Which of the following is the best way to reduce the direct risks associated with using an unsupported version of the software?

 Information systems auditors have found that software systems that are still in use are outdated for years and are no longer supported. The auditee stated that it still takes six months for the software to run on the current version. Which of the following is the best way to...

December 18, 2018 No Comments READ MORE +

 In order to develop a robust data security program, the first step you should take is:

 In order to develop a robust data security program, the first step you should take is:A . Talk to the senior management level of IC . Implement monitoring controls.D . Implement data loss prevention measuresE . Perform inventory of assetsView AnswerAnswer: D

December 16, 2018 No Comments READ MORE +

 Which of the following best reflects the mature strategic planning process?

 Which of the following best reflects the mature strategic planning process?A . Strategic planning includes specifications for control and safeguard mechanismsB . All projects have an action plan that includes IT requirementsC . IT strategic planning supports corporate strategyD . IT projects from strategic planning are approved by managementView...

December 15, 2018 No Comments READ MORE +

 The overall progress report for the project indicates that the project is proceeding as planned. However, progress reports from project grouping do not support this.

 The overall progress report for the project indicates that the project is proceeding as planned. However, progress reports from project grouping do not support this. The biggest risk from this situation may be:A . The project may not be completed in the safe periodB . User involvement may be...

December 1, 2018 No Comments READ MORE +

Which of the following questions should be the biggest concern?

 During the physical security audit, the information system auditor received a contactless proximity card that allowed to access to three specific floors of the corporate office building. Which of the following questions should be the biggest concern?A . In the first two days of field work of audit, the...

November 28, 2018 No Comments READ MORE +

 Which of the following recommendations should the information system auditor propose to reduce the likelihood of intruders using social engineering?

 Which of the following recommendations should the information system auditor propose to reduce the likelihood of intruders using social engineering?A . Deploy a security awareness training programB . Perform a simulated attackC . Implementing an intrusion detection system (IDS)D . Prohibit the use of social networking platformsView AnswerAnswer: A

November 27, 2018 No Comments READ MORE +

 Which of the following is a major consideration for information systems auditors when reviewing software license management?

 Which of the following is a major consideration for information systems auditors when reviewing software license management?A . No current software listB . Do not use a site licenseC . Lack of agreement on software third party preservationD . No backup license for future useView AnswerAnswer: A

November 25, 2018 No Comments READ MORE +

 Which of the following best describes the effectiveness of a portfolio management plan?

 Which of the following best describes the effectiveness of a portfolio management plan?A . Maturity level of the value management processB . Experience of portfolio managersC . Percentage of investment to achieve its predicted valueD . Stakeholders’ perception of IT valueView AnswerAnswer: A

November 24, 2018 No Comments READ MORE +

Which of the following would be the best advice for an information systems auditor?

 During the review of the IT Strategic Plan, the Information Systems Auditor found that some of the action plans focused on launching new systems and technologies were inconsistent with the company's strategy. Which of the following would be the best advice for an information systems auditor?A . Reassess the...

November 23, 2018 No Comments READ MORE +

 The main purposes of testing an alternate site that is part of a disaster recovery plan are:

 The main purposes of testing an alternate site that is part of a disaster recovery plan are:A . Verify that the infrastructure of the alternate site works as expected.B . Determine recovery time objectivesC . Identify the hidden costs of the maintenance site.D . Assess employee safety awarenessView AnswerAnswer:...

November 22, 2018 No Comments READ MORE +