CISA Exam Question 61

During an external review, an IS auditor observes an inconsistent approach in classifying system criticality within the organization. Which of the following should be recommended as the PRIMARY factor to determine system criticality?
  • CISA Exam Question 62

    An IS auditor wants to inspect recent events in a system to observe failed authentications and password changes. Which of the following is the MOST appropriate method to use for this purpose?
  • CISA Exam Question 63

    An organization's software developers need access to personally identifiable information (Pll) stored in a particular data format. Which of the following is the BEST way to protect this sensitive information while allowing the developers to use it in development and test environments?
  • CISA Exam Question 64

    Which of the following responsibilities of an organization's quality assurance (QA) function should raise concern for an IS auditor?
  • CISA Exam Question 65

    Which of the following is the BEST source of information tor an IS auditor to use when determining whether an organization's information security policy is adequate?