Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CISA Questions and answers with CertsForce

Viewing page 6 out of 10 pages
Viewing questions 251-300 out of questions
Questions # 251:

Which of the following activities should be separated in an organization’s incident management processes?

Options:

A.

Initiating and closing error logs


B.

Collecting and analyzing logs from devices


C.

Identifying root causes and recommending workarounds


D.

Recording and classifying incidents


Expert Solution
Questions # 252:

During a follow-up audit, an IS auditor learns that management has deferred the implementation of a previously agreed-upon recommendation. What is the responsibility of the auditor?

Options:

A.

Assess the impact of any risks the decision may pose to the organization.


B.

Amend the final report to reflect the decision to defer the implementation.


C.

Obtain commitment from management to implement the recommendation.


D.

Report the decision to defer the implementation to the steering committee.


Expert Solution
Questions # 253:

Which of the following is the BEST data integrity check?

Options:

A.

Counting the transactions processed per day


B.

Performing a sequence check


C.

Tracing data back to the point of origin


D.

Preparing and running test data


Expert Solution
Questions # 254:

What is the PRIMARY benefit of using one-time passwords?

Options:

A.

An intercepted password cannot be reused


B.

Security for applications can be automated


C.

Users do not have to memorize complex passwords


D.

Users cannot be locked out of an account


Expert Solution
Questions # 255:

An organization plans to centrally decommission end-of-life databases and migrate the data to the latest model of hardware. Which of the following BEST ensures data integrity is preserved during the migration?

Options:

A.

Reconciling sample data to most recent backups


B.

Obfuscating confidential data


C.

Encrypting the data


D.

Comparing checksums


Expert Solution
Questions # 256:

An organization is concerned with meeting new regulations for protecting data confidentiality and asks an IS auditor to evaluate their procedures for transporting data. Which of the

following would BEST support the organization ' s objectives?

Options:

A.

Cryptographic hashes


B.

Virtual local area network (VLAN)


C.

Encryption


D.

Dedicated lines


Expert Solution
Questions # 257:

Which of the following is the PRIMARY reason to involve IS auditors in the software acquisition process?

Options:

A.

To help ensure hardware and operating system requirements are considered


B.

To help ensure proposed contracts and service level agreements (SLAs) address key elements


C.

To help ensure the project management process complies with policies and procedures


D.

To help ensure adequate controls to address common threats and risks are considered


Expert Solution
Questions # 258:

Which of the following is MOST important to include when developing a business continuity plan (BCP)?

Options:

A.

Criteria for triggering the plan


B.

Details of linked security policies


C.

Details of a comprehensive asset inventory


D.

Plans for addressing all types of threats


Expert Solution
Questions # 259:

Which of the following should be of MOST concern to an IS auditor reviewing an organization ' s operational log management?

Options:

A.

Log file size has grown year over year.


B.

Critical events are being logged to immutable log files.


C.

Applications are logging events into multiple log files.


D.

Data formats have not been standardized across all logs.


Expert Solution
Questions # 260:

Data centers that want to prevent unauthorized personnel from entering during a power outage should ensure external access doors:

Options:

A.

Have physical key backup.


B.

Operate in fail-safe mode.


C.

Operate in fail-secure mode.


D.

Are alarmed and monitored.


Expert Solution
Questions # 261:

Which of the following controls BEST provides confidentiality and nonrepudiation for an online business looking for digital payment data security?

Options:

A.

Data Encryption Standard (DES)


B.

Advanced Encryption Standard (AES)


C.

Public Key Infrastructure (PKI)


D.

Virtual Private Network (VPN)


Expert Solution
Questions # 262:

Which of the following is the MOST important consideration when evaluating the data retention policy for a global organization with regional offices in multiple countries?

Options:

A.

The policy aligns with corporate policies and practices.


B.

The policy aligns with global best practices.


C.

The policy aligns with business goals and objectives.


D.

The policy aligns with local laws and regulations.


Expert Solution
Questions # 263:

Which of the following applications should an IS auditor consider to be the HIGHEST priority when reviewing disaster recovery planning (DRP) tests for an commerce company?

Options:

A.

An application for IT performance monitoring


B.

An application for HR management


C.

An application for financial management


D.

An application for traffic load balancing


Expert Solution
Questions # 264:

Which of the following is the PRIMARY basis on which audit objectives are established?

Options:

A.

Audit risk


B.

Consideration of risks


C.

Assessment of prior audits


D.

Business strategy


Expert Solution
Questions # 265:

A web proxy server for corporate connections to external resources reduces organizational risk by:

Options:

A.

anonymizing users through changed IP addresses.


B.

providing multi-factor authentication for additional security.


C.

providing faster response than direct access.


D.

load balancing traffic to optimize data pathways.


Expert Solution
Questions # 266:

Which of the following is the PRIMARY benefit of performing periodic maturity model assessments?

Options:

A.

It acts as a measuring tool and progress indicator.


B.

It identifies and fixes attribute weaknesses.


C.

It facilitates the execution of an improvement plan.


D.

It ensures organizational consistency and improvement.


Expert Solution
Questions # 267:

Which type of control has been established when an organization implements a security information and event management (SIEM) system?

Options:

A.

Preventive


B.

Detective


C.

Directive


D.

Corrective


Expert Solution
Questions # 268:

Which of the following should be the PRIMARY objective of a disaster recovery plan (DRP)?

Options:

A.

Minimizing loss of information


B.

Assessing the risk of key applications


C.

Identifying key business processes


D.

Documenting all IT assets


Expert Solution
Questions # 269:

While auditing a small organization ' s data classification processes and procedures, an IS auditor noticed that data is often classified at the incorrect level. What is the MOST effective way for the organization to improve this situation?

Options:

A.

Use automatic document classification based on content.


B.

Have IT security staff conduct targeted training for data owners.


C.

Publish the data classification policy on the corporate web portal.


D.

Conduct awareness presentations and seminars for information classification policies.


Expert Solution
Questions # 270:

Which of the following BEST ensures that effective change management is in place in an IS environment?

Options:

A.

User authorization procedures for application access are well established.


B.

User-prepared detailed test criteria for acceptance testing of the software.


C.

Adequate testing was carried out by the development team.


D.

Access to production source and object programs is well controlled.


Expert Solution
Questions # 271:

Which of the following is the BEST method to delete sensitive information from storage media that will be reused?

Options:

A.

Cross-cut shredding.


B.

Multiple overwriting.


C.

Repartitioning.


D.

Reformatting.


Expert Solution
Questions # 272:

An IS auditor discovers that validation controls in a web application have been moved from the server side into the browser to boost performance. This would MOST likely increase the risk of a successful attack by:

Options:

A.

structured query language (SQL) injection


B.

buffer overflow.


C.

denial of service (DoS).


D.

phishing.


Expert Solution
Questions # 273:

Which of the following concerns is MOST effectively addressed by implementing an IT framework for alignment between IT and business objectives?

Options:

A.

Inaccurate business impact analysis (BIA)


B.

Inadequate IT change management practices


C.

Lack of a benchmark analysis


D.

Inadequate IT portfolio management


Expert Solution
Questions # 274:

An IS auditor wants to inspect recent events in a system to observe failed authentications and password changes. Which of the following is the MOST appropriate method to use for this purpose?

Options:

A.

Penetration testing


B.

Authenticated scanning


C.

Change management records


D.

System log review


Expert Solution
Questions # 275:

Which of the following is MOST important to ensure when planning a black box penetration test?

Options:

A.

The management of the client organization is aware of the testing.


B.

The test results will be documented and communicated to management.


C.

The environment and penetration test scope have been determined.


D.

Diagrams of the organization ' s network architecture are available.


Expert Solution
Questions # 276:

Which of the following is an IS auditor ' s BEST recommendation to mitigate the risk of eavesdropping

associated with an application programming interface (API) integration implementation?

Options:

A.

Encrypt the extensible markup language (XML) file.


B.

Implement Transport Layer Security (TLS).


C.

Implement Simple Object Access Protocol (SOAP).


D.

Mask the API endpoints.


Expert Solution
Questions # 277:

Which of the following approaches BEST enables an IS auditor to detect security vulnerabilities within an application?

Options:

A.

Threat modeling


B.

Concept mapping


C.

Prototyping


D.

Threat intelligence


Expert Solution
Questions # 278:

Which of the following provides an IS auditor the BEST evidence that a third-party service provider ' s information security controls are effective?

Options:

A.

Documentation of the service provider’s security configuration controls


B.

A review of the service provider ' s policies and procedures


C.

An audit report of the controls by an external auditor


D.

An interview with the service provider ' s senior management


Expert Solution
Questions # 279:

Which of the following is the MOST important consideration for patching mission critical business application servers against known vulnerabilities?

Options:

A.

Patches are implemented in a test environment prior to rollout into production.


B.

Network vulnerability scans are conducted after patches are implemented.


C.

Vulnerability assessments are periodically conducted according to defined schedules.


D.

Roles and responsibilities for implementing patches are defined


Expert Solution
Questions # 280:

A system development project is experiencing delays due to ongoing staff shortages. Which of the following strategies would provide the GREATEST assurance of system quality at implementation?

Options:

A.

Implement overtime pay and bonuses for all development staff.


B.

Utilize new system development tools to improve productivity.


C.

Recruit IS staff to expedite system development.


D.

Deliver only the core functionality on the initial target date.


Expert Solution
Questions # 281:

An IS auditor learns the organization has experienced several server failures in its distributed environment. Which of the following is the BEST recommendation to limit the potential impact of server failures in the future?

Options:

A.

Redundant pathways


B.

Clustering


C.

Failover power


D.

Parallel testing


Expert Solution
Questions # 282:

Which of the following is an example of shadow IT?

Options:

A.

An employee using a cloud based order management tool without approval from IT


B.

An employee using a company provided laptop to access personal banking information


C.

An employee using personal email to communicate with clients without approval from IT


D.

An employee using a company-provided tablet to access social media during work hours


Expert Solution
Questions # 283:

A database administrator (DBA) should be prevented from having end user responsibilities:

Options:

A.

having end user responsibilities


B.

accessing sensitive information


C.

having access to production files


D.

using an emergency user ID


Expert Solution
Questions # 284:

An IS auditor is reviewing an organization ' s primary router access control list. Which of the following should result in a finding?

Options:

A.

There are conflicting permit and deny rules for the IT group.


B.

The network security group can change network address translation (NAT).


C.

Individual permissions are overriding group permissions.


D.

There is only one rule per group with access privileges.


Expert Solution
Questions # 285:

Which of the following would provide management with the MOST reasonable assurance that a new data warehouse will meet the needs of the

organization?

Options:

A.

Integrating data requirements into the system development life cycle (SDLC)


B.

Appointing data stewards to provide effective data governance


C.

Classifying data quality issues by the severity of their impact to the organization


D.

Facilitating effective communication between management and developers


Expert Solution
Questions # 286:

In response to an audit finding regarding a payroll application, management implemented a new automated control. Which of the following would be MOST helpful to the IS auditor when evaluating the effectiveness of the new control?

Options:

A.

Approved test scripts and results prior to implementation


B.

Written procedures defining processes and controls


C.

Approved project scope document


D.

A review of tabletop exercise results


Expert Solution
Questions # 287:

Which of the following technologies has the SMALLEST maximum range for data transmission between devices?

Options:

A.

Wi-Fi


B.

Bluetooth


C.

Long-term evolution (LTE)


D.

Near-field communication (NFC)


Expert Solution
Questions # 288:

Which of the following is the BEST control to mitigate the risk of shadow IT?

Options:

A.

Intrusion detection system (IDS)


B.

Vendor management reviews


C.

Vulnerability scanning


D.

Security awareness training


Expert Solution
Questions # 289:

An organization ' s security policy mandates that all new employees must receive appropriate security awareness training. Which of the following metrics would BEST assure compliance with this policy?

Options:

A.

Percentage of new hires that have completed the training.


B.

Number of new hires who have violated enterprise security policies.


C.

Number of reported incidents by new hires.


D.

Percentage of new hires who report incidents


Expert Solution
Questions # 290:

Which of the following areas is MOST likely to be overlooked when implementing a new data classification process?

Options:

A.

End-user computing (EUC) systems


B.

Email attachments


C.

Data sent to vendors


D.

New system applications


Expert Solution
Questions # 291:

An IS auditor is reviewing an organization ' s cloud access security broker (CASB) solution. Which ofthe following is MOST important for the auditor to verify?

Options:

A.

Cloud services are classified.


B.

Users are centrally managed.


C.

Cloud processes are resilient.


D.

Users are periodically recertified.


Expert Solution
Questions # 292:

Which of the following risk scenarios is BEST addressed by implementing policies and procedures related to full disk encryption?

Options:

A.

Data leakage as a result of employees leaving to work for competitors


B.

Noncompliance fines related to storage of regulated information


C.

Unauthorized logical access to information through an application interface


D.

Physical theft of media on which information is stored


Expert Solution
Questions # 293:

Which of the following is the BEST way to detect unauthorized copies of licensed software on systems?

Options:

A.

Implement controls to prohibit downloads of unauthorized software.


B.

Conduct periodic software scanning.


C.

Perform periodic counting of licenses.


D.

Require senior management approval when installing licenses.


Expert Solution
Questions # 294:

Coding standards provide which of the following?

Options:

A.

Program documentation


B.

Access control tables


C.

Data flow diagrams


D.

Field naming conventions


Expert Solution
Questions # 295:

An IS auditor is reviewing desktop software profiles and notes that a user has downloaded and installed several games that are not approved by the company. Which of the following is the MOST significant risk that could result from this situation?

Options:

A.

Violation of user ' s privacy


B.

Potential for malware


C.

Noncompliance with the acceptable use policy


D.

Interoperability issues with company software


Expert Solution
Questions # 296:

Which of the following should be of GREATEST concern to an IS auditor reviewing a network printer disposal process?

Options:

A.

Disposal policies and procedures are not consistently implemented


B.

Evidence is not available to verify printer hard drives have been sanitized prior to disposal.


C.

Business units are allowed to dispose printers directly to


D.

Inoperable printers are stored in an unsecured area.


Expert Solution
Questions # 297:

Which of the following should be the PRIMARY purpose of conducting tabletop exercises when re-viewing a security incident response plan?

Options:

A.

To provide efficiencies for alignment with incident response test scenarios


B.

To determine process improvement options for the incident response plan


C.

To gather documentation for responding to security audit inquiries


D.

To confirm that technology is in place to support the incident response plan


Expert Solution
Questions # 298:

An organization ' s strategy to source certain IT functions from a Software as a Service (SaaS) provider should be approved by the:

Options:

A.

chief financial officer (CFO).


B.

chief risk officer (CRO).


C.

IT steering committee.


D.

IT operations manager.


Expert Solution
Questions # 299:

Which of the following is an executive management concern that could be addressed by the implementation of a security metrics dashboard?

Options:

A.

Effectiveness of the security program


B.

Security incidents vs. industry benchmarks


C.

Total number of hours budgeted to security


D.

Total number of false positives


Expert Solution
Questions # 300:

Stress testing should ideally be earned out under a:

Options:

A.

test environment with production workloads.


B.

production environment with production workloads.


C.

production environment with test data.


D.

test environment with test data.


Expert Solution
Viewing page 6 out of 10 pages
Viewing questions 251-300 out of questions