Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CISA Questions and answers with CertsForce

Viewing page 4 out of 10 pages
Viewing questions 151-200 out of questions
Questions # 151:

An external attacker spoofing an internal Internet Protocol (IP) address can BEST be detected by which of the following?

Options:

A.

Comparing the source address to the domain name server (DNS) entry


B.

Using static IP addresses for identification


C.

Comparing the source address to the interface used as the entry point


D.

Using a state table to compare the message states of each packet as it enters the system


Expert Solution
Questions # 152:

Which of the following would BEST facilitate the successful implementation of an IT-related framework?

Options:

A.

Aligning the framework to industry best practices


B.

Establishing committees to support and oversee framework activities


C.

Involving appropriate business representation within the framework


D.

Documenting IT-related policies and procedures


Expert Solution
Questions # 153:

Which of the following is an example of a passive attack method?

Options:

A.

Keystroke logging


B.

Piggybacking


C.

Eavesdropping


D.

Phishing


Expert Solution
Questions # 154:

During a follow-up audit, an IS auditor finds that some critical recommendations have the IS auditor ' s BEST course of action?

Options:

A.

Require the auditee to address the recommendations in full.


B.

Adjust the annual risk assessment accordingly.


C.

Evaluate senior management ' s acceptance of the risk.


D.

Update the audit program based on management ' s acceptance of risk.


Expert Solution
Questions # 155:

Which of the following provides the BE ST method for maintaining the security of corporate applications pushed to employee-owned mobile devices?

Options:

A.

Enabling remote data destruction capabilities


B.

Implementing mobile device management (MDM)


C.

Disabling unnecessary network connectivity options


D.

Requiring security awareness training for mobile users


Expert Solution
Questions # 156:

Which of the following provides the MOST assurance over the completeness and accuracy ol loan application processing with respect to the implementation of a new system?

Options:

A.

Comparing code between old and new systems


B.

Running historical transactions through the new system


C.

Reviewing quality assurance (QA) procedures


D.

Loading balance and transaction data to the new system


Expert Solution
Questions # 157:

Which of the following is the BEST indication that a software development project is on track to meet its completion deadline?

Options:

A.

Technical specifications and development requirements have been agreed upon and formally recorded.


B.

Project plan due dates have been documented for each phase of the software development life cycle.


C.

Issues identified during user acceptance testing (UAT) have been addressed prior to the original implementation date.


D.

The planned software go-live date has been communicated in advance to end users and stakeholders.


Expert Solution
Questions # 158:

Which of the following is found in an audit charter?

Options:

A.

The process of developing the annual audit plan


B.

The authority given to the audit function


C.

Required training for audit staff


D.

Audit objectives and scope


Expert Solution
Questions # 159:

Malicious program code was found in an application and corrected prior to release into production. After the release, the same issue was reported. Which of the following is the IS auditor ' s BEST recommendation?

Options:

A.

Ensure corrected program code is compiled in a dedicated server.


B.

Ensure change management reports are independently reviewed.


C.

Ensure programmers cannot access code after the completion of program edits.


D.

Ensure the business signs off on end-to-end user acceptance test (UAT) results.


Expert Solution
Questions # 160:

Some control activities have been found to be only partially compliant with the design of the control. Which of the following is an IS auditor’s PRIMARY course of action?

Options:

A.

Recommend redesigning control activities to ensure acceptance by users.


B.

Evaluate the impact of the partial compliance.


C.

Discuss partial compliance with control owners.


D.

Include each instance of partial compliance as a finding in the final audit report.


Expert Solution
Questions # 161:

Which of the following is MOST helpful in identifying system performance constraints?

Options:

A.

Security logs


B.

Directory service logs


C.

Proxy logs


D.

Operational logs


Expert Solution
Questions # 162:

An IS auditor is assigned to perform a post-implementation review of an application system. Which of the following would impair the auditor’s independence?

Options:

A.

The auditor implemented a specific control during the development of the system.


B.

The auditor participated as a member of the project team without operational responsibilities.


C.

The auditor provided advice concerning best practices.


D.

The auditor designed an embedded audit module exclusively for audit.


Expert Solution
Questions # 163:

The following findings are the result of an IS auditor’s post-implementation review of a newly implemented system. Which of the following findings is of GREATEST significance?

Options:

A.

A lessons learned session was never conducted.


B.

Monthly dashboards did not always contain deliverables.


C.

The project’s 10% budget overrun was not reported to senior management.


D.

Measurable benefits were not defined.


Expert Solution
Questions # 164:

An IS auditor should ensure that an application ' s audit trail:

Options:

A.

has adequate security.


B.

logs ail database records.


C.

Is accessible online


D.

does not impact operational efficiency


Expert Solution
Questions # 165:

An incident response team has been notified of a virus outbreak in a network subnet. Which of the following should be the NEXT step?

Options:

A.

Focus on limiting the damage.


B.

Remove and restore the affected systems.


C.

Verify that the compromised systems are fully functional.


D.

Document the incident.


Expert Solution
Questions # 166:

Which of the following is the MOST important course of action to ensure a cloud access security broker (CASB) effectively detects and responds to threats?

Options:

A.

Monitoring data movement


B.

Implementing a long-term CASB contract


C.

Reviewing the information security policy


D.

Evaluating firewall effectiveness


Expert Solution
Questions # 167:

What would be an IS auditor ' s BEST course of action when an auditee is unable to close all audit recommendations by the time of the follow-up audit?

Options:

A.

Ensure the open issues are retained in the audit results.


B.

Terminate the follow-up because open issues are not resolved


C.

Recommend compensating controls for open issues.


D.

Evaluate the residual risk due to open issues.


Expert Solution
Questions # 168:

Which of the following is MOST helpful to an IS auditor reviewing the alignment of planned IT budget with the organization ' s goals and strategic objectives?

Options:

A.

Enterprise architecture (EA)


B.

Business impact analysis (BIA)


C.

Risk assessment report


D.

Audit recommendations


Expert Solution
Questions # 169:

The BEST way to determine whether programmers have permission to alter data in the production environment is by reviewing:

Options:

A.

the access control system ' s log settings.


B.

how the latest system changes were implemented.


C.

the access control system ' s configuration.


D.

the access rights that have been granted.


Expert Solution
Questions # 170:

Which of the following findings from a network security review presents the GREATEST risk to the organization?

Options:

A.

There are shared administrator accounts on internet-facing routers.


B.

An internet server in the demilitarized zone (DMZ) hosts a test web page.


C.

Operating system patches released last week have not been applied.


D.

The intrusion detection system (IDS) has pending updates from within the last week.


Expert Solution
Questions # 171:

An organization implemented a cybersecurity policy last year Which of the following is the GREATE ST indicator that the policy may need to be revised?

Options:

A.

A significant increase in authorized connections to third parties


B.

A significant increase in cybersecurity audit findings


C.

A significant increase in approved exceptions


D.

A significant increase in external attack attempts


Expert Solution
Questions # 172:

An IS auditor is reviewing the installation of a new server. The IS auditor ' s PRIMARY objective is to ensure that

Options:

A.

security parameters are set in accordance with the manufacturer s standards.


B.

a detailed business case was formally approved prior to the purchase.


C.

security parameters are set in accordance with the organization ' s policies.


D.

the procurement project invited lenders from at least three different suppliers.


Expert Solution
Questions # 173:

Which of the following is the GREATEST concern associated with a high number of IT policy exceptions approved by management?

Options:

A.

The exceptions are likely to continue indefinitely.


B.

The exceptions may result in noncompliance.


C.

The exceptions may elevate the level of operational risk.


D.

The exceptions may negatively impact process efficiency.


Expert Solution
Questions # 174:

An IS auditor has discovered that a software system still in regular use is years out of date and no longer supported. The auditee has stated that it will take six months until the software is running on the current version. Which of the following is the BEST way to reduce the immediate risk associated with using an unsupported version of the software?

Options:

A.

Verify all patches have been applied to the software system ' s outdated version.


B.

Close all unused ports on the outdated software system.


C.

Monitor network traffic attempting to reach the outdated software system.


D.

Segregate the outdated software system from the main network.


Expert Solution
Questions # 175:

Using swipe cards to limit employee access to restricted areas requires implementing which additional control?

Options:

A.

Physical sign-in of all employees for access to restricted areas


B.

Implementation of additional PIN pads


C.

Periodic review of access profiles by management


D.

Installation of closed-circuit television (CCTV)


Expert Solution
Questions # 176:

Which of the following is a threat to IS auditor independence?

Options:

A.

Internal auditors share the audit plan and control test plans with management prior to audit commencement.


B.

Internal auditors design remediation plans to address control gaps identified by internal audit.


C.

Internal auditors attend IT steering committee meetings.


D.

Internal auditors recommend appropriate controls for systems in development.


Expert Solution
Questions # 177:

Which of the following should be of MOST concern to an IS auditor reviewing the information systems acquisition, development, and implementation process?

Options:

A.

Data owners are not trained on the use of data conversion tools.


B.

A post-implementation lessons-learned exercise was not conducted.


C.

There is no system documentation available for review.


D.

System deployment is routinely performed by contractors.


Expert Solution
Questions # 178:

An organization is implementing a new system that supports a month-end business process. Which of the following implementation strategies would be MOST efficient to decrease business downtime?

Options:

A.

Big bang


B.

Phased


C.

Cutover


D.

Parallel


Expert Solution
Questions # 179:

Which of the following would be of GREATEST concern to an IS auditor reviewing the resiliency of an organizational network that has two internet connections?

Options:

A.

Network capacity testing has not been performed.


B.

The business continuity plan (BCP) has not been tested in the past six months.


C.

Non-critical applications are also connected to both connections.


D.

Both connections are from the same provider.


Expert Solution
Questions # 180:

Which of the following is the GREATEST risk associated with utilizing spreadsheets for financial reporting in end-user computing (EUC)?

Options:

A.

Lack of password protection


B.

Lack of processing integrity


C.

Increase in regulatory violations


D.

Increase in operational incidents


Expert Solution
Questions # 181:

Which of the following issues identified during a formal review of an organization ' s information security policies presents the GREATEST potential risk to the organization?

Options:

A.

The policies are not available to key risk stakeholders.


B.

The policies have not been reviewed by the risk management committee.


C.

The policies are not aligned with the information security risk appetite.


D.

The policies are not based on industry best practices for information security.


Expert Solution
Questions # 182:

Which of the following is MOST important to ensure successful implementation when an organization decides to purchase software from available products on the market?

Options:

A.

Requirements definition


B.

Post-implementation review


C.

Support and maintenance contract


D.

Software escrow


Expert Solution
Questions # 183:

An IS auditor wants to gain a better understanding of an organization’s selected IT operating system software. Which of the following would be MOST helpful to review?

Options:

A.

Service level agreements (SLAs)


B.

Project steering committee charter


C.

IT audit reports


D.

Enterprise architecture (EA)


Expert Solution
Questions # 184:

An IS auditor is reviewing processes for importing market price data from external data providers. Which of the following findings should the auditor consider MOST critical?

Options:

A.

The transfer protocol does not require authentication.


B.

The quality of the data is not monitored.


C.

Imported data is not disposed of frequently.


D.

The transfer protocol is not encrypted.


Expert Solution
Questions # 185:

Which of the following is MOST helpful to an IS auditor when assessing the effectiveness of controls?

Options:

A.

A control self-assessment (CSA)


B.

Results of control testing


C.

Interviews with management


D.

A control matrix


Expert Solution
Questions # 186:

An IS auditor is assigned to perform a post-implementation review of an application system. Which of the following would impair the auditor ' s independence?

Options:

A.

The auditor implemented a specific control during the development of the system.


B.

The auditor provided advice concerning best practices.


C.

The auditor participated as a member of the project team without operational responsibilities


D.

The auditor designed an embedded audit module exclusively for audit


Expert Solution
Questions # 187:

Which of the following should be the role of internal audit in an organization’s move to the cloud?

Options:

A.

Mitigating risk to an acceptable level.


B.

Assessing key controls that support the migration.


C.

Implementing security controls for data prior to migration.


D.

Identifying impacts to organizational budgets and resources.


Expert Solution
Questions # 188:

When an organization conducts business process improvements, the IS auditor should be MOST concerned with the:

Options:

A.

metrics used to evaluate key operating segments.


B.

adequacy of the controls in the redesigned process.


C.

adequacy of reporting to senior management.


D.

lack of version control over process documentation.


Expert Solution
Questions # 189:

An IS auditor is assessing an organization ' s DevSecOps approach. Which of the following BEST indicates a proactive approach to identifying vulnerabilities?

Options:

A.

Integration of automated security testing tools into the continuous integration/continuous delivery (CI/CD) process


B.

Open-source dependency checks within continuous integration/continuous delivery (CI/CD) process


C.

Use of the most current development frameworks and libraries


D.

Post-implementation vulnerability scans on application deployments


Expert Solution
Questions # 190:

What is the BEST control to address SQL injection vulnerabilities?

Options:

A.

Unicode translation


B.

Secure Sockets Layer (SSL) encryption


C.

Input validation


D.

Digital signatures


Expert Solution
Questions # 191:

An organization is implementing a data loss prevention (DLP) system in response to a new regulatory requirement Reviewing. which of the following would be MOST helpful in evaluating the system ' s design?

Options:

A.

System manuals


B.

Enterprise architecture (EA)


C.

Historical record of data breaches


D.

Industry trends


Expert Solution
Questions # 192:

The business case for an information system investment should be available for review until the:

Options:

A.

information system investment is retired.


B.

information system has reached end of life.


C.

formal investment decision is approved.


D.

benefits have been fully realized.


Expert Solution
Questions # 193:

An IS auditor has been asked to review the integrity of data transfer between two business-critical systems that have not been tested since implementation. Which of the following would provide the MOST useful information to plan an audit?

Options:

A.

Quality assurance (QA) testing


B.

System change logs


C.

IT testing policies and procedures


D.

Previous system interface testing records


Expert Solution
Questions # 194:

Which of the following observations should be of GREATEST concern to an IS auditor performing an audit of change and release management controls for a new complex system developed by a small in-house IT team?

Options:

A.

Access to change testing strategy and results is not restricted to staff outside the IT team.


B.

Some user acceptance testing (IJAT) was completed by members of the IT team.


C.

IT administrators have access to the production and development environment


D.

Post-implementation testing is not conducted for all system releases.


Expert Solution
Questions # 195:

Which of the following is the PRIMARY purpose of enterprise architecture (EA) within an organization?

Options:

A.

To design and implement individual IT systems


B.

To oversee network security protocols


C.

To design and manage day-to-day IT operations


D.

To structure IT projects to achieve desired business results


Expert Solution
Questions # 196:

Which of the following BEST demonstrates that IT strategy Is aligned with organizational goals and objectives?

Options:

A.

IT strategies are communicated to all Business stakeholders


B.

Organizational strategies are communicated to the chief information officer (CIO).


C.

Business stakeholders are Involved In approving the IT strategy.


D.

The chief information officer (CIO) is involved In approving the organizational strategies


Expert Solution
Questions # 197:

A source code repository should be designed to:

Options:

A.

prevent changes from being incorporated into existing code.


B.

prevent developers from accessing secure source code.


C.

provide secure versioning and backup capabilities for existing code.


D.

provide automatic incorporation and distribution of modified code.


Expert Solution
Questions # 198:

An IS auditor discovers that due to resource constraints a database administrator (DBA) is responsible for developing and executing changes into the production environment Which ot the following should the auditor do FIRSTS

Options:

A.

Determine whether another DBA could make the changes


B.

Report a potential segregation of duties violation


C.

identify whether any compensating controls exist


D.

Ensure a change management process is followed prior to implementation


Expert Solution
Questions # 199:

Which of the following is the MOST effective control over visitor access to highly secured areas?

Options:

A.

Visitors are required to be escorted by authorized personnel.


B.

Visitors are required to use biometric authentication.


C.

Visitors are monitored online by security cameras


D.

Visitors are required to enter through dead-man doors.


Expert Solution
Questions # 200:

Following a discussion on the results of a recent audit engagement, the process owner of the audited area has provided an action plan addressing the gaps and recommendations. The auditor disagrees with some of the responses where the process owner is accepting a level of residual risk that is not within the organization’s risk appetite. What is the auditor’s BEST course of action?

Options:

A.

Escalate the situation to audit management.


B.

Accept the action plan proposed by the process owner.


C.

Include the issue in the next report to the audit committee.


D.

Inform executive management of the residual risk.


Expert Solution
Viewing page 4 out of 10 pages
Viewing questions 151-200 out of questions