Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CISA Questions and answers with CertsForce

Viewing page 2 out of 10 pages
Viewing questions 51-100 out of questions
Questions # 51:

A secure server room has a badge reader system that records name, date, and time information whenever a staff member uses a badge to enter or exit. When reviewing the system logs, an IS auditor notices records for some employees entering, but not exiting, the room. Which of the following would be the MOST effective compensating control to recommend?

Options:

A.

Installing security cameras at the doors


B.

Changing to a biometric access control system


C.

Implementing a monitored mantrap at entrance and exit points


D.

Requiring two-factor authentication at entrance and exit points


Expert Solution
Questions # 52:

Management has requested a post-implementation review of a newly implemented purchasing package to determine the extent that business requirements are being met. Which of the following

is MOST likely to be assessed?

Options:

A.

Acceptance testing results


B.

Results of live processing


C.

Implementation methodology


D.

Purchasing guidelines and policies


Expert Solution
Questions # 53:

A now regulation requires organizations to report significant security incidents to the regulator within 24 hours of identification. Which of the following is the IS auditor’s BEST recommendation to facilitate compliance with the regulation?

Options:

A.

Establish key performance indicators (KPls) for timely identification of security incidents.


B.

Engage an external security incident response expert for incident handling.


C.

Enhance the alert functionality of the intrusion detection system (IDS).


D.

Include the requirement in the incident management response plan.


Expert Solution
Questions # 54:

An IS audit reveals that an organization operating in business continuity mode during a pandemic situation has not performed a simulation test of the

business continuity plan (BCP). Which of the following is the auditor ' s BEST course of action?

Options:

A.

Confirm the BCP has been recently updated.


B.

Review the effectiveness of the business response.


C.

Raise an audit issue for the lack of simulated testing.


D.

Interview staff members to obtain commentary on the BCP ' s effectiveness.


Expert Solution
Questions # 55:

Which of the following is the BEST way to ensure an organization ' s data classification policies are preserved during the process of data transformation?

Options:

A.

Map data classification controls to data sets.


B.

Control access to extract, transform, and load (ETL) tools.


C.

Conduct a data discovery exercise across all business applications.


D.

Implement classification labels in metadata during data creation.


Expert Solution
Questions # 56:

Management has requested a post-implementation review of a newly implemented purchasing package to determine to what extent business requirements are being met. Which of the following is MOST likely to be assessed?

Options:

A.

Purchasing guidelines and policies


B.

Implementation methodology


C.

Results of line processing


D.

Test results


Expert Solution
Questions # 57:

What should an IS auditor do FIRST upon discovering that a service provider did not notify its customers of a security breach?

Options:

A.

Notify law enforcement of the finding.


B.

Require the third party to notify customers.


C.

The audit report with a significant finding.


D.

Notify audit management of the finding.


Expert Solution
Questions # 58:

An IS auditor is reviewing how password resets are performed for users working remotely. Which type of documentation should be requested to understand the detailed steps required for this activity?

Options:

A.

Standards


B.

Guidelines


C.

Policies


D.

Procedures


Expert Solution
Questions # 59:

What would be an IS auditor ' s BEST recommendation upon finding that a third-party IT service provider hosts the organization ' s human resources (HR) system in a foreign country?

Options:

A.

Perform background verification checks.


B.

Review third-party audit reports.


C.

Implement change management review.


D.

Conduct a privacy impact analysis.


Expert Solution
Questions # 60:

In order for a firewall to effectively protect a network against external attacks, what fundamental practice must be followed?

Options:

A.

The firewall must be placed in the demilitarized zone (DMZ).


B.

Only essential external services should be permitted.


C.

Filters for external information must be defined.


D.

All external communication must be via the firewall.


Expert Solution
Questions # 61:

Which of the following issues associated with a data center ' s closed-circuit television (CCTV) surveillance cameras should be of MOST concern to an IS auditor?

Options:

A.

CCTV recordings are not regularly reviewed.


B.

CCTV cameras are not installed in break rooms


C.

CCTV records are deleted after one year.


D.

CCTV footage is not recorded 24 x 7.


Expert Solution
Questions # 62:

Which of the following should be of GREATEST concern to an IS auditor assessing an organization ' s patch management program?

Options:

A.

Patches are deployed from multiple deployment servers.


B.

There is no process in place to scan the network to identify missing patches.


C.

Patches for medium- and low-risk vulnerabilities are omitted.


D.

There is no process in place to quarantine servers that have not been patched.


Expert Solution
Questions # 63:

The waterfall life cycle model of software development is BEST suited for which of the following situations?

Options:

A.

The protect requirements are wall understood.


B.

The project is subject to time pressures.


C.

The project intends to apply an object-oriented design approach.


D.

The project will involve the use of new technology.


Expert Solution
Questions # 64:

An IS auditor is reviewing logical access controls for an organization ' s financial business application Which of the following findings should be of GREATEST concern to the auditor?

Options:

A.

Users are not required to change their passwords on a regular basis


B.

Management does not review application user activity logs


C.

User accounts are shared between users


D.

Password length is set to eight characters


Expert Solution
Questions # 65:

The PRIMARY advantage of using open-source-based solutions is that they:

Options:

A.

Have well-defined support levels.


B.

Are easily implemented.


C.

Reduce dependence on vendors.


D.

Offer better security features.


Expert Solution
Questions # 66:

Which of the following should an IS auditor use when verifying a three-way match has occurred in an enterprise resource planning (ERR) system?

Options:

A.

Bank confirmation


B.

Goods delivery notification


C.

Purchase requisition


D.

Purchase order


Expert Solution
Questions # 67:

During a pre-implementation review, an IS auditor notes that some scenarios have not been tested. Management has indicated that the project is critical and cannot be postponed. Which of the following is the auditor ' s BEST course of action?

Options:

A.

Determine whether the tested scenarios covered the most significant project risks.


B.

Help management complete remaining scenario testing before implementation.


C.

Recommend project implementation be postponed until all scenarios have been tested.


D.

Perform remaining scenario testing in the production environment post implementation.


Expert Solution
Questions # 68:

Which of the following is the BEST recommendation to drive accountability for achieving the desired outcomes specified in a benefits realization plan for an IT project?

Options:

A.

Document the dependencies between the project and other projects within the same program.


B.

Ensure that IT takes ownership for the delivery and tracking of all aspects of the benefits realization plan.


C.

Ensure that the project manager has formal authority for managing the benefits realization plan.


D.

Assign responsibilities, measures, and timelines for each identified benefit within the plan.


Expert Solution
Questions # 69:

Which of the following is the MOST appropriate indicator of change management effectiveness?

Options:

A.

Time lag between changes to the configuration and the update of records


B.

Number of system software changes


C.

Time lag between changes and updates of documentation materials


D.

Number of incidents resulting from changes


Expert Solution
Questions # 70:

The PRIMARY objective of a control self-assessment (CSA) is to:

Options:

A.

educate functional areas on risks and controls.


B.

ensure appropriate access controls are implemented.


C.

eliminate the audit risk by leveraging management ' s analysis.


D.

gain assurance for business functions that cannot be audited.


Expert Solution
Questions # 71:

Which type of attack targets security vulnerabilities in web applications to gain access to data sets?

Options:

A.

Denial of service (DOS)


B.

SQL injection


C.

Phishing attacks


D.

Rootkits


Expert Solution
Questions # 72:

Which of the following would BEST reduce the risk of application programming interface (API) unavailability?

Options:

A.

Establishing dedicated servers for incoming API requests


B.

Implementing a continuous integration and deployment process


C.

Conducting periodic stress testing


D.

Limiting the rate of incoming requests


Expert Solution
Questions # 73:

Which of the following provides IS audit professionals with the BEST source of direction for performing audit functions?

Options:

A.

Audit charter


B.

IT steering committee


C.

Information security policy


D.

Audit best practices


Expert Solution
Questions # 74:

An organization offers an e-commerce platform that allows consumer-to-consumer transactions. The platform now uses blockchain technology to ensure the parties are unable to deny the transactions. Which of the following attributes BEST describes the risk element that this technology is addressing?

Options:

A.

Integrity


B.

Nonrepudiation


C.

Confidentiality


D.

Availability


Expert Solution
Questions # 75:

Which of the following is the BEST detective control for a job scheduling process involving data transmission?

Options:

A.

Metrics denoting the volume of monthly job failures are reported and reviewed by senior management.


B.

Jobs are scheduled to be completed daily and data is transmitted using a Secure File Transfer Protocol (SFTP).


C.

Jobs are scheduled and a log of this activity is retained for subsequent review.


D.

Job failure alerts are automatically generated and routed to support personnel.


Expert Solution
Questions # 76:

A data center ' s physical access log system captures each visitor ' s identification document numbers along with the visitor ' s photo. Which of the following sampling methods would be MOST useful to an IS auditor conducting compliance testing for the effectiveness of the system?

Options:

A.

Quota sampling


B.

Haphazard sampling


C.

Attribute sampling


D.

Variable sampling


Expert Solution
Questions # 77:

Which of the following is the MOST important area of focus for an IS auditor assessing the management of cryptographic keys in a public key infrastructure (PKI)?

Options:

A.

Checking the subscription of the key management system


B.

Identifying unusual activities by the key processors


C.

Reviewing key compromise detection activities


D.

Reviewing PKI documentation


Expert Solution
Questions # 78:

An IS auditor noted a recent production incident in which a teller transaction system incorrectly charged fees to customers due to a defect from a recent release. Which of the following should be the auditor ' s NEXT step?

Options:

A.

Evaluate developer training.


B.

Evaluate the incident management process.


C.

Evaluate the change management process.


D.

Evaluate secure code practices.


Expert Solution
Questions # 79:

In which phase of the audit life cycle process should an IS auditor initially discuss observations with management?

Options:

A.

Planning phase


B.

Reporting phase


C.

Follow-up phase


D.

Fieldwork phase


Expert Solution
Questions # 80:

Which of the following should be of GREATEST concern to an IS auditor performing a review of information security controls?

Options:

A.

The information security policy has not been approved by the chief audit executive (CAE).


B.

The information security policy does not include mobile device provisions


C.

The information security policy is not frequently reviewed


D.

The information security policy has not been approved by the policy owner


Expert Solution
Questions # 81:

An IS auditor finds that irregularities have occurred and that auditee management has chosen to ignore them. If reporting to external authorities is required which of the following is the BEST action for the IS auditor to take?

Options:

A.

Submit the report to appropriate regulators immediately.


B.

Obtain approval from audit management to submit the report.


C.

Obtain approval from auditee management to release the report.


D.

Obtain approval from both audit and auditee management to release the report.


Expert Solution
Questions # 82:

Which of the following security measures is MOST important for protecting Internet of Things (IoT) devices from potential cyberattacks?

Options:

A.

Logging and monitoring network traffic


B.

Confirming firmware compliance to current security requirements


C.

Changing default passwords


D.

Reviewing and updating the network diagram on a regular basis


Expert Solution
Questions # 83:

Which of the following presents the GREATEST risk of data leakage in the cloud environment?

Options:

A.

Lack of data retention policy


B.

Multi-tenancy within the same database


C.

Lack of role-based access


D.

Expiration of security certificate


Expert Solution
Questions # 84:

Which of the following should be given GREATEST consideration when implementing the use of an open-source product?

Options:

A.

Support


B.

Performance


C.

Confidentiality


D.

Usability


Expert Solution
Questions # 85:

Following a discussion on the results of a recent audit engagement, the process owner of the audited area has provided an action plan addressing the gaps and recommendations. The auditor disagrees with some of the responses where the process owner is accepting a level of residual risk that is not within the organization ' s risk appetite. What is the auditor ' s BEST course of action?

Options:

A.

Include the issue in the next report to the audit committee.


B.

Inform executive management of the residual risk.


C.

Accept the action plan proposed by the process owner.


D.

Escalate the situation to audit management.


Expert Solution
Questions # 86:

An organization is considering allowing users to connect personal devices to the corporate network. Which of the following should be done FIRST?

Options:

A.

Conduct security awareness training.


B.

Implement an acceptable use policy


C.

Create inventory records of personal devices


D.

Configure users on the mobile device management (MDM) solution


Expert Solution
Questions # 87:

Which of the following documents should define roles and responsibilities within an IT audit organization?

Options:

A.

Audit charter


B.

Annual audit plan


C.

Engagement letter


D.

Audit scope letter


Expert Solution
Questions # 88:

When auditing the feasibility study of a system development project, the IS auditor should:

Options:

A.

review qualifications of key members of the project team.


B.

review the request for proposal (RFP) to ensure that it covers the scope of work.


C.

review cost-benefit documentation for reasonableness.


D.

ensure that vendor contracts are reviewed by legal counsel.


Expert Solution
Questions # 89:

An IS auditor is reviewing job scheduling software and notes instances of delayed processing time, unexpected job interruption, and out-of-sequence job execution. Which of the following should the auditor examine FIRST to help determine the reasons for these instances?

Options:

A.

System schedule


B.

Job schedule


C.

Exception log


D.

Change log


Expert Solution
Questions # 90:

A bank wants to outsource a system to a cloud provider residing in another country. Which of the following would be the MOST appropriate IS audit recommendation?

Options:

A.

Find an alternative provider in the bank ' s home country.


B.

Ensure the provider ' s internal control system meets bank requirements.


C.

Proceed as intended, as the provider has to observe all laws of the clients’ countries.


D.

Ensure the provider has disaster recovery capability.


Expert Solution
Questions # 91:

A programmer has made unauthorized changes lo key fields in a payroll system report. Which of the following control weaknesses would have contributed MOST to this problem?

Options:

A.

The programmer did not involve the user in testing


B.

The user requirements were not documented


C.

The programmer has access to the production programs


D.

Payroll files were not under the control of a librarian


Expert Solution
Questions # 92:

An organization is planning an acquisition and has engaged an IS auditor lo evaluate the IT governance framework of the target company. Which of the following would be MOST helpful In determining the effectiveness of the framework?

Options:

A.

Sell-assessment reports of IT capability and maturity


B.

IT performance benchmarking reports with competitors


C.

Recent third-party IS audit reports


D.

Current and previous internal IS audit reports


Expert Solution
Questions # 93:

Which of the following is an IS auditor’s MOST important step in a privacy audit?

Options:

A.

Assess the controls in place for data management.


B.

Determine whether privacy training is being conducted for employees.


C.

Review third-party agreements for adequate personally identifiable information (PII) protection measures.


D.

Analyze all stages of the personally identifiable information (PII) data life cycle to identify potential risks.


Expert Solution
Questions # 94:

Which of the following findings from an IT governance review should be of GREATEST concern?

Options:

A.

The IT budget is not monitored


B.

All IT services are provided by third parties.


C.

IT value analysis has not been completed.


D.

IT supports two different operating systems.


Expert Solution
Questions # 95:

An IS auditor reviewing the threat assessment tor a data center would be MOST concerned if:

Options:

A.

some of the identified throats are unlikely to occur.


B.

all identified throats relate to external entities.


C.

the exercise was completed by local management.


D.

neighboring organizations operations have been included.


Expert Solution
Questions # 96:

Which of the following should be the PRIMARY consideration when validating a data analytic algorithm that has never been used before?

Options:

A.

Enhancing the design of data visualization


B.

Increasing speed and efficiency of audit procedures


C.

Confirming completeness and accuracy


D.

Decreasing the time for data analytics execution


Expert Solution
Questions # 97:

Which of the following should be of GREATEST concern to an IS auditor reviewing an organization’s IT process performance reports over the last quarter?

Options:

A.

Key performance indicators (KPIs) are not consistently monitored.


B.

Metrics were defined without key stakeholder input.


C.

Performance reporting includes too many technical terms.


D.

Metrics are not aligned with industry benchmarks.


Expert Solution
Questions # 98:

Of the following who should be responsible for cataloging and inventorying robotic process automation (RPA) processes?

Options:

A.

IT personnel


B.

Business owner


C.

Information security personnel


D.

Data steward


Expert Solution
Questions # 99:

When testing the adequacy of tape backup procedures, which step BEST verifies that regularly scheduled Backups are timely and run to completion?

Options:

A.

Observing the execution of a daily backup run


B.

Evaluating the backup policies and procedures


C.

Interviewing key personnel evolved In the backup process


D.

Reviewing a sample of system-generated backup logs


Expert Solution
Questions # 100:

An IS auditor learns that an organization ' s business continuity plan (BCP) has not been updated in the last 18 months and that the organization recently closed a production plant. Which of the following is the auditor ' s BEST course of action?

Options:

A.

Determine whether the business impact analysis (BIA) is current with the organization ' s structure and context.


B.

Determine the types of technologies used at the plant and how they may affect the BCP.


C.

Perform testing to determine the impact to the recovery time objective (R TO).


D.

Assess the risk to operations from the closing of the plant.


Expert Solution
Viewing page 2 out of 10 pages
Viewing questions 51-100 out of questions