Free Certified Information Systems Auditor Questions and Answers — Questions and Answers
Question 1: An IS auditor notices that a corporation has contracted out software development to a startup company as a third party. Which of the following should the IS auditor advise the firm to implement in order to protect the investment they have made in software?
- A high penalty clause should be included in the contract.
- Due diligence should be performed on the software vendor.
- A quarterly audit of the vendor facilities should be performed.
- There should be a source code escrow agreement in place. (Correct answer)
Correct answer: There should be a source code escrow agreement in place.
A source code escrow agreement is primarily advised to assist safeguard the enterprise's investment in software because the source code will be accessible through a reliable third party and can be retrieved in the event that the start-up vendor goes out of business.
Question 2: A data center's physical security controls are being examined by an IS auditor, who finds various cause for concern. Which one of the following is the MOST crucial?
- There are no security cameras inside the data center.
- The emergency power off button cover is missing.
- The emergency exit door is blocked. (Correct answer)
- Scheduled maintenance of the fire suppression system was not performed.
Correct answer: The emergency exit door is blocked.
The obstruction of the emergency escape is the most significant issue because life safety is always the top priority.
Question 3: The BEST method for determining an enterprise's risk appetite is:
- the steering committee (Correct answer)
- the chief legal officer
- security management
- the audit committee
Correct answer: the steering committee
Due to the fact that the steering committee includes senior management in its membership, it is ideally suited to ascertain the enterprise's risk appetite.
Question 4: The activities that should be chosen for determining an earlier project completion time, which is to be gained by paying a premium for early completion, are those that:
- that have zero slack time (Correct answer)
- whose sum of slack time is the shortest
- whose sum of activity time is the shortest
- that give the longest possible completion time
Correct answer: that have zero slack time
To achieve an earlier project completion time by paying a premium, activities on the critical path should be targeted. These are the activities with zero slack time, meaning any delay in them will directly delay the entire project. Accelerating activities with slack time would not shorten the overall project duration, making them inefficient for 'crashing' a project.
Question 5: An IS auditor is tasked with auditing a software development project that is more than 80% finished but has already gone over budget by 25% and by 10% in terms of time. What should the IS auditor do out of the following?
- Review the IT governance structure.
- Report that the organization does not have effective project management.
- Review the conduct of the project and the business case. (Correct answer)
- Recommend the project manager be changed.
Correct answer: Review the conduct of the project and the business case.
When a project is significantly over budget and behind schedule, the IS auditor's primary role is to investigate the underlying causes. This involves reviewing the project's execution and management practices (conduct) and re-evaluating the original justification and expected benefits (business case). This comprehensive review helps identify root problems and provides actionable insights for corrective measures, rather than just stating a problem or recommending personnel changes without a full understanding.
Question 6: The original code was later restored when a malicious programmer changed a production software to alter data. Which of the following would be able to catch the malicious activity the BEST?
- Comparing object code
- Comparing source code
- Reviewing executable and source code integrity
- Reviewing system log files (Correct answer)
Correct answer: Reviewing system log files
System log files record user activities, system events, and changes made to configurations or data. In the event of a malicious programmer altering production software, these logs would provide an audit trail detailing who accessed the system, when the changes occurred, and potentially what modifications were made. This makes reviewing system log files the most effective method for detecting and investigating unauthorized activity and identifying the malicious actor.
Question 7: Which of the following would BEST guarantee that a wide area network (WAN) is continuously operational throughout the organization?
- Complete full system backup daily
- A duplicate machine alongside each server
- Built-in alternative routing (Correct answer)
- A repair contract with a service provider
Correct answer: Built-in alternative routing
To ensure continuous operation of a Wide Area Network (WAN), redundancy and fault tolerance are crucial. Built-in alternative routing allows network traffic to automatically reroute through different paths or devices if a primary link or component fails. This mechanism minimizes downtime and ensures uninterrupted connectivity across the organization, making it the best guarantee for continuous WAN availability.
An IS auditor notices that a corporation has contracted out software development to a startup company as a third party.
Which of the following should the IS auditor advise the firm to implement in order to protect the investment they have made in software?