1. The final acceptance testing of a new application system should be the responsibility of the:
A) IS audit team. B) user group C) IS management D) quality assurance team
2. Which of the following is MOST important when an organization contracts for the long-term use of a custom-developed application?
A) Documented coding standards B) Error correction management C) Contract renewal provisions D) Escrow clause
3. Which should be reviewed FIRST by an IS auditor to ensure that data is being secured appropriately for an application?
A) Data classification B) Data encryption C) Data access D) Data storage
4. Which of the following would a digital signature MOST likely prevent?
A) Corruption B) Unauthorized change C) Repudiation D) Disclosure
5. A computer program used by multiple departments has data quality issues. There is no agreement as to who should be responsible for corrective action. Which of the following is an IS auditor's BEST course of action?
A) Recommend the IT department be assigned data cleansing responsibility. B) Modify the program to automatically cleanse the data and close the issue. C) Assign responsibility to the primary department using the program. D) Note the disagreement and recommend establishing data governance.
1. Right Answer: D Explanation:
2. Right Answer: C Explanation:
3. Right Answer: A Explanation: Data classification is necessary to provide proper access rights to the users. If you do not classify data according to their sensitivity and importance to the business, you cannot apply proper access rules to them. Data owners are responsible for defining access rules. The data classification process starts with the process of establishing ownership of data. This process also helps to prepare data dictionary
4. Right Answer: A Explanation: The main reason of using digital signature is to ensure message integrity.it also helps to ensure authenticity and non-repudiation of the message. A digital signature can never ensure the confidentiality of data
Leave a comment