What is the first step in a business process re-engineering project?
Correct Answer: C
Explanation/Reference: Explanation: Defining the scope of areas to be reviewed is the first step in a business process re- engineering project.
Question 767
Which of the following controls is MOST appropriate against brute force attacks at login?
Correct Answer: A
Question 768
While reviewing transactions, an IS auditor discovers inconsistencies in a relational database Which of the following would be the auditor's BEST recommendation?
Correct Answer: B
Question 769
Which of the following is the MOST effective control to mitigate unintentional misuse of authorized access?
Correct Answer: C
The most effective control to mitigate unintentional misuse of authorized access is security awareness training. This is because security awareness training can educate users on the proper use of their access rights, the potential consequences of misuse, and the best practices to protect the confidentiality, integrity, and availability of information systems. Security awareness training can also help users recognize and avoid common threats such as phishing, malware, and social engineering. Annual sign-off of acceptable use policy, regular monitoring of user access logs, and formalized disciplinary action are not the most effective controls to mitigate unintentional misuse of authorized access. These controls may help deter or detect intentional misuse, but they do not address the root cause of unintentional misuse, which is often a lack of knowledge or awareness of security policies and procedures.
Question 770
An IS auditor finds that the process for removing access for terminated employees is not documented What is the MOST significant risk from this observation?
Correct Answer: D
The most significant risk from this observation is that access rights may not be removed in a timely manner. If the process for removing access for terminated employees is not documented, there is no clear guidance or accountability for who, how, when, and what actions should be taken to revoke the access rights of the employees who leave the organization. This could result in delays, inconsistencies, or omissions in removing access rights, which could allow terminated employees to retain unauthorized access to the organization's systems and data. This could compromise the security, confidentiality, integrity, and availability of the information assets. References: * CISA Review Manual (Digital Version) * CISA Questions, Answers & Explanations Database