01. An IS auditor finds a small number of user access requests that had not been authorized by managers through the normal predefined workflow steps and escalation rules. The IS auditor should:
a) recommend that the owner of the identity management (IDM) system fix the workflow issues.
b) report the problem to the audit committee.
c) conduct a security risk assessment.
d) perform an additional analysis.
02. When seeking an earlier project completion time to be obtained by paying a premium for early completion, the activities that should be selected are those:
a) that have zero slack time.
b) whose sum of slack time is the shortest.
c) that give the longest possible completion time.
d) whose sum of activity time is the shortest.
03. An IS auditor is assigned to audit a software development project that is more than 80 percent complete but has already overrun its schedule by 10 percent and its costs by 25 percent. Which of the following actions should the IS auditor take?
a) Report that the organization does not have effective project management.
b) Review the conduct of the project and the business case.
c) Review the IT governance structure.
d) Recommend the project manager be changed.
04. Which of the following would BEST ensure continuity of a wide area network (WAN) across the organization?
a) Complete full system backup daily
b) A duplicate machine alongside each server.
c) Built-in alternative routing
d) A repair contract with a service provider
05. An enterprise's risk appetite is BEST established by:
a) the audit committee.
b) the chief legal officer.
c) security management.
d) the steering committee.
06. The concept behind process optimization is the ability to apply a systematic technique that reduces all but which of the following?
a) Organizational disputes
b) Complexity
c) Variances and inconsistencies
d) Risks to the process operations
07. A programmer maliciously modified a production program to change data and then restored the original code. Which of the following would MOST effectively detect the malicious activity?
a) Comparing object code
b) Comparing source code
c) Reviewing system log files
d) Reviewing executable and source code integrity
08. An IS auditor observes that an enterprise has outsourced software development to a third party that is a startup company. To ensure that the enterprise's investment in the software is protected, which of the following should the IS auditor recommend?
a) A source code escrow agreement should be in place.
b) A quarterly audit of the vendor facilities should be performed.
c) A high penalty clause should be included in the contract.
d) Due diligence should be performed on the software vendor.
09. An audit charter should:
a) clearly state audit objectives for, and the delegation of, authority to the maintenance and review of internal controls.
b) outline the overall authority, scope and responsibilities of the audit function.
c) be dynamic and change to coincide with the changing nature of technology and the audit profession.
d) document the audit procedures designed to achieve the planned audit objectives.
10. When the audit process starts, the auditor should become familiar with the roles and responsibilities of individuals in the company by doing which of the following?
a) Reviewing the IT strategic plan
b) Studying the company’s annual report
c) Analyzing the organizational charts
d) Observing individuals