CISA Exam Question 516

Following a security breach in which a hacker exploited a well-known vulnerability in the domain controller, an IS audit has been asked to conduct a control assessment. the auditor's BEST course of action would be to determine if:
  • CISA Exam Question 517

    Which of the following should an IS auditor be MOST concerned with during a post-implementation review?
  • CISA Exam Question 518

    An organization saves confidential information in a file with password protection and the file is placed in a shared folder. An attacker has stolen this information by obtaining the password through social engineering.
    Implementing which of the following would BEST enable the organization to prevent this type of incident in the future?
  • CISA Exam Question 519

    What is the PRIMARY purpose of documenting audit objectives when preparing for an engagement?
  • CISA Exam Question 520

    Which of the following would BEST manage the risk of changes in requirements after the analysis phase of a business application development project?