- (Topic 1)
When an organization claims it is secure because it is PCI-DSS certified, what is a good first question to ask towards assessing the effectiveness of their security program?
Correct Answer:C
- (Topic 5)
When dealing with risk, the information security practitioner may choose to:
Correct Answer:C
- (Topic 2)
Which of the following reports should you as an IT auditor use to check on compliance with a service level agreement’s requirement for uptime?
Correct Answer:D
- (Topic 2)
Which of the following tests is an IS auditor performing when a sample of programs is selected to determine if the source and object versions are the same?
Correct Answer:B
- (Topic 1)
Information security policies should be reviewed:
Correct Answer:A
- (Topic 5)
Involvement of senior management is MOST important in the development of:
Correct Answer:C