An organization has recently implemented a Voice-over IP (VoIP) communication system. Which ot the following should be the IS auditor's PRIMARY concern?
A. A single point of failure for both voice and data communications
B. Inability to use virtual private networks (VPNs) for internal traffic
C. Lack of integration of voice and data communications
D. Voice quality degradation due to packet toss
An IS auditor is preparing a plan for audits to be carried out over a specified period. Which of the following activities should the IS auditor perform FIRST?
A. Allocate audit resources.
B. Prioritize risks.
C. Review prior audit reports.
D. Determine the audit universe.
Which of the following is MOST useful when planning to audit an organization's compliance with cybersecurity regulations in foreign countries?
A. Prioritize the audit to focus on the country presenting the greatest amount of operational risk.
B. Follow the cybersecurity regulations of the country with the most stringent requirements.
C. Develop a template that standardizes the reporting of findings from each country's audit team
D. Map the different regulatory requirements to the organization's IT governance framework
When planning a follow-up, the IS auditor is informed by operational management that recent organizational changes have addressed the previously identified risk and implementing the action plan is no longer necessary. What should the auditor do NEXT?
A. Report that the changes make it impractical to determine whether the risks have been addressed.
B. Accept management's assertion and report that the risks have been addressed.
C. Determine whether the changes have introduced new risks that need to be addressed.
D. Review the changes and determine whether the risks have been addressed.
Which of the following is the BEST performance indicator for the effectiveness of an incident management program?
A. Average time between incidents
B. Incident alert meantime
C. Number of incidents reported
D. Incident resolution meantime
When performing a post-implementation review, the adequacy of the data conversion effort would BEST be evaluated by performing a thorough review of the:
A. functional conversion rules
B. go-live conversion results.
C. conversion user acceptance testing (UAT) results.
D. detailed conversion approach templates
An organization is in the process of acquiring a competitor. The information security manager has been asked to report on the security posture of the target acquisition. Which of the following should be the security manager's FIRST course of action?
A. Implement a security dashboard
B. Quantity the potential risk
C. Perform a gap analysis
D. Perform a vulnerability assessment
Which of the following would contribute MOST to employees' understanding of data handling responsibilities?
A. Requiring staff acknowledgement of security policies
B. Labeling documents according to appropriate security classification
C. Implementing a tailored security awareness training program
D. Demonstrating support by senior management of the security program
Which of the following projects would be MOST important to review in an audit of an organization's financial statements?
A. Resource optimization of the enterprise resource planning (ERP) system
B. Security enhancements to the customer relationship database
C. Automation of operational risk management processes
D. Outsourcing of the payroll system to an external service provider
An internal IS auditor recommends that incoming accounts payable payment files be encrypted. Which type of control is the auditor recommending?
A. Corrective
B. Detective
C. Preventive
D. Directive