1.
Which of the following would prevent accountability for an action performed, thus allowing nonrepudiation?
2.
Which of the following is the MOST critical step in planning an audit?
3.
To properly evaluate the collective effect of preventative, detective, or corrective controls within a process, an IS auditor should be aware of which of the following?
4.
What is the recommended initial step for an IS auditor to implement continuous-monitoring systems?
5.
What type of risk is associated with authorized program exits (trap doors)?
6.
Which of the following is best suited for searching for address field duplications?
7.
Which of the following is of greatest concern to the IS auditor?
8.
An integrated test facility is not considered a useful audit tool because it cannot compare processing output with independently calculated data. True or false?
9.
An advantage of a continuous audit approach is that it can improve system security when used in time-sharing environments that process a large number of transactions. True or false?
10.
If an IS auditor finds evidence of risk involved in not implementing proper segregation of duties, such as having the security administrator perform an operations function, what is the auditor's primary responsibility?