During audit framework. an IS auditor teams that employees are allowed to connect their personal devices to company-owned computers. How can the auditor BEST validate that appropriate security controls are in place to prevent data loss?
Correct Answer: B
The best way to validate that appropriate security controls are in place to prevent data loss is to review compliance with data loss and applicable mobile device user acceptance policies. This will ensure that the organization has established clear rules and guidelines for employees to follow when connecting their personal devices to company-owned computers. A walk-through, a DLP tool configuration, and a security awareness training are not sufficient to validate the effectiveness of the controls, as they may not cover all possible scenarios and risks. References: IT Audit Fundamentals Certificate Resources
CISA Exam Question 212
Which of the following would be an auditor's GREATEST concern when reviewing data inputs from spreadsheets into the core finance system?
Correct Answer: A
The auditor's greatest concern when reviewing data inputs from spreadsheets into the core finance system would be undocumented code that formats data and transmits directly to the database. This is because undocumented code can introduce errors, inconsistencies, and security risks in the data processing and reporting. Undocumented code can also make it difficult to verify the accuracy, completeness, and validity of the data inputs and outputs, as well as to trace the source and destination of the data. Undocumented code can also violate the principles of segregation of duties, as the same person who creates the code may also have access to the data and the database. The other options are not as concerning as undocumented code, although they may also pose some risks. A lack of complete inventory of spreadsheets and inconsistent file naming may make it challenging to identify and locate the relevant spreadsheets, but they do not directly affect the quality or integrity of the data inputs. The department data protection policy not being reviewed or updated for two years may indicate a lack of awareness or compliance with the current data protection regulations, but it does not necessarily imply that the data inputs are compromised or inaccurate. Spreadsheets being accessible by all members of the finance department may increase the risk of unauthorized or accidental changes to the data, but it can be mitigated by implementing access controls, password protection, and audit trails. References: ISACA, CISA Review Manual, 27th Edition, 2019, p. 2261 Five Common Spreadsheet Risks and Ways to Control Them2 GREATEST Concerns When Reviewing Data Inputs from Spreadsheets3
CISA Exam Question 213
An IS auditor is assigned to perform a post-implementation review of an application system. Which of the following would impair the auditor's independence?
Correct Answer: A
The auditor implemented a specific control during the development of the system. This would impair the auditor's independence, as it would create a self-review threat, which is a situation where an auditor has to evaluate or review the results of his or her own work or judgment1. A self-review threat may compromise the auditor's objectivity and impartiality, as the auditor may be biased or influenced by his or her own involvement or interest in the system1. The auditor may also face a conflict of interest or a loss of credibility if he or she has to report on any issues or deficiencies related to the control he or she implemented.
CISA Exam Question 214
Which of the following is a threat to IS auditor independence?
Correct Answer: C
CISA Exam Question 215
An organization has replaced all of the storage devices at its primary data center with new higher-capacity units The replaced devices have been installed at the disaster recovery site to replace older units An IS auditor s PRIMARY concern would be whether
Correct Answer: A
An IS auditor's primary concern would be whether the recovery site devices can handle the storage requirements. The storage requirements are determined by the amount and type of data that needs to be backed up and restored in case of a disaster at the primary data center. The recovery site devices should have enough capacity, performance, reliability, and compatibility to meet these requirements. If the recovery site devices cannot handle the storage requirements, then there is a risk that some data may not be backed up properly or may not be available for recovery when needed. This could result in data loss, corruption, or inconsistency, which could affect the business continuity and integrity of the organization. Therefore, an IS auditor should verify that: * The recovery site devices have sufficient storage space to accommodate all the data that needs to be backed up from the primary data center. * The recovery site devices have adequate bandwidth and speed to transfer and access data efficiently and effectively. * The recovery site devices have appropriate security features and controls to protect data from unauthorized access or modification. * The recovery site devices are compatible with the primary data center devices in terms of hardware, software, format, and protocol. References: * 10: What Is a Disaster Recovery Site? Hot, Cold & Warm Site * 11: Disaster recovery site - What is the ideal distance to mitigate risks? - Advisera * 12: Offsite Data Backup Storage vs Disaster Recovery (DR) - LINBIT