NEW
Font size
WorksheetsASI 4
Total questions: 15
Worksheet time: 9mins
An IS auditor planning an audit of a bank wire transfer system in the context of regulation that requires banks to accurately report transactions. Which of the following represents the PRIMARY focus of the audit scope?
Data availability
Data confidentiality
Currency of data
Data integrity
An IS auditor reviewing the operating system integrity of a server would PRIMARILY:
Verify that privileged programs or services cannot be invoked by user programs
Determine whether administrator accounts have proper password controls
Ensure that file permissions are correct on configuration files
Verify that programs or services running on the server are from valid sources
Which of the following is the MOST common concern for an IS auditor regarding audit logs?
Logs can be examined only by system administrators
Logs require special tools for collection and review
Logs are typically not backed up regularly
Logs are collected but not analyzed
Which of the following would BEST help in preventing structured query language (SQL) injection attacks of a web application?
Built-in input validations within the application
Avoiding queries to the database from web applications
Avoiding use of Dynamic SQL within the programmed queries
All the database queries are reviewed by the database administrator (DBA)
Which of the following is the BEST control to implement in order to mitigate the risk of an insider attack?
Ensure that a comprehensive incident response plan has been put into place
Log all user activity for critical systems
Perform a criminal background check on all employees or contractors
Limit access to what is required for an individual’s job duties
Which of the following would be the BEST defense against the introduction of Trojan horse software into an organization?
A keystroke logger application
A virus scanning software application
A stateful inspection firewall
A debugger application
An IS auditor discovers that the chief information officer (CIO) of an organization using a wireless broadband modem utilizing global system for mobile communications (GSM) technology. This modem is being used to connect the CIO’s laptop to the corporate virtual private network (VPN) when the CIO travels outside the office. The IS auditor should:
Doing nothing since the inherent security features of GSM technology are appropriate
Recommend that the CIO stop using the laptop computer until encrpytion is enabled
Ensure media access control (MAC) address filtering is enabled on the network so unauthorized wireless users cannot connect
Suggest that two factor authentification be used over the wireless link to prevent unauthorized communications
Which of the following is the BEST way to minimize unauthorized access to unattended end-user PC systems?
Using a password-protected screen saver
Using auto logoff when a user leaves the system
Terminating a user session at a predefined intervals
Switching off the monitor so the screen is blank
The implementation of which of the following would MOST effectively prevent unauthorized access to a system administration account?
Host intrusion detection software
Automatic password expiration policy
Password complexity rules
Two factor authentication
An organization’s IT director has approved the installation of a wireless local area network (WLAN) access point in a conference room for a team of consultants to access the Internet with their laptop computers. The BEST control to protect the corporate servers from unauthorized access is to ensure that:
Encryption is enabled on the access point
The conference room network is on a separate virtual LAN (VLAN)
Antivirus signatures and patch levels are current on the consultants’ laptop
Default user ID are disabled and strong passwords are set on the corporate servers
The IS auditor is reviewing an organization’s human resources (HR) database implementation. The auditor discovers that the database servers are clustered for high availability, all default database accounts have been removed and database audit logs are kept and reviewed on a weekly basis.
What other area should the auditor check to ensure that the databases are appropriately secured?
Database digital signatures
Database encryption nonces and other variables
Database media access control (MAC) address authentication
Database initialization parameters
A small organization has only one database administrator (DBA). The DBA has root access to the UNIX server, which host the database application. How should segregation of duties be enforced in this scenario?
Hire a second DBA and split the duties between the two individuals
Remove the DBA’s root access on all UNIX servers
Ensure that all actions of the DBA are logged and that all logs are backed up to tape
Ensure that all the database logs are forwarded to a UNIX server where the DBA does not have root access.
A new business application has been designed in a large, complex organization and the business owner has requested that the various reports be viewed on a “need to know” basis. Which of the following access control methods would be the BEST method to achieve this requirement?
Mandatory
Role-based
Discretionary
Single sign-on (SSO)
Which of the following is the BEST control to prevent the deletion of audit logs by unauthorized individuals in an organization?
Actions on log files should be tracked in another log
Write access to audit logs should be disabled
Only selected personnel should have rights to view or delete audit logs
Backup of audit logs should be performed periodically
An IS auditor learns that the IT department is considering a plan to switch from centralized user access administration to distributed administration for applications which are used in its offices worldwide. All applications are hosted in the main office data center. Under the new plan, each country will have a local administrator to manage and maintain local user access.
What should the IS auditor recommend with respect to the risks associated with this plan?
The plan is not acceptable because of the increased risk of unauthorized user access
The plan is acceptable as long as all user access is approved by senior management in the main office.
The plan is not acceptable because local administrators may lack the appropriate security skills or training
The plan is acceptable as long as appropriate monitoring controls are put in place and user access levels are adequately approved
