ISACA Exam Questions

Which of the following should be the IS auditor’s next action?

An IS auditor reviewing a database application discovers that the current configuration does not
match the originally designed structure. Which of the following should be the IS auditor’s next
action?

A.
Analyze the need for the structural change.

B.
Recommend restoration to the originally designed structure.

C.
Recommend the implementation of a change control process.

D.
Determine if the modifications were properly approved.

Explanation:

An IS auditor should first determine if the modifications were properly approved. Choices A, B and
C are possible subsequent actions, should the IS auditor find that the structural modification had
not been approved.