Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CISA Questions and answers with CertsForce

Viewing page 3 out of 10 pages
Viewing questions 101-150 out of questions
Questions # 101:

Which of the following is an IS auditor ' s BEST recommendation to protect an organization from attacks when its file server needs to be accessible to external users?

Options:

A.

Enforce a secure tunnel connection.


B.

Enhance internal firewalls.


C.

Set up a demilitarized zone (DMZ).


D.

Implement a secure protocol.


Expert Solution
Questions # 102:

An organization uses an automated continuous integration/continuous deployment (CI/CD) tool to deploy changes to production. Which of the following would be an IS auditor ' s GREATEST concern in this situation?

Options:

A.

Releases are scheduled once per week.


B.

Post-implementation reviews are conducted quarterly.


C.

Test cases may be inaccurate.


D.

Functional requirements are changed frequently by users.


Expert Solution
Questions # 103:

An IS auditor reviewing an organization’s online payment system finds that the system sometimes duplicates payments. Which control will BEST compensate for this weakness?

Options:

A.

Manually receipting payments.


B.

Using hash totals.


C.

Using control totals.


D.

Performing a bank reconciliation.


Expert Solution
Questions # 104:

What is the MOST effective way to detect installation of unauthorized software packages by employees?

Options:

A.

Regular scanning of hard drives


B.

Communicating the policy to employees


C.

Logging of activity on the network


D.

Maintaining current antivirus software


Expert Solution
Questions # 105:

In an environment that automatically reports all program changes, which of the following is the MOST efficient way to detect unauthorized changes to production programs?

Options:

A.

Reviewing the last compile date of production programs


B.

Manually comparing code in production programs to controlled copies


C.

Periodically running and reviewing test data against production programs


D.

Verifying user management approval of modifications


Expert Solution
Questions # 106:

In a 24/7 processing environment, a database contains several privileged application accounts with passwords set to never expire. Which of the following recommendations would BEST address the risk with minimal disruption to the business?

Options:

A.

Modify applications to no longer require direct access to the database.


B.

Introduce database access monitoring into the environment


C.

Modify the access management policy to make allowances for application accounts.


D.

Schedule downtime to implement password changes.


Expert Solution
Questions # 107:

The GREATEST benefit of using a polo typing approach in software development is that it helps to:

Options:

A.

minimize scope changes to the system.


B.

decrease the time allocated for user testing and review.


C.

conceptualize and clarify requirements.


D.

Improve efficiency of quality assurance (QA) testing


Expert Solution
Questions # 108:

In a high-volume, real-time system, the MOST effective technique by which to continuously monitor and analyze transaction processing is:

Options:

A.

integrated test facility (ITF).


B.

parallel simulation.


C.

transaction tagging.


D.

embedded audit modules.


Expert Solution
Questions # 109:

An IS audit manager is preparing the staffing plan for an audit engagement of a cloud service provider. What should be the manager ' s PRIMARY concern when being made aware that a new

auditor in the department previously worked for this provider?

Options:

A.

Independence


B.

Professional conduct


C.

Subject matter expertise


D.

Resource availability


Expert Solution
Questions # 110:

The BEST way to provide assurance that a project is adhering to the project plan is to:

Options:

A.

require design reviews at appropriate points in the life cycle.


B.

have an IS auditor participate on the steering committee.


C.

have an IS auditor participate on the quality assurance (QA) team.


D.

conduct compliance audits at major system milestones.


Expert Solution
Questions # 111:

During a review of a production schedule, an IS auditor observes that a staff member is not complying with mandatory operational procedures. The auditor ' s NEXT step should be to:

Options:

A.

note the noncompliance in the audit working papers.


B.

issue an audit memorandum identifying the noncompliance.


C.

include the noncompliance in the audit report.


D.

determine why the procedures were not followed.


Expert Solution
Questions # 112:

Which of the following should an IS auditor be MOST concerned with during a post-implementation review?

Options:

A.

The system does not have a maintenance plan.


B.

The system contains several minor defects.


C.

The system deployment was delayed by three weeks.


D.

The system was over budget by 15%.


Expert Solution
Questions # 113:

During a disaster recovery audit, an IS auditor finds that a business impact analysis (BIA) has not been performed. The auditor should FIRST

Options:

A.

perform a business impact analysis (BIA).


B.

issue an intermediate report to management.


C.

evaluate the impact on current disaster recovery capability.


D.

conduct additional compliance testing.


Expert Solution
Questions # 114:

An IS auditor is asked to review an organization ' s technology relationships, interfaces, and data. Which of the following enterprise architecture (EA) areas is MOST appropriate this review? (Choose Correct answer and give explanation from CISA Certification - Information Systems Auditor official book)

Options:

A.

Reference architecture


B.

Infrastructure architecture


C.

Information security architecture


D.

Application architecture


Expert Solution
Questions # 115:

Which of the following approaches will ensure recovery time objectives (RTOs) are met for an organization ' s disaster recovery plan (DRP)?

Options:

A.

Performing a cyber resilience test


B.

Performing a full interruption test


C.

Performing a tabletop test


D.

Performing a parallel test


Expert Solution
Questions # 116:

Which of the following should be the IS auditor ' s PRIMARY focus when evaluating an organizations offsite storage facility?

Options:

A.

Adequacy of physical and environmental controls


B.

Results of business continuity plan (BCP) tests


C.

Shared facilities


D.

Retention policy and period


Expert Solution
Questions # 117:

Which of the following is the BEST review for an IS auditor to conduct when a vulnerability has been exploited by an employee?

Options:

A.

Compliance audit


B.

Application security testing


C.

Forensic audit


D.

Penetration testing


Expert Solution
Questions # 118:

Which of the following is the MOST appropriate testing approach when auditing a daily data flow between two systems via an automated interface to confirm that it is complete and accurate?

Options:

A.

Confirm that the encryption standard applied to the interface is in line with best practice.


B.

Inspect interface configurations and an example output of the systems.


C.

Perform data reconciliation between the two systems for a sample of 25 days.


D.

Conduct code review for both systems and inspect design documentation.


Expert Solution
Questions # 119:

Which of the following is the GREATEST risk associated with hypervisors in virtual environments?

Options:

A.

Availability issues


B.

Virtual sprawl


C.

Single point of failure


D.

Lack of patches


Expert Solution
Questions # 120:

Which of the following provides the GREATEST assurance that a middleware application compiling data from multiple sales transaction databases for forecasting is operating effectively?

Options:

A.

Continuous auditing


B.

Manual checks


C.

Exception reporting


D.

Automated reconciliations


Expert Solution
Questions # 121:

An IS audit manager was temporarily tasked with supervising a project manager assigned to the organization ' s payroll application upgrade. Upon returning to the audit department, the audit manager has been asked to perform an audit to validate the implementation of the payroll application. The audit manager is the only one in the audit department with IT project management

experience. What is the BEST course of action?

Options:

A.

Transfer the assignment to a different audit manager despite lack of IT project management experience.


B.

Outsource the audit to independent and qualified resources.


C.

Manage the audit since there is no one else with the appropriate experience.


D.

Have a senior IS auditor manage the project with the IS audit manager performing final review.


Expert Solution
Questions # 122:

Which of the following is the PRIMARY role of the IS auditor m an organization ' s information classification process?

Options:

A.

Securing information assets in accordance with the classification assigned


B.

Validating that assets are protected according to assigned classification


C.

Ensuring classification levels align with regulatory guidelines


D.

Defining classification levels for information assets within the organization


Expert Solution
Questions # 123:

Which of the following provides the BEST providence that outsourced provider services are being properly managed?

Options:

A.

The service level agreement (SLA) includes penalties for non-performance.


B.

Adequate action is taken for noncompliance with the service level agreement (SLA).


C.

The vendor provides historical data to demonstrate its performance.


D.

Internal performance standards align with corporate strategy.


Expert Solution
Questions # 124:

Which of the following is the PRIMARY reason for implementing continuous auditing?

Options:

A.

Evidence is reviewed for completeness and accuracy.


B.

Management is aware of issues in real time.


C.

It is incorporated into continuous monitoring activities.


D.

Risks are identified in a timely manner.


Expert Solution
Questions # 125:

A manager Identifies active privileged accounts belonging to staff who have left the organization. Which of the following is the threat actor In this scenario?

Options:

A.

Terminated staff


B.

Unauthorized access


C.

Deleted log data


D.

Hacktivists


Expert Solution
Questions # 126:

Which of the following should be the GREATEST concern to an IS auditor reviewing an organization ' s job scheduling practices?

Options:

A.

Most jobs are run manually.


B.

Jobs are executed during working hours.


C.

Job dependencies are undefined.


D.

Job processing procedures are missing.


Expert Solution
Questions # 127:

Which of the following must be in place before an IS auditor initiates audit follow-up activities?

Options:

A.

Available resources for the activities included in the action plan


B.

A management response in the final report with a committed implementation date


C.

A heal map with the gaps and recommendations displayed in terms of risk


D.

Supporting evidence for the gaps and recommendations mentioned in the audit report


Expert Solution
Questions # 128:

In order to be useful, a key performance indicator (KPI) MUST

Options:

A.

be approved by management.


B.

be measurable in percentages.


C.

be changed frequently to reflect organizational strategy.


D.

have a target value.


Expert Solution
Questions # 129:

Audit observations should be FIRST communicated with the auditee:

Options:

A.

when drafting the report.


B.

during fieldwork.


C.

at the end of fieldwork.


D.

within the audit report


Expert Solution
Questions # 130:

During the design phase of a software development project, the PRIMARY responsibility of an IS auditor is to evaluate the:

Options:

A.

Future compatibility of the application.


B.

Proposed functionality of the application.


C.

Controls incorporated into the system specifications.


D.

Development methodology employed.


Expert Solution
Questions # 131:

Which of the following should be the FIRST consideration when deciding whether data should be moved to a cloud provider for storage?

Options:

A.

Data storage costs


B.

Data classification


C.

Vendor cloud certification


D.

Service level agreements (SLAs)


Expert Solution
Questions # 132:

A company has implemented an IT segregation of duties policy. In a role-based environment, which of the following roles may be assigned to an application developer?

Options:

A.

IT operator


B.

System administration


C.

Emergency support


D.

Database administration


Expert Solution
Questions # 133:

An organization has recently acquired and implemented intelligent-agent software for granting loans to customers. During the post-implementation review, which of the following is the MOST important procedure for the IS auditor to perform?

Options:

A.

Review system and error logs to verify transaction accuracy.


B.

Review input and output control reports to verify the accuracy of the system decisions.


C.

Review signed approvals to ensure responsibilities for decisions of the system are well defined.


D.

Review system documentation to ensure completeness.


Expert Solution
Questions # 134:

Which of the following would an IS auditor find to be the GREATEST risk associated with the server room in a remote office location?

Options:

A.

The server room is secured by a key lock instead of an electronic lock.


B.

The server room ' s location is known by people who work in the area.


C.

The server room does not have temperature controls.


D.

The server room does not have biometric controls.


Expert Solution
Questions # 135:

Which of the following is the GREATEST risk when relying on reports generated by end-user computing (EUC)?

Options:

A.

Data may be inaccurate.


B.

Reports may not work efficiently.


C.

Reports may not be timely.


D.

Historical data may not be available.


Expert Solution
Questions # 136:

Which of the following will be the MOST effective method to verify that a service vendor keeps control levels as required by the client?

Options:

A.

Conduct periodic onsite assessments using agreed-upon criteria.


B.

Conduct an unannounced vulnerability assessment of the vendor’s IT systems.


C.

Periodically review the service level agreement (SLA) with the vendor.


D.

Obtain evidence of the vendor ' s control self-assessment (CSA).


Expert Solution
Questions # 137:

Which of the following is the BEST way to prevent social engineering incidents?

Options:

A.

Maintain an onboarding and annual security awareness program.


B.

Ensure user workstations are running the most recent version of antivirus software.


C.

Include security responsibilities in job descriptions and require signed acknowledgment.


D.

Enforce strict email security gateway controls


Expert Solution
Questions # 138:

An IS auditor is evaluating the access controls for a shared customer relationship management (CRM) system. Which of the following would be the GREATEST concern?

Options:

A.

Single sign-on is not enabled


B.

Audit logging is not enabled


C.

Security baseline is not consistently applied


D.

Complex passwords are not required


Expert Solution
Questions # 139:

An IS auditor has been asked to advise on measures to improve IT governance within the organization. Which of the following IS the BEST recommendation?

Options:

A.

Benchmark organizational performance against industry peers


B.

Implement key performance indicators (KPIs).


C.

Require executive management to draft IT strategy


D.

Implement annual third-party audits.


Expert Solution
Questions # 140:

Which of the following provides the MOST useful information to an IS auditor when selecting projects for inclusion in an IT audit plan?

Options:

A.

Project charter


B.

Project plan


C.

Project issue log


D.

Project business case


Expert Solution
Questions # 141:

During an exit interview, senior management disagrees with some of me facts presented m the draft audit report and wants them removed from the report. Which of the following would be the auditor ' s BEST course of action?

Options:

A.

Revise the assessment based on senior management ' s objections.


B.

Escalate the issue to audit management.


C.

Finalize the draft audit report without changes.


D.

Gather evidence to analyze senior management ' s objections


Expert Solution
Questions # 142:

Which of the following is MOST important to ensure when developing an effective security awareness program?

Options:

A.

Training personnel are information security professionals.


B.

Outcome metrics for the program are established.


C.

Security threat scenarios are included in the program content.


D.

Phishing exercises are conducted post-training


Expert Solution
Questions # 143:

Which of the following would be of GREATEST concern to an IS auditor reviewing an IT-related customer service project?

Options:

A.

The project risk exceeds the organization ' s risk appetite.


B.

Executing the project will require additional investments.


C.

Expected business value is expressed in qualitative terms.


D.

The organization will be the first to offer the proposed services.


Expert Solution
Questions # 144:

During audit framework. an IS auditor teams that employees are allowed to connect their personal devices to company-owned computers. How can the auditor BEST validate that appropriate security controls are in place to prevent data loss?

Options:

A.

Conduct a walk-through to view results of an employee plugging in a device to transfer confidential data.


B.

Review compliance with data loss and applicable mobile device user acceptance policies.


C.

Verify the data loss prevention (DLP) tool is properly configured by the organization.


D.

Verify employees have received appropriate mobile device security awareness training.


Expert Solution
Questions # 145:

An IS auditor reviewing an organization’s online payment system finds that the system sometimes duplicates payments. Which control will BEST compensate for this weakness?

Options:

A.

Using hash totals


B.

Performing a bank reconciliation


C.

Manually receipting payments


D.

Using control totals


Expert Solution
Questions # 146:

With regard to resilience, which of the following is the GREATEST risk to an organization that has implemented a new critical system?

Options:

A.

A business impact analysis (BIA) has not been performed


B.

Business data is not sanitized in the development environment


C.

There is no plan for monitoring system downtime


D.

The process owner has not signed off on user acceptance testing (UAT)


Expert Solution
Questions # 147:

The PRIMARY objective of a privacy protection policy is to increase awareness of:

Options:

A.

Cybercrimes that target an organization’s computer network.


B.

The benefits of using encryption for personal data protection.


C.

The legal requirements for protecting personal information.


D.

System configuration procedures to protect privacy.


Expert Solution
Questions # 148:

A KEY benefit of integrated auditing is that it:

Options:

A.

Facilitates the business in reviewing its control environment.


B.

Enables continuous auditing and monitoring.


C.

Improves the review of audit work by team leaders.


D.

Combines skill sets from operational, functional, and IS auditors.


Expert Solution
Questions # 149:

Which of the following audit procedures would provide the BEST assurance that an application program is functioning as designed?

Options:

A.

Using a continuous auditing module


B.

Interviewing business management


C.

Confirming accounts


D.

Reviewing program documentation


Expert Solution
Questions # 150:

An organization has decided to reengineer business processes to improve the performance of overall IT service delivery. Which of the following recommendations from the project team should be the GREATEST concern to the IS auditor?

Options:

A.

Disable operational logging to enhance the processing speed and save storage.


B.

Adopt a service delivery model based on insights from peer organizations.


C.

Delegate business decisions to the chief risk officer (CRO).


D.

Eliminate certain reports and key performance indicators (KPIs)


Expert Solution
Viewing page 3 out of 10 pages
Viewing questions 101-150 out of questions