GAQM
CPEH-001 · Question #746
During the security audit of IT processes, an IS auditor found that there were no documented security procedures. What should the IS auditor do?
The correct answer is D. Identify and evaluate existing practices. See the full explanation below for the reasoning.
Question
During the security audit of IT processes, an IS auditor found that there were no documented security procedures. What should the IS auditor do?
Options
- ACreate a procedures document
- BTerminate the audit
- CConduct compliance testing
- DIdentify and evaluate existing practices
How the community answered
(35 responses)- A14% (5)
- B3% (1)
- C9% (3)
- D74% (26)
Community Discussion
No community discussion yet for this question.