When reviewing the configuration of network devices, an IS auditor should FIRST identify:
When reviewing the configuration of network devices, an IS auditor should FIRST identify:
Which of the following functions should be performed by the application owners to ensure an adequate segregati
Which of the following functions should be performed by the application owners to ensure an adequate segregation of duties between IS and end users?
Accountability for the maintenance of appropriate security measures over information assets resides with the:
Accountability for the maintenance of appropriate security measures over information assets resides with the:
The GREATEST risk when end users have access to a database at its system level, instead of through the applica
The GREATEST risk when end users have access to a database at its system level, instead of through the application, is that the users can:
To determine who has been given permission to use a particular system resource, an IS auditor should review:
To determine who has been given permission to use a particular system resource, an IS auditor should review:
Which of the following is the MOST effective control when granting temporary access to vendors?
Which of the following is the MOST effective control when granting temporary access to vendors?
During a logical access controls review, an IS auditor observes that user accounts are shared. The GREATEST ri
During a logical access controls review, an IS auditor observes that user accounts are shared. The GREATEST risk resulting from this situation is that:
Which of the following satisfies a two-factor user authentication?
Which of the following satisfies a two-factor user authentication?
What is the MOST effective method of preventing unauthorized use of data files?
What is the MOST effective method of preventing unauthorized use of data files?
Which of the following is the PRIMARY safeguard for securing software and data within an information processin
Which of the following is the PRIMARY safeguard for securing software and data within an information processing facility?