1. Information system auditors identified separation of duties in ERP systems. What is the most effective
way to avoid repetitive configurations?
- A. Implement a role-based model to manage user access
- B. Routinely review access permissions
- C. Rectify separation of duties
- D. Use a standard user access matrix
✔️ A. Implement a role-based model to manage user access
2. When creating a disaster recovery plan, which factor should primarily determine the availability
requirement of a single application?
- A. Data confidentiality handled by the application
- B. The importance of the business processes that the application supports
- C. The total cost of ownership (TCO) associated with the application
- D. Network bandwidth requirements for the application
✔️ B. The importance of the business processes that the application supports
3. What is the initial step to establish a comprehensive data security program?
- A. Consult with senior IT management
- B. Set up monitoring controls
- C. Enact data loss prevention strategies
- D. Conduct an asset inventory
✔️ D. Conduct an asset inventory
4. What is a primary benefit of using object-oriented system development?
, - A. It is effective for data with intricate relationships
- B. It allows partitioning of the system in a client-server architecture
- C. It is simpler to code than procedural languages
- D. It decreases the necessity for system documentation
✔️ A. It is effective for data with intricate relationships
5. Following a theft of portable computers with customer sensitive data, what should the information
systems auditor recommend to prevent future incidents?
- A. Improve physical security measures
- B. Utilize encrypted disk drives
- C. Require dual certifications
- D. Use cable locks
✔️ A. Improve physical security measures
6. During an audit of physical security, a contactless proximity card was provided that allows access to
three floors. Which issue should raise the most concern?
- A. The card did not function during the audit's initial days
- B. Failed access attempts were not investigated
- C. The card mistakenly permits access to restricted areas
- D. No escort was needed during the audit
✔️ C. The card mistakenly permits access to restricted areas
7. A company's procedures necessitate urgent change approvals within 7 days. The auditor notes that
the manager checks compliance by reviewing outstanding urgent changes monthly. What is the biggest
risk in this situation?
- A. Audit risk
- B. Detection risk