CISA · domain
scenario questions
Practise Certified Information Systems Auditor CISA scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice scenario questions questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about scenario questions
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common scenario questions exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All scenario questions questions (995)
Click any question to see the full explanation, or start a practice session above.
During a build vs. buy analysis, the IS auditor observes that the organization decided to build a custom application because no vendor solution met all requirements. Which of the following risks should the auditor emphasize?
Medium2An organization is implementing a privacy program to comply with GDPR. Which THREE of the following are essential elements for managing cross-border data transfers?
Hard3A multinational company must comply with GDPR and local data protection laws when transferring personal data from the EU to a subsidiary in the US. Which transfer mechanism is most commonly accepted as providing adequate protection?
Hard4An online retail company runs its e-commerce platform on a virtualized infrastructure with 50 virtual servers. The platform experiences intermittent slowdowns during peak hours, and recent monitoring reports show that disk I/O latency on the storage area network (SAN) frequently exceeds 50 ms during these periods. The SAN has two fabric switches and a single storage array with 12 TB of usable capacity, currently at 80% utilization. The company’s disaster recovery plan requires recovery point objective (RPO) of 1 hour and recovery time objective (RTO) of 4 hours for the e-commerce platform. During a recent test failover to the disaster recovery site, the IT team discovered that the replication link between primary and DR sites is saturated, causing replication lag of up to 3 hours. The team also noted that the DR site storage has only 6 TB of usable capacity, now at 60% utilization. The IT manager is concerned about meeting the RPO and RTO. Which course of action should the IT team take first?
Hard5A company is using an agile development methodology for a critical business application. The IS auditor is concerned about the lack of formal documentation. What is the BEST approach to mitigate this risk?
Medium6A large organization is implementing a new HR management system to handle payroll and employee data. The project is currently in the build phase with a planned go-live in three months. Recently, the vendor notified the project team that a critical security patch will be released in two months that addresses a data leakage vulnerability present in the current version. The patch includes new features that are not in the contract. The project manager estimates that integrating the patch and re-testing will delay the project by at least four months. Business stakeholders insist on meeting the original go-live date because the legacy system is being decommissioned. The organization has a strict policy that all systems processing sensitive data must have the latest security patches within 30 days of release. What should the project team do?
Medium7An IS auditor is reviewing the audit follow-up process. The auditor notes that management has implemented corrective actions for 80% of previous audit findings. What should the auditor conclude?
Medium8A company is developing a mobile banking application. Which test phase is MOST critical to ensure that the application functions correctly from the end user's perspective?
Easy9An organization uses automated job scheduling for nightly batch processing. One job fails due to a missing dependency file. What is the most effective control to prevent recurrence?
Easy10An IS auditor is performing a walkthrough of a purchase-to-pay process. The auditor selects a sample of purchase orders and traces them through the system to verify that controls are properly designed and implemented. This is an example of:
Hard11During a review of firewall rule sets, an IS auditor finds a rule that allows any source IP to access any destination IP on TCP port 443. Which of the following should the auditor do FIRST?
Medium12Refer to the exhibit. A CISA is analyzing these logs. What is the MOST likely security incident?
Hard13An IS auditor finds that a control deficiency could lead to a material misstatement if combined with another deficiency. How should this be classified?
Hard14An IS auditor is evaluating the security of the architecture. Which of the following is the MOST critical finding?
Medium15An IT auditor is reviewing the policy hierarchy of an organization. Which of the following correctly describes the relationship between a policy and a procedure?
Hard16An organization is implementing a cloud resource management strategy to optimize costs and prevent waste. Which three practices should the auditor recommend?
Hard17Match each regulatory standard to its focus area.
Medium18An IS auditor is performing a compliance audit of data privacy regulations. The auditor finds that the organization's privacy policy is not fully aligned with regulatory requirements. Which of the following is the auditor's BEST course of action?
Hard19An IS auditor is conducting an audit of a small manufacturing company's IT operations. The company has 50 employees and uses a single server running Windows Server 2019 for file sharing and print services. There is no formal change management process. The IT manager, who also doubles as the system administrator, has full administrative rights and is the only person who can make changes to the server. During the audit, the auditor notices that the server's local security policy is configured to allow unlimited password attempts and no account lockout. The IT manager states that this is to avoid locking out users who forget their passwords. The auditor also finds that the guest account is enabled on the server. What should the auditor recommend as the HIGHEST priority action?
Easy20A financial institution operates a critical payment processing system that must maintain 99.999% availability. The system is deployed across two data centers in active-active mode with load balancing. During a routine maintenance window, a network misconfiguration caused all traffic to be directed to one data center, which then became overloaded and crashed, resulting in 30 minutes of downtime. The incident response team wants to prevent recurrence. Which of the following is the BEST action?
Medium21An organization uses a hot site for disaster recovery. During a recent test, the hot site did not have the latest version of the application software. What is the MOST likely cause?
Medium22Which is the MOST likely cause?
Easy23An organization's IT security policy requires that all employees complete annual security awareness training. An auditor notes that completion rate is only 60%. What is the MOST effective way to monitor compliance?
Medium24An IS auditor is reviewing the balanced scorecard for IT. Which of the following metrics BEST aligns with the 'customer perspective'?
Hard25What is the primary purpose of a chargeback model for IT services?
Medium26An IS auditor is planning an audit of an organization's IT infrastructure. Which of the following is the PRIMARY benefit of using a risk-based approach?
Easy27An IS auditor is reviewing the process for granting privileged access in a large organization. Which of the following findings should be of MOST concern?
Medium28During a business impact analysis (BIA), a department manager states that their process can be disrupted for up to 8 hours, but data loss cannot exceed 15 minutes. Which two metrics are defined by these statements?
Hard29An information systems auditor is evaluating user accounts in an organization's Linux environment. The accounts have the following properties: - The 'root' account has its password field set to '!!' (disabled). - The 'admin' account has its password field set to '!' (locked) and UID 0. - The 'test' account is a regular user with UID 1000. Based on this information, which user account poses the HIGHEST security risk?
Medium30An IS auditor reviews the log entry above. Which of the following is the MOST likely cause of the authentication failure?
Hard31An organization is implementing ITIL 4. Which TWO of the following are part of the four dimensions of service management? (Select TWO.)
Medium32Which TWO of the following are primary objectives of capacity management? (Select exactly 2.)
Medium33Which of the following is the PRIMARY purpose of conducting a penetration test?
Easy34An organization's business continuity plan (BCP) includes alternate facilities that can be operational within 24 hours. The maximum tolerable downtime (MTD) for a critical process is 12 hours. What is the most significant gap?
Medium35An organization uses a cloud-based CRM system. The asset management team has implemented tagging to track resource costs by department. During an audit, the IS auditor finds that several orphaned resources (e.g., virtual machines, storage volumes) exist that are not tagged and have been running for months. The cloud service provider's cost allocation report shows these resources under a default account. What is the most significant risk associated with this finding?
Hard36An organization has implemented a role-based access control (RBAC) system. A user complains that they cannot access a file needed to complete a critical task. The file's permission indicates that only the 'Manager' role has read access. The user is assigned to the 'Analyst' role. Which of the following is the BEST course of action?
Hard37A multinational manufacturing company with operations in 20 countries has historically allowed each regional division to manage its own IT systems independently. Recently, the company experienced a significant data breach originating from a region with weaker security controls, leading to financial losses and reputational damage. The board has mandated stronger IT governance to prevent future incidents. The CIO proposes implementing a global IT governance framework with centralized policy enforcement. However, regional directors argue that local regulations and business needs require autonomy. The governance committee must decide on a course of action that balances risk and business flexibility. Which of the following approaches is the MOST appropriate?
Hard38An IS auditor is reviewing a post-implementation review report for a new financial system. Which finding would most indicate that the project did not meet its objectives?
Medium39Which of the following is the BEST example of an analytical procedure used during an IS audit?
Medium40Given this configuration, which is the PRIMARY concern?
Medium41An organization is evaluating a cloud-based identity as a service (IDaaS) for single sign-on (SSO). Which of the following security concerns is MOST critical to address?
Hard42An organization's backup strategy includes taking full backups weekly and transactional log backups every 15 minutes. The auditor wants to verify that backup encryption is implemented for offsite storage. Which control is most relevant?
Hard43Which type of change in ITIL requires approval from the Change Advisory Board (CAB) before implementation?
Easy44A company has multiple business units with conflicting IT priorities. Which governance body should resolve this?
Medium45Based on the exhibit, what should the IS auditor MOST likely recommend?
Hard46Which TWO of the following are primary objectives of an information system audit?
Easy47Which of the following is the PRIMARY purpose of conducting a privacy impact assessment (PIA)?
Easy48Refer to the exhibit. A security administrator is troubleshooting why external users cannot reach the web server at 203.0.113.10 from the internet. Based on the configuration, what is the MOST likely issue?
Hard49A medium-sized retail company relies on an ERP system for order processing and inventory management. The system is hosted on-premises with daily backups stored on tape. The company's business continuity plan specifies an RTO of 4 hours and an RPO of 1 hour for the ERP system. During a recent fire drill, it was discovered that restoring the ERP system from tape took over 6 hours, and the most recent backup was from the previous day. Which of the following is the BEST course of action to meet the RTO and RPO goals?
Easy50An organization uses role-based access control (RBAC) for its enterprise resource planning (ERP) system. What is the greatest risk if user role assignments are not reviewed regularly?
Medium51An organization is selecting a key performance indicator (KPI) to measure the effectiveness of its patch management process. Which of the following is the MOST appropriate KPI?
Medium52During a security audit, it is discovered that a database containing customer credit card numbers is not encrypted at rest. The database is used by a legacy application that cannot be modified. Which compensating control most effectively reduces the risk?
Medium53An organization is planning a full interruption test of its disaster recovery plan. Which THREE of the following should the IS auditor recommend as best practices for this type of test? (Select three.)
Hard54Which TWO of the following are common objectives of an IT balanced scorecard? (Choose two.)
Easy55During the requirements gathering phase for a new financial system, stakeholders disagree on the priority of security controls versus user convenience. Which of the following is the BEST approach?
Medium56An organization has implemented role-based access control (RBAC). Which of the following is the PRIMARY benefit of RBAC?
Easy57A hospital is implementing a new electronic health records (EHR) system. The system will be used by doctors, nurses, and administrative staff. During the user acceptance testing (UAT) phase, the nursing staff reports that the interface for entering patient vitals is too slow and requires many clicks, which slows down their workflow. The project team has already completed system testing and is preparing for go-live in two weeks. The development team can make a quick fix to streamline the vital signs entry by adding a shortcut, but this change has not been tested. The IT director is concerned about patient safety and wants to ensure the system is usable. What is the BEST course of action?
Medium58When an organization uses an external provider to manage its IT help desk, this is an example of which sourcing model?
Medium59An organization is implementing a new customer relationship management (CRM) system using an agile methodology. Which THREE areas should the IS auditor focus on to assess the effectiveness of controls during the development process?
Medium60An organization is considering outsourcing its IT help desk. Which of the following is a key risk that should be addressed in the outsourcing contract?
Medium61Which TWO of the following are essential components of an effective incident response plan? (Select exactly 2.)
Medium62Which of the following is a key control in the deployment phase of the SDLC?
Easy63During an ERP implementation, the project team decides to disable segregation of duties (SoD) controls in the system to accelerate go-live. After go-live, the IS auditor identifies that a single user can perform incompatible functions. What is the BEST course of action?
Hard64A multinational corporation is deploying a data loss prevention (DLP) solution across its network. The DLP system must be configured to prevent the exfiltration of personally identifiable information (PII) while minimizing false positives. Which approach is most effective?
Hard65A large enterprise recently experienced a data breach due to an insider threat. The IT governance committee is reviewing the incident and considering measures to prevent recurrence. Which of the following is the BEST course of action to address the root cause?
Medium66An organization uses a standard change model for low-risk, pre-approved changes. Which of the following is an example of a standard change?
Medium67In a spiral SDLC model, what is the primary purpose of risk analysis in each iteration?
Easy68An organization is migrating from a legacy system to a new ERP. Which TWO of the following are the HIGHEST risks during data migration?
Medium69A systems analyst is gathering requirements for a new customer relationship management (CRM) system. Which of the following is the MOST important activity to ensure that the final system meets user needs?
Easy70Which TWO of the following are components of audit risk in the ISACA risk model? (Select TWO.)
Easy71According to ISACA IT Audit Standards, which of the following is the primary purpose of audit documentation (working papers)?
Easy72An organization plan to integrate a third-party payment gateway into its e-commerce platform. Which of the following is the MOST critical security control to implement before going live?
Hard73Arrange the steps to implement a password policy in the correct order.
Medium74During a third-party software vendor audit, the IS auditor discovers that the vendor uses a common shared database for multiple clients and relies on application-level access controls. Which of the following is the GREATEST concern?
Hard75An organization is implementing a public key infrastructure (PKI) to issue digital certificates for internal applications. Which THREE of the following are essential elements of PKI governance that an IS auditor should review?
Hard76An organization uses shared accounts for system administration. Which of the following is the MOST significant audit concern?
Medium77An IS auditor is reviewing the organization's incident management process. Which THREE of the following are essential components of an effective incident response plan?
Hard78Which of the following is an example of a detective control in the SDLC testing phase?
Medium79An IT auditor is reviewing the business continuity plan (BCP) testing schedule. The organization conducts a test where participants discuss their roles and responses to a scenario without any actual system activation. Which type of test is this?
Easy80An IS auditor reviews the exhibit during an audit of database controls. What is the most appropriate recommendation?
Medium81An organization is implementing a change management process. A change that requires approval from the Change Advisory Board (CAB) but is scheduled to be implemented during the next maintenance window is classified as which type of change?
Hard82Which TWO of the following are key components of an IT governance framework?
Medium83In a RACI matrix for the change management process, who is typically Accountable for the overall change process?
Hard84An IS auditor is reviewing a vendor's SOC 2 report as part of a systems acquisition. Which TWO aspects should the auditor verify to ensure the report is reliable?
Medium85An IT steering committee is reviewing a proposed project to migrate critical applications to the cloud. Which of the following is the PRIMARY role of the IT steering committee in this decision?
Medium86Which TWO of the following are key components of an IT governance framework? (Choose two.)
Easy87An organization is implementing COBIT 2019. Which TWO of the following are governance enablers? (Choose two.)
Medium88An IS auditor is reviewing change management procedures. Which of the following situations would be of GREATEST concern?
Medium89Which human resource control is PRIMARILY intended to detect fraud in IT operations?
Easy90In a RACI matrix for an IT change management process, who is responsible for performing the change?
Easy91A financial institution is evaluating its IT governance structure. Which of the following roles is BEST suited to ensure independent oversight of IT investments?
Medium92Based on the exhibit, what is the security risk of this bucket policy?
Easy93An IS auditor is evaluating the effectiveness of an organization's business continuity plan (BCP). Which of the following findings would be of GREATEST concern?
Easy94An organization wants to ensure that IT performance is measured against strategic goals. Which tool is BEST suited?
Easy95An IT auditor is reviewing the change management process for a financial application. The auditor finds that emergency changes are frequently implemented without post-implementation review. What is the MOST significant risk?
Medium96An organization's IT governance committee is reviewing a proposal to use a public cloud provider that does not meet the organization's data encryption standards. The board has set a low risk appetite for data privacy. What is the BEST action?
Hard97An auditor finds that access reviews have not been completed for two quarters. What is the MOST significant risk?
Hard98An IS auditor is selecting an appropriate audit sample. Which THREE of the following are factors that affect the sample size?
Medium99A company is implementing a new procurement system. The project team is considering using a rapid application development (RAD) methodology. Which of the following is a potential risk of using RAD?
Medium100Which THREE of the following are components of the COBIT 2019 governance system?
Hard101An IT auditor is reviewing the asset management process for hardware lifecycle. Which two controls should the auditor verify to ensure secure disposition of decommissioned servers?
Medium102An IS auditor is assessing the controls in an agile development environment. What is the MOST effective way to verify that security testing is performed iteratively?
Medium103Match each encryption key type to its usage.
Medium104An IS auditor is evaluating the effectiveness of a control. The auditor observes the control being performed and then independently performs the same control to confirm the result. Which combination of evidence types is being used?
Hard105An organization is negotiating a contract with a cloud service provider. Which clause is most important for the IS auditor to ensure is included?
Easy106During a change advisory board (CAB) meeting, a proposed change to the database server is discussed. The change involves implementing a security patch that requires a reboot. The change is categorized as 'normal' and has been risk-assessed as low impact. What is the most likely role of the CAB in this scenario?
Medium107An IS auditor is evaluating the capacity management process. The auditor notices that CPU utilization has been consistently above 90% for the past three months. The IT manager states that no proactive capacity planning has been performed. What is the primary risk?
Medium108An organization is deciding between building a custom application and purchasing a commercial off-the-shelf (COTS) product. The primary factor favoring the build option is:
Hard109A financial institution recently experienced a data breach where an attacker exfiltrated customer data through an SQL injection vulnerability in a web application. The IS auditor has been asked to review the application security controls. The web application is developed in-house and runs on an application server behind a web application firewall (WAF). The auditor reviews the WAF logs and finds that no SQL injection attacks were detected before the breach, but the logs show many blocked XSS attempts. The developer states that all input validation is performed on the client side using JavaScript. During the audit, the auditor also finds that the application uses a shared database account with DBA privileges for all connections. What is the MOST significant weakness that directly contributed to the breach?
Medium110Which of the following audit types is performed by an independent third-party auditor and is typically required for regulatory compliance?
Easy111An organization outsources its data center operations to a third-party provider. Which of the following is the MOST important clause to include in the contract to ensure the organization can verify the provider's controls?
Medium112An organization is deciding between developing a custom application and purchasing a commercial off-the-shelf (COTS) product. The project manager favors a COTS solution because it offers faster deployment. Which of the following is the MOST important consideration for the IS auditor to evaluate in this build vs. buy decision?
Hard113An organization is selecting a disaster recovery (DR) site. The primary data center is located in a region prone to earthquakes. The DR site should be at a sufficient distance to avoid the same disaster. Which type of alternate site provides the best balance of cost and recovery time for a medium-sized organization?
Hard114Which of the following is a key control during the deployment phase of a system development life cycle?
Easy115During the planning phase of an IS audit, which of the following is the PRIMARY purpose of conducting a risk assessment?
Easy116During an information systems audit, the IS auditor finds that data classification labels are not consistently applied across the organization. What is the most likely root cause of this issue?
Hard117During a disaster recovery test, the recovery time objective (RTO) for a critical application was not met. Which of the following is the MOST likely cause?
Easy118An IS auditor is assessing network security controls. Which TWO of the following are key elements of a firewall rule review?
Medium119A large financial institution is evaluating the effectiveness of its IT governance framework. The board has requested a review to ensure alignment with business objectives and regulatory requirements. Which of the following is the MOST important factor for the board to consider when assessing the IT governance framework?
Medium120Refer to the exhibit. An auditor finds that the file 'sensitive.txt' has world-writable permissions. Which of the following is the most appropriate remediation action?
Easy121An IT steering committee is evaluating a proposal to migrate critical applications to the cloud. Which factor is MOST important to ensure alignment with business strategy?
Medium122In business continuity planning, a company identifies a critical business process with a maximum tolerable downtime (MTD) of 4 hours. What is the primary purpose of this metric?
Easy123An organization is migrating data from a legacy system to a new ERP. What is the most critical data migration risk?
Medium124According to ISACA IT Audit Standards, which phase of the audit process includes the development of an audit programme?
Easy125Based on the exhibit, what is the MOST likely compliance issue requiring immediate remediation?
Hard126During a post-implementation review of a new accounting system, the IS auditor notes the following: the project was completed on time and within budget, but user satisfaction is low and there are several outstanding defect reports. Which THREE of the following are the MOST appropriate recommendations?
Hard127Refer to the exhibit. Based on the governance status report, which component should be addressed as a priority?
Easy128Which TWO of the following are components of audit risk in IS auditing?
Medium129An organization's online transaction processing system experienced a sudden performance degradation. The database administrator checked system resources and found excessive I/O wait time on the storage subsystem. Which of the following is the MOST likely root cause?
Medium130Which THREE of the following are common techniques for ensuring business resilience?
Hard131A compliance audit is primarily concerned with:
Easy132An organization uses automated job scheduling for batch processing. A critical job fails due to a dependency on another job that has not completed. Which of the following controls would BEST prevent this issue?
Medium133A healthcare organization must comply with HIPAA regulations regarding patient data privacy. The IT department has implemented technical controls, but the compliance officer discovers that some employees are sharing passwords. What is the BEST governance response?
Easy134Which TWO of the following are examples of IT governance frameworks? (Select TWO.)
Easy135During an audit of network security controls, the IS auditor reviews firewall rule sets and identifies a rule that allows any-to-any traffic from the internal network to the Internet. The rule has a business justification. What is the auditor's BEST recommendation?
Hard136A company is integrating a third-party payment gateway into its e-commerce platform. Which of the following is the MOST important security control to implement?
Medium137A medium-sized manufacturing company has recently deployed an ERP system to integrate its financial, supply chain, and HR processes. The IT department is small (5 staff) and reports to the CFO. The company has no formal IT governance committee; IT decisions are made by the CFO and CEO informally. During a recent audit, it was found that several critical security patches for the ERP system have not been applied, and there are no documented procedures for change management. The IT manager states that patches are applied when time permits, and changes are discussed via email. The CFO argues that the ERP is running fine and the audit findings are low risk. The IS auditor needs to recommend a course of action to improve IT governance. Which of the following is the MOST appropriate initial step?
Easy138Match each COBIT 5 domain to its description.
Medium139Refer to the exhibit. An IS auditor finds this bucket policy attached to an S3 bucket storing sensitive customer data. What should the auditor recommend?
Medium140Refer to the exhibit. An IS auditor is reviewing firewall logs and notices repeated denied SSH attempts from an internal host (10.0.1.50) to a server (172.16.0.1). After the denied attempts, the host initiates permitted HTTPS connections to another server (172.16.0.5). Which of the following is the BEST interpretation of this pattern?
Medium141A small e-commerce company uses a cloud-based e-commerce platform with automatic scaling. The company's business continuity plan relies on the cloud provider's promise of 99.99% uptime. During a regional outage affecting the cloud provider's primary availability zone, the company's website became unavailable for 2 hours, resulting in lost sales. The IT manager wants to improve resilience. Which of the following is the BEST action?
Easy142An organization is developing a business continuity strategy. According to best practices, which THREE of the following should be included in the strategy?
Medium143During an audit of a financial application, the IS auditor discovers that user access reviews are performed quarterly instead of monthly as required by policy. Which of the following is the BEST initial action for the auditor?
Medium144Which of the following is the BEST indicator that an organization's data security governance is effective?
Hard145An IS auditor is reviewing an emergency change that was implemented to fix a critical security vulnerability. What is the most important post-implementation step?
Hard146Which of the following are COBIT 2019 management objectives?
Hard147Which of the following is a key component of an IT balanced scorecard from the 'internal process' perspective?
Medium148An organization's IT governance framework includes a policy that all system access must be reviewed quarterly. The internal audit finds that reviews are incomplete. What is the BEST action?
Medium149A project manager is selecting a development methodology for a project with well-defined requirements and low uncertainty. Which methodology is most appropriate?
Easy150During an audit of a healthcare organization's information security program, the IS auditor finds that the security awareness training is conducted only at hire. Which of the following is the MOST significant risk associated with this practice?
Medium151An organization is implementing a custom ERP system. During user acceptance testing (UAT), critical bugs are found that affect core financial processing. The project sponsor suggests deploying the system on schedule and fixing bugs after go-live. What is the BEST course of action?
Medium152During a system deployment, the above error occurs. What is the MOST likely cause?
Medium153Which ITIL 4 guiding principle emphasizes understanding the current state and building on existing capabilities rather than starting from scratch?
Medium154Which TWO of the following are essential components of a disaster recovery plan (DRP)?
Easy155An organization is developing a business continuity strategy for its key customer-facing application. The BIA determined an RTO of 2 hours and an RPO of 30 minutes. Which TWO strategies are most appropriate to meet these objectives?
Medium156An IT department is structured with a central group that manages infrastructure and security, while business units have their own IT staff for application support. This is an example of which IT organizational structure?
Medium157Which type of disaster recovery test involves actually switching over to the alternate site and processing live transactions, but does not require the primary site to be shut down?
Easy158According to ISO/IEC 38500, a board member insists on approving all IT acquisitions above a certain threshold. Which principle of corporate governance of IT does this support?
Hard159During an audit of patch management, the IS auditor notes that several critical patches have not been applied within the defined SLA. Which of the following is the BEST approach to evaluate the risk acceptance of these unpatched vulnerabilities?
Hard160An organization is implementing a data loss prevention (DLP) solution. Which of the following is the BEST approach to minimize false positives while ensuring sensitive data is protected?
Medium161An organization is considering whether to build a custom application or purchase a commercial off-the-shelf (COTS) product. Which of the following factors would most strongly support a build decision?
Medium162An IS auditor is reviewing the process for granting access to a critical financial system. The auditor finds that access requests are approved by the system owner but there is no segregation between the request and approval functions for emergency access. Which of the following is the BEST control to mitigate this risk?
Medium163An organization uses shared accounts for system administration. Which of the following is the BEST control to mitigate the risk of non-repudiation?
Medium164Which TWO of the following are indicators that an IS auditor may need to adjust the audit approach during fieldwork? (Select TWO.)
Hard165An IS auditor is performing a compliance audit of a company's data privacy practices. Which type of evidence would be most appropriate to verify that employees have completed mandatory privacy training?
Medium166An organization is evaluating a vendor for a custom application development. The vendor states they are assessed at CMMI Level 2 (Managed). Which of the following best describes the implication of this rating?
Medium167An organization is adopting agile development methodology. Which control is MOST critical to ensure security is integrated?
Hard168A company is developing a custom application. During the requirements phase, the project manager documents that the system must encrypt all sensitive data at rest. Which of the following is the BEST control to ensure this requirement is met throughout the development lifecycle?
Easy169An organization has implemented a security awareness training program. Which of the following metrics would BEST indicate that the program is effective?
Easy170An IS auditor is assessing the risk of fraud in a financial system. Which combination of audit risk components is most directly relevant?
Hard171Which of the following is the BEST control to ensure that system changes are authorized?
Easy172An IS auditor is reviewing the logical access controls for a critical financial application. Which of the following is the MOST important control to ensure that user access rights remain appropriate over time?
Easy173An organization uses a public key infrastructure (PKI) to issue digital certificates. The IS auditor is reviewing the certificate lifecycle management. Which of the following is the GREATEST risk if certificate revocation lists (CRLs) are not updated in a timely manner?
Medium174An IT balanced scorecard for a retail company shows that the percentage of IT projects delivered on time has decreased from 85% to 70%. Which perspective of the balanced scorecard is MOST directly affected?
Medium175An organization is implementing a key management program to protect encryption keys. Which of the following is the MOST important control to ensure the security of cryptographic keys?
Easy176Based on the exhibit, what is the MOST likely security risk?
Medium177During a vendor audit, an IS auditor discovers that a cloud service provider uses subcontractors to manage data storage. The contract does not mention subcontracting. Which THREE risks should the auditor highlight to management?
Hard178During an IS audit, the auditor finds that a control deficiency could result in a material misstatement. According to ISACA standards, this should be classified as:
Medium179Scenario: A mid-sized manufacturing company has recently experienced a significant IT outage that halted production for 8 hours. The root cause was a failed firmware update on a core switch that was performed outside the change management process by a senior network engineer who claimed the update was urgent to patch a critical vulnerability. The company has a well-documented change management policy that requires all changes to be reviewed by the change advisory board (CAB) before implementation, except for emergency changes which require post-implementation review within 48 hours. The engineer did not follow the emergency change process; he implemented the update directly. The IT director wants to prevent such incidents in the future. Which of the following is the BEST action?
Hard180You are an IS auditor for a financial institution that processes credit card payments. The organization uses a key management system (KMS) to store encryption keys for point-of-sale (POS) data. The KMS is a hardware security module (HSM) located in a secured data center. The audit reveals that the HSM is administered by two individuals who both have full access to the HSM, including the ability to export keys. The organization has a policy requiring split knowledge and dual control for key management, but in practice, the two administrators often perform key ceremonies alone due to scheduling conflicts. The logs show that one administrator exported a key last month without the other present, and the export was approved via email by the other administrator after the fact. Which of the following is the BEST corrective action?
Medium181An IS auditor is reviewing problem management processes. Which TWO of the following are key outputs of effective problem management? (Select two.)
Easy182During a business impact analysis (BIA), the auditor identifies a critical process with a maximum tolerable downtime (MTD) of 4 hours. The IT department proposes a recovery time objective (RTO) of 2 hours and a recovery point objective (RPO) of 1 hour. Which statement is correct?
Medium183During an audit of a public key infrastructure (PKI), the IS auditor finds that certificate revocation lists (CRLs) are only updated weekly. Which of the following is the MOST significant risk?
Hard184Which TWO of the following are benefits of an iterative SDLC approach compared to waterfall? (Select two.)
Medium185A company is migrating its customer database to a public cloud provider. Which of the following encryption strategies best protects data while minimizing performance impact on queries?
Hard186A healthcare organization is required to comply with HIPAA regulations for protecting electronic protected health information (ePHI). The organization uses a cloud-based electronic health record (EHR) system. During a compliance audit, it is discovered that some employees are accessing patient records without a legitimate business need. The EHR system logs all access, but there is no automated process to review logs or detect anomalous behavior. The organization has implemented role-based access control (RBAC) and requires strong passwords, but unauthorized access continues. The IT manager proposes implementing a security information and event management (SIEM) system to collect and correlate logs. However, the budget is limited. Which additional control would be most cost-effective to reduce unauthorized access to patient records?
Medium187A company's security policy requires that all laptops have full disk encryption. During an audit, it is discovered that several laptops have encryption enabled but the recovery keys are stored on the local drive. What is the MOST significant risk?
Easy188During an audit of an organization's disaster recovery plan (DRP), the IS auditor finds that the plan was last tested 18 months ago and no test results were documented. What should the auditor recommend?
Medium189A multinational corporation has implemented a hot site disaster recovery solution for its critical financial applications. Which of the following is the MOST important consideration to ensure the effectiveness of the hot site?
Hard190During an audit, the auditor identifies a control deficiency that could result in a material misstatement. According to ISACA guidelines, this is classified as:
Medium191Which of the following is the PRIMARY objective of a post-implementation review of an information system?
Easy192Which of the following is the PRIMARY reason for an external IS audit to be more independent than an internal audit?
Easy193An IS auditor is assessing the data inventory of a financial institution to ensure compliance with privacy regulations. Which TWO of the following are essential elements that should be included in the data inventory?
Medium194Arrange the steps to set up a virtual private network (VPN) for remote access in the correct order.
Medium195According to ISACA IT Audit Standards, which of the following is a key requirement for audit documentation?
Easy196During a business impact analysis (BIA), which of the following is the MOST important metric to identify for each critical business process?
Medium197An IS auditor is evaluating the vendor selection process for a new system. Which of the following is the most important factor to include in the contract?
Medium198An organization is implementing a data loss prevention (DLP) solution. Which of the following is the MOST important step to ensure the DLP rules are effective?
Easy199According to ISACA IT Audit Standards, which of the following is the MOST important consideration when determining the scope of an IS audit?
Medium200An IS auditor is evaluating the effectiveness of controls over a critical financial application. Which TWO of the following are appropriate audit procedures to test the design and implementation of controls? (Select TWO.)
Medium201An IT governance framework has been implemented, but the board is not receiving regular reports on IT performance. Which of the following is the BEST course of action?
Medium202An organization uses a third-party vendor for application support. The vendor has subcontracted some support activities to another firm (fourth party). The contract with the vendor requires the vendor to ensure fourth-party compliance, but there is no direct oversight. What is the IS auditor's primary recommendation?
Hard203An IT steering committee is reviewing a proposed project to implement a new customer relationship management (CRM) system. The project has strong support from the sales department but is opposed by the finance department due to cost concerns. What is the primary role of the IT steering committee in this situation?
Medium204During a security audit, which rule poses the greatest risk?
Easy205A company is developing a new financial application. Which THREE of the following are valid reasons to involve internal audit during the development phase?
Hard206During the system development life cycle (SDLC), which THREE of the following are recognized benefits of involving internal audit early in the process?
Easy207An organization is implementing a public key infrastructure (PKI) to support digital certificates. Which of the following is the MOST critical control to ensure the integrity of the certificate lifecycle?
Medium208An IS auditor is reviewing the change management process and notices that several emergency changes were implemented without post-implementation review. What is the PRIMARY concern?
Hard209A company is designing its backup strategy for a critical database that must be available 24/7. The database experiences high transaction volumes. Which backup method minimizes data loss while allowing continuous operations?
Easy210During a post-implementation review of a new payroll system, the IS auditor identifies several outstanding issues. Which TWO issues should be considered most critical to address immediately? (Select TWO)
Medium211During an incident, the IT team identifies that a critical patch was not applied due to an expired software maintenance contract. Which of the following is the BEST long-term remediation?
Hard212Which TWO of the following are effective controls to prevent fraud in IT? (Select TWO)
Medium213An organization is implementing a business continuity plan (BCP) and needs to determine the maximum acceptable downtime for a critical system. Which metric should be defined FIRST?
Hard214A company's backup policy requires daily full backups to tape and offsite storage. After a ransomware attack, the IT team discovers that the latest backup set is corrupted. Which of the following controls would have BEST prevented this?
Medium215An organization has implemented a balanced scorecard (BSC) for IT performance measurement. Which of the following is the PRIMARY benefit of using a BSC?
Easy216Which TWO of the following are key activities in the system design phase of the SDLC?
Medium217An IS auditor is reviewing a post-implementation review report for a new ERP system. Which of the following findings would be of greatest concern to the auditor?
Hard218An organization uses automated job scheduling for batch processing. A critical payroll job fails due to a dependency on a prior job that did not complete. The job scheduler is configured to handle dependencies. What should the auditor verify regarding rerun procedures?
Hard219During a security audit, it was found that users in the finance department have unnecessary access to HR payroll data. Which access control principle has been violated?
Easy220A company decides to outsource the development of a customer portal. Which of the following is the MOST critical control to include in the contract?
Medium221A company is replacing its legacy on-premises ERP system with a cloud-based SaaS solution. The project manager is concerned about data migration risks. Which of the following is the BEST approach to mitigate data integrity issues during migration?
Medium222During an incident response exercise, the IT team discovers that the failover to the disaster recovery (DR) site failed because the DR site's storage area network (SAN) was not zoned correctly for the replicated data. Which of the following controls would BEST prevent this issue?
Hard223Refer to the exhibit. During a penetration test, a security analyst captures this SAML response. Which of the following security weaknesses is most evident?
Hard224Which TWO of the following are key controls for ensuring data privacy during system development?
Medium225An organization has implemented a key management program. Which of the following is the MOST critical control for ensuring the security of cryptographic keys?
Medium226An organization is implementing a data retention policy for personally identifiable information (PII) to comply with GDPR. Which of the following is the MOST appropriate approach?
Hard227An IS auditor is reviewing the process for granting access to a sensitive financial application. Which TWO of the following are the MOST important controls to ensure appropriate access?
Easy228Which TWO of the following are key components of an IT governance framework? (Choose two.)
Medium229During user acceptance testing, a user with the above permission set cannot execute a fund transfer. What is the MOST likely reason?
Easy230A large financial institution is developing a new online banking platform using an Agile methodology. The development team has implemented continuous integration and continuous deployment (CI/CD) pipeline. During a routine security scan, the IS auditor discovers that a developer accidentally committed a configuration file containing database credentials into the public-facing code repository. The credentials were exposed for 48 hours before being detected. Which of the following is the most critical control failure that allowed this incident to occur?
Hard231Which of the following is the PRIMARY purpose of audit working papers?
Medium232An IS auditor identifies a control deficiency that could result in a material misstatement in the financial statements. According to audit reporting standards, this should be classified as:
Hard233Which of the following is the best example of audit evidence obtained through re-performance?
Medium234An IS auditor is reviewing an organization's logical access control processes. Which of the following is the primary purpose of conducting regular user access recertifications?
Easy235An IS auditor is reviewing a third-party service provider's controls. Which of the following is the MOST important clause to include in the contract to ensure the auditor can assess the provider's controls?
Medium236A company is implementing IT governance based on COBIT 2019. Which of the following design factors would have the GREATEST impact on the governance system design?
Hard237An IS auditor is reviewing an agile software development project. Which of the following is the most important control to assess?
Medium238An organization is developing a critical application using an agile methodology. The project sponsor demands frequent deliveries but the development team is concerned about insufficient testing. Which of the following BEST mitigates this risk?
Hard239An IT auditor is evaluating the change management process for a financial trading system. Which of the following is the BEST indicator of a mature change management process?
Medium240An IS auditor is assessing the vulnerability management program of a financial services company. The auditor reviews the latest vulnerability scan report and finds that several critical vulnerabilities have not been patched within the defined SLA of 30 days. The IT manager explains that patches could not be applied due to compatibility issues with legacy applications, and risk acceptance has been documented for some but not all. Which THREE of the following are the MOST appropriate audit findings?
Medium241During an IT audit, the auditor observes that mandatory vacation policies are not enforced for IT staff with access to financial systems. What is the PRIMARY risk associated with this finding?
Hard242An organization is implementing a large ERP system. The project team plans to migrate legacy data to the new system. Which of the following is the MOST significant risk associated with data migration?
Hard243Which THREE of the following are required components of a SMART recommendation? (Select three.)
Hard244An IS auditor is reviewing physical access controls at a data center. Which of the following controls is MOST effective for preventing tailgating?
Easy245Which THREE of the following are responsibilities of the board of directors regarding IT governance? (Choose three.)
Hard246Which TWO are primary objectives of an identity and access management (IAM) program? (Select exactly 2.)
Hard247An IS auditor is reviewing the change management process for a critical financial application. Which of the following is the most important element to verify in an emergency change request?
Medium248Which THREE of the following are phases of the audit process as defined by ISACA? (Select THREE.)
Hard249A company is implementing a cloud-based identity and access management (IAM) system. Which of the following best describes the principle of least privilege in this context?
Medium250A large enterprise is assessing its IT governance maturity. Which THREE of the following are indicators of a mature governance process? (Select exactly three.)
Hard251An IS auditor is reviewing the incident response (IR) process. Which of the following is the MOST important characteristic of an effective tabletop exercise?
Medium252An organization is transitioning from a waterfall to an agile development methodology. Which of the following is a key risk that the IS auditor should highlight?
Medium253An IS auditor is reviewing a penetration test report that shows a critical vulnerability in a web application. The IT manager states that the vulnerability will not be fixed because it requires significant code changes and the application is being decommissioned in six months. What should the auditor do?
Hard254A database administrator accidentally deleted a critical table. The last full backup was taken 24 hours ago, and transaction logs are archived every 15 minutes. Which recovery method will minimize data loss?
Medium255Which of the following is the PRIMARY purpose of a service desk?
Easy256An IT manager wants to measure the effectiveness of the organization's patch management process. Which of the following KPIs would be most appropriate?
Medium257Which of the following is a permanent file item in an IS audit working paper?
Medium258Which of the following is the BEST indicator that an organization's incident management process is effective?
Easy259A company is outsourcing software development. What is the IS auditor's PRIMARY concern?
Medium260An organization uses continuous auditing techniques to monitor transactions. The IS auditor is evaluating the effectiveness of these techniques. Which of the following is the PRIMARY benefit of continuous auditing over traditional periodic auditing?
Medium261What is the primary control weakness in this IAM policy?
Medium262Which THREE are core components of a comprehensive identity and access management (IAM) system? (Choose three.)
Hard263An organization is considering outsourcing its IT infrastructure management. Which of the following is the MOST important factor to include in the service level agreement (SLA)?
Medium264An organization's mobile device management (MDM) policy requires that all corporate data on employee-owned smartphones be protected. Which control best ensures that corporate data can be remotely wiped without affecting personal data?
Easy265An IT governance framework should include which TWO key components? (Select exactly two.)
Easy266An organization experiences a ransomware attack that encrypts critical files. Which of the following is the BEST recovery strategy to minimize data loss?
Medium267Which of the following evidence types involves the auditor independently performing a control procedure to verify its effectiveness?
Easy268An IS auditor is testing a control that requires two approvals for purchase orders over $10,000. The auditor selects a sample of 50 purchase orders from the population of 500. Using statistical sampling, the auditor finds 2 deviations. The tolerable deviation rate is 5%. What should the auditor conclude?
Medium269An organization wants to ensure that data is not retained longer than necessary. Which of the following is the BEST control to implement?
Easy270An organization has a policy requiring all employees to complete annual information security awareness training. Which of the following is the BEST way to verify compliance with this policy?
Easy271An auditor is reviewing IT asset management processes. The auditor finds that several servers running an older operating system are still in production, even though the vendor has ended support. What is the primary risk associated with this finding?
Medium272An organization has implemented a clean desk policy. Which of the following is the BEST audit procedure to verify compliance?
Medium273During a review of firewall rule sets, an IS auditor identifies a rule that allows 'any-any' traffic from an internal subnet to the DMZ. The rule was implemented six months ago based on a business request that has since been completed. The firewall administrator explains that the rule was kept for convenience. Which of the following is the BEST audit recommendation?
Hard274An IS auditor is assessing the vendor management process. Which TWO are key controls for managing third-party risk?
Easy275A large financial institution is implementing a new core banking system to replace a legacy system. The project has been underway for 18 months and is behind schedule. User acceptance testing (UAT) has revealed significant data integrity issues, including missing customer records and incorrect interest calculations. The project manager, under pressure from senior management to meet a regulatory deadline, proposes going live with a promise to fix the issues in a post-implementation phase. The development team has been making ad hoc code changes directly in the test environment without version control or proper testing. Additionally, the IS auditor discovers that the business requirements were never formally signed off by the user community; only verbal approvals were obtained. The project has consumed 90% of the budget but only 60% of the functionality is tested. Which of the following is the BEST course of action for the IS auditor to recommend?
Hard276Which of the following is the BEST indicator of the effectiveness of a security awareness program?
Easy277Which TWO of the following are indicators of poor project governance that an IS auditor should identify?
Hard278An organization uses a cloud service provider (CSP) for critical applications. The IS auditor is reviewing the contract for vendor concentration risk. Which TWO clauses are MOST relevant to mitigating this risk?
Hard279Which TWO of the following are benefits of implementing an IT governance framework?
Easy280An IS auditor is reviewing the firewall rule base. Which of the following findings would be of MOST concern?
Medium281A company's endpoint protection solution alerts on a file that is digitally signed by a trusted software vendor but exhibits malicious behavior on execution. What type of threat does this scenario most likely depict?
Hard282Refer to the exhibit. An application log shows an error. What is the MOST likely cause of this error?
Medium283An IS auditor is assessing an ERP implementation. Which of the following control concerns is MOST likely to arise from segregation of duties conflicts?
Medium284An organization uses role-based access control (RBAC). An employee is transferred to a new department. According to best practices, what should be done regarding the employee's access rights?
Medium285A company is developing a mobile application that processes credit card payments. During the testing phase, which of the following types of testing is MOST critical to ensure security?
Medium286An IS auditor is assessing audit risk for a payroll system. The inherent risk is assessed as moderate, control risk as high due to weak segregation of duties, and detection risk is set at low because of extensive substantive testing. What is the impact on overall audit risk?
Hard287Which THREE of the following are key components of an effective information security awareness program? (Choose three.)
Hard288An organization is implementing a new incident management process aligned with ITIL. The IT team discovers a critical system is down, affecting all users. According to ITIL, what severity level should be assigned to this incident?
Easy289Which TWO of the following are important controls for managing cloud resources to prevent cost overruns? (Select TWO).
Medium290An IS auditor is reviewing the key management program for an organization's encryption systems. Which of the following is the MOST critical control to ensure the security of encryption keys?
Medium291A company is implementing a new IT governance framework. Which of the following is the PRIMARY benefit of aligning IT strategy with business strategy?
Easy292During a post-implementation review, an IS auditor identifies that the system's actual transaction processing time is significantly higher than the benchmark specified in the service level agreement (SLA). The vendor claims it is due to inadequate network bandwidth provided by the client. What should the auditor do first?
Hard293Which TWO of the following are recommended practices for aligning IT strategy with business goals, according to COBIT 2019?
Medium294An IS auditor is evaluating the release management process for a software application. Which TWO are essential components of a successful release plan?
Hard295Which of the following best describes audit risk in the context of an IS audit?
Hard296A multinational corporation is implementing a new enterprise resource planning (ERP) system across multiple regions. The project uses a phased roll-out. After the first phase in Asia, the system experiences intermittent synchronization errors between the central database and regional servers. The IT team suspects network latency but cannot reproduce the issue consistently. The project sponsor wants to proceed with the next phase in Europe to avoid further delays. The IS auditor is performing a post-implementation review. What is the MOST appropriate recommendation?
Hard297An organization has a policy that requires all employees to undergo annual security awareness training. This is an example of which type of document in the policy hierarchy?
Easy298A small business wants to protect customer data collected through its e-commerce website. Which control is most appropriate for protecting the data at rest and in transit?
Easy299During an audit of physical security, the IS auditor observes that employees frequently leave confidential documents on their desks overnight. Which TWO controls should the auditor recommend?
Easy300During the user acceptance testing (UAT) phase of a new financial application, the business users report that the system calculates interest incorrectly for certain loan types. The project manager wants to fix this quickly. Which of the following is the BEST course of action?
Hard301Which of the following is the PRIMARY purpose of a change advisory board (CAB) in the change management process?
Medium302An IS auditor is planning an audit of a decentralized organization with multiple business units. The auditor wants to use a risk-based approach. Which of the following is the MOST appropriate factor to prioritize audit coverage?
Hard303Which TWO of the following are key considerations when managing software licenses in an organization? (Select TWO).
Medium304Which TWO of the following are the MOST effective controls to prevent unauthorized changes to production data?
Medium305During which phase of the SDLC should security requirements be formally documented and approved?
Easy306Which THREE of the following are typical controls in the design phase of the SDLC?
Medium307An organization is implementing a new IT governance framework. Which of the following is the PRIMARY benefit of aligning IT strategy with business strategy?
Easy308An organization processes personal data of EU residents and has implemented pseudonymisation as a privacy control. The IS auditor is reviewing the effectiveness of this control in meeting GDPR requirements. Which of the following is the MOST important limitation of pseudonymisation?
Hard309An IS auditor is performing a risk assessment for an audit of a cloud service provider. Which THREE factors should be considered when assessing inherent risk? (Select THREE.)
Hard310An organization is implementing a new ERP system and is concerned about segregation of duties (SoD) conflicts. What is the BEST approach to address this during the implementation?
Medium311A multinational corporation is implementing a bring your own device (BYOD) policy. Which of the following is the most important security control to ensure corporate data is protected on employee devices?
Hard312A financial services organization recently experienced a data breach where customer financial records were exfiltrated. The investigation reveals that an attacker gained access through a compromised privileged account belonging to a database administrator. The attacker used valid credentials to log into the database server and then exported a large volume of data using native database tools. The security team notes that the organization has multi-factor authentication (MFA) enabled for all remote access, but the database server was accessed from an internal IP address. The organization also has a data loss prevention (DLP) system, but it did not alert on the export because the traffic was encrypted. The database activity monitoring (DAM) system did log the export, but alerts were not reviewed due to high volume and many false positives. Which of the following would have been most effective in preventing this breach?
Hard313What is the PRIMARY purpose of a post-implementation review?
Easy314An organization is implementing a privileged access management (PAM) solution. Which of the following is the PRIMARY benefit of using a PAM tool?
Medium315An organization is implementing a new IT policy. What is the MOST important step to ensure compliance?
Medium316Based on the exhibit, what is the default retention period for data?
Easy317Which testing phase is MOST effective for validating that the system meets business needs?
Easy318A company plans to outsource its data center operations to a cloud service provider. What is the MOST important governance consideration for the board before finalizing the contract?
Medium319Which TWO of the following are key performance indicators (KPIs) for IT operations?
Medium320An IS auditor is planning a risk-based audit of a financial system. Which TWO of the following factors should the auditor consider when assessing inherent risk? (Select two.)
Medium321An organization is implementing a new financial system. Which of the following is the MOST important control to ensure data integrity during the data migration phase?
Easy322Refer to the exhibit. An auditor finds that users are able to reuse previous passwords easily. Which setting should be modified to address this weakness?
Medium323What is the MOST significant weakness in the planned remediation?
Hard324A company uses a RAID 5 array for its file server. One disk fails, and the system continues to operate. However, during the rebuild process, a second disk fails. What is the likely consequence?
Hard325Which THREE of the following are characteristics of a SMART recommendation? (Select three.)
Hard326A multinational corporation is deploying a new cloud-based collaboration platform for its 5,000 employees. The platform will store sensitive project data and intellectual property. The CISO mandates that all data must be encrypted at rest and in transit, and that access must be controlled via the company's identity provider (IdP) using SAML 2.0. During a pilot with the R&D department, the security team discovers that the platform's audit logs do not record failed login attempts from the IdP. The platform vendor states that the IdP is responsible for authentication, so the platform only logs successful assertions. The CISO is concerned about the lack of visibility into brute-force attacks. The company already has a SIEM that receives logs from the IdP and other sources. What is the BEST course of action?
Medium327An IS auditor is reviewing the physical access controls at a data center. Which of the following is the MOST effective control to prevent tailgating?
Easy328An IS auditor is reviewing capacity management practices. Which TWO indicators suggest that proactive capacity management is being performed effectively?
Medium329An IS auditor is performing a compliance audit of a data privacy regulation. Which of the following is the PRIMARY source of audit criteria?
Medium330Based on the exhibit, which control deficiency is most critical for the IS auditor to address?
Hard331An IS auditor is reviewing the incident response (IR) process. Which of the following is the BEST way to test the effectiveness of the IR plan?
Easy332Refer to the exhibit. Which of the following is the most significant risk associated with the backup policy for critical data?
Hard333A multinational corporation is implementing a global IT governance framework. Which of the following challenges is MOST likely to arise?
Hard334During a software asset management (SAM) audit, it is discovered that the organization is using software that has reached end-of-life. Which of the following is the MOST significant risk associated with this situation?
Hard335An IS auditor finds that a project failed to meet its objectives because key stakeholders were not involved in the requirements definition phase. Which phase of the SDLC was most neglected?
Medium336Which of the following is the PRIMARY reason for implementing network segmentation?
Easy337An organization is designing an IT balanced scorecard to align IT performance with business goals. Which perspective would include metrics related to IT employee skills and training?
Hard338An organization uses a cloud-based ERP system to manage financial transactions. The system is accessed by employees in finance, procurement, and sales departments. The IS auditor is reviewing the user access review process. The access review is performed quarterly by the IT manager using a report generated by the ERP system. The report lists all users and their roles. The IT manager manually checks off users who are still employed and approves the report. The auditor notes that the IT manager does not have detailed knowledge of job functions in each department. Additionally, the ERP system allows role combinations that may create segregation of duties conflicts, such as a user having both 'create purchase order' and 'approve purchase order' roles. The company's policy requires segregation of duties reviews to be performed by business process owners. Which of the following is the BEST recommendation?
Medium339An organization has defined an SLA that requires critical incidents to be resolved within 4 hours. A P1 incident is reported at 10:00 AM. At what time must the incident be resolved to meet the SLA?
Easy340Which TWO of the following are typically included in the fieldwork phase of an IS audit? (Select two.)
Medium341An IS auditor is evaluating the encryption strategy for a healthcare organization subject to HIPAA. Which of the following is the MOST significant risk if the organization relies solely on encryption as a safe harbor?
Hard342An IS auditor is reviewing the backup process for a critical database. Which TWO of the following are essential controls to ensure data recoverability?
Easy343In a waterfall SDLC, which phase requires formal sign-off from the business owner before proceeding to the next phase?
Easy344An IS auditor is reviewing the design phase of a new procurement system. Which TWO of the following controls are MOST critical to include in the system design to prevent unauthorized purchases?
Medium345An IS auditor is reviewing an organization's data classification policy. Which of the following findings is MOST critical?
Medium346Refer to the exhibit. An IS auditor is reviewing an IAM policy for a cloud data platform. The auditor notices that user jdoe has READ_ONLY access to all tables matching 'sales_', but asmith has READ_WRITE access to the same set of tables. Which of the following is the MOST critical control issue?
Hard347Which control failure is MOST significant?
Hard348Order the steps for conducting an audit engagement from start to finish.
Medium349An IS auditor is reviewing the physical access controls at a data center. Which TWO of the following are the MOST effective controls to prevent unauthorized tailgating?
Medium350An IS auditor is reviewing the incident management process. Incidents are categorized as P1 (critical) through P4 (low). The SLA for P1 incidents requires initial response within 15 minutes and resolution within 4 hours. The auditor notes that the average time to respond to P1 incidents is 12 minutes, but the average resolution time is 6 hours. The root cause analysis shows that many P1 incidents are due to known errors documented in the known error database (KEDB). What is the most significant finding?
Hard351During an agile software development project, a sprint review meeting is conducted. What is the PRIMARY purpose of this meeting from an IS audit perspective?
Medium352An IS auditor is reviewing a request for proposal (RFP) for a new system. Which TWO elements should be included in the RFP?
Easy353Refer to the exhibit. Which of the following statements is TRUE regarding this S3 bucket policy?
Medium354During a post-implementation review of a financial system, an IS auditor finds that several critical reports are not being generated correctly. Which of the following should the auditor recommend FIRST?
Easy355An organization is implementing a data loss prevention (DLP) solution. Which TWO of the following are key considerations for effective DLP deployment?
Easy356An IS auditor is evaluating the effectiveness of an organization's change management process. Which of the following is the most important control to verify during the audit?
Easy357During an audit, the IS auditor discovers that the audit log for a critical server is overwritten every 24 hours. The auditor wants to ensure logs are preserved for a longer period. Which of the following recommendations is most appropriate?
Medium358Which testing type is performed by end-users to verify that the system meets their needs?
Easy359Which of the following is the BEST control to ensure that user acceptance testing (UAT) is effective?
Medium360An IS auditor is reviewing a change management process. Which TWO elements should be documented in a normal change request to ensure adequate governance? (Select TWO)
Medium361An organization is implementing a new financial system and has completed user acceptance testing (UAT). The project manager reports that all critical defects have been fixed and retested, but several low-severity issues remain unresolved. What is the BEST course of action?
Medium362An IS auditor is reviewing the organization's encryption key management program. Which of the following is the MOST critical control to ensure the confidentiality of encrypted data in the event of a key compromise?
Medium363An IS auditor is reviewing a vulnerability scan report and finds that a critical vulnerability on a web server has been open for 90 days beyond the remediation SLA. The system owner states that the vulnerability cannot be patched because it would break a legacy application. What should the auditor recommend?
Hard364An IS auditor uses statistical sampling to test a population of 10,000 transactions. The auditor discovers 5 errors in the sample of 200. Which of the following conclusions is most appropriate?
Hard365An IS auditor is evaluating the change management process. Which of the following is the BEST indicator that emergency changes are being properly controlled?
Medium366An IS auditor is assessing the effectiveness of access controls. Which TWO procedures provide the strongest evidence? (Select two.)
Medium367Based on the log, what is the MOST likely root cause of the backup failure?
Easy368Which THREE of the following are essential components of a data classification program?
Hard369A medium-sized e-commerce company recently suffered a ransomware attack that encrypted critical databases. The IT team restored systems from backups, but the incident exposed a lack of clear roles and responsibilities for incident response. The board has asked the IT governance committee to review and improve the incident response governance. The committee notes that while there is an incident response policy, it is not regularly tested, and staff are unsure of their roles. The company also lacks a formal communication protocol for notifying stakeholders. What should the committee prioritize to strengthen governance over incident response?
Easy370An organization is adopting an agile development methodology for a new financial application. During a sprint review, the product owner expresses concern that the system does not enforce segregation of duties (SoD). The development team argues that SoD will be addressed in a future sprint. As the IS auditor, what is the BEST recommendation?
Hard371A small business wants to protect customer data stored on a local file server. Which of the following is the MOST cost-effective control to prevent unauthorized access?
Easy372An organization is implementing a data loss prevention (DLP) solution. Which of the following is the BEST approach to reduce false positives during initial deployment?
Medium373An IS auditor is reviewing the user access recertification process. Which of the following findings would MOST concern the auditor regarding the effectiveness of access reviews?
Medium374An organization's backup strategy includes full backups every Sunday and incremental backups on other days. On Wednesday, a failure occurs. Which backups are needed to restore the data?
Medium375Refer to the exhibit. The IS auditor reviews the router's version output during an audit. What is the MOST significant finding?
Easy376A multinational corporation is evaluating its IT governance structure. The board wants to ensure that IT investments are prioritized based on risk and value. Which framework component is MOST critical?
Hard377A mid-sized company is implementing a new IT service management (ITSM) tool to improve incident management. The IT manager wants to ensure that the tool aligns with ITIL best practices. The company has a dedicated service desk team that handles about 200 incidents per week. The IT manager is considering whether to implement a self-service portal for users to submit incidents and check status, or to continue using email-based incident reporting. The service desk team is concerned that a self-service portal might reduce their direct interaction with users and potentially lead to less personalized support. However, the IT manager believes that a portal could improve efficiency and tracking. The company's IT governance framework requires that any major IT investment be approved by the steering committee and that there be a clear business case. The IT manager has prepared a business case but the steering committee wants to ensure that the solution is aligned with ITIL and that it addresses key incident management processes. Which of the following is the most appropriate next step for the IT manager?
Easy378An IS auditor is reviewing backup procedures for a critical database. Which THREE are key considerations for ensuring backup reliability and recoverability?
Medium379An IS auditor is reviewing the effectiveness of a control that requires dual approval for payments over $10,000. The auditor selects a sample of payments and independently verifies that two approvals were obtained. This audit procedure is:
Medium380During an operational audit of an IT department, the auditor finds that system uptime is 99.9% but the department missed two critical project deadlines. Which conclusion is most appropriate?
Medium381An IS auditor is reviewing a waterfall SDLC project that has completed the requirements phase. Which of the following is the greatest risk to the project?
Medium382An IS auditor is reviewing the change management process for a critical financial application. Which of the following findings would be of GREATEST concern?
Hard383Which TWO of the following are components of the IT balanced scorecard?
Easy384An IS auditor is reviewing the logical access controls for a cloud-based HR system. The system contains sensitive employee data. The auditor notes that user provisioning is performed by the HR department without IT involvement, and there is no formal access request or approval process. Which THREE of the following are the MOST significant risks?
Easy385Which TWO of the following are key elements of a change request document?
Medium386Which TWO of the following are key controls that an IS auditor should expect to find in a well-managed system development life cycle (SDLC)?
Medium387During an operational audit, the auditor wants to evaluate the efficiency of a data entry process. Which of the following audit procedures would be most appropriate?
Medium388An IS auditor is reviewing the physical access controls at a data center. Which of the following is the MOST effective control to prevent tailgating?
Medium389An organization is developing a policy on acceptable use of company IT resources. Which of the following should be included to support effective governance?
Medium390An IS auditor is testing the effectiveness of a control that requires dual authorization for all transactions over $10,000. The population consists of 5,000 transactions, of which 250 exceed the threshold. The auditor uses a sample of 50 transactions from the entire population and finds 3 exceptions. What type of sampling method did the auditor use?
Hard391A multinational corporation is implementing a global HR system. The project team decides to use a pilot implementation in one region before rolling out to others. What is the PRIMARY risk if the pilot region is not representative of the entire organization?
Hard392During a post-implementation review of a new financial system, the IS auditor finds that user acceptance testing (UAT) was completed with only 60% of test cases passed. Which of the following is the MOST significant risk?
Medium393An IS auditor reviews the change request. Which of the following is the most significant risk?
Hard394Which of the following is the PRIMARY purpose of a data classification scheme?
Easy395A system has a Mean Time Between Failures (MTBF) of 200 hours and a Mean Time To Repair (MTTR) of 20 hours. What is the availability of the system?
Medium396During which phase of the SDLC should security requirements be formally documented and approved by the business owner?
Easy397Order the steps for conducting a business impact analysis (BIA) in the correct sequence.
Medium398A multinational corporation has defined its risk appetite as 'moderate' for IT investments. The IT steering committee is evaluating a new project with potential high returns but also significant cybersecurity risks. The project's risk profile is assessed as 'high' by the risk management team. What should the committee do FIRST?
Hard399An organization wants to ensure that its backup tapes are protected from unauthorized access. Which of the following is the MOST effective control?
Easy400Refer to the exhibit. Which perspective shows the greatest deviation from target?
Hard401An organization has implemented a business continuity plan (BCP) and disaster recovery plan (DRP). During a recent full interruption test, the IT team discovered that the recovery time objective (RTO) for a critical application was not met. What is the MOST likely reason for this failure?
Medium402An IS auditor is reviewing the access recertification process for a financial application. The process requires users' managers to confirm access rights quarterly. Which of the following findings should MOST concern the auditor?
Medium403An IS auditor is reviewing an emergency change that was implemented to fix a critical security vulnerability. Which of the following post-implementation controls is MOST important to ensure the change was properly managed?
Hard404According to ISO/IEC 38500, which principle requires that IT investments are made for valid business reasons and with clear business outcomes?
Easy405An organization is acquiring a new financial system. The contract includes a clause that allows the organization to audit the vendor's controls. Which type of report would most efficiently provide assurance over the vendor's internal controls?
Medium406A university is implementing a new student information system. The project team uses an iterative development approach. During user acceptance testing, students report that the online course registration portal crashes when more than 100 users register simultaneously. The development team identifies a database connection pooling issue and estimates a fix will take three weeks. The project deadline is in two weeks. The project manager suggests deploying the system as is and fixing the issue after go-live, as the crash is rare. The IS auditor is consulted. What should the auditor recommend?
Medium407An IS auditor is reviewing a contract for a new software solution. Which of the following contract types poses the HIGHEST risk to the buyer if requirements are not well-defined?
Medium408A security auditor discovers that a server has been compromised due to an unpatched vulnerability. Which of the following would have most effectively prevented this incident?
Medium409During an audit of the incident response process, the IS auditor finds that the organization relies on shared accounts for system administration. Which TWO of the following are the MOST significant risks associated with shared accounts?
Medium410An organization is conducting a Business Impact Analysis (BIA). Which of the following metrics defines the maximum acceptable outage time for a critical business process?
Medium411During a spiral model SDLC project, an IS auditor is reviewing risk assessment documentation. Which of the following would be the GREATEST concern?
Hard412Refer to the exhibit. The organization is planning to achieve the target level. What is the MOST appropriate action?
Medium413Which of the following is the PRIMARY benefit of using a hardware security module (HSM) for key management?
Easy414An IS auditor is reviewing a systems acquisition project that involves purchasing an ERP system. Which of the following is the MOST significant risk related to data migration during implementation?
Medium415Order the steps for performing a data backup in the correct sequence.
Medium416Which of the following are key considerations when implementing a data classification policy? (Choose THREE.)
Medium417In a spiral model SDLC, risk analysis is performed at the beginning of each iteration. What is the PRIMARY benefit of this approach?
Hard418During the planning phase of an IS audit, the auditor identifies that the organization has recently implemented a new ERP system. Which of the following actions should the auditor prioritize?
Medium419Which TWO of the following are key objectives of a post-implementation review of a new system?
Medium420What is the FIRST step in implementing an identity and access management (IAM) program?
Easy421Scenario: A healthcare organization is implementing a new electronic health records (EHR) system. The project has been delayed due to scope creep and resource constraints. The project sponsor is pressuring the project manager to accelerate the timeline by skipping user acceptance testing (UAT) and going live immediately. The organization has a governance policy that requires all IT projects to complete UAT before deployment. The project manager is concerned about quality and patient safety. Which of the following is the BEST course of action?
Medium422An organization has an availability requirement of 99.99% for its online transaction processing system. The system's MTBF is 720 hours. What is the maximum allowable MTTR to meet this requirement?
Hard423An IT department uses a balanced scorecard (BSC) to measure performance. The financial perspective shows that IT costs are within budget, but customer satisfaction scores are declining. The learning and growth perspective indicates low employee engagement. Which action should the IT governance committee prioritize?
Hard424An IT auditor is reviewing the organization's policy hierarchy. Which of the following correctly represents the typical order from highest to lowest level?
Hard425An IS auditor is reviewing the business impact analysis (BIA) for a financial services company. Which THREE metrics are typically defined in a BIA?
Medium426An organization's IT strategy is developed by the IT department without input from business stakeholders. Which of the following is the MOST significant risk?
Hard427An organization is implementing a software asset management (SAM) program. Which of the following is the PRIMARY benefit of SAM?
Medium428An IS auditor is evaluating the incident response (IR) plan. Which of the following is the BEST indicator that the plan is effective?
Medium429A medium-sized manufacturing company has a decentralized IT structure where each business unit manages its own IT budget and projects. The CEO is concerned that IT investments are not aligned with corporate strategy and that there is duplication of effort. The IT department lacks a formal project portfolio management process. The company has experienced several project failures due to poor prioritization. The CEO has asked the newly hired IT auditor to recommend an initial step to improve IT governance. The auditor should recommend:
Easy430A company is migrating from a legacy system to a cloud-based ERP. Which of the following is the MOST important control to ensure data integrity during data conversion?
Easy431In an Agile software development project, who is primarily responsible for prioritizing the product backlog?
Easy432An IS auditor is reviewing the privileged access management (PAM) process. Which TWO of the following are the MOST effective controls to prevent misuse of privileged accounts?
Medium433Which of the following is the BEST indicator of IT performance from the customer perspective in an IT balanced scorecard?
Easy434During an audit, the IS auditor finds that the business continuity plan (BCP) was last updated two years ago and does not include new cloud-based applications. The organization has not conducted a BCP test in 18 months. What should the auditor recommend FIRST?
Hard435An organization has implemented a new IT service management (ITSM) tool. The IT manager wants to measure the effectiveness of incident management. Which metric is MOST appropriate?
Hard436An IS auditor is reviewing a backup strategy that includes daily full backups and weekly offsite storage. The recovery time objective (RTO) for a critical application is 4 hours. Which of the following findings would be of GREATEST concern?
Hard437An organization is adopting ITIL 4 for service management. Which guiding principle emphasizes starting from existing processes rather than building from scratch?
Medium438An IT steering committee is evaluating a major system upgrade. Which of the following is the PRIMARY benefit of using an IT balanced scorecard in this evaluation?
Medium439An organization is implementing a new IT governance framework. Which of the following is the PRIMARY benefit of using a framework like COBIT?
Easy440Which TWO of the following are components of the ITIL 4 four dimensions of service management? (Select TWO.)
Medium441An IS auditor is reviewing an agile project that uses Scrum. Which event provides the best opportunity for the auditor to assess whether completed user stories meet the defined acceptance criteria?
Medium442During a post-implementation review of a new HR system, the auditor finds that the system's disaster recovery plan (DRP) was not tested before go-live. Which of the following is the BEST recommendation?
Hard443During a review of the patch management process, the IS auditor finds that critical security patches are applied within 30 days, but the policy requires application within 7 days. The IT manager argues that the delay is due to testing requirements. What should the auditor recommend?
Medium444Which TWO of the following are key controls in the system development life cycle?
Medium445A company is updating its business continuity plan (BCP). Which THREE of the following should be included as key components?
Hard446Which of the following is a key difference between internal and external IS auditors?
Medium447An organization is developing a custom application. The project manager reports that the development team has implemented 80% of the features but only 50% of the budget is used. What is the MOST significant risk from an IS audit perspective?
Hard448During a risk-based audit, the IS auditor identifies a control deficiency that could lead to a material misstatement in financial reporting. According to standard classification, this is best described as a:
Medium449A bank is converting data from its legacy core banking system to a new platform. Which control is MOST critical to ensure the completeness and accuracy of data conversion?
Medium450Which THREE of the following are typical objectives of an IT governance framework for system acquisition?
Hard451During a privacy audit, the IS auditor discovers that the organization does not have a complete data inventory. What is the PRIMARY risk associated with this finding?
Medium452Which of the following audit types is MOST likely to be performed by an organization's own employees?
Easy453An IS auditor is reviewing a system development project to assess whether it is on schedule. Which of the following would provide the BEST evidence of project progress against the planned timeline?
Medium454A government agency has an IT governance framework that includes an IT strategy committee, an IT steering committee, and a project management office. Despite this, there is a lack of transparency regarding IT spending and resource allocation. The agency's annual audit found that several IT initiatives were not approved by the steering committee and were funded out of operational budgets. The CFO is frustrated because IT costs are unpredictable. The agency's chief information officer (CIO) reports to the CFO but the IT steering committee is chaired by the CIO. The auditor's best recommendation to improve governance is to:
Hard455Refer to the exhibit. During a security audit, an IS analyst identifies that a critical business application hosted on 192.168.1.100:443 is unreachable from the 10.0.1.0/24 subnet. Which of the following is the MOST likely cause?
Hard456During a business impact analysis (BIA), the IS auditor identifies that the maximum tolerable downtime (MTD) for an online payment system is 2 hours, and the recovery point objective (RPO) is 15 minutes. The current disaster recovery solution uses nightly backups (12-hour RPO) and can restore the system in 4 hours. Which risk is most critical?
Medium457During a change management board (CAB) meeting, a proposed change to the network firewall configuration is discussed. The change is considered low risk and pre-approved. Which type of change does this represent?
Easy458Which TWO of the following are effective controls to prevent unauthorized access to sensitive data in a database? (Choose two.)
Medium459You are the IT governance lead at a multinational corporation with a complex IT environment spanning multiple business units. The company has recently experienced a series of minor security incidents where unauthorized access was gained through unused user accounts that were not disabled after employees left the organization. Additionally, there have been delays in provisioning access for new hires, leading to productivity losses. The IT department currently uses a manual process for access management, with each business unit maintaining its own user lists. The company has a policy that requires access reviews every quarter, but these are often missed or performed superficially. The CIO has asked you to recommend a solution that addresses these issues while ensuring compliance with regulations such as GDPR and SOX. Which of the following is the BEST course of action?
Hard460During system development, which testing phase is performed by developers to verify that individual program units function correctly?
Medium461Which TWO of the following are indicators that a project is at risk of failure according to ISACA's project governance framework?
Hard462Refer to the exhibit. An auditor notices this log entry during a review. The user john.doe does not have a legitimate business need to access executive salaries. Which of the following is the MOST likely control failure?
Medium463Which THREE of the following are essential elements of an emergency change request? (Select three.)
Hard464An IS auditor is reviewing an organization's key management program. Which of the following is the GREATEST risk associated with using a single key for both encryption and decryption of sensitive data?
Hard465An IT steering committee is reviewing a proposal for a new customer relationship management (CRM) system. What is the committee's MOST important role?
Medium466Which of the following is the PRIMARY purpose of a business impact analysis (BIA)?
Easy467An auditor discovers that a financial institution's IT department uses a decentralized model, with each business unit managing its own applications. What is a PRIMARY risk of this structure?
Hard468An auditor is selecting a sample of purchase orders for testing. The auditor decides to select every 50th purchase order from a list. This is an example of:
Medium469Which TWO of the following are types of analytical procedures used in an IS audit? (Select two.)
Medium470Which THREE of the following are key performance indicators (KPIs) commonly used to measure IT performance? (Select THREE.)
Hard471Which THREE of the following are common challenges when integrating a software package with existing legacy systems? (Select exactly three.)
Hard472An organization is implementing a large ERP system. The project manager is concerned about segregation of duties conflicts. Which THREE controls should the IS auditor recommend to mitigate segregation of duties risks during implementation? (Select THREE)
Hard473An IS auditor is reviewing an agile software development project. Which of the following would be the BEST evidence that adequate controls are in place for user acceptance?
Medium474Match each log type to its typical content.
Medium475An IT manager needs to ensure that the organization's IT resources are used efficiently. Which of the following is the BEST metric to measure IT resource utilization?
Easy476Which TWO of the following are BEST indicators that a system development project is at risk of failure?
Hard477During a spiral SDLC project, the IS auditor should focus on which aspect as the primary risk?
Hard478During a firewall rule review, an IS auditor identifies several rules that allow any-to-any traffic. Which THREE of the following should the auditor recommend as the MOST appropriate actions?
Hard479An organization experiences a critical system failure during non-business hours. The IT team discovers that the last full backup was 48 hours ago, and the incremental backups for the past 24 hours are corrupted. The recovery time objective (RTO) for this system is 4 hours, and the recovery point objective (RPO) is 1 hour. Which of the following is the MOST immediate concern?
Medium480Which of the following is a key advantage of using an iterative SDLC model over a waterfall model?
Easy481An organization has a clean desk policy. Which of the following is the BEST audit procedure to test compliance with this policy?
Medium482A multinational organization operates a critical ERP system on a virtualized infrastructure across two data centers (primary and DR). The primary data center is located in Region A, and the DR site in Region B, 500 km away. The ERP database is 2 TB and changes at an average rate of 10 MB per second. The organization uses synchronous replication between the two sites over a dedicated 10 Gbps WAN link. During a recent disaster simulation, the IT team observed that the replication link experienced 15 ms latency, causing the primary database to slow down significantly under peak load, ultimately missing the defined RTO of 4 hours for full failover. The business has an RPO of 15 minutes. The CISO asks the IS auditor to recommend a solution that balances cost and performance while meeting both RTO and RPO. Which of the following is the BEST course of action?
Hard483A mid-sized company is upgrading its legacy financial system to a new cloud-based ERP. The project manager has decided to use a big-bang cutover approach to minimize costs and time. During the first week post-go-live, users report that several critical reports are generating incorrect totals. An initial investigation reveals that the data mapping from the old system to the new system was not fully validated. Which of the following should the IS auditor recommend as the most appropriate corrective action?
Easy484Which of the following is the PRIMARY benefit of using a prototype during system development?
Easy485An organization's IT department is considering a shift from insourcing to co-sourcing for application development. What is a PRIMARY advantage of co-sourcing?
Medium486An organization is implementing a data masking solution for a non-production database. Which of the following is the MOST important requirement?
Medium487An organization has a policy requiring annual information security awareness training for all employees. During a recent audit, it was found that 20% of employees had not completed the training. What is the BEST course of action for the IT governance committee?
Easy488An IT auditor is reviewing the problem management process. The IT team maintains a repository of known errors with documented workarounds. Which component of problem management is this?
Medium489Which THREE of the following are common challenges when implementing a bring-your-own-device (BYOD) policy that affect information systems operations? (Select exactly 3.)
Hard490Which TWO of the following are essential controls to ensure data integrity during a cloud migration project?
Medium491Which of the following are effective controls to protect sensitive data in use? (Choose TWO.)
Easy492A company outsources its data center operations to a third-party provider. Which of the following is the MOST important control to include in the outsourcing contract?
Medium493An organization is planning to implement a data loss prevention (DLP) solution to protect sensitive data. Which THREE of the following are essential steps to ensure the effectiveness of the DLP program?
Hard494Which THREE of the following are commonly used data encryption standards? (Choose three.)
Easy495An IS auditor is reviewing logical access controls for a critical application. Which of the following is the MOST important control to detect unauthorized access?
Medium496An IS auditor is reviewing change management for a financial application. Which TWO of the following findings would most likely indicate a control weakness?
Hard497A multinational corporation's IT audit reveals that the IT department uses a single instance of an ERP system for all subsidiaries. Which COBIT 2019 governance system component is MOST relevant to address the risks of this centralized approach?
Hard498An IS auditor is reviewing an agile software development project. Which TWO controls should the auditor expect to see in place?
Medium499Which of the following is the most important factor to consider when determining sample size for a compliance test?
Easy500An organization is implementing a data classification policy and needs to assign ownership for sensitive data. Which of the following is the most appropriate role to assign as the data owner?
Medium501A multinational corporation is replacing its legacy on-premises customer relationship management (CRM) system with a new cloud-based CRM solution. The project involves migrating data from the old system, customizing the new system to match business processes, and integrating with an existing enterprise resource planning (ERP) system. The project has a tight deadline of six months. During the planning phase, the project team decides to use a waterfall methodology because the requirements are well-defined. However, three months into the project, the business users request significant changes to the customer data fields, which were not originally specified. The project manager is concerned that accommodating these changes will delay the project. The integration with the ERP system is also proving more complex than anticipated, with data mapping errors causing delays. The go-live date is fixed due to the end-of-support for the legacy system. What is the BEST course of action for the project manager?
Hard502A company is in the process of acquiring a new customer relationship management (CRM) system. During which phase of the systems development life cycle (SDLC) should the business requirements be formally documented?
Easy503An organization uses risk-based authentication (RBA) for user access. Which of the following factors would MOST likely trigger a step-up authentication?
Medium504An IS auditor is evaluating the effectiveness of a security awareness program. Which of the following metrics would BEST indicate that the program is achieving its objectives?
Medium505An organization's IT policy review cycle is set to every two years. However, a new regulation requires immediate changes to data retention policies. What is the best course of action?
Medium506An IS auditor is auditing the user access management process for a large healthcare organization that uses an electronic health records (EHR) system. The organization has 5,000 users including doctors, nurses, and administrative staff. The auditor reviews a sample of access requests and finds that 20% of the requests were approved by the user's manager but the approval was not documented in the system. The auditor also finds that there is no periodic review of user access rights. The IT security manager states that users are automatically provisioned based on their role in the HR system, and that access reviews are performed manually by managers but not documented. What is the auditor's BEST recommendation to address the most significant risk?
Medium507Which TWO of the following are key responsibilities of an IT steering committee?
Medium508A project team is using a prototyping approach for a new system. Which of the following is the BEST control to ensure the prototype accurately reflects user needs?
Medium509Which of the following best describes the primary advantage of using statistical sampling over non-statistical sampling in an IS audit?
Hard510During a disaster recovery test, the IS auditor observes that the alternate site uses a warm site configuration. Which of the following is a characteristic of a warm site?
Hard511When implementing a data classification policy, which of the following roles is PRIMARILY responsible for assigning classification labels to data?
Easy512During a software asset management (SAM) audit, the IS auditor discovers that the organization is using software versions that are no longer supported by the vendor. What is the primary risk?
Medium513An IS auditor is reviewing the system development life cycle (SDLC) for a custom application. The project manager has decided to skip the design phase and proceed directly from requirements to coding. Which of the following risks are MOST likely to increase as a result? (Choose two.)
Hard514An organization is planning to deploy a web application firewall (WAF) to protect a critical application. Which deployment mode should be used to ensure that the WAF can block malicious traffic without introducing a single point of failure?
Medium515During a system development project, the IS auditor notes that code reviews are performed only after the code is unit tested. Which of the following is the MOST significant risk associated with this practice?
Medium516An IS auditor is assessing the risk of material misstatement in a financial system. The auditor determines that inherent risk is high, control risk is moderate, and detection risk is low. What is the overall audit risk?
Hard517An IS auditor is reviewing the password policy for a system that processes sensitive financial data. Which of the following is the MOST effective control to mitigate the risk of password cracking?
Hard518In a traditional waterfall SDLC, when should the test plan be developed?
Easy519During an incident response, the IT team isolates a compromised system from the network. Which of the following is the primary purpose of this action?
Easy520A nonprofit organization develops a small online donation platform using a third-party payment gateway. The project team skips formal security testing because of budget constraints. After launch, a security researcher discovers that the application fails to validate input on the donation amount field, allowing manipulation. The nonprofit loses several thousand dollars before the issue is patched. The IS auditor is asked to review the system development process. Which of the following is the PRIMARY finding?
Easy521An IS auditor reviews the exhibit. Which of the following is the most likely cause of the denied traffic?
Easy522Which of the following is an example of a compliance audit?
Easy523Which TWO of the following are HR controls that help mitigate the risk of insider fraud in IT? (Select TWO.)
Easy524An IS auditor is reviewing the change management process for a financial application. Which of the following findings would be of MOST concern?
Medium525A company stores sensitive customer data in a database. To comply with privacy regulations, the data must be anonymized for analytics. Which technique provides the strongest anonymization while preserving data utility?
Hard526Refer to the exhibit. This log entry MOST likely indicates:
Hard527An external auditor is conducting a compliance audit for a company subject to SOX. Which standard is most relevant for this engagement?
Medium528An organization has outsourced its IT help desk to a third-party provider. Which of the following is the MOST critical control to ensure service quality?
Hard529An IS auditor is performing a walkthrough of a purchase-to-pay process. Which of the following is the auditor most likely trying to achieve?
Medium530Refer to the exhibit. A security analyst notices that users on the INSIDE network (10.1.1.0/24) can browse HTTPS websites but cannot resolve domain names. What is the most likely cause?
Hard531An organization is implementing a new IT governance framework. Which of the following is a key component of the COBIT 2019 governance system?
Medium532A financial services company is migrating its core banking system to a public cloud to improve scalability and reduce costs. The project is high-risk due to regulatory compliance requirements (e.g., data residency, audit trails). The IT governance committee has reviewed the project plan and finds that the risk assessment is incomplete – it does not address the potential impact of a cloud provider outage on critical transactions. The committee must approve the project or request changes. The project manager argues that the cloud provider's SLA guarantees 99.99% uptime and that additional controls would delay the project. What should the governance committee do?
Medium533An organization is considering acquiring a commercial off-the-shelf (COTS) ERP system. Which of the following risks is most effectively mitigated by including a contractual clause for audit rights?
Hard534An organization wants to protect its intellectual property from unauthorized disclosure via email. Which control should be implemented?
Easy535Based on the exhibit, which control is most likely missing to prevent this type of event?
Hard536During a post-implementation review of a new customer relationship management (CRM) system, the IS auditor finds that the system is processing transactions slower than anticipated. What is the BEST initial course of action for the auditor?
Medium537An IT manager is reviewing the access control model for a financial application. The policy requires that no single person can approve a transaction. Which access control principle does this policy enforce?
Medium538An organization has recently implemented a cloud-based identity provider (IdP) for single sign-on (SSO) across all SaaS applications. Users authenticate using their corporate credentials via SAML 2.0. After a week, the IT security team notices a significant increase in failed login attempts from various IP addresses targeting a specific user account. The helpdesk reports that the user, a senior executive, has not complained about any issues. The security team investigates and finds that the account lockout policy is set to 5 failed attempts within 15 minutes, after which the account is locked for 30 minutes. The failed attempts are occurring in bursts of 4, then stopping, then resuming from different IPs. The organization uses conditional access policies that require MFA from unknown locations. However, the failed attempts appear to be stopped at the authentication prompt and never reach the MFA stage. What is the most likely explanation and the best course of action?
Hard539Based on the exhibit, what is the MOST appropriate action for IT management?
Easy540An IS auditor is assessing the effectiveness of network segmentation for a payment card processing environment. Which of the following is the PRIMARY benefit of network segmentation in meeting PCI DSS requirements?
Easy541Which TWO of the following are characteristics of the iterative SDLC model?
Easy542A hospital is implementing a new electronic health record (EHR) system. The project team includes clinicians and IT staff. During integration testing, the system fails to exchange lab results with the existing legacy system due to format mismatches. The IT team suggests developing a custom interface. The clinical team is concerned that any custom solution may not comply with health data privacy regulations. The project sponsor pressures the team to quickly fix the issue to avoid delays. The IS auditor is reviewing this situation. What is the MOST appropriate action for the auditor to recommend?
Medium543An IS auditor is reviewing the vulnerability management program. The auditor notes that a critical vulnerability was identified in a production system six months ago and has not been patched due to a business impact assessment. Which of the following should the auditor examine NEXT?
Medium544Order the steps for responding to a security incident in the correct sequence.
Medium545Which TWO of the following are essential components of a business case for a new system?
Easy546An organization is developing a new customer portal. The development team wants to use an agile methodology. Which of the following is a key benefit of using agile for this project?
Easy547In a RACI matrix for an IT process, which role should be assigned to the person who ultimately approves the outcome and is held accountable for its success?
Medium548An organization uses a chargeback model to allocate IT costs to business units. What is a PRIMARY benefit of this approach?
Easy549An IS auditor is reviewing firewall rule sets and discovers a rule that permits any source IP to access the internal database server on TCP port 1433 (Microsoft SQL). The rule was documented as a temporary measure but has been in place for 18 months. What is the auditor's BEST course of action?
Hard550An IS auditor is assessing the risk of a new financial application. The auditor determines that inherent risk is high due to complex transactions, but control risk is low because of strong automated controls. If detection risk is set at 5%, what is the audit risk?
Medium551Which TWO of the following are primary objectives of a data loss prevention (DLP) strategy?
Hard552Match each testing technique to its description.
Medium553Which of the following is the PRIMARY purpose of performing a walkthrough during the audit planning phase?
Medium554During a post-implementation review of a new ERP system, the IS auditor identified that the project was delivered within budget but user satisfaction scores are low. Which THREE areas should the auditor examine further?
Hard555An IS auditor is reviewing an organization's vulnerability management program. The auditor notes that a critical vulnerability in a key application has not been patched for 90 days, and there is no documented risk acceptance. What should the auditor do FIRST?
Hard556Which of the following is the PRIMARY purpose of a business impact analysis (BIA) in business continuity planning?
Easy557In an agile development environment, an IS auditor reviews the backlog and finds that security requirements are not explicitly included. What is the best recommendation?
Hard558During an audit of a privileged access management (PAM) system, the auditor finds that privileged sessions are recorded but not reviewed. What is the primary risk?
Hard559A security review of the above Apache configuration identifies a critical vulnerability. Which of the following is the MOST significant issue?
Hard560An organization uses the access list above on its perimeter firewall. Which of the following is a valid conclusion?
Easy561During an agile software development project, which of the following events provides the best opportunity for the IS auditor to assess the effectiveness of controls implemented in the current sprint?
Easy562An organization is migrating sensitive customer data to a public cloud. Which of the following encryption strategies provides the STRONGEST protection against data exposure to the cloud provider?
Medium563Refer to the exhibit. An administrator applied this ACL to a VLAN interface. The server at 10.0.0.100 hosts a web application. What is the effect of this ACL?
Hard564An organization's IT strategy is not aligned with business strategy due to lack of communication. Which of the following would BEST improve alignment?
Hard565An organization performs daily full backups of its critical database. The recovery time objective (RTO) is 4 hours. During a disaster, it takes 6 hours to restore the database. What is the most likely cause?
Easy566During an audit of privacy controls, the IS auditor discovers that the organization processes personal data of EU residents but has not appointed a Data Protection Officer (DPO). Which regulation is MOST likely being violated?
Hard567During a vendor evaluation for a critical system, the IS auditor notes that the vendor's SOC 2 report includes an adverse opinion. What should be the auditor's PRIMARY recommendation?
Medium568An organization is implementing a backup strategy for its critical database. The database is updated continuously during business hours, and the recovery point objective (RPO) is 15 minutes. Which backup method should be used to meet the RPO while minimizing backup storage and performance impact?
Medium569Which TWO of the following are guiding principles of ITIL 4? (Select TWO)
Medium570During the fieldwork phase, an IS auditor discovers that a control is not operating as designed. The auditor reperforms the control and finds that it is effective. Which of the following conclusions is MOST appropriate?
Hard571Which THREE of the following are commonly accepted practices for securing mobile devices in an enterprise environment?
Medium572A multinational corporation operates in a highly regulated industry. The IT governance framework includes a risk appetite statement approved by the board. Recently, the company suffered a significant data breach due to an unpatched vulnerability that had been identified three months earlier. The IT audit found that the vulnerability was reported to the IT department but was not prioritized for remediation because it was deemed low risk by the IT operations team. The incident response plan was not activated because the breach was not initially detected. The board wants to strengthen governance to prevent recurrence. The most effective course of action for the auditor to recommend is:
Hard573An organization is implementing a new identity management system. Which testing approach is MOST effective for verifying access controls?
Medium574An organization is considering whether to build a custom application or purchase a commercial off-the-shelf (COTS) product. Which of the following factors is MOST important when deciding to build rather than buy?
Medium575A security architect is designing a data classification schema for a multinational corporation. Which combination of factors is MOST critical for determining the classification level of a data asset?
Hard576An organization uses a risk-based audit approach. For a high-risk area, the auditor decides to perform 100% testing instead of sampling. Which of the following is a valid reason for this decision?
Hard577An IS auditor is planning an audit of a financial application. The auditor wants to ensure that audit effort is focused on areas with the highest risk. Which approach should the auditor adopt?
Medium578Which of the following is a key performance indicator (KPI) for IT service management?
Easy579An organization is implementing a new payroll system using an agile methodology. Which TWO of the following are the MOST important controls for the IS auditor to assess?
Medium580An organization is implementing a new identity management system. Which THREE of the following are essential requirements for the system?
Medium581An organization outsources its IT help desk to a third-party vendor. Which clause is MOST important for the IS auditor to verify in the contract to ensure the organization can assess the vendor's controls?
Medium582An IS auditor is reviewing the access recertification process for a financial institution. The process requires users and their managers to confirm access rights quarterly. During the review, the auditor finds that recertifications are consistently completed late, with an average delay of 45 days. Additionally, terminated employees' access is not always removed promptly, and there are no compensating controls. Which of the following is the MOST significant risk arising from these findings?
Medium583An IT manager submits a request to change the firewall configuration during business hours. According to best practices for change management, what should be done FIRST?
Easy584An IS auditor is reviewing the organization's data inventory process for privacy compliance. Which TWO of the following are the MOST important elements that should be included in the data inventory?
Medium585An IS auditor is reviewing an agile project. Which THREE of the following are controls the auditor should evaluate?
Hard586Which TWO of the following are types of statistical sampling methods? (Select TWO.)
Medium587An organization's IT department implemented a new change management process that requires all changes to be approved by a change advisory board (CAB). A critical security patch needs to be deployed within 2 hours to address an active zero-day vulnerability. The change request was submitted but the CAB is not scheduled to meet for another 24 hours. What is the BEST course of action?
Medium588Which TWO of the following are the MOST effective controls to prevent unauthorized access to a data center's server room? (Choose two.)
Hard589Which of the following is the PRIMARY purpose of conducting a privacy impact assessment (PIA) before implementing a new system that processes personal data?
Easy590An IS auditor is reviewing the logical access controls of an enterprise resource planning (ERP) system. The auditor finds that terminated employees' accounts are disabled but not deleted. What is the PRIMARY risk associated with this practice?
Easy591Which of the following is the PRIMARY purpose of an IT governance framework?
Easy592Arrange the steps to implement a patch management process in the correct order.
Medium593During an SDLC audit, the IS auditor finds that security requirements were not formally documented during the requirements phase. Which of the following is the BEST recommendation to mitigate the associated risk?
Medium594An organization is developing a business continuity strategy. Which THREE of the following are essential components of a comprehensive BC strategy?
Hard595Which of the following is the most reliable form of audit evidence?
Medium596Which THREE of the following are common risks associated with the prototyping methodology?
Hard597Which of the following is a primary advantage of fixed-price contracts in systems acquisition?
Easy598Which of the following is a key principle of corporate governance of IT according to ISO/IEC 38500?
Easy599In a large enterprise, the IT department uses a RACI matrix for its change management process. The change manager is responsible for executing the change, but which role is typically accountable for the success or failure of the change?
Hard600During which phase of the audit process does the auditor perform procedures such as inquiry, observation, and inspection?
Easy601An organization has a disaster recovery plan that includes a hot site. During a full interruption test, the recovery team discovers that the hot site's network configuration is incompatible with the production environment. What is the most likely root cause?
Hard602Which TWO of the following are common risks in the procurement of custom-developed software?
Medium603After a security incident, an organization discovers that an employee accessed sensitive files without authorization. Which of the following is the most effective preventive control to reduce the risk of such unauthorized access?
Medium604During an audit, the IS auditor identifies that a system access control deficiency could lead to unauthorized modification of financial data. The deficiency does not have a compensating control. How should the auditor classify this finding?
Medium605Which type of audit evidence involves the auditor independently performing a control procedure to verify its effectiveness?
Medium606Order the steps for performing a disaster recovery test in the correct sequence.
Medium607An organization is implementing a new cloud-based HR system. The project sponsor wants to skip regular project status meetings to speed up delivery. Which THREE of the following are the MOST significant risks of eliminating these meetings?
Hard608An IS auditor is assessing the organization's compliance with privacy regulations regarding cross-border data transfers. Which TWO of the following are acceptable mechanisms to legitimize such transfers under the GDPR?
Medium609Which THREE of the following are valid reasons for implementing a service level management process? (Select THREE.)
Hard610Which TWO of the following are physical security controls to prevent unauthorized access to a data center?
Medium611During a disaster recovery test, the team discovers that the backup server is unable to restore data because of incompatible software versions. Which TWO controls should have been implemented to prevent this?
Easy612An IS auditor is reviewing the physical access controls at a data center. Which of the following is the MOST effective control to prevent tailgating?
Easy613An IS auditor is reviewing the audit documentation from a prior year and finds that a material weakness was reported but not remediated. According to ISACA standards, which audit phase should address this?
Hard614Which of the following is a potential risk in this RACI matrix?
Medium615An IS auditor is reviewing the system development life cycle (SDLC) methodology. Which phase should include the development of detailed test plans?
Easy616During a post-implementation review of a system, an IS auditor finds that the actual transaction processing time is 30% slower than projected. What should the auditor recommend FIRST?
Medium617An organization is implementing a new financial system using the waterfall SDLC model. Which of the following is the MOST critical control to ensure that business requirements are met?
Easy618A government agency is developing a case management system for law enforcement. The project follows an agile approach, releasing iterations every two weeks. During a sprint demo, users discover that the system does not redact personally identifiable information (PII) in documents shared with external parties, violating privacy laws. The development team says they planned to add redaction in a future sprint. The product owner wants to prioritize PII redaction immediately. The project manager is concerned that this will disrupt the release schedule. The IS auditor is assessing the project's risk management. Which of the following is the BEST recommendation?
Hard619Which of the following BEST describes the role of threat modeling in the design phase of the SDLC?
Medium620An organization is deploying a major system upgrade. The change request has been approved by CAB, but the deployment plan does not include a rollback procedure. As an IS auditor, what should you recommend?
Hard621An IT manager notices that the CPU utilization of a critical server consistently exceeds 90% during peak hours. Which is the BEST course of action?
Medium622Which of the following is the PRIMARY objective of a penetration test?
Easy623An IS auditor is reviewing the human resources practices in the IT department. Which THREE of the following controls are most effective in reducing the risk of fraud?
Hard624A company performs daily full backups of its database and weekly incremental backups. The backup retention policy requires keeping full backups for 30 days and incremental backups for 7 days. An auditor reviews the backup schedule. Which backup type provides the fastest restore?
Medium625Which of the following is the PRIMARY purpose of an IT strategy committee?
Easy626During the follow-up phase of an audit, the auditor discovers that a previous finding has not been remediated. What is the auditor's BEST course of action?
Medium627In a waterfall SDLC, when should user acceptance testing (UAT) typically occur?
Easy628An auditor is evaluating the IT governance framework of a large bank. Which TWO of the following are components of COBIT 2019's governance system? (Select TWO.)
Medium629An IS auditor is evaluating the reliability of audit evidence. Which TWO of the following are characteristics of reliable audit evidence?
Easy630An organization is implementing a new release management process. Which TWO activities are essential components of a successful release?
Easy631An organization is planning to replace its legacy accounting system with a commercial off-the-shelf (COTS) software package. Which of the following is the PRIMARY risk of using a COTS solution?
Easy632A healthcare organization has implemented a data classification policy with three levels: Public, Internal, and Restricted. The IT department recently received a report of a potential data breach. An internal auditor discovered that a database containing Protected Health Information (PHI) classified as Restricted was accessible via a web application that did not enforce encryption in transit. The web application uses HTTPS, but the auditor found that the connection was downgraded to HTTP due to a misconfiguration in the load balancer. Additionally, the database logs show that an external IP address queried the database for thousands of patient records over a two-hour period. The database was configured to allow only specific internal application servers, but the firewall rule was incorrectly set to allow connections from any IP address. The security team needs to determine the most effective immediate action to prevent further unauthorized access and protect the data. Which course of action should the security team take FIRST?
Hard633An organization has outsourced its IT operations to a third-party provider. The IS auditor is planning an audit of the outsourced services. What is the most appropriate source of audit evidence?
Easy634Refer to the exhibit. A developer is inserting a new employee record. What is the cause of this error?
Easy635Which of the following is a key objective of the design phase in the SDLC?
Easy636Which TWO of the following are phases of the audit process? (Select two.)
Easy637An organization's IT service desk is the single point of contact for all incidents. The SLA for resolving P2 incidents is 8 hours. The auditor finds that the service desk frequently reassigns P2 incidents to second-level support without updating the incident record, causing delays in resolution. The average resolution time for P2 incidents is 10 hours. What is the primary control weakness?
Hard638An IS auditor is reviewing the data subject rights fulfillment process for GDPR compliance. Which TWO of the following are required to be completed within the one-month response period?
Medium639Which IT sourcing model involves using an external provider to manage some IT functions while retaining others in-house?
Easy640Based on the exhibit, the IS auditor is reviewing access to the payroll folder. Which of the following is the MOST significant finding?
Hard641An organization uses a third-party cloud service for data storage. Which of the following is the BEST way to ensure data confidentiality in the event of a cloud provider breach?
Hard642A company requires employees to use smart cards for facility access. Which additional control would BEST prevent tailgating?
Easy643During a change management audit, the IS auditor notes that an emergency change was implemented to fix a critical security vulnerability. Which of the following should the auditor expect to find in the change documentation?
Medium644An organization's IT security policy requires background checks for all IT staff handling sensitive data. Which of the following is the PRIMARY reason for this requirement?
Medium645A company has been developing a custom inventory management system using Scrum. In the current sprint, the team discovered that the integration module with the legacy ERP system has severe performance issues: under peak load, transactions time out and fail. The product owner is concerned because the release is scheduled in two weeks. The development team estimates that a proper fix will take three weeks. A similar issue occurred in a previous sprint and was temporarily resolved by reducing the number of concurrent transactions, which lowered performance but kept the system operational. The stakeholders are anxious about the deadline because the legacy ERP will be retired shortly after the planned go-live. What is the BEST action for the team to take?
Hard646The IT governance objective 'Evaluate-Direct-Monitor' in COBIT 2019 is primarily associated with which role?
Easy647A retail company is merging with a competitor. The IT departments of both organizations have different IT governance structures: Company A uses a centralized model with strict change management, while Company B uses a decentralized model with autonomous business unit IT. The CIO has been tasked with integrating the IT functions post-merger. The board expects cost synergies and improved service levels. The integration team is facing resistance from Company B's business heads who fear loss of agility. The CIO needs to propose a governance model for the merged entity. Which approach would BEST meet the board's expectations while addressing resistance?
Medium648An IS auditor is assessing the effectiveness of an organization's IT governance framework. Which THREE of the following are key indicators of a mature governance process?
Hard649The exhibit shows a log entry from a domain controller. The IS auditor is investigating account lockout issues. What is the MOST likely cause of this event?
Hard650An IS auditor is reviewing a system development project and notices that user acceptance testing (UAT) is being conducted in the production environment due to lack of a separate test environment. What is the primary risk?
Medium651An IS auditor is evaluating the effectiveness of a backup strategy for a critical database. Which TWO of the following are essential controls to ensure data recoverability?
Medium652An organization has decentralized IT management with each business unit making its own technology decisions. Which of the following is the BEST way to maintain enterprise-wide governance?
Hard653Which TWO of the following are examples of detective controls? (Choose two.)
Medium654A company's backup policy requires that backup media be stored offsite. Which of the following is the PRIMARY reason for this requirement?
Easy655An organization is disposing of old servers. The IS auditor reviews the asset disposition process and finds that hard drives are being erased using a standard format command. What is the auditor's primary concern?
Hard656During an audit of a cloud service provider, the IS auditor finds that the provider's datacenter access logs show multiple successful logins by an employee during non-business hours over several weeks. The employee works in the sales department. What should the auditor do first?
Medium657An organization is considering replacing its legacy financial system with a new ERP solution. Which of the following is the PRIMARY advantage of purchasing a commercial off-the-shelf (COTS) ERP package over building a custom system?
Easy658An e-commerce company stores customer payment card data in a tokenized database. The tokenization system replaces credit card numbers with tokens, and the actual card numbers are stored in a separate, highly restricted vault. The company is audited for Payment Card Industry Data Security Standard (PCI DSS) compliance. During the audit, it is discovered that the tokenization system sometimes fails due to high load, causing the application to fall back to storing actual card numbers temporarily. This fallback mechanism was not documented or approved. The company also uses the same encryption key for the vault as for other non-sensitive data. The auditor identifies several non-compliances. Which of the following should the company prioritize to remediate?
Medium659During an ERP implementation, the project team decides to customize the software to align with existing business processes. Which of the following risks is MOST likely to increase as a result of extensive customization?
Medium660Which of the following is a key difference between internal and external auditors?
Medium661An organization is implementing a disaster recovery plan. The DR team wants to test the plan with minimal risk and without impacting production operations. Which type of test is most appropriate?
Medium662An organization has defined an RTO of 4 hours for its critical financial system. During a disaster recovery test, the system was recovered in 3.5 hours, but data loss was 30 minutes. Which metric is most directly addressed by the recovery time?
Easy663During the planning phase of an IS audit, the auditor identifies that the organization has recently implemented a new ERP system. The audit team has limited experience with this ERP. Which of the following is the BEST course of action?
Medium664Which of the following is the PRIMARY benefit of conducting a tabletop exercise for disaster recovery?
Easy665You are an IS auditor reviewing the remote access configuration for a medium-sized enterprise. The company uses a VPN concentrator to allow employees to connect from home. The VPN is configured with IPsec using pre-shared keys (PSK) and requires no multi-factor authentication. Employees use company-issued laptops with full disk encryption. The VPN logs show that connections are coming from a wide range of IP addresses, including some from countries where the company has no business operations. The IT manager argues that the PSK is changed monthly and that full disk encryption mitigates any risk. However, during the audit, you find that the PSK is stored in a shared document on an internal file server accessible to all employees. Additionally, the VPN concentrator uses a single PSK for all users. Which of the following is the MOST critical finding?
Hard666An IS auditor is planning an audit of a newly implemented financial system. Which of the following is the PRIMARY consideration when determining the audit scope?
Easy667Refer to the exhibit. An IS auditor reviewing backup logs notices this error. Which of the following is the MOST likely root cause?
Medium668During an audit, an IS auditor finds that a system administrator has not taken mandatory vacation in three years. Which control is most likely being violated?
Hard669Which TWO of the following are essential elements of a business continuity plan (BCP) for a newly developed system?
Easy670An IT policy exception is requested to allow a legacy system that cannot be patched to remain in operation. What is the BEST way to manage this exception?
Medium671Refer to the exhibit. A cloud load balancer uses this JSON configuration. A request arrives from source IP 10.0.1.100 to port 80. Which backend pool will receive the request?
Medium672An organization is acquiring a third-party SaaS application. Which of the following should be included in the contract to ensure data protection?
Medium673Refer to the exhibit. An IT operator receives this error message from an automated backup job. What is the MOST likely cause of this failure?
Hard674An organization has the storage bucket policy shown. Which of the following is the MOST likely intent of this policy?
Medium675You are the lead IT auditor for a multinational corporation that recently completed a merger with another company. During the post-merger integration audit, you discover that the acquired company's legacy HR system contains sensitive personal data of 20,000 employees and has been directly accessible from the internet for the last 18 months. The system runs on an unsupported operating system (Windows Server 2008) and uses a custom-built application with no logging enabled. The acquired company's IT manager argues that the server is isolated behind a firewall and has never been compromised. However, your review of firewall logs shows numerous connection attempts from unknown IP addresses. The integration team plans to decommission this system in three months. You need to determine the appropriate audit response. Which of the following should you do NEXT?
Hard676An organization classifies IT incidents based on severity. A critical financial application is unavailable, impacting all users. According to ITIL best practices, which severity level should this incident be assigned?
Medium677Which type of disaster recovery test involves a full switch-over from the primary site to the alternate site, resulting in actual disruption of normal operations?
Easy678An IS auditor is reviewing the logical access controls for a financial application. The auditor notices that user access reviews are performed annually by the application owner, but there is no documentation indicating that managers confirm the continued need for access. Which of the following is the MOST significant risk associated with this finding?
Medium679During an audit of an organization's change management process, the IS auditor selects a sample of 50 change requests from a population of 500. The auditor finds that 3 of the 50 did not have proper approval. What is the estimated error rate in the population?
Medium680An organization is adopting ITIL 4 to improve its service management practices. Which guiding principle emphasizes understanding how different components work together to deliver value?
Hard681Refer to the exhibit. Which of the following services is accessible from the internet to host 10.1.1.100?
Medium682An organization is implementing a business continuity plan (BCP). Which of the following is the PRIMARY purpose of conducting a business impact analysis (BIA)?
Easy683An administrator sees the above error after a failed backup job. What is the MOST likely cause?
Medium684An organization has a policy requiring strong passwords. Which additional control is most effective at preventing credential stuffing attacks?
Easy685Which document is typically included in the permanent file of audit documentation?
Easy686An auditor is reviewing IT policy compliance and finds that a critical policy was last updated three years ago. The organization has undergone significant changes. What is the auditor's PRIMARY concern?
Hard687An IS auditor is reviewing a software development project that follows the waterfall model. Which of the following is the MAIN advantage of this methodology?
Easy688Which THREE of the following are responsibilities of the board of directors regarding IT governance? (Choose three.)
Hard689During a change management audit, an IS auditor finds that a critical system change was approved by the change manager without a CAB meeting. The change was categorized as a standard change. Which of the following should the auditor do FIRST?
Medium690An auditor is reviewing the encryption strategy for a healthcare application that stores protected health information (PHI) in a database. The database currently uses transparent data encryption (TDE). What is a key risk associated with TDE?
Medium691Refer to the exhibit. A tester executes test case TC-101 and records the result shown. What is the NEXT appropriate step in the testing process?
Medium692A small business lacks formal IT governance. What is the FIRST step to establish governance?
Easy693An organization is implementing a new IT governance framework. Which of the following is the BEST approach to ensure alignment between IT strategy and business goals?
Medium694When implementing a commercial off-the-shelf (COTS) software package, which of the following is the MOST important activity to ensure the software meets business requirements?
Easy695Which TWO of the following are examples of administrative controls for information security?
Easy696An organization uses the policy shown. Which of the following is an omission in the policy?
Hard697An IS auditor is evaluating the design of controls over a new financial system. Which of the following is the BEST approach to assess control design?
Hard698During a penetration test, a tester discovers that an application stores passwords using a reversible encryption algorithm. Which of the following is the BEST remediation?
Medium699According to ITIL 4, which guiding principle emphasizes understanding the current state before making improvements?
Medium700An IS auditor is reviewing the change management process for a financial institution. The auditor finds that emergency changes bypass normal approval but are documented and reviewed within 48 hours. Which of the following is the BEST recommendation?
Hard701A company is experiencing frequent server crashes due to memory leaks. The operations team has implemented a monitoring solution. Which of the following is the BEST indicator to trigger an automated failover to a standby server?
Easy702An organization is adopting COBIT 2019. Which TWO of the following are components of the governance system?
Medium703During system development, the project team discovers that the original requirements are incomplete. What is the BEST course of action?
Medium704An organization is implementing an automated job scheduling system. Which of the following is the PRIMARY benefit of using dependency management in job scheduling?
Medium705An IS auditor is reviewing a change management process. A developer made an emergency change directly to production without following the standard change approval process. The change was later documented as a normal change. Which control weakness is MOST indicated by this scenario?
Medium706A multinational corporation is adopting a hybrid cloud strategy. The IT governance board must decide on a framework to ensure alignment with business objectives and regulatory compliance. Which framework is MOST appropriate?
Hard707Based on the backup logs, the backup administrator notices that the incremental backup job failed due to insufficient storage. Which TWO actions should the administrator take to resolve the immediate issue and prevent recurrence?
Hard708An IT auditor is reviewing the alignment of IT with business strategy. Which THREE of the following are indicators of effective IT strategy alignment? (Select THREE.)
Hard709During an audit of a cloud service provider, the IS auditor discovers that the provider's data center access logs show an employee accessing the production environment outside of normal business hours without a change request. What should the auditor do FIRST?
Medium710During a spiral SDLC project, the project team has completed a risk analysis and created a prototype. What is the most likely next step in the spiral model?
Hard711Which TWO of the following are examples of analytical procedures used as audit evidence? (Select two.)
Medium712An IS auditor is reviewing the system design phase of a project. Which of the following activities is most important to ensure that security is adequately addressed?
Medium713Which of the following is a characteristic of non-statistical (judgmental) sampling?
Medium714An IS auditor is reviewing the logical access controls for a critical database. Which of the following findings should be considered the HIGHEST risk?
Medium715A company is implementing a new customer relationship management (CRM) system. The project team is currently defining user roles and permissions. Which of the following is the PRIMARY reason to enforce segregation of duties (SoD) within the CRM?
Easy716Which TWO of the following are primary objectives of IT governance as defined by COBIT 5?
Medium717A company's IT service desk receives multiple reports of users being unable to access a cloud-based CRM system. The network team confirms that internet connectivity is working. Which of the following should be the FIRST step in troubleshooting the issue?
Medium718A medium-sized financial services firm recently suffered a ransomware attack that encrypted critical servers and backups. The recovery process took three weeks because the backup tapes were stored in the same building (which was also infected) and the backup software had a vulnerability that allowed the ransomware to delete old backups. The firm's BCP did not account for simultaneous loss of primary and secondary data. As the IS auditor, you are asked to recommend the most effective improvement to the backup strategy to prevent recurrence and improve resilience. Which of the following actions should the firm implement?
Easy719A multinational corporation is implementing a disaster recovery plan for its critical financial systems. The plan includes off-site backups and redundant hardware. During a recent test, the recovery time objective (RTO) was met, but the recovery point objective (RPO) was exceeded by 30 minutes due to delayed data replication. Which of the following is the BEST action to address this issue?
Medium720Which of the following is the PRIMARY purpose of audit working papers?
Easy721During which phase of the waterfall SDLC should security requirements be formally documented and approved by the business owner?
Easy722Which of the following is the primary purpose of conducting a static application security test (SAST) during the development phase of the SDLC?
Easy723An IT auditor is reviewing the capacity management process. Which TWO of the following are key activities that should be performed?
Medium724A healthcare organization is required to comply with HIPAA regulations for data backup and disaster recovery. They operate a primary data center and a colocation facility for disaster recovery. The current backup strategy involves nightly full backups to tape, which are stored off-site monthly. The recovery time for the electronic health record (EHR) system is estimated at 8 hours, but the RTO required by the business is 2 hours. Additionally, the RPO requirement is 15 minutes. The IT manager proposes implementing a continuous data protection (CDP) solution. However, the CFO is concerned about the cost. Which of the following is the BEST argument to justify the CDP investment?
Hard725Refer to the exhibit. An IS auditor is reviewing the architecture. Which of the following is the MOST critical security weakness?
Hard726Match each CISA domain to its focus.
Medium727A company is implementing a new ERP system. The project team plans to use a parallel conversion strategy. What is the PRIMARY advantage of this approach?
Medium728What is the PRIMARY purpose of conducting a feasibility study before acquiring a new information system?
Easy729A company is implementing a privileged access management (PAM) system. Which of the following is the MOST important control to prevent lateral movement after a privileged account is compromised?
Hard730An organization is developing a web application using an Agile methodology. The security team wants to integrate security testing early in the development lifecycle. Which of the following is the BEST approach to achieve this?
Medium731An organization's business continuity plan includes a reciprocal agreement with another company. What is the PRIMARY risk of this arrangement?
Hard732Which TWO of the following are key components of an IT governance framework?
Easy733An IS auditor is preparing working papers. Which of the following items should be included in the permanent file rather than the current file?
Hard734In a RACI matrix, the person who is ultimately accountable for a process outcome is assigned which role?
Easy735In ITIL incident management, which severity level typically indicates a critical incident that severely impacts business operations and requires immediate resolution?
Easy736An IS auditor is using statistical sampling to test a population of 10,000 transactions. The desired confidence level is 95%, and the tolerable error rate is 5%. Which of the following factors would MOST likely increase the required sample size?
Easy737Which of the following disaster recovery test types involves a full switch-over to the alternate site, resulting in actual disruption to normal operations?
Easy738Which of the following is a key performance indicator (KPI) for IT service management?
Easy739An IS auditor is reviewing change management procedures and finds that standard changes are approved by the change manager without CAB review. What is the auditor's BEST conclusion?
Medium740Match each type of access control to its definition.
Medium741During an IT audit, the auditor discovers that the IT department has not conducted a business impact analysis (BIA) for three years. The organization's disaster recovery plan (DRP) is based on the previous BIA. The IT manager argues that the DRP is still valid because no major changes have occurred. What should the auditor recommend?
Hard742During an audit, the auditor uses a sampling method where the population is divided into subgroups, and samples are selected from each subgroup. This method is known as:
Hard743During a data migration from a legacy system to a new ERP, the following log entries were generated. Which TWO issues should the IS auditor flag as high risk?
Easy744A company is migrating its on-premises data center to a public cloud provider. Which of the following is the MOST important control to implement before migration to ensure data security?
Medium745During an ERP implementation, data migration is a critical activity. Which of the following controls would be most effective in ensuring the accuracy and completeness of migrated data?
Hard746Based on the exhibit, which of the following is the MOST likely result of the current firewall configuration?
Hard747A project uses a waterfall model. After design, the team discovers that the requirements have changed significantly. What is the BEST action?
Hard748During an audit of the incident management process, the IS auditor finds that tabletop exercises have not been conducted in the past two years. What is the MOST significant risk associated with this finding?
Medium749An organization has implemented a database activity monitoring (DAM) solution. Which of the following are BEST practices for tuning the DAM to reduce false positives? (Choose TWO.)
Hard750Which of the following backup types copies only data that has changed since the last full backup?
Easy751An IS auditor is evaluating the use of continuous auditing techniques. Which of the following is the most significant benefit of implementing continuous monitoring over traditional periodic audits?
Hard752An IS auditor is reviewing a post-implementation review of a new payroll system. Which TWO findings should most concern the auditor? (Select two.)
Medium753A large enterprise is implementing a backup strategy for a critical database that requires an RTO of 2 hours and an RPO of 15 minutes. The database is 2 TB in size. Which backup method would BEST meet these requirements while minimizing storage costs?
Hard754Which THREE are indicators of a possible data exfiltration attempt via the network? (Choose three.)
Hard755Which of the following is the PRIMARY reason an external audit is considered more independent than an internal audit?
Easy756Which policy hierarchy document provides detailed steps for performing a specific task, such as resetting a user password?
Medium757During the acquisition of a new software package, the procurement team evaluates two vendors. Vendor A offers a lower upfront cost but higher annual maintenance fees. Vendor B has a higher upfront cost but includes three years of maintenance. What is the MOST important factor for the IS auditor to consider?
Medium758Which TWO controls are most effective for protecting data at rest on a database server? (Choose two.)
Medium759An organization outsources its help desk to a third-party vendor. The contract includes a service level agreement (SLA) with response times. The auditor wants to ensure that the organization can monitor vendor performance. Which clause is most important?
Medium760Which of the following types of audit evidence provides the highest level of assurance?
Medium761During the implementation of a new ERP system, the project team discovers that the legacy system data cannot be directly migrated due to incompatible data formats. The project manager proposes building a custom script to extract, transform, and load (ETL) data. Which of the following is the BEST course of action?
Medium762A multinational corporation operates an e-commerce platform hosted in a private cloud environment. The platform consists of web servers, application servers, and a database cluster. The database cluster uses synchronous replication across two data centers (Primary and DR) located 500 km apart. The recovery time objective (RTO) for the platform is 2 hours, and the recovery point objective (RPO) is 15 minutes. During a recent disaster simulation, the primary data center lost power completely. The IT team initiated failover to the DR site. However, the failover process took 3 hours due to a misconfiguration in the DNS failover scripts, and the database was found to be inconsistent because the replication link was broken 30 minutes before the power loss. The team had to restore from a backup that was 4 hours old. After the incident, management requests a review of the disaster recovery plan. Which of the following is the BEST course of action to address the issues identified?
Hard763During the fieldwork phase, an IS auditor uses analytical procedures to compare current year IT expenses to prior year. A significant increase is noted. What should the auditor do next?
Medium764Which physical security control is most effective for preventing unauthorized individuals from tailgating into a data center?
Easy765Match each audit risk component to its definition.
Medium766You are an information security manager for a global financial services company. The organization maintains a hybrid infrastructure with critical customer data stored on an on-premises Oracle database server (DB-SRV-01) and in an AWS S3 bucket (customer-data-prod). At 10:00 AM, the security operations center (SOC) alerts you to an anomalous outbound data transfer from DB-SRV-01 to an unknown IP address in a high-risk country. The transfer started at 9:45 AM and involves 500 MB of data, likely including personally identifiable information (PII). The SOC has already quarantined the server's network egress by blocking all outbound traffic from DB-SRV-01, but the server remains connected to the internal production network. Meanwhile, a separate analysis indicates that the S3 bucket has been accessed via an IAM key that was stolen from a compromised developer workstation three days ago. The key has not been rotated. The incident response team is preparing to act. The primary objective is to protect information assets and minimize data exposure. Given this scenario, which of the following actions should the team take FIRST?
Medium767Refer to the exhibit. A CISA is reviewing this S3 bucket policy. What is the PRIMARY security concern?
Easy768An IS auditor reviews the disposal process of hard drives. Which of the following methods provides the HIGHEST assurance that data cannot be recovered?
Hard769An organization is implementing IT governance based on COBIT. Which THREE of the following are enablers? (Select exactly three.)
Medium770An IS auditor is selecting audit procedures to test controls over user access. Which of the following is an example of a re-performance procedure?
Easy771During a problem management meeting, the team identifies a recurring issue causing multiple incidents. The root cause is known, but a permanent fix is not yet available. Which of the following is the BEST approach to manage this situation until a permanent fix is implemented?
Medium772An IS auditor is testing the effectiveness of a control that involves a manual review of exception reports. The population of exceptions is 5,000 items. The auditor wants to achieve a 95% confidence level with a tolerable error rate of 2%. Which sampling method is MOST appropriate?
Hard773Which backup method copies all data that has changed since the last full backup, regardless of subsequent incremental backups, and is often used to reduce restore time?
Easy774An organization is selecting an alternate site for disaster recovery. The site must have sufficient equipment to resume operations within a few hours, and the organization is willing to share the site with another business. Which type of alternate site is MOST appropriate?
Hard775An IT auditor is reviewing capacity management. The server team monitors CPU utilization and disk space. They receive alerts when thresholds are exceeded. Which practice is most effective for proactive capacity planning?
Easy776An organization is implementing an IT governance framework to align IT with business objectives. Which TWO of the following are primary responsibilities of the IT steering committee?
Medium777Based on the exhibit, which metric would be LEAST relevant to the 'Customer' perspective?
Medium778A large financial institution has a well-defined IT governance framework with a clear organizational structure, policies, and processes. However, the internal audit department has identified that several IT projects are over budget and behind schedule. The project managers blame unclear requirements and scope creep. The IT governance committee meets monthly but reviews projects only at a high level. The auditor's best recommendation to improve project governance is to:
Medium779An IS auditor is evaluating the change management process for a critical financial application. The auditor finds that all standard changes are approved by the Change Advisory Board (CAB). However, emergency changes are approved by the IT manager and later ratified by the CAB. Which of the following is the greatest risk associated with this process?
Hard780An IS auditor selects a sample of 50 transactions from a population of 1,000 using a random number generator. This is an example of which sampling method?
Medium781Which COBIT 2019 governance objective describes the board's responsibility for overseeing IT?
Easy782What is the primary purpose of the planning phase in an IS audit?
Easy783Which TWO of the following are primary objectives of information classification? (Choose two.)
Easy784An IS auditor is reviewing the configuration for a web application. Which of the following is the MOST significant security weakness?
Medium785A small manufacturing company uses a network-attached storage (NAS) device to store design files, financial records, and employee data. The NAS is backed up weekly to an external hard drive that is stored in the same office. The company has no encryption on the NAS or the backup drive. One weekend, the office is burglarized, and both the NAS and the backup drive are stolen. The company had no remote backup. Which of the following would have best protected the data in this scenario?
Easy786During a risk assessment, an IS auditor identifies that the IT department has not performed a business impact analysis (BIA) for critical systems. Which of the following is the MOST significant risk?
Hard787An IS auditor is reviewing the software asset management (SAM) process. The organization uses a mix of commercial off-the-shelf (COTS) and open-source software. The auditor finds that several servers are running end-of-life (EOL) operating systems that are no longer patched. Which TWO risks are most directly associated with this finding?
Medium788An organization is evaluating two vendors for a critical cloud-based ERP system. Which TWO contractual clauses are most important to include to ensure the organization can monitor vendor performance and security? (Select TWO)
Medium789Based on the exhibit, what is the most likely control weakness that allowed this condition?
Medium790Which of the following is a key objective of the COBIT 2019 management objective 'Align, Plan, and Organize' (APO)?
Medium791An IS auditor is reviewing automated job scheduling controls. A critical batch job failed due to a dependency on a previous job that had not completed. The system did not alert operations staff. Which control weakness is most significant?
Hard792During user acceptance testing (UAT) of a new financial system, users report that the system fails to enforce a segregation of duties rule where the same user should not be able to create a purchase order and approve it. The requirement was documented in the functional specifications. Which of the following is the MOST likely cause of this issue?
Medium793Refer to the exhibit. An IS auditor is reviewing backup error logs. The error indicates a failed backup due to a missing file. What is the MOST likely cause?
Easy794During a review of the incident management process, the IS auditor finds that the incident response (IR) team conducts tabletop exercises annually, but the scenarios are limited to malware outbreaks. Which of the following should be the auditor's GREATEST concern?
Hard795An IS auditor is reviewing the incident management process. The organization has a policy that all security incidents must be reported within one hour. However, the average reporting time is four hours. Which is the BEST corrective action?
Hard796An organization is replacing its legacy customer relationship management (CRM) system. Which of the following is the MOST important control to ensure data integrity during the data conversion process?
Easy797Which of the following is a principle of ISO/IEC 38500 for corporate governance of IT?
Easy798An IS auditor is performing a walkthrough of the accounts payable process. Which audit procedure is the auditor primarily executing?
Medium799During data conversion from a legacy system to a new ERP, the project team decides to clean data during extraction but not during loading. What is the PRIMARY risk associated with this approach?
Hard800An organization is implementing an ERP system and is concerned about segregation of duties conflicts. What is the most effective control to address this risk during implementation?
Medium801An IS auditor is evaluating a system development project that uses an outsourced team. The contract allows the vendor to reuse some of the developed code in other projects. What is the auditor's PRIMARY concern?
Hard802When implementing a commercial off-the-shelf (COTS) system, what is the MOST important factor?
Easy803What is the primary security concern in this architecture?
Hard804Which THREE of the following are best practices for managing system testing in an IS development project?
Medium805An IS auditor is evaluating the design of controls over a critical financial application. The auditor performs a walkthrough and identifies that a control is missing but management has compensating controls. Which of the following is the auditor's BEST next step?
Hard806Which TWO of the following are benefits of using a version control system in software development?
Easy807A company outsources its data center operations. Which IT governance practice is MOST critical to ensure the outsourcing arrangement meets business requirements?
Hard808A financial institution is required by regulators to demonstrate that IT controls are effective. Which of the following provides the BEST evidence?
Hard809An IT department uses a balanced scorecard to measure performance. Which metric would BEST reflect the 'customer perspective'?
Easy810Which of the following is a key objective of a post-implementation review?
Easy811Refer to the exhibit. An auditor reviews the security log of a sensitive server. Which of the following is the MOST suspicious event?
Medium812Which THREE of the following are typical phases in the system development life cycle (SDLC)?
Easy813A multinational corporation's data center in the European Union (EU) stores personal data of EU citizens. The company must comply with the General Data Protection Regulation (GDPR), which requires that personal data be protected and that data subjects have the right to erasure ('right to be forgotten'). The company's IT team uses a centralized identity management system that stores user credentials and personal data in an active directory (AD) forest. The AD forest is replicated across multiple data centers worldwide, including a non-EU country. The data protection officer (DPO) is concerned that personal data might be inadvertently replicated to jurisdictions without adequate protection. Which of the following is the most effective way to address this concern?
Hard814An IS auditor is evaluating the controls over program changes. Which TWO of the following are essential controls?
Medium815An IS auditor is reviewing the end-of-life (EOL) software policy. Which THREE risks are associated with running unsupported software? (Select THREE).
Hard816During the design phase of an SDLC, which TWO activities should be performed to ensure security is integrated into the system? (Select TWO)
Easy817An organization's IT service desk categorizes incidents based on severity levels. A P1 incident is defined as a critical system outage affecting all users. Which of the following is the MOST appropriate target for the initial response time for a P1 incident?
Easy818An IT manager is reviewing the service level agreements (SLAs) for a cloud-based email service. The SLA guarantees 99.9% uptime per month. The service experienced an outage of 45 minutes in a 30-day month. Did the service meet the SLA?
Medium819You are the IT audit manager for a multinational corporation. The company recently implemented a new enterprise resource planning (ERP) system using a phased rollout approach. The first phase (finance module) was deployed to three regional offices six months ago. During a post-implementation review, you discovered that the user acceptance testing (UAT) for the finance module was completed in only two days instead of the planned two weeks. The UAT was performed by a small group of power users selected by the project manager, and they reported no critical issues. However, after go-live, several finance staff in one region found that the system does not support a statutory reporting requirement specific to that country, which was not tested. The project manager argues that the requirement was never documented in the business requirements specification. The system has been live for six months, and the missing functionality requires a significant customization that will take three months and cost $200,000. Management is reluctant to fund the customization because the budget is exhausted. As the IT auditor, what is the BEST course of action?
Hard820An IS auditor is testing the effectiveness of a preventive control that rejects invalid transactions. The auditor uses a computer-assisted audit technique (CAAT) to create a set of test transactions. What is the primary risk associated with this approach?
Hard821During the feasibility study for a new inventory system, the project team identifies that the expected benefits are significantly lower than the initial estimates. What is the MOST appropriate action for the IS auditor to recommend?
Easy822An IS auditor is planning an audit of a small organization with limited IT staff. Which approach is most appropriate?
Medium823An organization is adopting ISO/IEC 38500 to govern IT. Which of the following best illustrates the application of the 'Human Behaviour' principle?
Hard824An IT audit revealed that the organization's IT steering committee has not met in the past six months. Which of the following is the MOST likely consequence of this situation?
Medium825Which THREE of the following are components of the ITIL 4 service value system? (Select THREE)
Hard826Which TWO of the following are benefits of establishing an IT steering committee?
Easy827An organization's availability management team reports that a critical server has an MTBF of 720 hours and an MTTR of 4 hours. What is the availability percentage for this server?
Medium828Which TWO of the following are components of an IT balanced scorecard? (Select TWO)
Easy829During which phase of the IS audit process does the auditor perform walkthroughs and test controls?
Easy830Which TWO of the following are primary objectives of the audit planning phase? (Select TWO.)
Easy831Which of the following is the PRIMARY objective of an operational audit?
Easy832An organization uses automated job scheduling with dependency management. A critical nightly batch job failed because a prerequisite job did not complete successfully. The job scheduler automatically attempted to rerun the failed job three times, each time failing due to the same dependency. The operations team was not alerted until the next morning. What control should the auditor recommend to improve this process?
Medium833A system has a Mean Time Between Failures (MTBF) of 500 hours and a Mean Time To Repair (MTTR) of 20 hours. What is the availability of the system?
Hard834An organization is planning to outsource its data center operations. Which of the following governance practices should be implemented to ensure proper oversight?
Medium835During an operational audit, the auditor uses ratio analysis to compare current year expenses to prior years and industry benchmarks. This is an example of which type of audit evidence?
Medium836Which TWO of the following are key elements of an effective incident response plan? (Select exactly 2.)
Medium837Which of the following is the BEST method to ensure that a system development project is completed on time?
Medium838An organization is implementing an enterprise resource planning (ERP) system. The project team plans to migrate legacy data without performing a full reconciliation between source and target systems. As an IS auditor, which of the following should be your PRIMARY concern?
Hard839An organization is performing software asset management (SAM) to ensure license compliance. Which two activities should the auditor verify?
Medium840An organization is developing a mobile app that will handle personal health information (PHI). The security team mandates that data must be encrypted both in transit and at rest. Which of the following implementation strategies BEST ensures compliance?
Hard841Which THREE of the following are common risks associated with outsourcing software development?
Hard842During a review of encryption practices, the IS auditor finds that an organization uses the same encryption key for all customer data at rest. What is the PRIMARY concern?
Medium843An organization uses a hot site as its disaster recovery alternative. Which of the following is the MOST critical consideration when selecting a hot site?
Medium844In the context of IT governance, what is the PRIMARY purpose of an exception management process for IT policies?
Hard845Which THREE of the following are commonly recognized benefits of implementing a formal IT service management (ITSM) framework such as ITIL?
Hard846During an audit of an organization's information security programme, the IS auditor finds that the security awareness training completion rate is 95% but phishing simulation tests show a 30% failure rate. What should the auditor recommend?
Medium847An IT manager is developing a governance policy for change management. Which element is MOST important to include?
Easy848An organization uses a chargeback model for IT services. What is the PRIMARY benefit of this approach?
Easy849Which TWO of the following are key components of an effective information security awareness program?
Easy850In a risk-based audit approach, which of the following BEST describes how an IS auditor should prioritize audit coverage?
Hard851In a DevOps environment, which practice BEST supports auditability?
Hard852An IS auditor is planning an audit of a small organization with limited IT staff. Which of the following is a key consideration for the audit approach?
Hard853An organization is implementing a new IT governance framework to align IT with business objectives. Which framework focuses on the principles of evaluate-direct-monitor?
Easy854Which of the following is a key difference between an internal audit and an external audit?
Medium855An IS auditor is reviewing the availability management process. The auditor calculates that the mean time between failures (MTBF) is 200 hours and the mean time to repair (MTTR) is 20 hours. What is the availability percentage?
Medium856Which THREE of the following are components of a typical IT governance framework?
Hard857During the design phase of a waterfall project, the development team discovers that a key security requirement was omitted from the functional specification. The design has already been partially completed based on the flawed specification. What is the MOST appropriate action?
Hard858An IT auditor is reviewing the release management process. Which of the following is the MOST important control to ensure that new releases do not negatively impact production systems?
Medium859Which TWO of the following are types of audit evidence recognized in IS audit practice?
Easy860An IS auditor is reviewing the disaster recovery plan (DRP) for an e-commerce company that generates 90% of its revenue online. The DRP states that the recovery time objective (RTO) for the transactional database is 4 hours, and the recovery point objective (RPO) is 1 hour. The current backup strategy includes nightly full backups and hourly transaction log backups stored on a local disk array. The backups are then copied to a remote datacenter via a WAN link with an average transfer speed of 10 Mbps. The database size is 500 GB. The auditor calculates that the time to transfer the full backup over the WAN is approximately 12 hours. The organization's management is confident that the DRP is adequate because they have never had to invoke it. What is the auditor's MOST critical finding?
Hard861An IS auditor is reviewing a contract with a vendor for a new financial system. Which of the following clauses is MOST critical to ensure auditability?
Hard862An IS auditor is evaluating the privacy controls of an e-commerce company that collects and processes personal data from customers in multiple jurisdictions, including the European Union (GDPR). The company has a data inventory but has not conducted a privacy impact assessment (PIA) for a new customer analytics platform that processes sensitive data. Which THREE of the following are the MOST critical deficiencies that the auditor should report?
Medium863During an audit, an IS auditor finds that the organization uses a cloud-based identity provider (IdP) for single sign-on (SSO) but does not enforce multi-factor authentication (MFA) for all users. Which of the following is the BEST recommendation to reduce risk?
Hard864Which THREE of the following are characteristics of SMART recommendations in an audit report? (Select three.)
Hard865An IS auditor is reviewing the vendor management program for a critical outsourced service. The vendor has recently been acquired by another company. Which TWO factors should the auditor be most concerned about regarding the acquisition?
Medium866During system implementation, a critical defect is found in the production environment. The project manager wants to apply an emergency patch without full testing. Which of the following is the BEST course of action?
Hard867Which type of audit is primarily concerned with evaluating the efficiency and effectiveness of operations?
Easy868A company is designing a public cloud-based application that processes highly sensitive personal data. Which of the following data protection strategies provides the STRONGEST assurance that data remains confidential even if the cloud provider's infrastructure is compromised?
Hard869An organization uses RAID 5 for its database server. Which of the following is the PRIMARY advantage of RAID 5?
Medium870An IS auditor is reviewing an organization's change management process. The auditor notes that all emergency changes are approved post-implementation by the change advisory board (CAB) within 48 hours. Which of the following is the auditor's BEST course of action?
Hard871During a change management review, an IS auditor discovers that a recent database upgrade was implemented without prior approval from the Change Advisory Board (CAB) because it was classified as a 'standard change.' However, the change involved migrating to a new database version that required application code modifications. What should concern the auditor most?
Medium872During a system development project, the project manager notices that the actual cost is significantly higher than the planned cost at the 50% completion point. The earned value (EV) is $500,000, the actual cost (AC) is $600,000, and the planned value (PV) is $550,000. Which of the following is the MOST appropriate action?
Hard873Which of the following is the MOST important objective of system testing?
Easy874A financial institution is implementing a data classification policy. Which of the following is the most important factor in determining the classification level of a data asset?
Easy875In the audit follow-up phase, which TWO actions are essential? (Select two.)
Medium876An organization is implementing a new CRM system using an iterative development methodology. The IS auditor wants to verify that appropriate controls are in place. Which THREE of the following are essential controls for iterative development? (Select THREE.)
Hard877Which TWO of the following are primary objectives of a business continuity plan (BCP)?
Medium878An IS auditor is reviewing the logical access controls of a system. Which of the following is the BEST evidence that access rights are appropriately assigned?
Easy879A company outsources its IT help desk to a third-party vendor. The service level agreement (SLA) specifies that all P1 incidents must be resolved within 2 hours. During an audit, the auditor finds that the vendor’s average resolution time for P1 incidents is 3 hours. What is the most appropriate recommendation?
Medium880A company's IT governance policy requires that all critical systems have a documented business continuity plan (BCP). During an audit, an IT auditor finds that the BCP for a critical financial system has not been updated in three years. Which of the following is the BEST recommendation?
Medium881An IS auditor is reviewing physical security controls at a data center. The data center hosts critical servers and uses a badge access system with PINs, CCTV cameras, and a mantrap entry. The auditor observes that employees sometimes hold the door open for others without badging. Which TWO of the following are the MOST effective controls to address this tailgating risk?
Easy882During an IT audit, the auditor finds that a system administrator has local administrator rights on multiple production servers and uses a shared service account for routine maintenance. What is the PRIMARY risk associated with this practice?
Easy883During a change management process review, an IS auditor finds that the change advisory board (CAB) approved a change that subsequently caused a major service outage. The change was classified as 'normal' with no emergency. What is the auditor's primary concern?
Medium884An organization is implementing a new IT service management system based on ITIL 4. Which TWO of the following are guiding principles of ITIL 4?
Medium885According to COBIT 2019, which design factor is MOST critical for tailoring a governance system?
Medium886An organization's IT strategy must be aligned with business strategy. Which of the following is the PRIMARY benefit of this alignment?
Easy887During an audit of IT asset management, the IS auditor finds that several servers are running an operating system that has reached end-of-life (EOL). The organization has not deployed any compensating controls. Which of the following is the GREATEST risk?
Hard888Which of the following audit types is most likely to be conducted by an employee of the organization being audited, potentially raising independence concerns?
Easy889Arrange the steps to configure a firewall rule in the correct order.
Medium890Which TWO of the following are examples of administrative controls for information security? (Choose two.)
Easy891During an audit, the IS auditor identifies that the audit team lacks the technical expertise to evaluate a specific system. According to ISACA standards, the auditor should:
Easy892An organization is planning to purchase a cloud-based HR system. Which THREE of the following should be included in the vendor contract to ensure adequate control and oversight? (Select three.)
Hard893A company is migrating its applications to a public IaaS cloud. What is the primary concern for protecting data in this environment?
Medium894What is the PRIMARY purpose of conducting a static application security testing (SAST) during the development phase?
Easy895An organization is implementing a new ERP system. The project sponsor requests a change that will significantly increase project scope without additional budget. Which of the following is the BEST action for the project manager?
Hard896An IT auditor is reviewing backup procedures. The organization performs daily full backups and retains them for 30 days. Additionally, weekly backups are retained for 12 months. Which of the following is the MOST likely risk associated with this backup strategy?
Medium897An organization stores sensitive research data in a cloud storage service. The data must be encrypted at rest and in transit, and the organization wants to maintain control over encryption keys. Which solution best meets these requirements?
Hard898An organization wants to implement an exception management process for IT policies. Which of the following is the most important step to ensure effective control?
Hard899An IS auditor is evaluating the encryption key management program of a healthcare organization that processes protected health information (PHI). The organization uses a mix of symmetric and asymmetric keys. Which TWO of the following are key management practices that should be addressed to ensure effective protection of PHI?
Medium900An IS auditor is reviewing an agile software development project. Which of the following practices would BEST help ensure that security controls are adequately addressed?
Medium901Which of the following is a requirement for effective segregation of duties in IT?
Easy902An IS auditor is reviewing a project that uses an iterative SDLC approach. Which THREE controls should the auditor expect to see in place during the development iterations? (Select THREE)
Hard903An organization's data classification policy defines 'Confidential' data as requiring encryption at rest. An IS auditor discovers that a database containing customer personal information is not encrypted. What is the auditor's BEST course of action?
Hard904An IS auditor is planning an audit of a newly implemented ERP system. The auditor wants to ensure that the audit covers critical controls. Which of the following is the most appropriate first step in the audit planning process?
Easy905Which THREE of the following are essential components of a change management process?
Easy906Match each disaster recovery site type to its description.
Medium907An organization is adopting a DevOps approach for system development. Which THREE controls should an IS auditor expect to see in place to maintain security and compliance?
Hard908An organization uses a COTS (commercial off-the-shelf) ERP system with significant customizations. The IS auditor is reviewing the system's configuration management. Which of the following findings would MOST indicate a weakness?
Hard909An IS auditor is performing a review of an organization's IT governance framework. Which of the following findings would be of MOST concern?
Hard910An organization's IT department is structured with a central unit that provides infrastructure and support, while individual business units have their own application development teams. This structure is BEST described as:
Medium911An IT auditor is reviewing the system development life cycle (SDLC) process for a critical application. Which of the following findings would be of MOST concern?
Medium912An IS auditor is reviewing the privileged access management (PAM) process. The auditor finds that shared administrative accounts are used for critical system maintenance and that passwords are changed quarterly. Which of the following is the BEST recommendation to mitigate the risk of audit trail loss?
Hard913A company's backup policy requires that backup tapes be stored offsite for at least one year. During an audit, the auditor finds that the offsite storage facility is not access-controlled and backup tapes are not encrypted. Which of the following is the auditor's BEST recommendation?
Medium914A company is deciding whether to centralize or decentralize its IT function. Which of the following is an advantage of a centralized IT structure?
Medium915During an IT audit, the auditor discovers that the IT strategy is not formally documented. Which of the following is the MOST significant risk associated with this finding?
Easy916During a disaster recovery planning audit, the IS auditor notes that the organization's plan includes a hot standby site. However, the plan has not been updated in two years, and the last test was a tabletop exercise 18 months ago. The organization has recently implemented a new ERP system. Which THREE findings should the auditor report as most significant?
Hard917An organization's backup strategy includes daily incremental backups and weekly full backups. During a disaster recovery test, the restoration of a critical server fails because a required incremental backup is corrupt. Which control should the organization implement to verify the integrity of backups?
Hard918During a change management audit, which TWO of the following are essential elements of a normal change request? (Select two.)
Medium919A company's security policy requires that all laptops have full-disk encryption. During an audit, 10% of laptops are found without encryption. Which of the following is the MOST effective corrective action?
Medium920An organization is implementing a new CRM system using an agile methodology. The IS auditor wants to assess whether security requirements are being addressed. What is the best evidence for the auditor to review?
Medium921A company uses role-based access control (RBAC). An employee moves from one department to another but retains some previous access due to overlapping role permissions. This condition is known as:
Hard922Which THREE factors should an IS auditor consider when determining the sample size for a compliance test? (Select three.)
Hard923During a nightly batch job, the above error appears in the application logs. The transaction table ACCT_TRANS has a unique constraint on the REF_NUM column. Which of the following is the MOST likely root cause?
Hard924An organization is using a spiral model for a high-risk project. The IS auditor wants to ensure that risk assessment is performed at each iteration. Which of the following is the BEST evidence that this control is effective?
Hard925During a security assessment, an auditor discovers that employees are sharing passwords to access a critical system. Which of the following controls would BEST mitigate this risk?
Easy926An IS auditor is planning an audit of a financial system. The auditor identifies that the inherent risk is high due to the complexity of transactions, but control risk is low because of strong automated controls. Which component of audit risk will be MOST affected by the auditor's testing strategy?
Medium927A small manufacturing company decides to acquire an off-the-shelf inventory management system. The purchasing manager selects a vendor based solely on the lowest price, ignoring the vendor's financial stability and support history. After purchase, the vendor declares bankruptcy, leaving the company without support. The system has a critical bug that halts inventory tracking. The IT manager considers hiring a consultant to fix the bug. As an IS auditor, what should the auditor's PRIMARY concern be?
Easy928Which TWO of the following are key responsibilities of an IT steering committee?
Medium929Which THREE are commonly used techniques to protect sensitive data in a cloud environment? (Select exactly 3.)
Medium930During an audit of incident management processes, the IS auditor reviews past incident reports and conducts interviews. The organization recently experienced a ransomware attack that encrypted critical systems. The incident response team was able to contain the attack but struggled with forensic collection due to lack of pre-defined procedures. Which TWO of the following should the auditor recommend as the HIGHEST priority improvements?
Hard931An organization is implementing a new incident management process based on ITIL. An incident classified as P1 (Priority 1) occurs. According to ITIL best practices, what is the most appropriate initial action?
Easy932Refer to the exhibit. An auditor reviews the log shipping configuration for a critical database. Based on the information provided, what is the MOST significant finding?
Easy933An organization outsources its data center operations to a third-party vendor. The contract includes a right-to-audit clause. During a scheduled audit, the vendor refuses to provide access to logs from a subcontractor managing network security. What is the IS auditor's best course of action?
Medium934After issuing the final audit report, the IS auditor should perform follow-up procedures. What is the PRIMARY purpose of follow-up?
Medium935An organization is evaluating its business continuity plan (BCP) to ensure alignment with the IT disaster recovery plan. Which TWO of the following are critical elements that should be included in the BCP to support effective business resilience?
Hard936Which THREE of the following are indicators of mature IT governance?
Hard937An organization is implementing an agile methodology for a new software project. Which of the following is the MOST effective control to ensure that security requirements are addressed?
Hard938An IS auditor is reviewing the termination procedure for IT employees. Which of the following is the most critical control to ensure immediate effectiveness?
Hard939An organization implemented a business continuity plan (BCP) that includes manual workarounds. Which of the following is the PRIMARY risk of relying on manual processes during a disruption?
Medium940A university's research department stores sensitive research data on a file server that is shared among faculty and graduate students. The server is accessible from the campus network and via VPN for remote access. Recently, a student downloaded a large dataset containing personally identifiable information (PII) of research subjects to a personal laptop. The laptop was later stolen. The university's incident response team determines that the student had legitimate access to the data for research purposes. Which control would have most effectively prevented the data exposure?
Easy941Which THREE of the following are key elements that should be included in a risk assessment report for information systems?
Hard942During a recent audit, the IT auditor found that the problem management process does not include a known error database (KEDB). Which of the following is the MOST significant risk associated with this finding?
Medium943An organization is implementing COBIT 2019 to improve IT governance. Which of the following is a key component of the governance system according to COBIT 2019?
Medium944An organization is evaluating its business continuity plan (BCP) for a critical application with a recovery time objective (RTO) of 4 hours and a recovery point objective (RPO) of 1 hour. The current backup strategy involves daily full backups and hourly transaction log backups. Which of the following is the MOST significant risk?
Hard945An organization is implementing a new CRM system and has chosen a build (in-house development) approach over buying a COTS product. Which of the following is the most significant risk of this decision?
Medium946An IS auditor is evaluating the effectiveness of an organization's information security awareness program. Which of the following is the BEST indicator of program effectiveness?
Hard947In the context of ITIL change management, which change type requires approval from the Change Advisory Board (CAB)?
Medium948Which THREE of the following are key considerations when selecting a software development methodology for a project?
Hard949Which TWO are primary criteria for classifying information assets within an organization? (Choose two.)
Easy950An IT department is struggling with project delays and budget overruns. Which governance practice would be MOST effective?
Medium951Which TWO of the following are typical controls in the testing phase of the SDLC? (Select two.)
Medium952Which THREE of the following are key metrics to include in a disaster recovery test report? (Select exactly 3.)
Hard953During a systems audit, the auditor finds that the project did not follow the organization's systems development methodology. What should the auditor do FIRST?
Hard954An organization is selecting a vendor for a new enterprise resource planning (ERP) system. Which of the following is the MOST critical factor in the vendor selection process?
Easy955Match each security control to its category.
Medium956A financial services company is developing a new customer-facing web application for account management. The project is using a waterfall methodology. The initial requirements were gathered six months ago, and the coding phase is nearly complete. The business sponsor now requests a new feature that allows customers to view transaction receipts online. The project manager is concerned that this change will delay the project by two months and exceed the budget. The sponsor insists that the feature is critical for customer satisfaction and that the project must adapt. The development team estimates it will take 200 hours to implement. The steering committee is divided. As an IS auditor, what would be the BEST recommendation to resolve this?
Hard957An IS auditor is reviewing the release management process for a critical application. The release strategy includes a phased rollout to 10% of users initially, then 50%, then 100%. The first phase revealed a data integrity issue that affected a subset of transactions. The release manager decided to continue with the next phase while a patch was being developed. What should the auditor most recommend?
Hard958A multinational corporation is designing its disaster recovery strategy to meet a recovery point objective (RPO) of 15 minutes for its critical database. Which replication method is MOST appropriate?
Hard959An IS auditor is reviewing vendor management practices for a cloud-based SaaS solution. Which TWO of the following are critical elements to include in the contract's service level agreement (SLA)? (Select TWO.)
Medium960An organization has configured HSRP as shown. During a failover test, the primary router (G0/1) is shut down, but the DR site router does not become active. What is the MOST likely reason?
Hard961An IS auditor is evaluating an organization's SDLC controls for a new system. Which TWO of the following are key controls that should be in place during the design phase? (Select TWO.)
Medium962Arrange the steps to perform a risk assessment in the correct order.
Medium963An organization is selecting a vendor for a new procurement system. Which of the following is the MOST important factor to include in the contract?
Medium964During an audit of the information security program, the IS auditor reviews the organization's information security policy. Which of the following is the PRIMARY purpose of an information security policy?
Easy965Which of the following is the MOST effective control to prevent unauthorized USB devices from connecting to corporate workstations?
Medium966An IS auditor is reviewing a business continuity plan (BCP). Which TWO of the following are key components of the business continuity strategy? (Select two.)
Medium967An IS auditor is assessing the backup and recovery procedures for a critical database. Which TWO of the following are the MOST important controls to ensure recoverability?
Hard968Which THREE of the following are acceptable methods for gathering audit evidence? (Select THREE.)
Medium969An IS auditor is assessing the effectiveness of controls over a critical financial system. Which TWO types of evidence provide the highest level of assurance? (Select TWO.)
Medium970An IS auditor is using analytical procedures during the planning phase. Which of the following is an example of an analytical procedure?
Medium971An organization's backup strategy involves weekly full backups and daily incremental backups. After a system failure, the restoration takes longer than expected. What is the most likely cause?
Easy972According to ISACA audit standards, which TWO of the following are phases of the audit process? (Select two.)
Easy973An IS auditor is reviewing the logical access controls of a financial application. Which of the following is the BEST way to verify that user access rights are appropriate?
Medium974An organization is developing its IT strategy to align with the overall business strategy. The business strategy emphasizes rapid market expansion through digital products. Which of the following IT strategies would BEST support this business goal?
Easy975An IS auditor is preparing the audit report. According to ISACA standards, which of the following should be included in the final audit report?
Easy976A company is considering restructuring its IT department from a centralized to a decentralized model to give business units more autonomy. What is a PRIMARY governance risk associated with this move?
Medium977Refer to the exhibit. An auditor reviews the ACL and notes that it allows traffic from a specific host while blocking other IPs in the same subnet. What is the most likely security issue?
Easy978An organization has experienced several security incidents due to unauthorized changes to production systems. Which governance mechanism should be strengthened?
Medium979Refer to the exhibit. The IAM policy is intended to allow only requests originating from account 123456789012 to perform any S3 actions. Why does the policy NOT achieve this objective?
Medium980An IT steering committee is reviewing a proposal for a new customer relationship management (CRM) system. Which of the following BEST demonstrates that the proposal aligns with the organization's strategic goals?
Easy981An IS auditor is reviewing the capacity management process for a server hosting a critical application. The server's CPU utilization has been consistently above 90% for the past three months, and memory usage is at 85%. There are no threshold alerts configured. The capacity plan shows that additional resources are scheduled to be added in six months. What should the auditor most recommend?
Medium982An IT auditor is reviewing the business continuity plan (BCP) for a financial services firm. The plan includes a hot site that is shared with another organization under a reciprocal agreement. Which of the following findings should be of MOST concern to the auditor?
Hard983An organization is implementing a COTS application. The project team plans to heavily customize the application to meet unique business processes. Which of the following is the most significant risk?
Hard984A software development company uses a cloud-based source code repository (e.g., GitHub) to store proprietary code. The company has two-factor authentication (2FA) enabled for all accounts. A developer's personal computer was infected with malware that stole the developer's session cookies and local credentials. The attacker used the stolen session to access the code repository and exfiltrated the entire codebase. The company's security team reviews the incident and notes that the repository has audit logging, but the logs were not monitored in real time. The team wants to implement additional controls to prevent a similar incident. Which control would have been most effective in preventing the exfiltration?
Medium985An IS auditor is evaluating the patch management process. The auditor notes that critical security patches are applied within 30 days, but the policy requires 7 days. The IT manager states that the delay is due to testing requirements. What should the auditor recommend?
Hard986Which TWO of the following are considered essential components of an information security policy framework? (Choose two.)
Medium987An organization is adopting a decentralized IT structure to better meet the needs of its business units. Which of the following is a potential risk of this approach?
Medium988An IT auditor is reviewing the change management process for a financial institution. The auditor finds that emergency changes are frequently approved by the change manager without CAB review. Which risk is most associated with this practice?
Medium989A company plans to implement a commercial off-the-shelf (COTS) application and requires significant customization to match its unique business processes. The vendor advises against extensive customization because it may complicate future upgrades. What is the BEST course of action?
Hard990A financial institution is deploying a data loss prevention (DLP) solution. Which of the following is the MOST important prerequisite to ensure the DLP can effectively detect sensitive data?
Easy991An IT auditor is evaluating the capacity management process. Which of the following findings would be of MOST concern?
Hard992An organization is implementing a change management process based on ITIL. Which THREE change types should be included in the policy?
Hard993Which of the following is a key performance indicator (KPI) for IT service management?
Easy994A company's availability monitoring shows that a critical application has an average MTBF of 720 hours and an average MTTR of 4 hours. What is the availability percentage?
Hard995Which TWO of the following are key benefits of using a system development life cycle (SDLC) methodology? (Select exactly two.)
MediumOther domains
All CISA exam domains
Frequently asked questions
- What does the scenario questions domain cover on the CISA exam?
- scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 995 scenario questions questions in the CISA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only scenario questions questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.