wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

ASI 4

Total questions: 15

Worksheet time: 9mins

Name
Class
Date
1.

An IS auditor planning an audit of a bank wire transfer system in the context of regulation that requires banks to accurately report transactions. Which of the following represents the PRIMARY focus of the audit scope?

a)

Data availability

b)

Data confidentiality

c)

Currency of data

d)

Data integrity

2.

An IS auditor reviewing the operating system integrity of a server would PRIMARILY:

a)

Verify that privileged programs or services cannot be invoked by user programs

b)

Determine whether administrator accounts have proper password controls

c)

Ensure that file permissions are correct on configuration files

d)

Verify that programs or services running on the server are from valid sources

3.

Which of the following is the MOST common concern for an IS auditor regarding audit logs?

a)

Logs can be examined only by system administrators

b)

Logs require special tools for collection and review

c)

Logs are typically not backed up regularly

d)

Logs are collected but not analyzed

4.

Which of the following would BEST help in preventing structured query language (SQL) injection attacks of a web application?

a)

Built-in input validations within the application

b)

Avoiding queries to the database from web applications

c)

Avoiding use of Dynamic SQL within the programmed queries

d)

All the database queries are reviewed by the database administrator (DBA)

5.

Which of the following is the BEST control to implement in order to mitigate the risk of an insider attack?

a)

Ensure that a comprehensive incident response plan has been put into place

b)

Log all user activity for critical systems

c)

Perform a criminal background check on all employees or contractors

d)

Limit access to what is required for an individual’s job duties

6.

Which of the following would be the BEST defense against the introduction of Trojan horse software into an organization?

a)

A keystroke logger application

b)

A virus scanning software application

c)

A stateful inspection firewall

d)

A debugger application

7.

An IS auditor discovers that the chief information officer (CIO) of an organization using a wireless broadband modem utilizing global system for mobile communications (GSM) technology. This modem is being used to connect the CIO’s laptop to the corporate virtual private network (VPN) when the CIO travels outside the office. The IS auditor should:

a)

Doing nothing since the inherent security features of GSM technology are appropriate

b)

Recommend that the CIO stop using the laptop computer until encrpytion is enabled

c)

Ensure media access control (MAC) address filtering is enabled on the network so unauthorized wireless users cannot connect

d)

Suggest that two factor authentification be used over the wireless link to prevent unauthorized communications

8.

Which of the following is the BEST way to minimize unauthorized access to unattended end-user PC systems?

a)

Using a password-protected screen saver

b)

Using auto logoff when a user leaves the system

c)

Terminating a user session at a predefined intervals

d)

Switching off the monitor so the screen is blank

9.

The implementation of which of the following would MOST effectively prevent unauthorized access to a system administration account?

a)

Host intrusion detection software

b)

Automatic password expiration policy

c)

Password complexity rules

d)

Two factor authentication

10.

An organization’s IT director has approved the installation of a wireless local area network (WLAN) access point in a conference room for a team of consultants to access the Internet with their laptop computers. The BEST control to protect the corporate servers from unauthorized access is to ensure that:

a)

Encryption is enabled on the access point

b)

The conference room network is on a separate virtual LAN (VLAN)

c)

Antivirus signatures and patch levels are current on the consultants’ laptop

d)

Default user ID are disabled and strong passwords are set on the corporate servers

11.

The IS auditor is reviewing an organization’s human resources (HR) database implementation. The auditor discovers that the database servers are clustered for high availability, all default database accounts have been removed and database audit logs are kept and reviewed on a weekly basis.


What other area should the auditor check to ensure that the databases are appropriately secured?

a)

Database digital signatures

b)

Database encryption nonces and other variables

c)

Database media access control (MAC) address authentication

d)

Database initialization parameters

12.

A small organization has only one database administrator (DBA). The DBA has root access to the UNIX server, which host the database application. How should segregation of duties be enforced in this scenario?

a)

Hire a second DBA and split the duties between the two individuals

b)

Remove the DBA’s root access on all UNIX servers

c)

Ensure that all actions of the DBA are logged and that all logs are backed up to tape

d)

Ensure that all the database logs are forwarded to a UNIX server where the DBA does not have root access.

13.

A new business application has been designed in a large, complex organization and the business owner has requested that the various reports be viewed on a “need to know” basis. Which of the following access control methods would be the BEST method to achieve this requirement?

a)

Mandatory

b)

Role-based

c)

Discretionary

d)

Single sign-on (SSO)

14.

Which of the following is the BEST control to prevent the deletion of audit logs by unauthorized individuals in an organization?

a)

Actions on log files should be tracked in another log

b)

Write access to audit logs should be disabled

c)

Only selected personnel should have rights to view or delete audit logs

d)

Backup of audit logs should be performed periodically

15.

An IS auditor learns that the IT department is considering a plan to switch from centralized user access administration to distributed administration for applications which are used in its offices worldwide. All applications are hosted in the main office data center. Under the new plan, each country will have a local administrator to manage and maintain local user access.


What should the IS auditor recommend with respect to the risks associated with this plan?

a)

The plan is not acceptable because of the increased risk of unauthorized user access

b)

The plan is acceptable as long as all user access is approved by senior management in the main office.

c)

The plan is not acceptable because local administrators may lack the appropriate security skills or training

d)

The plan is acceptable as long as appropriate monitoring controls are put in place and user access levels are adequately approved