System Audit
25 questions · Fundamental Engineering
In the system design phase, when an audit is performed on the control to reduce the risk of user requirements not being met, which of the following is a point to be checked?
Which of the following is a checkpoint for auditing the control of risks related to information leakage and unauthorized use of documents concerning a system?
Which of the following is the most appropriate description of a system auditor?
Which of the following is the most appropriate description concerning an interview conducted by a system auditor?
Which of the following is an appropriate description concerning a system audit team?
Which of the following is the most appropriate purpose for which a system auditor exchanges opinions with an audited department concerning the draft version of an audit report?
Which of the following is the appropriate activity performed by a system auditor who audits access control?
Which of the following is an appropriate description of a checkpoint during the audit of a control for reducing the risk of system trouble regarding the application of a software patch?
Which of the following is subject to system audits that evaluate and verify internal controls related to IT?
In the system design stage, which of the following is the point to be checked during the audit of control for reducing the risk of non-fulfillment of user requirements?
When IT controls are classified into preventive controls and detective controls, which of the following is to be classified as a detective control?
Which of the following is the most appropriate point to be checked in the audit of a system test?
The director requested a system auditor to audit the operating status of an accounting system that was developed by the information systems department and is operated by the accounting department. Which of the following is the most appropriate description concerning the system auditor for this audit?
Among situations that are identified as results of performing an ISMS internal audit on the basis of ISO/IEC 27001:2013 (Information security management systems—Requirements), which of the following is a situation that the auditor should record in the audit report as a finding?
An information security audit was performed about the security when backup media that contain confidential information are handed over to a vendor for external storage. Among situations that are identified as a result of this audit, which of the following is a situation that the auditor should record in the audit report as a finding?
Which of the following is the most appropriate measure that a management executive must take to secure the appearance of independence for an internal system auditor?
When software asset management is audited, which of the following activities is the most appropriate?
Among the implementation structures of a system audit, which of the following is the most important to avoid from the standpoint of the independence of a system auditor?
Which of the following is the system audit implementation structure that should be avoided from the standpoint of independence of the system auditors?
Which of the following is an appropriate activity that is undertaken by a system auditor who audits access control?
Which of the following is subject to system audits that evaluate and verify the internal control related to IT?
Among the statuses found through auditing the operation management of the system operations, which of the following must be described in the audit report as a finding?
Which of the following is an appropriate description concerning the implementation of a system audit?