Courseiva

CISA · domain

scenario questions

Practise Certified Information Systems Auditor CISA scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

934 questions244 easy408 medium282 hard

Focused practice

Practice scenario questions questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about scenario questions

scenario questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common scenario questions exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Question index

All scenario questions questions (934)

Click any question to see the full explanation, or start a practice session above.

1

During a build vs. buy analysis, the IS auditor observes that the organization decided to build a custom application because no vendor solution met all requirements. Which of the following risks should the auditor emphasize?

Medium
2

An organization is implementing a privacy program to comply with GDPR. Which THREE of the following are essential elements for managing cross-border data transfers?

Hard
3

An online retail company runs its e-commerce platform on a virtualized infrastructure with 50 virtual servers. The platform experiences intermittent slowdowns during peak hours, and recent monitoring reports show that disk I/O latency on the storage area network (SAN) frequently exceeds 50 ms during these periods. The SAN has two fabric switches and a single storage array with 12 TB of usable capacity, currently at 80% utilization. The company’s disaster recovery plan requires recovery point objective (RPO) of 1 hour and recovery time objective (RTO) of 4 hours for the e-commerce platform. During a recent test failover to the disaster recovery site, the IT team discovered that the replication link between primary and DR sites is saturated, causing replication lag of up to 3 hours. The team also noted that the DR site storage has only 6 TB of usable capacity, now at 60% utilization. The IT manager is concerned about meeting the RPO and RTO. Which course of action should the IT team take first?

Hard
4

A company is using an agile development methodology for a critical business application. The IS auditor is concerned about the lack of formal documentation. What is the BEST approach to mitigate this risk?

Medium
5

An IS auditor is reviewing the audit follow-up process. The auditor notes that management has implemented corrective actions for 80% of previous audit findings. What should the auditor conclude?

Medium
6

A company is developing a mobile banking application. Which test phase is MOST critical to ensure that the application functions correctly from the end user's perspective?

Easy
7

An organization uses automated job scheduling for nightly batch processing. One job fails due to a missing dependency file. What is the most effective control to prevent recurrence?

Easy
8

An IS auditor is conducting a preliminary review of a newly acquired subsidiary and needs to understand the organizational structure, key business processes, and the technology environment before drafting the engagement plan. Which of the following techniques is MOST appropriate for gathering this broad understanding?

Easy
9

During a review of firewall rule sets, an IS auditor finds a rule that allows any source IP to access any destination IP on TCP port 443. Which of the following should the auditor do FIRST?

Medium
10

An IS auditor is planning the use of computer-assisted audit techniques (CAATs) to test a large transaction population for duplicate payments. Which of the following is the MOST important consideration before relying on the CAAT results?

Hard
11

An IS auditor is evaluating the security of the architecture. Which of the following is the MOST critical finding?

Medium
12

An IT auditor is reviewing the policy hierarchy of an organization. Which of the following correctly describes the relationship between a policy and a procedure?

Hard
13

An IS auditor is performing a compliance audit of data privacy regulations. The auditor finds that the organization's privacy policy is not fully aligned with regulatory requirements. Which of the following is the auditor's BEST course of action?

Hard
14

An IS auditor is conducting an audit of a small manufacturing company's IT operations. The company has 50 employees and uses a single server running Windows Server 2019 for file sharing and print services. There is no formal change management process. The IT manager, who also doubles as the system administrator, has full administrative rights and is the only person who can make changes to the server. During the audit, the auditor notices that the server's local security policy is configured to allow unlimited password attempts and no account lockout. The IT manager states that this is to avoid locking out users who forget their passwords. The auditor also finds that the guest account is enabled on the server. What should the auditor recommend as the HIGHEST priority action?

Easy
15

An organization uses a hot site for disaster recovery. During a recent test, the hot site did not have the latest version of the application software. What is the MOST likely cause?

Medium
16

An organization's IT security policy requires that all employees complete annual security awareness training. An auditor notes that completion rate is only 60%. What is the MOST effective way to monitor compliance?

Medium
17

A hospital is implementing a new electronic health record (EHR) system to replace a legacy system. During the implementation phase, the project manager proposes using a parallel changeover strategy. Which of the following is the MOST significant risk associated with this approach?

Medium
18

What is the primary purpose of a chargeback model for IT services?

Medium
19

An IS auditor is planning an audit of an organization's IT infrastructure. Which of the following is the PRIMARY benefit of using a risk-based approach?

Easy
20

An IS auditor is reviewing the process for granting privileged access in a large organization. Which of the following findings should be of MOST concern?

Medium
21

During a business impact analysis (BIA), a department manager states that their process can be disrupted for up to 8 hours, but data loss cannot exceed 15 minutes. Which two metrics are defined by these statements?

Hard
22

An information systems auditor is evaluating user accounts in an organization's Linux environment. The accounts have the following properties: - The 'root' account has its password field set to '!!' (disabled). - The 'admin' account has its password field set to '!' (locked) and UID 0. - The 'test' account is a regular user with UID 1000. Based on this information, which user account poses the HIGHEST security risk?

Medium
23

An organization is implementing ITIL 4. Which TWO of the following are part of the four dimensions of service management? (Select TWO.)

Medium
24

Which TWO of the following are primary objectives of capacity management? (Select exactly 2.)

Medium
25

Which of the following is the PRIMARY purpose of conducting a penetration test?

Easy
26

An IS auditor is designing test procedures for an audit of an organization's network perimeter. The auditor plans to use computer-assisted audit techniques (CAATs) to analyze firewall log data covering six months. Which TWO of the following are the MOST important considerations when using CAATs in this engagement? (Choose two.)

Hard
27

An organization's business continuity plan (BCP) includes alternate facilities that can be operational within 24 hours. The maximum tolerable downtime (MTD) for a critical process is 12 hours. What is the most significant gap?

Medium
28

A multinational manufacturing company with operations in 20 countries has historically allowed each regional division to manage its own IT systems independently. Recently, the company experienced a significant data breach originating from a region with weaker security controls, leading to financial losses and reputational damage. The board has mandated stronger IT governance to prevent future incidents. The CIO proposes implementing a global IT governance framework with centralized policy enforcement. However, regional directors argue that local regulations and business needs require autonomy. The governance committee must decide on a course of action that balances risk and business flexibility. Which of the following approaches is the MOST appropriate?

Hard
29

An IS auditor is reviewing a post-implementation review report for a new financial system. Which finding would most indicate that the project did not meet its objectives?

Medium
30

Which of the following is the BEST example of an analytical procedure used during an IS audit?

Medium
31

Given this configuration, which is the PRIMARY concern?

Medium
32

An organization is evaluating a cloud-based identity as a service (IDaaS) for single sign-on (SSO). Which of the following security concerns is MOST critical to address?

Hard
33

An organization's backup strategy includes taking full backups weekly and transactional log backups every 15 minutes. The auditor wants to verify that backup encryption is implemented for offsite storage. Which control is most relevant?

Hard
34

Which type of change in ITIL requires approval from the Change Advisory Board (CAB) before implementation?

Easy
35

A company has multiple business units with conflicting IT priorities. Which governance body should resolve this?

Medium
36

Based on the exhibit, what should the IS auditor MOST likely recommend?

Hard
37

Which TWO of the following are primary objectives of an information system audit?

Easy
38

Which of the following is the PRIMARY purpose of conducting a privacy impact assessment (PIA)?

Easy
39

An IS auditor is reviewing the physical security controls at a data center that hosts the organization's primary transaction processing systems. The auditor observes that the data center uses a single-factor proximity card reader at the main entrance, the server room door is propped open during a vendor maintenance visit, and CCTV cameras record continuously but recordings are retained for only seven days. Which of the following should the auditor identify as the MOST significant control weakness?

Medium
40

A medium-sized retail company relies on an ERP system for order processing and inventory management. The system is hosted on-premises with daily backups stored on tape. The company's business continuity plan specifies an RTO of 4 hours and an RPO of 1 hour for the ERP system. During a recent fire drill, it was discovered that restoring the ERP system from tape took over 6 hours, and the most recent backup was from the previous day. Which of the following is the BEST course of action to meet the RTO and RPO goals?

Easy
41

An organization uses role-based access control (RBAC) for its enterprise resource planning (ERP) system. What is the greatest risk if user role assignments are not reviewed regularly?

Medium
42

An IS auditor is reviewing an organization's network segmentation design. The organization states that its cardholder data environment is isolated from the corporate network. During testing, the auditor discovers that a management VLAN can reach both environments and that the firewall permits administrative protocols from the management VLAN to any host. Which of the following is the auditor's BEST conclusion?

Medium
43

An organization is planning a full interruption test of its disaster recovery plan. Which THREE of the following should the IS auditor recommend as best practices for this type of test? (Select three.)

Hard
44

An IS auditor is reviewing the physical security controls at a data center that hosts the organization's core banking platform. During the walkthrough, the auditor notes that the mantrap entrance functions correctly, but the loading dock door is propped open for ventilation and the CCTV system records only the main corridor. Which TWO of the following findings should the auditor report as control weaknesses? (Choose two.)

Medium
45

Which TWO of the following are common objectives of an IT balanced scorecard? (Choose two.)

Easy
46

During the requirements gathering phase for a new financial system, stakeholders disagree on the priority of security controls versus user convenience. Which of the following is the BEST approach?

Medium
47

An organization has implemented role-based access control (RBAC). Which of the following is the PRIMARY benefit of RBAC?

Easy
48

A hospital is implementing a new electronic health records (EHR) system. The system will be used by doctors, nurses, and administrative staff. During the user acceptance testing (UAT) phase, the nursing staff reports that the interface for entering patient vitals is too slow and requires many clicks, which slows down their workflow. The project team has already completed system testing and is preparing for go-live in two weeks. The development team can make a quick fix to streamline the vital signs entry by adding a shortcut, but this change has not been tested. The IT director is concerned about patient safety and wants to ensure the system is usable. What is the BEST course of action?

Medium
49

When an organization uses an external provider to manage its IT help desk, this is an example of which sourcing model?

Medium
50

An organization is implementing a new customer relationship management (CRM) system using an agile methodology. Which THREE areas should the IS auditor focus on to assess the effectiveness of controls during the development process?

Medium
51

An organization is considering outsourcing its IT help desk. Which of the following is a key risk that should be addressed in the outsourcing contract?

Medium
52

Which TWO of the following are essential components of an effective incident response plan? (Select exactly 2.)

Medium
53

Which of the following is a key control in the deployment phase of the SDLC?

Easy
54

A multinational corporation is deploying a data loss prevention (DLP) solution across its network. The DLP system must be configured to prevent the exfiltration of personally identifiable information (PII) while minimizing false positives. Which approach is most effective?

Hard
55

A large enterprise recently experienced a data breach due to an insider threat. The IT governance committee is reviewing the incident and considering measures to prevent recurrence. Which of the following is the BEST course of action to address the root cause?

Medium
56

An organization uses a standard change model for low-risk, pre-approved changes. Which of the following is an example of a standard change?

Medium
57

In a spiral SDLC model, what is the primary purpose of risk analysis in each iteration?

Easy
58

An organization is migrating from a legacy system to a new ERP. Which TWO of the following are the HIGHEST risks during data migration?

Medium
59

A systems analyst is gathering requirements for a new customer relationship management (CRM) system. Which of the following is the MOST important activity to ensure that the final system meets user needs?

Easy
60

According to ISACA IT Audit Standards, which of the following is the primary purpose of audit documentation (working papers)?

Easy
61

Arrange the steps to implement a password policy in the correct order.

Medium
62

During a third-party software vendor audit, the IS auditor discovers that the vendor uses a common shared database for multiple clients and relies on application-level access controls. Which of the following is the GREATEST concern?

Hard
63

An organization uses shared accounts for system administration. Which of the following is the MOST significant audit concern?

Medium
64

An IS auditor is reviewing the organization's incident management process. Which THREE of the following are essential components of an effective incident response plan?

Hard
65

An IT auditor is reviewing the business continuity plan (BCP) testing schedule. The organization conducts a test where participants discuss their roles and responses to a scenario without any actual system activation. Which type of test is this?

Easy
66

An organization is implementing a change management process. A change that requires approval from the Change Advisory Board (CAB) but is scheduled to be implemented during the next maintenance window is classified as which type of change?

Hard
67

In a RACI matrix for the change management process, who is typically Accountable for the overall change process?

Hard
68

An IT steering committee is reviewing a proposed project to migrate critical applications to the cloud. Which of the following is the PRIMARY role of the IT steering committee in this decision?

Medium
69

Which TWO of the following are key components of an IT governance framework? (Choose two.)

Easy
70

An organization is implementing COBIT 2019. Which TWO of the following are governance enablers? (Choose two.)

Medium
71

An IS auditor is reviewing change management procedures. Which of the following situations would be of GREATEST concern?

Medium
72

In a RACI matrix for an IT change management process, who is responsible for performing the change?

Easy
73

An IS auditor is reviewing the post-implementation review (PIR) of a newly deployed human resources (HR) system. Which of the following should be the PRIMARY focus of the PIR?

Easy
74

A financial institution is evaluating its IT governance structure. Which of the following roles is BEST suited to ensure independent oversight of IT investments?

Medium
75

An IS auditor is reviewing the physical security controls at a data center. The auditor observes that the data center has a single entrance with a biometric scanner, but the door is propped open by a cleaning cart while the cleaning staff works inside. Which of the following is the MOST appropriate action for the auditor to take?

Easy
76

Based on the exhibit, what is the security risk of this bucket policy?

Easy
77

An IS auditor is evaluating the effectiveness of an organization's business continuity plan (BCP). Which of the following findings would be of GREATEST concern?

Easy
78

An organization wants to ensure that IT performance is measured against strategic goals. Which tool is BEST suited?

Easy
79

An IT auditor is reviewing the change management process for a financial application. The auditor finds that emergency changes are frequently implemented without post-implementation review. What is the MOST significant risk?

Medium
80

An organization's IT governance committee is reviewing a proposal to use a public cloud provider that does not meet the organization's data encryption standards. The board has set a low risk appetite for data privacy. What is the BEST action?

Hard
81

An IS auditor is reviewing an organization's implementation of a security information and event management (SIEM) system. The auditor wants to assess whether the SIEM is effectively supporting incident detection and response. Which TWO of the following are the MOST important factors for the auditor to evaluate? (Choose two.)

Hard
82

An auditor finds that access reviews have not been completed for two quarters. What is the MOST significant risk?

Hard
83

An IS auditor is selecting an appropriate audit sample. Which THREE of the following are factors that affect the sample size?

Medium
84

A company is implementing a new procurement system. The project team is considering using a rapid application development (RAD) methodology. Which of the following is a potential risk of using RAD?

Medium
85

Which THREE of the following are components of the COBIT 2019 governance system?

Hard
86

An IT auditor is reviewing the asset management process for hardware lifecycle. Which two controls should the auditor verify to ensure secure disposition of decommissioned servers?

Medium
87

An IS auditor is reviewing a network access control list and finds that a rule permits traffic from any source to a database server on port 1521. Management states the rule is required for a legacy application. Which of the following is the MOST appropriate audit response?

Hard
88

An IS auditor is reviewing the audit committee's oversight of the IT audit function. Which of the following is the MOST important factor for the auditor to consider when assessing the committee's effectiveness?

Easy
89

An IS auditor is assessing the controls in an agile development environment. What is the MOST effective way to verify that security testing is performed iteratively?

Medium
90

An IS auditor is reviewing a project to implement a new loan origination system. The project manager has produced a detailed work breakdown structure (WBS), a critical path schedule, and a resource-loaded plan. Which of the following should the auditor verify FIRST to assess whether the project schedule is realistic?

Medium
91

An IS auditor is evaluating the effectiveness of a control. The auditor observes the control being performed and then independently performs the same control to confirm the result. Which combination of evidence types is being used?

Hard
92

An organization is negotiating a contract with a cloud service provider. Which clause is most important for the IS auditor to ensure is included?

Easy
93

During a change advisory board (CAB) meeting, a proposed change to the database server is discussed. The change involves implementing a security patch that requires a reboot. The change is categorized as 'normal' and has been risk-assessed as low impact. What is the most likely role of the CAB in this scenario?

Medium
94

An IS auditor is evaluating the capacity management process. The auditor notices that CPU utilization has been consistently above 90% for the past three months. The IT manager states that no proactive capacity planning has been performed. What is the primary risk?

Medium
95

An organization is deciding between building a custom application and purchasing a commercial off-the-shelf (COTS) product. The primary factor favoring the build option is:

Hard
96

A financial institution recently experienced a data breach where an attacker exfiltrated customer data through an SQL injection vulnerability in a web application. The IS auditor has been asked to review the application security controls. The web application is developed in-house and runs on an application server behind a web application firewall (WAF). The auditor reviews the WAF logs and finds that no SQL injection attacks were detected before the breach, but the logs show many blocked XSS attempts. The developer states that all input validation is performed on the client side using JavaScript. During the audit, the auditor also finds that the application uses a shared database account with DBA privileges for all connections. What is the MOST significant weakness that directly contributed to the breach?

Medium
97

An IS auditor is reviewing the physical security controls at a data center. The auditor observes that entry to the data center requires a smart card and a PIN, and that the door is a single-leaf door with a standard lock. Which of the following is the MOST important physical security control that the auditor should recommend?

Easy
98

Which of the following audit types is performed by an independent third-party auditor and is typically required for regulatory compliance?

Easy
99

An organization outsources its data center operations to a third-party provider. Which of the following is the MOST important clause to include in the contract to ensure the organization can verify the provider's controls?

Medium
100

An organization is selecting a disaster recovery (DR) site. The primary data center is located in a region prone to earthquakes. The DR site should be at a sufficient distance to avoid the same disaster. Which type of alternate site provides the best balance of cost and recovery time for a medium-sized organization?

Hard
101

Which of the following is a key control during the deployment phase of a system development life cycle?

Easy
102

During the planning phase of an IS audit, which of the following is the PRIMARY purpose of conducting a risk assessment?

Easy
103

During an information systems audit, the IS auditor finds that data classification labels are not consistently applied across the organization. What is the most likely root cause of this issue?

Hard
104

An IS auditor is assessing network security controls. Which TWO of the following are key elements of a firewall rule review?

Medium
105

A large financial institution is evaluating the effectiveness of its IT governance framework. The board has requested a review to ensure alignment with business objectives and regulatory requirements. Which of the following is the MOST important factor for the board to consider when assessing the IT governance framework?

Medium
106

Refer to the exhibit. An auditor finds that the file 'sensitive.txt' has world-writable permissions. Which of the following is the most appropriate remediation action?

Easy
107

An IT steering committee is evaluating a proposal to migrate critical applications to the cloud. Which factor is MOST important to ensure alignment with business strategy?

Medium
108

In business continuity planning, a company identifies a critical business process with a maximum tolerable downtime (MTD) of 4 hours. What is the primary purpose of this metric?

Easy
109

An organization is migrating data from a legacy system to a new ERP. What is the most critical data migration risk?

Medium
110

According to ISACA IT Audit Standards, which phase of the audit process includes the development of an audit programme?

Easy
111

An IS auditor is assessing the implementation of a new system that uses a relational database. The project team plans to migrate data from several legacy sources. Which TWO of the following controls are MOST important to include in the data conversion plan to help ensure the integrity of migrated data? (Choose two.)

Medium
112

During a post-implementation review of a new accounting system, the IS auditor notes the following: the project was completed on time and within budget, but user satisfaction is low and there are several outstanding defect reports. Which THREE of the following are the MOST appropriate recommendations?

Hard
113

Which TWO of the following are components of audit risk in IS auditing?

Medium
114

Which THREE of the following are common techniques for ensuring business resilience?

Hard
115

A compliance audit is primarily concerned with:

Easy
116

An organization uses automated job scheduling for batch processing. A critical job fails due to a dependency on another job that has not completed. Which of the following controls would BEST prevent this issue?

Medium
117

A healthcare organization must comply with HIPAA regulations regarding patient data privacy. The IT department has implemented technical controls, but the compliance officer discovers that some employees are sharing passwords. What is the BEST governance response?

Easy
118

An IS auditor is evaluating an organization's IT governance maturity using COBIT 2019. The auditor finds that IT processes are largely ad hoc, with no formal documentation or consistent monitoring. However, the organization has recently implemented a tool to automate some IT service management tasks. Management believes this tool elevates their maturity to a managed level. The auditor should:

Hard
119

Which TWO of the following are examples of IT governance frameworks? (Select TWO.)

Easy
120

During an audit of network security controls, the IS auditor reviews firewall rule sets and identifies a rule that allows any-to-any traffic from the internal network to the Internet. The rule has a business justification. What is the auditor's BEST recommendation?

Hard
121

An IS auditor is assessing how an organization manages the risk of malicious code on employee workstations. The organization has deployed endpoint detection and response (EDR) agents on all workstations and maintains a centralized console. Which of the following is the MOST important factor in determining whether the EDR deployment effectively reduces malicious code risk?

Medium
122

A medium-sized manufacturing company has recently deployed an ERP system to integrate its financial, supply chain, and HR processes. The IT department is small (5 staff) and reports to the CFO. The company has no formal IT governance committee; IT decisions are made by the CFO and CEO informally. During a recent audit, it was found that several critical security patches for the ERP system have not been applied, and there are no documented procedures for change management. The IT manager states that patches are applied when time permits, and changes are discussed via email. The CFO argues that the ERP is running fine and the audit findings are low risk. The IS auditor needs to recommend a course of action to improve IT governance. Which of the following is the MOST appropriate initial step?

Easy
123

An IS auditor is conducting an audit of a payroll application and selects a statistical sample of 200 payment transactions from a population of 20,000. Testing reveals 12 transactions where the gross pay was calculated incorrectly due to a flawed overtime rule. Which of the following is the MOST appropriate interpretation of this result?

Medium
124

During an audit of a data center, an IS auditor discovers that a critical server's operating system has not been patched for eight months because the vendor's patch conflicted with a legacy application. Management accepts the risk and documents a compensating control of enhanced network monitoring. Which of the following should the IS auditor do NEXT?

Hard
125

An organization is developing a business continuity strategy. According to best practices, which THREE of the following should be included in the strategy?

Medium
126

During an audit of a financial application, the IS auditor discovers that user access reviews are performed quarterly instead of monthly as required by policy. Which of the following is the BEST initial action for the auditor?

Medium
127

Which of the following is the BEST indicator that an organization's data security governance is effective?

Hard
128

An IS auditor is reviewing an emergency change that was implemented to fix a critical security vulnerability. What is the most important post-implementation step?

Hard
129

Which of the following is a key component of an IT balanced scorecard from the 'internal process' perspective?

Medium
130

An organization's IT governance framework includes a policy that all system access must be reviewed quarterly. The internal audit finds that reviews are incomplete. What is the BEST action?

Medium
131

An IS auditor is evaluating how an organization manages operating system patches on internet-facing web servers. The patch management procedure requires testing in a staging environment, approval by the change manager, and deployment within 30 days of release. The auditor finds that emergency patches for critical vulnerabilities are deployed directly to production within 24 hours without staging tests. Which of the following is the MOST appropriate conclusion?

Hard
132

A project manager is selecting a development methodology for a project with well-defined requirements and low uncertainty. Which methodology is most appropriate?

Easy
133

An IS auditor is reviewing how a data center schedules preventive maintenance on its uninterruptible power supply (UPS) systems and backup generators. The operations manager states that maintenance is performed monthly by an external vendor and that no formal maintenance window is documented because the work is done during low-usage hours. Which of the following is the MOST significant audit concern?

Medium
134

An IS auditor is reviewing the implementation of a new payroll system. The project team has decided to use a pilot conversion approach. Which TWO of the following are the MOST significant advantages of this approach? (Choose two.)

Hard
135

An organization is implementing a custom ERP system. During user acceptance testing (UAT), critical bugs are found that affect core financial processing. The project sponsor suggests deploying the system on schedule and fixing bugs after go-live. What is the BEST course of action?

Medium
136

Which ITIL 4 guiding principle emphasizes understanding the current state and building on existing capabilities rather than starting from scratch?

Medium
137

Which TWO of the following are essential components of a disaster recovery plan (DRP)?

Easy
138

An organization is developing a business continuity strategy for its key customer-facing application. The BIA determined an RTO of 2 hours and an RPO of 30 minutes. Which TWO strategies are most appropriate to meet these objectives?

Medium
139

An IT department is structured with a central group that manages infrastructure and security, while business units have their own IT staff for application support. This is an example of which IT organizational structure?

Medium
140

Which type of disaster recovery test involves actually switching over to the alternate site and processing live transactions, but does not require the primary site to be shut down?

Easy
141

During an audit of patch management, the IS auditor notes that several critical patches have not been applied within the defined SLA. Which of the following is the BEST approach to evaluate the risk acceptance of these unpatched vulnerabilities?

Hard
142

An organization is implementing a data loss prevention (DLP) solution. Which of the following is the BEST approach to minimize false positives while ensuring sensitive data is protected?

Medium
143

An IS auditor is reviewing the IT governance of a financial services firm. The auditor discovers that the IT steering committee has approved a major core banking system upgrade, but the project lacks a formal business case and no post-implementation review is planned. Which of the following is the MOST significant risk arising from this situation?

Hard
144

A business continuity plan (BCP) includes a tabletop exercise once a year. An IS auditor finds that the exercise only involves IT staff. Which of the following is the BEST recommendation?

Medium
145

An organization is considering whether to build a custom application or purchase a commercial off-the-shelf (COTS) product. Which of the following factors would most strongly support a build decision?

Medium
146

An IS auditor is reviewing the process for granting access to a critical financial system. The auditor finds that access requests are approved by the system owner but there is no segregation between the request and approval functions for emergency access. Which of the following is the BEST control to mitigate this risk?

Medium
147

An organization uses shared accounts for system administration. Which of the following is the BEST control to mitigate the risk of non-repudiation?

Medium
148

Which TWO of the following are indicators that an IS auditor may need to adjust the audit approach during fieldwork? (Select TWO.)

Hard
149

An IS auditor is performing a compliance audit of a company's data privacy practices. Which type of evidence would be most appropriate to verify that employees have completed mandatory privacy training?

Medium
150

An organization is evaluating a vendor for a custom application development. The vendor states they are assessed at CMMI Level 2 (Managed). Which of the following best describes the implication of this rating?

Medium
151

An organization is adopting agile development methodology. Which control is MOST critical to ensure security is integrated?

Hard
152

A company is developing a custom application. During the requirements phase, the project manager documents that the system must encrypt all sensitive data at rest. Which of the following is the BEST control to ensure this requirement is met throughout the development lifecycle?

Easy
153

An organization has implemented a security awareness training program. Which of the following metrics would BEST indicate that the program is effective?

Easy
154

An IS auditor is assessing the risk of fraud in a financial system. Which combination of audit risk components is most directly relevant?

Hard
155

Which of the following is the BEST control to ensure that system changes are authorized?

Easy
156

An IS auditor is reviewing the logical access controls for a critical financial application. Which of the following is the MOST important control to ensure that user access rights remain appropriate over time?

Easy
157

An organization uses a public key infrastructure (PKI) to issue digital certificates. The IS auditor is reviewing the certificate lifecycle management. Which of the following is the GREATEST risk if certificate revocation lists (CRLs) are not updated in a timely manner?

Medium
158

An IT balanced scorecard for a retail company shows that the percentage of IT projects delivered on time has decreased from 85% to 70%. Which perspective of the balanced scorecard is MOST directly affected?

Medium
159

An organization is implementing a key management program to protect encryption keys. Which of the following is the MOST important control to ensure the security of cryptographic keys?

Easy
160

Based on the exhibit, what is the MOST likely security risk?

Medium
161

An IS auditor is reviewing the logical access controls of a legacy payroll application that authenticates users directly against its own internal user table rather than the corporate directory. Management states that this was a deliberate design choice by the vendor. Which of the following is the MOST significant audit concern with this arrangement?

Medium
162

An IS auditor is reviewing an organization's IT governance framework and notices that the IT steering committee, chaired by the CIO, approves all IT investments and also monitors their benefits realization. The board has delegated full IT decision-making authority to this committee. The auditor is MOST likely to conclude that:

Medium
163

During a vendor audit, an IS auditor discovers that a cloud service provider uses subcontractors to manage data storage. The contract does not mention subcontracting. Which THREE risks should the auditor highlight to management?

Hard
164

An IS auditor is assessing the security of an organization's virtualized environment. The organization uses a type 1 hypervisor and has multiple virtual machines (VMs) running on a single physical host. The auditor is concerned about the risk of VM escape, where an attacker compromises the hypervisor from within a VM. Which of the following controls are MOST effective in mitigating this risk? (Choose two.)

Hard
165

During an IS audit, the auditor finds that a control deficiency could result in a material misstatement. According to ISACA standards, this should be classified as:

Medium
166

Scenario: A mid-sized manufacturing company has recently experienced a significant IT outage that halted production for 8 hours. The root cause was a failed firmware update on a core switch that was performed outside the change management process by a senior network engineer who claimed the update was urgent to patch a critical vulnerability. The company has a well-documented change management policy that requires all changes to be reviewed by the change advisory board (CAB) before implementation, except for emergency changes which require post-implementation review within 48 hours. The engineer did not follow the emergency change process; he implemented the update directly. The IT director wants to prevent such incidents in the future. Which of the following is the BEST action?

Hard
167

You are an IS auditor for a financial institution that processes credit card payments. The organization uses a key management system (KMS) to store encryption keys for point-of-sale (POS) data. The KMS is a hardware security module (HSM) located in a secured data center. The audit reveals that the HSM is administered by two individuals who both have full access to the HSM, including the ability to export keys. The organization has a policy requiring split knowledge and dual control for key management, but in practice, the two administrators often perform key ceremonies alone due to scheduling conflicts. The logs show that one administrator exported a key last month without the other present, and the export was approved via email by the other administrator after the fact. Which of the following is the BEST corrective action?

Medium
168

During a business impact analysis (BIA), the auditor identifies a critical process with a maximum tolerable downtime (MTD) of 4 hours. The IT department proposes a recovery time objective (RTO) of 2 hours and a recovery point objective (RPO) of 1 hour. Which statement is correct?

Medium
169

During an audit of a public key infrastructure (PKI), the IS auditor finds that certificate revocation lists (CRLs) are only updated weekly. Which of the following is the MOST significant risk?

Hard
170

Which TWO of the following are benefits of an iterative SDLC approach compared to waterfall? (Select two.)

Medium
171

A company is migrating its customer database to a public cloud provider. Which of the following encryption strategies best protects data while minimizing performance impact on queries?

Hard
172

A multinational corporation has implemented a hot site disaster recovery solution for its critical financial applications. Which of the following is the MOST important consideration to ensure the effectiveness of the hot site?

Hard
173

Which of the following is the PRIMARY objective of a post-implementation review of an information system?

Easy
174

An IS auditor is reviewing a project that is developing a new customer relationship management (CRM) system using the Agile Scrum framework. The project team has completed several sprints, and the product owner has accepted the increments. The auditor wants to ensure that the system will meet the organization's security requirements before go-live. Which of the following is the MOST effective way for the auditor to achieve this?

Medium
175

Which of the following is the PRIMARY reason for an external IS audit to be more independent than an internal audit?

Easy
176

An IS auditor is assessing the data inventory of a financial institution to ensure compliance with privacy regulations. Which TWO of the following are essential elements that should be included in the data inventory?

Medium
177

Arrange the steps to set up a virtual private network (VPN) for remote access in the correct order.

Medium
178

According to ISACA IT Audit Standards, which of the following is a key requirement for audit documentation?

Easy
179

During a business impact analysis (BIA), which of the following is the MOST important metric to identify for each critical business process?

Medium
180

An IS auditor is evaluating the vendor selection process for a new system. Which of the following is the most important factor to include in the contract?

Medium
181

An IS auditor is reviewing the requirements definition phase of a new system development project. The business analyst has documented functional requirements but has not yet defined non-functional requirements. Which of the following is the MOST significant risk of proceeding to the design phase without non-functional requirements?

Hard
182

An organization is implementing a data loss prevention (DLP) solution. Which of the following is the MOST important step to ensure the DLP rules are effective?

Easy
183

According to ISACA IT Audit Standards, which of the following is the MOST important consideration when determining the scope of an IS audit?

Medium
184

An IS auditor is evaluating the effectiveness of controls over a critical financial application. Which TWO of the following are appropriate audit procedures to test the design and implementation of controls? (Select TWO.)

Medium
185

An IT governance framework has been implemented, but the board is not receiving regular reports on IT performance. Which of the following is the BEST course of action?

Medium
186

An organization uses a third-party vendor for application support. The vendor has subcontracted some support activities to another firm (fourth party). The contract with the vendor requires the vendor to ensure fourth-party compliance, but there is no direct oversight. What is the IS auditor's primary recommendation?

Hard
187

An IT steering committee is reviewing a proposed project to implement a new customer relationship management (CRM) system. The project has strong support from the sales department but is opposed by the finance department due to cost concerns. What is the primary role of the IT steering committee in this situation?

Medium
188

A hospital's IT department has implemented a new electronic health record (EHR) system. The IS auditor is reviewing the IT governance over the project and finds that the project sponsor is the CIO, who also chairs the IT steering committee that approved the project. Which of the following is the MOST significant governance risk?

Easy
189

A company is developing a new financial application. Which THREE of the following are valid reasons to involve internal audit during the development phase?

Hard
190

During the system development life cycle (SDLC), which THREE of the following are recognized benefits of involving internal audit early in the process?

Easy
191

A company is designing its backup strategy for a critical database that must be available 24/7. The database experiences high transaction volumes. Which backup method minimizes data loss while allowing continuous operations?

Easy
192

An IS auditor is planning an audit of a cloud service provider's controls over data backup and recovery. The auditor needs to obtain evidence about the provider's backup procedures and restoration testing. Which of the following is the MOST appropriate source of evidence?

Medium
193

During a post-implementation review of a new payroll system, the IS auditor identifies several outstanding issues. Which TWO issues should be considered most critical to address immediately? (Select TWO)

Medium
194

During an incident, the IT team identifies that a critical patch was not applied due to an expired software maintenance contract. Which of the following is the BEST long-term remediation?

Hard
195

Which TWO of the following are effective controls to prevent fraud in IT? (Select TWO)

Medium
196

An IS auditor is preparing the audit report after completing fieldwork on an organization's backup and restoration process. Management disagrees with one of the findings and has provided additional evidence. Which of the following is the auditor's MOST appropriate course of action?

Medium
197

An organization has implemented a balanced scorecard (BSC) for IT performance measurement. Which of the following is the PRIMARY benefit of using a BSC?

Easy
198

Which TWO of the following are key activities in the system design phase of the SDLC?

Medium
199

An IS auditor is reviewing a post-implementation review report for a new ERP system. Which of the following findings would be of greatest concern to the auditor?

Hard
200

An IS auditor is reviewing the problem management process. The auditor finds that problem tickets are often closed without identifying the root cause, and incidents continue to recur. Which of the following is the MOST likely consequence of this practice?

Easy
201

Which TWO of the following are key controls for ensuring data privacy during system development?

Medium
202

An organization has implemented a key management program. Which of the following is the MOST critical control for ensuring the security of cryptographic keys?

Medium
203

An organization is implementing a data retention policy for personally identifiable information (PII) to comply with GDPR. Which of the following is the MOST appropriate approach?

Hard
204

An IS auditor is reviewing the process for granting access to a sensitive financial application. Which TWO of the following are the MOST important controls to ensure appropriate access?

Easy
205

An IS auditor is reviewing a batch job scheduling environment. A critical nightly job that feeds the general ledger depends on a file transfer from a subsidiary. The scheduler is configured so that if the transfer does not complete by 02:00, the job is cancelled and the ledger is not updated. Operations staff report that they manually rerun the job each morning when this occurs. Which of the following is the MOST important issue for the auditor to raise?

Hard
206

Which of the following is the PRIMARY purpose of audit working papers?

Medium
207

An IS auditor identifies a control deficiency that could result in a material misstatement in the financial statements. According to audit reporting standards, this should be classified as:

Hard
208

Which of the following is the best example of audit evidence obtained through re-performance?

Medium
209

An IS auditor is reviewing an organization's logical access control processes. Which of the following is the primary purpose of conducting regular user access recertifications?

Easy
210

An IS auditor is reviewing a third-party service provider's controls. Which of the following is the MOST important clause to include in the contract to ensure the auditor can assess the provider's controls?

Medium
211

A company is implementing IT governance based on COBIT 2019. Which of the following design factors would have the GREATEST impact on the governance system design?

Hard
212

An organization is developing a critical application using an agile methodology. The project sponsor demands frequent deliveries but the development team is concerned about insufficient testing. Which of the following BEST mitigates this risk?

Hard
213

An IT auditor is evaluating the change management process for a financial trading system. Which of the following is the BEST indicator of a mature change management process?

Medium
214

An IS auditor is assessing the IT governance framework of a retail company. The auditor finds that the company has a formal IT strategy, an IT steering committee, and a defined IT organizational structure. However, the auditor notes that there is no process to ensure that IT investments are justified and prioritized. Which of the following are the MOST appropriate recommendations to address this deficiency? (Choose two.)

Hard
215

During an IT audit, the auditor observes that mandatory vacation policies are not enforced for IT staff with access to financial systems. What is the PRIMARY risk associated with this finding?

Hard
216

An organization is implementing a large ERP system. The project team plans to migrate legacy data to the new system. Which of the following is the MOST significant risk associated with data migration?

Hard
217

An IS auditor is reviewing physical access controls at a data center. Which of the following controls is MOST effective for preventing tailgating?

Easy
218

Which TWO are primary objectives of an identity and access management (IAM) program? (Select exactly 2.)

Hard
219

An IS auditor is reviewing the change management process for a critical financial application. Which of the following is the most important element to verify in an emergency change request?

Medium
220

An IS auditor is evaluating a wireless network deployed in a corporate headquarters. The auditor discovers that the network uses WPA2-Enterprise with 802.1X authentication, but the RADIUS server accepts any client presenting a valid domain user account, including accounts belonging to recently terminated employees that have not yet been disabled. Which of the following is the GREATEST risk arising from this configuration?

Hard
221

Which THREE of the following are phases of the audit process as defined by ISACA? (Select THREE.)

Hard
222

A company is implementing a cloud-based identity and access management (IAM) system. Which of the following best describes the principle of least privilege in this context?

Medium
223

A large enterprise is assessing its IT governance maturity. Which THREE of the following are indicators of a mature governance process? (Select exactly three.)

Hard
224

An organization is transitioning from a waterfall to an agile development methodology. Which of the following is a key risk that the IS auditor should highlight?

Medium
225

An IS auditor is reviewing a penetration test report that shows a critical vulnerability in a web application. The IT manager states that the vulnerability will not be fixed because it requires significant code changes and the application is being decommissioned in six months. What should the auditor do?

Hard
226

An IS auditor is evaluating the backup strategy for a system with a recovery point objective (RPO) of 15 minutes and a recovery time objective (RTO) of 2 hours. The current strategy is a full backup nightly to tape with tapes transported offsite weekly. Which finding is MOST significant?

Medium
227

Which of the following is the PRIMARY purpose of a service desk?

Easy
228

An IS auditor is reviewing an organization's IT service continuity plan (ITSCP) that supports its business continuity plan (BCP). The auditor finds that the ITSCP includes recovery strategies for critical systems but lacks details on roles and responsibilities during a disaster. Which TWO of the following should the auditor recommend to address this gap? (Choose two.)

Hard
229

An IS auditor is evaluating the reliability of audit evidence obtained from an IT system. Which TWO of the following factors most directly affect the reliability of the evidence? (Choose two.)

Hard
230

Which of the following is a permanent file item in an IS audit working paper?

Medium
231

An IS auditor is reviewing the network segmentation of a retail company's cardholder data environment (CDE). The auditor finds that the CDE and the corporate user VLAN are separated by a firewall, but the same flat Layer 2 domain spans both segments, and no internal segmentation firewall exists between the CDE web tier and the CDE database tier. Which of the following findings should the auditor report as the GREATEST risk?

Medium
232

Which of the following is the BEST indicator that an organization's incident management process is effective?

Easy
233

A company is outsourcing software development. What is the IS auditor's PRIMARY concern?

Medium
234

Which THREE are core components of a comprehensive identity and access management (IAM) system? (Choose three.)

Hard
235

An organization is considering outsourcing its IT infrastructure management. Which of the following is the MOST important factor to include in the service level agreement (SLA)?

Medium
236

An organization's mobile device management (MDM) policy requires that all corporate data on employee-owned smartphones be protected. Which control best ensures that corporate data can be remotely wiped without affecting personal data?

Easy
237

An IS auditor is reviewing the physical security controls for a data center. The auditor observes that the data center has a raised floor, a fire suppression system, and biometric access controls. The auditor also notes that the data center is located in a region prone to flooding. Which of the following controls is MOST important to mitigate the risk of flooding?

Medium
238

An IT governance framework should include which TWO key components? (Select exactly two.)

Easy
239

An IS auditor is leading an audit engagement and discovers that a key member of the audit team lacks the technical expertise to evaluate a newly implemented cloud encryption control. The audit manager insists the team member proceed anyway to save time. According to ISACA IT Audit Standards, what is the MOST appropriate action for the IS auditor to take?

Medium
240

An organization experiences a ransomware attack that encrypts critical files. Which of the following is the BEST recovery strategy to minimize data loss?

Medium
241

Which of the following evidence types involves the auditor independently performing a control procedure to verify its effectiveness?

Easy
242

An organization wants to ensure that data is not retained longer than necessary. Which of the following is the BEST control to implement?

Easy
243

An IS auditor is planning an audit of a cloud-hosted application and needs to determine whether the cloud provider's controls are adequate. The provider offers a SOC 2 Type II report. Which of the following should the auditor do FIRST?

Medium
244

An organization has a policy requiring all employees to complete annual information security awareness training. Which of the following is the BEST way to verify compliance with this policy?

Easy
245

An auditor is reviewing IT asset management processes. The auditor finds that several servers running an older operating system are still in production, even though the vendor has ended support. What is the primary risk associated with this finding?

Medium
246

An organization has implemented a clean desk policy. Which of the following is the BEST audit procedure to verify compliance?

Medium
247

During a review of firewall rule sets, an IS auditor identifies a rule that allows 'any-any' traffic from an internal subnet to the DMZ. The rule was implemented six months ago based on a business request that has since been completed. The firewall administrator explains that the rule was kept for convenience. Which of the following is the BEST audit recommendation?

Hard
248

A large financial institution is implementing a new core banking system to replace a legacy system. The project has been underway for 18 months and is behind schedule. User acceptance testing (UAT) has revealed significant data integrity issues, including missing customer records and incorrect interest calculations. The project manager, under pressure from senior management to meet a regulatory deadline, proposes going live with a promise to fix the issues in a post-implementation phase. The development team has been making ad hoc code changes directly in the test environment without version control or proper testing. Additionally, the IS auditor discovers that the business requirements were never formally signed off by the user community; only verbal approvals were obtained. The project has consumed 90% of the budget but only 60% of the functionality is tested. Which of the following is the BEST course of action for the IS auditor to recommend?

Hard
249

Which of the following is the BEST indicator of the effectiveness of a security awareness program?

Easy
250

Which TWO of the following are indicators of poor project governance that an IS auditor should identify?

Hard
251

Which TWO of the following are benefits of implementing an IT governance framework?

Easy
252

An IS auditor is reviewing the firewall rule base. Which of the following findings would be of MOST concern?

Medium
253

A company's endpoint protection solution alerts on a file that is digitally signed by a trusted software vendor but exhibits malicious behavior on execution. What type of threat does this scenario most likely depict?

Hard
254

Refer to the exhibit. An application log shows an error. What is the MOST likely cause of this error?

Medium
255

An IS auditor is assessing an ERP implementation. Which of the following control concerns is MOST likely to arise from segregation of duties conflicts?

Medium
256

An organization uses role-based access control (RBAC). An employee is transferred to a new department. According to best practices, what should be done regarding the employee's access rights?

Medium
257

A company is developing a mobile application that processes credit card payments. During the testing phase, which of the following types of testing is MOST critical to ensure security?

Medium
258

Which THREE of the following are key components of an effective information security awareness program? (Choose three.)

Hard
259

An IS auditor is reviewing the audit committee's oversight of the IT audit function. The auditor notes that the audit committee approves the annual IT audit plan but does not receive regular updates on the status of management's remediation of audit findings. Which of the following is the MOST significant risk arising from this situation?

Easy
260

A company is implementing a new IT governance framework. Which of the following is the PRIMARY benefit of aligning IT strategy with business strategy?

Easy
261

During a post-implementation review, an IS auditor identifies that the system's actual transaction processing time is significantly higher than the benchmark specified in the service level agreement (SLA). The vendor claims it is due to inadequate network bandwidth provided by the client. What should the auditor do first?

Hard
262

An IS auditor is assessing the security of an organization's virtualization environment. The auditor finds that the hypervisor management interface is accessible from the general corporate network and uses default credentials. Which of the following is the MOST critical risk associated with this finding?

Hard
263

Which TWO of the following are recommended practices for aligning IT strategy with business goals, according to COBIT 2019?

Medium
264

A multinational corporation is implementing a new enterprise resource planning (ERP) system across multiple regions. The project uses a phased roll-out. After the first phase in Asia, the system experiences intermittent synchronization errors between the central database and regional servers. The IT team suspects network latency but cannot reproduce the issue consistently. The project sponsor wants to proceed with the next phase in Europe to avoid further delays. The IS auditor is performing a post-implementation review. What is the MOST appropriate recommendation?

Hard
265

Midway through a multi-year ERP implementation, the CIO asks the IS auditor to review how the organization is realizing the intended business benefits. The project is on schedule and within budget, but business unit managers report that key process changes have not been adopted. Which of the following is the MOST appropriate action for the IS auditor to recommend?

Medium
266

A small business wants to protect customer data collected through its e-commerce website. Which control is most appropriate for protecting the data at rest and in transit?

Easy
267

During an audit of physical security, the IS auditor observes that employees frequently leave confidential documents on their desks overnight. Which TWO controls should the auditor recommend?

Easy
268

During the user acceptance testing (UAT) phase of a new financial application, the business users report that the system calculates interest incorrectly for certain loan types. The project manager wants to fix this quickly. Which of the following is the BEST course of action?

Hard
269

Which of the following is the PRIMARY purpose of a change advisory board (CAB) in the change management process?

Medium
270

An IS auditor is planning an audit of a decentralized organization with multiple business units. The auditor wants to use a risk-based approach. Which of the following is the MOST appropriate factor to prioritize audit coverage?

Hard
271

Which TWO of the following are key considerations when managing software licenses in an organization? (Select TWO).

Medium
272

Which TWO of the following are the MOST effective controls to prevent unauthorized changes to production data?

Medium
273

During which phase of the SDLC should security requirements be formally documented and approved?

Easy
274

Which THREE of the following are typical controls in the design phase of the SDLC?

Medium
275

An organization is implementing a new IT governance framework. Which of the following is the PRIMARY benefit of aligning IT strategy with business strategy?

Easy
276

An organization processes personal data of EU residents and has implemented pseudonymisation as a privacy control. The IS auditor is reviewing the effectiveness of this control in meeting GDPR requirements. Which of the following is the MOST important limitation of pseudonymisation?

Hard
277

An IS auditor is performing a risk assessment for an audit of a cloud service provider. Which THREE factors should be considered when assessing inherent risk? (Select THREE.)

Hard
278

An IS auditor is assessing the capacity management process for a virtualized data center. The auditor finds that CPU and memory utilization on a cluster of hosts regularly exceeds 85 percent during month-end processing, causing performance degradation. Management states that they monitor utilization but have no formal forecasting or trend analysis. Which of the following is the MOST significant risk arising from this situation?

Hard
279

An organization is implementing a new ERP system and is concerned about segregation of duties (SoD) conflicts. What is the BEST approach to address this during the implementation?

Medium
280

A multinational corporation is implementing a bring your own device (BYOD) policy. Which of the following is the most important security control to ensure corporate data is protected on employee devices?

Hard
281

A financial services organization recently experienced a data breach where customer financial records were exfiltrated. The investigation reveals that an attacker gained access through a compromised privileged account belonging to a database administrator. The attacker used valid credentials to log into the database server and then exported a large volume of data using native database tools. The security team notes that the organization has multi-factor authentication (MFA) enabled for all remote access, but the database server was accessed from an internal IP address. The organization also has a data loss prevention (DLP) system, but it did not alert on the export because the traffic was encrypted. The database activity monitoring (DAM) system did log the export, but alerts were not reviewed due to high volume and many false positives. Which of the following would have been most effective in preventing this breach?

Hard
282

What is the PRIMARY purpose of a post-implementation review?

Easy
283

An organization is implementing a privileged access management (PAM) solution. Which of the following is the PRIMARY benefit of using a PAM tool?

Medium
284

An organization is implementing a new IT policy. What is the MOST important step to ensure compliance?

Medium
285

An IS auditor is reviewing an organization's endpoint protection controls after several employees reported slow performance on their laptops. The auditor observes that the anti-malware solution performs a full disk scan every night, and the audit log shows that the last successful signature update was 47 days ago. Which of the following is the MOST significant concern the auditor should report?

Medium
286

An IS auditor is planning an engagement and needs to obtain an understanding of the organization's IT environment to develop the audit programme. Which of the following techniques is MOST appropriate for this purpose?

Medium
287

Which testing phase is MOST effective for validating that the system meets business needs?

Easy
288

A company plans to outsource its data center operations to a cloud service provider. What is the MOST important governance consideration for the board before finalizing the contract?

Medium
289

An IS auditor is planning a risk-based audit of a financial system. Which TWO of the following factors should the auditor consider when assessing inherent risk? (Select two.)

Medium
290

An organization is implementing a new financial system. Which of the following is the MOST important control to ensure data integrity during the data migration phase?

Easy
291

Refer to the exhibit. An auditor finds that users are able to reuse previous passwords easily. Which setting should be modified to address this weakness?

Medium
292

A company uses a RAID 5 array for its file server. One disk fails, and the system continues to operate. However, during the rebuild process, a second disk fails. What is the likely consequence?

Hard
293

Which THREE of the following are characteristics of a SMART recommendation? (Select three.)

Hard
294

An organization's IT department has a policy that all new hires must sign an acceptable use policy (AUP) before gaining access to systems. During an audit, the IS auditor finds that several contractors were granted access without signing the AUP. Which of the following is the auditor's BEST recommendation?

Easy
295

An IS auditor is reviewing the physical access controls at a data center. Which of the following is the MOST effective control to prevent tailgating?

Easy
296

An IS auditor is reviewing the ITIL incident management process. Which THREE are the correct priority levels and their typical definitions?

Easy
297

An IS auditor is reviewing capacity management practices. Which TWO indicators suggest that proactive capacity management is being performed effectively?

Medium
298

An IS auditor is performing a compliance audit of a data privacy regulation. Which of the following is the PRIMARY source of audit criteria?

Medium
299

An IS auditor is reviewing the incident response (IR) process. Which of the following is the BEST way to test the effectiveness of the IR plan?

Easy
300

An IS auditor is reviewing how a data center protects its backup tapes while they are in transit to an offsite storage facility. Management states that tapes are encrypted before shipment and that a courier transports them in sealed containers. Which of the following is the MOST appropriate evidence to confirm that the tapes are protected in transit?

Easy
301

A multinational corporation is implementing a global IT governance framework. Which of the following challenges is MOST likely to arise?

Hard
302

During a software asset management (SAM) audit, it is discovered that the organization is using software that has reached end-of-life. Which of the following is the MOST significant risk associated with this situation?

Hard
303

An IS auditor finds that a project failed to meet its objectives because key stakeholders were not involved in the requirements definition phase. Which phase of the SDLC was most neglected?

Medium
304

Which of the following is the PRIMARY reason for implementing network segmentation?

Easy
305

An organization is designing an IT balanced scorecard to align IT performance with business goals. Which perspective would include metrics related to IT employee skills and training?

Hard
306

An IS auditor is evaluating an organization's capacity management process for a critical database server. The auditor observes that CPU utilization averages 85% during peak hours, memory utilization is at 90%, and disk I/O wait times are consistently high. The organization has no formal capacity plan. Which of the following is the MOST significant risk the auditor should report?

Hard
307

An organization uses a cloud-based ERP system to manage financial transactions. The system is accessed by employees in finance, procurement, and sales departments. The IS auditor is reviewing the user access review process. The access review is performed quarterly by the IT manager using a report generated by the ERP system. The report lists all users and their roles. The IT manager manually checks off users who are still employed and approves the report. The auditor notes that the IT manager does not have detailed knowledge of job functions in each department. Additionally, the ERP system allows role combinations that may create segregation of duties conflicts, such as a user having both 'create purchase order' and 'approve purchase order' roles. The company's policy requires segregation of duties reviews to be performed by business process owners. Which of the following is the BEST recommendation?

Medium
308

An organization has defined an SLA that requires critical incidents to be resolved within 4 hours. A P1 incident is reported at 10:00 AM. At what time must the incident be resolved to meet the SLA?

Easy
309

Which TWO of the following are typically included in the fieldwork phase of an IS audit? (Select two.)

Medium
310

An IS auditor is evaluating the encryption strategy for a healthcare organization subject to HIPAA. Which of the following is the MOST significant risk if the organization relies solely on encryption as a safe harbor?

Hard
311

An IS auditor is reviewing the backup process for a critical database. Which TWO of the following are essential controls to ensure data recoverability?

Easy
312

In a waterfall SDLC, which phase requires formal sign-off from the business owner before proceeding to the next phase?

Easy
313

An IS auditor is reviewing the design phase of a new procurement system. Which TWO of the following controls are MOST critical to include in the system design to prevent unauthorized purchases?

Medium
314

An IS auditor is reviewing an organization's data classification policy. Which of the following findings is MOST critical?

Medium
315

An IS auditor is reviewing an organization's incident management process after a ransomware attack encrypted several file servers. Which TWO of the following should the auditor verify as part of assessing the effectiveness of the incident response? (Choose two.)

Hard
316

Order the steps for conducting an audit engagement from start to finish.

Medium
317

An IS auditor is reviewing the physical access controls at a data center. Which TWO of the following are the MOST effective controls to prevent unauthorized tailgating?

Medium
318

An IS auditor is reviewing the incident management process. Incidents are categorized as P1 (critical) through P4 (low). The SLA for P1 incidents requires initial response within 15 minutes and resolution within 4 hours. The auditor notes that the average time to respond to P1 incidents is 12 minutes, but the average resolution time is 6 hours. The root cause analysis shows that many P1 incidents are due to known errors documented in the known error database (KEDB). What is the most significant finding?

Hard
319

During an agile software development project, a sprint review meeting is conducted. What is the PRIMARY purpose of this meeting from an IS audit perspective?

Medium
320

During a post-implementation review of a financial system, an IS auditor finds that several critical reports are not being generated correctly. Which of the following should the auditor recommend FIRST?

Easy
321

An organization is implementing a data loss prevention (DLP) solution. Which TWO of the following are key considerations for effective DLP deployment?

Easy
322

An organization's security team proposes deploying a network-based intrusion prevention system (IPS) inline at the internet perimeter. Management asks the IS auditor to comment on the operational implications before approving the purchase. Which of the following should the auditor identify as the MOST significant operational risk of the inline placement?

Medium
323

An IS auditor is evaluating the effectiveness of an organization's change management process. Which of the following is the most important control to verify during the audit?

Easy
324

During an audit, the IS auditor discovers that the audit log for a critical server is overwritten every 24 hours. The auditor wants to ensure logs are preserved for a longer period. Which of the following recommendations is most appropriate?

Medium
325

Which testing type is performed by end-users to verify that the system meets their needs?

Easy
326

Which of the following is the BEST control to ensure that user acceptance testing (UAT) is effective?

Medium
327

An IS auditor is reviewing a change management process. Which TWO elements should be documented in a normal change request to ensure adequate governance? (Select TWO)

Medium
328

An IS auditor is reviewing an organization's IT governance framework and notes that the board of directors has established an IT strategy committee. Which TWO of the following are the MOST appropriate responsibilities for this committee? (Choose two.)

Medium
329

An IS auditor is reviewing an organization's IT governance structure. The board of directors has delegated all IT oversight to the CIO, who reports to the CFO. The auditor finds that the board receives only annual summaries of IT performance and never reviews IT risks. Which of the following is the MOST significant governance concern?

Medium
330

An IS auditor uses statistical sampling to test a population of 10,000 transactions. The auditor discovers 5 errors in the sample of 200. Which of the following conclusions is most appropriate?

Hard
331

An IS auditor is evaluating the change management process. Which of the following is the BEST indicator that emergency changes are being properly controlled?

Medium
332

An IS auditor is reviewing an organization's security monitoring architecture. The organization uses a SIEM to collect logs from servers, firewalls, and applications. Management reports that the SIEM is functioning as designed and alerts are generated. Which of the following findings would be of MOST concern to the auditor?

Hard
333

An IS auditor is assessing the effectiveness of access controls. Which TWO procedures provide the strongest evidence? (Select two.)

Medium
334

Which THREE of the following are essential components of a data classification program?

Hard
335

A medium-sized e-commerce company recently suffered a ransomware attack that encrypted critical databases. The IT team restored systems from backups, but the incident exposed a lack of clear roles and responsibilities for incident response. The board has asked the IT governance committee to review and improve the incident response governance. The committee notes that while there is an incident response policy, it is not regularly tested, and staff are unsure of their roles. The company also lacks a formal communication protocol for notifying stakeholders. What should the committee prioritize to strengthen governance over incident response?

Easy
336

An IS auditor is reviewing the IT organizational structure of a mid-sized manufacturing company. The auditor finds that the IT department reports to the CFO, and there is no separate IT strategy committee. The CEO believes that IT is a support function and does not need board-level representation. Which of the following is the MOST appropriate recommendation for the auditor?

Easy
337

A small business wants to protect customer data stored on a local file server. Which of the following is the MOST cost-effective control to prevent unauthorized access?

Easy
338

An organization is implementing a data loss prevention (DLP) solution. Which of the following is the BEST approach to reduce false positives during initial deployment?

Medium
339

An IS auditor is reviewing a system development project that uses a commercial software package customized with vendor-supplied extension points. The project team has documented customizations in a separate repository but has not maintained a traceability matrix linking business requirements to configuration items. Which of the following is the GREATEST risk arising from this situation?

Hard
340

An IS auditor is reviewing the user access recertification process. Which of the following findings would MOST concern the auditor regarding the effectiveness of access reviews?

Medium
341

An organization's backup strategy includes full backups every Sunday and incremental backups on other days. On Wednesday, a failure occurs. Which backups are needed to restore the data?

Medium
342

A multinational corporation is evaluating its IT governance structure. The board wants to ensure that IT investments are prioritized based on risk and value. Which framework component is MOST critical?

Hard
343

A mid-sized company is implementing a new IT service management (ITSM) tool to improve incident management. The IT manager wants to ensure that the tool aligns with ITIL best practices. The company has a dedicated service desk team that handles about 200 incidents per week. The IT manager is considering whether to implement a self-service portal for users to submit incidents and check status, or to continue using email-based incident reporting. The service desk team is concerned that a self-service portal might reduce their direct interaction with users and potentially lead to less personalized support. However, the IT manager believes that a portal could improve efficiency and tracking. The company's IT governance framework requires that any major IT investment be approved by the steering committee and that there be a clear business case. The IT manager has prepared a business case but the steering committee wants to ensure that the solution is aligned with ITIL and that it addresses key incident management processes. Which of the following is the most appropriate next step for the IT manager?

Easy
344

During an operational audit of an IT department, the auditor finds that system uptime is 99.9% but the department missed two critical project deadlines. Which conclusion is most appropriate?

Medium
345

An IS auditor is reviewing a waterfall SDLC project that has completed the requirements phase. Which of the following is the greatest risk to the project?

Medium
346

An IS auditor is reviewing the change management process for a critical financial application. Which of the following findings would be of GREATEST concern?

Hard
347

An IS auditor is reviewing the logical access controls for a cloud-based HR system. The system contains sensitive employee data. The auditor notes that user provisioning is performed by the HR department without IT involvement, and there is no formal access request or approval process. Which THREE of the following are the MOST significant risks?

Easy
348

Which TWO of the following are key elements of a change request document?

Medium
349

Which TWO of the following are key controls that an IS auditor should expect to find in a well-managed system development life cycle (SDLC)?

Medium
350

An organization is developing a policy on acceptable use of company IT resources. Which of the following should be included to support effective governance?

Medium
351

An IS auditor is assessing the capacity management process for a cloud-based enterprise resource planning (ERP) system. The organization has experienced performance degradation during peak periods, and the cloud provider's auto-scaling features are not fully utilized. Which of the following should the auditor recommend FIRST?

Medium
352

A multinational corporation is implementing a global HR system. The project team decides to use a pilot implementation in one region before rolling out to others. What is the PRIMARY risk if the pilot region is not representative of the entire organization?

Hard
353

During a post-implementation review of a new financial system, the IS auditor finds that user acceptance testing (UAT) was completed with only 60% of test cases passed. Which of the following is the MOST significant risk?

Medium
354

An IS auditor is reviewing the access control list (ACL) on a router that connects the corporate network to the internet. The auditor notices that the ACL permits inbound traffic on port 3389 (RDP) from any source IP address to a specific internal server. Which of the following is the MOST appropriate recommendation?

Easy
355

Which of the following is the PRIMARY purpose of a data classification scheme?

Easy
356

A system has a Mean Time Between Failures (MTBF) of 200 hours and a Mean Time To Repair (MTTR) of 20 hours. What is the availability of the system?

Medium
357

During which phase of the SDLC should security requirements be formally documented and approved by the business owner?

Easy
358

A multinational corporation has defined its risk appetite as 'moderate' for IT investments. The IT steering committee is evaluating a new project with potential high returns but also significant cybersecurity risks. The project's risk profile is assessed as 'high' by the risk management team. What should the committee do FIRST?

Hard
359

A global retail company is implementing an IT governance framework. The board of directors has asked the IS auditor to identify the KEY components that should be included in the framework to ensure effective governance. Which TWO of the following are essential components of an IT governance framework? (Choose two.)

Hard
360

An IS auditor is reviewing the backup strategy for a financial institution's core transaction processing system. The system processes high volumes of transactions continuously and requires a recovery point objective (RPO) of 5 minutes. The current strategy includes nightly full backups and hourly incremental backups. Which of the following should the auditor recommend as the MOST appropriate improvement?

Medium
361

An organization wants to ensure that its backup tapes are protected from unauthorized access. Which of the following is the MOST effective control?

Easy
362

An organization has implemented a business continuity plan (BCP) and disaster recovery plan (DRP). During a recent full interruption test, the IT team discovered that the recovery time objective (RTO) for a critical application was not met. What is the MOST likely reason for this failure?

Medium
363

An IS auditor is reviewing the access recertification process for a financial application. The process requires users' managers to confirm access rights quarterly. Which of the following findings should MOST concern the auditor?

Medium
364

According to ISO/IEC 38500, which principle requires that IT investments are made for valid business reasons and with clear business outcomes?

Easy
365

An organization is acquiring a new financial system. The contract includes a clause that allows the organization to audit the vendor's controls. Which type of report would most efficiently provide assurance over the vendor's internal controls?

Medium
366

An IS auditor is reviewing the IT operations of a small company. The auditor finds that scheduled batch jobs are monitored manually by an operator who checks job logs each morning. Which of the following is the MOST significant risk associated with this practice?

Easy
367

An IS auditor is reviewing the job scheduling environment for an organization's overnight batch processing on a mainframe. The auditor finds that operators have the authority to modify job control statements, restart failed jobs, and manually release jobs held for review, all using the same production operator ID. Which finding should the auditor report as the GREATEST concern?

Medium
368

A university is implementing a new student information system. The project team uses an iterative development approach. During user acceptance testing, students report that the online course registration portal crashes when more than 100 users register simultaneously. The development team identifies a database connection pooling issue and estimates a fix will take three weeks. The project deadline is in two weeks. The project manager suggests deploying the system as is and fixing the issue after go-live, as the crash is rare. The IS auditor is consulted. What should the auditor recommend?

Medium
369

A security auditor discovers that a server has been compromised due to an unpatched vulnerability. Which of the following would have most effectively prevented this incident?

Medium
370

During an audit of the incident response process, the IS auditor finds that the organization relies on shared accounts for system administration. Which TWO of the following are the MOST significant risks associated with shared accounts?

Medium
371

An organization is conducting a Business Impact Analysis (BIA). Which of the following metrics defines the maximum acceptable outage time for a critical business process?

Medium
372

Which of the following is the PRIMARY benefit of using a hardware security module (HSM) for key management?

Easy
373

An IS auditor is reviewing the endpoint security controls of a hospital that permits clinicians to use personal laptops and tablets to access the electronic health record (EHR) system. The auditor finds that the organization issued written acceptable-use agreements, but devices are not inspected, and no enrollment process exists. Which of the following is the MOST significant risk arising from this situation?

Medium
374

An IS auditor is reviewing a systems acquisition project that involves purchasing an ERP system. Which of the following is the MOST significant risk related to data migration during implementation?

Medium
375

Order the steps for performing a data backup in the correct sequence.

Medium
376

Which of the following are key considerations when implementing a data classification policy? (Choose THREE.)

Medium
377

An IS auditor is assessing the risk of material misstatement in a highly automated transaction processing environment. The auditor notes that the system automatically calculates interest and posts it to customer accounts. Which of the following audit approaches would BEST address the risk of incorrect interest calculations?

Hard
378

In a spiral model SDLC, risk analysis is performed at the beginning of each iteration. What is the PRIMARY benefit of this approach?

Hard
379

An IS auditor is reviewing the IT governance framework of a small organization. The auditor finds that the IT manager reports directly to the CFO, and there is no separate IT steering committee. Which of the following is the MOST appropriate conclusion?

Easy
380

During the planning phase of an IS audit, the auditor identifies that the organization has recently implemented a new ERP system. Which of the following actions should the auditor prioritize?

Medium
381

Which TWO of the following are key objectives of a post-implementation review of a new system?

Medium
382

An IS auditor is planning an audit of a data center and must decide whether to test controls or rely on the work of the organization's internal audit function. Which of the following is the MOST important activity before the auditor can rely on that work?

Easy
383

An IS auditor is evaluating how an organization disposes of decommissioned hard drives that previously stored customer financial records. Management states that drives are physically destroyed by a third-party vendor, but no certificates of destruction are retained and the vendor's personnel perform the destruction at the organization's loading dock without supervision. Which of the following is the MOST important control weakness?

Hard
384

Scenario: A healthcare organization is implementing a new electronic health records (EHR) system. The project has been delayed due to scope creep and resource constraints. The project sponsor is pressuring the project manager to accelerate the timeline by skipping user acceptance testing (UAT) and going live immediately. The organization has a governance policy that requires all IT projects to complete UAT before deployment. The project manager is concerned about quality and patient safety. Which of the following is the BEST course of action?

Medium
385

An IT department uses a balanced scorecard (BSC) to measure performance. The financial perspective shows that IT costs are within budget, but customer satisfaction scores are declining. The learning and growth perspective indicates low employee engagement. Which action should the IT governance committee prioritize?

Hard
386

An IT auditor is reviewing the organization's policy hierarchy. Which of the following correctly represents the typical order from highest to lowest level?

Hard
387

An IS auditor is assessing the security controls in a newly developed mobile banking application. The development team used the OWASP Mobile Application Security Verification Standard (MASVS) as a guide. Which of the following would be the MOST effective evidence that the application meets the standard's requirements for secure data storage?

Hard
388

An IS auditor is reviewing the business impact analysis (BIA) for a financial services company. Which THREE metrics are typically defined in a BIA?

Medium
389

An organization's IT strategy is developed by the IT department without input from business stakeholders. Which of the following is the MOST significant risk?

Hard
390

An organization is implementing a software asset management (SAM) program. Which of the following is the PRIMARY benefit of SAM?

Medium
391

An IS auditor is evaluating the incident response (IR) plan. Which of the following is the BEST indicator that the plan is effective?

Medium
392

A medium-sized manufacturing company has a decentralized IT structure where each business unit manages its own IT budget and projects. The CEO is concerned that IT investments are not aligned with corporate strategy and that there is duplication of effort. The IT department lacks a formal project portfolio management process. The company has experienced several project failures due to poor prioritization. The CEO has asked the newly hired IT auditor to recommend an initial step to improve IT governance. The auditor should recommend:

Easy
393

A company is migrating from a legacy system to a cloud-based ERP. Which of the following is the MOST important control to ensure data integrity during data conversion?

Easy
394

In an Agile software development project, who is primarily responsible for prioritizing the product backlog?

Easy
395

An IS auditor is reviewing an organization's IT operations incident management process. The auditor finds that incidents are categorized and prioritized, but there is no formal escalation procedure. Which TWO of the following are the MOST significant risks of not having an escalation procedure? (Choose two.)

Medium
396

An IS auditor is reviewing the privileged access management (PAM) process. Which TWO of the following are the MOST effective controls to prevent misuse of privileged accounts?

Medium
397

Which of the following is the BEST indicator of IT performance from the customer perspective in an IT balanced scorecard?

Easy
398

During an audit, the IS auditor finds that the business continuity plan (BCP) was last updated two years ago and does not include new cloud-based applications. The organization has not conducted a BCP test in 18 months. What should the auditor recommend FIRST?

Hard
399

An organization has implemented a new IT service management (ITSM) tool. The IT manager wants to measure the effectiveness of incident management. Which metric is MOST appropriate?

Hard
400

An organization is adopting ITIL 4 for service management. Which guiding principle emphasizes starting from existing processes rather than building from scratch?

Medium
401

A financial services firm has a mature IT governance framework. The IS auditor is reviewing the IT governance structure and notices that the IT steering committee meets quarterly and focuses primarily on project approvals. Which of the following is the MOST significant concern regarding this committee's effectiveness?

Medium
402

An IS auditor is reviewing the backup and restoration controls for a hospital's electronic health record (EHR) system, which runs on a relational database with a recovery point objective (RPO) of 15 minutes. The database administrator performs a full backup every Sunday at 01:00, differential backups nightly at 01:00, and transaction log backups every 15 minutes. During testing, the auditor observes that a restore of the database to a point in time at 14:07 on Wednesday completed successfully but took 9 hours, exceeding the stated maximum tolerable downtime (MTD) of 4 hours. Which TWO conclusions should the auditor draw from this observation? (Choose two.)

Hard
403

An IT steering committee is evaluating a major system upgrade. Which of the following is the PRIMARY benefit of using an IT balanced scorecard in this evaluation?

Medium
404

An organization is implementing a new IT governance framework. Which of the following is the PRIMARY benefit of using a framework like COBIT?

Easy
405

Which TWO of the following are components of the ITIL 4 four dimensions of service management? (Select TWO.)

Medium
406

An IS auditor is reviewing an agile project that uses Scrum. Which event provides the best opportunity for the auditor to assess whether completed user stories meet the defined acceptance criteria?

Medium
407

During a post-implementation review of a new HR system, the auditor finds that the system's disaster recovery plan (DRP) was not tested before go-live. Which of the following is the BEST recommendation?

Hard
408

During a review of the patch management process, the IS auditor finds that critical security patches are applied within 30 days, but the policy requires application within 7 days. The IT manager argues that the delay is due to testing requirements. What should the auditor recommend?

Medium
409

An IS auditor is examining how an organization classifies and handles its data. The auditor finds that the data classification policy defines four tiers but does not specify retention periods, handling procedures, or labeling requirements for each tier. Management states that employees use their judgment when handling sensitive information. Which of the following is the MOST appropriate recommendation?

Hard
410

A company is updating its business continuity plan (BCP). Which THREE of the following should be included as key components?

Hard
411

A bank is converting data from its legacy core banking system to a new platform. Which control is MOST critical to ensure the completeness and accuracy of data conversion?

Medium
412

Which of the following audit types is MOST likely to be performed by an organization's own employees?

Easy
413

An IS auditor is reviewing a system development project to assess whether it is on schedule. Which of the following would provide the BEST evidence of project progress against the planned timeline?

Medium
414

Refer to the exhibit. During a security audit, an IS analyst identifies that a critical business application hosted on 192.168.1.100:443 is unreachable from the 10.0.1.0/24 subnet. Which of the following is the MOST likely cause?

Hard
415

During a change management board (CAB) meeting, a proposed change to the network firewall configuration is discussed. The change is considered low risk and pre-approved. Which type of change does this represent?

Easy
416

An organization is implementing a new system using a rapid application development (RAD) approach. The IS auditor is concerned about the lack of formal documentation. Which of the following is the MOST appropriate audit response?

Medium
417

You are the IT governance lead at a multinational corporation with a complex IT environment spanning multiple business units. The company has recently experienced a series of minor security incidents where unauthorized access was gained through unused user accounts that were not disabled after employees left the organization. Additionally, there have been delays in provisioning access for new hires, leading to productivity losses. The IT department currently uses a manual process for access management, with each business unit maintaining its own user lists. The company has a policy that requires access reviews every quarter, but these are often missed or performed superficially. The CIO has asked you to recommend a solution that addresses these issues while ensuring compliance with regulations such as GDPR and SOX. Which of the following is the BEST course of action?

Hard
418

During system development, which testing phase is performed by developers to verify that individual program units function correctly?

Medium
419

Which TWO of the following are indicators that a project is at risk of failure according to ISACA's project governance framework?

Hard
420

Refer to the exhibit. An auditor notices this log entry during a review. The user john.doe does not have a legitimate business need to access executive salaries. Which of the following is the MOST likely control failure?

Medium
421

An IT steering committee is reviewing a proposal for a new customer relationship management (CRM) system. What is the committee's MOST important role?

Medium
422

An IS auditor is examining how a financial services firm enforces data loss prevention (DLP) for outbound email. The firm uses a network DLP appliance that inspects SMTP traffic and blocks messages containing unencrypted account numbers. The auditor discovers that employees can bypass the appliance by using a personal webmail account over HTTPS. Which of the following should the auditor recommend FIRST?

Hard
423

Which of the following is the PRIMARY purpose of a business impact analysis (BIA)?

Easy
424

An auditor discovers that a financial institution's IT department uses a decentralized model, with each business unit managing its own applications. What is a PRIMARY risk of this structure?

Hard
425

An auditor is selecting a sample of purchase orders for testing. The auditor decides to select every 50th purchase order from a list. This is an example of:

Medium
426

An IS auditor is evaluating how an organization detects unauthorized changes to the configuration of its internet-facing web servers. The organization runs a file integrity monitoring tool that hashes critical configuration files hourly and alerts on any hash mismatch. Which of the following is the MOST important factor in determining whether this control provides effective detection?

Medium
427

An IS auditor is examining how a data center protects its backup tapes while they are transported to an offsite vault. Management states that tapes are encrypted at rest using AES-256. Which of the following is the MOST important control the auditor should verify to protect the tapes during transit?

Medium
428

Which TWO of the following are types of analytical procedures used in an IS audit? (Select two.)

Medium
429

Which THREE of the following are common challenges when integrating a software package with existing legacy systems? (Select exactly three.)

Hard
430

An organization is implementing a large ERP system. The project manager is concerned about segregation of duties conflicts. Which THREE controls should the IS auditor recommend to mitigate segregation of duties risks during implementation? (Select THREE)

Hard
431

An IS auditor is reviewing an agile software development project. Which of the following would be the BEST evidence that adequate controls are in place for user acceptance?

Medium
432

An IT manager needs to ensure that the organization's IT resources are used efficiently. Which of the following is the BEST metric to measure IT resource utilization?

Easy
433

Which TWO of the following are BEST indicators that a system development project is at risk of failure?

Hard
434

During a spiral SDLC project, the IS auditor should focus on which aspect as the primary risk?

Hard
435

During a firewall rule review, an IS auditor identifies several rules that allow any-to-any traffic. Which THREE of the following should the auditor recommend as the MOST appropriate actions?

Hard
436

An organization experiences a critical system failure during non-business hours. The IT team discovers that the last full backup was 48 hours ago, and the incremental backups for the past 24 hours are corrupted. The recovery time objective (RTO) for this system is 4 hours, and the recovery point objective (RPO) is 1 hour. Which of the following is the MOST immediate concern?

Medium
437

Which of the following is a key advantage of using an iterative SDLC model over a waterfall model?

Easy
438

An organization has a clean desk policy. Which of the following is the BEST audit procedure to test compliance with this policy?

Medium
439

A mid-sized company is upgrading its legacy financial system to a new cloud-based ERP. The project manager has decided to use a big-bang cutover approach to minimize costs and time. During the first week post-go-live, users report that several critical reports are generating incorrect totals. An initial investigation reveals that the data mapping from the old system to the new system was not fully validated. Which of the following should the IS auditor recommend as the most appropriate corrective action?

Easy
440

Which of the following is the PRIMARY benefit of using a prototype during system development?

Easy
441

An IS auditor is assessing the effectiveness of the change management process for a critical financial application. The auditor wants to determine whether changes are adequately tested before being deployed to production. Which TWO of the following procedures would provide the MOST relevant evidence? (Choose two.)

Medium
442

An IS auditor is reviewing an organization's problem management process. The auditor finds that problem records are created only after multiple incidents with the same root cause have occurred, and there is no proactive trend analysis. Which TWO of the following are the MOST important improvements the auditor should recommend? (Choose two.)

Medium
443

An organization's IT department is considering a shift from insourcing to co-sourcing for application development. What is a PRIMARY advantage of co-sourcing?

Medium
444

An IS auditor is reviewing how an organization manages its backup media. The auditor learns that full backups are written to tape each night, the tapes are stored in a cabinet in the data center, and the same cabinet is used to store cleaning supplies and spare hardware. Which of the following is the MOST significant risk the auditor should highlight?

Medium
445

An organization is implementing a data masking solution for a non-production database. Which of the following is the MOST important requirement?

Medium
446

An organization has a policy requiring annual information security awareness training for all employees. During a recent audit, it was found that 20% of employees had not completed the training. What is the BEST course of action for the IT governance committee?

Easy
447

An IT auditor is reviewing the problem management process. The IT team maintains a repository of known errors with documented workarounds. Which component of problem management is this?

Medium
448

Which THREE of the following are common challenges when implementing a bring-your-own-device (BYOD) policy that affect information systems operations? (Select exactly 3.)

Hard
449

Which TWO of the following are essential controls to ensure data integrity during a cloud migration project?

Medium
450

A company outsources its data center operations to a third-party provider. Which of the following is the MOST important control to include in the outsourcing contract?

Medium
451

An IS auditor is evaluating the reliability of audit evidence obtained during a review of an outsourced payroll provider. Which TWO of the following considerations most directly affect the reliability of that evidence? (Choose two.)

Medium
452

Which THREE of the following are commonly used data encryption standards? (Choose three.)

Easy
453

An IS auditor is reviewing logical access controls for a critical application. Which of the following is the MOST important control to detect unauthorized access?

Medium
454

An IS auditor is reviewing change management for a financial application. Which TWO of the following findings would most likely indicate a control weakness?

Hard
455

An organization is implementing a data classification policy and needs to assign ownership for sensitive data. Which of the following is the most appropriate role to assign as the data owner?

Medium
456

An IS auditor is reviewing an organization's IT operations incident management process. The auditor finds that incidents are logged, but there is no formal problem management process. Which TWO of the following are the MOST likely consequences of this deficiency? (Choose two.)

Hard
457

A multinational corporation is replacing its legacy on-premises customer relationship management (CRM) system with a new cloud-based CRM solution. The project involves migrating data from the old system, customizing the new system to match business processes, and integrating with an existing enterprise resource planning (ERP) system. The project has a tight deadline of six months. During the planning phase, the project team decides to use a waterfall methodology because the requirements are well-defined. However, three months into the project, the business users request significant changes to the customer data fields, which were not originally specified. The project manager is concerned that accommodating these changes will delay the project. The integration with the ERP system is also proving more complex than anticipated, with data mapping errors causing delays. The go-live date is fixed due to the end-of-support for the legacy system. What is the BEST course of action for the project manager?

Hard
458

An IS auditor is designing substantive test procedures for a newly implemented automated accounts payable system and wants to rely less on the client's automated controls. The auditor decides to use computer-assisted audit techniques to test the completeness and accuracy of transaction processing. Which TWO of the following techniques would BEST provide direct evidence about the population of transactions? (Choose two.)

Hard
459

A company is in the process of acquiring a new customer relationship management (CRM) system. During which phase of the systems development life cycle (SDLC) should the business requirements be formally documented?

Easy
460

An IS auditor is reviewing the acquisition of a new software package. The vendor provides a Service Organization Control (SOC) 2 Type II report. Which of the following is the MOST important factor for the auditor to consider when relying on this report?

Medium
461

An organization uses risk-based authentication (RBA) for user access. Which of the following factors would MOST likely trigger a step-up authentication?

Medium
462

An IS auditor is evaluating the effectiveness of a security awareness program. Which of the following metrics would BEST indicate that the program is achieving its objectives?

Medium
463

An organization's IT policy review cycle is set to every two years. However, a new regulation requires immediate changes to data retention policies. What is the best course of action?

Medium
464

An IS auditor is auditing the user access management process for a large healthcare organization that uses an electronic health records (EHR) system. The organization has 5,000 users including doctors, nurses, and administrative staff. The auditor reviews a sample of access requests and finds that 20% of the requests were approved by the user's manager but the approval was not documented in the system. The auditor also finds that there is no periodic review of user access rights. The IT security manager states that users are automatically provisioned based on their role in the HR system, and that access reviews are performed manually by managers but not documented. What is the auditor's BEST recommendation to address the most significant risk?

Medium
465

An IS auditor is reviewing an organization's disaster recovery plan (DRP) for its primary data center. The DRP specifies a reciprocal arrangement with a partner organization for backup processing. Which of the following is the MOST significant risk associated with this arrangement that the auditor should highlight?

Hard
466

A project team is using a prototyping approach for a new system. Which of the following is the BEST control to ensure the prototype accurately reflects user needs?

Medium
467

An IS auditor is planning an audit of a cloud service provider's security controls. The auditor has limited access to the provider's internal systems. Which of the following would be the MOST effective way to obtain assurance over the provider's security controls?

Medium
468

An IS auditor is reviewing the implementation of a new payroll system that was developed in-house. The project team followed a traditional waterfall SDLC. During the post-implementation review, the auditor found that the system was delivered on time and within budget, but several critical payroll calculations were incorrect, leading to employee underpayments. The root cause was traced to a misunderstanding of tax law changes that occurred during the requirements phase. Which of the following is the MOST likely control weakness that contributed to this issue?

Hard
469

Which of the following best describes the primary advantage of using statistical sampling over non-statistical sampling in an IS audit?

Hard
470

During a disaster recovery test, the IS auditor observes that the alternate site uses a warm site configuration. Which of the following is a characteristic of a warm site?

Hard
471

When implementing a data classification policy, which of the following roles is PRIMARILY responsible for assigning classification labels to data?

Easy
472

During a software asset management (SAM) audit, the IS auditor discovers that the organization is using software versions that are no longer supported by the vendor. What is the primary risk?

Medium
473

During a system development project, the IS auditor notes that code reviews are performed only after the code is unit tested. Which of the following is the MOST significant risk associated with this practice?

Medium
474

During an incident response, the IT team isolates a compromised system from the network. Which of the following is the primary purpose of this action?

Easy
475

A nonprofit organization develops a small online donation platform using a third-party payment gateway. The project team skips formal security testing because of budget constraints. After launch, a security researcher discovers that the application fails to validate input on the donation amount field, allowing manipulation. The nonprofit loses several thousand dollars before the issue is patched. The IS auditor is asked to review the system development process. Which of the following is the PRIMARY finding?

Easy
476

An IS auditor reviews the exhibit. Which of the following is the most likely cause of the denied traffic?

Easy
477

Which of the following is an example of a compliance audit?

Easy
478

Which TWO of the following are HR controls that help mitigate the risk of insider fraud in IT? (Select TWO.)

Easy
479

An IS auditor is reviewing the change management process for a financial application. Which of the following findings would be of MOST concern?

Medium
480

A company stores sensitive customer data in a database. To comply with privacy regulations, the data must be anonymized for analytics. Which technique provides the strongest anonymization while preserving data utility?

Hard
481

An IS auditor is evaluating the IT service continuity plan for a hospital's electronic health record (EHR) system. The auditor finds that the plan includes a recovery time objective (RTO) of 4 hours, but the hospital's clinical staff state that they can tolerate only 1 hour of downtime before patient safety is compromised. Which of the following should the auditor recommend FIRST?

Medium
482

Refer to the exhibit. This log entry MOST likely indicates:

Hard
483

An organization has outsourced its IT help desk to a third-party provider. Which of the following is the MOST critical control to ensure service quality?

Hard
484

An IS auditor is performing a walkthrough of a purchase-to-pay process. Which of the following is the auditor most likely trying to achieve?

Medium
485

An IS auditor is evaluating how an organization enforces segregation of duties (SoD) within its enterprise resource planning (ERP) system. Management states that SoD conflicts are identified during user provisioning. Which TWO of the following audit procedures would BEST determine whether SoD controls operate effectively on an ongoing basis? (Choose two.)

Hard
486

An IS auditor is reviewing the antivirus and endpoint protection deployment across a hospital's clinical workstations. The auditor finds that signature updates are delivered daily, real-time scanning is enabled on all workstations, but the endpoint protection console shows that 40 of 600 workstations have not checked in for more than 30 days. Which of the following should the auditor do FIRST?

Easy
487

A financial services company is migrating its core banking system to a public cloud to improve scalability and reduce costs. The project is high-risk due to regulatory compliance requirements (e.g., data residency, audit trails). The IT governance committee has reviewed the project plan and finds that the risk assessment is incomplete – it does not address the potential impact of a cloud provider outage on critical transactions. The committee must approve the project or request changes. The project manager argues that the cloud provider's SLA guarantees 99.99% uptime and that additional controls would delay the project. What should the governance committee do?

Medium
488

An organization is considering acquiring a commercial off-the-shelf (COTS) ERP system. Which of the following risks is most effectively mitigated by including a contractual clause for audit rights?

Hard
489

An organization wants to protect its intellectual property from unauthorized disclosure via email. Which control should be implemented?

Easy
490

Based on the exhibit, which control is most likely missing to prevent this type of event?

Hard
491

During a post-implementation review of a new customer relationship management (CRM) system, the IS auditor finds that the system is processing transactions slower than anticipated. What is the BEST initial course of action for the auditor?

Medium
492

An IT manager is reviewing the access control model for a financial application. The policy requires that no single person can approve a transaction. Which access control principle does this policy enforce?

Medium
493

An organization is acquiring a new software package. The IS auditor is asked to review the contract with the vendor. Which of the following clauses is MOST important to ensure the organization can continue to use the software even if the vendor goes out of business?

Easy
494

Based on the exhibit, what is the MOST appropriate action for IT management?

Easy
495

An organization's IT department has grown rapidly, and the CIO wants to ensure that employees understand expected behaviors when handling sensitive data and operating critical systems. Which of the following is the MOST appropriate governance mechanism to establish?

Easy
496

An IS auditor is reviewing the problem management process after a series of recurring production outages. The auditor finds that incidents are resolved quickly but the same underlying faults reappear. Which TWO activities should the auditor expect to find in an effective problem management process? (Choose two.)

Medium
497

An IS auditor is assessing the effectiveness of network segmentation for a payment card processing environment. Which of the following is the PRIMARY benefit of network segmentation in meeting PCI DSS requirements?

Easy
498

Which TWO of the following are characteristics of the iterative SDLC model?

Easy
499

A hospital is implementing a new electronic health record (EHR) system. The project team includes clinicians and IT staff. During integration testing, the system fails to exchange lab results with the existing legacy system due to format mismatches. The IT team suggests developing a custom interface. The clinical team is concerned that any custom solution may not comply with health data privacy regulations. The project sponsor pressures the team to quickly fix the issue to avoid delays. The IS auditor is reviewing this situation. What is the MOST appropriate action for the auditor to recommend?

Medium
500

An IS auditor is reviewing the vulnerability management program. The auditor notes that a critical vulnerability was identified in a production system six months ago and has not been patched due to a business impact assessment. Which of the following should the auditor examine NEXT?

Medium
501

Order the steps for responding to a security incident in the correct sequence.

Medium
502

Which TWO of the following are essential components of a business case for a new system?

Easy
503

An organization is developing a new customer portal. The development team wants to use an agile methodology. Which of the following is a key benefit of using agile for this project?

Easy
504

In a RACI matrix for an IT process, which role should be assigned to the person who ultimately approves the outcome and is held accountable for its success?

Medium
505

An organization uses a chargeback model to allocate IT costs to business units. What is a PRIMARY benefit of this approach?

Easy
506

An IS auditor is reviewing firewall rule sets and discovers a rule that permits any source IP to access the internal database server on TCP port 1433 (Microsoft SQL). The rule was documented as a temporary measure but has been in place for 18 months. What is the auditor's BEST course of action?

Hard
507

Which TWO of the following are primary objectives of a data loss prevention (DLP) strategy?

Hard
508

An IS auditor is reviewing the requirements definition phase of a new system development project. The auditor finds that business users have provided functional requirements, but non-functional requirements are largely missing. Which TWO of the following are the MOST significant risks of proceeding without well-defined non-functional requirements? (Choose two.)

Hard
509

An IS auditor is reviewing how a retail company protects stored payment card data. The company states it encrypts card numbers using AES-256, but the auditor finds that the database encryption keys are stored in a plaintext configuration file on the same application server as the encrypted data. Which of the following is the auditor's PRIMARY concern?

Hard
510

Which of the following is the PRIMARY purpose of performing a walkthrough during the audit planning phase?

Medium
511

During a post-implementation review of a new ERP system, the IS auditor identified that the project was delivered within budget but user satisfaction scores are low. Which THREE areas should the auditor examine further?

Hard
512

An IS auditor is reviewing an organization's vulnerability management program. The auditor notes that a critical vulnerability in a key application has not been patched for 90 days, and there is no documented risk acceptance. What should the auditor do FIRST?

Hard
513

Which of the following is the PRIMARY purpose of a business impact analysis (BIA) in business continuity planning?

Easy
514

In an agile development environment, an IS auditor reviews the backlog and finds that security requirements are not explicitly included. What is the best recommendation?

Hard
515

An IS auditor is documenting the audit programme for an engagement and must decide how specific the procedures should be. Which of the following BEST describes the appropriate level of detail for procedures recorded in the audit programme?

Medium
516

A security review of the above Apache configuration identifies a critical vulnerability. Which of the following is the MOST significant issue?

Hard
517

During an agile software development project, which of the following events provides the best opportunity for the IS auditor to assess the effectiveness of controls implemented in the current sprint?

Easy
518

An organization is migrating sensitive customer data to a public cloud. Which of the following encryption strategies provides the STRONGEST protection against data exposure to the cloud provider?

Medium
519

An organization's IT strategy is not aligned with business strategy due to lack of communication. Which of the following would BEST improve alignment?

Hard
520

During an audit of privacy controls, the IS auditor discovers that the organization processes personal data of EU residents but has not appointed a Data Protection Officer (DPO). Which regulation is MOST likely being violated?

Hard
521

During a vendor evaluation for a critical system, the IS auditor notes that the vendor's SOC 2 report includes an adverse opinion. What should be the auditor's PRIMARY recommendation?

Medium
522

An organization is implementing a new human resources system. The IS auditor wants to determine whether the system will enforce segregation of duties (SoD) for sensitive transactions such as payroll changes and employee master data updates. Which of the following is the MOST appropriate source of evidence?

Easy
523

An IS auditor is reviewing a data center's environmental controls and observes that the fire suppression system uses water sprinklers in the main server room. The auditor learns that the sprinkler system was installed when the facility was a general office space. Management states that the sprinklers have never activated. Which of the following should the IS auditor recommend as the MOST appropriate control improvement?

Medium
524

An organization has decided to adopt a formal IT governance framework to improve alignment between IT and business objectives. Management asks the IS auditor to advise on the FIRST step in the adoption process. Which of the following should the IS auditor recommend?

Medium
525

Which TWO of the following are guiding principles of ITIL 4? (Select TWO)

Medium
526

A multinational corporation operates in a highly regulated industry. The IT governance framework includes a risk appetite statement approved by the board. Recently, the company suffered a significant data breach due to an unpatched vulnerability that had been identified three months earlier. The IT audit found that the vulnerability was reported to the IT department but was not prioritized for remediation because it was deemed low risk by the IT operations team. The incident response plan was not activated because the breach was not initially detected. The board wants to strengthen governance to prevent recurrence. The most effective course of action for the auditor to recommend is:

Hard
527

An organization is implementing a new identity management system. Which testing approach is MOST effective for verifying access controls?

Medium
528

An organization is considering whether to build a custom application or purchase a commercial off-the-shelf (COTS) product. Which of the following factors is MOST important when deciding to build rather than buy?

Medium
529

A security architect is designing a data classification schema for a multinational corporation. Which combination of factors is MOST critical for determining the classification level of a data asset?

Hard
530

An organization uses a risk-based audit approach. For a high-risk area, the auditor decides to perform 100% testing instead of sampling. Which of the following is a valid reason for this decision?

Hard
531

An IS auditor is planning an audit of a financial application. The auditor wants to ensure that audit effort is focused on areas with the highest risk. Which approach should the auditor adopt?

Medium
532

An IS auditor is reviewing the backup strategy for a transactional database that processes customer orders. The database is backed up nightly with full backups, and transaction log backups occur every 15 minutes. The recovery point objective (RPO) for the system is 5 minutes. Which of the following is the MOST significant finding the auditor should report?

Hard
533

An IS auditor is examining how a hospital enforces least privilege for its electronic health record (EHR) system. During walkthroughs, the auditor observes that nurses can access the billing module and that no formal process exists to request, approve, or periodically recertify role assignments. Which of the following is the MOST appropriate recommendation?

Medium
534

An organization is implementing a new payroll system using an agile methodology. Which TWO of the following are the MOST important controls for the IS auditor to assess?

Medium
535

An IS auditor is reviewing an organization's data loss prevention (DLP) strategy. The organization has implemented a network DLP solution but has not yet deployed endpoint DLP. Which TWO of the following are the MOST significant risks of relying solely on network DLP? (Choose two.)

Medium
536

An organization is implementing a new identity management system. Which THREE of the following are essential requirements for the system?

Medium
537

An organization outsources its IT help desk to a third-party vendor. Which clause is MOST important for the IS auditor to verify in the contract to ensure the organization can assess the vendor's controls?

Medium
538

An IS auditor is reviewing the access recertification process for a financial institution. The process requires users and their managers to confirm access rights quarterly. During the review, the auditor finds that recertifications are consistently completed late, with an average delay of 45 days. Additionally, terminated employees' access is not always removed promptly, and there are no compensating controls. Which of the following is the MOST significant risk arising from these findings?

Medium
539

An IT manager submits a request to change the firewall configuration during business hours. According to best practices for change management, what should be done FIRST?

Easy
540

An IS auditor is reviewing the organization's data inventory process for privacy compliance. Which TWO of the following are the MOST important elements that should be included in the data inventory?

Medium
541

Which TWO of the following are types of statistical sampling methods? (Select TWO.)

Medium
542

An organization's IT department implemented a new change management process that requires all changes to be approved by a change advisory board (CAB). A critical security patch needs to be deployed within 2 hours to address an active zero-day vulnerability. The change request was submitted but the CAB is not scheduled to meet for another 24 hours. What is the BEST course of action?

Medium
543

An IS auditor is reviewing the IT operations function of a mid-sized organization. Management asks which control would BEST ensure that capacity problems are detected before they affect users of critical production systems.

Easy
544

Which TWO of the following are the MOST effective controls to prevent unauthorized access to a data center's server room? (Choose two.)

Hard
545

Which of the following is the PRIMARY purpose of conducting a privacy impact assessment (PIA) before implementing a new system that processes personal data?

Easy
546

An IS auditor is reviewing the logical access controls of an enterprise resource planning (ERP) system. The auditor finds that terminated employees' accounts are disabled but not deleted. What is the PRIMARY risk associated with this practice?

Easy
547

Which of the following is the PRIMARY purpose of an IT governance framework?

Easy
548

Arrange the steps to implement a patch management process in the correct order.

Medium
549

An organization is developing a business continuity strategy. Which THREE of the following are essential components of a comprehensive BC strategy?

Hard
550

Which of the following is the most reliable form of audit evidence?

Medium
551

An IS auditor is assessing the physical and environmental controls of a primary data center located in a region subject to seasonal flooding. Management has installed a raised floor, a water detection system, and a pre-action fire suppression system. Which TWO of the following findings would the auditor consider MOST significant? (Choose two.)

Hard
552

Which of the following is a primary advantage of fixed-price contracts in systems acquisition?

Easy
553

An IS auditor is reviewing the job scheduling function for a mainframe environment that runs nightly batch processing. The auditor finds that the senior operator has standing access to modify production JCL and job schedules without a second approval. Which control should the auditor recommend to BEST mitigate the associated risk?

Medium
554

Which of the following is a key principle of corporate governance of IT according to ISO/IEC 38500?

Easy
555

During which phase of the audit process does the auditor perform procedures such as inquiry, observation, and inspection?

Easy
556

An organization has a disaster recovery plan that includes a hot site. During a full interruption test, the recovery team discovers that the hot site's network configuration is incompatible with the production environment. What is the most likely root cause?

Hard
557

After a security incident, an organization discovers that an employee accessed sensitive files without authorization. Which of the following is the most effective preventive control to reduce the risk of such unauthorized access?

Medium
558

An IS auditor is assessing how an organization classifies and handles its information assets. The auditor finds that a data classification policy exists but is inconsistently applied across business units. Which TWO of the following are the MOST important elements the auditor should verify are present to support effective data classification? (Choose two.)

Medium
559

Which type of audit evidence involves the auditor independently performing a control procedure to verify its effectiveness?

Medium
560

An IS auditor is planning a compliance audit of a payment gateway that processes credit card transactions. The auditor needs to determine whether the control environment meets the requirements of the applicable payment card industry standard. Which of the following should be the auditor's PRIMARY basis for defining the audit criteria?

Medium
561

Order the steps for performing a disaster recovery test in the correct sequence.

Medium
562

An organization is implementing a new cloud-based HR system. The project sponsor wants to skip regular project status meetings to speed up delivery. Which THREE of the following are the MOST significant risks of eliminating these meetings?

Hard
563

Which THREE of the following are valid reasons for implementing a service level management process? (Select THREE.)

Hard
564

An IS auditor is evaluating a control that requires the security administrator to review privileged access logs weekly. During testing, the auditor finds the reviews were performed but no evidence of follow-up exists for two anomalies identified in one review. Which of the following conclusions is MOST appropriate?

Hard
565

An IS auditor is reviewing the IT service continuity plan for a regional bank. The plan identifies a recovery time objective of 6 hours for the core banking system and designates a warm site with pre-installed hardware but no replicated data. The plan states that data will be restored from nightly backups stored in an offsite vault. Which of the following is the MOST critical issue the auditor should raise?

Medium
566

During a disaster recovery test, the team discovers that the backup server is unable to restore data because of incompatible software versions. Which TWO controls should have been implemented to prevent this?

Easy
567

An IS auditor is reviewing the IT governance framework of a financial services firm. The auditor notes that the IT strategy is updated annually, but there is no process to monitor whether IT initiatives are aligned with the strategy. Which of the following is the BEST recommendation?

Medium
568

An IS auditor is reviewing the audit documentation from a prior year and finds that a material weakness was reported but not remediated. According to ISACA standards, which audit phase should address this?

Hard
569

An IS auditor is reviewing an organization's backup and recovery procedures for a critical database. The backup policy states that full backups are performed weekly and transaction log backups every 15 minutes. The recovery point objective (RPO) for the database is 5 minutes. Which of the following is the MOST appropriate recommendation?

Medium
570

During a post-implementation review of a system, an IS auditor finds that the actual transaction processing time is 30% slower than projected. What should the auditor recommend FIRST?

Medium
571

During a review of a data center, an IS auditor observes that backup tapes containing customer records are transported nightly by a courier to an offsite vault. The tapes are placed in sealed containers, but the auditor learns that the courier contract does not require background checks for drivers and that no encryption is applied to the tape contents. Which of the following should the auditor recommend as the MOST effective compensating control?

Hard
572

An IS auditor is conducting an audit of a payroll application and needs to verify that user access rights match each employee's current job responsibilities. Which of the following is the MOST appropriate source of evidence for this test?

Easy
573

An organization is implementing a new financial system using the waterfall SDLC model. Which of the following is the MOST critical control to ensure that business requirements are met?

Easy
574

A government agency is developing a case management system for law enforcement. The project follows an agile approach, releasing iterations every two weeks. During a sprint demo, users discover that the system does not redact personally identifiable information (PII) in documents shared with external parties, violating privacy laws. The development team says they planned to add redaction in a future sprint. The product owner wants to prioritize PII redaction immediately. The project manager is concerned that this will disrupt the release schedule. The IS auditor is assessing the project's risk management. Which of the following is the BEST recommendation?

Hard
575

Which of the following BEST describes the role of threat modeling in the design phase of the SDLC?

Medium
576

An IS auditor is assessing the effectiveness of an organization's IT governance implementation. Which TWO of the following are the MOST important indicators that IT governance is effectively implemented? (Choose two.)

Hard
577

An organization is deploying a major system upgrade. The change request has been approved by CAB, but the deployment plan does not include a rollback procedure. As an IS auditor, what should you recommend?

Hard
578

Which of the following is the PRIMARY objective of a penetration test?

Easy
579

Which of the following is the PRIMARY purpose of an IT strategy committee?

Easy
580

During the follow-up phase of an audit, the auditor discovers that a previous finding has not been remediated. What is the auditor's BEST course of action?

Medium
581

In a waterfall SDLC, when should user acceptance testing (UAT) typically occur?

Easy
582

An auditor is evaluating the IT governance framework of a large bank. Which TWO of the following are components of COBIT 2019's governance system? (Select TWO.)

Medium
583

An IS auditor is evaluating how an organization manages its backup and restoration process for a critical financial application. The backup job completes successfully each night and writes to a tape library. Management states that recovery capability has been proven because the backup job reports success. Which audit procedure would BEST test whether the backups are actually restorable?

Hard
584

An IS auditor is conducting an audit of a hospital's electronic health record system. During fieldwork, the auditor discovers that several database administrators have the ability to modify patient records directly in the production database without leaving an audit trail. The auditor wants to gather sufficient appropriate evidence to determine whether this is a widespread issue. Which of the following is the MOST appropriate action?

Medium
585

An organization is implementing a new release management process. Which TWO activities are essential components of a successful release?

Easy
586

An organization is planning to replace its legacy accounting system with a commercial off-the-shelf (COTS) software package. Which of the following is the PRIMARY risk of using a COTS solution?

Easy
587

An organization has outsourced its IT operations to a third-party provider. The IS auditor is planning an audit of the outsourced services. What is the most appropriate source of audit evidence?

Easy
588

An IS auditor is assessing an organization's problem management process. The auditor finds that while incidents are logged and resolved, there is no formal problem management procedure. Several recurring incidents have been resolved with workarounds but not investigated for root cause. Which of the following is the MOST significant consequence of this deficiency?

Medium
589

An IS auditor is reviewing the problem management process of a financial services firm. The auditor finds that incidents are frequently resolved by the service desk using documented workarounds, but no problem records are created, and root cause analysis is rarely performed. As a result, the same high-impact incident has recurred 14 times in three months. Which of the following is the MOST significant risk arising from this practice?

Medium
590

Which of the following is a key objective of the design phase in the SDLC?

Easy
591

Which TWO of the following are phases of the audit process? (Select two.)

Easy
592

An organization's IT service desk is the single point of contact for all incidents. The SLA for resolving P2 incidents is 8 hours. The auditor finds that the service desk frequently reassigns P2 incidents to second-level support without updating the incident record, causing delays in resolution. The average resolution time for P2 incidents is 10 hours. What is the primary control weakness?

Hard
593

Which IT sourcing model involves using an external provider to manage some IT functions while retaining others in-house?

Easy
594

An organization uses a third-party cloud service for data storage. Which of the following is the BEST way to ensure data confidentiality in the event of a cloud provider breach?

Hard
595

A company requires employees to use smart cards for facility access. Which additional control would BEST prevent tailgating?

Easy
596

An IS auditor is reviewing an organization's IT governance structure and finds that the IT steering committee meets quarterly but has no defined charter or decision-making authority. Which of the following is the MOST significant risk arising from this situation?

Medium
597

An organization's IT security policy requires background checks for all IT staff handling sensitive data. Which of the following is the PRIMARY reason for this requirement?

Medium
598

An IS auditor is evaluating an organization's backup strategy for a critical database. The database is backed up nightly using a full backup, and transaction logs are backed up every 15 minutes. The auditor discovers that the transaction log backups are written to the same storage array as the database files. Which of the following is the MOST significant risk?

Hard
599

The IT governance objective 'Evaluate-Direct-Monitor' in COBIT 2019 is primarily associated with which role?

Easy
600

A retail company is merging with a competitor. The IT departments of both organizations have different IT governance structures: Company A uses a centralized model with strict change management, while Company B uses a decentralized model with autonomous business unit IT. The CIO has been tasked with integrating the IT functions post-merger. The board expects cost synergies and improved service levels. The integration team is facing resistance from Company B's business heads who fear loss of agility. The CIO needs to propose a governance model for the merged entity. Which approach would BEST meet the board's expectations while addressing resistance?

Medium
601

An IS auditor is assessing the effectiveness of an organization's IT governance framework. Which THREE of the following are key indicators of a mature governance process?

Hard
602

An IS auditor is evaluating the effectiveness of a backup strategy for a critical database. Which TWO of the following are essential controls to ensure data recoverability?

Medium
603

An organization has decentralized IT management with each business unit making its own technology decisions. Which of the following is the BEST way to maintain enterprise-wide governance?

Hard
604

Which TWO of the following are examples of detective controls? (Choose two.)

Medium
605

A company's backup policy requires that backup media be stored offsite. Which of the following is the PRIMARY reason for this requirement?

Easy
606

An IS auditor is evaluating an organization's IT risk management process. The auditor finds that risk assessments are performed annually by the IT department alone, without input from business units. Which of the following is the MOST significant concern?

Hard
607

An organization is disposing of old servers. The IS auditor reviews the asset disposition process and finds that hard drives are being erased using a standard format command. What is the auditor's primary concern?

Hard
608

During an audit of a cloud service provider, the IS auditor finds that the provider's datacenter access logs show multiple successful logins by an employee during non-business hours over several weeks. The employee works in the sales department. What should the auditor do first?

Medium
609

An IS auditor is assessing the business impact analysis (BIA) for a critical business function. The BIA identifies a maximum tolerable downtime (MTD) of 8 hours and a recovery time objective (RTO) of 4 hours. The current disaster recovery plan (DRP) states that the recovery of this function will take 6 hours. What should the IS auditor conclude?

Easy
610

An e-commerce company stores customer payment card data in a tokenized database. The tokenization system replaces credit card numbers with tokens, and the actual card numbers are stored in a separate, highly restricted vault. The company is audited for Payment Card Industry Data Security Standard (PCI DSS) compliance. During the audit, it is discovered that the tokenization system sometimes fails due to high load, causing the application to fall back to storing actual card numbers temporarily. This fallback mechanism was not documented or approved. The company also uses the same encryption key for the vault as for other non-sensitive data. The auditor identifies several non-compliances. Which of the following should the company prioritize to remediate?

Medium
611

During an ERP implementation, the project team decides to customize the software to align with existing business processes. Which of the following risks is MOST likely to increase as a result of extensive customization?

Medium
612

Which of the following is a key difference between internal and external auditors?

Medium
613

An organization is implementing a disaster recovery plan. The DR team wants to test the plan with minimal risk and without impacting production operations. Which type of test is most appropriate?

Medium
614

An organization has defined an RTO of 4 hours for its critical financial system. During a disaster recovery test, the system was recovered in 3.5 hours, but data loss was 30 minutes. Which metric is most directly addressed by the recovery time?

Easy
615

During the planning phase of an IS audit, the auditor identifies that the organization has recently implemented a new ERP system. The audit team has limited experience with this ERP. Which of the following is the BEST course of action?

Medium
616

An organization outsources its data center operations. What is the BEST way to ensure the service provider's controls are effective?

Hard
617

Which of the following is the PRIMARY benefit of conducting a tabletop exercise for disaster recovery?

Easy
618

You are an IS auditor reviewing the remote access configuration for a medium-sized enterprise. The company uses a VPN concentrator to allow employees to connect from home. The VPN is configured with IPsec using pre-shared keys (PSK) and requires no multi-factor authentication. Employees use company-issued laptops with full disk encryption. The VPN logs show that connections are coming from a wide range of IP addresses, including some from countries where the company has no business operations. The IT manager argues that the PSK is changed monthly and that full disk encryption mitigates any risk. However, during the audit, you find that the PSK is stored in a shared document on an internal file server accessible to all employees. Additionally, the VPN concentrator uses a single PSK for all users. Which of the following is the MOST critical finding?

Hard
619

An IS auditor is planning an audit of a newly implemented financial system. Which of the following is the PRIMARY consideration when determining the audit scope?

Easy
620

An IT policy exception is requested to allow a legacy system that cannot be patched to remain in operation. What is the BEST way to manage this exception?

Medium
621

An organization has the storage bucket policy shown. Which of the following is the MOST likely intent of this policy?

Medium
622

You are the lead IT auditor for a multinational corporation that recently completed a merger with another company. During the post-merger integration audit, you discover that the acquired company's legacy HR system contains sensitive personal data of 20,000 employees and has been directly accessible from the internet for the last 18 months. The system runs on an unsupported operating system (Windows Server 2008) and uses a custom-built application with no logging enabled. The acquired company's IT manager argues that the server is isolated behind a firewall and has never been compromised. However, your review of firewall logs shows numerous connection attempts from unknown IP addresses. The integration team plans to decommission this system in three months. You need to determine the appropriate audit response. Which of the following should you do NEXT?

Hard
623

An IS auditor is reviewing the backup strategy for a financial institution. The backup administrator states that full backups are taken every Sunday, and incremental backups are taken Monday through Saturday. On Thursday morning, a database server fails, and the administrator needs to restore the server to its state as of Wednesday night. Which backup sets must the administrator use to perform this restoration?

Medium
624

An organization classifies IT incidents based on severity. A critical financial application is unavailable, impacting all users. According to ITIL best practices, which severity level should this incident be assigned?

Medium
625

Which type of disaster recovery test involves a full switch-over from the primary site to the alternate site, resulting in actual disruption of normal operations?

Easy
626

An IS auditor is reviewing the logical access controls for a financial application. The auditor notices that user access reviews are performed annually by the application owner, but there is no documentation indicating that managers confirm the continued need for access. Which of the following is the MOST significant risk associated with this finding?

Medium
627

An organization is adopting ITIL 4 to improve its service management practices. Which guiding principle emphasizes understanding how different components work together to deliver value?

Hard
628

An organization is implementing a business continuity plan (BCP). Which of the following is the PRIMARY purpose of conducting a business impact analysis (BIA)?

Easy
629

An organization has a policy requiring strong passwords. Which additional control is most effective at preventing credential stuffing attacks?

Easy
630

Which document is typically included in the permanent file of audit documentation?

Easy
631

An auditor is reviewing IT policy compliance and finds that a critical policy was last updated three years ago. The organization has undergone significant changes. What is the auditor's PRIMARY concern?

Hard
632

An IS auditor is reviewing a software development project that follows the waterfall model. Which of the following is the MAIN advantage of this methodology?

Easy
633

Which THREE of the following are responsibilities of the board of directors regarding IT governance? (Choose three.)

Hard
634

During a change management audit, an IS auditor finds that a critical system change was approved by the change manager without a CAB meeting. The change was categorized as a standard change. Which of the following should the auditor do FIRST?

Medium
635

An auditor is reviewing the encryption strategy for a healthcare application that stores protected health information (PHI) in a database. The database currently uses transparent data encryption (TDE). What is a key risk associated with TDE?

Medium
636

Refer to the exhibit. A tester executes test case TC-101 and records the result shown. What is the NEXT appropriate step in the testing process?

Medium
637

An IS auditor is reviewing the governance structure of a large retail company. The board has delegated all IT oversight to the IT steering committee, which meets quarterly and focuses primarily on project prioritization. The auditor notes that the board receives no IT-related reports and does not review IT risks. Which of the following is the MOST significant governance concern?

Medium
638

An organization is implementing a new IT governance framework. Which of the following is the BEST approach to ensure alignment between IT strategy and business goals?

Medium
639

When implementing a commercial off-the-shelf (COTS) software package, which of the following is the MOST important activity to ensure the software meets business requirements?

Easy
640

Which TWO of the following are examples of administrative controls for information security?

Easy
641

An IS auditor is evaluating the design of controls over a new financial system. Which of the following is the BEST approach to assess control design?

Hard
642

During a penetration test, a tester discovers that an application stores passwords using a reversible encryption algorithm. Which of the following is the BEST remediation?

Medium
643

According to ITIL 4, which guiding principle emphasizes understanding the current state before making improvements?

Medium
644

During system development, the project team discovers that the original requirements are incomplete. What is the BEST course of action?

Medium
645

An organization is implementing an automated job scheduling system. Which of the following is the PRIMARY benefit of using dependency management in job scheduling?

Medium
646

An IS auditor is reviewing an organization's data loss prevention (DLP) deployment. The auditor finds that the DLP solution is configured to monitor outbound email traffic at the network gateway, but endpoint agents are not installed on any workstations. Management states that this configuration is sufficient because all sensitive data leaves through email. Which of the following is the MOST significant risk arising from this configuration?

Medium
647

A multinational corporation is adopting a hybrid cloud strategy. The IT governance board must decide on a framework to ensure alignment with business objectives and regulatory compliance. Which framework is MOST appropriate?

Hard
648

An IT auditor is reviewing the alignment of IT with business strategy. Which THREE of the following are indicators of effective IT strategy alignment? (Select THREE.)

Hard
649

An IS auditor is evaluating an organization's IT governance framework. The auditor finds that IT decisions are made ad hoc by various business units without alignment to corporate strategy. Which TWO of the following are the MOST important governance mechanisms the auditor should recommend to address this issue? (Choose two.)

Hard
650

During a spiral SDLC project, the project team has completed a risk analysis and created a prototype. What is the most likely next step in the spiral model?

Hard
651

Which TWO of the following are examples of analytical procedures used as audit evidence? (Select two.)

Medium
652

An IS auditor is reviewing the system design phase of a project. Which of the following activities is most important to ensure that security is adequately addressed?

Medium
653

Which of the following is a characteristic of non-statistical (judgmental) sampling?

Medium
654

A company is implementing a new customer relationship management (CRM) system. The project team is currently defining user roles and permissions. Which of the following is the PRIMARY reason to enforce segregation of duties (SoD) within the CRM?

Easy
655

An IS auditor is reviewing the physical security of a data center. The auditor observes that the main entrance uses a proximity card reader, but the door to the server cage area is propped open with a box because the badge reader is malfunctioning. Staff state that the reader has been broken for two weeks and that a work order has been submitted. Which of the following should the IS auditor recommend FIRST?

Easy
656

A company's IT service desk receives multiple reports of users being unable to access a cloud-based CRM system. The network team confirms that internet connectivity is working. Which of the following should be the FIRST step in troubleshooting the issue?

Medium
657

A medium-sized financial services firm recently suffered a ransomware attack that encrypted critical servers and backups. The recovery process took three weeks because the backup tapes were stored in the same building (which was also infected) and the backup software had a vulnerability that allowed the ransomware to delete old backups. The firm's BCP did not account for simultaneous loss of primary and secondary data. As the IS auditor, you are asked to recommend the most effective improvement to the backup strategy to prevent recurrence and improve resilience. Which of the following actions should the firm implement?

Easy
658

During which phase of the waterfall SDLC should security requirements be formally documented and approved by the business owner?

Easy
659

Which of the following is the primary purpose of conducting a static application security test (SAST) during the development phase of the SDLC?

Easy
660

An IT auditor is reviewing the capacity management process. Which TWO of the following are key activities that should be performed?

Medium
661

A healthcare organization is required to comply with HIPAA regulations for data backup and disaster recovery. They operate a primary data center and a colocation facility for disaster recovery. The current backup strategy involves nightly full backups to tape, which are stored off-site monthly. The recovery time for the electronic health record (EHR) system is estimated at 8 hours, but the RTO required by the business is 2 hours. Additionally, the RPO requirement is 15 minutes. The IT manager proposes implementing a continuous data protection (CDP) solution. However, the CFO is concerned about the cost. Which of the following is the BEST argument to justify the CDP investment?

Hard
662

An IS auditor is evaluating the security of an organization's wireless network. The organization uses WPA3-Enterprise with 802.1X authentication. The auditor discovers that the RADIUS server is configured to accept EAP-TLS certificates but does not validate the certificate revocation status. Which of the following is the MOST likely consequence of this configuration?

Hard
663

A company is implementing a new ERP system. The project team plans to use a parallel conversion strategy. What is the PRIMARY advantage of this approach?

Medium
664

An IS auditor is reviewing a software-as-a-service (SaaS) provider that hosts a company's customer relationship management (CRM) data. The contract states the provider will maintain a SOC 2 Type II report, but the most recent report covers a period ending 14 months ago, and the provider has not responded to requests for a bridge letter. Which of the following should the auditor conclude?

Hard
665

What is the PRIMARY purpose of conducting a feasibility study before acquiring a new information system?

Easy
666

An organization is developing a web application using an Agile methodology. The security team wants to integrate security testing early in the development lifecycle. Which of the following is the BEST approach to achieve this?

Medium
667

An organization's business continuity plan includes a reciprocal agreement with another company. What is the PRIMARY risk of this arrangement?

Hard
668

An IS auditor is preparing working papers. Which of the following items should be included in the permanent file rather than the current file?

Hard
669

In a RACI matrix, the person who is ultimately accountable for a process outcome is assigned which role?

Easy
670

An IS auditor is examining how a retail bank protects stored cardholder data. The bank encrypts the primary account number in its customer database using AES-256, but the auditor learns that the encryption keys are stored in a configuration file on the same database server, readable by the database administrator account. Which of the following is the MOST appropriate conclusion?

Hard
671

In ITIL incident management, which severity level typically indicates a critical incident that severely impacts business operations and requires immediate resolution?

Easy
672

Which of the following is a key performance indicator (KPI) for IT service management?

Easy
673

An IS auditor is reviewing an organization's IT operations schedule and job dependency configuration for its overnight batch processing. The auditor discovers that several critical financial reconciliation jobs are scheduled with no predecessor dependencies and no defined restart procedures. The auditor also notes that operators frequently rerun failed jobs without documenting the cause. Which TWO findings should the auditor report as MOST significant operational risks? (Choose two.)

Hard
674

An IS auditor is reviewing change management procedures and finds that standard changes are approved by the change manager without CAB review. What is the auditor's BEST conclusion?

Medium
675

Match each type of access control to its definition.

Medium
676

An organization's business impact analysis shows that a payment processing system has a recovery time objective of two hours and a recovery point objective of fifteen minutes. The current disaster recovery strategy restores the system from nightly tape backups at an alternate site, with an observed restoration time of eight hours and up to twenty-four hours of data loss. Which action should the IS auditor recommend FIRST?

Hard
677

During an IT audit, the auditor discovers that the IT department has not conducted a business impact analysis (BIA) for three years. The organization's disaster recovery plan (DRP) is based on the previous BIA. The IT manager argues that the DRP is still valid because no major changes have occurred. What should the auditor recommend?

Hard
678

An organization is implementing a new customer relationship management (CRM) system. The project manager proposes using a pilot conversion strategy, where the new system is implemented in one department first, then gradually rolled out to others. Which of the following is the PRIMARY benefit of this approach?

Medium
679

During an audit, the auditor uses a sampling method where the population is divided into subgroups, and samples are selected from each subgroup. This method is known as:

Hard
680

A multinational corporation has adopted a decentralized IT governance model where business units have significant autonomy over IT decisions. The IS auditor is assessing the effectiveness of this model. Which of the following is the MOST critical factor for the auditor to evaluate?

Medium
681

During an ERP implementation, data migration is a critical activity. Which of the following controls would be most effective in ensuring the accuracy and completeness of migrated data?

Hard
682

A project uses a waterfall model. After design, the team discovers that the requirements have changed significantly. What is the BEST action?

Hard
683

An IS auditor is conducting a follow-up review of prior audit findings. Management has implemented a new automated control but has not yet updated the risk register to reflect the residual risk. Which of the following should the auditor do FIRST?

Medium
684

During an audit of the incident management process, the IS auditor finds that tabletop exercises have not been conducted in the past two years. What is the MOST significant risk associated with this finding?

Medium
685

An organization has implemented a database activity monitoring (DAM) solution. Which of the following are BEST practices for tuning the DAM to reduce false positives? (Choose TWO.)

Hard
686

Which of the following backup types copies only data that has changed since the last full backup?

Easy
687

An IS auditor is evaluating the use of continuous auditing techniques. Which of the following is the most significant benefit of implementing continuous monitoring over traditional periodic audits?

Hard
688

An IS auditor is reviewing a post-implementation review of a new payroll system. Which TWO findings should most concern the auditor? (Select two.)

Medium
689

A large enterprise is implementing a backup strategy for a critical database that requires an RTO of 2 hours and an RPO of 15 minutes. The database is 2 TB in size. Which backup method would BEST meet these requirements while minimizing storage costs?

Hard
690

Which THREE are indicators of a possible data exfiltration attempt via the network? (Choose three.)

Hard
691

An IS auditor is reviewing an organization's problem management process. The auditor wants to verify that the process effectively identifies and resolves root causes of incidents. Which TWO of the following are the MOST important controls to ensure effective problem management? (Choose two.)

Medium
692

An IS auditor is reviewing a project that replaced a legacy system. The project used a phased cutover, with each phase going live in a different region. After the final phase, the auditor finds that the legacy system was kept in read-only mode for six months, but no formal reconciliation was performed between legacy and new system balances during that period. Which of the following is the MOST significant concern?

Hard
693

Which of the following is the PRIMARY reason an external audit is considered more independent than an internal audit?

Easy
694

An IS auditor is evaluating the results of a penetration test performed by an external vendor on a web-facing application. The report identifies a critical SQL injection vulnerability. Which of the following is the MOST appropriate action for the IS auditor to recommend FIRST?

Medium
695

Which policy hierarchy document provides detailed steps for performing a specific task, such as resetting a user password?

Medium
696

During the acquisition of a new software package, the procurement team evaluates two vendors. Vendor A offers a lower upfront cost but higher annual maintenance fees. Vendor B has a higher upfront cost but includes three years of maintenance. What is the MOST important factor for the IS auditor to consider?

Medium
697

An organization outsources its help desk to a third-party vendor. The contract includes a service level agreement (SLA) with response times. The auditor wants to ensure that the organization can monitor vendor performance. Which clause is most important?

Medium
698

Which of the following types of audit evidence provides the highest level of assurance?

Medium
699

An organization's IT department has recently implemented a new project management methodology. The IS auditor is reviewing the project portfolio and finds that projects are prioritized based on the personal preferences of the IT director rather than strategic alignment. Which of the following is the MOST significant risk arising from this practice?

Easy
700

An IS auditor is reviewing a biometric access control system used to protect a data center. The system uses fingerprint recognition and is configured so that any single enrolled user who fails three consecutive attempts is locked out and must be re-enrolled by security staff. Which of the following is the MOST significant security concern with this configuration?

Hard
701

During the implementation of a new ERP system, the project team discovers that the legacy system data cannot be directly migrated due to incompatible data formats. The project manager proposes building a custom script to extract, transform, and load (ETL) data. Which of the following is the BEST course of action?

Medium
702

During the fieldwork phase, an IS auditor uses analytical procedures to compare current year IT expenses to prior year. A significant increase is noted. What should the auditor do next?

Medium
703

Which physical security control is most effective for preventing unauthorized individuals from tailgating into a data center?

Easy
704

Refer to the exhibit. A CISA is reviewing this S3 bucket policy. What is the PRIMARY security concern?

Easy
705

During a problem management meeting, the team identifies a recurring issue causing multiple incidents. The root cause is known, but a permanent fix is not yet available. Which of the following is the BEST approach to manage this situation until a permanent fix is implemented?

Medium
706

An IS auditor is testing the effectiveness of a control that involves a manual review of exception reports. The population of exceptions is 5,000 items. The auditor wants to achieve a 95% confidence level with a tolerable error rate of 2%. Which sampling method is MOST appropriate?

Hard
707

Which backup method copies all data that has changed since the last full backup, regardless of subsequent incremental backups, and is often used to reduce restore time?

Easy
708

An IT auditor is reviewing capacity management. The server team monitors CPU utilization and disk space. They receive alerts when thresholds are exceeded. Which practice is most effective for proactive capacity planning?

Easy
709

During a follow-up audit, an IS auditor finds that management implemented a compensating control rather than the recommended primary control to address a previously reported high-risk finding. The residual risk is now within the organization's risk appetite. How should the IS auditor respond?

Hard
710

An organization is implementing an IT governance framework to align IT with business objectives. Which TWO of the following are primary responsibilities of the IT steering committee?

Medium
711

A large financial institution has a well-defined IT governance framework with a clear organizational structure, policies, and processes. However, the internal audit department has identified that several IT projects are over budget and behind schedule. The project managers blame unclear requirements and scope creep. The IT governance committee meets monthly but reviews projects only at a high level. The auditor's best recommendation to improve project governance is to:

Medium
712

An IS auditor selects a sample of 50 transactions from a population of 1,000 using a random number generator. This is an example of which sampling method?

Medium
713

Which COBIT 2019 governance objective describes the board's responsibility for overseeing IT?

Easy
714

What is the primary purpose of the planning phase in an IS audit?

Easy
715

Which TWO of the following are primary objectives of information classification? (Choose two.)

Easy
716

An IS auditor is evaluating the disaster recovery plan (DRP) for a organization that relies on a cloud-based ERP system. The DRP states that the recovery time objective (RTO) is 4 hours and the recovery point objective (RPO) is 1 hour. The cloud provider's SLA guarantees 99.9% availability but does not specify RTO or RPO. Which of the following should the auditor recommend FIRST?

Hard
717

During an audit of an organization's backup and recovery process, the IS auditor finds that full backups are performed weekly and incremental backups are performed nightly. Restoration testing has not been performed in over two years. Which of the following should the auditor do FIRST?

Medium
718

During a risk assessment, an IS auditor identifies that the IT department has not performed a business impact analysis (BIA) for critical systems. Which of the following is the MOST significant risk?

Hard
719

An IS auditor is reviewing the software asset management (SAM) process. The organization uses a mix of commercial off-the-shelf (COTS) and open-source software. The auditor finds that several servers are running end-of-life (EOL) operating systems that are no longer patched. Which TWO risks are most directly associated with this finding?

Medium
720

An IS auditor is evaluating an organization's IT governance maturity using COBIT 2019. The auditor finds that IT processes are largely ad hoc, with no formal documentation, and success depends on individual heroics. Which of the following maturity levels BEST describes this situation?

Hard
721

An organization is evaluating two vendors for a critical cloud-based ERP system. Which TWO contractual clauses are most important to include to ensure the organization can monitor vendor performance and security? (Select TWO)

Medium
722

Based on the exhibit, what is the most likely control weakness that allowed this condition?

Medium
723

An IS auditor is reviewing automated job scheduling controls. A critical batch job failed due to a dependency on a previous job that had not completed. The system did not alert operations staff. Which control weakness is most significant?

Hard
724

Refer to the exhibit. An IS auditor is reviewing backup error logs. The error indicates a failed backup due to a missing file. What is the MOST likely cause?

Easy
725

During a review of the incident management process, the IS auditor finds that the incident response (IR) team conducts tabletop exercises annually, but the scenarios are limited to malware outbreaks. Which of the following should be the auditor's GREATEST concern?

Hard
726

An organization is replacing its legacy customer relationship management (CRM) system. Which of the following is the MOST important control to ensure data integrity during the data conversion process?

Easy
727

An IS auditor is evaluating the IT governance structure of a multinational corporation. The auditor finds that IT decisions are made independently by regional business units, with no central oversight. The corporate IT strategy exists but is not enforced. Which of the following is the MOST likely consequence of this governance approach?

Hard
728

An IS auditor is reviewing the problem management process. The auditor finds that problem tickets are only created after a major incident, and there is no proactive analysis of incident trends to identify underlying problems. Which of the following is the MOST likely consequence of this approach?

Medium
729

Which of the following is a principle of ISO/IEC 38500 for corporate governance of IT?

Easy
730

An IS auditor is reviewing a project to implement a new customer relationship management (CRM) system. The project manager has created a work breakdown structure (WBS) and a Gantt chart. Which of the following should the auditor verify to ensure the project schedule is realistic?

Medium
731

An IS auditor is performing a walkthrough of the accounts payable process. Which audit procedure is the auditor primarily executing?

Medium
732

During data conversion from a legacy system to a new ERP, the project team decides to clean data during extraction but not during loading. What is the PRIMARY risk associated with this approach?

Hard
733

An organization is implementing an ERP system and is concerned about segregation of duties conflicts. What is the most effective control to address this risk during implementation?

Medium
734

An IS auditor is evaluating a system development project that uses an outsourced team. The contract allows the vendor to reuse some of the developed code in other projects. What is the auditor's PRIMARY concern?

Hard
735

When implementing a commercial off-the-shelf (COTS) system, what is the MOST important factor?

Easy
736

An IS auditor is evaluating the design of controls over a critical financial application. The auditor performs a walkthrough and identifies that a control is missing but management has compensating controls. Which of the following is the auditor's BEST next step?

Hard
737

A retail organization's board has approved an IT governance framework that delegates decision rights for infrastructure standards to a central architecture board, while reserving funding decisions above a threshold for the board's technology committee. Business units must comply with the standards but may request exceptions. Which of the following is the MOST important control for the IS auditor to verify when assessing the effectiveness of this framework?

Hard
738

Which TWO of the following are benefits of using a version control system in software development?

Easy
739

An IS auditor reviewing the backup strategy for a financial application finds that full backups run every Sunday, with daily incremental backups Monday through Saturday. The recovery point objective (RPO) for the application is 4 hours. Which of the following is the MOST significant finding?

Medium
740

A company outsources its data center operations. Which IT governance practice is MOST critical to ensure the outsourcing arrangement meets business requirements?

Hard
741

An IT department uses a balanced scorecard to measure performance. Which metric would BEST reflect the 'customer perspective'?

Easy
742

Which of the following is a key objective of a post-implementation review?

Easy
743

Which THREE of the following are typical phases in the system development life cycle (SDLC)?

Easy
744

A multinational corporation's data center in the European Union (EU) stores personal data of EU citizens. The company must comply with the General Data Protection Regulation (GDPR), which requires that personal data be protected and that data subjects have the right to erasure ('right to be forgotten'). The company's IT team uses a centralized identity management system that stores user credentials and personal data in an active directory (AD) forest. The AD forest is replicated across multiple data centers worldwide, including a non-EU country. The data protection officer (DPO) is concerned that personal data might be inadvertently replicated to jurisdictions without adequate protection. Which of the following is the most effective way to address this concern?

Hard
745

An IS auditor is reviewing the end-of-life (EOL) software policy. Which THREE risks are associated with running unsupported software? (Select THREE).

Hard
746

During the design phase of an SDLC, which TWO activities should be performed to ensure security is integrated into the system? (Select TWO)

Easy
747

An IT manager is reviewing the service level agreements (SLAs) for a cloud-based email service. The SLA guarantees 99.9% uptime per month. The service experienced an outage of 45 minutes in a 30-day month. Did the service meet the SLA?

Medium
748

You are the IT audit manager for a multinational corporation. The company recently implemented a new enterprise resource planning (ERP) system using a phased rollout approach. The first phase (finance module) was deployed to three regional offices six months ago. During a post-implementation review, you discovered that the user acceptance testing (UAT) for the finance module was completed in only two days instead of the planned two weeks. The UAT was performed by a small group of power users selected by the project manager, and they reported no critical issues. However, after go-live, several finance staff in one region found that the system does not support a statutory reporting requirement specific to that country, which was not tested. The project manager argues that the requirement was never documented in the business requirements specification. The system has been live for six months, and the missing functionality requires a significant customization that will take three months and cost $200,000. Management is reluctant to fund the customization because the budget is exhausted. As the IT auditor, what is the BEST course of action?

Hard
749

An IS auditor is assessing the audit risk for an engagement covering a core banking application. The auditor determines that inherent risk is high because the application processes high-value transactions in real time. The auditor also concludes that control risk is low because strong automated controls and segregation of duties are in place and have been tested. Which of the following BEST describes the appropriate response to this assessment?

Hard
750

An IS auditor is testing the effectiveness of a preventive control that rejects invalid transactions. The auditor uses a computer-assisted audit technique (CAAT) to create a set of test transactions. What is the primary risk associated with this approach?

Hard
751

During the feasibility study for a new inventory system, the project team identifies that the expected benefits are significantly lower than the initial estimates. What is the MOST appropriate action for the IS auditor to recommend?

Easy
752

An IS auditor is planning an audit of a small organization with limited IT staff. Which approach is most appropriate?

Medium
753

An IT audit revealed that the organization's IT steering committee has not met in the past six months. Which of the following is the MOST likely consequence of this situation?

Medium
754

An IS auditor is examining the job scheduling controls for an organization's nightly batch processing on a mainframe. The auditor finds that operators can modify job schedules, add ad hoc jobs, and override job dependencies without supervisory approval or logging. Which of the following is the MOST appropriate recommendation?

Easy
755

Which THREE of the following are components of the ITIL 4 service value system? (Select THREE)

Hard
756

A mid-sized insurance company has decided to adopt a formal IT governance framework because its board is concerned about unmanaged IT risk. The CIO asks the IS auditor to recommend the FIRST step in establishing the governance framework. Which of the following should the IS auditor recommend?

Medium
757

Which TWO of the following are benefits of establishing an IT steering committee?

Easy
758

An organization's availability management team reports that a critical server has an MTBF of 720 hours and an MTTR of 4 hours. What is the availability percentage for this server?

Medium
759

During which phase of the IS audit process does the auditor perform walkthroughs and test controls?

Easy
760

An IS auditor is evaluating a cloud service provider's (CSP) security posture before the organization migrates a customer-facing application to the provider's infrastructure as a service (IaaS) environment. The auditor is reviewing the shared responsibility model and the provider's assurance documentation. Which TWO of the following are the auditor's MOST important considerations? (Choose two.)

Hard
761

Which TWO of the following are primary objectives of the audit planning phase? (Select TWO.)

Easy
762

Which of the following is the PRIMARY objective of an operational audit?

Easy
763

An organization uses automated job scheduling with dependency management. A critical nightly batch job failed because a prerequisite job did not complete successfully. The job scheduler automatically attempted to rerun the failed job three times, each time failing due to the same dependency. The operations team was not alerted until the next morning. What control should the auditor recommend to improve this process?

Medium
764

A system has a Mean Time Between Failures (MTBF) of 500 hours and a Mean Time To Repair (MTTR) of 20 hours. What is the availability of the system?

Hard
765

An IS auditor is reviewing the IT operations of a small organization. The auditor notes that the operations team performs daily server health checks, but there is no formal capacity management process. The organization recently experienced a slowdown during month-end processing. Which of the following is the MOST likely cause of the slowdown that the auditor should investigate?

Easy
766

An organization is planning to outsource its data center operations. Which of the following governance practices should be implemented to ensure proper oversight?

Medium
767

A hospital's data centre uses a generator and an uninterruptible power supply (UPS) to protect clinical systems. During a walkthrough, the IS auditor observes that the UPS batteries have never been load-tested and the generator is exercised monthly without transferring the load. Which conclusion is MOST appropriate?

Easy
768

During an operational audit, the auditor uses ratio analysis to compare current year expenses to prior years and industry benchmarks. This is an example of which type of audit evidence?

Medium
769

Which TWO of the following are key elements of an effective incident response plan? (Select exactly 2.)

Medium
770

An IS auditor is reviewing the organization's IT governance framework. The board has delegated oversight of IT to an IT steering committee. The auditor finds that the committee meets quarterly, but its charter does not define decision rights or escalation procedures. Which of the following is the MOST significant concern?

Medium
771

Which of the following is the BEST method to ensure that a system development project is completed on time?

Medium
772

An organization is implementing an enterprise resource planning (ERP) system. The project team plans to migrate legacy data without performing a full reconciliation between source and target systems. As an IS auditor, which of the following should be your PRIMARY concern?

Hard
773

An organization is performing software asset management (SAM) to ensure license compliance. Which two activities should the auditor verify?

Medium
774

An IS auditor is assessing an organization's IT governance implementation. The auditor finds that IT policies are outdated, roles and responsibilities are unclear, and there is no regular reporting on IT performance to the board. Which TWO of the following are the MOST critical actions to improve IT governance? (Choose two.)

Hard
775

Which THREE of the following are common risks associated with outsourcing software development?

Hard
776

During a review of encryption practices, the IS auditor finds that an organization uses the same encryption key for all customer data at rest. What is the PRIMARY concern?

Medium
777

An organization uses a hot site as its disaster recovery alternative. Which of the following is the MOST critical consideration when selecting a hot site?

Medium
778

In the context of IT governance, what is the PRIMARY purpose of an exception management process for IT policies?

Hard
779

Which THREE of the following are commonly recognized benefits of implementing a formal IT service management (ITSM) framework such as ITIL?

Hard
780

An IS auditor is performing a risk assessment to prioritize audit engagements for the annual audit plan. Which TWO of the following factors should the auditor consider when evaluating inherent risk? (Choose two.)

Medium
781

During an audit of an organization's information security programme, the IS auditor finds that the security awareness training completion rate is 95% but phishing simulation tests show a 30% failure rate. What should the auditor recommend?

Medium
782

An IT manager is developing a governance policy for change management. Which element is MOST important to include?

Easy
783

An organization uses a chargeback model for IT services. What is the PRIMARY benefit of this approach?

Easy
784

Which TWO of the following are key components of an effective information security awareness program?

Easy
785

An organization has just completed a post-implementation review of a new payroll system. Management is now deciding whether to formally transfer ownership of the system from the project team to IT operations. Which of the following is the MOST important prerequisite before this transfer is approved?

Medium
786

In a risk-based audit approach, which of the following BEST describes how an IS auditor should prioritize audit coverage?

Hard
787

During an audit of a data center, the IS auditor observes that visitors are escorted at all times but the visitor log is not reconciled to the badge access system. Which of the following BEST describes the audit concern?

Easy
788

An IS auditor is reviewing the testing phase of a new system development project. The project team has decided to use beta testing as the primary method for user acceptance testing (UAT). Which of the following is the MOST appropriate audit concern regarding this decision?

Hard
789

In a DevOps environment, which practice BEST supports auditability?

Hard
790

An IS auditor is planning an audit of a small organization with limited IT staff. Which of the following is a key consideration for the audit approach?

Hard
791

Which of the following is a key difference between an internal audit and an external audit?

Medium
792

An IS auditor is reviewing the availability management process. The auditor calculates that the mean time between failures (MTBF) is 200 hours and the mean time to repair (MTTR) is 20 hours. What is the availability percentage?

Medium
793

Which THREE of the following are components of a typical IT governance framework?

Hard
794

An IS auditor is reviewing the capacity management process for a virtualized server environment. The auditor finds that CPU and memory utilization reports are generated monthly, but no formal forecasting is performed, and no thresholds are defined for triggering capacity upgrades. Which of the following is the MOST significant risk arising from this situation?

Medium
795

An IT auditor is reviewing the release management process. Which of the following is the MOST important control to ensure that new releases do not negatively impact production systems?

Medium
796

Which TWO of the following are types of audit evidence recognized in IS audit practice?

Easy
797

An IS auditor is reviewing the disaster recovery plan (DRP) for an e-commerce company that generates 90% of its revenue online. The DRP states that the recovery time objective (RTO) for the transactional database is 4 hours, and the recovery point objective (RPO) is 1 hour. The current backup strategy includes nightly full backups and hourly transaction log backups stored on a local disk array. The backups are then copied to a remote datacenter via a WAN link with an average transfer speed of 10 Mbps. The database size is 500 GB. The auditor calculates that the time to transfer the full backup over the WAN is approximately 12 hours. The organization's management is confident that the DRP is adequate because they have never had to invoke it. What is the auditor's MOST critical finding?

Hard
798

An IS auditor is reviewing a contract with a vendor for a new financial system. Which of the following clauses is MOST critical to ensure auditability?

Hard
799

During an audit, an IS auditor finds that the organization uses a cloud-based identity provider (IdP) for single sign-on (SSO) but does not enforce multi-factor authentication (MFA) for all users. Which of the following is the BEST recommendation to reduce risk?

Hard
800

Which THREE of the following are characteristics of SMART recommendations in an audit report? (Select three.)

Hard
801

An IS auditor is reviewing the vendor management program for a critical outsourced service. The vendor has recently been acquired by another company. Which TWO factors should the auditor be most concerned about regarding the acquisition?

Medium
802

During system implementation, a critical defect is found in the production environment. The project manager wants to apply an emergency patch without full testing. Which of the following is the BEST course of action?

Hard
803

Which type of audit is primarily concerned with evaluating the efficiency and effectiveness of operations?

Easy
804

A company is designing a public cloud-based application that processes highly sensitive personal data. Which of the following data protection strategies provides the STRONGEST assurance that data remains confidential even if the cloud provider's infrastructure is compromised?

Hard
805

An organization uses RAID 5 for its database server. Which of the following is the PRIMARY advantage of RAID 5?

Medium
806

An IS auditor is assessing an organization's IT governance. The auditor finds that the IT balanced scorecard is used to measure IT performance, but the metrics are heavily focused on internal IT processes and do not include business or customer perspectives. Which of the following is the MOST likely consequence of this imbalance?

Medium
807

An IS auditor is reviewing an organization's change management process. The auditor notes that all emergency changes are approved post-implementation by the change advisory board (CAB) within 48 hours. Which of the following is the auditor's BEST course of action?

Hard
808

Which of the following is the MOST important objective of system testing?

Easy
809

A financial institution is implementing a data classification policy. Which of the following is the most important factor in determining the classification level of a data asset?

Easy
810

In the audit follow-up phase, which TWO actions are essential? (Select two.)

Medium
811

During an audit of a bank's online transaction processing system, the IS auditor discovers that batch totals are reconciled only at the end of each business day, while individual transactions are posted to customer accounts in real time. Which of the following is the GREATEST risk arising from this control design?

Hard
812

An organization is implementing a new CRM system using an iterative development methodology. The IS auditor wants to verify that appropriate controls are in place. Which THREE of the following are essential controls for iterative development? (Select THREE.)

Hard
813

An IS auditor is reviewing the audit charter of an organization's internal audit function. Which of the following should the auditor expect to find as the PRIMARY purpose of the audit charter?

Easy
814

An IS auditor is reviewing the logical access controls of a system. Which of the following is the BEST evidence that access rights are appropriately assigned?

Easy
815

A company outsources its IT help desk to a third-party vendor. The service level agreement (SLA) specifies that all P1 incidents must be resolved within 2 hours. During an audit, the auditor finds that the vendor’s average resolution time for P1 incidents is 3 hours. What is the most appropriate recommendation?

Medium
816

An IS auditor is reviewing an organization's IT governance policies and finds that the IT strategy is updated annually, but there is no process to monitor external factors such as regulatory changes or emerging technologies. Which of the following is the MOST significant risk of this deficiency?

Medium
817

An IS auditor is reviewing the backup strategy for a critical database server. The database administrator states that a full backup is performed every Sunday, and transaction log backups are performed every hour. The auditor finds that the transaction log backups are stored on the same volume as the database data files. Which of the following is the MOST significant risk associated with this configuration?

Medium
818

An IS auditor is reviewing a software development project that uses a DevOps pipeline. The auditor observes that developers can push code directly to production without independent review. Which of the following is the MOST significant risk arising from this practice?

Hard
819

An IS auditor is evaluating the reliability of evidence obtained from a system-generated exception report. The report is produced by a script written by a database administrator who has both the ability to modify the script and the production data. The auditor has obtained the report directly from the system. Which of the following is the MOST important factor affecting the auditor's reliance on this evidence?

Hard
820

An IS auditor is reviewing physical security controls at a data center. The data center hosts critical servers and uses a badge access system with PINs, CCTV cameras, and a mantrap entry. The auditor observes that employees sometimes hold the door open for others without badging. Which TWO of the following are the MOST effective controls to address this tailgating risk?

Easy
821

During an IT audit, the auditor finds that a system administrator has local administrator rights on multiple production servers and uses a shared service account for routine maintenance. What is the PRIMARY risk associated with this practice?

Easy
822

During a change management process review, an IS auditor finds that the change advisory board (CAB) approved a change that subsequently caused a major service outage. The change was classified as 'normal' with no emergency. What is the auditor's primary concern?

Medium
823

An organization is implementing a new IT service management system based on ITIL 4. Which TWO of the following are guiding principles of ITIL 4?

Medium
824

An organization's IT strategy must be aligned with business strategy. Which of the following is the PRIMARY benefit of this alignment?

Easy
825

During an audit of IT asset management, the IS auditor finds that several servers are running an operating system that has reached end-of-life (EOL). The organization has not deployed any compensating controls. Which of the following is the GREATEST risk?

Hard
826

Which of the following audit types is most likely to be conducted by an employee of the organization being audited, potentially raising independence concerns?

Easy
827

Which TWO of the following are examples of administrative controls for information security? (Choose two.)

Easy
828

During an audit, the IS auditor identifies that the audit team lacks the technical expertise to evaluate a specific system. According to ISACA standards, the auditor should:

Easy
829

An IS auditor is assessing an organization's capacity management process for a virtualized server environment. Management wants to confirm that the process will provide early warning before performance degrades. Which TWO practices are MOST important for the auditor to verify are in place? (Choose two.)

Medium
830

An organization is planning to purchase a cloud-based HR system. Which THREE of the following should be included in the vendor contract to ensure adequate control and oversight? (Select three.)

Hard
831

An IS auditor is assessing the capacity management process for a rapidly growing e-commerce platform. The auditor finds that capacity planning is based solely on historical CPU and memory utilization, with no forecasting of business growth or seasonal peak demand. During the most recent holiday season, the platform experienced severe performance degradation and a two-hour outage. Which of the following should the auditor identify as the PRIMARY weakness in the capacity management process?

Hard
832

What is the PRIMARY purpose of conducting a static application security testing (SAST) during the development phase?

Easy
833

An organization is implementing a new ERP system. The project sponsor requests a change that will significantly increase project scope without additional budget. Which of the following is the BEST action for the project manager?

Hard
834

An IT auditor is reviewing backup procedures. The organization performs daily full backups and retains them for 30 days. Additionally, weekly backups are retained for 12 months. Which of the following is the MOST likely risk associated with this backup strategy?

Medium
835

An IS auditor has completed fieldwork for an audit of a data center's physical access controls and has documented several findings. Before drafting the final report, the auditor discusses the findings with the data center manager. Which of the following is the PRIMARY purpose of this discussion?

Easy
836

An organization wants to implement an exception management process for IT policies. Which of the following is the most important step to ensure effective control?

Hard
837

An IS auditor is reviewing an agile software development project. Which of the following practices would BEST help ensure that security controls are adequately addressed?

Medium
838

Which of the following is a requirement for effective segregation of duties in IT?

Easy
839

An IS auditor is reviewing a project that uses an iterative SDLC approach. Which THREE controls should the auditor expect to see in place during the development iterations? (Select THREE)

Hard
840

An IS auditor is evaluating a data loss prevention (DLP) deployment intended to stop sensitive customer records from leaving a bank's network. Management wants assurance that the solution is operating effectively. Which TWO of the following are the MOST important factors for the auditor to assess? (Choose two.)

Medium
841

An IS auditor is examining how an organization classifies and handles its information assets. The auditor finds that the data classification policy defines four sensitivity levels and corresponding handling rules, but the asset inventory does not record a classification for most systems. Which of the following is the MOST likely consequence of this gap?

Easy
842

An organization's data classification policy defines 'Confidential' data as requiring encryption at rest. An IS auditor discovers that a database containing customer personal information is not encrypted. What is the auditor's BEST course of action?

Hard
843

An IS auditor is planning an audit of a newly implemented ERP system. The auditor wants to ensure that the audit covers critical controls. Which of the following is the most appropriate first step in the audit planning process?

Easy
844

Which THREE of the following are essential components of a change management process?

Easy
845

An IS auditor is conducting a follow-up review of a previously identified high-risk finding. Management has implemented a compensating control instead of the recommended control. Which of the following is the MOST appropriate action for the auditor to take?

Medium
846

An organization is adopting a DevOps approach for system development. Which THREE controls should an IS auditor expect to see in place to maintain security and compliance?

Hard
847

An organization uses a COTS (commercial off-the-shelf) ERP system with significant customizations. The IS auditor is reviewing the system's configuration management. Which of the following findings would MOST indicate a weakness?

Hard
848

An IS auditor is performing a review of an organization's IT governance framework. Which of the following findings would be of MOST concern?

Hard
849

An organization's IT department is structured with a central unit that provides infrastructure and support, while individual business units have their own application development teams. This structure is BEST described as:

Medium
850

An IS auditor is reviewing the IT operations of a small organization that runs a critical application on a single physical server. The auditor finds that backups are performed daily to a local tape drive, but the tapes are stored in the same room as the server. Which of the following is the MOST significant risk?

Easy
851

An IT auditor is reviewing the system development life cycle (SDLC) process for a critical application. Which of the following findings would be of MOST concern?

Medium
852

An IS auditor is reviewing the privileged access management (PAM) process. The auditor finds that shared administrative accounts are used for critical system maintenance and that passwords are changed quarterly. Which of the following is the BEST recommendation to mitigate the risk of audit trail loss?

Hard
853

A company's backup policy requires that backup tapes be stored offsite for at least one year. During an audit, the auditor finds that the offsite storage facility is not access-controlled and backup tapes are not encrypted. Which of the following is the auditor's BEST recommendation?

Medium
854

A company is deciding whether to centralize or decentralize its IT function. Which of the following is an advantage of a centralized IT structure?

Medium
855

During an IT audit, the auditor discovers that the IT strategy is not formally documented. Which of the following is the MOST significant risk associated with this finding?

Easy
856

During a disaster recovery planning audit, the IS auditor notes that the organization's plan includes a hot standby site. However, the plan has not been updated in two years, and the last test was a tabletop exercise 18 months ago. The organization has recently implemented a new ERP system. Which THREE findings should the auditor report as most significant?

Hard
857

An organization's backup strategy includes daily incremental backups and weekly full backups. During a disaster recovery test, the restoration of a critical server fails because a required incremental backup is corrupt. Which control should the organization implement to verify the integrity of backups?

Hard
858

An IS auditor is evaluating an organization's job scheduling practices for a critical batch process that updates the general ledger. The process runs nightly and must complete before the start of the business day. The auditor finds that the job scheduler uses a single service account with domain administrator privileges to run all jobs, and there are no alerts for job failures. Which of the following is the MOST significant risk arising from this configuration?

Hard
859

During a change management audit, which TWO of the following are essential elements of a normal change request? (Select two.)

Medium
860

A company's security policy requires that all laptops have full-disk encryption. During an audit, 10% of laptops are found without encryption. Which of the following is the MOST effective corrective action?

Medium
861

An organization is implementing a new CRM system using an agile methodology. The IS auditor wants to assess whether security requirements are being addressed. What is the best evidence for the auditor to review?

Medium
862

A company uses role-based access control (RBAC). An employee moves from one department to another but retains some previous access due to overlapping role permissions. This condition is known as:

Hard
863

An IS auditor is reviewing the tape backup process for a mid-sized organization. Backups run nightly and complete successfully, and tapes are stored in a fireproof safe in the same data center as the servers. Which of the following is the MOST significant finding?

Easy
864

An IS auditor is evaluating the security of an organization's wireless network. The organization uses WPA3-Enterprise with 802.1X authentication against a RADIUS server. The auditor discovers that the RADIUS server is configured to accept EAP-MD5 as an authentication method for legacy devices. Which of the following is the MOST significant security concern with this configuration?

Hard
865

An IS auditor is reviewing the IT operations team's use of system-generated alerts. The auditor finds that alerts are configured to notify the operations team via email, but there is no escalation path if an alert is not acknowledged within a specified time. Which of the following is the MOST significant risk?

Easy
866

During a nightly batch job, the above error appears in the application logs. The transaction table ACCT_TRANS has a unique constraint on the REF_NUM column. Which of the following is the MOST likely root cause?

Hard
867

An IS auditor is executing a compliance test of change management controls over a core banking application. The audit programme requires evidence that all production changes were approved before implementation. Which of the following techniques provides the MOST persuasive evidence for this test?

Medium
868

An IS auditor is reviewing the data backup strategy for a hospital's electronic health record (EHR) system. The auditor finds that full backups are performed weekly, with daily incremental backups, but the backup tapes are stored in the same server room as the production system. Which of the following is the MOST significant finding?

Medium
869

An organization is using a spiral model for a high-risk project. The IS auditor wants to ensure that risk assessment is performed at each iteration. Which of the following is the BEST evidence that this control is effective?

Hard
870

During a security assessment, an auditor discovers that employees are sharing passwords to access a critical system. Which of the following controls would BEST mitigate this risk?

Easy
871

An IS auditor is planning an audit of a financial system. The auditor identifies that the inherent risk is high due to the complexity of transactions, but control risk is low because of strong automated controls. Which component of audit risk will be MOST affected by the auditor's testing strategy?

Medium
872

A small manufacturing company decides to acquire an off-the-shelf inventory management system. The purchasing manager selects a vendor based solely on the lowest price, ignoring the vendor's financial stability and support history. After purchase, the vendor declares bankruptcy, leaving the company without support. The system has a critical bug that halts inventory tracking. The IT manager considers hiring a consultant to fix the bug. As an IS auditor, what should the auditor's PRIMARY concern be?

Easy
873

An organization has a policy that requires all IT projects to have a business case approved by the IT steering committee. The IS auditor discovers that a major infrastructure upgrade was initiated without an approved business case. Which of the following is the auditor's PRIMARY concern?

Medium
874

Which TWO of the following are key responsibilities of an IT steering committee?

Medium
875

Which THREE are commonly used techniques to protect sensitive data in a cloud environment? (Select exactly 3.)

Medium
876

An IS auditor is reviewing problem management for a payment processor. Recurring incidents share the same root cause, but the problem record has remained open for eight months with no root cause identified because the vendor will not release diagnostic data. Change requests to apply a workaround have been raised and closed repeatedly. Which action should the IS auditor recommend FIRST?

Hard
877

An organization is establishing an IT governance committee. The committee's charter includes overseeing IT investments, monitoring IT performance, and ensuring compliance with regulations. Which of the following should the IS auditor recommend as the MOST important characteristic of the committee's membership?

Easy
878

An IS auditor is assessing whether an organization's IT steering committee is fulfilling its governance responsibilities. The committee charter states that it oversees IT investment prioritization, monitors IT performance against agreed objectives, and resolves escalated resource conflicts. Which TWO of the following observations would the auditor MOST likely identify as deficiencies in the committee's operation? (Choose two.)

Hard
879

An organization outsources its data center operations to a third-party vendor. The contract includes a right-to-audit clause. During a scheduled audit, the vendor refuses to provide access to logs from a subcontractor managing network security. What is the IS auditor's best course of action?

Medium
880

After issuing the final audit report, the IS auditor should perform follow-up procedures. What is the PRIMARY purpose of follow-up?

Medium
881

An organization is evaluating its business continuity plan (BCP) to ensure alignment with the IT disaster recovery plan. Which TWO of the following are critical elements that should be included in the BCP to support effective business resilience?

Hard
882

Which THREE of the following are indicators of mature IT governance?

Hard
883

An organization is implementing an agile methodology for a new software project. Which of the following is the MOST effective control to ensure that security requirements are addressed?

Hard
884

An IS auditor is reviewing the termination procedure for IT employees. Which of the following is the most critical control to ensure immediate effectiveness?

Hard
885

An organization implemented a business continuity plan (BCP) that includes manual workarounds. Which of the following is the PRIMARY risk of relying on manual processes during a disruption?

Medium
886

Which THREE of the following are key elements that should be included in a risk assessment report for information systems?

Hard
887

During a recent audit, the IT auditor found that the problem management process does not include a known error database (KEDB). Which of the following is the MOST significant risk associated with this finding?

Medium
888

An IS auditor is assessing the sufficiency of audit evidence gathered for a conclusion about database access controls. Which TWO of the following characteristics must the evidence possess to be considered appropriate? (Choose two.)

Medium
889

An organization is evaluating its business continuity plan (BCP) for a critical application with a recovery time objective (RTO) of 4 hours and a recovery point objective (RPO) of 1 hour. The current backup strategy involves daily full backups and hourly transaction log backups. Which of the following is the MOST significant risk?

Hard
890

An organization is implementing a new CRM system and has chosen a build (in-house development) approach over buying a COTS product. Which of the following is the most significant risk of this decision?

Medium
891

An IS auditor is evaluating the effectiveness of an organization's information security awareness program. Which of the following is the BEST indicator of program effectiveness?

Hard
892

In the context of ITIL change management, which change type requires approval from the Change Advisory Board (CAB)?

Medium
893

Which THREE of the following are key considerations when selecting a software development methodology for a project?

Hard
894

Which TWO are primary criteria for classifying information assets within an organization? (Choose two.)

Easy
895

An IT department is struggling with project delays and budget overruns. Which governance practice would be MOST effective?

Medium
896

Which TWO of the following are typical controls in the testing phase of the SDLC? (Select two.)

Medium
897

Which THREE of the following are key metrics to include in a disaster recovery test report? (Select exactly 3.)

Hard
898

An organization is selecting a vendor for a new enterprise resource planning (ERP) system. Which of the following is the MOST critical factor in the vendor selection process?

Easy
899

An IS auditor is reviewing the physical security of a data center that houses production servers. During a walkthrough, the auditor observes that the main entrance uses a badge reader, but the door to the network operations center (NOC) is propped open with a chair. Which of the following is the MOST appropriate action for the auditor to take?

Easy
900

Match each security control to its category.

Medium
901

A financial services company is developing a new customer-facing web application for account management. The project is using a waterfall methodology. The initial requirements were gathered six months ago, and the coding phase is nearly complete. The business sponsor now requests a new feature that allows customers to view transaction receipts online. The project manager is concerned that this change will delay the project by two months and exceed the budget. The sponsor insists that the feature is critical for customer satisfaction and that the project must adapt. The development team estimates it will take 200 hours to implement. The steering committee is divided. As an IS auditor, what would be the BEST recommendation to resolve this?

Hard
902

An IS auditor is reviewing the release management process for a critical application. The release strategy includes a phased rollout to 10% of users initially, then 50%, then 100%. The first phase revealed a data integrity issue that affected a subset of transactions. The release manager decided to continue with the next phase while a patch was being developed. What should the auditor most recommend?

Hard
903

An IS auditor is reviewing a post-implementation review (PIR) of a new CRM system. The auditor finds that the project was completed on time and within budget, but the business case benefits have not been realized. Which of the following is the MOST likely cause?

Medium
904

An IS auditor is evaluating an organization's SDLC controls for a new system. Which TWO of the following are key controls that should be in place during the design phase? (Select TWO.)

Medium
905

Arrange the steps to perform a risk assessment in the correct order.

Medium
906

An organization is selecting a vendor for a new procurement system. Which of the following is the MOST important factor to include in the contract?

Medium
907

During an audit of the information security program, the IS auditor reviews the organization's information security policy. Which of the following is the PRIMARY purpose of an information security policy?

Easy
908

Which of the following is the MOST effective control to prevent unauthorized USB devices from connecting to corporate workstations?

Medium
909

An IS auditor is reviewing a business continuity plan (BCP). Which TWO of the following are key components of the business continuity strategy? (Select two.)

Medium
910

Which THREE of the following are acceptable methods for gathering audit evidence? (Select THREE.)

Medium
911

An IS auditor is assessing the effectiveness of an organization's IT governance framework. Which TWO of the following are essential components that the auditor should verify are in place? (Choose two.)

Medium
912

An IS auditor is using analytical procedures during the planning phase. Which of the following is an example of an analytical procedure?

Medium
913

An IS auditor is assessing an organization's IT governance framework and finds that the IT balanced scorecard includes metrics such as system uptime, number of help desk tickets resolved, and average response time. The auditor notes that these are all internal IT operational metrics. The MOST significant concern is that:

Hard
914

An IS auditor is assessing physical security at a data center that houses the organization's core transaction processing systems. The auditor observes that the main entrance uses a badge reader, but the door to the server hall is propped open with a box while staff move equipment. Which of the following is the auditor's GREATEST concern?

Easy
915

An IS auditor is reviewing the logical access controls of a financial application. Which of the following is the BEST way to verify that user access rights are appropriate?

Medium
916

An organization is developing its IT strategy to align with the overall business strategy. The business strategy emphasizes rapid market expansion through digital products. Which of the following IT strategies would BEST support this business goal?

Easy
917

An IS auditor is preparing the audit report. According to ISACA standards, which of the following should be included in the final audit report?

Easy
918

A company is considering restructuring its IT department from a centralized to a decentralized model to give business units more autonomy. What is a PRIMARY governance risk associated with this move?

Medium
919

An organization has experienced several security incidents due to unauthorized changes to production systems. Which governance mechanism should be strengthened?

Medium
920

An IT steering committee is reviewing a proposal for a new customer relationship management (CRM) system. Which of the following BEST demonstrates that the proposal aligns with the organization's strategic goals?

Easy
921

An IS auditor is evaluating the network segmentation of a manufacturing company that separates its corporate network from the industrial control system (ICS) environment. The auditor finds that a firewall exists between the zones, but engineering workstations on the corporate network can reach programmable logic controllers directly over several open ports. Which TWO of the following findings should the auditor report as the MOST significant weaknesses? (Choose two.)

Medium
922

An IT auditor is reviewing the business continuity plan (BCP) for a financial services firm. The plan includes a hot site that is shared with another organization under a reciprocal agreement. Which of the following findings should be of MOST concern to the auditor?

Hard
923

An organization is implementing a COTS application. The project team plans to heavily customize the application to meet unique business processes. Which of the following is the most significant risk?

Hard
924

An IS auditor is evaluating the patch management process. The auditor notes that critical security patches are applied within 30 days, but the policy requires 7 days. The IT manager states that the delay is due to testing requirements. What should the auditor recommend?

Hard
925

Which TWO of the following are considered essential components of an information security policy framework? (Choose two.)

Medium
926

An organization is adopting a decentralized IT structure to better meet the needs of its business units. Which of the following is a potential risk of this approach?

Medium
927

An IT auditor is reviewing the change management process for a financial institution. The auditor finds that emergency changes are frequently approved by the change manager without CAB review. Which risk is most associated with this practice?

Medium
928

A company plans to implement a commercial off-the-shelf (COTS) application and requires significant customization to match its unique business processes. The vendor advises against extensive customization because it may complicate future upgrades. What is the BEST course of action?

Hard
929

A financial institution is deploying a data loss prevention (DLP) solution. Which of the following is the MOST important prerequisite to ensure the DLP can effectively detect sensitive data?

Easy
930

An IT auditor is evaluating the capacity management process. Which of the following findings would be of MOST concern?

Hard
931

An organization is implementing a change management process based on ITIL. Which THREE change types should be included in the policy?

Hard
932

A company's availability monitoring shows that a critical application has an average MTBF of 720 hours and an average MTTR of 4 hours. What is the availability percentage?

Hard
933

Which TWO of the following are key benefits of using a system development life cycle (SDLC) methodology? (Select exactly two.)

Medium
934

An IS auditor is reviewing the deployment pipeline for an organization's e-commerce platform. The pipeline automatically deploys every code commit that passes automated unit tests to production without manual approval. The organization argues this accelerates feature delivery. Which of the following is the auditor's GREATEST concern with this approach?

Medium

Frequently asked questions

What does the scenario questions domain cover on the CISA exam?
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 934 scenario questions questions in the CISA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only scenario questions questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.