Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CISA Questions and answers with CertsForce

Viewing page 1 out of 10 pages
Viewing questions 1-50 out of questions
Questions # 1:

When planning an audit to assess controls for an application in the cloud environment, it is MOST important for an IS auditor to understand:

Options:

A.

The noncompliance fee for violating a service level agreement (SLA).


B.

Availability reports from the cloud platform architecture.


C.

The shared responsibility model between cloud provider and organization.


D.

Business process reengineering that is supported by the cloud system.


Expert Solution
Questions # 2:

Which of the following is MOST important when implementing a data classification program?

Options:

A.

Understanding the data classification levels


B.

Formalizing data ownership


C.

Developing a privacy policy


D.

Planning for secure storage capacity


Expert Solution
Questions # 3:

Results from which of the following would BEST provide assurance to a governing body that an organization’s information system controls have been reviewed objectively?

Options:

A.

Administrative audit.


B.

External audit.


C.

Forensic audit.


D.

Internal audit.


Expert Solution
Questions # 4:

An organization ' s IT risk assessment should include the identification of:

Options:

A.

vulnerabilities


B.

compensating controls


C.

business needs


D.

business process owners


Expert Solution
Questions # 5:

Which of the following is the BEST control lo mitigate attacks that redirect Internet traffic to an unauthorized website?

Options:

A.

Utilize a network-based firewall.


B.

Conduct regular user security awareness training.


C.

Perform domain name system (DNS) server security hardening.


D.

Enforce a strong password policy meeting complexity requirement.


Expert Solution
Questions # 6:

An organization is enhancing the security of a client-facing web application following a proposal to acquire personal information for a business purpose. Which of the following is MOST important to review before implementing this initiative?

Options:

A.

Regulatory compliance requirements


B.

Data ownership assignments


C.

Encryption capabilities


D.

Customer notification procedures


Expert Solution
Questions # 7:

Which of the following is the BEST reason for software developers to use automated testing versus manual testing?

Options:

A.

CAATs are easily developed


B.

Improved regression testing


C.

Ease of maintaining automated test scripts


D.

Reduces the scope of acceptance testing


Expert Solution
Questions # 8:

When building or upgrading enterprise cryptographic infrastructure, which of the following is the MOST critical requirement for growing business environments?

Options:

A.

Service discovery


B.

Backup and restoration capabilities


C.

Network throttling


D.

Scalable architectures and systems


Expert Solution
Questions # 9:

Which of the following BEST reflects a mature strategic planning process?

Options:

A.

Action plans with IT requirements built into all projects


B.

An IT strategic plan with specifications of controls and safeguards


C.

An IT strategic plan that supports the corporate strategy


D.

IT projects from the strategic plan are approved by management


Expert Solution
Questions # 10:

Which audit approach is MOST helpful in optimizing the use of IS audit resources?

Options:

A.

Agile auditing


B.

Continuous auditing


C.

Outsourced auditing


D.

Risk-based auditing


Expert Solution
Questions # 11:

An IS auditor has traced the source of a transaction fraud to the desktop system of an e-business staff member who is on leave. Which of the following is the BEST way for the auditor to ensure the success of the investigation?

Options:

A.

Create an image of the attacked system and dump the memory to a file for review.


B.

Immediately seal off the attacked system and block all access until after the investigation.


C.

Reboot the attacked system and promptly review log files and file timestamps.


D.

Interview the business staff and ask them to provide details of recent system activities.


Expert Solution
Questions # 12:

Which of the following MOST effectively manages frequent program file changes where simultaneous code edits are used?

Options:

A.

Mandatory architecture reviews.


B.

Source code composition scanning.


C.

Source code version control.


D.

Change control self-assessments (CSAs).


Expert Solution
Questions # 13:

While executing follow-up activities, an IS auditor is concerned that management has implemented corrective actions that are different from those originally discussed and agreed with the audit function. In order to resolve the situation, the IS auditor ' s BEST course of action would be to:

Options:

A.

re-prioritize the original issue as high risk and escalate to senior management.


B.

schedule a follow-up audit in the next audit cycle.


C.

postpone follow-up activities and escalate the alternative controls to senior audit management.


D.

determine whether the alternative controls sufficiently mitigate the risk.


Expert Solution
Questions # 14:

Following an IT audit, management has decided to accept the risk highlighted in the audit report. Which of the following would provide the MOST assurance to the IS auditor that management

is adequately balancing the needs of the business with the need to manage risk?

Options:

A.

A communication plan exists for informing parties impacted by the risk.


B.

Potential impact and likelihood are adequately documented.


C.

Identified risk is reported into the organization ' s risk committee.


D.

Established criteria exist for accepting and approving risk.


Expert Solution
Questions # 15:

Which of the following is the BEST control to mitigate the malware risk associated with an instant messaging (IM) system?

Options:

A.

Blocking attachments in IM


B.

Blocking external IM traffic


C.

Allowing only corporate IM solutions


D.

Encrypting IM traffic


Expert Solution
Questions # 16:

Which of the following is the PRIMARY objective of performing quality assurance (QA) in a system development process?

Options:

A.

To ensure that expected benefits have been realized


B.

To ensure the developed system meets business requirements


C.

To ensure the developed system integrates well with another system


D.

To help determine high-level requirements for the new system


Expert Solution
Questions # 17:

Which of the following physical controls provides the GREATEST assurance that only authorized individuals can access a data center?

Options:

A.

The data center is patrolled by a security guard.


B.

Access to the data center is monitored by video cameras.


C.

ID badges must be displayed before access is granted


D.

Access to the data center is controlled by a mantrap.


Expert Solution
Questions # 18:

What is the PRIMARY purpose of documenting audit objectives when preparing for an engagement?

Options:

A.

To address the overall risk associated with the activity under review


B.

To identify areas with relatively high probability of material problems


C.

To help ensure maximum use of audit resources during the engagement


D.

To help prioritize and schedule auditee meetings


Expert Solution
Questions # 19:

Which of the following is an example of a preventative control in an accounts payable system?

Options:

A.

The system only allows payments to vendors who are included In the system ' s master vendor list.


B.

Backups of the system and its data are performed on a nightly basis and tested periodically.


C.

The system produces daily payment summary reports that staff use to compare against invoice totals.


D.

Policies and procedures are clearly communicated to all members of the accounts payable department


Expert Solution
Questions # 20:

An IS auditor is conducting a post-implementation review of an enterprise resource planning (ERP) system. End users indicated concerns with the accuracy of critical automatic calculations made by the system. The auditor ' s FIRST course of action should be to:

Options:

A.

review recent changes to the system.


B.

verify completeness of user acceptance testing (UAT).


C.

verify results to determine validity of user concerns.


D.

review initial business requirements.


Expert Solution
Questions # 21:

Which of the following is the MOST important determining factor when establishing appropriate timeframes for follow-up activities related to audit findings?

Options:

A.

Availability of IS audit resources


B.

Remediation dates included in management responses


C.

Peak activity periods for the business


D.

Complexity of business processes identified in the audit


Expert Solution
Questions # 22:

Which of the following performance management tools BEST helps an IS auditor evaluate the success of an organization’s IT strategy implementation and execution?

Options:

A.

IT benchmarking


B.

Capability maturity model


C.

Six Sigma


D.

IT metrics dashboard


Expert Solution
Questions # 23:

Which of the following is the MOST important consideration when relying on the work of the prior auditor?

Options:

A.

Qualifications of the prior auditor


B.

Management agreement with recommendations


C.

Duration of the prior audit


D.

Number of findings identified by the prior auditor


Expert Solution
Questions # 24:

When an IS auditor needs to confirm that an organization is encrypting sensitive information at a database level, which of the following would provide the BEST assurance?

Options:

A.

Reviewing the drive settings of the host server


B.

Checking network traffic for clear text transmissions


C.

Verifying a sample of critical fields


D.

Reviewing the organization’s encryption policy


Expert Solution
Questions # 25:

An external audit firm was engaged to perform a validation and verification review for a systems implementation project. The IS auditor identifies that regression testing is not part of the project plan and was not performed by the systems implementation team. According to the team, the parallel testing being performed is sufficient, making regression testing unnecessary. What should be the auditor’s NEXT step?

Options:

A.

Evaluate the extent of the parallel testing being performed


B.

Recommend integration and stress testing be conducted by the systems implementation team


C.

Conclude that parallel testing is sufficient and regression testing is not needed


D.

Recommend regression testing be conducted by the systems implementation team


Expert Solution
Questions # 26:

An IT governance body wants to determine whether IT service delivery is based on consistently effective processes. Which of the following is the BEST approach?

Options:

A.

Evaluate key performance indicators (KPIs).


B.

Conduct a gap analysis.


C.

Develop a maturity model.


D.

Implement a control self-assessment (CSA).


Expert Solution
Questions # 27:

Which of the following operational log management considerations is MOST important for an organization undergoing a digital transformation?

Options:

A.

Changes in operating costs for log management


B.

Centralization of current log management


C.

Tuning of log reviews to provide enhanced oversight


D.

IT resource capability to manage application uptime


Expert Solution
Questions # 28:

An organization is concerned about duplicate vendor payments on a complex system with a high volume of transactions. Which of the following would be MOST helpful to an IS auditor to determine whether duplicate vendor payments exist?

Options:

A.

Computer-assisted technique


B.

Stratified sampling


C.

Statistical sampling


D.

Process walk-through


Expert Solution
Questions # 29:

Which of the following is MOST important to include in a feasibility study when developing a business case for an IT investment?

Options:

A.

An analysis of costs and benefits associated with proposed solutions


B.

Availability of IT resources proposed for the project


C.

Evidence that all possible risk scenarios have been considered


D.

Key stakeholders responsible for review and approval of proposed solutions


Expert Solution
Questions # 30:

Which of the following is a corrective control?

Options:

A.

Separating equipment development testing and production


B.

Verifying duplicate calculations in data processing


C.

Reviewing user access rights for segregation


D.

Executing emergency response plans


Expert Solution
Questions # 31:

Which of the following will provide the GREATEST assurance to IT management that a quality management system (QMS) is effective?

Options:

A.

A high percentage of stakeholders satisfied with the quality of IT


B.

Ahigh percentage of incidents being quickly resolved


C.

Ahigh percentage of IT processes reviewed by quality assurance (QA)


D.

Ahigh percentage of IT employees attending quality training


Expert Solution
Questions # 32:

During a security audit, an IS auditor is tasked with reviewing log entries obtained from an enterprise intrusion prevention system (IPS). Which type of risk would be associated with the potential for the auditor to miss a sequence of logged events that could indicate an error in the IPS configuration?

Options:

A.

Sampling risk


B.

Detection risk


C.

Control risk


D.

Inherent risk


Expert Solution
Questions # 33:

A system performance dashboard indicates several application servers are reaching the defined threshold for maximum CPU allocation. Which of the following would be the IS auditor ' s BEST recommendation for the IT department?

Options:

A.

Increase the defined processing threshold to reflect capacity consumption during normal operations.


B.

Notify end users of potential disruptions caused by degradation of servers.


C.

Terminate both ingress and egress connections of these servers to avoid overload.


D.

Validate the processing capacity of these servers is adequate to complete computing tasks.


Expert Solution
Questions # 34:

An organization is disposing of a system containing sensitive data and has deleted all files from the hard disk. An IS auditor should be concerned because:

Options:

A.

deleted data cannot easily be retrieved.


B.

deleting the files logically does not overwrite the files ' physical data.


C.

backup copies of files were not deleted as well.


D.

deleting all files separately is not as efficient as formatting the hard disk.


Expert Solution
Questions # 35:

Which of the following should be an IS auditor ' s GREATEST concern when an international organization intends to roll out a global data privacy policy?

Options:

A.

Requirements may become unreasonable.


B.

The policy may conflict with existing application requirements.


C.

Local regulations may contradict the policy.


D.

Local management may not accept the policy.


Expert Solution
Questions # 36:

Which of the following presents the GREATEST challenge to the alignment of business and IT?

Options:

A.

Lack of chief information officer (CIO) involvement in board meetings


B.

Insufficient IT budget to execute new business projects


C.

Lack of information security involvement in business strategy development


D.

An IT steering committee chaired by the chief information officer (CIO)


Expert Solution
Questions # 37:

Which of the following findings would be of GREATEST concern to an IS auditor assessing an organization ' s patch management process?

Options:

A.

The organization ' s software inventory is not complete.


B.

Applications frequently need to be rebooted for patches to take effect.


C.

Software vendors are bundling patches.


D.

Testing patches takes significant time.


Expert Solution
Questions # 38:

A finance department has a multi-year project to upgrade the enterprise resource planning (ERP) system hosting the general ledger. and in year one, the system version upgrade will be applied. Which of the following should be the PRIMARY focus of the IS auditor reviewing the first year of the project?

Options:

A.

unit testing


B.

Network performance


C.

User acceptance testing (UAT)


D.

Regression testing


Expert Solution
Questions # 39:

To mitigate the risk of exposing data through application programming interface (API) queries. which of the following design considerations is MOST important?

Options:

A.

Data retention


B.

Data minimization


C.

Data quality


D.

Data integrity


Expert Solution
Questions # 40:

Which of the following is the BEST reason for an IS auditor to emphasize to management the importance of using an IT governance framework?

Options:

A.

Frameworks enable IT benchmarks against competitors


B.

Frameworks can be tailored and optimized for different organizations


C.

Frameworks help facilitate control self-assessments (CSAs)


D.

Frameworks help organizations understand and manage IT risk


Expert Solution
Questions # 41:

The following findings are the result of an IS auditor ' s post-implementation review of a newly implemented system. Which of the following findings is of GREATEST significance?

Options:

A.

A lessons-learned session was never conducted.


B.

The projects 10% budget overrun was not reported to senior management.


C.

Measurable benefits were not defined.


D.

Monthly dashboards did not always contain deliverables.


Expert Solution
Questions # 42:

Which of the following risk scenarios is BEST mitigated through the use of a data loss prevention (DLP) tool?

Options:

A.

An employee is sending company documents to an external email to increase productivity.


B.

A former employee retains access to an application that authenticates via single sign-on < SSO).


C.

An employee uses production data in a test environment.


D.

An employee selects the incorrect data classification on documents.


Expert Solution
Questions # 43:

Which of the following is the GREATEST benefit of adopting an Agile audit methodology?

Options:

A.

Better ability to address key risks


B.

Less frequent client interaction


C.

Annual cost savings


D.

Reduced documentation requirements


Expert Solution
Questions # 44:

Which of the following is the MOST important benefit of involving IS audit when implementing governance of enterprise IT?

Options:

A.

Identifying relevant roles for an enterprise IT governance framework


B.

Making decisions regarding risk response and monitoring of residual risk


C.

Verifying that legal, regulatory, and contractual requirements are being met


D.

Providing independent and objective feedback to facilitate improvement of IT processes


Expert Solution
Questions # 45:

Which of the following are examples of corrective controls?

Options:

A.

Implementing separation of duties and hash totals


B.

Performing internal audit reviews and remediation activities


C.

Applying rollback scripts and backup procedures


D.

Enforcing disciplinary action and termination procedures


Expert Solution
Questions # 46:

An organization has decided to purchase a web-based email service from a third-party vendor and eliminate its own email server infrastructure. What type of cloud computing environment would BEST meet the organization ' s objective?

Options:

A.

Platform as a Service (PaaS)


B.

Software as a Service (SaaS)


C.

Database as a Service (DBaaS)


D.

Infrastructure as a Service (laaS)


Expert Solution
Questions # 47:

Which of the following would an IS auditor recommend as the MOST effective preventive control to reduce the risk of data leakage?

Options:

A.

Ensure that paper documents arc disposed security.


B.

Implement an intrusion detection system (IDS).


C.

Verify that application logs capture any changes made.


D.

Validate that all data files contain digital watermarks


Expert Solution
Questions # 48:

An IS auditor is reviewing a data conversion project Which of the following is the auditor ' s BEST recommendation prior to go-live?

Options:

A.

Review test procedures and scenarios


B.

Conduct a mock conversion test


C.

Establish a configuration baseline


D.

Automate the test scripts


Expert Solution
Questions # 49:

Which of the following risks is BEST mitigated by implementing an automated three-way match?

Options:

A.

Inaccurate customer records


B.

Purchase order delays


C.

lnaccurate customer discounts


D.

Invalid payment processing


Expert Solution
Questions # 50:

An IS audit team is evaluating documentation of the most recent application user access review. It is determined that the user list was not system generated. Which of the following should be of

MOST concern?

Options:

A.

Confidentiality of the user list


B.

Timeliness of the user list review


C.

Completeness of the user list


D.

Availability of the user list


Expert Solution
Viewing page 1 out of 10 pages
Viewing questions 1-50 out of questions