NEW
Font size
WorksheetsPower up P3
Total questions: 50
Worksheet time: 1hrs 12mins
An IS auditor is assigned to audit a software development project which is more than 80 percent complete,
but has already overrun time by 10 percent and costs by 25 percent. Which of the following actions should
the IS auditor take?
Report that the organization does not have effective project management
Recommend the project manager be changed
Review the IT governance structure
Review the conduct of the project and the business case
Which of the following is the PRIMARY safeguard for securing software and data within an information
processing facility?
Security awareness
Reading the security policy
Security committee
Logical access controls
Which of the following should an IS auditor review to understand project progress in terms of time, budget
and deliverables for early detection of possible overruns and for projecting estimates at completion
(EACs)?
Function point analysis
Earned value analysis
Cost budget
Program Evaluation and Review Technique
A legacy payroll application is migrated to a new application. Which of the following stakeholders should be
PRIMARILY responsible for reviewing and signing-off on the accuracy and completeness of the data before
going live?
IS auditor
Database administrator
Project manager
Data owner
Which of the following situations would increase the likelihood of fraud?
Application programmers are implementing changes to production programs
Application programmers are implementing changes to test programs
Operations support staff are implementing changes to batch schedules
Database administrators are implementing changes to data structures
The purpose of a checksum on an amount field in an electronic data interchange (EDI) communication of financial transactions is to ensure:
integrity.
authenticity
authorization
nonrepudiation
To reduce the possibility of losing data during processing, the FIRST point at which control totals should be implemented is:
in transit to the computer
between related computer runs
during data preparation
during the return of the data to the user department
Electromagnetic emissions from a terminal represent an exposure because they:
affect noise pollution
disrupt processor functions
produce dangerous levels of electric current
can be detected and displayed
Which of the following is the GREATEST risk when implementing a data warehouse?
A. increased response time on the production systems
B. Access controls that are not adequate to prevent data modification
C. Data duplication
D. Data that is not updated or current
Which of the following is the GREATEST risk to the effectiveness of application system controls?
Removal of manual processing steps
inadequate procedure manuals
Collusion between employees
Unresolved regulatory compliance issues
The FIRST step in data classification is to:
establish ownership
perform a criticality analysis
define access rules
create a data dictionary
An IS auditor is told by IS management that the organization has recently reached the highest level of the
software capability maturity model (CMM). The software quality process MOST recently added by the
organization is:
continuous improvement
quantitative quality goals
a documented process
a process tailored to specific projects
The FIRST step in managing the risk of a cyber attack is to:
assess the vulnerability impact
identify critical information assets
evaluate the likelihood of threats
estimate potential damage
An appropriate control for ensuring the authenticity of orders received in an EDI application is to:
acknowledge receipt of electronic orders with a confirmation message
perform reasonableness checks on quantities ordered before filling orders
verify the identity of senders and determine if orders correspond to contract terms
encrypt electronic orders
After installing a network, an organization installed a vulnerability assessment tool or security scanner to identify possible weaknesses. Which is the MOST serious risk associated with such tools?
Differential reporting
False-negative reporting
False-positive reporting
Less-detail reporting
Which of the following user profiles should be of MOST concern to an IS auditor when performing an audit
of an EFT system?
Three users with the ability to capture and verify their own messages
Five users with the ability to capture and send their own messages
Five users with the ability to verify other users and to send their own messages
Three users with the ability to capture and verify the messages of other users and to send their own
messages
Which of the following is the most important element in the design of a data warehouse?
Speed of the transactions
Volatility of the data
Vulnerability of the system
Quality of the metadata
A business application system accesses a corporate database using a single ID and password embedded
in a program. Which of the following would provide efficient access control over the organization's data?
Introduce a secondary authentication method such as card swipe
Apply role-based permissions within the application system
Have users input the ID and password for each database transaction
Set an expiration period for the database password embedded in the program
Which of the following would MOST effectively enhance the security of a challenge-response based
authentication system?
Selecting a more robust algorithm to generate challenge strings
implementing measures to prevent session hijacking attacks
increasing the frequency of associated password changes
increasing the length of authentication strings
An information security policy stating that 'the display of passwords must be masked or suppressed'
addresses which of the following attack methods?
Piggybacking
Dumpster diving
Shoulder surfing
Impersonation
The PRIMARY objective of performing a post incident review is that it presents an opportunity to:
improve internal control procedures
harden the network to industry best practices
highlight the importance of incident response management to management
improve employee awareness of the incident response process
Time constraints and expanded needs have been found by an IS auditor to be the root causes for recent
violations of corporate data definition standards in a new business intelligence project. Which of the
following is the MOST appropriate suggestion for an auditor to make?
Align the data definition standards after completion of the project
Achieve standards alignment through an increase of resources devoted to the project
Delay the project until compliance with standards can be achieved
Enforce standard compliance by adopting punitive measures against violators
Ideally, stress testing should be carried out in a:
test environment using live workloads
test environment using test data
production environment using live workloads
production environment using test data
After reviewing its business processes, a large organization is deploying a new web application based on a
VoIP technology. Which of the following is the MOST appropriate approach for implementing access
control that will facilitate security management of the VoIP web application?
Fine-grained access control
Role-based access control (RBAC)
Access control lists
Network/service access control
Which of the following should an IS auditor recommend for the protection of specific sensitive information
stored in the data warehouse?
implement column- and row-level permissions
Enhance user authentication via strong passwords
Organize the data warehouse into subject matter-specific databases
Log user access to the data warehouse
Which of the following is the BEST method for preventing the leakage of confidential information in a laptop
computer?
Encrypt the hard disk with the owner's public key
Enable the boot password (hardware-based password).
Use a biometric authentication device
Use two-factor authentication to logon to the notebook
An IS auditor has identified the lack of an authorization process for users of an application. The IS auditor's
main concern should be that:
more than one individual can claim to be a specific user
there is no way to limit the functions assigned to users
user accounts can be shared
users have a need-to-know privilege
Which of the following is an object-oriented technology characteristic that permits an enhanced degree of security over data?
inheritance
Dynamic warehousing
Encapsulation
Polymorphism
Which of the following is a dynamic analysis tool for the purpose of testing software modules?
Desk checking
Black box test
Structured walkthrough
Design and code
The MOST important difference between hashing and encryption is that hashing:
is irreversible.
output is the same length as the original message
is concerned with integrity and security
is the same at the sending and receiving end
Which of the following is an advantage of prototyping
The finished system normally has strong internal
controls.
Prototype systems can provide significant time and cost savings
Change control is often less complicated with prototype systems
it ensures that functions or extras are not added to the intended system
The application systems of an organization using open-source software have no single recognized
developer producing patches. Which of the following would be the MOST secure way of updating opensource
software?
identify and test suitable patches before applying them
Rewrite the patches and apply them
Code review and application of available patches
Develop in-house patches
An advantage of using sanitized live transactions in test data is that:
all transaction types will be included
every error condition is likely to be tested
no special routines are required to assess the results
test transactions are representative of live processing
Which of the following is the MOST effective control when granting temporary access to vendors?
Vendor access corresponds to the service level agreement (SLA).
User accounts are created with expiration dates and are based on services provided
Administrator access is provided for a limited period
User IDs are deleted when the work is completed
When a new system is to be implemented within a short time frame, it is MOST important to:
perform user acceptance testing
ensure that the code has been documented and reviewed
add last-minute enhancements to functionalities
test transactions are representative of live processing
The MOST likely explanation for the use of applets in an Internet application is that:
it is sent over the network from the server
they improve the performance of the web server and network
the server does not run the program and the output is not sent over the network
it is a JAVA program downloaded through the web browser and executed by the web server of the client
machine.
Which of the following systems or tools can recognize that a credit card transaction is more likely to have resulted from a stolen credit card than from the holder of the credit card?
Intrusion detection systems
Data mining techniques
Firewalls
Packet filtering routers
Which of the following system and data conversion strategies provides the GREATEST redundancy?
Direct cutover
Pilot study
Phased approach
Parallel run
During the development of an application, the quality assurance testing and user acceptance testing were combined. The MAJOR concern for an IS auditor reviewing the project is that there will be:
increased maintenance
improper documentation of testing
inadequate functional testing
delays in problem resolution
An IS auditor reviewing a proposed application software acquisition should ensure that the:
products are compatible with the current or planned OS
operating system (OS) being used is compatible with the existing hardware platform
planned OS updates have been scheduled to minimize negative impacts on company needs
OS has the latest versions and updates
The purpose of code signing is to provide assurance that:
the software has not been subsequently modified
the application can safely interface with another signed application
the signer of the application is trusted
the private key of the signer has not been compromised
An organization has recently installed a security patch, which crashed the production server. To minimize the probability of this occurring again, an IS auditor should
apply the patch according to the patch's release notes
thoroughly test the patch before sending it to production
approve the patch after doing a risk assessment
ensure that a good change management process is in place
An organization is implementing a new system to replace a legacy system. Which of the following conversion practices creates the GREATEST risk?
Pilot
Parallel
Direct cutover
Phased
Following best practices, formal plans for implementation of new information systems are developed during the:
development phase
design phase
testing phase
deployment phase
A programmer maliciously modified a production program to change data and then restored the original code. Which of the following would MOST effectively detect the malicious activity?
Comparing source code
Reviewing system log files
Comparing object code
Reviewing executable and source code integrity
Which of the following types of testing would determine whether a new or modified system can operate in its target environment without adversely impacting other existing systems?
Parallel testing
Pilot testing
Interface/ integration testing
Sociability testing
At the end of the testing phase of software development, an IS auditor observes that an intermittent software error has not been corrected. No action has been taken to resolve the error. The IS auditor should
report the error as a finding and leave further exploration to the auditee's discretion.
attempt to resolve the error.
recommend that problem resolution be escalated.
ignore the error
Which type of testing focuses on ensuring that the system can handle a specific number of users accessing it simultaneously?
Load testing
Regression testing
Smoke testing
Unit testing
What is the main risk associated with not having proper access controls in place for a data warehouse?
Data corruption
Data leakage
Data duplication
Data loss
Which of the following is the most effective way to ensure that a security patch does not crash the production server?
Apply the patch according to the patch's release notes
Thoroughly test the patch before sending it to production
Approve the patch after doing a risk assessment
Ensure that a good change management process is in place
