Question 61

An IS auditor is a member of an application development team that is selecting software. Which of the following would impair the auditor's independence?
  • Question 62

    Which of the following would give an auditor the BEST view of design and implementation decisions when an organization uses programmatic automation for Infrastructure as a Service (IaaS) deployments? The visibility of:
  • Question 63

    Network environments and virtual instances shall be designed and configured to restrict and monitor traffic between trusted and untrusted connections. These configurations shall be reviewed at least annually, and supported by a documented justification for use for all allowed services, protocols, ports, and by compensating controls. Which of the following controls BEST matches this control description?
  • Question 64

    As a developer building codes into a container in a DevSecOps environment, which of the following is the appropriate place(s) to perform security tests?
  • Question 65

    APIs and web services require extensive hardening and must assume attacks from authenticated and unauthenticated adversaries.