Question 156

When auditing third-party service providers, an IS auditor should be concerned with which of the following?
  • Question 157

    An IS auditor is providing input to an RFP to acquire a financial application system. Which of the following is MOST important for the auditor to recommend?
  • Question 158

    During a review of an organization's network threat response process, the IS auditor noticed that the majority of alerts were closed without resolution. Management responded that those alerts were unworkable doe to lack of actionable intelligence, and therefore the support team is allowed to dose them. What is the BEST way for the auditor to address this
  • Question 159

    What is the PRIMARY reason for an organization to classify the data stored on its internal networks?
  • Question 160

    Which of the following observations should be of GREATEST concern to an IS auditor reviewing a large organization's virtualization environment?