wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

ASI 3

Total questions: 14

Worksheet time: 17mins

Name
Class
Date
1.

An IS auditor is to assess the suitability of a service level agreement (SLA) between the organization and the supplier of outsourced services. To which of the following observations should the IS auditor pay the MOST attention? The SLA does not contain a:

a)

Transition clause from the old supplier to a new supplier in the case of expiration or termination.

b)

Late payment clause between the customer and the supplier

c)

Contractual commitment for service improvement

d)

Dispute resolution procedure between the contracting parties

2.

An IS auditor reviewing a new outsourcing contract with a service provider would be MOST concerned if which of the following was missing?

a)

A clause providing a “right to audit” service provider

b)

A clause defining penalty payments for poor performance

c)

Predefined service level report templates

d)

A clause regarding supplier limitation of liability

3.

When reviewing the desktop software compliance of an organization, the IS auditor should be MOST concerned if the installed software:

a)

Was installed, but not documented in the IT department records

b)

Was installed and the license has expired

c)

Is not listed in the approved software standards document

d)

License will expire in next 15 days

4.

Due to a recent economic downturn, an IT organization has terminated several administrators at remote sites and consolidated all IT administration to the organization’s central headquarters. During the annual IT audit, the auditor determines that the organization has implemented remote admin connectivity to each site using low-cost DSL connections and an automated SNMP-based monitoring system to detect any hardware or software issues that may occur.


In the auditor’s mind, what should be the biggest area of concern?

a)

The authentication methods used for the remote admin may not be secure and default SNMP passwords may be in use

b)

Physical security at remote sites may not be adequate

c)

Terminated employees may retain access to systems at remote sites

d)

The connection to remote sites is secure through the use of a virtual private network (VPN)

5.

An IT executive of an insurance company asked an external auditor to evaluate the user IDs for emergency access (fire call ID). The IS auditor found that fire call accounts are granted without a predefined expiration date. What should the IS auditor recommend?

a)

Review of the access control privilege authorization process

b)

Implementation of an identity management system (IMS)

c)

Enhancement of procedures to audit changes made to sensitive customer data

d)

Granting of fire call accounts only to managers

6.

During an application audit, an IS auditor is asked to provide assurance of the database referential integrity. Which of the following should be reviewed?

a)

Field definition

b)

Master table definition

c)

Composite keys

d)

Foreign key structure

7.

An IS auditor is reviewing database security for an organization. Which of the following is the MOST important consideration for database hardening?

a)

The default configurations are changed

b)

All tables in the database are normalized

c)

Stored procedures and triggers are encrypted

d)

The service port used by the database server is changed

8.

In auditing a database environment, an IS auditor will be MOST concerned if the database administrator (DBA) is performing which of the following functions?

a)

Performing database changes according to change management procedures

b)

Installing patches or upgrades to the operating system

c)

Sizing table space and consulting on table join limitations

d)

Performing backup and recovery procedures

9.

An IS auditor reviewing local area network (LAN) performance in an organization should FIRST examine:

a)

Connection and connection-less services

b)

The network topology diagram

c)

Data, voice and video throughput requirement

d)

The capacity of the wide area network (WAN) connection

10.

An IS auditor is evaluating the effectiveness of the organization’s change management process.

What is the MOST important control that the IS auditor should look for to ensure system availability?

a)

That changes are authorized by IT managers at all times

b)

That user acceptance testing (UAT) is performed and properly documented

c)

That test plans and procedures exist and are closely followed

d)

That capacity planning is performed as part of each development project

11.

Which of the following specifically addresses how to detect cyber attacks against an organization’s IT systems and how to recover from an attack?

a)

An incident response plan (IRP)

b)

An IT contingency plan

c)

A business continuity plan (BCP)

d)

A continuity of operations plan (COOP)

12.

The IS auditor is reviewing the implementation of storage area network (SAN). The SAN administrator indicates that logging and monitoring is active, hard zoning is used to isolate data from different business units and all unused SAN ports are disabled. The administrator implemented the system performed and documented security testing during implementation and determined that he/she is the only user with administrative rights to the system.


What should the auditor’s initial determination be?

a)

The SAN is secure and no significant risks exist

b)

The SAN presents a potential risks because soft zoning should be used

c)

The SAN presents a potential risks because audit logs are not reviewed in a timely manner

d)

The SAN presents a potential risks because only one employee has access

13.

An IS auditor is reviewing the expansion plans for an organization which is opening a new office about 80 meters away from their existing facility. The plan is to implement fiber-optic cabling within the new facility and it has been determined that a 100-meter, Category 5 (Cat 5), unshielded twisted-pair (UTP) cable can be installed to provide the connectivity between both buildings.


What is the PRIMARY risk that the auditor should identify with this expansion plan?

a)

The link between building may not meet the long-term business requirements

b)

The fiber-optic cabling will be expensive to install and maintain

c)

The implementation plan may not be achievable

d)

The new building is too close to the existing facility (a single disaster could destroy both sites)

14.

An organization is considering using a new IT service provider. From an audit perspective, which of the following would be the MOST important item to review?

a)

References from other clients for the service provider

b)

The physical security of the service provider site

c)

The service level agreement (SLA) with the service provider

d)

Background checks of the service provider’s employees