Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CISA Questions and answers with CertsForce

Viewing page 5 out of 10 pages
Viewing questions 201-250 out of questions
Questions # 201:

When auditing the adequacy of a cooling system for a data center, which of the following is MOST important for the IS auditor to review?

Options:

A.

Environmental performance metrics


B.

Geographical location of the data center


C.

Disaster recovery plan (DRP) testing results


D.

Facilities maintenance records


Expert Solution
Questions # 202:

An IS auditor requests direct access to data required to perform audit procedures instead of asking management to provide the data Which of the following is the PRIMARY advantage of this approach?

Options:

A.

Audit transparency


B.

Data confidentiality


C.

Professionalism


D.

Audit efficiency


Expert Solution
Questions # 203:

Which of the following is an effective way to ensure the integrity of file transfers in a peer-to-peer (P2P) computing environment?

Options:

A.

Associate a message authentication code with each file transferred.


B.

Ensure the files are transferred through an intrusion detection system (IDS).


C.

Encrypt the packets shared between peers within the environment.


D.

Connect the client computers in the environment to a jump server.


Expert Solution
Questions # 204:

Which of the following is MOST important with regard to an application development acceptance test?

Options:

A.

The programming team is involved in the testing process.


B.

All data files are tested for valid information before conversion.


C.

User management approves the test design before the test is started.


D.

The quality assurance (QA) team is in charge of the testing process.


Expert Solution
Questions # 205:

An IS auditor is reviewing an organization that performs backups on local database servers every two weeks and does not have a formal policy to govern data backup and restoration procedures. Which of the following findings presents the GREATEST risk to the organization?

Options:

A.

Lack of offsite data backups


B.

Absence of a data backup policy


C.

Lack of periodic data restoration testing


D.

Insufficient data backup frequency


Expert Solution
Questions # 206:

Which of the following is MOST important to include in a business case for an IT-enabled investment?

Options:

A.

Business impact analysis (BIA)


B.

Cost-benefit analysis


C.

Security requirements


D.

Risk assessment


Expert Solution
Questions # 207:

in a controlled application development environment, the MOST important segregation of duties should be between the person who implements changes into the production environment and the:

Options:

A.

application programmer


B.

systems programmer


C.

computer operator


D.

quality assurance (QA) personnel


Expert Solution
Questions # 208:

Which of the following controls is the BEST recommendation to prevent the skimming of debit or credit card data in point of sale (POS) systems?

Options:

A.

Encryption


B.

Chip and PIN


C.

Hashing


D.

Biometric authentication


Expert Solution
Questions # 209:

Which of the following is the PRIMARY reason for an IS auditor to conduct post-implementation reviews?

Options:

A.

To determine whether project objectives in the business case have been achieved


B.

To ensure key stakeholder sign-off has been obtained


C.

To align project objectives with business needs


D.

To document lessons learned to improve future project delivery


Expert Solution
Questions # 210:

Which of the following BEST facilitates strategic program management?

Options:

A.

Implementing stage gates


B.

Establishing a quality assurance (QA) process


C.

Aligning projects with business portfolios


D.

Tracking key project milestones


Expert Solution
Questions # 211:

When reviewing past results of a recurring annual audit, an IS auditor notes that findings may not have been reported and independence may not have been maintained. Which of the following is the auditor ' s BEST course of action?

Options:

A.

Inform senior management.


B.

Reevaluate internal controls.


C.

Inform audit management.


D.

Re-perform past audits to ensure independence.


Expert Solution
Questions # 212:

An organization ' s enterprise architecture (EA) department decides to change a legacy system ' s components while maintaining its original functionality. Which of the following is MOST important for an IS auditor to understand when reviewing this decision?

Options:

A.

The current business capabilities delivered by the legacy system


B.

The proposed network topology to be used by the redesigned system


C.

The data flows between the components to be used by the redesigned system


D.

The database entity relationships within the legacy system


Expert Solution
Questions # 213:

Which of the following should an IS auditor expect to see in a network vulnerability assessment?

Options:

A.

Misconfiguration and missing updates


B.

Malicious software and spyware


C.

Zero-day vulnerabilities


D.

Security design flaws


Expert Solution
Questions # 214:

Which of the following methods BEST enforces data leakage prevention in a multi-tenant cloud environment?

Options:

A.

Monitoring tools are configured to alert in case of downtime


B.

A comprehensive security review is performed every quarter.


C.

Data for different tenants is segregated by database schema


D.

Tenants are required to implement data classification polices


Expert Solution
Questions # 215:

Which of the following findings related to segregation of duties should be of GREATEST concern to an IS auditor?

Options:

A.

The person who tests source code also approves changes.


B.

The person who administers servers is also part of the infrastructure management team.


C.

The person who creates new user accounts also modifies user access levels.


D.

The person who edits source code also has write access to production.


Expert Solution
Questions # 216:

Which of the following is MOST important to consider when defining disaster recovery strategies?

Options:

A.

Maximum tolerable downtime (MTD)


B.

Mean time to restore (MTTR)


C.

Mean time to acknowledge


D.

Maximum time between failures (MTBF)


Expert Solution
Questions # 217:

Which of the following is PRIMARILY used in blockchain technology to create a distributed immutable ledger?

Options:

A.

Artificial intelligence (Al)


B.

Application hardening


C.

Edge computing


D.

Encryption


Expert Solution
Questions # 218:

Which of the following application input controls would MOST likely detect data input errors in the customer account number field during the processing of an accounts receivable transaction?

Options:

A.

Limit check


B.

Parity check


C.

Reasonableness check


D.

Validity check


Expert Solution
Questions # 219:

An IS auditor believes that management has accepted a level of residual risk that is not appropriate for the organization. Which of the following is the auditor’s MOST appropriate course of action?

Options:

A.

Submit a report informing the board of management’s decision to accept the risk.


B.

Discuss the matter with IS audit management and executive management.


C.

Include management’s response to accept the risk in the audit report and take no further action.


D.

Include the risk as a finding in the audit report but do not note management’s risk acceptance.


Expert Solution
Questions # 220:

Which of the following would a digital signature MOST likely prevent?

Options:

A.

Repudiation


B.

Unauthorized change


C.

Corruption


D.

Disclosure


Expert Solution
Questions # 221:

Which of the following IT service management activities is MOST likely to help with identifying the root cause of repeated instances of network latency?

Options:

A.

Change management


B.

Problem management


C.

incident management


D.

Configuration management


Expert Solution
Questions # 222:

When processing speed is the highest priority, which cryptographic algorithm should be used to verify the integrity of a bit-for-bit copy from digital evidence?

Options:

A.

MD5


B.

SHA-1


C.

AES


D.

SHA-2


Expert Solution
Questions # 223:

Which of the following would be the BEST process for continuous auditing to a large financial Institution?

Options:

A.

Testing encryption standards on the disaster recovery system


B.

Validating access controls for real-time data systems


C.

Performing parallel testing between systems


D.

Validating performance of help desk metrics


Expert Solution
Questions # 224:

Which of the following is the PRIMARY advantage of using an automated security log monitoring tool instead of conducting a manual review to monitor the use of privileged access?

Options:

A.

Reduced costs associated with automating the review


B.

Increased likelihood of detecting suspicious activity


C.

Ease of storing and maintaining log file


D.

Ease of log retrieval for audit purposes


Expert Solution
Questions # 225:

Which of the following is the PRIMARY reason an IS auditor should discuss observations with management before delivering a final report?

Options:

A.

Validate the audit observations_


B.

Identify business risks associated with the observations.


C.

Assist the management with control enhancements.


D.

Record the proposed course of corrective action.


Expert Solution
Questions # 226:

When auditing the alignment of IT to the business strategy, it is MOST Important for the IS auditor to:

Options:

A.

compare the organization ' s strategic plan against industry best practice.


B.

interview senior managers for their opinion of the IT function.


C.

ensure an IT steering committee is appointed to monitor new IT projects.


D.

evaluate deliverables of new IT initiatives against planned business services.


Expert Solution
Questions # 227:

Providing security certification for a new system should include which of the following prior to the system ' s implementation?

Options:

A.

End-user authorization to use the system in production


B.

External audit sign-off on financial controls


C.

Testing of the system within the production environment


D.

An evaluation of the configuration management practices


Expert Solution
Questions # 228:

A month after a company purchased and implemented system and performance monitoring software, reports were too large and therefore were not reviewed or acted upon The MOST effective plan of action would be to:

Options:

A.

evaluate replacement systems and performance monitoring software.


B.

restrict functionality of system monitoring software to security-related events.


C.

re-install the system and performance monitoring software.


D.

use analytical tools to produce exception reports from the system and performance monitoring software


Expert Solution
Questions # 229:

Which type of testing is used to identify security vulnerabilities in source code in the development environment?

Options:

A.

Interactive application security testing (IAST)


B.

Runtime application self-protection (RASP)


C.

Dynamic analysis security testing (DAST)


D.

Static analysis security testing (SAST)


Expert Solution
Questions # 230:

Which of following areas is MOST important for an IS auditor to focus on when reviewing the maturity model for a technology organization?

Options:

A.

Standard operating procedures


B.

Service level agreements (SLAs)


C.

Roles and responsibility matrix


D.

Business resiliency


Expert Solution
Questions # 231:

An IS auditor observes that a business-critical application does not currently have any level of fault tolerance. Which of the following is the GREATEST concern with this situation?

Options:

A.

Degradation of services


B.

Limited tolerance for damage


C.

Decreased mean time between failures (MTBF)


D.

Single point of failure


Expert Solution
Questions # 232:

Which of the following would be of GREATEST concern to an IS auditor evaluating an organization’s change management process?

Options:

A.

Change management meeting minutes are not available for several meetings.


B.

Change requests are not subject to prioritization.


C.

Changes are approved after being moved to production.


D.

A list of authorized requestors for emergency changes does not exist.


Expert Solution
Questions # 233:

What is the BEST way to reduce the risk of inaccurate or misleading data proliferating through business intelligence systems?

Options:

A.

Establish rules for converting data from one format to another


B.

Implement data entry controls for new and existing applications


C.

Implement a consistent database indexing strategy


D.

Develop a metadata repository to store and access metadata


Expert Solution
Questions # 234:

Which of the following should be of GREATEST concern to an IS auditor when auditing an organization ' s IT strategy development process?

Options:

A.

The IT strategy was developed before the business plan


B.

A business impact analysis (BIA) was not performed to support the IT strategy


C.

The IT strategy was developed based on the current IT capability


D.

Information security was not included as a key objective m the IT strategic plan.


Expert Solution
Questions # 235:

Which of the following would BEST enable an organization to address the security risks associated with a recently implemented bring your own device (BYOD) strategy?

Options:

A.

Mobile device tracking program


B.

Mobile device upgrade program


C.

Mobile device testing program


D.

Mobile device awareness program


Expert Solution
Questions # 236:

An organizations audit charier PRIMARILY:

Options:

A.

describes the auditors ' authority to conduct audits.


B.

defines the auditors ' code of conduct.


C.

formally records the annual and quarterly audit plans.


D.

documents the audit process and reporting standards.


Expert Solution
Questions # 237:

An organization has moved all of its infrastructure to the cloud. Which of the following would be an IS auditor’s GREATEST concern related to the organization’s ability to continue operations in case of a disaster?

Options:

A.

There is no evidence that disaster recovery plan (DRP) testing was performed after the migration.


B.

Only business-critical servers were configured with redundancy services on the cloud service provider.


C.

The previous infrastructure was not retained to support business operations in case of a disaster.


D.

The step-by-step recovery process was not updated in the disaster recovery plan (DRP) after the migration.


Expert Solution
Questions # 238:

Which of the following is a PRIMARY responsibility of a quality assurance (QA) team?

Options:

A.

Creating test data to facilitate the user acceptance testing (IJAT) process


B.

Managing employee onboarding processes and background checks


C.

Advising the steering committee on quality management issues and remediation efforts


D.

Implementing procedures to facilitate adoption of quality management best practices


Expert Solution
Questions # 239:

Which of the following is the GREATEST benefit of an effective data classification process?

Options:

A.

Data custodians are identified.


B.

Data retention periods are well defined


C.

Data is protected according to its sensitivity


D.

Appropriate ownership over data is assigned


Expert Solution
Questions # 240:

To help determine whether a controls-reliant approach to auditing financial systems in a company should be used, which sequence of IS audit work is MOST appropriate?

Options:

A.

Review of the general IS controls followed by a review of the application controls


B.

Detailed examination of financial transactions followed by review of the general ledger


C.

Review of major financial applications followed by a review of IT governance processes


D.

Review of application controls followed by a test of key business process controls


Expert Solution
Questions # 241:

Which of the following is the BEST way to strengthen the security of smart devices to prevent data leakage?

Options:

A.

Enforce strong security settings on smart devices.


B.

Require employees to formally acknowledge security procedures.


C.

Review access logs to the organization ' s sensitive data in a timely manner.


D.

Include usage restrictions in bring your own device (BYOD) security procedures.


Expert Solution
Questions # 242:

An IS auditor finds that some employees are using public cloud-based AI tools. Which of the following presents the GREATEST concern?

Options:

A.

Data reliability


B.

Cost overruns


C.

Copyright infringements


D.

Data leakage


Expert Solution
Questions # 243:

Which of the following would be of GREATEST concern to an IS auditor reviewing an IT strategy document?

Options:

A.

The previous year’s IT strategic goals were not achieved.


B.

Target architecture is defined at a technical level.


C.

Financial estimates of new initiatives are disclosed within the document.


D.

Strategic IT goals are derived solely from the latest market trends.


Expert Solution
Questions # 244:

An emergency power-off switch should:

Options:

A.

be protected.


B.

be remotely accessible.


C.

be under dual control.


D.

not be identified.


Expert Solution
Questions # 245:

An IS auditor is reviewing an organization ' s business continuity plan (BCP) following a change in organizational structure with significant impact to business processes. Which of the following findings should be the auditor ' s GREATEST concern?

Options:

A.

Key business process end users did not participate in the business impact " analysis (BIA)


B.

Copies of the BCP have not been distributed to new business unit end users sjnce the reorganization


C.

A test plan for the BCP has not been completed during the last two years


Expert Solution
Questions # 246:

An IS auditor finds that periodic reviews of read-only users for a reporting system are not being performed. Which of the following should be the IS auditor ' s NEXT course of action?

Options:

A.

Review the list of end users and evaluate for authorization.


B.

Report this control process weakness to senior management.


C.

Verify managements approval for this exemption


D.

Obtain a verbal confirmation from IT for this exemption.


Expert Solution
Questions # 247:

A security review focused on data loss prevention (DLP) revealed the organization has no visibility to data stored in the cloud. What is the IS auditor ' s BEST recommendation to address this

issue?

Options:

A.

Enhance the firewall at the network perimeter.


B.

Implement a file system scanner to discover data stored in the cloud.


C.

Employ a cloud access security broker (CASB).


D.

Utilize a DLP tool on desktops to monitor user activities.


Expert Solution
Questions # 248:

A review of an organization’s IT portfolio revealed several applications that are not in use. The BEST way to prevent this situation from recurring would be to implement.

Options:

A.

A formal request for proposal (RFP) process


B.

Business case development procedures


C.

An information asset acquisition policy


D.

Asset life cycle management.


Expert Solution
Questions # 249:

Which of the following is the MOST likely root cause of shadow IT in an organization?

Options:

A.

Lengthy approval for technology investment


B.

The opportunity to reduce software license fees


C.

Ease of use for cloud-based applications and services


D.

Approved software not meeting user requirements


Expert Solution
Questions # 250:

Which of the following access rights presents the GREATEST risk when granted to a new member of the system development staff?

Options:

A.

Write access to production program libraries


B.

Write access to development data libraries


C.

Execute access to production program libraries


D.

Execute access to development program libraries


Expert Solution
Viewing page 5 out of 10 pages
Viewing questions 201-250 out of questions