Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

Which of the following COSO internal control framework components encompasses establishing structures, reporting lines, authorities, and responsibilities?

A.

Control environment.

B.

Control activities.

C.

Information and communication.

D.

Monitoring.

An organization decided to reorganize into a flatter structure. Which of the following changes would be expected with this new structure?

A.

Lower costs.

B.

Slower decision making at the senior executive level.

C.

Limited creative freedom in lower-level managers.

D.

Senior-level executives more focused on short-term, routine decision making

At what stage of project integration management would a project manager and project management team typically coordinate the various technical and organizational interfaces that exist in the project?

A.

Project plan development.

B.

Project plan execution

C.

Integrated change control.

D.

Project quality planning

An organization has decided to allow its managers to use their own smart phones at work. With this change, which of the following is most important to Include In the IT department ' s comprehensive policies and procedures?

A.

Required documentation of process for discontinuing use of the devices

B.

Required removal of personal pictures and contacts.

C.

Required documentation of expiration of contract with service provider.

D.

Required sign-off on conflict of interest statement.

Which of the following backup methodologies would be most efficient in backing up a database in the production environment?

A.

Disk mirroring of the data being stored on the database.

B.

A differential backup that is performed on a weekly basis.

C.

An array of independent disks used to back up the database.

D.

An incremental backup of the database on a daily basis.

Which of the following is an example of two-factor authentication?

A.

The user ' s facial geometry and voice recognition.

B.

The user ' s password and a separate passphrase.

C.

The user ' s key fob and a smart card.

D.

The user ' s fingerprint and a personal Identification number.

Which of the following storage options would give the organization the best chance of recovering data?

A.

Encrypted physical copies of the data, and their encryption keys are stored together at the organization and are readily available upon request.

B.

Encrypted physical copies of the data are stored separately from their encryption keys, and both are held in secure locations a few hours away from the organization.

C.

Encrypted reports on usage and database structure changes are stored on a cloud-based, secured database that is readily accessible.

D.

Encrypted copies of the data are stored in a separate secure location a few hours away, while the encryption keys are stored at the organization and are readilyavailable.

What is the primary purpose of data and systems backup?

A.

To restore all data and systems immediately after the occurrence of an incident.

B.

To set the maximum allowable downtime to restore systems and data after the occurrence of an incident.

C.

To set the point in time to which systems and data must be recovered after the occurrence of an incident.

D.

To restore data and systems to a previous point in time after the occurrence of an incident

One change control function that is required in client/server environments, but is not required in mainframe environments, is to ensure that:

A.

Program versions are synchronized across the network.

B.

Emergency move procedures are documented and followed.

C.

Appropriate users are involved in program change testing.

D.

Movement from the test library to the production library is controlled.

Which of the following are appropriate functions for an IT steering committee?

    Assess the technical adequacy of standards for systems design and programming.

    Continually monitor the adequacy and accuracy of software and hardware in use.

    Assess the effects of new technology on the organization ' s IT operations.

    Provide broad oversight of implementation, training, and operation of new systems.

A.

1, 2, and 3

B.

1, 2, and 4

C.

1, 3, and 4

D.

2, 3, and 4

According to I1A guidance on IT. which of the following activities regarding information security Is most likely to be the responsibility of line management as opposed to executive management, internal auditors, or the board?

A.

Review and monitor security controls.

B.

Dedicate sufficient security resources.

C.

Provide oversight to the security function.

D.

Assess information control environments.

Which statement is true regarding the development of a risk-based internal audit plan?

A.

It requires a previously conducted assurance engagement on the organization’s risk management maturity

B.

It requires an assessment by the internal audit function of key risks identified within the organization ' s risk management system

C.

It requires that at least 90% of planned engagements address areas critical to the organization ' s strategy

D.

It requires that an organization adheres to a well-recognized risk management framework in order to identify and manage its risks

Which of the following data privacy concerns can be attributed specifically to blockchain technologies?

A.

Cybercriminals mainly resort to blockchain technologies to phish for private data

B.

Since blockchain transactions can be easily tampered with, the risk of private data leakage is high

C.

Data privacy regulations overregulate the usage of private data in blockchain transactions

D.

Immutability of blockchain technologies makes private data erasure a challenge

When executive compensation is based on the organization ' s financial results, which of the following situations is most likely to arise?

A.

The organization reports inappropriate estimates and accruals due to poof accounting controls.

B.

The organization uses an unreliable process forgathering and reporting executive compensation data.

C.

The organization experiences increasing discontent of employees, if executives are eligible for compensation amounts that are deemed unreasonable.

D.

The organization encourages employee behavior that is inconsistent with the interests of relevant stakeholders.

Which of the following is the most appropriate beginning step of a work program for an assurance engagement involving smart devices?

A.

Train all employees on bring-your-own-device (BYOD) policies.

B.

Understand what procedures are in place for locking lost devices

C.

Obtain a list of all smart devices in use

D.

Test encryption of all smart devices