1. What would be an IS auditor's BEST recommendation upon finding that a third-party IT service provider hosts the organization's human resources (HR) system in a foreign country?
A) Conduct a privacy impact analysis. B) Implement change management review. C) Review third-party audit reports. D) Perform background verification checks.
2. The success of an IT projects is measured PRIMARILY by the:
A) translation of business vision to function vision B) implementation of current technology C) benefit that the business derives from the outcome D) efficient use of resources
3. Which of the following are the PRIMARY considerations when determining the timing of remediation testing?
A) The level of management and business commitment to implementing agreed action plans B) The difficulty of scheduling resources and availability of management for a follow-up engagement C) The availability and competencies of control owners for implementing the agreed action D) The significance of the reported findings and the impact if corrective actions are not taken
4. Code changes are compiled and placed in a change folder by the developer. An implementation team migrates changes to production from the change folder.Which of the following BEST indicates separation of duties is in place during the migration process?
A) A second individual performs code review before the change is released to production. B) The developer approves changes prior to moving them to the change folder. C) The implementation team does not have experience writing code. D) The implementation team does not have access to change the source code.
5. Which of the following should be reviewed FIRSTwhen assessing the effectiveness of an organization's network security procedures and controls?
A) Data recovery capability B) Inventory of authorized devices C) Vulnerability remediation D) Malware defenses
Leave a comment