact. What is the most likely role of the CAB in this scenario?
Medium94An IS auditor is evaluating the capacity management process. The auditor notices that CPU utilization has been consistently above 90% for the past three months. The IT manager states that no proactive capacity planning has been performed. What is the primary risk?
Medium95An organization is deciding between building a custom application and purchasing a commercial off-the-shelf (COTS) product. The primary factor favoring the build option is:
Hard96A financial institution recently experienced a data breach where an attacker exfiltrated customer data through an SQL injection vulnerability in a web application. The IS auditor has been asked to review the application security controls. The web application is developed in-house and runs on an application server behind a web application firewall (WAF). The auditor reviews the WAF logs and finds that no SQL injection attacks were detected before the breach, but the logs show many blocked XSS attempts. The developer states that all input validation is performed on the client side using JavaScript. During the audit, the auditor also finds that the application uses a shared database account with DBA privileges for all connections. What is the MOST significant weakness that directly contributed to the breach?
Medium97An IS auditor is reviewing the physical security controls at a data center. The auditor observes that entry to the data center requires a smart card and a PIN, and that the door is a single-leaf door with a standard lock. Which of the following is the MOST important physical security control that the auditor should recommend?
Easy98Which of the following audit types is performed by an independent third-party auditor and is typically required for regulatory compliance?
Easy99An organization outsources its data center operations to a third-party provider. Which of the following is the MOST important clause to include in the contract to ensure the organization can verify the provider's controls?
Medium100An organization is selecting a disaster recovery (DR) site. The primary data center is located in a region prone to earthquakes. The DR site should be at a sufficient distance to avoid the same disaster. Which type of alternate site provides the best balance of cost and recovery time for a medium-sized organization?
Hard101Which of the following is a key control during the deployment phase of a system development life cycle?
Easy102During the planning phase of an IS audit, which of the following is the PRIMARY purpose of conducting a risk assessment?
Easy103During an information systems audit, the IS auditor finds that data classification labels are not consistently applied across the organization. What is the most likely root cause of this issue?
Hard104An IS auditor is assessing network security controls. Which TWO of the following are key elements of a firewall rule review?
Medium105A large financial institution is evaluating the effectiveness of its IT governance framework. The board has requested a review to ensure alignment with business objectives and regulatory requirements. Which of the following is the MOST important factor for the board to consider when assessing the IT governance framework?
Medium106Refer to the exhibit. An auditor finds that the file 'sensitive.txt' has world-writable permissions. Which of the following is the most appropriate remediation action?
Easy107An IT steering committee is evaluating a proposal to migrate critical applications to the cloud. Which factor is MOST important to ensure alignment with business strategy?
Medium108In business continuity planning, a company identifies a critical business process with a maximum tolerable downtime (MTD) of 4 hours. What is the primary purpose of this metric?
Easy109An organization is migrating data from a legacy system to a new ERP. What is the most critical data migration risk?
Medium110According to ISACA IT Audit Standards, which phase of the audit process includes the development of an audit programme?
Easy111An IS auditor is assessing the implementation of a new system that uses a relational database. The project team plans to migrate data from several legacy sources. Which TWO of the following controls are MOST important to include in the data conversion plan to help ensure the integrity of migrated data? (Choose two.)
Medium112During a post-implementation review of a new accounting system, the IS auditor notes the following: the project was completed on time and within budget, but user satisfaction is low and there are several outstanding defect reports. Which THREE of the following are the MOST appropriate recommendations?
Hard113Which TWO of the following are components of audit risk in IS auditing?
Medium114Which THREE of the following are common techniques for ensuring business resilience?
Hard115A compliance audit is primarily concerned with:
Easy116An organization uses automated job scheduling for batch processing. A critical job fails due to a dependency on another job that has not completed. Which of the following controls would BEST prevent this issue?
Medium117A healthcare organization must comply with HIPAA regulations regarding patient data privacy. The IT department has implemented technical controls, but the compliance officer discovers that some employees are sharing passwords. What is the BEST governance response?
Easy118An IS auditor is evaluating an organization's IT governance maturity using COBIT 2019. The auditor finds that IT processes are largely ad hoc, with no formal documentation or consistent monitoring. However, the organization has recently implemented a tool to automate some IT service management tasks. Management believes this tool elevates their maturity to a managed level. The auditor should:
Hard119Which TWO of the following are examples of IT governance frameworks? (Select TWO.)
Easy120During an audit of network security controls, the IS auditor reviews firewall rule sets and identifies a rule that allows any-to-any traffic from the internal network to the Internet. The rule has a business justification. What is the auditor's BEST recommendation?
Hard121An IS auditor is assessing how an organization manages the risk of malicious code on employee workstations. The organization has deployed endpoint detection and response (EDR) agents on all workstations and maintains a centralized console. Which of the following is the MOST important factor in determining whether the EDR deployment effectively reduces malicious code risk?
Medium122A medium-sized manufacturing company has recently deployed an ERP system to integrate its financial, supply chain, and HR processes. The IT department is small (5 staff) and reports to the CFO. The company has no formal IT governance committee; IT decisions are made by the CFO and CEO informally. During a recent audit, it was found that several critical security patches for the ERP system have not been applied, and there are no documented procedures for change management. The IT manager states that patches are applied when time permits, and changes are discussed via email. The CFO argues that the ERP is running fine and the audit findings are low risk. The IS auditor needs to recommend a course of action to improve IT governance. Which of the following is the MOST appropriate initial step?
Easy123An IS auditor is conducting an audit of a payroll application and selects a statistical sample of 200 payment transactions from a population of 20,000. Testing reveals 12 transactions where the gross pay was calculated incorrectly due to a flawed overtime rule. Which of the following is the MOST appropriate interpretation of this result?
Medium124During an audit of a data center, an IS auditor discovers that a critical server's operating system has not been patched for eight months because the vendor's patch conflicted with a legacy application. Management accepts the risk and documents a compensating control of enhanced network monitoring. Which of the following should the IS auditor do NEXT?
Hard125An organization is developing a business continuity strategy. According to best practices, which THREE of the following should be included in the strategy?
Medium126During an audit of a financial application, the IS auditor discovers that user access reviews are performed quarterly instead of monthly as required by policy. Which of the following is the BEST initial action for the auditor?
Medium127Which of the following is the BEST indicator that an organization's data security governance is effective?
Hard128An IS auditor is reviewing an emergency change that was implemented to fix a critical security vulnerability. What is the most important post-implementation step?
Hard129Which of the following is a key component of an IT balanced scorecard from the 'internal process' perspective?
Medium130An organization's IT governance framework includes a policy that all system access must be reviewed quarterly. The internal audit finds that reviews are incomplete. What is the BEST action?
Medium131An IS auditor is evaluating how an organization manages operating system patches on internet-facing web servers. The patch management procedure requires testing in a staging environment, approval by the change manager, and deployment within 30 days of release. The auditor finds that emergency patches for critical vulnerabilities are deployed directly to production within 24 hours without staging tests. Which of the following is the MOST appropriate conclusion?
Hard132A project manager is selecting a development methodology for a project with well-defined requirements and low uncertainty. Which methodology is most appropriate?
Easy133An IS auditor is reviewing how a data center schedules preventive maintenance on its uninterruptible power supply (UPS) systems and backup generators. The operations manager states that maintenance is performed monthly by an external vendor and that no formal maintenance window is documented because the work is done during low-usage hours. Which of the following is the MOST significant audit concern?
Medium134An IS auditor is reviewing the implementation of a new payroll system. The project team has decided to use a pilot conversion approach. Which TWO of the following are the MOST significant advantages of this approach? (Choose two.)
Hard135An organization is implementing a custom ERP system. During user acceptance testing (UAT), critical bugs are found that affect core financial processing. The project sponsor suggests deploying the system on schedule and fixing bugs after go-live. What is the BEST course of action?
Medium136Which ITIL 4 guiding principle emphasizes understanding the current state and building on existing capabilities rather than starting from scratch?
Medium137Which TWO of the following are essential components of a disaster recovery plan (DRP)?
Easy138An organization is developing a business continuity strategy for its key customer-facing application. The BIA determined an RTO of 2 hours and an RPO of 30 minutes. Which TWO strategies are most appropriate to meet these objectives?
Medium139An IT department is structured with a central group that manages infrastructure and security, while business units have their own IT staff for application support. This is an example of which IT organizational structure?
Medium140Which type of disaster recovery test involves actually switching over to the alternate site and processing live transactions, but does not require the primary site to be shut down?
Easy141During an audit of patch management, the IS auditor notes that several critical patches have not been applied within the defined SLA. Which of the following is the BEST approach to evaluate the risk acceptance of these unpatched vulnerabilities?
Hard142An organization is implementing a data loss prevention (DLP) solution. Which of the following is the BEST approach to minimize false positives while ensuring sensitive data is protected?
Medium143An IS auditor is reviewing the IT governance of a financial services firm. The auditor discovers that the IT steering committee has approved a major core banking system upgrade, but the project lacks a formal business case and no post-implementation review is planned. Which of the following is the MOST significant risk arising from this situation?
Hard144A business continuity plan (BCP) includes a tabletop exercise once a year. An IS auditor finds that the exercise only involves IT staff. Which of the following is the BEST recommendation?
Medium145An organization is considering whether to build a custom application or purchase a commercial off-the-shelf (COTS) product. Which of the following factors would most strongly support a build decision?
Medium146An IS auditor is reviewing the process for granting access to a critical financial system. The auditor finds that access requests are approved by the system owner but there is no segregation between the request and approval functions for emergency access. Which of the following is the BEST control to mitigate this risk?
Medium147An organization uses shared accounts for system administration. Which of the following is the BEST control to mitigate the risk of non-repudiation?
Medium148Which TWO of the following are indicators that an IS auditor may need to adjust the audit approach during fieldwork? (Select TWO.)
Hard149An IS auditor is performing a compliance audit of a company's data privacy practices. Which type of evidence would be most appropriate to verify that employees have completed mandatory privacy training?
Medium150An organization is evaluating a vendor for a custom application development. The vendor states they are assessed at CMMI Level 2 (Managed). Which of the following best describes the implication of this rating?
Medium151An organization is adopting agile development methodology. Which control is MOST critical to ensure security is integrated?
Hard152A company is developing a custom application. During the requirements phase, the project manager documents that the system must encrypt all sensitive data at rest. Which of the following is the BEST control to ensure this requirement is met throughout the development lifecycle?
Easy153An organization has implemented a security awareness training program. Which of the following metrics would BEST indicate that the program is effective?
Easy154An IS auditor is assessing the risk of fraud in a financial system. Which combination of audit risk components is most directly relevant?
Hard155Which of the following is the BEST control to ensure that system changes are authorized?
Easy156An IS auditor is reviewing the logical access controls for a critical financial application. Which of the following is the MOST important control to ensure that user access rights remain appropriate over time?
Easy157An organization uses a public key infrastructure (PKI) to issue digital certificates. The IS auditor is reviewing the certificate lifecycle management. Which of the following is the GREATEST risk if certificate revocation lists (CRLs) are not updated in a timely manner?
Medium158An IT balanced scorecard for a retail company shows that the percentage of IT projects delivered on time has decreased from 85% to 70%. Which perspective of the balanced scorecard is MOST directly affected?
Medium159An organization is implementing a key management program to protect encryption keys. Which of the following is the MOST important control to ensure the security of cryptographic keys?
Easy160Based on the exhibit, what is the MOST likely security risk?
Medium161An IS auditor is reviewing the logical access controls of a legacy payroll application that authenticates users directly against its own internal user table rather than the corporate directory. Management states that this was a deliberate design choice by the vendor. Which of the following is the MOST significant audit concern with this arrangement?
Medium162An IS auditor is reviewing an organization's IT governance framework and notices that the IT steering committee, chaired by the CIO, approves all IT investments and also monitors their benefits realization. The board has delegated full IT decision-making authority to this committee. The auditor is MOST likely to conclude that:
Medium163During a vendor audit, an IS auditor discovers that a cloud service provider uses subcontractors to manage data storage. The contract does not mention subcontracting. Which THREE risks should the auditor highlight to management?
Hard164An IS auditor is assessing the security of an organization's virtualized environment. The organization uses a type 1 hypervisor and has multiple virtual machines (VMs) running on a single physical host. The auditor is concerned about the risk of VM escape, where an attacker compromises the hypervisor from within a VM. Which of the following controls are MOST effective in mitigating this risk? (Choose two.)
Hard165During an IS audit, the auditor finds that a control deficiency could result in a material misstatement. According to ISACA standards, this should be classified as:
Medium166Scenario: A mid-sized manufacturing company has recently experienced a significant IT outage that halted production for 8 hours. The root cause was a failed firmware update on a core switch that was performed outside the change management process by a senior network engineer who claimed the update was urgent to patch a critical vulnerability. The company has a well-documented change management policy that requires all changes to be reviewed by the change advisory board (CAB) before implementation, except for emergency changes which require post-implementation review within 48 hours. The engineer did not follow the emergency change process; he implemented the update directly. The IT director wants to prevent such incidents in the future. Which of the following is the BEST action?
Hard167You are an IS auditor for a financial institution that processes credit card payments. The organization uses a key management system (KMS) to store encryption keys for point-of-sale (POS) data. The KMS is a hardware security module (HSM) located in a secured data center. The audit reveals that the HSM is administered by two individuals who both have full access to the HSM, including the ability to export keys. The organization has a policy requiring split knowledge and dual control for key management, but in practice, the two administrators often perform key ceremonies alone due to scheduling conflicts. The logs show that one administrator exported a key last month without the other present, and the export was approved via email by the other administrator after the fact. Which of the following is the BEST corrective action?
Medium168During a business impact analysis (BIA), the auditor identifies a critical process with a maximum tolerable downtime (MTD) of 4 hours. The IT department proposes a recovery time objective (RTO) of 2 hours and a recovery point objective (RPO) of 1 hour. Which statement is correct?
Medium169During an audit of a public key infrastructure (PKI), the IS auditor finds that certificate revocation lists (CRLs) are only updated weekly. Which of the following is the MOST significant risk?
Hard170Which TWO of the following are benefits of an iterative SDLC approach compared to waterfall? (Select two.)
Medium171A company is migrating its customer database to a public cloud provider. Which of the following encryption strategies best protects data while minimizing performance impact on queries?
Hard172A multinational corporation has implemented a hot site disaster recovery solution for its critical financial applications. Which of the following is the MOST important consideration to ensure the effectiveness of the hot site?
Hard173Which of the following is the PRIMARY objective of a post-implementation review of an information system?
Easy174An IS auditor is reviewing a project that is developing a new customer relationship management (CRM) system using the Agile Scrum framework. The project team has completed several sprints, and the product owner has accepted the increments. The auditor wants to ensure that the system will meet the organization's security requirements before go-live. Which of the following is the MOST effective way for the auditor to achieve this?
Medium175Which of the following is the PRIMARY reason for an external IS audit to be more independent than an internal audit?
Easy176An IS auditor is assessing the data inventory of a financial institution to ensure compliance with privacy regulations. Which TWO of the following are essential elements that should be included in the data inventory?
Medium177Arrange the steps to set up a virtual private network (VPN) for remote access in the correct order.
Medium178According to ISACA IT Audit Standards, which of the following is a key requirement for audit documentation?
Easy179During a business impact analysis (BIA), which of the following is the MOST important metric to identify for each critical business process?
Medium180An IS auditor is evaluating the vendor selection process for a new system. Which of the following is the most important factor to include in the contract?
Medium181An IS auditor is reviewing the requirements definition phase of a new system development project. The business analyst has documented functional requirements but has not yet defined non-functional requirements. Which of the following is the MOST significant risk of proceeding to the design phase without non-functional requirements?
Hard182An organization is implementing a data loss prevention (DLP) solution. Which of the following is the MOST important step to ensure the DLP rules are effective?
Easy183According to ISACA IT Audit Standards, which of the following is the MOST important consideration when determining the scope of an IS audit?
Medium184An IS auditor is evaluating the effectiveness of controls over a critical financial application. Which TWO of the following are appropriate audit procedures to test the design and implementation of controls? (Select TWO.)
Medium185An IT governance framework has been implemented, but the board is not receiving regular reports on IT performance. Which of the following is the BEST course of action?
Medium186An organization uses a third-party vendor for application support. The vendor has subcontracted some support activities to another firm (fourth party). The contract with the vendor requires the vendor to ensure fourth-party compliance, but there is no direct oversight. What is the IS auditor's primary recommendation?
Hard187An IT steering committee is reviewing a proposed project to implement a new customer relationship management (CRM) system. The project has strong support from the sales department but is opposed by the finance department due to cost concerns. What is the primary role of the IT steering committee in this situation?
Medium188A hospital's IT department has implemented a new electronic health record (EHR) system. The IS auditor is reviewing the IT governance over the project and finds that the project sponsor is the CIO, who also chairs the IT steering committee that approved the project. Which of the following is the MOST significant governance risk?
Easy189A company is developing a new financial application. Which THREE of the following are valid reasons to involve internal audit during the development phase?
Hard190During the system development life cycle (SDLC), which THREE of the following are recognized benefits of involving internal audit early in the process?
Easy191A company is designing its backup strategy for a critical database that must be available 24/7. The database experiences high transaction volumes. Which backup method minimizes data loss while allowing continuous operations?
Easy192An IS auditor is planning an audit of a cloud service provider's controls over data backup and recovery. The auditor needs to obtain evidence about the provider's backup procedures and restoration testing. Which of the following is the MOST appropriate source of evidence?
Medium193During a post-implementation review of a new payroll system, the IS auditor identifies several outstanding issues. Which TWO issues should be considered most critical to address immediately? (Select TWO)
Medium194During an incident, the IT team identifies that a critical patch was not applied due to an expired software maintenance contract. Which of the following is the BEST long-term remediation?
Hard195Which TWO of the following are effective controls to prevent fraud in IT? (Select TWO)
Medium196An IS auditor is preparing the audit report after completing fieldwork on an organization's backup and restoration process. Management disagrees with one of the findings and has provided additional evidence. Which of the following is the auditor's MOST appropriate course of action?
Medium197An organization has implemented a balanced scorecard (BSC) for IT performance measurement. Which of the following is the PRIMARY benefit of using a BSC?
Easy198Which TWO of the following are key activities in the system design phase of the SDLC?
Medium199An IS auditor is reviewing a post-implementation review report for a new ERP system. Which of the following findings would be of greatest concern to the auditor?
Hard200An IS auditor is reviewing the problem management process. The auditor finds that problem tickets are often closed without identifying the root cause, and incidents continue to recur. Which of the following is the MOST likely consequence of this practice?
Easy201Which TWO of the following are key controls for ensuring data privacy during system development?
Medium202An organization has implemented a key management program. Which of the following is the MOST critical control for ensuring the security of cryptographic keys?
Medium203An organization is implementing a data retention policy for personally identifiable information (PII) to comply with GDPR. Which of the following is the MOST appropriate approach?
Hard204An IS auditor is reviewing the process for granting access to a sensitive financial application. Which TWO of the following are the MOST important controls to ensure appropriate access?
Easy205An IS auditor is reviewing a batch job scheduling environment. A critical nightly job that feeds the general ledger depends on a file transfer from a subsidiary. The scheduler is configured so that if the transfer does not complete by 02:00, the job is cancelled and the ledger is not updated. Operations staff report that they manually rerun the job each morning when this occurs. Which of the following is the MOST important issue for the auditor to raise?
Hard206Which of the following is the PRIMARY purpose of audit working papers?
Medium207An IS auditor identifies a control deficiency that could result in a material misstatement in the financial statements. According to audit reporting standards, this should be classified as:
Hard208Which of the following is the best example of audit evidence obtained through re-performance?
Medium209An IS auditor is reviewing an organization's logical access control processes. Which of the following is the primary purpose of conducting regular user access recertifications?
Easy210An IS auditor is reviewing a third-party service provider's controls. Which of the following is the MOST important clause to include in the contract to ensure the auditor can assess the provider's controls?
Medium211A company is implementing IT governance based on COBIT 2019. Which of the following design factors would have the GREATEST impact on the governance system design?
Hard212An organization is developing a critical application using an agile methodology. The project sponsor demands frequent deliveries but the development team is concerned about insufficient testing. Which of the following BEST mitigates this risk?
Hard213An IT auditor is evaluating the change management process for a financial trading system. Which of the following is the BEST indicator of a mature change management process?
Medium214An IS auditor is assessing the IT governance framework of a retail company. The auditor finds that the company has a formal IT strategy, an IT steering committee, and a defined IT organizational structure. However, the auditor notes that there is no process to ensure that IT investments are justified and prioritized. Which of the following are the MOST appropriate recommendations to address this deficiency? (Choose two.)
Hard215During an IT audit, the auditor observes that mandatory vacation policies are not enforced for IT staff with access to financial systems. What is the PRIMARY risk associated with this finding?
Hard216An organization is implementing a large ERP system. The project team plans to migrate legacy data to the new system. Which of the following is the MOST significant risk associated with data migration?
Hard217An IS auditor is reviewing physical access controls at a data center. Which of the following controls is MOST effective for preventing tailgating?
Easy218Which TWO are primary objectives of an identity and access management (IAM) program? (Select exactly 2.)
Hard219An IS auditor is reviewing the change management process for a critical financial application. Which of the following is the most important element to verify in an emergency change request?
Medium220An IS auditor is evaluating a wireless network deployed in a corporate headquarters. The auditor discovers that the network uses WPA2-Enterprise with 802.1X authentication, but the RADIUS server accepts any client presenting a valid domain user account, including accounts belonging to recently terminated employees that have not yet been disabled. Which of the following is the GREATEST risk arising from this configuration?
Hard221Which THREE of the following are phases of the audit process as defined by ISACA? (Select THREE.)
Hard222A company is implementing a cloud-based identity and access management (IAM) system. Which of the following best describes the principle of least privilege in this context?
Medium223A large enterprise is assessing its IT governance maturity. Which THREE of the following are indicators of a mature governance process? (Select exactly three.)
Hard224An organization is transitioning from a waterfall to an agile development methodology. Which of the following is a key risk that the IS auditor should highlight?
Medium225An IS auditor is reviewing a penetration test report that shows a critical vulnerability in a web application. The IT manager states that the vulnerability will not be fixed because it requires significant code changes and the application is being decommissioned in six months. What should the auditor do?
Hard226An IS auditor is evaluating the backup strategy for a system with a recovery point objective (RPO) of 15 minutes and a recovery time objective (RTO) of 2 hours. The current strategy is a full backup nightly to tape with tapes transported offsite weekly. Which finding is MOST significant?
Medium227Which of the following is the PRIMARY purpose of a service desk?
Easy228An IS auditor is reviewing an organization's IT service continuity plan (ITSCP) that supports its business continuity plan (BCP). The auditor finds that the ITSCP includes recovery strategies for critical systems but lacks details on roles and responsibilities during a disaster. Which TWO of the following should the auditor recommend to address this gap? (Choose two.)
Hard229An IS auditor is evaluating the reliability of audit evidence obtained from an IT system. Which TWO of the following factors most directly affect the reliability of the evidence? (Choose two.)
Hard230Which of the following is a permanent file item in an IS audit working paper?
Medium231An IS auditor is reviewing the network segmentation of a retail company's cardholder data environment (CDE). The auditor finds that the CDE and the corporate user VLAN are separated by a firewall, but the same flat Layer 2 domain spans both segments, and no internal segmentation firewall exists between the CDE web tier and the CDE database tier. Which of the following findings should the auditor report as the GREATEST risk?
Medium232Which of the following is the BEST indicator that an organization's incident management process is effective?
Easy233A company is outsourcing software development. What is the IS auditor's PRIMARY concern?
Medium234Which THREE are core components of a comprehensive identity and access management (IAM) system? (Choose three.)
Hard235An organization is considering outsourcing its IT infrastructure management. Which of the following is the MOST important factor to include in the service level agreement (SLA)?
Medium236An organization's mobile device management (MDM) policy requires that all corporate data on employee-owned smartphones be protected. Which control best ensures that corporate data can be remotely wiped without affecting personal data?
Easy237An IS auditor is reviewing the physical security controls for a data center. The auditor observes that the data center has a raised floor, a fire suppression system, and biometric access controls. The auditor also notes that the data center is located in a region prone to flooding. Which of the following controls is MOST important to mitigate the risk of flooding?
Medium238An IT governance framework should include which TWO key components? (Select exactly two.)
Easy239An IS auditor is leading an audit engagement and discovers that a key member of the audit team lacks the technical expertise to evaluate a newly implemented cloud encryption control. The audit manager insists the team member proceed anyway to save time. According to ISACA IT Audit Standards, what is the MOST appropriate action for the IS auditor to take?
Medium240An organization experiences a ransomware attack that encrypts critical files. Which of the following is the BEST recovery strategy to minimize data loss?
Medium241Which of the following evidence types involves the auditor independently performing a control procedure to verify its effectiveness?
Easy242An organization wants to ensure that data is not retained longer than necessary. Which of the following is the BEST control to implement?
Easy243An IS auditor is planning an audit of a cloud-hosted application and needs to determine whether the cloud provider's controls are adequate. The provider offers a SOC 2 Type II report. Which of the following should the auditor do FIRST?
Medium244An organization has a policy requiring all employees to complete annual information security awareness training. Which of the following is the BEST way to verify compliance with this policy?
Easy245An auditor is reviewing IT asset management processes. The auditor finds that several servers running an older operating system are still in production, even though the vendor has ended support. What is the primary risk associated with this finding?
Medium246An organization has implemented a clean desk policy. Which of the following is the BEST audit procedure to verify compliance?
Medium247During a review of firewall rule sets, an IS auditor identifies a rule that allows 'any-any' traffic from an internal subnet to the DMZ. The rule was implemented six months ago based on a business request that has since been completed. The firewall administrator explains that the rule was kept for convenience. Which of the following is the BEST audit recommendation?
Hard248A large financial institution is implementing a new core banking system to replace a legacy system. The project has been underway for 18 months and is behind schedule. User acceptance testing (UAT) has revealed significant data integrity issues, including missing customer records and incorrect interest calculations. The project manager, under pressure from senior management to meet a regulatory deadline, proposes going live with a promise to fix the issues in a post-implementation phase. The development team has been making ad hoc code changes directly in the test environment without version control or proper testing. Additionally, the IS auditor discovers that the business requirements were never formally signed off by the user community; only verbal approvals were obtained. The project has consumed 90% of the budget but only 60% of the functionality is tested. Which of the following is the BEST course of action for the IS auditor to recommend?
Hard249Which of the following is the BEST indicator of the effectiveness of a security awareness program?
Easy250Which TWO of the following are indicators of poor project governance that an IS auditor should identify?
Hard251Which TWO of the following are benefits of implementing an IT governance framework?
Easy252An IS auditor is reviewing the firewall rule base. Which of the following findings would be of MOST concern?
Medium253A company's endpoint protection solution alerts on a file that is digitally signed by a trusted software vendor but exhibits malicious behavior on execution. What type of threat does this scenario most likely depict?
Hard254Refer to the exhibit. An application log shows an error. What is the MOST likely cause of this error?
Medium255An IS auditor is assessing an ERP implementation. Which of the following control concerns is MOST likely to arise from segregation of duties conflicts?
Medium256An organization uses role-based access control (RBAC). An employee is transferred to a new department. According to best practices, what should be done regarding the employee's access rights?
Medium257A company is developing a mobile application that processes credit card payments. During the testing phase, which of the following types of testing is MOST critical to ensure security?
Medium258Which THREE of the following are key components of an effective information security awareness program? (Choose three.)
Hard259An IS auditor is reviewing the audit committee's oversight of the IT audit function. The auditor notes that the audit committee approves the annual IT audit plan but does not receive regular updates on the status of management's remediation of audit findings. Which of the following is the MOST significant risk arising from this situation?
Easy260A company is implementing a new IT governance framework. Which of the following is the PRIMARY benefit of aligning IT strategy with business strategy?
Easy261During a post-implementation review, an IS auditor identifies that the system's actual transaction processing time is significantly higher than the benchmark specified in the service level agreement (SLA). The vendor claims it is due to inadequate network bandwidth provided by the client. What should the auditor do first?
Hard262An IS auditor is assessing the security of an organization's virtualization environment. The auditor finds that the hypervisor management interface is accessible from the general corporate network and uses default credentials. Which of the following is the MOST critical risk associated with this finding?
Hard263Which TWO of the following are recommended practices for aligning IT strategy with business goals, according to COBIT 2019?
Medium264A multinational corporation is implementing a new enterprise resource planning (ERP) system across multiple regions. The project uses a phased roll-out. After the first phase in Asia, the system experiences intermittent synchronization errors between the central database and regional servers. The IT team suspects network latency but cannot reproduce the issue consistently. The project sponsor wants to proceed with the next phase in Europe to avoid further delays. The IS auditor is performing a post-implementation review. What is the MOST appropriate recommendation?
Hard265Midway through a multi-year ERP implementation, the CIO asks the IS auditor to review how the organization is realizing the intended business benefits. The project is on schedule and within budget, but business unit managers report that key process changes have not been adopted. Which of the following is the MOST appropriate action for the IS auditor to recommend?
Medium266A small business wants to protect customer data collected through its e-commerce website. Which control is most appropriate for protecting the data at rest and in transit?
Easy267During an audit of physical security, the IS auditor observes that employees frequently leave confidential documents on their desks overnight. Which TWO controls should the auditor recommend?
Easy268During the user acceptance testing (UAT) phase of a new financial application, the business users report that the system calculates interest incorrectly for certain loan types. The project manager wants to fix this quickly. Which of the following is the BEST course of action?
Hard269Which of the following is the PRIMARY purpose of a change advisory board (CAB) in the change management process?
Medium270An IS auditor is planning an audit of a decentralized organization with multiple business units. The auditor wants to use a risk-based approach. Which of the following is the MOST appropriate factor to prioritize audit coverage?
Hard271Which TWO of the following are key considerations when managing software licenses in an organization? (Select TWO).
Medium272Which TWO of the following are the MOST effective controls to prevent unauthorized changes to production data?
Medium273During which phase of the SDLC should security requirements be formally documented and approved?
Easy274Which THREE of the following are typical controls in the design phase of the SDLC?
Medium275An organization is implementing a new IT governance framework. Which of the following is the PRIMARY benefit of aligning IT strategy with business strategy?
Easy276An organization processes personal data of EU residents and has implemented pseudonymisation as a privacy control. The IS auditor is reviewing the effectiveness of this control in meeting GDPR requirements. Which of the following is the MOST important limitation of pseudonymisation?
Hard277An IS auditor is performing a risk assessment for an audit of a cloud service provider. Which THREE factors should be considered when assessing inherent risk? (Select THREE.)
Hard278An IS auditor is assessing the capacity management process for a virtualized data center. The auditor finds that CPU and memory utilization on a cluster of hosts regularly exceeds 85 percent during month-end processing, causing performance degradation. Management states that they monitor utilization but have no formal forecasting or trend analysis. Which of the following is the MOST significant risk arising from this situation?
Hard279An organization is implementing a new ERP system and is concerned about segregation of duties (SoD) conflicts. What is the BEST approach to address this during the implementation?
Medium280A multinational corporation is implementing a bring your own device (BYOD) policy. Which of the following is the most important security control to ensure corporate data is protected on employee devices?
Hard281A financial services organization recently experienced a data breach where customer financial records were exfiltrated. The investigation reveals that an attacker gained access through a compromised privileged account belonging to a database administrator. The attacker used valid credentials to log into the database server and then exported a large volume of data using native database tools. The security team notes that the organization has multi-factor authentication (MFA) enabled for all remote access, but the database server was accessed from an internal IP address. The organization also has a data loss prevention (DLP) system, but it did not alert on the export because the traffic was encrypted. The database activity monitoring (DAM) system did log the export, but alerts were not reviewed due to high volume and many false positives. Which of the following would have been most effective in preventing this breach?
Hard282What is the PRIMARY purpose of a post-implementation review?
Easy283An organization is implementing a privileged access management (PAM) solution. Which of the following is the PRIMARY benefit of using a PAM tool?
Medium284An organization is implementing a new IT policy. What is the MOST important step to ensure compliance?
Medium285An IS auditor is reviewing an organization's endpoint protection controls after several employees reported slow performance on their laptops. The auditor observes that the anti-malware solution performs a full disk scan every night, and the audit log shows that the last successful signature update was 47 days ago. Which of the following is the MOST significant concern the auditor should report?
Medium286An IS auditor is planning an engagement and needs to obtain an understanding of the organization's IT environment to develop the audit programme. Which of the following techniques is MOST appropriate for this purpose?
Medium287Which testing phase is MOST effective for validating that the system meets business needs?
Easy288A company plans to outsource its data center operations to a cloud service provider. What is the MOST important governance consideration for the board before finalizing the contract?
Medium289An IS auditor is planning a risk-based audit of a financial system. Which TWO of the following factors should the auditor consider when assessing inherent risk? (Select two.)
Medium290An organization is implementing a new financial system. Which of the following is the MOST important control to ensure data integrity during the data migration phase?
Easy291Refer to the exhibit. An auditor finds that users are able to reuse previous passwords easily. Which setting should be modified to address this weakness?
Medium292A company uses a RAID 5 array for its file server. One disk fails, and the system continues to operate. However, during the rebuild process, a second disk fails. What is the likely consequence?
Hard293Which THREE of the following are characteristics of a SMART recommendation? (Select three.)
Hard294An organization's IT department has a policy that all new hires must sign an acceptable use policy (AUP) before gaining access to systems. During an audit, the IS auditor finds that several contractors were granted access without signing the AUP. Which of the following is the auditor's BEST recommendation?
Easy295An IS auditor is reviewing the physical access controls at a data center. Which of the following is the MOST effective control to prevent tailgating?
Easy296An IS auditor is reviewing the ITIL incident management process. Which THREE are the correct priority levels and their typical definitions?
Easy297An IS auditor is reviewing capacity management practices. Which TWO indicators suggest that proactive capacity management is being performed effectively?
Medium298An IS auditor is performing a compliance audit of a data privacy regulation. Which of the following is the PRIMARY source of audit criteria?
Medium299An IS auditor is reviewing the incident response (IR) process. Which of the following is the BEST way to test the effectiveness of the IR plan?
Easy300An IS auditor is reviewing how a data center protects its backup tapes while they are in transit to an offsite storage facility. Management states that tapes are encrypted before shipment and that a courier transports them in sealed containers. Which of the following is the MOST appropriate evidence to confirm that the tapes are protected in transit?
Easy301A multinational corporation is implementing a global IT governance framework. Which of the following challenges is MOST likely to arise?
Hard302During a software asset management (SAM) audit, it is discovered that the organization is using software that has reached end-of-life. Which of the following is the MOST significant risk associated with this situation?
Hard303An IS auditor finds that a project failed to meet its objectives because key stakeholders were not involved in the requirements definition phase. Which phase of the SDLC was most neglected?
Medium304Which of the following is the PRIMARY reason for implementing network segmentation?
Easy305An organization is designing an IT balanced scorecard to align IT performance with business goals. Which perspective would include metrics related to IT employee skills and training?
Hard306An IS auditor is evaluating an organization's capacity management process for a critical database server. The auditor observes that CPU utilization averages 85% during peak hours, memory utilization is at 90%, and disk I/O wait times are consistently high. The organization has no formal capacity plan. Which of the following is the MOST significant risk the auditor should report?
Hard307An organization uses a cloud-based ERP system to manage financial transactions. The system is accessed by employees in finance, procurement, and sales departments. The IS auditor is reviewing the user access review process. The access review is performed quarterly by the IT manager using a report generated by the ERP system. The report lists all users and their roles. The IT manager manually checks off users who are still employed and approves the report. The auditor notes that the IT manager does not have detailed knowledge of job functions in each department. Additionally, the ERP system allows role combinations that may create segregation of duties conflicts, such as a user having both 'create purchase order' and 'approve purchase order' roles. The company's policy requires segregation of duties reviews to be performed by business process owners. Which of the following is the BEST recommendation?
Medium308An organization has defined an SLA that requires critical incidents to be resolved within 4 hours. A P1 incident is reported at 10:00 AM. At what time must the incident be resolved to meet the SLA?
Easy309Which TWO of the following are typically included in the fieldwork phase of an IS audit? (Select two.)
Medium310An IS auditor is evaluating the encryption strategy for a healthcare organization subject to HIPAA. Which of the following is the MOST significant risk if the organization relies solely on encryption as a safe harbor?
Hard311An IS auditor is reviewing the backup process for a critical database. Which TWO of the following are essential controls to ensure data recoverability?
Easy312In a waterfall SDLC, which phase requires formal sign-off from the business owner before proceeding to the next phase?
Easy313An IS auditor is reviewing the design phase of a new procurement system. Which TWO of the following controls are MOST critical to include in the system design to prevent unauthorized purchases?
Medium314An IS auditor is reviewing an organization's data classification policy. Which of the following findings is MOST critical?
Medium315An IS auditor is reviewing an organization's incident management process after a ransomware attack encrypted several file servers. Which TWO of the following should the auditor verify as part of assessing the effectiveness of the incident response? (Choose two.)
Hard316Order the steps for conducting an audit engagement from start to finish.
Medium317An IS auditor is reviewing the physical access controls at a data center. Which TWO of the following are the MOST effective controls to prevent unauthorized tailgating?
Medium318An IS auditor is reviewing the incident management process. Incidents are categorized as P1 (critical) through P4 (low). The SLA for P1 incidents requires initial response within 15 minutes and resolution within 4 hours. The auditor notes that the average time to respond to P1 incidents is 12 minutes, but the average resolution time is 6 hours. The root cause analysis shows that many P1 incidents are due to known errors documented in the known error database (KEDB). What is the most significant finding?
Hard319During an agile software development project, a sprint review meeting is conducted. What is the PRIMARY purpose of this meeting from an IS audit perspective?
Medium320During a post-implementation review of a financial system, an IS auditor finds that several critical reports are not being generated correctly. Which of the following should the auditor recommend FIRST?
Easy321An organization is implementing a data loss prevention (DLP) solution. Which TWO of the following are key considerations for effective DLP deployment?
Easy322An organization's security team proposes deploying a network-based intrusion prevention system (IPS) inline at the internet perimeter. Management asks the IS auditor to comment on the operational implications before approving the purchase. Which of the following should the auditor identify as the MOST significant operational risk of the inline placement?
Medium323An IS auditor is evaluating the effectiveness of an organization's change management process. Which of the following is the most important control to verify during the audit?
Easy324During an audit, the IS auditor discovers that the audit log for a critical server is overwritten every 24 hours. The auditor wants to ensure logs are preserved for a longer period. Which of the following recommendations is most appropriate?
Medium325Which testing type is performed by end-users to verify that the system meets their needs?
Easy326Which of the following is the BEST control to ensure that user acceptance testing (UAT) is effective?
Medium327An IS auditor is reviewing a change management process. Which TWO elements should be documented in a normal change request to ensure adequate governance? (Select TWO)
Medium328An IS auditor is reviewing an organization's IT governance framework and notes that the board of directors has established an IT strategy committee. Which TWO of the following are the MOST appropriate responsibilities for this committee? (Choose two.)
Medium329An IS auditor is reviewing an organization's IT governance structure. The board of directors has delegated all IT oversight to the CIO, who reports to the CFO. The auditor finds that the board receives only annual summaries of IT performance and never reviews IT risks. Which of the following is the MOST significant governance concern?
Medium330An IS auditor uses statistical sampling to test a population of 10,000 transactions. The auditor discovers 5 errors in the sample of 200. Which of the following conclusions is most appropriate?
Hard331An IS auditor is evaluating the change management process. Which of the following is the BEST indicator that emergency changes are being properly controlled?
Medium332An IS auditor is reviewing an organization's security monitoring architecture. The organization uses a SIEM to collect logs from servers, firewalls, and applications. Management reports that the SIEM is functioning as designed and alerts are generated. Which of the following findings would be of MOST concern to the auditor?
Hard333An IS auditor is assessing the effectiveness of access controls. Which TWO procedures provide the strongest evidence? (Select two.)
Medium334Which THREE of the following are essential components of a data classification program?
Hard335A medium-sized e-commerce company recently suffered a ransomware attack that encrypted critical databases. The IT team restored systems from backups, but the incident exposed a lack of clear roles and responsibilities for incident response. The board has asked the IT governance committee to review and improve the incident response governance. The committee notes that while there is an incident response policy, it is not regularly tested, and staff are unsure of their roles. The company also lacks a formal communication protocol for notifying stakeholders. What should the committee prioritize to strengthen governance over incident response?
Easy336An IS auditor is reviewing the IT organizational structure of a mid-sized manufacturing company. The auditor finds that the IT department reports to the CFO, and there is no separate IT strategy committee. The CEO believes that IT is a support function and does not need board-level representation. Which of the following is the MOST appropriate recommendation for the auditor?
Easy337A small business wants to protect customer data stored on a local file server. Which of the following is the MOST cost-effective control to prevent unauthorized access?
Easy338An organization is implementing a data loss prevention (DLP) solution. Which of the following is the BEST approach to reduce false positives during initial deployment?
Medium339An IS auditor is reviewing a system development project that uses a commercial software package customized with vendor-supplied extension points. The project team has documented customizations in a separate repository but has not maintained a traceability matrix linking business requirements to configuration items. Which of the following is the GREATEST risk arising from this situation?
Hard340An IS auditor is reviewing the user access recertification process. Which of the following findings would MOST concern the auditor regarding the effectiveness of access reviews?
Medium341An organization's backup strategy includes full backups every Sunday and incremental backups on other days. On Wednesday, a failure occurs. Which backups are needed to restore the data?
Medium342A multinational corporation is evaluating its IT governance structure. The board wants to ensure that IT investments are prioritized based on risk and value. Which framework component is MOST critical?
Hard343A mid-sized company is implementing a new IT service management (ITSM) tool to improve incident management. The IT manager wants to ensure that the tool aligns with ITIL best practices. The company has a dedicated service desk team that handles about 200 incidents per week. The IT manager is considering whether to implement a self-service portal for users to submit incidents and check status, or to continue using email-based incident reporting. The service desk team is concerned that a self-service portal might reduce their direct interaction with users and potentially lead to less personalized support. However, the IT manager believes that a portal could improve efficiency and tracking. The company's IT governance framework requires that any major IT investment be approved by the steering committee and that there be a clear business case. The IT manager has prepared a business case but the steering committee wants to ensure that the solution is aligned with ITIL and that it addresses key incident management processes. Which of the following is the most appropriate next step for the IT manager?
Easy344During an operational audit of an IT department, the auditor finds that system uptime is 99.9% but the department missed two critical project deadlines. Which conclusion is most appropriate?
Medium345An IS auditor is reviewing a waterfall SDLC project that has completed the requirements phase. Which of the following is the greatest risk to the project?
Medium346An IS auditor is reviewing the change management process for a critical financial application. Which of the following findings would be of GREATEST concern?
Hard347An IS auditor is reviewing the logical access controls for a cloud-based HR system. The system contains sensitive employee data. The auditor notes that user provisioning is performed by the HR department without IT involvement, and there is no formal access request or approval process. Which THREE of the following are the MOST significant risks?
Easy348Which TWO of the following are key elements of a change request document?
Medium349Which TWO of the following are key controls that an IS auditor should expect to find in a well-managed system development life cycle (SDLC)?
Medium350An organization is developing a policy on acceptable use of company IT resources. Which of the following should be included to support effective governance?
Medium351An IS auditor is assessing the capacity management process for a cloud-based enterprise resource planning (ERP) system. The organization has experienced performance degradation during peak periods, and the cloud provider's auto-scaling features are not fully utilized. Which of the following should the auditor recommend FIRST?
Medium352A multinational corporation is implementing a global HR system. The project team decides to use a pilot implementation in one region before rolling out to others. What is the PRIMARY risk if the pilot region is not representative of the entire organization?
Hard353During a post-implementation review of a new financial system, the IS auditor finds that user acceptance testing (UAT) was completed with only 60% of test cases passed. Which of the following is the MOST significant risk?
Medium354An IS auditor is reviewing the access control list (ACL) on a router that connects the corporate network to the internet. The auditor notices that the ACL permits inbound traffic on port 3389 (RDP) from any source IP address to a specific internal server. Which of the following is the MOST appropriate recommendation?
Easy355Which of the following is the PRIMARY purpose of a data classification scheme?
Easy356A system has a Mean Time Between Failures (MTBF) of 200 hours and a Mean Time To Repair (MTTR) of 20 hours. What is the availability of the system?
Medium357During which phase of the SDLC should security requirements be formally documented and approved by the business owner?
Easy358A multinational corporation has defined its risk appetite as 'moderate' for IT investments. The IT steering committee is evaluating a new project with potential high returns but also significant cybersecurity risks. The project's risk profile is assessed as 'high' by the risk management team. What should the committee do FIRST?
Hard359A global retail company is implementing an IT governance framework. The board of directors has asked the IS auditor to identify the KEY components that should be included in the framework to ensure effective governance. Which TWO of the following are essential components of an IT governance framework? (Choose two.)
Hard360An IS auditor is reviewing the backup strategy for a financial institution's core transaction processing system. The system processes high volumes of transactions continuously and requires a recovery point objective (RPO) of 5 minutes. The current strategy includes nightly full backups and hourly incremental backups. Which of the following should the auditor recommend as the MOST appropriate improvement?
Medium361An organization wants to ensure that its backup tapes are protected from unauthorized access. Which of the following is the MOST effective control?
Easy362An organization has implemented a business continuity plan (BCP) and disaster recovery plan (DRP). During a recent full interruption test, the IT team discovered that the recovery time objective (RTO) for a critical application was not met. What is the MOST likely reason for this failure?
Medium363An IS auditor is reviewing the access recertification process for a financial application. The process requires users' managers to confirm access rights quarterly. Which of the following findings should MOST concern the auditor?
Medium364According to ISO/IEC 38500, which principle requires that IT investments are made for valid business reasons and with clear business outcomes?
Easy365An organization is acquiring a new financial system. The contract includes a clause that allows the organization to audit the vendor's controls. Which type of report would most efficiently provide assurance over the vendor's internal controls?
Medium366An IS auditor is reviewing the IT operations of a small company. The auditor finds that scheduled batch jobs are monitored manually by an operator who checks job logs each morning. Which of the following is the MOST significant risk associated with this practice?
Easy367An IS auditor is reviewing the job scheduling environment for an organization's overnight batch processing on a mainframe. The auditor finds that operators have the authority to modify job control statements, restart failed jobs, and manually release jobs held for review, all using the same production operator ID. Which finding should the auditor report as the GREATEST concern?
Medium368A university is implementing a new student information system. The project team uses an iterative development approach. During user acceptance testing, students report that the online course registration portal crashes when more than 100 users register simultaneously. The development team identifies a database connection pooling issue and estimates a fix will take three weeks. The project deadline is in two weeks. The project manager suggests deploying the system as is and fixing the issue after go-live, as the crash is rare. The IS auditor is consulted. What should the auditor recommend?
Medium369A security auditor discovers that a server has been compromised due to an unpatched vulnerability. Which of the following would have most effectively prevented this incident?
Medium370During an audit of the incident response process, the IS auditor finds that the organization relies on shared accounts for system administration. Which TWO of the following are the MOST significant risks associated with shared accounts?
Medium371An organization is conducting a Business Impact Analysis (BIA). Which of the following metrics defines the maximum acceptable outage time for a critical business process?
Medium372Which of the following is the PRIMARY benefit of using a hardware security module (HSM) for key management?
Easy373An IS auditor is reviewing the endpoint security controls of a hospital that permits clinicians to use personal laptops and tablets to access the electronic health record (EHR) system. The auditor finds that the organization issued written acceptable-use agreements, but devices are not inspected, and no enrollment process exists. Which of the following is the MOST significant risk arising from this situation?
Medium374An IS auditor is reviewing a systems acquisition project that involves purchasing an ERP system. Which of the following is the MOST significant risk related to data migration during implementation?
Medium375Order the steps for performing a data backup in the correct sequence.
Medium376Which of the following are key considerations when implementing a data classification policy? (Choose THREE.)
Medium377An IS auditor is assessing the risk of material misstatement in a highly automated transaction processing environment. The auditor notes that the system automatically calculates interest and posts it to customer accounts. Which of the following audit approaches would BEST address the risk of incorrect interest calculations?
Hard378In a spiral model SDLC, risk analysis is performed at the beginning of each iteration. What is the PRIMARY benefit of this approach?
Hard379An IS auditor is reviewing the IT governance framework of a small organization. The auditor finds that the IT manager reports directly to the CFO, and there is no separate IT steering committee. Which of the following is the MOST appropriate conclusion?
Easy380During the planning phase of an IS audit, the auditor identifies that the organization has recently implemented a new ERP system. Which of the following actions should the auditor prioritize?
Medium381Which TWO of the following are key objectives of a post-implementation review of a new system?
Medium382An IS auditor is planning an audit of a data center and must decide whether to test controls or rely on the work of the organization's internal audit function. Which of the following is the MOST important activity before the auditor can rely on that work?
Easy383An IS auditor is evaluating how an organization disposes of decommissioned hard drives that previously stored customer financial records. Management states that drives are physically destroyed by a third-party vendor, but no certificates of destruction are retained and the vendor's personnel perform the destruction at the organization's loading dock without supervision. Which of the following is the MOST important control weakness?
Hard384Scenario: A healthcare organization is implementing a new electronic health records (EHR) system. The project has been delayed due to scope creep and resource constraints. The project sponsor is pressuring the project manager to accelerate the timeline by skipping user acceptance testing (UAT) and going live immediately. The organization has a governance policy that requires all IT projects to complete UAT before deployment. The project manager is concerned about quality and patient safety. Which of the following is the BEST course of action?
Medium385An IT department uses a balanced scorecard (BSC) to measure performance. The financial perspective shows that IT costs are within budget, but customer satisfaction scores are declining. The learning and growth perspective indicates low employee engagement. Which action should the IT governance committee prioritize?
Hard386An IT auditor is reviewing the organization's policy hierarchy. Which of the following correctly represents the typical order from highest to lowest level?
Hard387An IS auditor is assessing the security controls in a newly developed mobile banking application. The development team used the OWASP Mobile Application Security Verification Standard (MASVS) as a guide. Which of the following would be the MOST effective evidence that the application meets the standard's requirements for secure data storage?
Hard388An IS auditor is reviewing the business impact analysis (BIA) for a financial services company. Which THREE metrics are typically defined in a BIA?
Medium389An organization's IT strategy is developed by the IT department without input from business stakeholders. Which of the following is the MOST significant risk?
Hard390An organization is implementing a software asset management (SAM) program. Which of the following is the PRIMARY benefit of SAM?
Medium391An IS auditor is evaluating the incident response (IR) plan. Which of the following is the BEST indicator that the plan is effective?
Medium392A medium-sized manufacturing company has a decentralized IT structure where each business unit manages its own IT budget and projects. The CEO is concerned that IT investments are not aligned with corporate strategy and that there is duplication of effort. The IT department lacks a formal project portfolio management process. The company has experienced several project failures due to poor prioritization. The CEO has asked the newly hired IT auditor to recommend an initial step to improve IT governance. The auditor should recommend:
Easy393A company is migrating from a legacy system to a cloud-based ERP. Which of the following is the MOST important control to ensure data integrity during data conversion?
Easy394In an Agile software development project, who is primarily responsible for prioritizing the product backlog?
Easy395An IS auditor is reviewing an organization's IT operations incident management process. The auditor finds that incidents are categorized and prioritized, but there is no formal escalation procedure. Which TWO of the following are the MOST significant risks of not having an escalation procedure? (Choose two.)
Medium396An IS auditor is reviewing the privileged access management (PAM) process. Which TWO of the following are the MOST effective controls to prevent misuse of privileged accounts?
Medium397Which of the following is the BEST indicator of IT performance from the customer perspective in an IT balanced scorecard?
Easy398During an audit, the IS auditor finds that the business continuity plan (BCP) was last updated two years ago and does not include new cloud-based applications. The organization has not conducted a BCP test in 18 months. What should the auditor recommend FIRST?
Hard399An organization has implemented a new IT service management (ITSM) tool. The IT manager wants to measure the effectiveness of incident management. Which metric is MOST appropriate?
Hard400An organization is adopting ITIL 4 for service management. Which guiding principle emphasizes starting from existing processes rather than building from scratch?
Medium401A financial services firm has a mature IT governance framework. The IS auditor is reviewing the IT governance structure and notices that the IT steering committee meets quarterly and focuses primarily on project approvals. Which of the following is the MOST significant concern regarding this committee's effectiveness?
Medium402An IS auditor is reviewing the backup and restoration controls for a hospital's electronic health record (EHR) system, which runs on a relational database with a recovery point objective (RPO) of 15 minutes. The database administrator performs a full backup every Sunday at 01:00, differential backups nightly at 01:00, and transaction log backups every 15 minutes. During testing, the auditor observes that a restore of the database to a point in time at 14:07 on Wednesday completed successfully but took 9 hours, exceeding the stated maximum tolerable downtime (MTD) of 4 hours. Which TWO conclusions should the auditor draw from this observation? (Choose two.)
Hard403An IT steering committee is evaluating a major system upgrade. Which of the following is the PRIMARY benefit of using an IT balanced scorecard in this evaluation?
Medium404An organization is implementing a new IT governance framework. Which of the following is the PRIMARY benefit of using a framework like COBIT?
Easy405Which TWO of the following are components of the ITIL 4 four dimensions of service management? (Select TWO.)
Medium406An IS auditor is reviewing an agile project that uses Scrum. Which event provides the best opportunity for the auditor to assess whether completed user stories meet the defined acceptance criteria?
Medium407During a post-implementation review of a new HR system, the auditor finds that the system's disaster recovery plan (DRP) was not tested before go-live. Which of the following is the BEST recommendation?
Hard408During a review of the patch management process, the IS auditor finds that critical security patches are applied within 30 days, but the policy requires application within 7 days. The IT manager argues that the delay is due to testing requirements. What should the auditor recommend?
Medium409An IS auditor is examining how an organization classifies and handles its data. The auditor finds that the data classification policy defines four tiers but does not specify retention periods, handling procedures, or labeling requirements for each tier. Management states that employees use their judgment when handling sensitive information. Which of the following is the MOST appropriate recommendation?
Hard410A company is updating its business continuity plan (BCP). Which THREE of the following should be included as key components?
Hard411A bank is converting data from its legacy core banking system to a new platform. Which control is MOST critical to ensure the completeness and accuracy of data conversion?
Medium412Which of the following audit types is MOST likely to be performed by an organization's own employees?
Easy413An IS auditor is reviewing a system development project to assess whether it is on schedule. Which of the following would provide the BEST evidence of project progress against the planned timeline?
Medium414Refer to the exhibit. During a security audit, an IS analyst identifies that a critical business application hosted on 192.168.1.100:443 is unreachable from the 10.0.1.0/24 subnet. Which of the following is the MOST likely cause?
Hard415During a change management board (CAB) meeting, a proposed change to the network firewall configuration is discussed. The change is considered low risk and pre-approved. Which type of change does this represent?
Easy416An organization is implementing a new system using a rapid application development (RAD) approach. The IS auditor is concerned about the lack of formal documentation. Which of the following is the MOST appropriate audit response?
Medium417You are the IT governance lead at a multinational corporation with a complex IT environment spanning multiple business units. The company has recently experienced a series of minor security incidents where unauthorized access was gained through unused user accounts that were not disabled after employees left the organization. Additionally, there have been delays in provisioning access for new hires, leading to productivity losses. The IT department currently uses a manual process for access management, with each business unit maintaining its own user lists. The company has a policy that requires access reviews every quarter, but these are often missed or performed superficially. The CIO has asked you to recommend a solution that addresses these issues while ensuring compliance with regulations such as GDPR and SOX. Which of the following is the BEST course of action?
Hard418During system development, which testing phase is performed by developers to verify that individual program units function correctly?
Medium419Which TWO of the following are indicators that a project is at risk of failure according to ISACA's project governance framework?
Hard420Refer to the exhibit. An auditor notices this log entry during a review. The user john.doe does not have a legitimate business need to access executive salaries. Which of the following is the MOST likely control failure?
Medium421An IT steering committee is reviewing a proposal for a new customer relationship management (CRM) system. What is the committee's MOST important role?
Medium422An IS auditor is examining how a financial services firm enforces data loss prevention (DLP) for outbound email. The firm uses a network DLP appliance that inspects SMTP traffic and blocks messages containing unencrypted account numbers. The auditor discovers that employees can bypass the appliance by using a personal webmail account over HTTPS. Which of the following should the auditor recommend FIRST?
Hard423Which of the following is the PRIMARY purpose of a business impact analysis (BIA)?
Easy424An auditor discovers that a financial institution's IT department uses a decentralized model, with each business unit managing its own applications. What is a PRIMARY risk of this structure?
Hard425An auditor is selecting a sample of purchase orders for testing. The auditor decides to select every 50th purchase order from a list. This is an example of:
Medium426An IS auditor is evaluating how an organization detects unauthorized changes to the configuration of its internet-facing web servers. The organization runs a file integrity monitoring tool that hashes critical configuration files hourly and alerts on any hash mismatch. Which of the following is the MOST important factor in determining whether this control provides effective detection?
Medium427An IS auditor is examining how a data center protects its backup tapes while they are transported to an offsite vault. Management states that tapes are encrypted at rest using AES-256. Which of the following is the MOST important control the auditor should verify to protect the tapes during transit?
Medium428Which TWO of the following are types of analytical procedures used in an IS audit? (Select two.)
Medium429Which THREE of the following are common challenges when integrating a software package with existing legacy systems? (Select exactly three.)
Hard430An organization is implementing a large ERP system. The project manager is concerned about segregation of duties conflicts. Which THREE controls should the IS auditor recommend to mitigate segregation of duties risks during implementation? (Select THREE)
Hard431An IS auditor is reviewing an agile software development project. Which of the following would be the BEST evidence that adequate controls are in place for user acceptance?
Medium432An IT manager needs to ensure that the organization's IT resources are used efficiently. Which of the following is the BEST metric to measure IT resource utilization?
Easy433Which TWO of the following are BEST indicators that a system development project is at risk of failure?
Hard434During a spiral SDLC project, the IS auditor should focus on which aspect as the primary risk?
Hard435During a firewall rule review, an IS auditor identifies several rules that allow any-to-any traffic. Which THREE of the following should the auditor recommend as the MOST appropriate actions?
Hard436An organization experiences a critical system failure during non-business hours. The IT team discovers that the last full backup was 48 hours ago, and the incremental backups for the past 24 hours are corrupted. The recovery time objective (RTO) for this system is 4 hours, and the recovery point objective (RPO) is 1 hour. Which of the following is the MOST immediate concern?
Medium437Which of the following is a key advantage of using an iterative SDLC model over a waterfall model?
Easy438An organization has a clean desk policy. Which of the following is the BEST audit procedure to test compliance with this policy?
Medium439A mid-sized company is upgrading its legacy financial system to a new cloud-based ERP. The project manager has decided to use a big-bang cutover approach to minimize costs and time. During the first week post-go-live, users report that several critical reports are generating incorrect totals. An initial investigation reveals that the data mapping from the old system to the new system was not fully validated. Which of the following should the IS auditor recommend as the most appropriate corrective action?
Easy440Which of the following is the PRIMARY benefit of using a prototype during system development?
Easy441An IS auditor is assessing the effectiveness of the change management process for a critical financial application. The auditor wants to determine whether changes are adequately tested before being deployed to production. Which TWO of the following procedures would provide the MOST relevant evidence? (Choose two.)
Medium442An IS auditor is reviewing an organization's problem management process. The auditor finds that problem records are created only after multiple incidents with the same root cause have occurred, and there is no proactive trend analysis. Which TWO of the following are the MOST important improvements the auditor should recommend? (Choose two.)
Medium443An organization's IT department is considering a shift from insourcing to co-sourcing for application development. What is a PRIMARY advantage of co-sourcing?
Medium444An IS auditor is reviewing how an organization manages its backup media. The auditor learns that full backups are written to tape each night, the tapes are stored in a cabinet in the data center, and the same cabinet is used to store cleaning supplies and spare hardware. Which of the following is the MOST significant risk the auditor should highlight?
Medium445An organization is implementing a data masking solution for a non-production database. Which of the following is the MOST important requirement?
Medium446An organization has a policy requiring annual information security awareness training for all employees. During a recent audit, it was found that 20% of employees had not completed the training. What is the BEST course of action for the IT governance committee?
Easy447An IT auditor is reviewing the problem management process. The IT team maintains a repository of known errors with documented workarounds. Which component of problem management is this?
Medium448Which THREE of the following are common challenges when implementing a bring-your-own-device (BYOD) policy that affect information systems operations? (Select exactly 3.)
Hard449Which TWO of the following are essential controls to ensure data integrity during a cloud migration project?
Medium450A company outsources its data center operations to a third-party provider. Which of the following is the MOST important control to include in the outsourcing contract?
Medium451An IS auditor is evaluating the reliability of audit evidence obtained during a review of an outsourced payroll provider. Which TWO of the following considerations most directly affect the reliability of that evidence? (Choose two.)
Medium452Which THREE of the following are commonly used data encryption standards? (Choose three.)
Easy453An IS auditor is reviewing logical access controls for a critical application. Which of the following is the MOST important control to detect unauthorized access?
Medium454An IS auditor is reviewing change management for a financial application. Which TWO of the following findings would most likely indicate a control weakness?
Hard455An organization is implementing a data classification policy and needs to assign ownership for sensitive data. Which of the following is the most appropriate role to assign as the data owner?
Medium456An IS auditor is reviewing an organization's IT operations incident management process. The auditor finds that incidents are logged, but there is no formal problem management process. Which TWO of the following are the MOST likely consequences of this deficiency? (Choose two.)
Hard457A multinational corporation is replacing its legacy on-premises customer relationship management (CRM) system with a new cloud-based CRM solution. The project involves migrating data from the old system, customizing the new system to match business processes, and integrating with an existing enterprise resource planning (ERP) system. The project has a tight deadline of six months. During the planning phase, the project team decides to use a waterfall methodology because the requirements are well-defined. However, three months into the project, the business users request significant changes to the customer data fields, which were not originally specified. The project manager is concerned that accommodating these changes will delay the project. The integration with the ERP system is also proving more complex than anticipated, with data mapping errors causing delays. The go-live date is fixed due to the end-of-support for the legacy system. What is the BEST course of action for the project manager?
Hard458An IS auditor is designing substantive test procedures for a newly implemented automated accounts payable system and wants to rely less on the client's automated controls. The auditor decides to use computer-assisted audit techniques to test the completeness and accuracy of transaction processing. Which TWO of the following techniques would BEST provide direct evidence about the population of transactions? (Choose two.)
Hard459A company is in the process of acquiring a new customer relationship management (CRM) system. During which phase of the systems development life cycle (SDLC) should the business requirements be formally documented?
Easy460An IS auditor is reviewing the acquisition of a new software package. The vendor provides a Service Organization Control (SOC) 2 Type II report. Which of the following is the MOST important factor for the auditor to consider when relying on this report?
Medium461An organization uses risk-based authentication (RBA) for user access. Which of the following factors would MOST likely trigger a step-up authentication?
Medium462An IS auditor is evaluating the effectiveness of a security awareness program. Which of the following metrics would BEST indicate that the program is achieving its objectives?
Medium463An organization's IT policy review cycle is set to every two years. However, a new regulation requires immediate changes to data retention policies. What is the best course of action?
Medium464An IS auditor is auditing the user access management process for a large healthcare organization that uses an electronic health records (EHR) system. The organization has 5,000 users including doctors, nurses, and administrative staff. The auditor reviews a sample of access requests and finds that 20% of the requests were approved by the user's manager but the approval was not documented in the system. The auditor also finds that there is no periodic review of user access rights. The IT security manager states that users are automatically provisioned based on their role in the HR system, and that access reviews are performed manually by managers but not documented. What is the auditor's BEST recommendation to address the most significant risk?
Medium465An IS auditor is reviewing an organization's disaster recovery plan (DRP) for its primary data center. The DRP specifies a reciprocal arrangement with a partner organization for backup processing. Which of the following is the MOST significant risk associated with this arrangement that the auditor should highlight?
Hard466A project team is using a prototyping approach for a new system. Which of the following is the BEST control to ensure the prototype accurately reflects user needs?
Medium467An IS auditor is planning an audit of a cloud service provider's security controls. The auditor has limited access to the provider's internal systems. Which of the following would be the MOST effective way to obtain assurance over the provider's security controls?
Medium468An IS auditor is reviewing the implementation of a new payroll system that was developed in-house. The project team followed a traditional waterfall SDLC. During the post-implementation review, the auditor found that the system was delivered on time and within budget, but several critical payroll calculations were incorrect, leading to employee underpayments. The root cause was traced to a misunderstanding of tax law changes that occurred during the requirements phase. Which of the following is the MOST likely control weakness that contributed to this issue?
Hard469Which of the following best describes the primary advantage of using statistical sampling over non-statistical sampling in an IS audit?
Hard470During a disaster recovery test, the IS auditor observes that the alternate site uses a warm site configuration. Which of the following is a characteristic of a warm site?
Hard471When implementing a data classification policy, which of the following roles is PRIMARILY responsible for assigning classification labels to data?
Easy472During a software asset management (SAM) audit, the IS auditor discovers that the organization is using software versions that are no longer supported by the vendor. What is the primary risk?
Medium473During a system development project, the IS auditor notes that code reviews are performed only after the code is unit tested. Which of the following is the MOST significant risk associated with this practice?
Medium474During an incident response, the IT team isolates a compromised system from the network. Which of the following is the primary purpose of this action?
Easy475A nonprofit organization develops a small online donation platform using a third-party payment gateway. The project team skips formal security testing because of budget constraints. After launch, a security researcher discovers that the application fails to validate input on the donation amount field, allowing manipulation. The nonprofit loses several thousand dollars before the issue is patched. The IS auditor is asked to review the system development process. Which of the following is the PRIMARY finding?
Easy476An IS auditor reviews the exhibit. Which of the following is the most likely cause of the denied traffic?
Easy477Which of the following is an example of a compliance audit?
Easy478Which TWO of the following are HR controls that help mitigate the risk of insider fraud in IT? (Select TWO.)
Easy479An IS auditor is reviewing the change management process for a financial application. Which of the following findings would be of MOST concern?
Medium480A company stores sensitive customer data in a database. To comply with privacy regulations, the data must be anonymized for analytics. Which technique provides the strongest anonymization while preserving data utility?
Hard481An IS auditor is evaluating the IT service continuity plan for a hospital's electronic health record (EHR) system. The auditor finds that the plan includes a recovery time objective (RTO) of 4 hours, but the hospital's clinical staff state that they can tolerate only 1 hour of downtime before patient safety is compromised. Which of the following should the auditor recommend FIRST?
Medium482Refer to the exhibit. This log entry MOST likely indicates:
Hard483An organization has outsourced its IT help desk to a third-party provider. Which of the following is the MOST critical control to ensure service quality?
Hard484An IS auditor is performing a walkthrough of a purchase-to-pay process. Which of the following is the auditor most likely trying to achieve?
Medium485An IS auditor is evaluating how an organization enforces segregation of duties (SoD) within its enterprise resource planning (ERP) system. Management states that SoD conflicts are identified during user provisioning. Which TWO of the following audit procedures would BEST determine whether SoD controls operate effectively on an ongoing basis? (Choose two.)
Hard486An IS auditor is reviewing the antivirus and endpoint protection deployment across a hospital's clinical workstations. The auditor finds that signature updates are delivered daily, real-time scanning is enabled on all workstations, but the endpoint protection console shows that 40 of 600 workstations have not checked in for more than 30 days. Which of the following should the auditor do FIRST?
Easy487A financial services company is migrating its core banking system to a public cloud to improve scalability and reduce costs. The project is high-risk due to regulatory compliance requirements (e.g., data residency, audit trails). The IT governance committee has reviewed the project plan and finds that the risk assessment is incomplete – it does not address the potential impact of a cloud provider outage on critical transactions. The committee must approve the project or request changes. The project manager argues that the cloud provider's SLA guarantees 99.99% uptime and that additional controls would delay the project. What should the governance committee do?
Medium488An organization is considering acquiring a commercial off-the-shelf (COTS) ERP system. Which of the following risks is most effectively mitigated by including a contractual clause for audit rights?
Hard489An organization wants to protect its intellectual property from unauthorized disclosure via email. Which control should be implemented?
Easy490Based on the exhibit, which control is most likely missing to prevent this type of event?
Hard491During a post-implementation review of a new customer relationship management (CRM) system, the IS auditor finds that the system is processing transactions slower than anticipated. What is the BEST initial course of action for the auditor?
Medium492An IT manager is reviewing the access control model for a financial application. The policy requires that no single person can approve a transaction. Which access control principle does this policy enforce?
Medium493An organization is acquiring a new software package. The IS auditor is asked to review the contract with the vendor. Which of the following clauses is MOST important to ensure the organization can continue to use the software even if the vendor goes out of business?
Easy494Based on the exhibit, what is the MOST appropriate action for IT management?
Easy495An organization's IT department has grown rapidly, and the CIO wants to ensure that employees understand expected behaviors when handling sensitive data and operating critical systems. Which of the following is the MOST appropriate governance mechanism to establish?
Easy496An IS auditor is reviewing the problem management process after a series of recurring production outages. The auditor finds that incidents are resolved quickly but the same underlying faults reappear. Which TWO activities should the auditor expect to find in an effective problem management process? (Choose two.)
Medium497An IS auditor is assessing the effectiveness of network segmentation for a payment card processing environment. Which of the following is the PRIMARY benefit of network segmentation in meeting PCI DSS requirements?
Easy498Which TWO of the following are characteristics of the iterative SDLC model?
Easy499A hospital is implementing a new electronic health record (EHR) system. The project team includes clinicians and IT staff. During integration testing, the system fails to exchange lab results with the existing legacy system due to format mismatches. The IT team suggests developing a custom interface. The clinical team is concerned that any custom solution may not comply with health data privacy regulations. The project sponsor pressures the team to quickly fix the issue to avoid delays. The IS auditor is reviewing this situation. What is the MOST appropriate action for the auditor to recommend?
Medium500An IS auditor is reviewing the vulnerability management program. The auditor notes that a critical vulnerability was identified in a production system six months ago and has not been patched due to a business impact assessment. Which of the following should the auditor examine NEXT?
Medium501Order the steps for responding to a security incident in the correct sequence.
Medium502Which TWO of the following are essential components of a business case for a new system?
Easy503An organization is developing a new customer portal. The development team wants to use an agile methodology. Which of the following is a key benefit of using agile for this project?
Easy504In a RACI matrix for an IT process, which role should be assigned to the person who ultimately approves the outcome and is held accountable for its success?
Medium505An organization uses a chargeback model to allocate IT costs to business units. What is a PRIMARY benefit of this approach?
Easy506An IS auditor is reviewing firewall rule sets and discovers a rule that permits any source IP to access the internal database server on TCP port 1433 (Microsoft SQL). The rule was documented as a temporary measure but has been in place for 18 months. What is the auditor's BEST course of action?
Hard507Which TWO of the following are primary objectives of a data loss prevention (DLP) strategy?
Hard508An IS auditor is reviewing the requirements definition phase of a new system development project. The auditor finds that business users have provided functional requirements, but non-functional requirements are largely missing. Which TWO of the following are the MOST significant risks of proceeding without well-defined non-functional requirements? (Choose two.)
Hard509An IS auditor is reviewing how a retail company protects stored payment card data. The company states it encrypts card numbers using AES-256, but the auditor finds that the database encryption keys are stored in a plaintext configuration file on the same application server as the encrypted data. Which of the following is the auditor's PRIMARY concern?
Hard510Which of the following is the PRIMARY purpose of performing a walkthrough during the audit planning phase?
Medium511During a post-implementation review of a new ERP system, the IS auditor identified that the project was delivered within budget but user satisfaction scores are low. Which THREE areas should the auditor examine further?
Hard512An IS auditor is reviewing an organization's vulnerability management program. The auditor notes that a critical vulnerability in a key application has not been patched for 90 days, and there is no documented risk acceptance. What should the auditor do FIRST?
Hard513Which of the following is the PRIMARY purpose of a business impact analysis (BIA) in business continuity planning?
Easy514In an agile development environment, an IS auditor reviews the backlog and finds that security requirements are not explicitly included. What is the best recommendation?
Hard515An IS auditor is documenting the audit programme for an engagement and must decide how specific the procedures should be. Which of the following BEST describes the appropriate level of detail for procedures recorded in the audit programme?
Medium516A security review of the above Apache configuration identifies a critical vulnerability. Which of the following is the MOST significant issue?
Hard517During an agile software development project, which of the following events provides the best opportunity for the IS auditor to assess the effectiveness of controls implemented in the current sprint?
Easy518An organization is migrating sensitive customer data to a public cloud. Which of the following encryption strategies provides the STRONGEST protection against data exposure to the cloud provider?
Medium519An organization's IT strategy is not aligned with business strategy due to lack of communication. Which of the following would BEST improve alignment?
Hard520During an audit of privacy controls, the IS auditor discovers that the organization processes personal data of EU residents but has not appointed a Data Protection Officer (DPO). Which regulation is MOST likely being violated?
Hard521During a vendor evaluation for a critical system, the IS auditor notes that the vendor's SOC 2 report includes an adverse opinion. What should be the auditor's PRIMARY recommendation?
Medium522An organization is implementing a new human resources system. The IS auditor wants to determine whether the system will enforce segregation of duties (SoD) for sensitive transactions such as payroll changes and employee master data updates. Which of the following is the MOST appropriate source of evidence?
Easy523An IS auditor is reviewing a data center's environmental controls and observes that the fire suppression system uses water sprinklers in the main server room. The auditor learns that the sprinkler system was installed when the facility was a general office space. Management states that the sprinklers have never activated. Which of the following should the IS auditor recommend as the MOST appropriate control improvement?
Medium524An organization has decided to adopt a formal IT governance framework to improve alignment between IT and business objectives. Management asks the IS auditor to advise on the FIRST step in the adoption process. Which of the following should the IS auditor recommend?
Medium525Which TWO of the following are guiding principles of ITIL 4? (Select TWO)
Medium526A multinational corporation operates in a highly regulated industry. The IT governance framework includes a risk appetite statement approved by the board. Recently, the company suffered a significant data breach due to an unpatched vulnerability that had been identified three months earlier. The IT audit found that the vulnerability was reported to the IT department but was not prioritized for remediation because it was deemed low risk by the IT operations team. The incident response plan was not activated because the breach was not initially detected. The board wants to strengthen governance to prevent recurrence. The most effective course of action for the auditor to recommend is:
Hard527An organization is implementing a new identity management system. Which testing approach is MOST effective for verifying access controls?
Medium528An organization is considering whether to build a custom application or purchase a commercial off-the-shelf (COTS) product. Which of the following factors is MOST important when deciding to build rather than buy?
Medium529A security architect is designing a data classification schema for a multinational corporation. Which combination of factors is MOST critical for determining the classification level of a data asset?
Hard530An organization uses a risk-based audit approach. For a high-risk area, the auditor decides to perform 100% testing instead of sampling. Which of the following is a valid reason for this decision?
Hard531An IS auditor is planning an audit of a financial application. The auditor wants to ensure that audit effort is focused on areas with the highest risk. Which approach should the auditor adopt?
Medium532An IS auditor is reviewing the backup strategy for a transactional database that processes customer orders. The database is backed up nightly with full backups, and transaction log backups occur every 15 minutes. The recovery point objective (RPO) for the system is 5 minutes. Which of the following is the MOST significant finding the auditor should report?
Hard533An IS auditor is examining how a hospital enforces least privilege for its electronic health record (EHR) system. During walkthroughs, the auditor observes that nurses can access the billing module and that no formal process exists to request, approve, or periodically recertify role assignments. Which of the following is the MOST appropriate recommendation?
Medium534An organization is implementing a new payroll system using an agile methodology. Which TWO of the following are the MOST important controls for the IS auditor to assess?
Medium535An IS auditor is reviewing an organization's data loss prevention (DLP) strategy. The organization has implemented a network DLP solution but has not yet deployed endpoint DLP. Which TWO of the following are the MOST significant risks of relying solely on network DLP? (Choose two.)
Medium536An organization is implementing a new identity management system. Which THREE of the following are essential requirements for the system?
Medium537An organization outsources its IT help desk to a third-party vendor. Which clause is MOST important for the IS auditor to verify in the contract to ensure the organization can assess the vendor's controls?
Medium538An IS auditor is reviewing the access recertification process for a financial institution. The process requires users and their managers to confirm access rights quarterly. During the review, the auditor finds that recertifications are consistently completed late, with an average delay of 45 days. Additionally, terminated employees' access is not always removed promptly, and there are no compensating controls. Which of the following is the MOST significant risk arising from these findings?
Medium539An IT manager submits a request to change the firewall configuration during business hours. According to best practices for change management, what should be done FIRST?
Easy540An IS auditor is reviewing the organization's data inventory process for privacy compliance. Which TWO of the following are the MOST important elements that should be included in the data inventory?
Medium541Which TWO of the following are types of statistical sampling methods? (Select TWO.)
Medium542An organization's IT department implemented a new change management process that requires all changes to be approved by a change advisory board (CAB). A critical security patch needs to be deployed within 2 hours to address an active zero-day vulnerability. The change request was submitted but the CAB is not scheduled to meet for another 24 hours. What is the BEST course of action?
Medium543An IS auditor is reviewing the IT operations function of a mid-sized organization. Management asks which control would BEST ensure that capacity problems are detected before they affect users of critical production systems.
Easy544Which TWO of the following are the MOST effective controls to prevent unauthorized access to a data center's server room? (Choose two.)
Hard545Which of the following is the PRIMARY purpose of conducting a privacy impact assessment (PIA) before implementing a new system that processes personal data?
Easy546An IS auditor is reviewing the logical access controls of an enterprise resource planning (ERP) system. The auditor finds that terminated employees' accounts are disabled but not deleted. What is the PRIMARY risk associated with this practice?
Easy547Which of the following is the PRIMARY purpose of an IT governance framework?
Easy548Arrange the steps to implement a patch management process in the correct order.
Medium549An organization is developing a business continuity strategy. Which THREE of the following are essential components of a comprehensive BC strategy?
Hard550Which of the following is the most reliable form of audit evidence?
Medium551An IS auditor is assessing the physical and environmental controls of a primary data center located in a region subject to seasonal flooding. Management has installed a raised floor, a water detection system, and a pre-action fire suppression system. Which TWO of the following findings would the auditor consider MOST significant? (Choose two.)
Hard552Which of the following is a primary advantage of fixed-price contracts in systems acquisition?
Easy553An IS auditor is reviewing the job scheduling function for a mainframe environment that runs nightly batch processing. The auditor finds that the senior operator has standing access to modify production JCL and job schedules without a second approval. Which control should the auditor recommend to BEST mitigate the associated risk?
Medium554Which of the following is a key principle of corporate governance of IT according to ISO/IEC 38500?
Easy555During which phase of the audit process does the auditor perform procedures such as inquiry, observation, and inspection?
Easy556An organization has a disaster recovery plan that includes a hot site. During a full interruption test, the recovery team discovers that the hot site's network configuration is incompatible with the production environment. What is the most likely root cause?
Hard557After a security incident, an organization discovers that an employee accessed sensitive files without authorization. Which of the following is the most effective preventive control to reduce the risk of such unauthorized access?
Medium558An IS auditor is assessing how an organization classifies and handles its information assets. The auditor finds that a data classification policy exists but is inconsistently applied across business units. Which TWO of the following are the MOST important elements the auditor should verify are present to support effective data classification? (Choose two.)
Medium559Which type of audit evidence involves the auditor independently performing a control procedure to verify its effectiveness?
Medium560An IS auditor is planning a compliance audit of a payment gateway that processes credit card transactions. The auditor needs to determine whether the control environment meets the requirements of the applicable payment card industry standard. Which of the following should be the auditor's PRIMARY basis for defining the audit criteria?
Medium561Order the steps for performing a disaster recovery test in the correct sequence.
Medium562An organization is implementing a new cloud-based HR system. The project sponsor wants to skip regular project status meetings to speed up delivery. Which THREE of the following are the MOST significant risks of eliminating these meetings?
Hard563Which THREE of the following are valid reasons for implementing a service level management process? (Select THREE.)
Hard564An IS auditor is evaluating a control that requires the security administrator to review privileged access logs weekly. During testing, the auditor finds the reviews were performed but no evidence of follow-up exists for two anomalies identified in one review. Which of the following conclusions is MOST appropriate?
Hard565An IS auditor is reviewing the IT service continuity plan for a regional bank. The plan identifies a recovery time objective of 6 hours for the core banking system and designates a warm site with pre-installed hardware but no replicated data. The plan states that data will be restored from nightly backups stored in an offsite vault. Which of the following is the MOST critical issue the auditor should raise?
Medium566During a disaster recovery test, the team discovers that the backup server is unable to restore data because of incompatible software versions. Which TWO controls should have been implemented to prevent this?
Easy567An IS auditor is reviewing the IT governance framework of a financial services firm. The auditor notes that the IT strategy is updated annually, but there is no process to monitor whether IT initiatives are aligned with the strategy. Which of the following is the BEST recommendation?
Medium568An IS auditor is reviewing the audit documentation from a prior year and finds that a material weakness was reported but not remediated. According to ISACA standards, which audit phase should address this?
Hard569An IS auditor is reviewing an organization's backup and recovery procedures for a critical database. The backup policy states that full backups are performed weekly and transaction log backups every 15 minutes. The recovery point objective (RPO) for the database is 5 minutes. Which of the following is the MOST appropriate recommendation?
Medium570During a post-implementation review of a system, an IS auditor finds that the actual transaction processing time is 30% slower than projected. What should the auditor recommend FIRST?
Medium571During a review of a data center, an IS auditor observes that backup tapes containing customer records are transported nightly by a courier to an offsite vault. The tapes are placed in sealed containers, but the auditor learns that the courier contract does not require background checks for drivers and that no encryption is applied to the tape contents. Which of the following should the auditor recommend as the MOST effective compensating control?
Hard572An IS auditor is conducting an audit of a payroll application and needs to verify that user access rights match each employee's current job responsibilities. Which of the following is the MOST appropriate source of evidence for this test?
Easy573An organization is implementing a new financial system using the waterfall SDLC model. Which of the following is the MOST critical control to ensure that business requirements are met?
Easy574A government agency is developing a case management system for law enforcement. The project follows an agile approach, releasing iterations every two weeks. During a sprint demo, users discover that the system does not redact personally identifiable information (PII) in documents shared with external parties, violating privacy laws. The development team says they planned to add redaction in a future sprint. The product owner wants to prioritize PII redaction immediately. The project manager is concerned that this will disrupt the release schedule. The IS auditor is assessing the project's risk management. Which of the following is the BEST recommendation?
Hard575Which of the following BEST describes the role of threat modeling in the design phase of the SDLC?
Medium576An IS auditor is assessing the effectiveness of an organization's IT governance implementation. Which TWO of the following are the MOST important indicators that IT governance is effectively implemented? (Choose two.)
Hard577An organization is deploying a major system upgrade. The change request has been approved by CAB, but the deployment plan does not include a rollback procedure. As an IS auditor, what should you recommend?
Hard578Which of the following is the PRIMARY objective of a penetration test?
Easy579Which of the following is the PRIMARY purpose of an IT strategy committee?
Easy580During the follow-up phase of an audit, the auditor discovers that a previous finding has not been remediated. What is the auditor's BEST course of action?
Medium581In a waterfall SDLC, when should user acceptance testing (UAT) typically occur?
Easy582An auditor is evaluating the IT governance framework of a large bank. Which TWO of the following are components of COBIT 2019's governance system? (Select TWO.)
Medium583An IS auditor is evaluating how an organization manages its backup and restoration process for a critical financial application. The backup job completes successfully each night and writes to a tape library. Management states that recovery capability has been proven because the backup job reports success. Which audit procedure would BEST test whether the backups are actually restorable?
Hard584An IS auditor is conducting an audit of a hospital's electronic health record system. During fieldwork, the auditor discovers that several database administrators have the ability to modify patient records directly in the production database without leaving an audit trail. The auditor wants to gather sufficient appropriate evidence to determine whether this is a widespread issue. Which of the following is the MOST appropriate action?
Medium585An organization is implementing a new release management process. Which TWO activities are essential components of a successful release?
Easy586An organization is planning to replace its legacy accounting system with a commercial off-the-shelf (COTS) software package. Which of the following is the PRIMARY risk of using a COTS solution?
Easy587An organization has outsourced its IT operations to a third-party provider. The IS auditor is planning an audit of the outsourced services. What is the most appropriate source of audit evidence?
Easy588An IS auditor is assessing an organization's problem management process. The auditor finds that while incidents are logged and resolved, there is no formal problem management procedure. Several recurring incidents have been resolved with workarounds but not investigated for root cause. Which of the following is the MOST significant consequence of this deficiency?
Medium589An IS auditor is reviewing the problem management process of a financial services firm. The auditor finds that incidents are frequently resolved by the service desk using documented workarounds, but no problem records are created, and root cause analysis is rarely performed. As a result, the same high-impact incident has recurred 14 times in three months. Which of the following is the MOST significant risk arising from this practice?
Medium590Which of the following is a key objective of the design phase in the SDLC?
Easy591Which TWO of the following are phases of the audit process? (Select two.)
Easy592An organization's IT service desk is the single point of contact for all incidents. The SLA for resolving P2 incidents is 8 hours. The auditor finds that the service desk frequently reassigns P2 incidents to second-level support without updating the incident record, causing delays in resolution. The average resolution time for P2 incidents is 10 hours. What is the primary control weakness?
Hard593Which IT sourcing model involves using an external provider to manage some IT functions while retaining others in-house?
Easy594An organization uses a third-party cloud service for data storage. Which of the following is the BEST way to ensure data confidentiality in the event of a cloud provider breach?
Hard595A company requires employees to use smart cards for facility access. Which additional control would BEST prevent tailgating?
Easy596An IS auditor is reviewing an organization's IT governance structure and finds that the IT steering committee meets quarterly but has no defined charter or decision-making authority. Which of the following is the MOST significant risk arising from this situation?
Medium597An organization's IT security policy requires background checks for all IT staff handling sensitive data. Which of the following is the PRIMARY reason for this requirement?
Medium598An IS auditor is evaluating an organization's backup strategy for a critical database. The database is backed up nightly using a full backup, and transaction logs are backed up every 15 minutes. The auditor discovers that the transaction log backups are written to the same storage array as the database files. Which of the following is the MOST significant risk?
Hard599The IT governance objective 'Evaluate-Direct-Monitor' in COBIT 2019 is primarily associated with which role?
Easy600A retail company is merging with a competitor. The IT departments of both organizations have different IT governance structures: Company A uses a centralized model with strict change management, while Company B uses a decentralized model with autonomous business unit IT. The CIO has been tasked with integrating the IT functions post-merger. The board expects cost synergies and improved service levels. The integration team is facing resistance from Company B's business heads who fear loss of agility. The CIO needs to propose a governance model for the merged entity. Which approach would BEST meet the board's expectations while addressing resistance?
Medium601An IS auditor is assessing the effectiveness of an organization's IT governance framework. Which THREE of the following are key indicators of a mature governance process?
Hard602An IS auditor is evaluating the effectiveness of a backup strategy for a critical database. Which TWO of the following are essential controls to ensure data recoverability?
Medium603An organization has decentralized IT management with each business unit making its own technology decisions. Which of the following is the BEST way to maintain enterprise-wide governance?
Hard604Which TWO of the following are examples of detective controls? (Choose two.)
Medium605A company's backup policy requires that backup media be stored offsite. Which of the following is the PRIMARY reason for this requirement?
Easy606An IS auditor is evaluating an organization's IT risk management process. The auditor finds that risk assessments are performed annually by the IT department alone, without input from business units. Which of the following is the MOST significant concern?
Hard607An organization is disposing of old servers. The IS auditor reviews the asset disposition process and finds that hard drives are being erased using a standard format command. What is the auditor's primary concern?
Hard608During an audit of a cloud service provider, the IS auditor finds that the provider's datacenter access logs show multiple successful logins by an employee during non-business hours over several weeks. The employee works in the sales department. What should the auditor do first?
Medium609An IS auditor is assessing the business impact analysis (BIA) for a critical business function. The BIA identifies a maximum tolerable downtime (MTD) of 8 hours and a recovery time objective (RTO) of 4 hours. The current disaster recovery plan (DRP) states that the recovery of this function will take 6 hours. What should the IS auditor conclude?
Easy610An e-commerce company stores customer payment card data in a tokenized database. The tokenization system replaces credit card numbers with tokens, and the actual card numbers are stored in a separate, highly restricted vault. The company is audited for Payment Card Industry Data Security Standard (PCI DSS) compliance. During the audit, it is discovered that the tokenization system sometimes fails due to high load, causing the application to fall back to storing actual card numbers temporarily. This fallback mechanism was not documented or approved. The company also uses the same encryption key for the vault as for other non-sensitive data. The auditor identifies several non-compliances. Which of the following should the company prioritize to remediate?
Medium611During an ERP implementation, the project team decides to customize the software to align with existing business processes. Which of the following risks is MOST likely to increase as a result of extensive customization?
Medium612Which of the following is a key difference between internal and external auditors?
Medium613An organization is implementing a disaster recovery plan. The DR team wants to test the plan with minimal risk and without impacting production operations. Which type of test is most appropriate?
Medium614An organization has defined an RTO of 4 hours for its critical financial system. During a disaster recovery test, the system was recovered in 3.5 hours, but data loss was 30 minutes. Which metric is most directly addressed by the recovery time?
Easy615During the planning phase of an IS audit, the auditor identifies that the organization has recently implemented a new ERP system. The audit team has limited experience with this ERP. Which of the following is the BEST course of action?
Medium616An organization outsources its data center operations. What is the BEST way to ensure the service provider's controls are effective?
Hard617Which of the following is the PRIMARY benefit of conducting a tabletop exercise for disaster recovery?
Easy618You are an IS auditor reviewing the remote access configuration for a medium-sized enterprise. The company uses a VPN concentrator to allow employees to connect from home. The VPN is configured with IPsec using pre-shared keys (PSK) and requires no multi-factor authentication. Employees use company-issued laptops with full disk encryption. The VPN logs show that connections are coming from a wide range of IP addresses, including some from countries where the company has no business operations. The IT manager argues that the PSK is changed monthly and that full disk encryption mitigates any risk. However, during the audit, you find that the PSK is stored in a shared document on an internal file server accessible to all employees. Additionally, the VPN concentrator uses a single PSK for all users. Which of the following is the MOST critical finding?
Hard619An IS auditor is planning an audit of a newly implemented financial system. Which of the following is the PRIMARY consideration when determining the audit scope?
Easy620An IT policy exception is requested to allow a legacy system that cannot be patched to remain in operation. What is the BEST way to manage this exception?
Medium621An organization has the storage bucket policy shown. Which of the following is the MOST likely intent of this policy?
Medium622You are the lead IT auditor for a multinational corporation that recently completed a merger with another company. During the post-merger integration audit, you discover that the acquired company's legacy HR system contains sensitive personal data of 20,000 employees and has been directly accessible from the internet for the last 18 months. The system runs on an unsupported operating system (Windows Server 2008) and uses a custom-built application with no logging enabled. The acquired company's IT manager argues that the server is isolated behind a firewall and has never been compromised. However, your review of firewall logs shows numerous connection attempts from unknown IP addresses. The integration team plans to decommission this system in three months. You need to determine the appropriate audit response. Which of the following should you do NEXT?
Hard623An IS auditor is reviewing the backup strategy for a financial institution. The backup administrator states that full backups are taken every Sunday, and incremental backups are taken Monday through Saturday. On Thursday morning, a database server fails, and the administrator needs to restore the server to its state as of Wednesday night. Which backup sets must the administrator use to perform this restoration?
Medium624An organization classifies IT incidents based on severity. A critical financial application is unavailable, impacting all users. According to ITIL best practices, which severity level should this incident be assigned?
Medium625Which type of disaster recovery test involves a full switch-over from the primary site to the alternate site, resulting in actual disruption of normal operations?
Easy626An IS auditor is reviewing the logical access controls for a financial application. The auditor notices that user access reviews are performed annually by the application owner, but there is no documentation indicating that managers confirm the continued need for access. Which of the following is the MOST significant risk associated with this finding?
Medium627An organization is adopting ITIL 4 to improve its service management practices. Which guiding principle emphasizes understanding how different components work together to deliver value?
Hard628An organization is implementing a business continuity plan (BCP). Which of the following is the PRIMARY purpose of conducting a business impact analysis (BIA)?
Easy629An organization has a policy requiring strong passwords. Which additional control is most effective at preventing credential stuffing attacks?
Easy630Which document is typically included in the permanent file of audit documentation?
Easy631An auditor is reviewing IT policy compliance and finds that a critical policy was last updated three years ago. The organization has undergone significant changes. What is the auditor's PRIMARY concern?
Hard632An IS auditor is reviewing a software development project that follows the waterfall model. Which of the following is the MAIN advantage of this methodology?
Easy633Which THREE of the following are responsibilities of the board of directors regarding IT governance? (Choose three.)
Hard634During a change management audit, an IS auditor finds that a critical system change was approved by the change manager without a CAB meeting. The change was categorized as a standard change. Which of the following should the auditor do FIRST?
Medium635An auditor is reviewing the encryption strategy for a healthcare application that stores protected health information (PHI) in a database. The database currently uses transparent data encryption (TDE). What is a key risk associated with TDE?
Medium636Refer to the exhibit. A tester executes test case TC-101 and records the result shown. What is the NEXT appropriate step in the testing process?
Medium637An IS auditor is reviewing the governance structure of a large retail company. The board has delegated all IT oversight to the IT steering committee, which meets quarterly and focuses primarily on project prioritization. The auditor notes that the board receives no IT-related reports and does not review IT risks. Which of the following is the MOST significant governance concern?
Medium638An organization is implementing a new IT governance framework. Which of the following is the BEST approach to ensure alignment between IT strategy and business goals?
Medium639When implementing a commercial off-the-shelf (COTS) software package, which of the following is the MOST important activity to ensure the software meets business requirements?
Easy640Which TWO of the following are examples of administrative controls for information security?
Easy641An IS auditor is evaluating the design of controls over a new financial system. Which of the following is the BEST approach to assess control design?
Hard642During a penetration test, a tester discovers that an application stores passwords using a reversible encryption algorithm. Which of the following is the BEST remediation?
Medium643According to ITIL 4, which guiding principle emphasizes understanding the current state before making improvements?
Medium644During system development, the project team discovers that the original requirements are incomplete. What is the BEST course of action?
Medium645An organization is implementing an automated job scheduling system. Which of the following is the PRIMARY benefit of using dependency management in job scheduling?
Medium646An IS auditor is reviewing an organization's data loss prevention (DLP) deployment. The auditor finds that the DLP solution is configured to monitor outbound email traffic at the network gateway, but endpoint agents are not installed on any workstations. Management states that this configuration is sufficient because all sensitive data leaves through email. Which of the following is the MOST significant risk arising from this configuration?
Medium647A multinational corporation is adopting a hybrid cloud strategy. The IT governance board must decide on a framework to ensure alignment with business objectives and regulatory compliance. Which framework is MOST appropriate?
Hard648An IT auditor is reviewing the alignment of IT with business strategy. Which THREE of the following are indicators of effective IT strategy alignment? (Select THREE.)
Hard649An IS auditor is evaluating an organization's IT governance framework. The auditor finds that IT decisions are made ad hoc by various business units without alignment to corporate strategy. Which TWO of the following are the MOST important governance mechanisms the auditor should recommend to address this issue? (Choose two.)
Hard650During a spiral SDLC project, the project team has completed a risk analysis and created a prototype. What is the most likely next step in the spiral model?
Hard651Which TWO of the following are examples of analytical procedures used as audit evidence? (Select two.)
Medium652An IS auditor is reviewing the system design phase of a project. Which of the following activities is most important to ensure that security is adequately addressed?
Medium653Which of the following is a characteristic of non-statistical (judgmental) sampling?
Medium654A company is implementing a new customer relationship management (CRM) system. The project team is currently defining user roles and permissions. Which of the following is the PRIMARY reason to enforce segregation of duties (SoD) within the CRM?
Easy655An IS auditor is reviewing the physical security of a data center. The auditor observes that the main entrance uses a proximity card reader, but the door to the server cage area is propped open with a box because the badge reader is malfunctioning. Staff state that the reader has been broken for two weeks and that a work order has been submitted. Which of the following should the IS auditor recommend FIRST?
Easy656A company's IT service desk receives multiple reports of users being unable to access a cloud-based CRM system. The network team confirms that internet connectivity is working. Which of the following should be the FIRST step in troubleshooting the issue?
Medium657A medium-sized financial services firm recently suffered a ransomware attack that encrypted critical servers and backups. The recovery process took three weeks because the backup tapes were stored in the same building (which was also infected) and the backup software had a vulnerability that allowed the ransomware to delete old backups. The firm's BCP did not account for simultaneous loss of primary and secondary data. As the IS auditor, you are asked to recommend the most effective improvement to the backup strategy to prevent recurrence and improve resilience. Which of the following actions should the firm implement?
Easy658During which phase of the waterfall SDLC should security requirements be formally documented and approved by the business owner?
Easy659Which of the following is the primary purpose of conducting a static application security test (SAST) during the development phase of the SDLC?
Easy660An IT auditor is reviewing the capacity management process. Which TWO of the following are key activities that should be performed?
Medium661A healthcare organization is required to comply with HIPAA regulations for data backup and disaster recovery. They operate a primary data center and a colocation facility for disaster recovery. The current backup strategy involves nightly full backups to tape, which are stored off-site monthly. The recovery time for the electronic health record (EHR) system is estimated at 8 hours, but the RTO required by the business is 2 hours. Additionally, the RPO requirement is 15 minutes. The IT manager proposes implementing a continuous data protection (CDP) solution. However, the CFO is concerned about the cost. Which of the following is the BEST argument to justify the CDP investment?
Hard662An IS auditor is evaluating the security of an organization's wireless network. The organization uses WPA3-Enterprise with 802.1X authentication. The auditor discovers that the RADIUS server is configured to accept EAP-TLS certificates but does not validate the certificate revocation status. Which of the following is the MOST likely consequence of this configuration?
Hard663A company is implementing a new ERP system. The project team plans to use a parallel conversion strategy. What is the PRIMARY advantage of this approach?
Medium664An IS auditor is reviewing a software-as-a-service (SaaS) provider that hosts a company's customer relationship management (CRM) data. The contract states the provider will maintain a SOC 2 Type II report, but the most recent report covers a period ending 14 months ago, and the provider has not responded to requests for a bridge letter. Which of the following should the auditor conclude?
Hard665What is the PRIMARY purpose of conducting a feasibility study before acquiring a new information system?
Easy666An organization is developing a web application using an Agile methodology. The security team wants to integrate security testing early in the development lifecycle. Which of the following is the BEST approach to achieve this?
Medium667An organization's business continuity plan includes a reciprocal agreement with another company. What is the PRIMARY risk of this arrangement?
Hard668An IS auditor is preparing working papers. Which of the following items should be included in the permanent file rather than the current file?
Hard669In a RACI matrix, the person who is ultimately accountable for a process outcome is assigned which role?
Easy670An IS auditor is examining how a retail bank protects stored cardholder data. The bank encrypts the primary account number in its customer database using AES-256, but the auditor learns that the encryption keys are stored in a configuration file on the same database server, readable by the database administrator account. Which of the following is the MOST appropriate conclusion?
Hard671In ITIL incident management, which severity level typically indicates a critical incident that severely impacts business operations and requires immediate resolution?
Easy672Which of the following is a key performance indicator (KPI) for IT service management?
Easy673An IS auditor is reviewing an organization's IT operations schedule and job dependency configuration for its overnight batch processing. The auditor discovers that several critical financial reconciliation jobs are scheduled with no predecessor dependencies and no defined restart procedures. The auditor also notes that operators frequently rerun failed jobs without documenting the cause. Which TWO findings should the auditor report as MOST significant operational risks? (Choose two.)
Hard674An IS auditor is reviewing change management procedures and finds that standard changes are approved by the change manager without CAB review. What is the auditor's BEST conclusion?
Medium675Match each type of access control to its definition.
Medium676An organization's business impact analysis shows that a payment processing system has a recovery time objective of two hours and a recovery point objective of fifteen minutes. The current disaster recovery strategy restores the system from nightly tape backups at an alternate site, with an observed restoration time of eight hours and up to twenty-four hours of data loss. Which action should the IS auditor recommend FIRST?
Hard677During an IT audit, the auditor discovers that the IT department has not conducted a business impact analysis (BIA) for three years. The organization's disaster recovery plan (DRP) is based on the previous BIA. The IT manager argues that the DRP is still valid because no major changes have occurred. What should the auditor recommend?
Hard678An organization is implementing a new customer relationship management (CRM) system. The project manager proposes using a pilot conversion strategy, where the new system is implemented in one department first, then gradually rolled out to others. Which of the following is the PRIMARY benefit of this approach?
Medium679During an audit, the auditor uses a sampling method where the population is divided into subgroups, and samples are selected from each subgroup. This method is known as:
Hard680A multinational corporation has adopted a decentralized IT governance model where business units have significant autonomy over IT decisions. The IS auditor is assessing the effectiveness of this model. Which of the following is the MOST critical factor for the auditor to evaluate?
Medium681During an ERP implementation, data migration is a critical activity. Which of the following controls would be most effective in ensuring the accuracy and completeness of migrated data?
Hard682A project uses a waterfall model. After design, the team discovers that the requirements have changed significantly. What is the BEST action?
Hard683An IS auditor is conducting a follow-up review of prior audit findings. Management has implemented a new automated control but has not yet updated the risk register to reflect the residual risk. Which of the following should the auditor do FIRST?
Medium684During an audit of the incident management process, the IS auditor finds that tabletop exercises have not been conducted in the past two years. What is the MOST significant risk associated with this finding?
Medium685An organization has implemented a database activity monitoring (DAM) solution. Which of the following are BEST practices for tuning the DAM to reduce false positives? (Choose TWO.)
Hard686Which of the following backup types copies only data that has changed since the last full backup?
Easy687An IS auditor is evaluating the use of continuous auditing techniques. Which of the following is the most significant benefit of implementing continuous monitoring over traditional periodic audits?
Hard688An IS auditor is reviewing a post-implementation review of a new payroll system. Which TWO findings should most concern the auditor? (Select two.)
Medium689A large enterprise is implementing a backup strategy for a critical database that requires an RTO of 2 hours and an RPO of 15 minutes. The database is 2 TB in size. Which backup method would BEST meet these requirements while minimizing storage costs?
Hard690Which THREE are indicators of a possible data exfiltration attempt via the network? (Choose three.)
Hard691An IS auditor is reviewing an organization's problem management process. The auditor wants to verify that the process effectively identifies and resolves root causes of incidents. Which TWO of the following are the MOST important controls to ensure effective problem management? (Choose two.)
Medium692An IS auditor is reviewing a project that replaced a legacy system. The project used a phased cutover, with each phase going live in a different region. After the final phase, the auditor finds that the legacy system was kept in read-only mode for six months, but no formal reconciliation was performed between legacy and new system balances during that period. Which of the following is the MOST significant concern?
Hard693Which of the following is the PRIMARY reason an external audit is considered more independent than an internal audit?
Easy694An IS auditor is evaluating the results of a penetration test performed by an external vendor on a web-facing application. The report identifies a critical SQL injection vulnerability. Which of the following is the MOST appropriate action for the IS auditor to recommend FIRST?
Medium695Which policy hierarchy document provides detailed steps for performing a specific task, such as resetting a user password?
Medium696During the acquisition of a new software package, the procurement team evaluates two vendors. Vendor A offers a lower upfront cost but higher annual maintenance fees. Vendor B has a higher upfront cost but includes three years of maintenance. What is the MOST important factor for the IS auditor to consider?
Medium697An organization outsources its help desk to a third-party vendor. The contract includes a service level agreement (SLA) with response times. The auditor wants to ensure that the organization can monitor vendor performance. Which clause is most important?
Medium698Which of the following types of audit evidence provides the highest level of assurance?
Medium699An organization's IT department has recently implemented a new project management methodology. The IS auditor is reviewing the project portfolio and finds that projects are prioritized based on the personal preferences of the IT director rather than strategic alignment. Which of the following is the MOST significant risk arising from this practice?
Easy700An IS auditor is reviewing a biometric access control system used to protect a data center. The system uses fingerprint recognition and is configured so that any single enrolled user who fails three consecutive attempts is locked out and must be re-enrolled by security staff. Which of the following is the MOST significant security concern with this configuration?
Hard701During the implementation of a new ERP system, the project team discovers that the legacy system data cannot be directly migrated due to incompatible data formats. The project manager proposes building a custom script to extract, transform, and load (ETL) data. Which of the following is the BEST course of action?
Medium702During the fieldwork phase, an IS auditor uses analytical procedures to compare current year IT expenses to prior year. A significant increase is noted. What should the auditor do next?
Medium703Which physical security control is most effective for preventing unauthorized individuals from tailgating into a data center?
Easy704Refer to the exhibit. A CISA is reviewing this S3 bucket policy. What is the PRIMARY security concern?
Easy705During a problem management meeting, the team identifies a recurring issue causing multiple incidents. The root cause is known, but a permanent fix is not yet available. Which of the following is the BEST approach to manage this situation until a permanent fix is implemented?
Medium706An IS auditor is testing the effectiveness of a control that involves a manual review of exception reports. The population of exceptions is 5,000 items. The auditor wants to achieve a 95% confidence level with a tolerable error rate of 2%. Which sampling method is MOST appropriate?
Hard707Which backup method copies all data that has changed since the last full backup, regardless of subsequent incremental backups, and is often used to reduce restore time?
Easy708An IT auditor is reviewing capacity management. The server team monitors CPU utilization and disk space. They receive alerts when thresholds are exceeded. Which practice is most effective for proactive capacity planning?
Easy709During a follow-up audit, an IS auditor finds that management implemented a compensating control rather than the recommended primary control to address a previously reported high-risk finding. The residual risk is now within the organization's risk appetite. How should the IS auditor respond?
Hard710An organization is implementing an IT governance framework to align IT with business objectives. Which TWO of the following are primary responsibilities of the IT steering committee?
Medium711A large financial institution has a well-defined IT governance framework with a clear organizational structure, policies, and processes. However, the internal audit department has identified that several IT projects are over budget and behind schedule. The project managers blame unclear requirements and scope creep. The IT governance committee meets monthly but reviews projects only at a high level. The auditor's best recommendation to improve project governance is to:
Medium712An IS auditor selects a sample of 50 transactions from a population of 1,000 using a random number generator. This is an example of which sampling method?
Medium713Which COBIT 2019 governance objective describes the board's responsibility for overseeing IT?
Easy714What is the primary purpose of the planning phase in an IS audit?
Easy715Which TWO of the following are primary objectives of information classification? (Choose two.)
Easy716An IS auditor is evaluating the disaster recovery plan (DRP) for a organization that relies on a cloud-based ERP system. The DRP states that the recovery time objective (RTO) is 4 hours and the recovery point objective (RPO) is 1 hour. The cloud provider's SLA guarantees 99.9% availability but does not specify RTO or RPO. Which of the following should the auditor recommend FIRST?
Hard717During an audit of an organization's backup and recovery process, the IS auditor finds that full backups are performed weekly and incremental backups are performed nightly. Restoration testing has not been performed in over two years. Which of the following should the auditor do FIRST?
Medium718During a risk assessment, an IS auditor identifies that the IT department has not performed a business impact analysis (BIA) for critical systems. Which of the following is the MOST significant risk?
Hard719An IS auditor is reviewing the software asset management (SAM) process. The organization uses a mix of commercial off-the-shelf (COTS) and open-source software. The auditor finds that several servers are running end-of-life (EOL) operating systems that are no longer patched. Which TWO risks are most directly associated with this finding?
Medium720An IS auditor is evaluating an organization's IT governance maturity using COBIT 2019. The auditor finds that IT processes are largely ad hoc, with no formal documentation, and success depends on individual heroics. Which of the following maturity levels BEST describes this situation?
Hard721An organization is evaluating two vendors for a critical cloud-based ERP system. Which TWO contractual clauses are most important to include to ensure the organization can monitor vendor performance and security? (Select TWO)
Medium722Based on the exhibit, what is the most likely control weakness that allowed this condition?
Medium723An IS auditor is reviewing automated job scheduling controls. A critical batch job failed due to a dependency on a previous job that had not completed. The system did not alert operations staff. Which control weakness is most significant?
Hard724Refer to the exhibit. An IS auditor is reviewing backup error logs. The error indicates a failed backup due to a missing file. What is the MOST likely cause?
Easy725During a review of the incident management process, the IS auditor finds that the incident response (IR) team conducts tabletop exercises annually, but the scenarios are limited to malware outbreaks. Which of the following should be the auditor's GREATEST concern?
Hard726An organization is replacing its legacy customer relationship management (CRM) system. Which of the following is the MOST important control to ensure data integrity during the data conversion process?
Easy727An IS auditor is evaluating the IT governance structure of a multinational corporation. The auditor finds that IT decisions are made independently by regional business units, with no central oversight. The corporate IT strategy exists but is not enforced. Which of the following is the MOST likely consequence of this governance approach?
Hard728An IS auditor is reviewing the problem management process. The auditor finds that problem tickets are only created after a major incident, and there is no proactive analysis of incident trends to identify underlying problems. Which of the following is the MOST likely consequence of this approach?
Medium729Which of the following is a principle of ISO/IEC 38500 for corporate governance of IT?
Easy730An IS auditor is reviewing a project to implement a new customer relationship management (CRM) system. The project manager has created a work breakdown structure (WBS) and a Gantt chart. Which of the following should the auditor verify to ensure the project schedule is realistic?
Medium731An IS auditor is performing a walkthrough of the accounts payable process. Which audit procedure is the auditor primarily executing?
Medium732During data conversion from a legacy system to a new ERP, the project team decides to clean data during extraction but not during loading. What is the PRIMARY risk associated with this approach?
Hard733An organization is implementing an ERP system and is concerned about segregation of duties conflicts. What is the most effective control to address this risk during implementation?
Medium734An IS auditor is evaluating a system development project that uses an outsourced team. The contract allows the vendor to reuse some of the developed code in other projects. What is the auditor's PRIMARY concern?
Hard735When implementing a commercial off-the-shelf (COTS) system, what is the MOST important factor?
Easy736An IS auditor is evaluating the design of controls over a critical financial application. The auditor performs a walkthrough and identifies that a control is missing but management has compensating controls. Which of the following is the auditor's BEST next step?
Hard737A retail organization's board has approved an IT governance framework that delegates decision rights for infrastructure standards to a central architecture board, while reserving funding decisions above a threshold for the board's technology committee. Business units must comply with the standards but may request exceptions. Which of the following is the MOST important control for the IS auditor to verify when assessing the effectiveness of this framework?
Hard738Which TWO of the following are benefits of using a version control system in software development?
Easy739An IS auditor reviewing the backup strategy for a financial application finds that full backups run every Sunday, with daily incremental backups Monday through Saturday. The recovery point objective (RPO) for the application is 4 hours. Which of the following is the MOST significant finding?
Medium740A company outsources its data center operations. Which IT governance practice is MOST critical to ensure the outsourcing arrangement meets business requirements?
Hard741An IT department uses a balanced scorecard to measure performance. Which metric would BEST reflect the 'customer perspective'?
Easy742Which of the following is a key objective of a post-implementation review?
Easy743Which THREE of the following are typical phases in the system development life cycle (SDLC)?
Easy744A multinational corporation's data center in the European Union (EU) stores personal data of EU citizens. The company must comply with the General Data Protection Regulation (GDPR), which requires that personal data be protected and that data subjects have the right to erasure ('right to be forgotten'). The company's IT team uses a centralized identity management system that stores user credentials and personal data in an active directory (AD) forest. The AD forest is replicated across multiple data centers worldwide, including a non-EU country. The data protection officer (DPO) is concerned that personal data might be inadvertently replicated to jurisdictions without adequate protection. Which of the following is the most effective way to address this concern?
Hard745An IS auditor is reviewing the end-of-life (EOL) software policy. Which THREE risks are associated with running unsupported software? (Select THREE).
Hard746During the design phase of an SDLC, which TWO activities should be performed to ensure security is integrated into the system? (Select TWO)
Easy747An IT manager is reviewing the service level agreements (SLAs) for a cloud-based email service. The SLA guarantees 99.9% uptime per month. The service experienced an outage of 45 minutes in a 30-day month. Did the service meet the SLA?
Medium748You are the IT audit manager for a multinational corporation. The company recently implemented a new enterprise resource planning (ERP) system using a phased rollout approach. The first phase (finance module) was deployed to three regional offices six months ago. During a post-implementation review, you discovered that the user acceptance testing (UAT) for the finance module was completed in only two days instead of the planned two weeks. The UAT was performed by a small group of power users selected by the project manager, and they reported no critical issues. However, after go-live, several finance staff in one region found that the system does not support a statutory reporting requirement specific to that country, which was not tested. The project manager argues that the requirement was never documented in the business requirements specification. The system has been live for six months, and the missing functionality requires a significant customization that will take three months and cost $200,000. Management is reluctant to fund the customization because the budget is exhausted. As the IT auditor, what is the BEST course of action?
Hard749An IS auditor is assessing the audit risk for an engagement covering a core banking application. The auditor determines that inherent risk is high because the application processes high-value transactions in real time. The auditor also concludes that control risk is low because strong automated controls and segregation of duties are in place and have been tested. Which of the following BEST describes the appropriate response to this assessment?
Hard750An IS auditor is testing the effectiveness of a preventive control that rejects invalid transactions. The auditor uses a computer-assisted audit technique (CAAT) to create a set of test transactions. What is the primary risk associated with this approach?
Hard751During the feasibility study for a new inventory system, the project team identifies that the expected benefits are significantly lower than the initial estimates. What is the MOST appropriate action for the IS auditor to recommend?
Easy752An IS auditor is planning an audit of a small organization with limited IT staff. Which approach is most appropriate?
Medium753An IT audit revealed that the organization's IT steering committee has not met in the past six months. Which of the following is the MOST likely consequence of this situation?
Medium754An IS auditor is examining the job scheduling controls for an organization's nightly batch processing on a mainframe. The auditor finds that operators can modify job schedules, add ad hoc jobs, and override job dependencies without supervisory approval or logging. Which of the following is the MOST appropriate recommendation?
Easy755Which THREE of the following are components of the ITIL 4 service value system? (Select THREE)
Hard756A mid-sized insurance company has decided to adopt a formal IT governance framework because its board is concerned about unmanaged IT risk. The CIO asks the IS auditor to recommend the FIRST step in establishing the governance framework. Which of the following should the IS auditor recommend?
Medium757Which TWO of the following are benefits of establishing an IT steering committee?
Easy758An organization's availability management team reports that a critical server has an MTBF of 720 hours and an MTTR of 4 hours. What is the availability percentage for this server?
Medium759During which phase of the IS audit process does the auditor perform walkthroughs and test controls?
Easy760An IS auditor is evaluating a cloud service provider's (CSP) security posture before the organization migrates a customer-facing application to the provider's infrastructure as a service (IaaS) environment. The auditor is reviewing the shared responsibility model and the provider's assurance documentation. Which TWO of the following are the auditor's MOST important considerations? (Choose two.)
Hard761Which TWO of the following are primary objectives of the audit planning phase? (Select TWO.)
Easy762Which of the following is the PRIMARY objective of an operational audit?
Easy763An organization uses automated job scheduling with dependency management. A critical nightly batch job failed because a prerequisite job did not complete successfully. The job scheduler automatically attempted to rerun the failed job three times, each time failing due to the same dependency. The operations team was not alerted until the next morning. What control should the auditor recommend to improve this process?
Medium764A system has a Mean Time Between Failures (MTBF) of 500 hours and a Mean Time To Repair (MTTR) of 20 hours. What is the availability of the system?
Hard765An IS auditor is reviewing the IT operations of a small organization. The auditor notes that the operations team performs daily server health checks, but there is no formal capacity management process. The organization recently experienced a slowdown during month-end processing. Which of the following is the MOST likely cause of the slowdown that the auditor should investigate?
Easy766An organization is planning to outsource its data center operations. Which of the following governance practices should be implemented to ensure proper oversight?
Medium767A hospital's data centre uses a generator and an uninterruptible power supply (UPS) to protect clinical systems. During a walkthrough, the IS auditor observes that the UPS batteries have never been load-tested and the generator is exercised monthly without transferring the load. Which conclusion is MOST appropriate?
Easy768During an operational audit, the auditor uses ratio analysis to compare current year expenses to prior years and industry benchmarks. This is an example of which type of audit evidence?
Medium769Which TWO of the following are key elements of an effective incident response plan? (Select exactly 2.)
Medium770An IS auditor is reviewing the organization's IT governance framework. The board has delegated oversight of IT to an IT steering committee. The auditor finds that the committee meets quarterly, but its charter does not define decision rights or escalation procedures. Which of the following is the MOST significant concern?
Medium771Which of the following is the BEST method to ensure that a system development project is completed on time?
Medium772An organization is implementing an enterprise resource planning (ERP) system. The project team plans to migrate legacy data without performing a full reconciliation between source and target systems. As an IS auditor, which of the following should be your PRIMARY concern?
Hard773An organization is performing software asset management (SAM) to ensure license compliance. Which two activities should the auditor verify?
Medium774An IS auditor is assessing an organization's IT governance implementation. The auditor finds that IT policies are outdated, roles and responsibilities are unclear, and there is no regular reporting on IT performance to the board. Which TWO of the following are the MOST critical actions to improve IT governance? (Choose two.)
Hard775Which THREE of the following are common risks associated with outsourcing software development?
Hard776During a review of encryption practices, the IS auditor finds that an organization uses the same encryption key for all customer data at rest. What is the PRIMARY concern?
Medium777An organization uses a hot site as its disaster recovery alternative. Which of the following is the MOST critical consideration when selecting a hot site?
Medium778In the context of IT governance, what is the PRIMARY purpose of an exception management process for IT policies?
Hard779Which THREE of the following are commonly recognized benefits of implementing a formal IT service management (ITSM) framework such as ITIL?
Hard780An IS auditor is performing a risk assessment to prioritize audit engagements for the annual audit plan. Which TWO of the following factors should the auditor consider when evaluating inherent risk? (Choose two.)
Medium781During an audit of an organization's information security programme, the IS auditor finds that the security awareness training completion rate is 95% but phishing simulation tests show a 30% failure rate. What should the auditor recommend?
Medium782An IT manager is developing a governance policy for change management. Which element is MOST important to include?
Easy783An organization uses a chargeback model for IT services. What is the PRIMARY benefit of this approach?
Easy784Which TWO of the following are key components of an effective information security awareness program?
Easy785An organization has just completed a post-implementation review of a new payroll system. Management is now deciding whether to formally transfer ownership of the system from the project team to IT operations. Which of the following is the MOST important prerequisite before this transfer is approved?
Medium786In a risk-based audit approach, which of the following BEST describes how an IS auditor should prioritize audit coverage?
Hard787During an audit of a data center, the IS auditor observes that visitors are escorted at all times but the visitor log is not reconciled to the badge access system. Which of the following BEST describes the audit concern?
Easy788An IS auditor is reviewing the testing phase of a new system development project. The project team has decided to use beta testing as the primary method for user acceptance testing (UAT). Which of the following is the MOST appropriate audit concern regarding this decision?
Hard789In a DevOps environment, which practice BEST supports auditability?
Hard790An IS auditor is planning an audit of a small organization with limited IT staff. Which of the following is a key consideration for the audit approach?
Hard791Which of the following is a key difference between an internal audit and an external audit?
Medium792An IS auditor is reviewing the availability management process. The auditor calculates that the mean time between failures (MTBF) is 200 hours and the mean time to repair (MTTR) is 20 hours. What is the availability percentage?
Medium793Which THREE of the following are components of a typical IT governance framework?
Hard794An IS auditor is reviewing the capacity management process for a virtualized server environment. The auditor finds that CPU and memory utilization reports are generated monthly, but no formal forecasting is performed, and no thresholds are defined for triggering capacity upgrades. Which of the following is the MOST significant risk arising from this situation?
Medium795An IT auditor is reviewing the release management process. Which of the following is the MOST important control to ensure that new releases do not negatively impact production systems?
Medium796Which TWO of the following are types of audit evidence recognized in IS audit practice?
Easy797An IS auditor is reviewing the disaster recovery plan (DRP) for an e-commerce company that generates 90% of its revenue online. The DRP states that the recovery time objective (RTO) for the transactional database is 4 hours, and the recovery point objective (RPO) is 1 hour. The current backup strategy includes nightly full backups and hourly transaction log backups stored on a local disk array. The backups are then copied to a remote datacenter via a WAN link with an average transfer speed of 10 Mbps. The database size is 500 GB. The auditor calculates that the time to transfer the full backup over the WAN is approximately 12 hours. The organization's management is confident that the DRP is adequate because they have never had to invoke it. What is the auditor's MOST critical finding?
Hard798An IS auditor is reviewing a contract with a vendor for a new financial system. Which of the following clauses is MOST critical to ensure auditability?
Hard799During an audit, an IS auditor finds that the organization uses a cloud-based identity provider (IdP) for single sign-on (SSO) but does not enforce multi-factor authentication (MFA) for all users. Which of the following is the BEST recommendation to reduce risk?
Hard800Which THREE of the following are characteristics of SMART recommendations in an audit report? (Select three.)
Hard801An IS auditor is reviewing the vendor management program for a critical outsourced service. The vendor has recently been acquired by another company. Which TWO factors should the auditor be most concerned about regarding the acquisition?
Medium802During system implementation, a critical defect is found in the production environment. The project manager wants to apply an emergency patch without full testing. Which of the following is the BEST course of action?
Hard803Which type of audit is primarily concerned with evaluating the efficiency and effectiveness of operations?
Easy804A company is designing a public cloud-based application that processes highly sensitive personal data. Which of the following data protection strategies provides the STRONGEST assurance that data remains confidential even if the cloud provider's infrastructure is compromised?
Hard805An organization uses RAID 5 for its database server. Which of the following is the PRIMARY advantage of RAID 5?
Medium806An IS auditor is assessing an organization's IT governance. The auditor finds that the IT balanced scorecard is used to measure IT performance, but the metrics are heavily focused on internal IT processes and do not include business or customer perspectives. Which of the following is the MOST likely consequence of this imbalance?
Medium807An IS auditor is reviewing an organization's change management process. The auditor notes that all emergency changes are approved post-implementation by the change advisory board (CAB) within 48 hours. Which of the following is the auditor's BEST course of action?
Hard808Which of the following is the MOST important objective of system testing?
Easy809A financial institution is implementing a data classification policy. Which of the following is the most important factor in determining the classification level of a data asset?
Easy810In the audit follow-up phase, which TWO actions are essential? (Select two.)
Medium811During an audit of a bank's online transaction processing system, the IS auditor discovers that batch totals are reconciled only at the end of each business day, while individual transactions are posted to customer accounts in real time. Which of the following is the GREATEST risk arising from this control design?
Hard812An organization is implementing a new CRM system using an iterative development methodology. The IS auditor wants to verify that appropriate controls are in place. Which THREE of the following are essential controls for iterative development? (Select THREE.)
Hard813An IS auditor is reviewing the audit charter of an organization's internal audit function. Which of the following should the auditor expect to find as the PRIMARY purpose of the audit charter?
Easy814An IS auditor is reviewing the logical access controls of a system. Which of the following is the BEST evidence that access rights are appropriately assigned?
Easy815A company outsources its IT help desk to a third-party vendor. The service level agreement (SLA) specifies that all P1 incidents must be resolved within 2 hours. During an audit, the auditor finds that the vendor’s average resolution time for P1 incidents is 3 hours. What is the most appropriate recommendation?
Medium816An IS auditor is reviewing an organization's IT governance policies and finds that the IT strategy is updated annually, but there is no process to monitor external factors such as regulatory changes or emerging technologies. Which of the following is the MOST significant risk of this deficiency?
Medium817An IS auditor is reviewing the backup strategy for a critical database server. The database administrator states that a full backup is performed every Sunday, and transaction log backups are performed every hour. The auditor finds that the transaction log backups are stored on the same volume as the database data files. Which of the following is the MOST significant risk associated with this configuration?
Medium818An IS auditor is reviewing a software development project that uses a DevOps pipeline. The auditor observes that developers can push code directly to production without independent review. Which of the following is the MOST significant risk arising from this practice?
Hard819An IS auditor is evaluating the reliability of evidence obtained from a system-generated exception report. The report is produced by a script written by a database administrator who has both the ability to modify the script and the production data. The auditor has obtained the report directly from the system. Which of the following is the MOST important factor affecting the auditor's reliance on this evidence?
Hard820An IS auditor is reviewing physical security controls at a data center. The data center hosts critical servers and uses a badge access system with PINs, CCTV cameras, and a mantrap entry. The auditor observes that employees sometimes hold the door open for others without badging. Which TWO of the following are the MOST effective controls to address this tailgating risk?
Easy821During an IT audit, the auditor finds that a system administrator has local administrator rights on multiple production servers and uses a shared service account for routine maintenance. What is the PRIMARY risk associated with this practice?
Easy822During a change management process review, an IS auditor finds that the change advisory board (CAB) approved a change that subsequently caused a major service outage. The change was classified as 'normal' with no emergency. What is the auditor's primary concern?
Medium823An organization is implementing a new IT service management system based on ITIL 4. Which TWO of the following are guiding principles of ITIL 4?
Medium824An organization's IT strategy must be aligned with business strategy. Which of the following is the PRIMARY benefit of this alignment?
Easy825During an audit of IT asset management, the IS auditor finds that several servers are running an operating system that has reached end-of-life (EOL). The organization has not deployed any compensating controls. Which of the following is the GREATEST risk?
Hard826Which of the following audit types is most likely to be conducted by an employee of the organization being audited, potentially raising independence concerns?
Easy827Which TWO of the following are examples of administrative controls for information security? (Choose two.)
Easy828During an audit, the IS auditor identifies that the audit team lacks the technical expertise to evaluate a specific system. According to ISACA standards, the auditor should:
Easy829An IS auditor is assessing an organization's capacity management process for a virtualized server environment. Management wants to confirm that the process will provide early warning before performance degrades. Which TWO practices are MOST important for the auditor to verify are in place? (Choose two.)
Medium830An organization is planning to purchase a cloud-based HR system. Which THREE of the following should be included in the vendor contract to ensure adequate control and oversight? (Select three.)
Hard831An IS auditor is assessing the capacity management process for a rapidly growing e-commerce platform. The auditor finds that capacity planning is based solely on historical CPU and memory utilization, with no forecasting of business growth or seasonal peak demand. During the most recent holiday season, the platform experienced severe performance degradation and a two-hour outage. Which of the following should the auditor identify as the PRIMARY weakness in the capacity management process?
Hard832What is the PRIMARY purpose of conducting a static application security testing (SAST) during the development phase?
Easy833An organization is implementing a new ERP system. The project sponsor requests a change that will significantly increase project scope without additional budget. Which of the following is the BEST action for the project manager?
Hard834An IT auditor is reviewing backup procedures. The organization performs daily full backups and retains them for 30 days. Additionally, weekly backups are retained for 12 months. Which of the following is the MOST likely risk associated with this backup strategy?
Medium835An IS auditor has completed fieldwork for an audit of a data center's physical access controls and has documented several findings. Before drafting the final report, the auditor discusses the findings with the data center manager. Which of the following is the PRIMARY purpose of this discussion?
Easy836An organization wants to implement an exception management process for IT policies. Which of the following is the most important step to ensure effective control?
Hard837An IS auditor is reviewing an agile software development project. Which of the following practices would BEST help ensure that security controls are adequately addressed?
Medium838Which of the following is a requirement for effective segregation of duties in IT?
Easy839An IS auditor is reviewing a project that uses an iterative SDLC approach. Which THREE controls should the auditor expect to see in place during the development iterations? (Select THREE)
Hard840An IS auditor is evaluating a data loss prevention (DLP) deployment intended to stop sensitive customer records from leaving a bank's network. Management wants assurance that the solution is operating effectively. Which TWO of the following are the MOST important factors for the auditor to assess? (Choose two.)
Medium841An IS auditor is examining how an organization classifies and handles its information assets. The auditor finds that the data classification policy defines four sensitivity levels and corresponding handling rules, but the asset inventory does not record a classification for most systems. Which of the following is the MOST likely consequence of this gap?
Easy842An organization's data classification policy defines 'Confidential' data as requiring encryption at rest. An IS auditor discovers that a database containing customer personal information is not encrypted. What is the auditor's BEST course of action?
Hard843An IS auditor is planning an audit of a newly implemented ERP system. The auditor wants to ensure that the audit covers critical controls. Which of the following is the most appropriate first step in the audit planning process?
Easy844Which THREE of the following are essential components of a change management process?
Easy845An IS auditor is conducting a follow-up review of a previously identified high-risk finding. Management has implemented a compensating control instead of the recommended control. Which of the following is the MOST appropriate action for the auditor to take?
Medium846An organization is adopting a DevOps approach for system development. Which THREE controls should an IS auditor expect to see in place to maintain security and compliance?
Hard847An organization uses a COTS (commercial off-the-shelf) ERP system with significant customizations. The IS auditor is reviewing the system's configuration management. Which of the following findings would MOST indicate a weakness?
Hard848An IS auditor is performing a review of an organization's IT governance framework. Which of the following findings would be of MOST concern?
Hard849An organization's IT department is structured with a central unit that provides infrastructure and support, while individual business units have their own application development teams. This structure is BEST described as:
Medium850An IS auditor is reviewing the IT operations of a small organization that runs a critical application on a single physical server. The auditor finds that backups are performed daily to a local tape drive, but the tapes are stored in the same room as the server. Which of the following is the MOST significant risk?
Easy851An IT auditor is reviewing the system development life cycle (SDLC) process for a critical application. Which of the following findings would be of MOST concern?
Medium852An IS auditor is reviewing the privileged access management (PAM) process. The auditor finds that shared administrative accounts are used for critical system maintenance and that passwords are changed quarterly. Which of the following is the BEST recommendation to mitigate the risk of audit trail loss?
Hard853A company's backup policy requires that backup tapes be stored offsite for at least one year. During an audit, the auditor finds that the offsite storage facility is not access-controlled and backup tapes are not encrypted. Which of the following is the auditor's BEST recommendation?
Medium854A company is deciding whether to centralize or decentralize its IT function. Which of the following is an advantage of a centralized IT structure?
Medium855During an IT audit, the auditor discovers that the IT strategy is not formally documented. Which of the following is the MOST significant risk associated with this finding?
Easy856During a disaster recovery planning audit, the IS auditor notes that the organization's plan includes a hot standby site. However, the plan has not been updated in two years, and the last test was a tabletop exercise 18 months ago. The organization has recently implemented a new ERP system. Which THREE findings should the auditor report as most significant?
Hard857An organization's backup strategy includes daily incremental backups and weekly full backups. During a disaster recovery test, the restoration of a critical server fails because a required incremental backup is corrupt. Which control should the organization implement to verify the integrity of backups?
Hard858An IS auditor is evaluating an organization's job scheduling practices for a critical batch process that updates the general ledger. The process runs nightly and must complete before the start of the business day. The auditor finds that the job scheduler uses a single service account with domain administrator privileges to run all jobs, and there are no alerts for job failures. Which of the following is the MOST significant risk arising from this configuration?
Hard859During a change management audit, which TWO of the following are essential elements of a normal change request? (Select two.)
Medium860A company's security policy requires that all laptops have full-disk encryption. During an audit, 10% of laptops are found without encryption. Which of the following is the MOST effective corrective action?
Medium861An organization is implementing a new CRM system using an agile methodology. The IS auditor wants to assess whether security requirements are being addressed. What is the best evidence for the auditor to review?
Medium862A company uses role-based access control (RBAC). An employee moves from one department to another but retains some previous access due to overlapping role permissions. This condition is known as:
Hard863An IS auditor is reviewing the tape backup process for a mid-sized organization. Backups run nightly and complete successfully, and tapes are stored in a fireproof safe in the same data center as the servers. Which of the following is the MOST significant finding?
Easy864An IS auditor is evaluating the security of an organization's wireless network. The organization uses WPA3-Enterprise with 802.1X authentication against a RADIUS server. The auditor discovers that the RADIUS server is configured to accept EAP-MD5 as an authentication method for legacy devices. Which of the following is the MOST significant security concern with this configuration?
Hard865An IS auditor is reviewing the IT operations team's use of system-generated alerts. The auditor finds that alerts are configured to notify the operations team via email, but there is no escalation path if an alert is not acknowledged within a specified time. Which of the following is the MOST significant risk?
Easy866During a nightly batch job, the above error appears in the application logs. The transaction table ACCT_TRANS has a unique constraint on the REF_NUM column. Which of the following is the MOST likely root cause?
Hard867An IS auditor is executing a compliance test of change management controls over a core banking application. The audit programme requires evidence that all production changes were approved before implementation. Which of the following techniques provides the MOST persuasive evidence for this test?
Medium868An IS auditor is reviewing the data backup strategy for a hospital's electronic health record (EHR) system. The auditor finds that full backups are performed weekly, with daily incremental backups, but the backup tapes are stored in the same server room as the production system. Which of the following is the MOST significant finding?
Medium869An organization is using a spiral model for a high-risk project. The IS auditor wants to ensure that risk assessment is performed at each iteration. Which of the following is the BEST evidence that this control is effective?
Hard870During a security assessment, an auditor discovers that employees are sharing passwords to access a critical system. Which of the following controls would BEST mitigate this risk?
Easy871An IS auditor is planning an audit of a financial system. The auditor identifies that the inherent risk is high due to the complexity of transactions, but control risk is low because of strong automated controls. Which component of audit risk will be MOST affected by the auditor's testing strategy?
Medium872A small manufacturing company decides to acquire an off-the-shelf inventory management system. The purchasing manager selects a vendor based solely on the lowest price, ignoring the vendor's financial stability and support history. After purchase, the vendor declares bankruptcy, leaving the company without support. The system has a critical bug that halts inventory tracking. The IT manager considers hiring a consultant to fix the bug. As an IS auditor, what should the auditor's PRIMARY concern be?
Easy873An organization has a policy that requires all IT projects to have a business case approved by the IT steering committee. The IS auditor discovers that a major infrastructure upgrade was initiated without an approved business case. Which of the following is the auditor's PRIMARY concern?
Medium874Which TWO of the following are key responsibilities of an IT steering committee?
Medium875Which THREE are commonly used techniques to protect sensitive data in a cloud environment? (Select exactly 3.)
Medium876An IS auditor is reviewing problem management for a payment processor. Recurring incidents share the same root cause, but the problem record has remained open for eight months with no root cause identified because the vendor will not release diagnostic data. Change requests to apply a workaround have been raised and closed repeatedly. Which action should the IS auditor recommend FIRST?
Hard877An organization is establishing an IT governance committee. The committee's charter includes overseeing IT investments, monitoring IT performance, and ensuring compliance with regulations. Which of the following should the IS auditor recommend as the MOST important characteristic of the committee's membership?
Easy878An IS auditor is assessing whether an organization's IT steering committee is fulfilling its governance responsibilities. The committee charter states that it oversees IT investment prioritization, monitors IT performance against agreed objectives, and resolves escalated resource conflicts. Which TWO of the following observations would the auditor MOST likely identify as deficiencies in the committee's operation? (Choose two.)
Hard879An organization outsources its data center operations to a third-party vendor. The contract includes a right-to-audit clause. During a scheduled audit, the vendor refuses to provide access to logs from a subcontractor managing network security. What is the IS auditor's best course of action?
Medium880After issuing the final audit report, the IS auditor should perform follow-up procedures. What is the PRIMARY purpose of follow-up?
Medium881An organization is evaluating its business continuity plan (BCP) to ensure alignment with the IT disaster recovery plan. Which TWO of the following are critical elements that should be included in the BCP to support effective business resilience?
Hard882Which THREE of the following are indicators of mature IT governance?
Hard883An organization is implementing an agile methodology for a new software project. Which of the following is the MOST effective control to ensure that security requirements are addressed?
Hard884An IS auditor is reviewing the termination procedure for IT employees. Which of the following is the most critical control to ensure immediate effectiveness?
Hard885An organization implemented a business continuity plan (BCP) that includes manual workarounds. Which of the following is the PRIMARY risk of relying on manual processes during a disruption?
Medium886Which THREE of the following are key elements that should be included in a risk assessment report for information systems?
Hard887During a recent audit, the IT auditor found that the problem management process does not include a known error database (KEDB). Which of the following is the MOST significant risk associated with this finding?
Medium888An IS auditor is assessing the sufficiency of audit evidence gathered for a conclusion about database access controls. Which TWO of the following characteristics must the evidence possess to be considered appropriate? (Choose two.)
Medium889An organization is evaluating its business continuity plan (BCP) for a critical application with a recovery time objective (RTO) of 4 hours and a recovery point objective (RPO) of 1 hour. The current backup strategy involves daily full backups and hourly transaction log backups. Which of the following is the MOST significant risk?
Hard890An organization is implementing a new CRM system and has chosen a build (in-house development) approach over buying a COTS product. Which of the following is the most significant risk of this decision?
Medium891An IS auditor is evaluating the effectiveness of an organization's information security awareness program. Which of the following is the BEST indicator of program effectiveness?
Hard892In the context of ITIL change management, which change type requires approval from the Change Advisory Board (CAB)?
Medium893Which THREE of the following are key considerations when selecting a software development methodology for a project?
Hard894Which TWO are primary criteria for classifying information assets within an organization? (Choose two.)
Easy895An IT department is struggling with project delays and budget overruns. Which governance practice would be MOST effective?
Medium896Which TWO of the following are typical controls in the testing phase of the SDLC? (Select two.)
Medium897Which THREE of the following are key metrics to include in a disaster recovery test report? (Select exactly 3.)
Hard898An organization is selecting a vendor for a new enterprise resource planning (ERP) system. Which of the following is the MOST critical factor in the vendor selection process?
Easy899An IS auditor is reviewing the physical security of a data center that houses production servers. During a walkthrough, the auditor observes that the main entrance uses a badge reader, but the door to the network operations center (NOC) is propped open with a chair. Which of the following is the MOST appropriate action for the auditor to take?
Easy900Match each security control to its category.
Medium901A financial services company is developing a new customer-facing web application for account management. The project is using a waterfall methodology. The initial requirements were gathered six months ago, and the coding phase is nearly complete. The business sponsor now requests a new feature that allows customers to view transaction receipts online. The project manager is concerned that this change will delay the project by two months and exceed the budget. The sponsor insists that the feature is critical for customer satisfaction and that the project must adapt. The development team estimates it will take 200 hours to implement. The steering committee is divided. As an IS auditor, what would be the BEST recommendation to resolve this?
Hard902An IS auditor is reviewing the release management process for a critical application. The release strategy includes a phased rollout to 10% of users initially, then 50%, then 100%. The first phase revealed a data integrity issue that affected a subset of transactions. The release manager decided to continue with the next phase while a patch was being developed. What should the auditor most recommend?
Hard903An IS auditor is reviewing a post-implementation review (PIR) of a new CRM system. The auditor finds that the project was completed on time and within budget, but the business case benefits have not been realized. Which of the following is the MOST likely cause?
Medium904An IS auditor is evaluating an organization's SDLC controls for a new system. Which TWO of the following are key controls that should be in place during the design phase? (Select TWO.)
Medium905Arrange the steps to perform a risk assessment in the correct order.
Medium906An organization is selecting a vendor for a new procurement system. Which of the following is the MOST important factor to include in the contract?
Medium907During an audit of the information security program, the IS auditor reviews the organization's information security policy. Which of the following is the PRIMARY purpose of an information security policy?
Easy908Which of the following is the MOST effective control to prevent unauthorized USB devices from connecting to corporate workstations?
Medium909An IS auditor is reviewing a business continuity plan (BCP). Which TWO of the following are key components of the business continuity strategy? (Select two.)
Medium910Which THREE of the following are acceptable methods for gathering audit evidence? (Select THREE.)
Medium911An IS auditor is assessing the effectiveness of an organization's IT governance framework. Which TWO of the following are essential components that the auditor should verify are in place? (Choose two.)
Medium912An IS auditor is using analytical procedures during the planning phase. Which of the following is an example of an analytical procedure?
Medium913An IS auditor is assessing an organization's IT governance framework and finds that the IT balanced scorecard includes metrics such as system uptime, number of help desk tickets resolved, and average response time. The auditor notes that these are all internal IT operational metrics. The MOST significant concern is that:
Hard914An IS auditor is assessing physical security at a data center that houses the organization's core transaction processing systems. The auditor observes that the main entrance uses a badge reader, but the door to the server hall is propped open with a box while staff move equipment. Which of the following is the auditor's GREATEST concern?
Easy915An IS auditor is reviewing the logical access controls of a financial application. Which of the following is the BEST way to verify that user access rights are appropriate?
Medium916An organization is developing its IT strategy to align with the overall business strategy. The business strategy emphasizes rapid market expansion through digital products. Which of the following IT strategies would BEST support this business goal?
Easy917An IS auditor is preparing the audit report. According to ISACA standards, which of the following should be included in the final audit report?
Easy918A company is considering restructuring its IT department from a centralized to a decentralized model to give business units more autonomy. What is a PRIMARY governance risk associated with this move?
Medium919An organization has experienced several security incidents due to unauthorized changes to production systems. Which governance mechanism should be strengthened?
Medium920An IT steering committee is reviewing a proposal for a new customer relationship management (CRM) system. Which of the following BEST demonstrates that the proposal aligns with the organization's strategic goals?
Easy921An IS auditor is evaluating the network segmentation of a manufacturing company that separates its corporate network from the industrial control system (ICS) environment. The auditor finds that a firewall exists between the zones, but engineering workstations on the corporate network can reach programmable logic controllers directly over several open ports. Which TWO of the following findings should the auditor report as the MOST significant weaknesses? (Choose two.)
Medium922An IT auditor is reviewing the business continuity plan (BCP) for a financial services firm. The plan includes a hot site that is shared with another organization under a reciprocal agreement. Which of the following findings should be of MOST concern to the auditor?
Hard923An organization is implementing a COTS application. The project team plans to heavily customize the application to meet unique business processes. Which of the following is the most significant risk?
Hard924An IS auditor is evaluating the patch management process. The auditor notes that critical security patches are applied within 30 days, but the policy requires 7 days. The IT manager states that the delay is due to testing requirements. What should the auditor recommend?
Hard925Which TWO of the following are considered essential components of an information security policy framework? (Choose two.)
Medium926An organization is adopting a decentralized IT structure to better meet the needs of its business units. Which of the following is a potential risk of this approach?
Medium927An IT auditor is reviewing the change management process for a financial institution. The auditor finds that emergency changes are frequently approved by the change manager without CAB review. Which risk is most associated with this practice?
Medium928A company plans to implement a commercial off-the-shelf (COTS) application and requires significant customization to match its unique business processes. The vendor advises against extensive customization because it may complicate future upgrades. What is the BEST course of action?
Hard929A financial institution is deploying a data loss prevention (DLP) solution. Which of the following is the MOST important prerequisite to ensure the DLP can effectively detect sensitive data?
Easy930An IT auditor is evaluating the capacity management process. Which of the following findings would be of MOST concern?
Hard931An organization is implementing a change management process based on ITIL. Which THREE change types should be included in the policy?
Hard932A company's availability monitoring shows that a critical application has an average MTBF of 720 hours and an average MTTR of 4 hours. What is the availability percentage?
Hard933Which TWO of the following are key benefits of using a system development life cycle (SDLC) methodology? (Select exactly two.)
Medium934An IS auditor is reviewing the deployment pipeline for an organization's e-commerce platform. The pipeline automatically deploys every code commit that passes automated unit tests to production without manual approval. The organization argues this accelerates feature delivery. Which of the following is the auditor's GREATEST concern with this approach?
MediumOther domains
All CISA exam domains
Frequently asked questions
- What does the scenario questions domain cover on the CISA exam?
- scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 934 scenario questions questions in the CISA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only scenario questions questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.