WorksheetsCASA - 2 DISA
Total questions: 200
Worksheet time: 3hrs 20mins
Name
Class
Date
1.
1. An IS auditor is reviewing access to an application to determine whether the 10 most recent "new user" forms were correctly authorized. This is an example of:
a)
variable sampling.
b)
substantive testing.
c)
compliance testing.
d)
stop-or-go sampling.
2.
3. Senior management has requested that an IS auditor assist the departmental management in the implementation of necessary controls. The IS auditor should:
a)
refuse the assignment since it is not the role of the IS auditor.
b)
inform management of his/her inability to conduct future audits.
c)
perform the assignment and future audits with due professional care.
d)
obtain the approval of user management to perform the implementation and follow-up.
3.
5. Which of the following is a substantive test?
a)
Checking a list of exception reports
b)
Ensuring approval for parameter changes
c)
Using a statistical sample to inventory the tape library
d)
Reviewing password history reports
4.
6. The use of statistical sampling procedures helps minimize:
a)
sampling risk.
b)
detection risk.
c)
inherent risk.
d)
control risk.
5.
7. Which of the following is a benefit of a risk-based approach to audit planning? Audit:
a)
scheduling may be performed months in advance.
b)
budgets are more likely to be met by the IS audit staff.
c)
staff will be exposed to a variety of technologies.
d)
resources are allocated to the areas of highest concern.
6.
8. The PRIMARY objective of an IS audit function is to:
a)
determine whether everyone uses IS resources according to their job description.
b)
determine whether information systems safeguard assets and maintain data integrity.
c)
examine books of accounts and relative documentary evidence for the computerized system.
d)
determine the ability of the organization to detect fraud.
7.
9. An IS auditor conducting a review of software usage and licensing discovers that numerous PCs contain unauthorized software. Which of the following actions should the IS auditor take?
a)
Personally delete all copies of the unauthorized software.
b)
Inform the auditee of the unauthorized software, and follow up to confirm deletion.
c)
Report the use of the unauthorized software and the need to prevent recurrence to auditee management.
d)
Take no action, as it is a commonly accepted practice and operations management is responsible for monitoring such use.
8.
14. Which of the following sampling methods is MOST useful when testing for compliance?
a)
Attribute sampling
b)
Variable sampling
c)
Stratified mean per unit
d)
Difference estimation
9.
15. The PRIMARY purpose of an audit charter is to:
a)
document the audit process used by the enterprise.
b)
formally document the audit department's plan of action.
c)
document a code of professional conduct for the auditor.
d)
describe the authority and responsibilities of the audit department.
10.
21. Which of the following tests is an IS auditor performing when a sample of programs is selected to determine if the source and object versions are the same?
a)
A substantive test of program library controls
b)
A compliance test of program library controls
c)
A compliance test of the program compiler controls
d)
A substantive test of the program compiler controls
11.
25. With regard to sampling, it can be said that:
a)
sampling is generally applicable when the population relates to an intangible or undocumented control.
b)
if an auditor knows internal controls are strong, the confidence coefficient may be lowered.
c)
attribute sampling would help prevent excessive sampling of an attribute by stopping an audit test at the earliest possible moment.
d)
variable sampling is a technique to estimate the rate of occurrence of a given control or set of related controls.
12.
26. Which of the following processes describes risk assessment? Risk assessment is:
a)
subjective.
b)
objective.
c)
mathematical.
d)
statistical.
13.
33. When implementing continuous monitoring systems, an IS auditor's first step is to identify:
a)
reasonable target thresholds.
b)
high-risk areas within the organization.
c)
the location and format of output files.
d)
applications that provide the highest potential payback.
14.
40. In a critical server, an IS auditor discovers a Trojan horse that was produced by a known virus that exploits a vulnerability of an operating system. Which of the following should an IS auditor do FIRST?
a)
Investigate the virus's author.
b)
Analyze the operating system log.
c)
Ensure that the malicious code is removed.
d)
Install the patch that eliminates the vulnerability.
15.
42. An IS auditor has imported data from the client's database. The next step-confirming whether the imported data are complete-is performed by:
a)
matching control totals of the imported data to control totals of the original data.
b)
sorting the data to confirm whether the data are in the same order as the original data.
c)
reviewing the printout of the first 100 records of original data with the first 100 records of importeddata.
d)
filtering data for different categories and matching them to the original data.
16.
53. Which audit technique provides the BEST evidence of the segregation of duties in an IS department?
a)
Discussion with management
b)
Review of the organization chart
c)
Observation and interviews
d)
Testing of user access rights
17.
63. An IS auditor attempting to determine whether access to program documentation is restricted to authorized persons would MOST likely:
a)
evaluate the record retention plans for off-premises storage.
b)
interview programmers about the procedures currently being followed.
c)
compare utilization records to operations schedules.
d)
review data file access records to test the librarian function.
18.
65. Which of the following audit tools is MOST useful to an IS auditor when an audit trail is required?
a)
Integrated test facility (ITF)
b)
Continuous and intermittent simulation (CIS)
c)
Audit hooks
d)
Snapshots
19.
67. The BEST method of proving the accuracy of a system tax calculation is by:
a)
detailed visual review and analysis of the source code of the calculation programs.
b)
recreating program logic using generalized audit software to calculate monthly totals.
c)
preparing simulated transactions for processing and comparing the results to predetermined results.
d)
automatic flowcharting and analysis of the source code of the calculation programs.
20.
72. The traditional role of an IS auditor in a control self-assessment (CSA) should be that of:
a)
facilitator.
b)
manager.
c)
partner.
d)
stakeholder.
21.
77. To ensure that audit resources deliver the best value to the organization, the FIRST step would be to:
a)
schedule the audits and monitor the time spent on each audit.
b)
train the IS audit staff on current technology used in the company.
c)
develop the audit plan on the basis of a detailed risk assessment.
d)
monitor progress of audits and initiate cost control measures.
22.
81. When assessing the design of network monitoring controls, an IS auditor should FIRST review network:
a)
topology diagrams.
b)
bandwidth usage.
c)
traffic analysis reports.
d)
bottleneck locations.
23.
82. While conducting an audit, an IS auditor detects the presence of a virus. What should be the IS auditor's next step?
a)
Observe the response mechanism.
b)
Clear the virus from the network.
c)
Inform appropriate personnel immediately.
d)
Ensure deletion of the virus.
24.
84. The MOST likely effect of the lack of senior management commitment to IT strategic planning is:
a)
a lack of investment in technology.
b)
a lack of a methodology for systems development.
c)
the technology not aligning with the organization's objectives.
d)
an absence of control over technology contracts.
25.
91. From a control perspective, the key element in job descriptions is that they:
a)
provide instructions on how to do the job and define authority.
b)
are current, documented and readily available to the employee.
c)
communicate management's specific job performance expectations.
d)
establish responsibility and accountability for the employee's actions.
26.
95. The IT balanced scorecard is a business governance tool intended to monitor IT performance evaluation indicators other than:
a)
financial results.
b)
customer satisfaction.
c)
internal process efficiency.
d)
innovation capacity.
27.
97. Many organizations require an employee to take a mandatory vacation (holiday) of a week or more to:
a)
ensure the employee maintains a good quality of life, which will lead to greater productivity.
b)
reduce the opportunity for an employee to commit an improper or illegal act.
c)
provide proper cross-training for another employee.
d)
eliminate the potential disruption caused when an employee takes vacation one day at a time.
28.
101. Before implementing an IT balanced scorecard, an organization must:
a)
deliver effective and efficient services.
b)
define key performance indicators.
c)
provide business value to IT projects.
d)
control IT expenses.
29.
102. To support an organization's goals, the IS department should have:
a)
a low-cost philosophy.
b)
long- and short-range plans.
c)
leading-edge technology.
d)
planned to acquire new hardware and software.
30.
105. Which of the following goals would you expect to find in an organization's strategic plan?
a)
Test a new accounting package.
b)
Perform an evaluation of information technology needs.
c)
Implement a new project planning system within the next 12 months.
d)
Become the supplier of choice for the product offered.
31.
112. The rate of change in technology increases the importance of:
a)
outsourcing the IS function.
b)
implementing and enforcing good processes.
c)
hiring personnel willing to make a career within the organization.
d)
meeting user requirements.
32.
117. Which of the following should be included in an organization's IS security policy?
a)
A list of key IT resources to be secured
b)
The basis for access authorization
c)
Identity of sensitive security features
d)
Relevant software security features
33.
118. Which of the following is the initial step in creating a firewall policy?
a)
A cost-benefit analysis of methods for securing the applications
b)
Identification of network applications to be externally accessed
c)
Identification of vulnerabilities associated with network applications to be externally accessed
d)
Creation of an applications traffic matrix showingprotection methods
34.
119. The management of an organization has decided to establish a security awareness program. Which of the following would MOST likely be a part of the program?
a)
Utilization of an intrusion detection system to report incidents
b)
Mandating the use of passwords to access all software
c)
Installing an efficient user log system to track the actions of each user
d)
Training provided on a regular basis to all current and new employees
35.
120. Which of the following is the MOST critical for the successful implementation and maintenance of a security policy?
a)
Assimilation of the framework and intent of a written security policy by all appropriate parties
b)
Management support and approval for the implementation and maintenance of a security policy
c)
Enforcement of security rules by providing punitive actions for any violation of securityrules
d)
Stringent implementation, monitoring and enforcing of rules by the security officer through access control software
36.
121. A comprehensive and effective e-mail policy should address the issues of e-mail structure, policy enforcement, monitoring and:
a)
recovery.
b)
retention.
c)
rebuilding.
d)
reuse.
37.
125. The initial step in establishing an information security program is the:
a)
development and implementation of an information security standards manual.
b)
performance of a comprehensive security control review by the IS auditor.
c)
adoption of a corporate information security policy statement.
d)
purchase of security access control software.
38.
128. Which of the following is the MOST important function to be performed by IS management when a service has been outsourced?
a)
Ensuring that invoices are paid to the provider
b)
Participating in systems design with the provider
c)
Renegotiating the provider's fees
d)
Monitoring the outsourcing provider's performance
39.
129. Is it appropriate for an IS auditor from a company that is considering outsourcing its IS processing to request and review a copy of each vendor's business continuity plan?
a)
Yes, because the IS auditor will evaluate the adequacy of the service bureau's plan and assist his/her company in implementing a complementary plan.
b)
Yes, because based on the plan, the IS auditor will evaluate the financial stability of the service bureau and its ability to fulfill the contract.
c)
No, because the backup to be provided should be specified adequately in the contract.
d)
No, because the service bureau's business continuity plan is proprietary information.
40.
130. A probable advantage to an organization that has outsourced its data processing services is that:
a)
needed IS expertise can be obtained from the outside.
b)
greater control can be exercised over processing.
c)
processing priorities can be established and enforced internally.
d)
greater user involvement is required to communicate user needs.
41.
137. An IS auditor was hired to review e-business security. The IS auditor's first task was to examine each existing e-business application looking for vulnerabilities. Which would be the next task?
a)
Report the risks to the CIO and CEO immediately.
b)
Examine e-business application in development.
c)
Identify threats and likelihood of occurrence.
d)
Check the budget available for risk management.
42.
143. Which of the following would provide a mechanism whereby IS management can determine if the activities of the organization have deviated from the planned or expected levels?
a)
Quality management
b)
IS assessment methods
c)
Management principles
d)
Industry standards/benchmarking
43.
149. When segregation of duties concerns exist between IT support staff and end users, what would be a suitable compensating control?
a)
Restricting physical access to computing equipment
b)
Reviewing transaction and application logs
c)
Performing background checks prior to hiring IT staff
d)
Locking user sessions after a specified period of inactivity
44.
150. Giving responsibility to business units for the development of applications would MOST likely lead to:
a)
significantly reduced data communications needs.
b)
the exercise of a lower level of control.
c)
the exercise of a higher level of control.
d)
an improved segregation of duties.
45.
152. An IS auditor reviewing an organization that uses cross-training practices should assess the risk of:
a)
dependency on a single person.
b)
inadequate succession planning.
c)
one person knowing all parts of a system.
d)
a disruption of operations.
46.
154. Which of the following would MOST likely indicate that a customer data warehouse should remain in-house rather than be outsourced to an offshore operation?
a)
Time zone differences could impede communications between IT teams.
b)
Telecommunications cost could be much higher in the first year.
c)
Privacy laws could prevent cross-border flow of information.
d)
Software development may require more detailed specifications.
47.
155. To minimize costs and improve service levels an outsourcer should seek which of the following contract clauses?
a)
O/S and hardware refresh frequencies
b)
Gain-sharing performance bonuses
c)
Penalties for noncompliance
d)
Charges tied to variable cost metrics
48.
156. When an organization is outsourcing their information security function, which of the following should be kept in the organization?
a)
Accountability for the corporate security policy
b)
Defining the corporate security policy
c)
Implementing the corporate security policy
d)
Defining security procedures and guidelines
49.
160. The quality assurance group is typically responsible for:
a)
ensuring that the output received from system processing is complete.
b)
monitoring the execution of computer processing tasks.
c)
ensuring that programs and program changes and documentation adhere to established standards.
d)
designing procedures to protect data against accidental disclosure, modification or destruction.
50.
161. Which of the following risks could result from inadequate software baselining?
a)
Scope creep
b)
Sign-off delays
c)
Software integrity violations
d)
Inadequate controls
51.
162. Which of the following would be the MOST likely to ensure that business requirements are met during software development?
a)
Adequate training
b)
Programmers that clearly understand the business processes
c)
Documentation of business rules
d)
Early engagement of key users
52.
163. The request for proposal (RFP) for the acquisition of an application system would MOST likely be approved by the:
a)
project steering committee.
b)
project sponsor.
c)
project manager.
d)
user project team.
53.
164. Procedures to prevent scope creep should be baselined in which of the following systems development life cycle (SDLC) phases?
a)
Development
b)
Implementation
c)
Design
d)
Feasibility
54.
168. Which of the following groups should assume ownership of a systems development project and the resulting system?
a)
User management
b)
Senior management
c)
Project steering committee
d)
Systems development management
55.
171. In planning a software development project, which of the following is the MOST difficult to determine?
a)
Project slack times
b)
The project's critical path
c)
Time and resource requirements for individual tasks
d)
Relationships that preclude the start of an activity before others are complete
56.
172. The PRIMARY reason for separating the test and development environments is to:
a)
restrict access to systems under test.
b)
segregate user and development staff.
c)
control the stability of the test environment.
d)
secure access to systems under development.
57.
179. Change control for business application systems being developed using prototyping could be complicated by the:
a)
iterative nature of prototyping.
b)
rapid pace of modifications in requirements and design.
c)
emphasis on reports and screens.
d)
lack of integrated tools.
58.
187. The purpose of a checksum on an amount field in an electronic data interchange (EDI) communication of financial transactions is to ensure:
a)
integrity.
b)
authenticity.
c)
authorization.
d)
nonrepudiation.
59.
193. Which of the following types of controls is designed to provide the ability to verify data and record values through the stages of application processing?
a)
Range checks
b)
Run-to-run totals
c)
Limit checks on calculated amounts
d)
Exception reports
60.
206. Which of the following data validation edits is effective in detecting transposition and transcription errors?
a)
Range check
b)
Check digit
c)
Validity check
d)
Duplicate check
61.
207. Which of the following is the GREATEST risk when implementing a data warehouse?
a)
Increased response time on the production systems
b)
Access controls that are not adequate to prevent data modification
c)
Data duplication
d)
Data that is not updated or current
62.
212. Which of the following is often an advantage of using prototyping for systems development?
a)
The finished system will have adequate controls.
b)
The system will have adequate security/audit trail.
c)
It reduces time to deployment.
d)
It is easy to achieve change control.
63.
213. An IS auditor that participates in the testing stage of a software development project establishes that the individual modules perform correctly. The IS auditor should:
a)
conclude that the individual modules running as a group will be correct.
b)
document the test as positive proof that the system can produce the desired results.
c)
inform management and recommend an integrated test.
d)
provide additional test data.
64.
214. During the audit of an acquired software package, the IS auditor learned that the software purchase was based on information obtained through the Internet, rather than from responses to a request for proposal (RFP). The IS auditor should FIRST:
a)
test the software for compatibility with existing hardware.
b)
perform a gap analysis.
c)
review the licensing policy.
d)
ensure that the procedure had been approved.
65.
218. A debugging tool, which reports on the sequence of steps executed by a program, is called a(n):
a)
output analyzer.
b)
memory dump.
c)
compiler.
d)
logic path monitor.
66.
222. Which of the following facilitates program maintenance?
a)
More cohesive and loosely coupled programs
b)
Less cohesive and loosely coupled programs
c)
More cohesive and strongly coupled programs
d)
Less cohesive and strongly coupled programs
67.
228. Which of the following is an object-oriented technology characteristic that permits an enhanced degree of security over data?
a)
Inheritance
b)
Dynamic warehousing
c)
Encapsulation
d)
Polymorphism
68.
229. Which of the following BEST describes the objectives of following a standard system development methodology?
a)
To ensure that appropriate staffing is assigned and to provide a method of controlling costs and schedules
b)
To provide a method of controlling costs and schedules and to ensure communication among users, IS auditors, management and IS personnel
c)
To provide a method of controllingcosts and schedules and an effective means of auditing project development
d)
To ensure communication among users, IS auditors, management and personnel, and to ensure that appropriate staffing is assigned
69.
234. When implementing an application software package, which of the following presents the GREATEST risk?
a)
Uncontrolled multiple software versions
b)
Source programs that are not synchronized with object code
c)
Incorrectly set parameters
d)
Programming errors
70.
239. An IS auditor's PRIMARY concern when application developers wish to use a copy of yesterday's production transaction file for volume tests is that:
a)
users may prefer to use contrived data for testing.
b)
unauthorized access to sensitive data may result.
c)
error handling and credibility checks may not be fully proven.
d)
the full functionality of the new process may not necessarily be tested.
71.
240. Which of the following is the PRIMARY purpose for conducting parallel testing?
a)
To determine if the system is cost-effective
b)
To enable comprehensive unit and system testing
c)
To highlight errors in the program interfaces with files
d)
To ensure the new system meets user requirements
72.
246. Which of the following is MOST likely to occur when a system development project is in the middle of the programming/coding phase?
a)
Unit tests
b)
Stress tests
c)
Regression tests
d)
Acceptance tests
73.
247. A distinguishing feature of fourth-generation languages (4GLs) is portability, which means?
a)
Environmental independence
b)
Workbench concepts (i.e., temporary storage, test editing, etc.)
c)
Ability to design screen formats and develop graphical outputs
d)
Ability to execute online operations
74.
258. The purpose of debugging programs is to:
a)
generate random data that can be used to test programs before implementing them.
b)
protect valid changes from being overwritten by other changes during programming.
c)
define the program development and maintenance costs to be include in the feasibility study.
d)
ensure that abnormalterminations and coding flaws are detected and corrected.
75.
263. A data warehouse is:
a)
object-oriented.
b)
subject-oriented.
c)
departmental specific.
d)
a volatile database
76.
267. An organization planning to purchase a software package asks the IS auditor for a risk assessment. Which of the following is the MAJOR risk?
a)
Unavailability of the source code
b)
Lack of a vendor-quality certification
c)
Absence of vendor/client references
d)
Little vendor experience with the package
77.
271. The GREATEST benefit in implementing an expert system is the:
a)
capturing of the knowledge and experience of individuals in an organization.
b)
sharing of knowledge in a central repository.
c)
enhancement of personnel productivity and performance.
d)
reduction of employee turnover in key departments.
78.
272. Which of the following types of testing would determine whether a new or modified system can operate in its target environment without adversely impacting other existing systems?
a)
Parallel testing
b)
Pilot testing
c)
Interface/integration testing
d)
Sociability testing
79.
274. Good quality software is BEST achieved:
a)
through thorough testing.
b)
by finding and quickly correcting programming errors.
c)
by determining the amount of testing using the available time and budget.
d)
by applying well-defined processes and structured reviews throughout the project.
80.
275. Which of the following is an implementation risk within the process of decision support systems?
a)
Management control
b)
Semistructured dimensions
c)
Inability to specify purpose and usage patterns
d)
Changes in decision processes
81.
285. An IS auditor finds out-of-range data in some tables of a database. Which of the following controls should the IS auditor recommend to avoid this situation?
a)
Log all table update transactions.
b)
Implement before-and-after image reporting.
c)
Use tracing and tagging.
d)
Implement integrity constraints in the database.
82.
286. A financial institution is using an expert system for managing credit limits. An IS auditor reviewing the system should be MOST concerned with the:
a)
validation of data inputs into the system.
b)
level of experience and skills contained in the knowledge base.
c)
access control settings.
d)
implemented processing controls.
83.
287. Responsibility and reporting lines cannot always be established when auditing automated systems since:
a)
diversified control makes ownership irrelevant.
b)
staff traditionally changes jobs with greater frequency.
c)
ownership is difficult to establish where resources are shared.
d)
duties change frequently in the rapid development of technology.
84.
288. When assessing the portability of a database application, the IS auditor should verify that:
a)
a structured query language (SQL) is used.
b)
information import and export procedures exist with other systems.
c)
indexes are used.
d)
all entities have a significant name and identified primary and foreign keys.
85.
290. Which of the following would help to ensure the portability of an application connected to a database? The:
a)
verification of database import and export procedures.
b)
usage of a structured query language (SQL).
c)
analysis of stored procedures/triggers.
d)
synchronization of the entity-relation model with the database physical schema.
86.
297. A retail company recently installed data warehousing client software at geographically diverse sites. Due to time zone differences between the sites, updates to the warehouse are not synchronized. Which of the following will be affected the MOST?
a)
Data availability
b)
Data completeness
c)
Data redundancy
d)
Data inaccuracy
87.
302. When two or more systems are integrated, input/output controls must be reviewed by the IS auditor in the:
a)
systems receiving the output of other systems.
b)
systems sending output to other systems.
c)
systems sending and receiving data.
d)
interfaces between the two systems.
88.
307. Which of the following is a control to compensate for a programmer having access to accounts payable production data?
a)
Processing controls such as range checks and logic edits
b)
Reviewing accounts payable output reports by data entry
c)
Reviewing system-produced reports for checks (cheques) over a stated amount
d)
Having the accounts payable supervisor match all checks (cheques) to approved invoices
89.
309. An IS auditor performing a review of the EFT operations of a retailing company would verify that the customers credit limit is checked before funds are transferred by reviewing the EFT:
a)
system's interface.
b)
switch facility.
c)
personal identification number generating procedure.
d)
operation backup procedures.
90.
313. Which of the following is the MOST critical and contributes the MOST to the quality of data in a data warehouse?
a)
Accuracy of the source data
b)
Credibility of the data source
c)
Accuracy of the extraction process
d)
Accuracy of the data transformation
91.
314. After discovering a security vulnerability in a third-party application that interfaces with several external systems, a patch is applied to a significant number of modules. Which of the following tests should an IS auditor recommend?
a)
Stress
b)
Black box
c)
Interface
d)
System
92.
315. Which of the following is the FIRST step in a business process reengineering (BPR) project?
a)
Defining the areas to be reviewed
b)
Developing a project plan
c)
Understanding the process under review
d)
Reengineering and streamlining the process under review
93.
318. Which of the following would be a risk specifically associated with the agile development process?
a)
Lack of documentation
b)
Lack of testing
c)
Poor requirements definition
d)
Poor project management practices
94.
321. When planning to add personnel to tasks imposing time constraints on the duration of a project, which of the following should be revalidated FIRST?
a)
The project budget
b)
The critical path for the project
c)
The length of the remaining tasks
d)
The personnel assigned to other tasks
95.
328. Which of the following should an IS auditor review to gain an understanding of the effectiveness of controls over the management of multiple projects?
a)
Project database
b)
Policy documents
c)
Project portfolio database
d)
Program organization
96.
329. An organization donating used computers should ensure that:
a)
the computers were not used to store confidential data.
b)
a nondisclosure agreement has been signed.
c)
the data storage media are sanitized.
d)
all data has been deleted.
97.
331. During the review of a web-based software development project, the IS auditor realizes that coding standards are not enforced and code reviews are rarely carried out. This will MOST likely increase the likelihood of a successful:
a)
buffer overflow.
b)
brute force attack.
c)
distributed denial-of-service attack.
d)
war dialing attack.
98.
335. For an online transaction processing system, transactions per second is a measure of:
a)
throughput.
b)
response time.
c)
turnaround time.
d)
uptime.
99.
340. An IS auditor evaluating the resilience of a high-availability network should be MOST concerned if:
a)
the setup is geographically dispersed.
b)
the network servers are clustered in a site.
c)
a hot site is ready for activation.
d)
diverse routing is implemented for the network.
100.
349. Which of the following would an IS auditor expect to find in a console log?
a)
Names of system users
b)
Shift supervisor identification
c)
System errors
d)
Data edit errors
101.
351. Which of the following will help detect changes made by an intruder to the system log of a server?
a)
Mirroring the system log on another server
b)
Simultaneously duplicating the system log on a write-once disk
c)
Write-protecting the directory containing the system log
d)
Storing the backup of the system log offsite
102.
353. IT operations for a large organization have been outsourced. An IS auditor reviewing the outsourced operation should be MOST concerned about which of the following findings?
a)
The outsourcing contract does not cover disaster recovery for the outsourced IT operations.
b)
The service provider does not have incident handling procedures.
c)
Recently a corrupted database could not be recovered because of library management problems.
d)
Incident logs are not beingreviewed.
103.
354. An organization has outsourced IT operations to a service provider. The organization's IS auditor makes the following observations:
a)
Improve the backup of critical systems.
b)
Delay moving the servers.
c)
Incorporate disaster recovery in the contract.
d)
Back up data to a location further away from the service provider.
104.
355. Which of the following BEST ensures the integrity of a server's operating system?
a)
Protecting the server in a secure location
b)
Setting a boot password
c)
Hardening the server configuration
d)
Implementing activity logging
105.
356. An IS auditor detected that several PCs connected to the Internet have a low security level that is allowing for the free recording of cookies. This creates a risk because cookies locally store:
a)
information about the Internet site.
b)
information about the user.
c)
information for the Internet connection.
d)
Internet pages.
106.
357. Which of the following is the MOST probable cause for a mail server being used to send spam?
a)
Installing an open relay server
b)
Enabling Post Office Protocol (POP3)
c)
Using Simple Mail Transfer Protocol (SMTP)
d)
Activating user accounting
107.
362. An organization wants to enforce data integrity principles and achieve faster performance/execution in a database application. Which of the following design principles should be applied?
a)
User (customized) triggers
b)
Data validation at the front end
c)
Data validation at the back end
d)
Referential integrity
108.
363. To share data in a multivendor network environment, it is essential to implement program-to-program communication. With respect to program-to-program communication features, that can be implemented in this environment, which of the following makes implementation and maintenance difficult?
a)
User isolation
b)
Controlled remote access
c)
Transparent remote access
d)
The network environments
109.
364. An IS auditor is reviewing the database administration (DBA) function to ascertain whether adequate provision has been made for controlling data. The IS auditor should determine that the:
a)
function reports to data processing operations.
b)
responsibilities of the function are well defined.
c)
database administrator is a competent systems programmer.
d)
audit software has the capability of efficiently accessing the database.
110.
365. Which of the following is a control over database administration activities?
a)
A database checkpoint to restart processing after a system failure
b)
Database compression to reduce unused space
c)
Supervisory review of access logs
d)
Backup and recovery procedures to ensure database availability
111.
368. The objective of concurrency control in a database system is to:
a)
restrict updating of the database to authorized users.
b)
prevent integrity problems, when two processes attempt to update the same data at the same time.
c)
prevent inadvertent or unauthorized disclosure of data in the database.
d)
ensure the accuracy, completeness and consistency ofdata.
112.
370. Which of the following controls would provide the GREATEST assurance of database integrity?
a)
Audit log procedures
b)
Table link/reference checks
c)
Query/table access time checks
d)
Rollback and rollforward database features
113.
371. The database administrator has decided to disable certain normalization controls in the database management system (DBMS) software to provide users with increased query performance. This will MOST likely increase the risk of:
a)
loss of audit trails.
b)
redundancy of data.
c)
loss of data integrity.
d)
unauthorized access to data.
114.
374. Following a reorganization of a company's legacy database, it was discovered that records were accidentally deleted. Which of the following controls would have MOST effectively detected this occurrence?
a)
Range check
b)
Table lookups
c)
Run-to-run totals
d)
One-for-one checking
115.
380. Which of the following types of firewalls provide the GREATEST degree and granularity of control?
a)
Screening router
b)
Packet filter
c)
Application gateway
d)
Circuit gateway
116.
382. Which of the following is MOST directly affected by network performance monitoring tools?
a)
Integrity
b)
Availability
c)
Completeness
d)
Confidentiality
117.
383. In a small organization, an employee performs computer operations and, when the situation demands, program modifications. Which of the following should the IS auditor recommend?
a)
Automated logging of changes to development libraries
b)
Additional staff to provide separation of duties
c)
Procedures that verify that only approved program changes are implemented
d)
Access controls to prevent the operator from making program modifications
118.
384. Checking for authorized software baselines is an activity addressed within which of the following?
a)
Project management
b)
Configuration management
c)
Problem management
d)
Risk management
119.
387. One of the purposes of library control software is to allow:
a)
programmers access to production source and object libraries.
b)
batch program updating.
c)
operators to update the control library with the production version before testing is completed.
d)
read-only access to source code.
120.
391. Which of the following is a control to detect an unauthorized change in a production environment?
a)
Denying programmers access to production data
b)
Requiring change requests to include benefits and costs
c)
Periodically comparing control and current object and source programs
d)
Establishing procedures for emergency changes
121.
394. An IS auditor reviewing database controls discovered that changes to the database during normal working hours were handled through a standard set of procedures. However, changes made after normal hours required only an abbreviated number of steps. In this situation, which of the following would be considered an adequate set of compensating controls?
a)
Allow changes to be made only with the DBA user account.
b)
Make changes to the database after granting access to a normal user account
c)
Use the DBA user account to make changes, log the changes and review the change log the following day.
d)
Use the normal user account to make changes, log the changes and review the change log the following day.
122.
397. A programmer maliciously modified a production program to change data and then restored the original code. Which of the following would MOST effectively detect the malicious activity?
a)
Comparing source code
b)
Reviewing system log files
c)
Comparing object code
d)
Reviewing executable and source code integrity
123.
401. Which of the following is the MOST effective method for dealing with the spreading of a network worm that exploits a vulnerability in a protocol?
a)
Install the vendor's security fix for the vulnerability.
b)
Block the protocol traffic in the perimeter firewall.
c)
Block the protocol traffic between internal network segments.
d)
Stop the service until an appropriate security fix is installed.
124.
410. Which of the following BEST reduces the ability of one device to capture the packets that are meant for another device?
a)
Filters
b)
Switches
c)
Routers
d)
Firewalls
125.
411. In a database management system (DBMS), the location of data and the method of accessing the data are provided by the:
a)
data dictionary.
b)
metadata.
c)
directory system.
d)
data definition language.
126.
420. Utility programs that assemble software modules needed to execute a machine instruction application program version are:
a)
text editors.
b)
program library managers.
c)
linkage editors and loaders.
d)
debuggers and development aids.
127.
437. In a client-server architecture, a domain name service (DNS) is MOST important, because it provides the:
a)
address of the domain server.
b)
resolution service for the name/address.
c)
IP addresses for the Internet.
d)
domain name system.
128.
440. Which of the following would be considered an essential feature of a network management system?
a)
A graphical interface to map the network topology
b)
Capacity to interact with the Internet to solve the problems
c)
Connectivity to a help desk for advice on difficult issues
d)
An export facility for piping data to spreadsheets
129.
443. When reviewing the implementation of a LAN, the IS auditor should FIRST review the:
a)
node list.
b)
acceptance test report.
c)
network diagram.
d)
user's list.
130.
446. Reconfiguring which of the following firewall types will prevent inward downloading of files through the File Transfer Protocol (FTP)?
a)
Circuit gateway
b)
Application gateway
c)
Packet filter
d)
Screening router
131.
450. Java applets and ActiveX controls are distributed executable programs that execute in the background of a web browser client. This practice is considered reasonable when:
a)
a firewall exists.
b)
a secure web connection is used.
c)
the source of the executable is certain.
d)
the host web site is part of the organization.
132.
451. In large corporate networks having supply partners across the globe, network traffic may continue to rise. The infrastructure components in such environments should be scalable. Which of the following firewall architectures limits future scalability?
a)
Appliances
b)
Operating system-based
c)
Host-based
d)
Demilitarized
133.
452. Which of the following types of transmission media provide the BEST security against unauthorized access?
a)
Copper wire
b)
Twisted pair
c)
Fiber-optic cables
d)
Coaxial cables
134.
454. To determine how data are accessed across different platforms in a heterogeneous environment, an IS auditor should FIRST review:
a)
business software.
b)
infrastructure platform tools.
c)
application services.
d)
system development tools.
135.
456. A review of wide area network (WAN) usage discovers that traffic on one communication line between sites, synchronously linking the master and standby database, peaks at 96 percent of the line capacity. The IS auditor should conclude that:
a)
analysis is required to determine if a pattern emerges that results in a service loss for a short period of time.
b)
WAN capacity is adequate for the maximum traffic demands since saturation has not been reached.
c)
the line should immediately be replaced by one with a larger capacity to provide approximately 85 percent saturation.
d)
users should be instructed to reduce their traffic demands or distribute them across all service hours to flatten bandwidth consumption.
136.
459. The BEST way to minimize the risk of communication failures in an e-commerce environment would be to use:
a)
compression software to minimize transmission duration.
b)
functional or message acknowledgments.
c)
a packet-filtering firewall to reroute messages.
d)
leased asynchronous transfer mode lines.
137.
464. An IS auditor analyzing the audit log of a database management system (DBMS) finds that some transactions were partially executed as a result of an error, and are not rolled back. Which of the following transaction processing features has been violated?
a)
Consistency
b)
Isolation
c)
Durability
d)
Atomicity
138.
467. Which of the following BEST limits the impact of server failures in a distributed environment?
a)
Redundant pathways
b)
Clustering
c)
Dial backup lines
d)
Standby power
139.
469. Accountability for the maintenance of appropriate security measures over information assets resides with the:
a)
security administrator.
b)
systems administrator.
c)
data and systems owners.
d)
systems operations group.
140.
477. A callback system requires that a user with an id and password call a remote server through a dial-up line, then the server disconnects and:
a)
dials back to the user machine based on the user id and password and using a telephone number from its database.
b)
dials back to the user machine based on the user id and password and using a telephone number provided by the user during the original connection.
c)
waits for a redialfrom the user machine for confirmation and then verifies the user id and password using its database.
d)
waits for a redial from the user machine for confirmation and then verifies the user id and password using the sender's database.
141.
478. The MOST effective method of preventing unauthorized use of data files is:
a)
automated file entry.
b)
tape librarian.
c)
access control software.
d)
locked library.
142.
483. When reviewing an organization's logical access security, which of the following should be of MOST concern to an IS auditor?
a)
Passwords are not shared.
b)
Password files are not encrypted.
c)
Redundant logon IDs are deleted.
d)
The allocation of logon IDs is controlled.
143.
485. When performing an audit of access rights, an IS auditor should be suspicious of which of the following if allocated to a computer operator?
a)
Read access to data
b)
Delete access to transaction data files
c)
Logged read/execute access to programs
d)
Update access to job control language/script files
144.
486. To prevent unauthorized entry to the data maintained in a dial-up, fast response system, an IS auditor should recommend:
a)
online terminals be placed in restricted areas.
b)
online terminals be equipped with key locks.
c)
ID cards be required to gain access to online terminals.
d)
online access be terminated after a specified number of unsuccessful attempts.
145.
494. A MAJOR risk of using single sign-on (SSO) is that it:
a)
has a single authentication point.
b)
represents a single point of failure.
c)
causes an administrative bottleneck.
d)
leads to a lockout of valid users.
146.
495. With the help of the security officer, granting access to data is the responsibility of:
a)
data owners.
b)
programmers.
c)
system analysts.
d)
librarians.
147.
497. During the review of a biometrics system operation, the IS auditor should FIRST review the stage of:
a)
enrollment.
b)
identification.
c)
verification.
d)
storage.
148.
499. A hacker could obtain passwords without the use of computer tools or programs through the technique of:
a)
social engineering.
b)
sniffers.
c)
back doors.
d)
Trojan horses.
149.
504. Which of the following is an example of the defense in-depth security principle?
a)
Using two firewalls of different vendors to consecutively check the incoming network traffic
b)
Using a firewall as well as logical access controls on the hosts to control incoming network traffic
c)
Having no physical signs on the outside of a computer center building
d)
Using two firewalls in parallel to check different types of incoming traffic
150.
516. The MOST important key success factor in planning a penetration test is:
a)
the documentation of the planned testing procedure.
b)
scheduling and deciding on the timed length of the test.
c)
the involvement of the management of the client organization.
d)
the qualifications and experience of staff involved in the test.
151.
520. A certificate authority (CA) can delegate the processes of:
a)
revocation and suspension of a subscriber's certificate.
b)
generation and distribution of the CA public key.
c)
establishing a link between the requesting entity and its public key.
d)
issuing and distributing subscriber certificates.
152.
522. Which of the following is an advantage of elliptic curve encryption over RSA encryption?
a)
Computation speed
b)
Ability to support digital signatures
c)
Simpler key distribution
d)
Greater strength for a given key length
153.
525. To ensure message integrity, confidentiality and nonrepudiation between two parties, the MOST effective method would be to create a message digest by applying a cryptographic hashing algorithm against:
a)
the entire message, enciphering the message digest using the sender's private key, enciphering the message with a symmetric key and enciphering the key by using the receiver's public key.
b)
any part of the message, enciphering the message digest using the sender's private key, enciphering the message with a symmetric key and enciphering the key using the receiver's public key.
c)
the entire message, enciphering the message digest using the sender's private key, enciphering the message with a symmetric key and enciphering the symetric key using the receiver's public key.
d)
the entire message, enciphering the message digest using the sender's private key and enciphering the message using the receiver's public key.
154.
527. Which of the following would be of MOST concern to an IS auditor reviewing a VPN implementation? Computers on the network that are located:
a)
on the enterprise's facilities.
b)
at the backup site.
c)
in employees' homes.
d)
at the enterprise's remote offices.
155.
528. The PRIMARY reason for using digital signatures is to ensure data:
a)
confidentiality.
b)
integrity.
c)
availability.
d)
timeliness.
156.
539. When a PC that has been used for the storage of confidential data is sold on the open market, the:
a)
hard disk should be demagnetized.
b)
hard disk should be mid-level formatted.
c)
data on the hard disk should be deleted.
d)
data on the hard disk should be defragmented.
157.
541. A digital signature contains a message digest to:
a)
show if the message has been altered after transmission.
b)
define the encryption algorithm.
c)
confirm the identity of the originator.
d)
enable message transmission in a digital format.
158.
542. Which of the following manages the digital certificate life cycle to ensure adequate security and controls exist in digital signature applications related to e-commerce?
a)
Registration authority
b)
Certificate authority (CA)
c)
Certification relocation list
d)
Certification practice statement
159.
548. An IS auditor doing penetration testing during an audit of Internet connections would:
a)
evaluate configurations.
b)
examine security settings.
c)
ensure virus-scanning software is in use.
d)
use tools and techniques that are available to a hacker.
160.
549. Which of the following should concern an IS auditor when reviewing security in a client-server environment?
a)
Protecting data using an encryption technique
b)
Preventing unauthorized access using a diskless workstation
c)
The ability of users to access and modify the database directly
d)
Disabling floppy drives on the users' machines
161.
552. Which of the following controls would BEST detect intrusion?
a)
User ids and user privileges are granted through authorized procedures.
b)
Automatic logoff is used when a workstation is inactive for a particular period of time.
c)
Automatic logoff of the system after a specified number of unsuccessful attempts.
d)
Unsuccessful logon attempts are monitored by the security administrator.
162.
553. Which of the following is the MOST important objective of data protection?
a)
Identifying persons who need access to information
b)
Ensuring the integrity of information
c)
Denying or authorizing access to the IS system
d)
Monitoring logical accesses
163.
562. Which of the following controls would be the MOST comprehensive in a remote access network with multiple and diverse subsystems?
a)
Proxy server
b)
Firewall installation
c)
Network administrator
d)
Password implementation and administration
164.
565. Which of the following encrypt/decrypt steps provides the GREATEST assurance of achieving confidentiality, message integrity and nonrepudiation by either sender or recipient?
a)
The recipient uses his/her private key to decrypt the secret key.
b)
The encrypted prehash code and the message are encrypted using a secret key.
c)
The encrypted prehash code is derived mathematically from the message to be sent.
d)
The recipient uses the sender's public key, verified with a certificate authority, to decrypt the prehash code.
165.
567. E-mail message authenticity and confidentiality is BEST achieved by signing the message using the:
a)
sender's private key and encrypting the message using the receiver's public key.
b)
sender's public key and encrypting the message using the receiver's private key.
c)
receiver's private key and encrypting the message using the sender's public key.
d)
receiver's public key and encrypting the message using the sender's private key.
166.
569. Which of the following is the MOST secure and economical method for connecting a private network over the Internet in a small- to medium-sized organization?
a)
Virtual private network
b)
Dedicated line
c)
Leased line
d)
Integrated services digital network
167.
578. Which of the following is a concern when data are transmitted through Secure Sockets Layer (SSL) encryption, implemented on a trading partner's server?
a)
The organization does not have control over encryption.
b)
Messages are subjected to wire tapping.
c)
Data might not reach the intended recipient.
d)
The communication may not be secure.
168.
585. Which of the following provides nonrepudiation services for e-commerce transactions?
a)
Public key infrastructure (PKI)
b)
Data Encryption Standard (DES)
c)
Message authentication code (MAC)
d)
Personal identification number (PIN)
169.
599. Which of the following cryptographic systems is MOST appropriate for bulk data encryption and small devices such as smart cards?
a)
DES
b)
AES
c)
Triple DES
d)
RSA
170.
600. Disabling which of the following would make wireless local area networks more secure against unauthorized access?
a)
MAC (Media Access Control) address filtering
b)
WPA (Wi-Fi Protected Access Protocol)
c)
LEAP (Lightweight Extensible Authentication Protocol)
d)
SSID (service set identifier) broadcasting
171.
602. Which of the following is the MOST important action in recovering from a cyberattack?
a)
Creation of an incident response team
b)
Use of cyberforensic investigators
c)
Execution of a business continuity plan
d)
Filing an insurance claim
172.
609. A dry-pipe fire extinguisher system is a system that uses:
a)
water, but in which water does not enter the pipes until a fire has been detected.
b)
water, but in which the pipes are coated with special water-tight sealants.
c)
carbon dioxide instead of water.
d)
halon instead of water.
173.
612. An organization with extremely high security requirements is evaluating the effectiveness of biometric systems. Which of the following performance indicators is MOST important?
a)
False-acceptance rate (FAR)
b)
Equal-error rate (EER)
c)
False-rejection rate (FRR)
d)
False-identification rate (FIR)
174.
614. The BEST overall quantitative measure of the performance of biometric control devices is:
a)
false-rejection rate.
b)
false-acceptance rate.
c)
equal-error rate.
d)
estimated-error rate.
175.
617. Confidentiality of the data transmitted in a wireless LAN is BEST protected, if the session is:
a)
restricted to predefined MAC addresses.
b)
encrypted using static keys.
c)
encrypted using dynamic keys.
d)
initiated from devices that have encrypted storage.
176.
622. Validated digital signatures in an e-mail software application will:
a)
help detect spam.
b)
provide confidentiality.
c)
add to the workload of gateway servers.
d)
significantly reduce available bandwidth.
177.
626. Which of the following encryption techniques will BEST protect a wireless network from a man-in-the-middle attack?
a)
128-bit wired equivalent privacy (WEP)
b)
MAC-based pre-shared key (PSK)
c)
Randomly generated pre-shared key (PSK)
d)
Alphanumeric service set identifier (SSID)
178.
630. The use of residual biometric information to gain unauthorized access is an example of which of the following attacks?
a)
Replay
b)
Brute-force
c)
Cryptographic
d)
Mimic
179.
637. Which of the following BEST restricts users to those functions needed to perform their duties?
a)
Application level access control
b)
Data encryption
c)
Disabling floppy disk drives
d)
Network monitoring device
180.
640. An organization has a mix of access points that cannot be upgraded to stronger security and newer access points having advanced wireless security. The IS auditor recommends replacing the nonupgradeable access points. Which of the following would BEST justify the IS auditor's recommendation?
a)
The new access points with stronger security are affordable.
b)
The old access points are poorer in terms of performance.
c)
The organization's security would be as strong as its weakest points.
d)
The new access points are easier to manage.
181.
648. The PRIMARY purpose of implementing Redundent Array of Inexpensive Disks (RAID) level 1 in a file server is to:
a)
achieve performance improvement.
b)
provide user authentication.
c)
ensure availability of data.
d)
ensure the confidentiality of data.
182.
651. In addition to the backup considerations for all systems, which of the following is an important consideration in providing backup for online systems?
a)
Maintaining system software parameters
b)
Ensuring periodic dumps of transaction logs
c)
Ensuring grandfather-father-son file backups
d)
Maintaining important data at an offsite location
183.
659. When developing a backup strategy, the FIRST step is to:
a)
identify the data.
b)
select the storage location.
c)
specify the storage media.
d)
define the retention period.
184.
668. After implementation of a disaster recovery plan (DRP), predisaster and post-disaster operational cost for an organization will:
a)
decrease.
b)
not change (remain the same).
c)
increase.
d)
increase or decrease depending upon the nature of the business.
185.
675. This questions refers to the following information. An IS auditor conducting a review of disaster recovery planning at a financial processing organization has discovered the following:
a)
the deputy CEO be censured for his/her failure to approve the plan.
b)
a board of senior managers is set up to review the existing plan.
c)
the existing plan is approved and circulated to all key management and staff.
d)
a manager coordinates the creation of a new or revised plan within a defined time limit.
186.
679. A large chain of shops with electronic funds transfer (EFT) at point-of-sale devices has a central communications processor for connecting to the banking network. Which of the following is the BEST disaster recovery plan for the communications processor?
a)
Offsite storage of daily backups
b)
Alternative standby processor onsite
c)
Installation of duplex communication links
d)
Alternative standby processor at another network node
187.
680. Facilitating telecommunications continuity by providing redundant combinations of local carrier T-1 lines, microwaves and/or coaxial cables to access the local communication loop is:
a)
last-mile circuit protection.
b)
long-haul network diversity.
c)
diverse routing.
d)
alternative routing.
188.
685. Which of the following is MOST important to provide for in a disaster recovery plan?
a)
Backup of compiled object programs
b)
Reciprocal processing agreement
c)
Phone contact list
d)
Supply of special forms
189.
687. While reviewing the business continuity plan of an organization, the IS auditor observed that the organization's data and software files are backed up on a periodic basis. Which characteristic of an effective plan does this demonstrate?
a)
Deterrence
b)
Mitigation
c)
Recovery
d)
Response
190.
694. The cost of ongoing operations when a disaster recovery plan (DRP) is in place, compared to not having a DRP, will MOST likely:
a)
increase.
b)
decrease.
c)
remain the same.
d)
be unpredictable.
191.
695. Which of the following tasks should be performed FIRST when preparing a disaster recovery plan?
a)
Develop a recovery strategy.
b)
Perform a business impact analysis.
c)
Map software systems, hardware and network components.
d)
Appoint recovery teams with defined personnel, roles and hierarchy.
192.
698. After completing the business impact analysis (BIA) which of the following is the next step in the business continuity planning process?
a)
Test and maintain the plan.
b)
Develop a specific plan.
c)
Develop recovery strategies.
d)
Implement the plan.
193.
699. Which of the following is an appropriate test method to apply to a business continuity plan (BCP)?
a)
Pilot
b)
Paper
c)
Unit
d)
System
194.
705. To develop a successful business continuity plan, end-user involvement is critical during which of the following phases?
a)
Business recovery strategy
b)
Detailed plan development
c)
Business impact analysis (BIA)
d)
Testing and maintenance
195.
706. Which of the following processes is the FIRST step in developing a business continuity and disaster recovery plan for an organization?
a)
Alternate site selection
b)
Business impact analysis
c)
Test procedures and frequency
d)
Information classification
196.
712. Which of the following is the BEST method for determining the criticality of each application system in the production environment?
a)
Interview the application programmers.
b)
Perform a gap analysis.
c)
Review the most recent application audits.
d)
Perform a business impact analysis.
197.
713. Depending on the complexity of an organization's business continuity plan (BCP), the plan may be developed as a set of more than one plan to address various aspects of business continuity and disaster recovery. In such an environment, it is essential that:
a)
each plan be consistent with one another.
b)
all plans are integrated into a single plan.
c)
each plan is dependent on one another.
d)
the sequence for implementation of all plans is defined.
198.
716. During a business continuity audit the IS auditor found that the business continuity plan (BCP) covered only critical processes. The IS auditor should:
a)
recommend that the BCP cover all business processes.
b)
assess the impact of the processes not covered.
c)
report the findings to the IT manager.
d)
redefine critical processes.
199.
718. When auditing a disaster recovery plan (DRP) for a critical business area, the IS auditor finds that it does not cover all the systems. Which of the following is MOST appropriate action for the IS auditor?
a)
Alert management and evaluate the impact of not covering all systems.
b)
Cancel the audit.
c)
Complete the audit of the systems covered by the existing DRP.
d)
Postpone the audit until the systems are added to the DRP.
200.
721. An organization currently using tape backups takes one weekly full backup and daily incremental backups. They recently augmented their tape backup procedures with a backup-to-disk solution. This is appropriate because:
a)
fast synthetic backups for offsite storage are supported.
b)
backup to disk is always significantly faster than backup to tape.
c)
tape libraries are no longer needed.
d)
data storage on disks is more reliable than on tapes.
100 %
