Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CISA Questions and answers with CertsForce

Viewing page 7 out of 10 pages
Viewing questions 301-350 out of questions
Questions # 301:

Which of the following should an IS auditor be MOST concerned with when a system uses RFID?

Options:

A.

privacy


B.

Maintainability


C.

Scalability


D.

Nonrepudiation


Expert Solution
Questions # 302:

Which of the following would the IS auditor MOST likely review to determine whether modifications to the operating system parameters were authorized?

Options:

A.

Documentation of exit routines


B.

System initialization logs


C.

Change control log


D.

Security system parameters


Expert Solution
Questions # 303:

A national bank recently migrated a large number of business-critical applications to the cloud. Which of the following is MOST important to ensuring the resiliency of the applications?

Options:

A.

Negotiating a nondisclosure agreement (NDA) with the provider


B.

Conducting periodic system stress testing


C.

Creating restore points for critical applications


D.

Using a monitoring tool to assess uptime


Expert Solution
Questions # 304:

An organization’s information security department has recently created a centralized governance model to ensure that network-related findings are remediated within the service level agreement (SLA). What should the IS auditor use to assess the capability of this governance model?

Options:

A.

Key process controls.


B.

Key performance indicators (KPIs).


C.

Key risk indicators (KRIs).


D.

Key data elements.


Expert Solution
Questions # 305:

If enabled within firewall rules, which of the following services would present the GREATEST risk?

Options:

A.

Simple mail transfer protocol (SMTP)


B.

Simple object access protocol (SOAP)


C.

Hypertext transfer protocol (HTTP)


D.

File transfer protocol (FTP)


Expert Solution
Questions # 306:

An IS auditor discovers from patch logs that some in-scope systems are not compliant with the regular patching schedule. What should the auditor do NEXT?

Options:

A.

Interview IT management to clarify the current procedure.


B.

Report this finding to senior management.


C.

Review the organization ' s patch management policy.


D.

Request a plan of action to be established as a follow-up item.


Expert Solution
Questions # 307:

Which of the following is the MOST efficient control to reduce the risk associated with a systems administrator having network administrator responsibilities?

Options:

A.

The administrator must obtain temporary access to make critical changes.


B.

The administrator will need to request additional approval for critical changes.


C.

The administrator must sign a due diligence agreement.


D.

The administrator will be subject to unannounced audits.


Expert Solution
Questions # 308:

Which of the following is the PRIMARY reason to follow a configuration management process to maintain application?

Options:

A.

To optimize system resources


B.

To follow system hardening standards


C.

To optimize asset management workflows


D.

To ensure proper change control


Expert Solution
Questions # 309:

Which of the following should be of GREATEST concern to an IS auditor reviewing an organization ' s business continuity plan (BCP)?

Options:

A.

The BCP ' s contact information needs to be updated


B.

The BCP is not version controlled.


C.

The BCP has not been approved by senior management.


D.

The BCP has not been tested since it was first issued.


Expert Solution
Questions # 310:

Which of the following is MOST important for an effective control self-assessment (CSA) program?

Options:

A.

Determining the scope of the assessment


B.

Performing detailed test procedures


C.

Evaluating changes to the risk environment


D.

Understanding the business process


Expert Solution
Questions # 311:

Which of the following provides the BEST assurance that a new database management system (DBMS) meets the requirements of local privacy regulations?

Options:

A.

Compliance audit


B.

Administrative audit


C.

General IT controls review


D.

Forensic audit


Expert Solution
Questions # 312:

Which of the following metrics BEST demonstrates the effectiveness of an organization’s privacy program?

Options:

A.

Percentage of employees who have completed privacy training.


B.

Number of attempted privacy breaches.


C.

Percentage of privacy impact assessments (PIAs) completed.


D.

Number of requests from clients to delete their information.


Expert Solution
Questions # 313:

Before the release of a new application into an organization’s production environment, which of the following should be in place to ensure that proper testing has occurred and rollback plans are in place?

Options:

A.

Change approval board


B.

Standardized change requests


C.

Independent third-party approval


D.

Secure code review


Expert Solution
Questions # 314:

Which of following is MOST important to determine when conducting a post-implementation review?

Options:

A.

Whether the solution architecture compiles with IT standards


B.

Whether success criteria have been achieved


C.

Whether the project has been delivered within the approved budget


D.

Whether lessons teamed have been documented


Expert Solution
Questions # 315:

A finance department has a two-year project to upgrade the enterprise resource planning (ERP) system hosting the general ledger in year one the system version upgrade will be applied and in year two business processes will be updated to implement new system functionality. Which of the following should be the PRIMARY focus of an IS auditor reviewing the second year of the implementation ' ?

Options:

A.

Data migration


B.

Sociability testing


C.

User acceptance testing (UAT)


D.

Initial user access provisioning


Expert Solution
Questions # 316:

The MOST effective way to reduce sampling risk is to increase:

Options:

A.

confidence interval.


B.

population.


C.

audit sampling training.


D.

sample size.


Expert Solution
Questions # 317:

During the implementation of an upgraded enterprise resource planning (ERP) system, which of the following is the MOST important consideration for a go-live decision?

Options:

A.

Rollback strategy


B.

Test cases


C.

Post-implementation review objectives


D.

Business case


Expert Solution
Questions # 318:

Which of the following is the PRIMARY benefit of operational log management?

Options:

A.

It enhances user experience via predictive analysis.


B.

It improves security with real-time monitoring of network data.


C.

It organizes data to identify performance issues.


D.

It supports data aggregation using unified storage.


Expert Solution
Questions # 319:

Which of the following is the MOST significant impact to an organization that does not use an IT governance framework?

Options:

A.

adequate measurement of key risk indicators (KRIS)


B.

Inadequate alignment of IT plans and business objectives


C.

Inadequate business impact analysis (BIA) results and predictions


D.

Inadequate measurement of key performance indicators (KPls)


Expert Solution
Questions # 320:

Which of the following should be of MOST concern to an IS auditor reviewing the public key infrastructure (PKI) for enterprise email?

Options:

A.

The certificate revocation list has not been updated.


B.

The PKI policy has not been updated within the last year.


C.

The private key certificate has not been updated.


D.

The certificate practice statement has not been published


Expert Solution
Questions # 321:

An IS auditor is planning an audit of an organization ' s accounts payable processes. Which of the following controls is MOST important to assess in the audit?

Options:

A.

Segregation of duties between issuing purchase orders and making payments.


B.

Segregation of duties between receiving invoices and setting authorization limits


C.

Management review and approval of authorization tiers


D.

Management review and approval of purchase orders


Expert Solution
Questions # 322:

Which of the following is the GREATEST risk related to the use of virtualized environments?

Options:

A.

The host may be a potential single point of failure within the system.


B.

There may be insufficient processing capacity to assign to guests.


C.

There may be increased potential for session hijacking.


D.

Ability to change operating systems may be limited.


Expert Solution
Questions # 323:

During an IT governance audit, an IS auditor notes that IT policies and procedures are not regularly reviewed and updated. The GREATEST concern to the IS auditor is that policies and procedures might not:

Options:

A.

reflect current practices.


B.

include new systems and corresponding process changes.


C.

incorporate changes to relevant laws.


D.

be subject to adequate quality assurance (QA).


Expert Solution
Questions # 324:

Which of the following should be an IS auditor ' s PRIMARY consideration when determining which issues to include in an audit report?

Options:

A.

Professional skepticism


B.

Management ' s agreement


C.

Materiality


D.

Inherent risk


Expert Solution
Questions # 325:

Which of the following control measures is the MOST effective against unauthorized access of confidential information on stolen or lost laptops?

Options:

A.

Remote wipe capabilities


B.

Disk encryption


C.

User awareness


D.

Password-protected files


Expert Solution
Questions # 326:

An IS auditor has been asked to assess the security of a recently migrated database system that contains personal and financial data for a bank ' s customers. Which of the following controls is MOST important for the auditor to confirm is in place?

Options:

A.

The default configurations have been changed.


B.

All tables in the database are normalized.


C.

The service port used by the database server has been changed.


D.

The default administration account is used after changing the account password.


Expert Solution
Questions # 327:

Which of the following is the PRIMARY benefit of a tabletop exercise for an incident response plan?

Options:

A.

It demonstrates the maturity of the incident response program.


B.

It reduces the likelihood of an incident occurring.


C.

It identifies deficiencies in the operating environment.


D.

It increases confidence in the team ' s response readiness.


Expert Solution
Questions # 328:

Which of the following is the BEST way to mitigate the risk associated with unintentional modifications of complex calculations in end-user computing (EUC)?

Options:

A.

Have an independent party review the source calculations


B.

Execute copies of EUC programs out of a secure library


C.

implement complex password controls


D.

Verify EUC results through manual calculations


Expert Solution
Questions # 329:

Which of the following is the PRIMARY advantage of using virtualization technology for corporate applications?

Options:

A.

Stronger data security


B.

Better utilization of resources


C.

Increased application performance


D.

Improved disaster recovery


Expert Solution
Questions # 330:

Which of the following is MOST important for an IS auditor to confirm when reviewing an organization ' s incident response management program?

Options:

A.

All incidents have a severity level assigned.


B.

All identified incidents are escalated to the CEO and the CISO.


C.

Incident response is within defined service level agreements (SLAs).


D.

The alerting tools and incident response team can detect incidents.


Expert Solution
Questions # 331:

Which of the following is the BEST evidence that an organization ' s IT strategy is aligned lo its business objectives?

Options:

A.

The IT strategy is modified in response to organizational change.


B.

The IT strategy is approved by executive management.


C.

The IT strategy is based on IT operational best practices.


D.

The IT strategy has significant impact on the business strategy


Expert Solution
Questions # 332:

Which of the following methods provides the MOST reliable audit evidence?

Options:

A.

Inquiry


B.

Management attestation


C.

Re-performance of controls


D.

Observation


Expert Solution
Questions # 333:

Which of the following is the MOST important consideration when establishing vulnerability scanning on critical IT infrastructure?

Options:

A.

The scanning will be performed during non-peak hours.


B.

The scanning will be followed by penetration testing.


C.

The scanning will be cost-effective.


D.

The scanning will not degrade system performance.


Expert Solution
Questions # 334:

Which type of review is MOST important to conduct when an IS auditor is informed that a recent internal exploitation of a bug has been discovered in a business application?

Options:

A.

Penetration testing


B.

Application security testing


C.

Forensic audit


D.

Server security audit


Expert Solution
Questions # 335:

Which of the following is the MOST important consideration for a contingency facility?

Options:

A.

The contingency facility has the same badge access controls as the primary site.


B.

Both the contingency facility and the primary site have the same number of business assets in their inventory.


C.

The contingency facility is located a sufficient distance away from the primary site.


D.

Both the contingency facility and the primary site are easily identifiable.


Expert Solution
Questions # 336:

Which of the following is the BEST way for an IS auditor to assess the design of an automated application control?

Options:

A.

Interview the application developer.


B.

Obtain management attestation and sign-off.


C.

Review the application implementation documents.


D.

Review system configuration parameters and output.


Expert Solution
Questions # 337:

When drafting a disaster recovery strategy, what should be the MOST important outcome of a business impact analysis (BIA)?

Options:

A.

Establishing recovery point objectives (RPOs)


B.

Determining recovery priorities


C.

Establishing recovery time objectives (RTOs)


D.

Determining recovery costs


Expert Solution
Questions # 338:

Which of the following MUST be performed by senior audit leadership prior to starting an IS audit project?

Options:

A.

Signoff on the audit scope.


B.

Attend planning walk-throughs.


C.

Review audit planning documents.


D.

Meet with auditee leadership.


Expert Solution
Questions # 339:

When physical destruction IS not practical, which of the following is the MOST effective means of disposing of sensitive data on a hard disk?

Options:

A.

Overwriting multiple times


B.

Encrypting the disk


C.

Reformatting


D.

Deleting files sequentially


Expert Solution
Questions # 340:

When conducting an audit of an organization ' s use of AI in its customer service chatbots, an IS auditor should PRIMARILY focus on the:

Options:

A.

Safeguarding of personal data processing by the AI system.


B.

AI system ' s compliance with industry security standards.


C.

Speed and accuracy of chatbot responses to customer queries.


D.

AI system ' s ability to handle multiple customer queries at once.


Expert Solution
Questions # 341:

The implementation of an IT governance framework requires that the board of directors of an organization:

Options:

A.

Address technical IT issues.


B.

Be informed of all IT initiatives.


C.

Have an IT strategy committee.


D.

Approve the IT strategy.


Expert Solution
Questions # 342:

Which of the following staff should an IS auditor interview FIRST to obtain a general overview of the various technologies used across different programs?

Options:

A.

Technical architect


B.

Enterprise architect


C.

Program manager


D.

Solution architect


Expert Solution
Questions # 343:

Which of the following is MOST important for an IS auditor to confirm when reviewing an organization ' s plans to implement robotic process automation (RPA > to automate routine business tasks?

Options:

A.

The end-to-end process is understood and documented.


B.

Roles and responsibilities are defined for the business processes in scope.


C.

A benchmarking exercise of industry peers who use RPA has been completed.


D.

A request for proposal (RFP) has been issued to qualified vendors.


Expert Solution
Questions # 344:

Which of the following findings from a database security audit presents the GREATEST risk of critical security exposures?

Options:

A.

Legacy data has not been purged.


B.

Admin account passwords are not set to expire.


C.

Default settings have not been changed.


D.

Database activity logging is not complete.


Expert Solution
Questions # 345:

In a review of the organization standards and guidelines for IT management, which of the following should be included in an IS development methodology?

Options:

A.

Value-added activity analysis


B.

Risk management techniques


C.

Access control rules


D.

Incident management techniques


Expert Solution
Questions # 346:

The due date of an audit project is approaching, and the audit manager has determined that only 60% of the audit has been completed. Which of the following should the audit manager do FIRST?

Options:

A.

Determine where delays have occurred


B.

Assign additional resources to supplement the audit


C.

Escalate to the audit committee


D.

Extend the audit deadline


Expert Solution
Questions # 347:

Which of the following is the MOST effective control to mitigate unintentional misuse of authorized access?

Options:

A.

Annual sign-off of acceptable use policy


B.

Regular monitoring of user access logs


C.

Security awareness training


D.

Formalized disciplinary action


Expert Solution
Questions # 348:

Which of the following findings should be of GREATEST concern to an IS auditor assessing the risk associated with end-user computing (EUC) in an organization?

Options:

A.

Insufficient processes to track ownership of each EUC application?


B.

Insufficient processes to lest for version control


C.

Lack of awareness training for EUC users


D.

Lack of defined criteria for EUC applications


Expert Solution
Questions # 349:

The PRIMARY purpose of a configuration management system is to:

Options:

A.

track software updates.


B.

define baselines for software.


C.

support the release procedure.


D.

standardize change approval.


Expert Solution
Questions # 350:

An organization has established hiring policies and procedures designed specifically to ensure network administrators are well qualified Which type of control is in place?

Options:

A.

Detective


B.

Compensating


C.

Corrective


D.

Directive


Expert Solution
Viewing page 7 out of 10 pages
Viewing questions 301-350 out of questions