Test 1 Flashcards
In which of the following WAN message transmission technique does two network nodes establish a dedicated communications channel through the network before the nodes may communicate
Circuit switching
Which of the following type of network service stores information about the various resources in a central database on a network and help network devices locate services?
Directory Services
A computer network used for communication among the personal devices themselves (intrapersonal communication).
PAN
A computer network in which two or more computers or communicating devices or networks which are geographically separated but in same metropolitan city
MAN
Would be best suited to oversee the development of an information security policy?
Security Officers
What protocol uses serial interface for communication between two computers in WAN technology?
Point to point
Which cloud deployment model can be shared by several organizations?
Community cloud
Who is responsible for providing technical support for the hardware and software environment by developing. installing and operating the requested system?
System development management
In a Data Warehouse, which layer from an enterprise data flow architecture captures all data of interest to an organization and organize it to assist in reporting and analysis?
Core Data Warehouse
A PRIMARY advantage of control self-assessment (CSA) techniques is that:
It ascertains high-risk areas that might need a detailed review later
Main objective of a control self-assessment (CSA) program is to:
enhance audit responsibilities
Evidence gathering to evaluate the integrity of individual transactions, data or other information is which type of testing?
Substantive testing
An IS auditor is using a statistical sample to inventory the tape library. What type of test would this be considered?
Substantive
Using a statistical sample to inventory the tape library is what kind of test?
Substantive test
Statistical sampling reduces which risk: Detection, Inherent, Control, Audit
Detection risk
Using a statistical sample to inventory the tape library
Substantive test
With regard to confidence correlation, it can be said that if an auditor knows internal controls are strong,
the confidence coefficient may be lowered
Statistical sampling reduces which of the following risk:
detection risk
An IS auditor is using a statistical sample to inventory the tape library. What type of test would this be considered
Substantive
Primary purpose of an audit charter is to:
to prescribe authority and responsibilities of audit department.
In an audit of an inventory application, which approach would provide the BEST evidence that purchase orders are valid?
Testing whether inappropriate personnel can change application parameters.
IS auditor discovered numerous customer name duplications arising from variations in customer first names. To determine the extent of the duplication, the IS auditor would use:
generalized audit software to search for address field duplications.
In an IS audit of several critical servers, the IS auditor wants to analyze audit trails to discover potential anomalies in user or system behavior. Which of the following tools is MOST suitable for performing that task?
Trend/variance detection tools
When developing a risk-based audit strategy, an IS auditor should conduct a risk assessment to ensure that:
vulnerabilities and threats are identified.
An IS auditor has identified threats and potential impacts. Next, an IS auditor should:
identify and evaluate the existing controls.
Outline the overall authority, scope and responsibilities of the audit function.
Audit Charter
While planning an audit, an assessment of risk should be made to provide:
reasonable assurance that the audit will cover material items.
An integrated test facility is considered a useful audit tool because it:
compares processing output with independently calculated data.
The decisions and actions of an IS auditor are MOST likely to affect which of the following risks?
Detection
When evaluating the collective effect of preventive, detective or corrective controls within a process, an IS auditor should be aware:
of the point at which controls are exercised as data flow through the system.
The PRIMARY purpose of an audit charter is to:
Describe the authority and responsibilities of the audit department.
Which one of the following could an IS auditor use to validate the effectiveness of edit and validation routines?
Referential integrity test