CISA Exam Question 126

An IS auditor learns of a new regulation which imposes penalties based on the number of individuals whose personally identifiable information (PII) is exposed by a security breach. What would be the BEST recommendation to help the organization limit the liability associated with a breach to its customer information database?
  • CISA Exam Question 127

    A vendor requires privileged access to a key business application. Which of the following is the BEST recommendation to reduce the risk of data leakage?
  • CISA Exam Question 128

    Which of the following is MOST important for an IS auditor to verify when reviewing the use of an outsourcer for disposal of storage media?
  • CISA Exam Question 129

    An organization uses an automated continuous integration/continuous deployment (CI/CD) tool to deploy changes to production. Which of the following would be an IS auditor ' s GREATEST concern in this situation?
  • CISA Exam Question 130

    After delivering an audit report, the audit manager discovers that evidence was overlooked during the audit This evidence indicates that a procedural control may have failed and could contradict a conclusion of the audit Which of the following risks is MOST affected by this oversight?