exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 252 discussion

Actual exam question from Isaca's CISM
Question #: 252
Topic #: 1
[All CISM Questions]

Audit trails of changes to source code and object code are BEST tracked through:

  • A. use of compilers.
  • B. code review.
  • C. program library software.
  • D. job control statements.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
enk
Highly Voted 11 months, 2 weeks ago
Selected Answer: C
Answer is C. Github is a 'program library software'. It has version control that can be audited.
upvoted 5 times
...
e891cd1
Most Recent 7 months, 2 weeks ago
B. Code Review is an indepth process that includes document changes and code version control.
upvoted 2 times
...
yottabyte
8 months, 1 week ago
Selected Answer: B
B. Code Review seems to be apt.
upvoted 1 times
...
King21
1 year ago
Question talks about 'audit trails', this to me removes code review as an option. Answer should be C
upvoted 2 times
...
oluchecpoint
1 year, 1 month ago
Selected Answer: C
C. program library software. Program library software, often referred to as version control or source code management systems (e.g., Git, Subversion), is designed specifically to track changes to source code and object code. These tools allow developers to commit their code changes, provide comments about the changes made, and maintain a history of revisions. This makes it easier to review, roll back to previous versions, and track who made specific changes to the code, providing a comprehensive audit trail.
upvoted 4 times
AlexJacobson
10 months ago
Never in my life I have ever heard someone refer to version control software as "program library software". So it's hardly C, most likely B.
upvoted 1 times
...
...
sphenixfire
1 year, 2 months ago
Selected Answer: C
Code review has nothing to to with audit trails
upvoted 2 times
...
Agamennore
1 year, 2 months ago
Selected Answer: B
B for sure
upvoted 1 times
...
Bl1024
1 year, 2 months ago
Selected Answer: D
The question is about tracking audit trails, it has nothing to do with code review. The answer should be change management, hence - D
upvoted 2 times
...
[Removed]
1 year, 3 months ago
Selected Answer: C
According to CISM Review Manual, 27th Edition, in Domain 3 (Information Security Program Development and Management) and Domain 4 (Information Security Incident Management), it is indicated that software library controls or configuration management systems are used to store and manage source and object codes.
upvoted 4 times
ImTired
1 year, 1 month ago
The CISM review review manual only has 16 editions.
upvoted 5 times
AlexJacobson
10 months ago
That's the future edition from 2041. Dude's obviously a time traveler, hence [Removed] xD
upvoted 1 times
...
...
...
richck102
1 year, 5 months ago
B. code review.
upvoted 1 times
...
mad68
1 year, 6 months ago
Selected Answer: B
B. code review. Code review is a process where software developers or designated reviewers systematically examine and evaluate the source code to identify issues, defects, or opportunities for improvement. During code review, changes made to the code can be documented and tracked, providing an audit trail of the modifications. This helps in maintaining version control, identifying the author of changes, and ensuring accountability and transparency in the software development process.
upvoted 3 times
...
Abhey
1 year, 6 months ago
Selected Answer: B
Audit trails of changes to source code and object code are BEST tracked through code review.
upvoted 2 times
...
dark_3k03r
1 year, 7 months ago
Selected Answer: B
The best answer is B: Code Review as it forces someone to review the previous code and the new code to make a judgment call as to whether to approve the change or not. Rationale: A. Compiler creates code but doesn't keep track of code B. code review: This is the correct answer. C. program library software is a collection of code, but again doesn't keep track of code changes D. job control statements control the execution of a job for a mainframe. So that's not really relevant here.
upvoted 3 times
...
[Removed]
1 year, 8 months ago
Program library software can help manage collections of code, but it is not specifically designed to track changes to code over time so not sure if correct but out of given answers comes close
upvoted 1 times
[Removed]
1 year, 7 months ago
updating the above view -Audit trails of changes to source code and object code are BEST tracked through code review.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago