
The Best Practice Test Preparation for the CISA Certification Exam
CISA Exam Dumps, Practice Test Questions BUNDLE PACK
Governance & Management of IT: This section is designed to evaluate one’s capability to identify different critical concerns and recommend specific enterprise practices to safeguard and support information governance and related technologies. These include the following:
- IT Management – IT resource management; service provider management and acquisition; quality management and quality assurance of IT; IT performance reporting and monitoring.
- IT Governance – IT governance & IT strategy; IT policies, procedures, and standards; IT-related frameworks; organizational and enterprise structures; enterprise risk management; maturity models;
The benefits of Obtaining the ISACA CISA Exam Certification
ISACA CISA certification is often preferred by employers. You can have many benefits of obtaining the ISACA CISA exam by doing preparation from ISACA CISA Dumps. Candidates who have obtained any of the following certifications are eligible to apply for the CISA credential: Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified in the Governance of Enterprise IT (CGEIT), Certified in Risk and Information Systems Control (CRISC), Certified Software Development Asset Manager(CSDAM), International Information Systems Security Certification Consortium's Certified Internet Webmaster.
NEW QUESTION # 57
Which of the following should be of GREATEST concern to an organization's board when reviewing the internal audit department's quality assurance and improvement program?
- A. The program has not been approved by senior management.
- B. Program metrics have not been updated in over two years.
- C. The program does not Include periodic external assessments.
- D. The program does not incorporate recommendations from prior audits.
Answer: A
NEW QUESTION # 58
A company has purchased a rival organization and is looking to integrate security strategies. Which of the following is the GREATEST issue to consider?
- A. Differing security skills within the organizations
- B. Differing security technologies
- C. The organizations have different risk appetites
- D. Confidential information could be leaked
Answer: C
Explanation:
Section: Protection of Information Assets
NEW QUESTION # 59
The decision to accept an IT control risk related to data quality should be the responsibility of the:
- A. information security team.
- B. chief information officer (CIO).
- C. business owner.
- D. IS audit manager.
Answer: C
Explanation:
Explanation
The decision to accept an IT control risk related to data quality should be the responsibility of the business owner. The business owner is the person who has the authority and accountability for the business process that relies on the data quality. The business owner should understand the impact of data quality issues on the business objectives, performance, and compliance. The business owner should also be involved in defining the data quality requirements, assessing the data quality risks, and implementing the data quality controls or mitigation strategies.
NEW QUESTION # 60
An IS auditor invited to a development project meeting notes that no project risks have been documented.
When the IS auditor raises this issue, the project manager responds that it is too early to identify risks and that, if risks do start impactingthe project, a risk manager will be hired. The appropriate response of the IS auditor would be to:
- A. offer to work with the risk manager when one is appointed.
- B. stress the importance of spending time at this point in the project to consider and document risks, and to develop contingency plans.
- C. inform the project manager that the IS auditor will conduct a review of the risks at the completion of the requirements definition phase of the project.
- D. accept the project manager's position as the project manager is accountable for the outcome of the project.
Answer: B
Explanation:
Explanation/Reference:
Explanation:
The majority of project risks can typically be identified before a project begins, allowing mitigation/ avoidance plans to be put in place to deal with these risks. A project should have a clear link back to corporate strategy and tactical plans to support this strategy. The process of setting corporate strategy, setting objectives and developing tactical plans should include the consideration of risks. Appointing a risk manager is a good practice but waiting until the project has been impacted by risks is misguided. Risk management needs to be forward looking; allowing risks to evolve into issues that adversely impact the project represents a failure of risk management. With or without a risk manager, persons within and outside of the project team need to be consulted and encouraged to comment when they believe new risks have emerged or risk priorities have changed. The IS auditor has an obligation to the project sponsor and the organization to advise on appropriate project manage me ntpractices. Waiting for the possible appointment of a risk manager represents an unnecessary and dangerous delay to implementing risk management.
NEW QUESTION # 61
For an organization which uses a VoIP telephony system exclusively, the GREATEST concern associated with leaving a connected telephone in an unmonitored public area is the possibility of:
- A. theft of destruction of an expensive piece of electronic equipment.
- B. unauthorized use leading to theft of services and financial loss,
- C. connectivity issues when used with an analog local exchange earner.
- D. network compromise due to the introduction of malware.
Answer: D
NEW QUESTION # 62
During the discussion of a draft audit report IT management provided suitable evidence that a process has been implemented for a control that had been concluded by the IS auditor as ineffective Which of the following is the auditor's BEST action?
- A. Add comments about the action taken by IT management in the report
- B. Re-perform the audit before changing the conclusion
- C. Explain to IT management that the new control will be evaluated during follow-up
- D. Change the conclusion based on evidence provided by IT management
Answer: B
Explanation:
Explanation
The auditor's best action is to re-perform the audit before changing the conclusion, because the auditor needs to obtain sufficient and appropriate evidence to support the audit opinion. The evidence provided by IT management may not be reliable or relevant, and it may not reflect the actual effectiveness of the control during the audit period. Therefore, the auditor should verify the evidence independently and test the control again to ensure that it meets the audit criteria and objectives. The other options are not appropriate, because they either ignore or accept the evidence provided by IT management without verification, which may compromise the quality and integrity of the audit. References:
ISACA, CISA Review Manual, 27th Edition, chapter 1, section 1.51
ISACA, IT Audit and Assurance Standards, Guidelines and Tools and Techniques for IS Audit and Assurance Professionals, section 12062
NEW QUESTION # 63
The MOST effective control for reducing the risk related to phishing is:
- A. security training for all users.
- B. centralized monitoring of systems.
- C. publishing the policy on antiphishing on the intranet.
- D. including signatures for phishing in antivirus software.
Answer: A
Explanation:
Explanation/Reference:
Explanation:
Phishing is a type of e-mail attack that attempts to convince a user that the originator is genuine, with the intention of obtaining information. Phishing is an example of a social engineering attack. Any social engineering type of attack can best Decontrolled through security and awareness training.
NEW QUESTION # 64
Which of the following would have the HIGHEST priority in a business continuity plan (BCP)?
- A. Restoring the site
- B. Recovering sensitive processes
- C. Resuming critical processes
- D. Relocating operations to an alternative site
Answer: C
Explanation:
The resumption of critical processes has the highest priority as it enables business processes to begin immediately after the interruption and not later than the declared mean time between failure (MTBF). Recovery of sensitive processes refers to recovering the vital and sensitive processes that can be performed manually at a tolerable cost for an extended period of time and those that are not marked as high priority. Repairing and restoring the site to original status and resuming the business operations are time consuming operations and are not the highest priority. Relocating operations to an alternative site, either temporarily or permanently depending on the interruption, is a time consuming process; moreover, relocation may not be required.
NEW QUESTION # 65
Which of the following reports can MOST effectively be used to analyze a systems performance problem?
- A. Synchronization report
- B. Database usage log
- C. Console log
- D. Utilization report
Answer: C
NEW QUESTION # 66
Which of the following should be the FIRST consideration when deciding whether data should be moved to a cloud provider for storage?
- A. Data classification
- B. Service level agreements (SLAs)
- C. Data storage costs
- D. Vendor cloud certification
Answer: A
NEW QUESTION # 67
A sequence of bits appended to a digital document that is used to secure an e-mail sent through the Internet is called a:
- A. hash signature.
- B. digital signature.
- C. digest signature.
- D. electronic signature.
Answer: B
Explanation:
Section: Protection of Information Assets
Explanation/Reference:
Explanation:
A digital signature through the private cryptographic key authenticates a transmission from a sender through the private cryptographic key. It is a string of bits that uniquely represent another string of bits, a digital document. An electronic signature refers to the string of bits that digitally represents a handwritten signature captured by a computer system when a human applies it on an electronic pen pad, connected to the system.
NEW QUESTION # 68
Recovery facilities providing a redundant combination of Internet connections to the local communications loop is an example of which type of telecommunications continuity?
- A. Voice recovery
- B. Alternative routing
- C. Long-haul network diversity
- D. Last-mile circuit protection
Answer: D
Explanation:
Explanation
Recovery facilities providing a redundant combination of Internet connections to the local communications loop is an example of last-mile circuit protection. Last-mile circuit protection is a type of telecommunications continuity that ensures the availability and redundancy of the final segment of the network that connects the end-user to the service provider. The local communications loop, also known as the local loop or subscriber line, is the physical link between the customer premises and the nearest central office or point of presence of the service provider. By having multiple Internet connections from different providers or technologies, such as cable, DSL, fiber, wireless, or satellite, the recovery facilities can avoid losing connectivity in case one of the connections fails or is disrupted by a disaster5.
References:
9: Last Mile Redundancy - How to Ensure Business Continuity - Multapplied Networks
NEW QUESTION # 69
Which of the following tests is an IS auditor performing when a sample of programs is selected to determine if the source and object versions are the same?
- A. A substantive test of program library controls
- B. A compliance test of the program compiler controls
- C. A substantive test of the program compiler controls
- D. A compliance test of program library controls
Answer: D
Explanation:
Explanation/Reference:
Explanation:
A compliance test determines if controls are operating as designed and are being applied in a manner that complies with management policies and procedures. For example, if the IS auditor is concerned whether program library controls are working properly, the IS auditor might select a sample of programs to determine if the source and object versions are the same. In other words, the broad objective of any compliance test is to provide auditors with reasonable assurance that a particular control on which the auditor plans to rely is operating as the auditor perceived it in the preliminary evaluation.
NEW QUESTION # 70
What is the purpose of using a write blocker during the acquisition phase of a digital forensics investigation?
- A. To preserve chain of custody
- B. To prevent evidence alteration
- C. To protect against self-destruct utilities
- D. To prevent the actuation of installed malware
Answer: B
NEW QUESTION # 71
An IS auditor has discovered that a software system still in regular use is years out of date and no longer supported The auditee has stated that it will take six months until the software is running on the current version. Which of the following is the BEST way to reduce the immediate risk associated with using an unsupported version of the software?
- A. Monitor network traffic attempting to reach the outdated software system.
- B. Verify all patches have been applied to the software system's outdated version
- C. Close all unused ports on the outdated software system.
- D. Segregate the outdated software system from the main network.
Answer: D
NEW QUESTION # 72
.What should regression testing use to obtain accurate conclusions regarding the effects of changes or corrections to a program, and ensuring that those changes and corrections have not introduced new errors?
- A. Data from previous tests
- B. Independently created data
- C. Contrived data
- D. Live data
Answer: A
Explanation:
Regression testing should use data from previous tests to obtain accurate conclusions regarding the effects of changes or corrections to a program, and ensuring that those changes and corrections have not introduced new errors.
NEW QUESTION # 73
Which of the following would provide the BEST evidence that a cloud provider's change management process is effective?
- A. Written assurances from the vendor's CEO and CIO
- B. Minutes from regular change management meetings with the vendor
- C. A copy of change management policies provided by the vendor
- D. The results of a third-party review provided by the vendor
Answer: D
Explanation:
The results of a third-party review provided by the vendor would provide the best evidence that a cloud provider's change management process is effective, because it would be an independent and objective assessment of the vendor's compliance with best practices and standards for managing changes in the cloud environment. A third-party review would also include testing of the vendor's change management controls and procedures, and provide recommendations for improvement if needed.
Minutes from regular change management meetings with the vendor would not provide sufficient evidence, because they would only reflect the vendor's self-reported information and may not capture all the changes that occurred or their impact on the cloud services. Written assurances from the vendor's CEO and CIO would also not provide sufficient evidence, because they would be based on the vendor's own opinion and may not be verified by external sources. A copy of change management policies provided by the vendor would not provide sufficient evidence, because it would only show the vendor's intended approach to change management, but not how it is implemented or monitored in practice.
References:
ISACA Cloud Computing Audit Program, Section 4.5: Change Management
Cloud Computing: Business Benefits With Security, Governance and Assurance Perspectives, Section
4.3: Change Management
NEW QUESTION # 74
Which of the following is the MOST important control for virualized environments?
- A. Regular updates of policies for the operation of the virtualized environment
- B. Monitoring utilization of resources at the guest operating system level
- C. Redundancy of hardware resources and network components
- D. Hardening for the hypervisor and guest machines
Answer: D
Explanation:
The most important control for virtualized environments is hardening for the hypervisor and guest machines. Hardening the hypervisor and guest machines involves taking measures to ensure that the system is secure and protected from external threats. This includes ensuring that all security patches and updates are applied, that the systems are configured securely, and that only approved applications are allowed to run. Additionally, it is important to ensure that the system is regularly monitored for any malicious activity. For more information, please refer to the ISACA CISA Study Guide section 4.13.4.1.
NEW QUESTION # 75
While conducting an audit of a service provider, an IS auditor observes that the service provider has outsourced a part of the work to another provider. Since the work involves confidential information, the IS auditor's PRIMARY concern shouldbe that the:
- A. other service provider to whom work has been outsourced is not subject to audit.
- B. outsourcer will approach the other service provider directly for further work.
- C. contract may be terminated because prior permission from the outsourcer was not obtained.
- D. requirement for protecting confidentiality of information could be compromised.
Answer: D
Explanation:
Explanation/Reference:
Explanation:
Many countries have enacted regulations to protect the confidentiality of information maintained in their countries and/or exchanged with other countries. Where a service provider outsources part of its services to another service provider, there is a potential risk that the confidentiality of the information will be compromised. Choices B and C could be concerns but are not related to ensuring the confidentiality of information. There is no reason why an IS auditor should be concerned with choice D.
NEW QUESTION # 76
Which of the following reports would provide the GREATEST assurance to an IS auditor about the controls of a third party that processes critical data for the organization?
- A. Black box penetration test report
- B. Independent control assessment
- C. Vulnerability scan report
- D. The third party's control self-assessment (CSA)
Answer: B
NEW QUESTION # 77
......
Prepare for the Actual Certified Information Systems Auditor CISA Exam Practice Materials Collection: https://www.actualcollection.com/CISA-exam-questions.html
Certified Information Systems Auditor Certification CISA Sample Questions Reliable: https://drive.google.com/open?id=1oJO8hhOltJLJ0eraNsEYzDYL1ytA42my