nerdexam
GAQM

CPEH-001 · Question #746

During the security audit of IT processes, an IS auditor found that there were no documented security procedures. What should the IS auditor do?

The correct answer is D. Identify and evaluate existing practices. See the full explanation below for the reasoning.

Question

During the security audit of IT processes, an IS auditor found that there were no documented security procedures. What should the IS auditor do?

Options

  • ACreate a procedures document
  • BTerminate the audit
  • CConduct compliance testing
  • DIdentify and evaluate existing practices

How the community answered

(35 responses)
  • A
    14% (5)
  • B
    3% (1)
  • C
    9% (3)
  • D
    74% (26)

Community Discussion

No community discussion yet for this question.

Full CPEH-001 Practice