27 Apr 2026, 13:56 UTC≈1,570 views2 reactionsread 7 August 2026 An IS auditor noted that a change to a critical calculation was placed into the production environment without being tested. Which of the following is the BEST way to obtain assurance that the calculation functions correctly?
A. Check regular execution of the calculation batch job
B. Perform substantive testing using computer-assisted audit techniques (CAATs)
C. Obtain post-change approval from management
D. Intervi…
❤2
Signed Mohammed Elsherif
27 Apr 2026, 13:56 UTC≈1,720 views2 reactionsread 7 August 2026 Which of the following is the MOST effective way for an organization to ensure its third-party service providers are aware of information security requirements and expectations?
A. Providing information security training to third-party personnel
B. Auditing the service delivery of third-party providers
C. Inducting information security clauses within contracts
D. Requiring third parties to sign confidentiality agre…
❤2
Signed Mohammed Elsherif
27 Apr 2026, 13:56 UTC≈2,020 views2 reactionsread 7 August 2026 Which of the following is the MOST important consideration for an organization when strategizing to comply with privacy regulations? A. Ensuring there are staff members with in-depth knowledge of the privacy regulations
B. Ensuring up-to-date knowledge of where customer data is saved C. Ensuring regularly updated contracts with third parties that process customer data
D. Ensuring appropriate access to information sys…
❤2
Signed Mohammed Elsherif
27 Apr 2026, 13:56 UTC≈2,010 views4 reactionsread 7 August 2026 Which of the following cloud computing service model provides a way to rent operating systems, storage and network capacity over the Internet?
A. Software as a service B. Data as a service
C. Platform as a service D. Infrastructure as a service
❤3👍1
Signed Mohammed Elsherif
27 Apr 2026, 13:56 UTC≈1,850 views1 reactionsread 7 August 2026 Which of the following would be MOST time and cost efficient when performing a control self-assessment (CSA) for an organization with a large number of widely dispersed employees?
A. Top-down and bottom-up analysis
B. Face-to-face interviews
C. Survey questionnaire
D. Facilitated workshops
❤1
Signed Mohammed Elsherif
28 Jan 2026, 19:17 UTC≈2,970 views1 reactionsread 7 August 2026 Which of the following is the MOST effective approach for integrating security into application development?
A. Including security in user acceptance testing sign-off
B. Performing vulnerability scans
C. Developing security models in parallel
D. Defining security requirements
❤1
Signed Mohammed Elsherif
28 Jan 2026, 19:16 UTC≈2,920 views3 reactionsread 7 August 2026 An e-commerce enterprise's disaster recovery (DR) site has 30% less processing capability than the primary site. Based on this information, which of the following presents the GREATEST risk?
A. Network firewalls and database firewalls at the DR site do not provide high availability.
B. No disaster recovery plan (DRP) testing has been performed during the last six months.
C. The DR site is in a shared location that ho…
❤3
Signed Mohammed Elsherif
28 Jan 2026, 19:16 UTC≈2,560 views4 reactionsread 7 August 2026 After the merger of two organizations, which of the following is the MOST important task for an IS auditor to perform? A. Investigating access rights for expiration dates B. Verifying that access privileges have been reviewed
C. Updating the security policy
D. Updating the continuity plan for critical resources
❤4
Signed Mohammed Elsherif
28 Jan 2026, 19:15 UTC≈2,310 viewsread 7 August 2026 Which of the following should be reviewed FIRST when planning an IS audit?
A. Recent financial information
B. Annual business unit budget
C. IS audit standards
D. The business environment
Signed Mohammed Elsherif
10 Jan 2026, 13:32 UTC≈2,540 views0 reactionsread 7 August 2026 You are part of a security staff at a highly profitable bank and each day, all traffic on the network is logged for later review. Every Friday when major deposits are made you're seeing a series of bits placed in the "Urgent Pointer" field of a TCP packet. This is only 16 bits which isn't much but it concerns you because: A. This could be a sign of covert channeling in bank network communications and should be invest…
Signed Mohammed Elsherif
10 Jan 2026, 13:30 UTC≈2,160 viewsread 7 August 2026 A shared resource matrix is a technique commonly used to locate:
A. Malicious code
B. Security flaws
C. Trap doors
D. Covert channels
Signed Mohammed Elsherif
10 Jan 2026, 13:29 UTC≈2,000 viewsread 7 August 2026 Which of the following BEST indicates a need to review an organization's information security policy?
A. Completion of annual IT risk assessment
B. Increasing complexity of business transactions C. Increasing exceptions approved by management
D. High number of low-risk findings in the audit report
Signed Mohammed Elsherif
Showing the 12 most recent of 20 posts we hold for @CISA_AuditclubwithMohammedAhmed. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.