wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Power up P3

Total questions: 50

Worksheet time: 1hrs 12mins

Name
Class
Date
1.

An IS auditor is assigned to audit a software development project which is more than 80 percent complete,

but has already overrun time by 10 percent and costs by 25 percent. Which of the following actions should

the IS auditor take?

a)

Report that the organization does not have effective project management

b)

Recommend the project manager be changed

c)

Review the IT governance structure

d)

Review the conduct of the project and the business case

2.

Which of the following is the PRIMARY safeguard for securing software and data within an information

processing facility?

a)

Security awareness

b)

Reading the security policy

c)

Security committee

d)

Logical access controls

3.

Which of the following should an IS auditor review to understand project progress in terms of time, budget

and deliverables for early detection of possible overruns and for projecting estimates at completion

(EACs)?

a)

Function point analysis

b)

Earned value analysis

c)

Cost budget

d)

Program Evaluation and Review Technique

4.

A legacy payroll application is migrated to a new application. Which of the following stakeholders should be

PRIMARILY responsible for reviewing and signing-off on the accuracy and completeness of the data before

going live?

a)

IS auditor

b)

Database administrator

c)

Project manager

d)

Data owner

5.

Which of the following situations would increase the likelihood of fraud?

a)

Application programmers are implementing changes to production programs

b)

Application programmers are implementing changes to test programs

c)

Operations support staff are implementing changes to batch schedules

d)

Database administrators are implementing changes to data structures

6.

The purpose of a checksum on an amount field in an electronic data interchange (EDI) communication of financial transactions is to ensure:

a)

integrity.

b)

authenticity

c)

authorization

d)

nonrepudiation

7.

To reduce the possibility of losing data during processing, the FIRST point at which control totals should be implemented is:

a)

in transit to the computer

b)

between related computer runs

c)

during data preparation

d)

during the return of the data to the user department

8.

Electromagnetic emissions from a terminal represent an exposure because they:

a)

affect noise pollution

b)

disrupt processor functions

c)

produce dangerous levels of electric current

d)

can be detected and displayed

9.

Which of the following is the GREATEST risk when implementing a data warehouse?

a)

A. increased response time on the production systems

b)

B. Access controls that are not adequate to prevent data modification

c)

C. Data duplication

d)

D. Data that is not updated or current

10.

Which of the following is the GREATEST risk to the effectiveness of application system controls?

a)

Removal of manual processing steps

b)

inadequate procedure manuals

c)

Collusion between employees

d)

Unresolved regulatory compliance issues

11.

The FIRST step in data classification is to:

a)

establish ownership

b)

perform a criticality analysis

c)

define access rules

d)

create a data dictionary

12.

An IS auditor is told by IS management that the organization has recently reached the highest level of the

software capability maturity model (CMM). The software quality process MOST recently added by the

organization is:

a)

continuous improvement

b)

quantitative quality goals

c)

a documented process

d)

a process tailored to specific projects

13.

The FIRST step in managing the risk of a cyber attack is to:

a)

assess the vulnerability impact

b)

identify critical information assets

c)

evaluate the likelihood of threats

d)

estimate potential damage

14.

An appropriate control for ensuring the authenticity of orders received in an EDI application is to:

a)

acknowledge receipt of electronic orders with a confirmation message

b)

perform reasonableness checks on quantities ordered before filling orders

c)

verify the identity of senders and determine if orders correspond to contract terms

d)

encrypt electronic orders

15.

After installing a network, an organization installed a vulnerability assessment tool or security scanner to identify possible weaknesses. Which is the MOST serious risk associated with such tools?

a)

Differential reporting

b)

False-negative reporting

c)

False-positive reporting

d)

Less-detail reporting

16.

Which of the following user profiles should be of MOST concern to an IS auditor when performing an audit

of an EFT system?

a)

Three users with the ability to capture and verify their own messages

b)

Five users with the ability to capture and send their own messages

c)

Five users with the ability to verify other users and to send their own messages

d)

Three users with the ability to capture and verify the messages of other users and to send their own

messages

17.

Which of the following is the most important element in the design of a data warehouse?

a)

Speed of the transactions

b)

Volatility of the data

c)

Vulnerability of the system

d)

Quality of the metadata

18.

A business application system accesses a corporate database using a single ID and password embedded

in a program. Which of the following would provide efficient access control over the organization's data?

a)

Introduce a secondary authentication method such as card swipe

b)

Apply role-based permissions within the application system

c)

Have users input the ID and password for each database transaction

d)

Set an expiration period for the database password embedded in the program

19.

Which of the following would MOST effectively enhance the security of a challenge-response based

authentication system?

a)

Selecting a more robust algorithm to generate challenge strings

b)

implementing measures to prevent session hijacking attacks

c)

increasing the frequency of associated password changes

d)

increasing the length of authentication strings

20.

An information security policy stating that 'the display of passwords must be masked or suppressed'

addresses which of the following attack methods?

a)

Piggybacking

b)

Dumpster diving

c)

Shoulder surfing

d)

Impersonation

21.

The PRIMARY objective of performing a post incident review is that it presents an opportunity to:

a)

improve internal control procedures

b)

harden the network to industry best practices

c)

highlight the importance of incident response management to management

d)

improve employee awareness of the incident response process

22.

Time constraints and expanded needs have been found by an IS auditor to be the root causes for recent

violations of corporate data definition standards in a new business intelligence project. Which of the

following is the MOST appropriate suggestion for an auditor to make?

a)

Align the data definition standards after completion of the project

b)

Achieve standards alignment through an increase of resources devoted to the project

c)

Delay the project until compliance with standards can be achieved

d)

Enforce standard compliance by adopting punitive measures against violators

23.

Ideally, stress testing should be carried out in a:

a)

test environment using live workloads

b)

test environment using test data

c)

production environment using live workloads

d)

production environment using test data

24.

After reviewing its business processes, a large organization is deploying a new web application based on a

VoIP technology. Which of the following is the MOST appropriate approach for implementing access

control that will facilitate security management of the VoIP web application?

a)

Fine-grained access control

b)

Role-based access control (RBAC)

c)

Access control lists

d)

Network/service access control

25.

Which of the following should an IS auditor recommend for the protection of specific sensitive information

stored in the data warehouse?

a)

implement column- and row-level permissions

b)

Enhance user authentication via strong passwords

c)

Organize the data warehouse into subject matter-specific databases

d)

Log user access to the data warehouse

26.

Which of the following is the BEST method for preventing the leakage of confidential information in a laptop

computer?

a)

Encrypt the hard disk with the owner's public key

b)

Enable the boot password (hardware-based password).

c)

Use a biometric authentication device

d)

Use two-factor authentication to logon to the notebook

27.

An IS auditor has identified the lack of an authorization process for users of an application. The IS auditor's

main concern should be that:

a)

more than one individual can claim to be a specific user

b)

there is no way to limit the functions assigned to users

c)

user accounts can be shared

d)

users have a need-to-know privilege

28.

Which of the following is an object-oriented technology characteristic that permits an enhanced degree of security over data?

a)

inheritance

b)

Dynamic warehousing

c)

Encapsulation

d)

Polymorphism

29.

Which of the following is a dynamic analysis tool for the purpose of testing software modules?

a)

Desk checking

b)

Black box test

c)

Structured walkthrough

d)

Design and code

30.

The MOST important difference between hashing and encryption is that hashing:

a)

is irreversible.

b)

output is the same length as the original message

c)

is concerned with integrity and security

d)

is the same at the sending and receiving end

31.

Which of the following is an advantage of prototyping

a)

The finished system normally has strong internal

controls.

b)

Prototype systems can provide significant time and cost savings

c)

Change control is often less complicated with prototype systems

d)

it ensures that functions or extras are not added to the intended system

32.

The application systems of an organization using open-source software have no single recognized

developer producing patches. Which of the following would be the MOST secure way of updating opensource

software?

a)

identify and test suitable patches before applying them

b)

Rewrite the patches and apply them

c)

Code review and application of available patches

d)

Develop in-house patches

33.

An advantage of using sanitized live transactions in test data is that:

a)

all transaction types will be included

b)

every error condition is likely to be tested

c)

no special routines are required to assess the results

d)

test transactions are representative of live processing

34.

Which of the following is the MOST effective control when granting temporary access to vendors?

a)

Vendor access corresponds to the service level agreement (SLA).

b)

User accounts are created with expiration dates and are based on services provided

c)

Administrator access is provided for a limited period

d)

User IDs are deleted when the work is completed

35.

When a new system is to be implemented within a short time frame, it is MOST important to:

a)

perform user acceptance testing

b)

ensure that the code has been documented and reviewed

c)

add last-minute enhancements to functionalities

d)

test transactions are representative of live processing

36.

The MOST likely explanation for the use of applets in an Internet application is that:

a)

it is sent over the network from the server

b)

they improve the performance of the web server and network

c)

the server does not run the program and the output is not sent over the network

d)

it is a JAVA program downloaded through the web browser and executed by the web server of the client

machine.

37.

Which of the following systems or tools can recognize that a credit card transaction is more likely to have resulted from a stolen credit card than from the holder of the credit card?

a)

Intrusion detection systems

b)

Data mining techniques

c)

Firewalls

d)

Packet filtering routers

38.

Which of the following system and data conversion strategies provides the GREATEST redundancy?

a)

Direct cutover

b)

Pilot study

c)

Phased approach

d)

Parallel run

39.

During the development of an application, the quality assurance testing and user acceptance testing were combined. The MAJOR concern for an IS auditor reviewing the project is that there will be:

a)

increased maintenance

b)

improper documentation of testing

c)

inadequate functional testing

d)

delays in problem resolution

40.

An IS auditor reviewing a proposed application software acquisition should ensure that the:

a)

products are compatible with the current or planned OS

b)

operating system (OS) being used is compatible with the existing hardware platform

c)

planned OS updates have been scheduled to minimize negative impacts on company needs

d)

OS has the latest versions and updates

41.

The purpose of code signing is to provide assurance that:

a)

the software has not been subsequently modified

b)

the application can safely interface with another signed application

c)

the signer of the application is trusted

d)

the private key of the signer has not been compromised

42.

An organization has recently installed a security patch, which crashed the production server. To minimize the probability of this occurring again, an IS auditor should

a)

apply the patch according to the patch's release notes

b)

thoroughly test the patch before sending it to production

c)

approve the patch after doing a risk assessment

d)

ensure that a good change management process is in place

43.

An organization is implementing a new system to replace a legacy system. Which of the following conversion practices creates the GREATEST risk?

a)

Pilot

b)

Parallel

c)

Direct cutover

d)

Phased

44.

Following best practices, formal plans for implementation of new information systems are developed during the:

a)

development phase

b)

design phase

c)

testing phase

d)

deployment phase

45.

A programmer maliciously modified a production program to change data and then restored the original code. Which of the following would MOST effectively detect the malicious activity?

a)

Comparing source code

b)

Reviewing system log files

c)

Comparing object code

d)

Reviewing executable and source code integrity

46.

Which of the following types of testing would determine whether a new or modified system can operate in its target environment without adversely impacting other existing systems?

a)

Parallel testing

b)

Pilot testing

c)

Interface/ integration testing

d)

Sociability testing

47.

At the end of the testing phase of software development, an IS auditor observes that an intermittent software error has not been corrected. No action has been taken to resolve the error. The IS auditor should

a)

report the error as a finding and leave further exploration to the auditee's discretion.

b)

attempt to resolve the error.

c)

recommend that problem resolution be escalated.

d)

ignore the error

48.

Which type of testing focuses on ensuring that the system can handle a specific number of users accessing it simultaneously?

a)

Load testing

b)

Regression testing

c)

Smoke testing

d)

Unit testing

49.

What is the main risk associated with not having proper access controls in place for a data warehouse?

a)

Data corruption

b)

Data leakage

c)

Data duplication

d)

Data loss

50.

Which of the following is the most effective way to ensure that a security patch does not crash the production server?

a)

Apply the patch according to the patch's release notes

b)

Thoroughly test the patch before sending it to production

c)

Approve the patch after doing a risk assessment

d)

Ensure that a good change management process is in place