An IS auditor is asked to review a large organization's change management process. Which of the following practices presents the GREATEST risk?
A. Emergency code changes are promoted without user acceptance testing.Which of the following is the PRIMARY purpose of a rollback plan for a system change?
A. To ensure steps exist to remove the change if necessaryAn IS auditor concludes that logging and monitoring mechanisms within an organization are ineffective because critical servers are not included within the central log repository. Which of the following audit procedures would have MOST likely identified this exception?
A. Inspecting a sample of alerts generated from the central log repositoryAn IS audit manager was temporarily tasked with supervising a project manager assigned to the organization's payroll application upgrade. Upon returning to the audit department, the audit manager has been asked to perform an audit to validate the implementation of the payroll application. The audit manager is the only one in the audit department with IT project management experience. What is the BEST course of action?
A. Transfer the assignment to a different audit manager despite lack of IT project management experience.When an organization and its IT-hosting service provider are establishing a contract with each other, it is MOST important that the contract includes:
A. each party's security responsibilitiesISO 9126 is a standard to assist in evaluating the quality of a product. Which of the following is defined as a set of attributes that bear on the existence of a set of functions and their specified properties?
A. ReliabilityWhich of the following is critical to the successful establishment of an enterprise IT architecture?
A. A well-defined data migration policyWhen implementing a new risk assessment methodology, which of the following is the MOST important requirement?
A. The methodology must be approved by the chief executive officer.During an exit meeting, an IS auditor highlights that backup cycles are being missed due to operator error and that these exceptions are not being managed. Which of the following is the BEST way to help management understand the associated risk?
A. Explain the impact to disaster recovery.An organization uses public key infrastructure (PKI) to provide email security. Which of the following would be the MOST efficient method to determine whether email messages have been modified in transit?
A. The message is encrypted using a symmetric algorithm.Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Isaca exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CISA exam preparations and Isaca certification application, do not hesitate to visit our Vcedump.com to find your solutions here.