Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Isaca Isaca Certification CISA Questions and answers with CertsForce

Viewing page 8 out of 10 pages
Viewing questions 351-400 out of questions
Questions # 351:

Which of the following is the MOST effective control to mitigate against the risk of inappropriate activity by employees?

Options:

A.

User activity monitoring


B.

Two-factor authentication


C.

Network segmentation


D.

Access recertification


Expert Solution
Questions # 352:

During the discussion of a draft audit report IT management provided suitable evidence that a process has been implemented for a control that had been concluded by the IS auditor as ineffective Which of the following is the auditor ' s BEST action?

Options:

A.

Explain to IT management that the new control will be evaluated during follow-up


B.

Add comments about the action taken by IT management in the report


C.

Change the conclusion based on evidence provided by IT management


D.

Re-perform the audit before changing the conclusion


Expert Solution
Questions # 353:

Which of the following would provide the MOST important input during the planning phase for an audit on the implementation of a bring your own device (BYOD) program?

Options:

A.

Findings from prior audits


B.

Results of a risk assessment


C.

An inventory of personal devices to be connected to the corporate network


D.

Policies including BYOD acceptable user statements


Expert Solution
Questions # 354:

Which of the following should an IS auditor consider the MOST significant risk associated with a new health records system that replaces a legacy system?

Options:

A.

Staff were not involved in the procurement process, creating user resistance to the new system.


B.

Data is not converted correctly, resulting in inaccurate patient records.


C.

The deployment project experienced significant overruns, exceeding budget projections.


D.

The new system has capacity issues, leading to slow response times for users.


Expert Solution
Questions # 355:

Which of the following is MOST important for an IS auditor to verify when evaluating tne upgrade of an organization ' s enterprise resource planning (ERP) application?

Options:

A.

Application related documentation was updated to reflect the changes in the new version


B.

Security configurations were appropriately applied to the new version


C.

Users were provided security training on the new version


D.

Lessons teamed analysis was documented after the upgrade


Expert Solution
Questions # 356:

Which of the following is the BEST indicator for measuring performance of IT help desk function?

Options:

A.

Percentage of problems raised from incidents


B.

Mean time to categorize tickets


C.

Number 0t incidents reported


D.

Number of reopened tickets


Expert Solution
Questions # 357:

The charging method that effectively encourages the MOST efficient use of IS resources is:

Options:

A.

specific charges that can be tied back to specific usage.


B.

total utilization to achieve full operating capacity.


C.

residual income in excess of actual incurred costs.


D.

allocations based on the ability to absorb charges.


Expert Solution
Questions # 358:

Which of the following is the PRIMARY advantage of using an automated security log monitoring tool over a manual review to monitor the use of privileged access?

Options:

A.

Increased likelihood of detecting suspicious activity


B.

Reduced costs associated with automating the review


C.

Improved incident response time


D.

Reduced manual effort of reviewing logs


Expert Solution
Questions # 359:

An IS auditor finds that the cost of developing an application is now projected to significantly exceed the budget. Which of the following is the GREATEST risk to communicate to senior management?

Options:

A.

Noncompliance with project methodology


B.

Inability to achieve expected benefits


C.

Increased staff turnover


D.

Project abandonment


Expert Solution
Questions # 360:

Which of the following is the MOST important consideration when implementing a Zero Trust strategy for mobile, wireless, and Internet of Things (IoT) devices?

Options:

A.

Ensuring the latest firmware updates are applied regularly to all devices


B.

Validating the identity of all devices and users before granting access to resources


C.

Focusing on user training and awareness to prevent phishing attacks


D.

Implementing strong encryption protocols for data in transit and at rest


Expert Solution
Questions # 361:

An organization wants to use virtual desktops to deliver corporate applications to its end users. Which of the following should an IS auditor recommend to prevent domain name system (DNS) poisoning in their cloud environment?

Options:

A.

Enable verification of administrators to protect against impersonators modifying DNS tables.


B.

Configure ONS servers to create appropriately sized responses to domain resolution requests.


C.

Ensure DNS changes are propagated across all servers in the organization ' s cloud account.


D.

Provide corporate laptops to end users with built-in antivirus tools that scan for DNS vulnerabilities.


Expert Solution
Questions # 362:

An organization has engaged a third party to implement an application to perform business-critical calculations. Which of the following is the MOST important process to help ensure the application provides accurate calculations?

Options:

A.

Key performance indicator (KPI) monitoring


B.

Change management


C.

Configuration management


D.

Quality assurance (QA)


Expert Solution
Questions # 363:

An organization has purchased a new cloud-based application from a vendor. Which of the following should be the FIRST consideration when implementing the system?

Options:

A.

Preventing alterations to the source code during implementation.


B.

Ensuring vendor default accounts and passwords have been disabled.


C.

Verifying that the vendor is meeting maintenance agreements.


D.

Deleting the old copies of the program from escrow to avoid wrong versions.


Expert Solution
Questions # 364:

Which of the following responses to risk associated with segregation of duties would incur the LOWEST initial cost?

Options:

A.

Risk acceptance


B.

Risk mitigation


C.

Risk transference


D.

Risk reduction


Expert Solution
Questions # 365:

When an intrusion into an organization network is deleted, which of the following should be done FIRST?

Options:

A.

Block all compromised network nodes.


B.

Contact law enforcement.


C.

Notify senior management.


D.

Identity nodes that have been compromised.


Expert Solution
Questions # 366:

Which of the following is MOST likely to be a project deliverable of an agile software development methodology?

Options:

A.

Strictly managed software requirements baselines


B.

Extensive project documentation


C.

Automated software programming routines


D.

Rapidly created working prototypes


Expert Solution
Questions # 367:

An IS auditor suspects an organization ' s computer may have been used to commit a crime. Which of the following is the auditor ' s BEST course of action?

Options:

A.

Examine the computer to search for evidence supporting the suspicions.


B.

Advise management of the crime after the investigation.


C.

Contact the incident response team to conduct an investigation.


D.

Notify local law enforcement of the potential crime before further investigation.


Expert Solution
Questions # 368:

Which of the following should be an IS auditor ' s PRIMARY focus when evaluating the response process for cybercrimes?

Options:

A.

Communication with law enforcement


B.

Notification to regulators


C.

Root cause analysis


D.

Evidence collection


Expert Solution
Questions # 369:

Which of the following BEST enables an organization to measure the current state of IT processes against leading practices?

Options:

A.

IT policies


B.

Peer benchmarking


C.

Control framework


D.

Maturity model


Expert Solution
Questions # 370:

An IS auditor learns a server administration team regularly applies workarounds to address repeated failures of critical data processing services Which of the following would BEST enable the organization to resolve this issue?

Options:

A.

Problem management


B.

Incident management


C.

Service level management


D.

Change management


Expert Solution
Questions # 371:

The FIRST step in an incident response plan is to:

Options:

A.

validate the incident.


B.

notify the head of the IT department.


C.

isolate systems impacted by the incident.


D.

initiate root cause analysis.


Expert Solution
Questions # 372:

Which of the following will MOST likely compromise the control provided By a digital signature created using RSA encryption?

Options:

A.

Reversing the hash function using the digest


B.

Altering the plaintext message


C.

Deciphering the receiver ' s public key


D.

Obtaining the sender ' s private key


Expert Solution
Questions # 373:

Which of the following BEST guards against the risk of attack by hackers?

Options:

A.

Tunneling


B.

Encryption


C.

Message validation


D.

Firewalls


Expert Solution
Questions # 374:

Backup procedures for an organization ' s critical data are considered to be which type of control?

Options:

A.

Directive


B.

Corrective


C.

Detective


D.

Compensating


Expert Solution
Questions # 375:

Which of the following practices associated with capacity planning provides the GREATEST assurance that future incidents related to existing server performance will be prevented?

Options:

A.

Reviewing results from simulated high-demand stress test scenarios


B.

Performing a root cause analysis for past performance incidents


C.

Anticipating current service level agreements (SLAs) will remain unchanged


D.

Duplicating existing disk drive systems to improve redundancy and data storage


Expert Solution
Questions # 376:

Which of the following is an IS auditor ' s BEST approach when prepanng to evaluate whether the IT strategy supports the organization ' s vision and mission?

Options:

A.

Review strategic projects tor return on investments (ROls)


B.

Solicit feedback from other departments to gauge the organization ' s maturity


C.

Meet with senior management to understand business goals


D.

Review the organization ' s key performance indicators (KPls)


Expert Solution
Questions # 377:

During a follow-up audit, an IS auditor finds that senior management has implemented a different remediation action plan than what was previously agreed upon. Which of the following is the auditor ' s BEST course of action?

Options:

A.

Report the deviation by the control owner in the audit report.


B.

Evaluate the implemented control to ensure it mitigates the risk to an acceptable level.


C.

Cancel the follow-up audit and reschedule for the next audit period.


D.

Request justification from management for not implementing the recommended control.


Expert Solution
Questions # 378:

Which of the following BEST supports an organization ' s objective of restricting the use of removable storage devices by users?

Options:

A.

Data management policy


B.

Updated anti-malware solutions


C.

Data loss prevention (DLP)


D.

Online monitoring


Expert Solution
Questions # 379:

Which of the following system redundancy configurations BEST improves system resiliency and reduces the possibility of a single cause of failure impacting system dependability?

Options:

A.

Active redundancy


B.

Homogeneous redundancy


C.

Diverse redundancy


D.

Passive redundancy


Expert Solution
Questions # 380:

Which of the following is the BEST methodology to use for estimating the complexity of developing a large business application?

Options:

A.

Function point analysis


B.

Work breakdown structure


C.

Critical path analysts


D.

Software cost estimation


Expert Solution
Questions # 381:

An IS auditor is reviewing a contract for the outsourcing of IT facilities. If missing, which of the following should present the GREATEST concern to the auditor?

Options:

A.

Hardware configurations


B.

Access control requirements


C.

Help desk availability


D.

Perimeter network security diagram


Expert Solution
Questions # 382:

in a post-implantation Nation review of a recently purchased system it is MOST important for the iS auditor to determine whether the:

Options:

A.

stakeholder expectations were identified


B.

vendor product offered a viable solution.


C.

user requirements were met.


D.

test scenarios reflected operating activities.


Expert Solution
Questions # 383:

To improve efficiency, an organization has decided not to encrypt log files and plans to store the log data in native device formats. Which of the following is the GREATEST risk to the organization?

Options:

A.

Inability to automate data transfers.


B.

Inability to correlate security events in time.


C.

Increased cost of log data storage due to lack of compression.


D.

Unauthorized modification of log data.


Expert Solution
Questions # 384:

Which of the following is the MOST cost-effective way to determine the effectiveness of a business continuity plan (BCP)?

Options:

A.

Stress test


B.

Tabletop exercise


C.

Full operational test


D.

Post-implementation review


Expert Solution
Questions # 385:

Which of the following would MOST effectively help to reduce the number of repealed incidents in an organization?

Options:

A.

Testing incident response plans with a wide range of scenarios


B.

Prioritizing incidents after impact assessment.


C.

Linking incidents to problem management activities


D.

Training incident management teams on current incident trends


Expert Solution
Questions # 386:

An internal audit department recently established a quality assurance (QA) program. Which of the following activities Is MOST important to include as part of the QA program requirements?

Options:

A.

Long-term Internal audit resource planning


B.

Ongoing monitoring of the audit activities


C.

Analysis of user satisfaction reports from business lines


D.

Feedback from Internal audit staff


Expert Solution
Questions # 387:

Which of the following controls helps to reduce fraud risk associated with robotic process automation (RPA)?

Options:

A.

Inclusion of robots in business impact assessments (BIAs)


B.

Password rotation


C.

Recertification process for robots


D.

Common RPA testing framework


Expert Solution
Questions # 388:

Which of the following would be MOST effective in detecting the presence of an unauthorized wireless access point on an internal network?

Options:

A.

Continuous network monitoring


B.

Periodic network vulnerability assessments


C.

Review of electronic access logs


D.

Physical security reviews


Expert Solution
Questions # 389:

Which of the following is the PRIMARY role of the release plan?

Options:

A.

It identifies all configuration items within an IT environment.


B.

It provides a timeline and schedule for deploying new releases into production.


C.

It outlines the steps for database integration.


D.

It evaluates the impact of proposed changes and updates to IT systems.


Expert Solution
Questions # 390:

Which of the following is an objective of IT project portfolio management?

Options:

A.

Successful implementation of projects


B.

Selection of sound, strategically aligned investment opportunities


C.

Validation of business case benefits


D.

Establishment of tracking mechanisms


Expert Solution
Questions # 391:

Which type of attack poses the GREATEST risk to an organization ' s most sensitive data?

Options:

A.

Password attack


B.

Eavesdropping attack


C.

Insider attack


D.

Spear phishing attack


Expert Solution
Questions # 392:

When auditing IT organizational structure, which of the following findings presents the GREATEST risk to an organization?

Options:

A.

Significantly higher turnover


B.

Lack of customer satisfaction surveys


C.

Aging staff


D.

Increase in the frequency of software upgrades


Expert Solution
Questions # 393:

Which of the following should be of GREATEST concern to an IS auditor assessing the effectiveness of an organization ' s information security governance?

Options:

A.

Risk assessments of information assets are not periodically performed.


B.

All Control Panel Items


C.

The information security policy does not extend to service providers.


D.

There is no process to measure information security performance.


E.

The information security policy is not reviewed by executive management.


Expert Solution
Questions # 394:

Which of the following MUST be completed as part of the annual audit planning process?

Options:

A.

Business impact analysis (BIA)


B.

Fieldwork


C.

Risk assessment


D.

Risk control matrix


Expert Solution
Questions # 395:

An organization has developed mature risk management practices that are followed across all departments What is the MOST effective way for the audit team to leverage this risk management maturity?

Options:

A.

Implementing risk responses on management ' s behalf


B.

Integrating the risk register for audit planning purposes


C.

Providing assurances to management regarding risk


D.

Facilitating audit risk identification and evaluation workshops


Expert Solution
Questions # 396:

Who should be the FIRST to evaluate an audit report prior to issuing it to the project steering committee?

Options:

A.

IS audit manager


B.

Audit committee


C.

Business owner


D.

Project sponsor


Expert Solution
Questions # 397:

An IS auditor is conducting an IT governance audit and notices that many initiatives are managed informally by isolated project managers. Which of the following recommendations would have the GREATEST impact on improving the maturity of the IT team?

Options:

A.

Discontinue all current IT projects until formal approval is obtained and documented.


B.

Schedule a follow-up audit in the next year to confirm whether IT processes have matured.


C.

Document and track all IT decisions in a project management tool.


D.

Create an interdisciplinary IT steering committee to oversee IT prioritization and spending.


Expert Solution
Questions # 398:

Which of the following system attack methods is executed by entering malicious code into the search box of a vulnerable website, causing the server to reveal restricted information?

Options:

A.

Man-m-the-middle


B.

Denial of service (DoS)


C.

SQL injection


D.

Cross-site scripting


Expert Solution
Questions # 399:

Which of the following is MOST important for an IS auditor to review when evaluating the accuracy of a spreadsheet that contains several macros?

Options:

A.

Encryption of the spreadsheet


B.

Version history


C.

Formulas within macros


D.

Reconciliation of key calculations


Expert Solution
Questions # 400:

The use of which of the following is an inherent risk in the application container infrastructure?

Options:

A.

Shared registries


B.

Host operating system


C.

Shared data


D.

Shared kernel


Expert Solution
Viewing page 8 out of 10 pages
Viewing questions 351-400 out of questions