Domain 2: Governance and Management of IT Part 2B Flashcards

1
Q

Before implementing an IT balanced scorecard, an organization must:

A

define key performance indicators.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

A decision support system is used to help high-level management:

A

make decisions based on data analysis and interactive models.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

During a feasibility study regarding outsourcing IT processing, the relevance for the IS auditor of reviewing the vendor’s business continuity plan is to:

A

evaluate the adequacy of the service levels that the vendor can provide ina contingency.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

During an audit, which of the following situations are MOST concerning for an organization that significantly outsources IS processing to a private network?

A

The contract does not contain a right-to-audit clause for the third party.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

An employee who has access to highly confidential information resigned. Upon departure, which of the following should be done FIRST?

A

Revoke the employee’s access to all systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

An enterprise hosts its data center onsite and has outsourced the management of its key financial applications to a service provider. Which of the following controls BEST ensures that the service provider’s employees adhere to the security policies?

A

An indemnity clause is included in the contract with the service provider.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

An enterprise is looking to obtain cloud hosting services from a cloud vendor with a high level of maturity. Which of the following is MOST important for the auditor to ensure continued alignment with the enterprise’s security requirements?

A

The vendor agrees to provide annual external audit reports in the contract.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

An enterprise selected a vendor to develop and implement a new software system. To ensure that the enterprise’s investment in software is protected, which of the following security clauses is MOST important to include in the master services agreement?

A

Software escrow

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

In a review of the human resources policies and procedures within an organization, an IS auditor is MOST concerned with the absence of a:

A

termination checklist.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

In reviewing the IT short-range (tactical) plan, an IS auditor should determine whether:

A

there is an integration of IT and business personnel within projects.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

An IS auditor is assigned to review IT structures and activities recently outsourced to various providers. Which of the following should the IS auditor determine FIRST?

A

The contractual warranties of the providers support the business needs of the organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

An IS auditor is reviewing a contract management process to determine the financial viability of a software vendor for a critical business application. An IS auditor should determine whether the vendor being considered:

A

can support the organization in the long term.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

An IS auditor observes that an enterprise has outsourced software development to a third party that is a startup company. To ensure that the enterprise’s investment in software is protected, which of the following should be recommended by the IS auditor?

A

There should be a source code escrow agreement in place.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

An IS auditor reviewing an organization that uses cross-training practices should assess the risk of:

A

one person knowing all parts of a system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

An IS auditor reviewing an outsourcing contract of IT facilities expects it to define the:

A

ownership of intellectual property.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

An IS auditor was asked to review a contract for a vendor being considered to provide data center services. Which is the BEST way to determine whether the terms of the contract are adhered to after the contract is signed?

A

Conduct periodic audit reviews of the vendor.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Many organizations require an employee to take a mandatory vacation (holiday) of a week or more to:

A

reduce the opportunity for an employee to commit an improper or illegal act.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

An organization has contracted with a vendor for a turnkey solution for their electronic toll collection system (ETCS). The vendor has provided its proprietary application software as part of the solution. The contract should require that:

A

source code of the ETCS application is placed in escrow.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

An organization has outsourced its help desk activities. An IS auditor’s GREATEST concern when reviewing the contract and associated service level agreement between the organization and vendor should be the provisions for:

A

independent audit reports or full audit access.

20
Q

An organization purchased a third-party application and made significant modifications. While auditing the development process for this critical, customer-facing application, the IS auditor noted that the vendor has been in business for only one year. Which of the following helps to mitigate the risk relating to continued application support?

A

A software escrow agreement

21
Q

Organizations requiring employees to take a mandatory vacation each year PRIMARILY want to ensure:

A

potential irregularities in processing are identified by a temporary replacement.

22
Q

The PRIMARY benefit of an enterprise architecture initiative is to:

A

enable the organization to invest in the most appropriate technology.

23
Q

The PRIMARY control purpose of required vacations or job rotations is to:

A

detect improper or illegal employee acts.

24
Q

Regarding the outsourcing of IT services, which of the following conditions should be of GREATEST concern to an IS auditor?

A

Core activities that provide a differentiated advantage to the organization have been outsourced.

25
Q

To support an organization’s goals, an IT department should have:

A

long- and short- term plans.

26
Q

Value delivery from IT to the business is MOST effectively achieved by:

A

aligning the IT strategy with the enterprise strategy.

27
Q

When an employee is terminated from service, the MOST important action is to:

A

disable the employee’s logical access.

28
Q

When reviewing an organization’s approved software product list, which of the following is the MOST important thing to verify?

A

The risk associated with the use of the products is periodically assessed.

29
Q

Which of the following BEST provides assurance of the integrity of new staff?

A

Background screening

30
Q

Which of the following does an IS auditor consider the MOST relevant to short-term planning for an IT department?

A

Allocating resources

31
Q

Which of the following does an IS auditor FIRST reference when performing an IS audit?

A

Approved policies

32
Q

Which of the following goals do you expect to find in an organization’s strategic plan?

A

Approved suppliers for products offered by the company

33
Q

Which of the following is the BEST reference for an IS auditor to determine a vendor’s ability to meet service level agreement (SLA) requirements for a critical IT security service?

A

Agreed-on key performance metrics

34
Q

Which of the following is the MOST important for an IS auditor to consider when reviewing a service level agreement with an external IT service provider?

A

Uptime guarantee

35
Q

Which of the following is the MOST important for an IS auditor to consider when reviewing a service level agreement with an external IT service provider?

A

Uptime guarantee

36
Q

Which of the following is the MOST important function to be performed by IT management when a service has been outsourced?

A

Monitoring the outsourcing provider’s performance

37
Q

Which of the following is the MOST important IS audit consideration when an organization outsources a customer credit review system to a third-party service provider? The provider:

A

agrees to be subject to

external security reviews.

38
Q

Which of the following is the PRIMARY objective of an IT performance measurement process?

A

Optimize performance

39
Q

Which of the following reasons BEST describes the purpose of a mandatory vacation policy?

A

To identify potential errors or inconsistencies in business processes

40
Q

Which of the following should be of PRIMARY concern to an IS auditor reviewing the management of external IT service providers?

A

Determining if the services were provided as contracted

41
Q

Which of the following situations is addressed by a software escrow agreement?

A

The vendor of custom-written software goes out of business.

42
Q

While conducting an audit of a service provider, an IS auditor observes that the service provider has outsourced a part of the work to another provider. Because the work involves confidential information, the IS auditor’s PRIMARY concern should be that the:

A

requirement for protecting confidentiality of information can be compromised.

43
Q

While conducting an IS audit of a service provider for a government program involving confidential information, an IS auditor noted that the service provider delegated a part of the IS work to another subcontractor. Which of the following provides the MOST assurance that the requirements for protecting confidentiality of information are met?

A

Periodic independent audit of the work delegated to the subcontractor

44
Q

While evaluating software development practices in an organization, an IS auditor notes that the quality assurance (QA) function reports to project management. The MOST important concern for an IS auditor is the:

A

effectiveness of the QA function because it should interact between project management and user management.

45
Q

While reviewing a quality management system, the IS auditor should PRIMARILY focus on collecting evidence to show that:

A

Continuous improvement targets are being monitored.