Question 1

During an audit of identity and access management, an IS auditory finds that the engagement audit plan does not include the testing of controls that regulate access by third parties. Which of the following would be the auditor's BEST course of action?

Answer : C

Question 2

Which of the following approaches provides the BEST assurance and user confidence when an organization migrates data to a more complex enterprise resource planning (ERP) system?

Answer : D

Question 3

When reviewing an organization's information security policies, an IS auditor should verify that the policies have been defined PRIMARILY on the basis of

Answer : A

Question 4

Invoking a business continuity plan (BCP) is demonstrating which type of control?

Answer : C

Question 5

The risk of communication failure in an e-commerce environment is BEST minimized through the use of

Answer : B

