Which of the following is a social engineering attack method?
A. An employee is induced to reveal confidential IP addresses and passwords by answering questions over the phone.Which of the following findings should be an IS auditor's GREATEST concern when reviewing an organization's purchase of new IT infrastructure hardware?
A. The new infrastructure arrived with default system settings.Which of the following BEST ensures that effective change management is in place in an IS environment?
A. User authorization procedures for application access are well established.Which of the following risk scenarios is BEST mitigated through the use of a data loss prevention (DLP) tool?
A. An employee is sending company documents to an external email to increase productivity.Which type of attack targets security vulnerabilities in web applications to gain access to data sets?
A. Denial of service (DOS)Which of the following is the MOST effective way to ensure adequate system resources are available for high-priority activities?
A. System virtualizationIT management has accepted the risk associated with an IS auditor's finding due to the cost and complexity of the corrective actions. Which of the following should be the auditor's NEXT course of action?
A. Perform a cost-benefit analysis.In which of the following system development life cycle (SDLC) phases would an IS auditor expect to find that controls have been incorporated into system specifications?
A. ImplementationWhich of the following would an IS auditor find to be the GREATEST risk associated with the server room in a remote office location?
A. The server room is secured by a key lock instead of an electronic lock.A post-implementation review of a development project concludes that several business requirements were not reflected in the software requirement specifications. Which of the following should an IS auditor recommend to reduce this problem in the future?
A. Appoint a business unit representative.Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Isaca exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CISA exam preparations and Isaca certification application, do not hesitate to visit our Vcedump.com to find your solutions here.