CISA Exam Question 231

An IS auditor finds that application servers had inconsistent security settings leading to potential vulnerabilities. Which of the following is the BEST recommendation by the IS auditor?
  • CISA Exam Question 232

    The business case for an information system investment should be available for review until the:
  • CISA Exam Question 233

    An IS auditor concludes that logging and monitoring mechanisms within an organization are ineffective because critical servers are not included within the central log repository. Which of the following audit procedures would have MOST likely identified this exception?
  • CISA Exam Question 234

    During the evaluation of controls over a major application development project, the MOST effective use of an IS auditor's time would be to review and evaluate:
  • CISA Exam Question 235

    Which of the following responses to risk associated with separation of duties would incur the LOWEST initial cost?