Which of the following is the BEST compensating control when segregation of duties is lacking in a small IS department?
A. Background checks
B. User awareness training
C. Transaction log review
D. Mandatory holidays
Stress testing should ideally be earned out under a:
A. test environment with production workloads.
B. production environment with production workloads.
C. production environment with test data.
D. test environment with test data.
An IS auditor assessing the controls within a newly implemented call center would First
A. gather information from the customers regarding response times and quality of service.
B. review the manual and automated controls in the call center.
C. test the technical infrastructure at the call center.
D. evaluate the operational risk associated with the call center.
Which of the following is the BEST way to identify whether the IT help desk is meeting service level agreements (SLAS)?
A. Review exception reports
B. Review IT staffing schedules.
C. Analyze help desk ticket logs
D. Conduct IT management interviews
Which of the following would be an IS auditor's BEST recommendation to senior management when several IT initiatives are found to be misaligned with the organization's strategy?
A. Modify IT initiatives that do not map to business strategies.
B. Reassess IT initiatives that do not map to business strategies.
C. Define key performance indicators (KPIs) for IT.
D. Reassess the return on investment (ROI) for the IT initiatives.
An IS auditor is reviewing the backup procedures in an organization that has high volumes of data with frequent changes to transactions. Which of the following is the BEST backup scheme to recommend given the need for a shorter restoration time in the event of a disruption?
A. Differential backup
B. Full backup
C. Incremental backup
D. Mirror backup
During which phase of the incident management life cycle should metrics such as "mean time to incident discovery" and "cost of recovery" be reported?
A. Containment, analysis, tracking, and recovery
B. Post-incident assessment
C. Planning and preparation
D. Detection, triage, and investigation
Which of the following software development methods is based on iterative and incremental development, where requirements and solutions evolve through collaboration between self-organizing, cross-functional teams?
A. Agile Development
B. Software prototyping
C. Rapid application development
D. Component based development
Which of the following should be the PRIMARY consideration when developing an IT strategy?
A. IT key performance indicators based on business objectives
B. Alignment with overall business objectives
C. Alignment with the IT investment portfolio
D. Short and long-term plans for the enterprise IT architecture
Which of the following should the IS auditor use to BEST determine whether a project has met its business objectives?
A. Earned-value analysis
B. Completed project plan
C. Issues log with resolutions
D. Benefits realization document