In which phase of the audit life cycle process should an IS auditor initially discuss observations with management?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationAudit findings should be communicated as early as possible to avoid misunderstandings, provide an opportunity for corrective action, and ensure transparency. Option A (Incorrect):The planning phase involves defining audit scope, objectives, and methodology, but findings are not yet available to discuss with management. Option B (Incorrect):The reporting phase formalizes audit results, but discussing issuesonlyat this stage may lead to delays in corrective action. Option C (Incorrect):The follow-up phase ensures that management has implemented corrective actions, but this occursafterthe initial discussion of findings. Option D (Correct):The fieldwork phase is when auditors activelygather evidence, analyze data, and identify issues. Discussing observationsduringthis phase allows for immediate clarification, validation, and resolution of misunderstandings before the final report. References: ISACA CISA Review Manual -Domain 1: Information Systems Auditing Process-Discusses audit engagement, reporting, and communication best practices.
When evaluating the design of controls related to network monitoring, which of the following is MOST important for an IS auditor to review?
-
A
-
B
The ISP service level agreement
-
C
Reports of network traffic analysis
-
D
Network topology diagrams
Reveal answer details
Close answer details
Correct answerD
ExplanationNetwork topology diagrams are the most important for an IS auditor to review when evaluating the design of controls related to network monitoring, because they show how the network components are connected and configured, and what security measures are in place to protect the network from unauthorized access or attacks. Incident monitoring logs, the ISP service level agreement, and reports of network traffic analysis are useful for evaluating the effectiveness and performance of network monitoring, but not the design of controls. References: CISA Review Manual (Digital Version), Chapter 5, Section 5.3.3
An IS auditor has been asked to assess the security of a recently migrated database system that contains personal and financial data for a bank's customers. Which of the following controls is MOST important for the auditor to confirm is in place?
-
A
The default configurations have been changed.
-
B
All tables in the database are normalized.
-
C
The service port used by the database server has been changed.
-
D
The default administration account is used after changing the account password.
Reveal answer details
Close answer details
Which of the following BEST enables alignment of IT with business objectives?
-
A
Benchmarking against peer organizations
-
B
Developing key performance indicators (KPIs)
-
C
Completing an IT risk assessment
-
D
Leveraging an IT governance framework
Reveal answer details
Close answer details
Correct answerD
ExplanationLeveraging an IT governance framework is the best way to enable alignment of IT with business objectives, as it provides a set of principles, standards, processes, and practices that guide the effective delivery of IT services that support the organization's strategy and goals. Benchmarking against peer organizations, developing key performance indicators (KPIs), and completing an IT risk assessment are useful activities that can help measure and improve the performance and value of IT, but they are not sufficient to ensure alignment without a governance framework. References: CISA Review Manual (Digital Version), Chapter 1: Information Systems Auditing Process, Section 1.2: IT Governance
An IS auditor observes that a business-critical application does not currently have any level of fault tolerance. Which of the following is the GREATEST concern with this situation?
-
A
-
B
Limited tolerance for damage
-
C
Decreased mean time between failures (MTBF)
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationThe greatest concern with this situation is that a business-critical application does not currently have any level of fault tolerance and thus has a single point of failure. A single point of failure is a component or element of a system that, if it fails, will cause the entire system to stop functioning. Fault tolerance is the ability of a system to continue operating without interruption or degradation in the event of a failure of one or more of its components or elements. Fault tolerance can be achieved by using techniques such as redundancy, replication, backup, or failover. A business-critical application should have a high level of fault tolerance to ensure its availability, reliability, and continuity. References: CISA Review Manual (Digital Version), Chapter 5, Section 5.51 CISA Online Review Course,Domain 3, Module 3, Lesson 22
Which of the following should an IS auditor be MOST concerned with during a post-implementation review?
-
A
The system does not have a maintenance plan.
-
B
The system contains several minor defects.
-
C
The system deployment was delayed by three weeks.
-
D
The system was over budget by 15%.
Reveal answer details
Close answer details
Which of the following is an IS auditor ' s BEST approach when prepanng to evaluate whether the IT strategy supports the organization ' s vision and mission?
-
A
Review strategic projects tor return on investments (ROls)
-
B
Solicit feedback from other departments to gauge the organization ' s maturity
-
C
Meet with senior management to understand business goals
-
D
Review the organization ' s key performance indicators (KPls)
Reveal answer details
Close answer details
Correct answerC
ExplanationThe best approach for an IS auditor to evaluate whether the IT strategy supports the organization's vision and mission is to meet with senior management to understand the business goals and how IT can enable them. This will help the IS auditor to assess the alignment and integration of IT with the business strategy and to identify any gaps or opportunities for improvement. Reviewing ROIs, KPIs, or feedback from other departments may provide some insights, but they are not sufficient to evaluate the IT strategy. References: IS Audit and Assurance Standards, section "Standard 1201: Engagement Planning"
An IS auditor discovers an option in a database that allows the administrator to directly modify any table. This option is necessary to overcome bugs in the software, but is rarely used. Changes to tables are automatically logged. The IS auditor ' s FIRST action should be to:
-
A
recommend that the option to directly modify the database be removed immediately.
-
B
recommend that the system require two persons to be involved in modifying the database.
-
C
determine whether the log of changes to the tables is backed up.
-
D
determine whether the audit trail is secured and reviewed.
Reveal answer details
Close answer details
Correct answerD
ExplanationThe IS auditor's first action after discovering an option in a database that allows the administrator to directly modify any table should be to determine whether the audit trail is secured and reviewed. This is because direct modification of database tables can pose a significant risk to data integrity, security, and accountability. An audit trail is a record of all changes made to database tables, including who made them, when they were made, and what was changed. An audit trail can help to detect unauthorized or erroneous changes, provide evidence for investigations or audits, and support data recovery or restoration. The IS auditor should assess whether the audit trail is protected from tampering or deletion, and whether it is regularly reviewed for anomalies or exceptions.
Which of the following should an IS auditor use when verifying a three-way match has occurred in an enterprise resource planning (ERR) system?
-
A
-
B
Goods delivery notification
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationA three-way match is a process of verifying that a purchase order, a goods receipt and an invoice are consistent before making a payment 1. A three-way match ensures that the organization only pays for the goods or services that it ordered and received, and that the prices and quantities are accurate. A three-way match can prevent errors, fraud and overpayments in the accounts payable process. An IS auditor should use a purchase order when verifying a three-way match has occurred in an enterprise resource planning (ERP) system. A purchase order is a document that authorizes a purchase transaction and specifies the items, quantities, prices and terms of the order 2. A purchase order is the first document in the three-way match process, and it serves as the basis for comparing the goods receipt and the invoice. An IS auditor can use a purchase order to check if the ERP system has correctly recorded, matched and approved the three documents before making a payment. The other options are not as useful for verifying a three-way match. A bank confirmation is a document that verifies the balance and activity of a bank account 3. A bank confirmation can be used to confirm that a payment has been made or received, but it does not provide information about the details of the purchase transaction or the three-way match process. A goods delivery notification is a document that informs the buyer that the goods have been shipped or delivered by the seller 4. A goods delivery notification can be used to track the status of the delivery, but it does not provide information about the quantity or quality of the goods or the invoice amount. A purchase requisition is a document that requests authorization to purchase goods or services from a specific supplier 2. A purchase requisition can be used to initiate the purchasing process, but it does not provide information about the actual purchase order, goods receipt or invoice. References: Bank Confirmation - Overview, How It Works, Importance3 What is Goods Delivery Note? | Definition and Example4 What Is Three-Way Matching and Why Is It Important? | NetSuite1 Enterprise Resource Planning (ERP) - Definition, Types, Uses2
Question 10
Single choice
Which of the following should an IS auditor recommend be done FIRST when an organization is made aware of a new regulation that is likely to impact IT security requirements?
-
A
Update security policies based on the new regulation.
-
B
Determine which systems and IT-related processes may be impacted.
-
C
Evaluate how security awareness and training content may be impacted.
-
D
Review the design and effectiveness of existing IT controls.
Reveal answer details
Close answer details
Correct answerB
ExplanationThe first thing that an IS auditor should recommend when an organization is made aware of a new regulation that is likely to impact IT security requirements is to determine which systems and IT-related processes may be impacted. This is because the impact assessment is a crucial step to understand the scope and magnitude of the changes that the new regulation may entail, as well as the potential risks and gaps that need to be addressed. The impact assessment can help the organization to prioritize and plan the necessary actions and resourcesto comply with the new regulation in a timely and effective manner 12. Updating security policies based on the new regulation is not the first thing to do, because it requires a clear understanding of the impact and implications of the new regulation, which can only be obtained after conducting an impact assessment. Updating security policies without an impact assessment may result in incomplete, inconsistent, or ineffective policies that may not meet the regulatory requirements or the organizational needs 12. Evaluating how security awareness and training content may be impacted is not the first thing to do, because it is a secondary or supporting activity that depends on the results of the impact assessment and the policy updates. Evaluating security awareness and training content without an impact assessment or policy updates may result in inaccurate, outdated, or irrelevant content that may not reflect the regulatory requirements or the organizational expectations 34. Reviewing the design and effectiveness of existing IT controls is not the first thing to do, because it is a monitoring or assurance activity that follows the implementation of the changes based on the impact assessment and the policy updates. Reviewing IT controls without an impact assessment or policy updates may result in misleading, incomplete, or invalidfindings that may not capture the regulatory requirements or the organizational performance
Question 11
Single choice
Which of the following is the BEST recommendation to include in an organization ' s bring your own device (BYOD) policy to help prevent data leakage?
-
A
Require employees to waive privacy rights related to data on BYOD devices.
-
B
Require multi-factor authentication on BYOD devices,
-
C
Specify employee responsibilities for reporting lost or stolen BYOD devices.
-
D
Allow only registered BYOD devices to access the network.
Reveal answer details
Close answer details
Correct answerB
ExplanationThe best recommendation to include in an organization's bring your own device (BYOD) policy to help prevent data leakage is to require multi-factor authentication on BYOD devices. BYOD is a practice that allows employees to use their own personal devices, such as smartphones, tablets, or laptops, to access the organization's network, data, and systems. Data leakage is a risk that involves the unauthorized or accidental disclosure or transfer of sensitive or confidential data from the organization to external parties or devices. Multi-factor authentication is a security measure that requires users to provide two or more pieces of evidence to verify their identity and access rights, such as passwords, tokens, biometrics, or codes. Multi-factor authentication can help prevent data leakage by reducing the likelihood of unauthorized access to the organization's data and systems throughBYOD devices, especially if they are lost, stolen, or compromised. The other options are not as effective as requiring multi-factor authentication on BYOD devices, because they either do not prevent data leakage directly, or they are reactive rather than proactive measures. References: CISA Review Manual (Digital Version)1, Chapter 5, Section 5.2.3
Question 12
Single choice
An IS auditor is reviewing a machine learning algorithm-based system for loan approvals and is preparing a data set to test the algorithm for bias. Which of the following is MOST important for the auditor's test data set to include?
-
A
-
B
Applicants from a range of geographic areas and income levels
-
C
Incomplete records and incorrectly formatted data
-
D
Reveal answer details
Close answer details
Question 13
Single choice
Which of the following findings would be of GREATEST concern when reviewing project risk management practices?
-
A
Ongoing issues are not formally tracked.
-
B
Project management software is not being used.
-
C
Qualitative risk analyses have not been updated.
-
D
There are no formal milestone sign-offs.
Reveal answer details
Close answer details
Correct answerC
ExplanationThe best answer is C. Qualitative risk analyses have not been updated. ISACA guidance describes the risk register as a living document that should be regularly reviewed and amended so management has an up-to-date picture of risk when making decisions. If qualitative risk analyses are not updated, the project may be working from outdated assumptions about probabilit y, impact, and priority, which undermines the entire risk management process. Option A is a concern, but issue tracking is not as central to project risk management as keeping risk analysis current. Option B is not inherently a weakness because effective risk management does not depend on a specific software tool. Option D is a governance concern, but stale risk analysis more directly damages the organization's ability to identify, assess, prioritize, and respond to project risk. References (Official ISACA): ISACA Journal, Mitigating Technical Vulnerabilities With Risk Assessment - the risk register is a living document that should be regularly reviewed and amended. ISACA, Making Risk Management for Agile Projects Effective - risk registers are updated throughout the project lifecycle.
Question 14
Single choice
What should an IS auditor do FIRST upon discovering that a service provider did not notify its customers of a security breach?
-
A
Notify law enforcement of the finding.
-
B
Require the third party to notify customers.
-
C
The audit report with a significant finding.
-
D
Notify audit management of the finding.
Reveal answer details
Close answer details
Correct answerD
ExplanationThe IS auditor should notify audit management of the finding first, as this is a significant issue that may affect the audit scope and objectives. The IS auditor should not notify law enforcement or require the third party to notify customers without consulting audit management first. The audit report with a significant finding should be issued after the audit is completed and the findings are validated. References: ISACA, CISA Review Manual, 27th Edition, 2018, page 247
Question 15
Single choice
Which of the following is the BEST control to minimize the risk of unauthorized access to lost company-owned mobile devices?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationThe best control to minimize the risk of unauthorized access to lost company-owned mobile devices is device encryption. Device encryption is a process that transforms data on a device into an unreadable format using a cryptographic key. Device encryption protects the data stored on the device from being accessed by unauthorized parties, even if they bypass the password or PIN protection. Device encryption can also prevent data leakage if the device is disposed of or recycled without proper data sanitization. Password or PIN protection is a basic control that prevents unauthorized access to the device by requiring a secret code or pattern to unlock it. However, password or PIN protection can be easily compromised by brute force attacks, shoulder surfing, or social engineering. Device trackingsoftware is a tool that allows the device owner or administrator to locate, lock, or wipe the device remotely in case of loss or theft. However, device tracking software depends on the device's network connectivity and GPS functionality, which may not be available or reliable in some situations. Periodic backup is a process that copies the data from the device to another storage location for recovery purposes. Periodic backup can help restore the data in case of loss or damage of the device, but it does not prevent unauthorized access to the data on the device itself. References: CISA ReviewManual (Digital Version), Chapter 5: Protection of Information Assets, Section 5.4: Mobile Devices
Question 16
Single choice
What is the MAIN purpose of an organization ' s internal IS audit function?
-
A
Identify and initiate necessary changes in the control environment to help ensure sustainable improvement.
-
B
Independently attest the organization's compliance with applicable legal and regulatory requirements.
-
C
Review the organization ' s policies and procedures against industry best practices and standards.
-
D
Provide assurance to management about the effectiveness of the organization ' s risk management and internal controls.
Reveal answer details
Close answer details
Correct answerD
ExplanationTheprimary roleof an internalIS audit functionis to provideindependent assuranceonrisk management, internal controls, and governance processes. Option A (Incorrect):While audits may identifycontrol improvements, they donot initiate changes; management is responsible for implementation. Option B (Incorrect):Compliance audits arepartof IS auditing, but the main focus isassurance on risk and controls, not just compliance. Option C (Incorrect):Best practices and standards reviews are useful, but theydo not definethecore objectiveof an internal audit. Option D (Correct):The internal audit function ' smain goalis toassess and assurethe effectiveness of an organization'srisk management and internal controls. References: ISACA CISA Review Manual -Domain 1: Information Systems Auditing Process-Coversaudit objectives, assurance functions, and risk management.
Question 17
Single choice
Which of the following is MOST important to the effectiveness of smoke detectors installed in a data processing facility?
-
A
Detectors trigger audible alarms when activated.
-
B
Detectors have the correct industry certification.
-
C
Detectors are linked to dry pipe fire suppression systems.
-
D
Detectors are linked to wet pipe fire suppression systems.
Reveal answer details
Close answer details
Question 18
Single choice
Which of the following BEST protects evidence in a forensic investigation?
-
A
imaging the affected system
-
B
Powering down the affected system
-
C
Protecting the hardware of the affected system
-
D
Rebooting the affected system
Reveal answer details
Close answer details
Correct answerA
ExplanationImaging the affected system is the best way to protect evidence in a forensic investigation, because it creates a bit-by-bit copy of the original data that can be analyzed without altering or compromising the original source. Imaging preserves the integrity and authenticity of the evidence and allows for verification and validation of the results 34. Powering down or rebooting the affected system can cause data loss or corruption, while protecting the hardware does not prevent unauthorized access or tampering with the software or data. References: 3: CISA Review Manual (Digital Version), Chapter 6, Section 6.4.1 4: CISA Online Review Course, Module 6, Lesson 4
Question 19
Single choice
Which of the following helps to ensure the integrity of data for a system interface?
-
A
-
B
user acceptance testing (IJAT)
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationValidation checks are a type of data quality control that helps to ensure the integrity of data for a system interface. Validation checks verify that the data entered or transferred between systems is correct, consistent, and conforms to predefined rules or standards. Validation checks can prevent or detect errors, anomalies, or inconsistencies in the data that may affect the system's functionality, performance, or security. Option C is correct because validation checks are a common and effective method of ensuring data integrity for a system interface. Validation checks can be performed at various stages of the data lifecycle, such as input, processing, output, or storage. Validation checks can also be applied to different types of data, such as data types, codes, ranges, formats, consistency, and uniqueness. Option A is incorrect because system interface testing is a type of software testing that verifies the interaction between two separate systems or components of a system. System interface testing does not directly ensure the integrity of data for a system interface, but rather the functionality and reliability of the interface itself. System interface testing may use validation checks as part of its test cases, but it is not the same as validation checks. Option B is incorrect because user acceptance testing (UAT) is a type of software testing that evaluates whether the system meets the user's expectations and requirements. UAT does not directly ensure the integrity of data for a system interface, but rather the usability and acceptability of the system from the user's perspective. UAT may use validation checks as part of its test scenarios, but it is not the same as validation checks. Option D is incorrect because audit logs are records of events and activities that occur within a system or network. Audit logs do not directly ensure the integrity of data for a system interface, but rather provide evidence and accountability for the system's operations and security. Audit logs may use validation checks as part of their analysis or reporting, but they are not the same as validation checks. References: 5: Protection of Information Assets, Lesson 4: Data Quality Management, slide 5-6. CISA Review Manual (Digital Version)2, Chapter 5: Protection of Information Assets, Section 5.3: Data Quality Management, p. 281-282. CISA Review Manual (Print Version), Chapter 5: Protection of Information Assets, Section 5.3: Data Quality Management, p. 281-282. CISA Questions, Answers and Explanations Database3, Question ID: QAE_CISA_722. Data Validation - Overview, Types, Practical Examples4 Data Validity: The Best Practice for Your Business5 Validation - Data validation6 What is Data Validation? Types, Techniques, Tools7
Question 20
Single choice
An IS auditor is reviewing the perimeter security design of a network. Which of the following provides the GREATEST assurance outgoing Internet traffic is controlled?
-
A
Intrusion detection system (IDS)
-
B
Security information and event management (SIEM) system
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationA stateful firewall provides the greatest assurance that outgoing Internet traffic is controlled, as it monitors and filters packets based on their source, destination and connection state. A stateful firewall can prevent unauthorized or malicious traffic from leaving the network, as well as block incoming traffic that does not match an established connection. An intrusion detection system (IDS) can detect and alert on suspicious or anomalous traffic, but it does not block or control it. A security information and event management (SIEM) system can collect and analyze logs and events from various sources, but it does not directly control traffic. A load balancer can distribute traffic among multiple servers, but it does not filter or monitor it. References: CISA ReviewManual (Digital Version), Chapter 6, Section 6.2
Question 21
Single choice
Which of the following is the PRIMARY objective of performing quality assurance (QA) in a system development process?
-
A
To ensure that expected benefits have been realized
-
B
To ensure the developed system meets business requirements
-
C
To ensure the developed system integrates well with another system
-
D
To help determine high-level requirements for the new system
Reveal answer details
Close answer details
Question 22
Single choice
Which of the following is the PRIMARY purpose of enterprise architecture (EA) within an organization?
-
A
To structure IT projects to achieve desired business results.
-
B
To design and implement individual IT systems.
-
C
To design and manage day-to-day IT operations.
-
D
To oversee network security protocols.
Reveal answer details
Close answer details
Correct answerA
ExplanationThe correct answer is A. To structure IT projects to achieve desired business results. Enterprise architecture provides a structured view of the organization's business, information, application, and technology architecture. Its purpose is to ensure that IT initiatives and solutions support the organization's strategy, mission, business goals, and target operating model. ISACA explains that enterprise architecture supports a holistic organizational view and helps design business, information, and technology architecture. ISACA also describes EA as a framework used to architect the operating or business model and systems to meet vision, mission, and business goals and deliver enterprise strategy. Option B is too narrow because EA guides the architecture of systems and capabilities, but it is not mainly about designing and implementing individual systems. Option C is not correct because day-to-day IT operations are handled through IT service management and operations management. Option D is also too narrow because network security is only one part of the broader enterprise architecture. This question maps to Governance and Management of IT, because enterprise architecture supports IT strategy, business alignment, governance, and IT investment decision-making. References: ISACA CISA Exam Content Outline, Domain 2 ISACA guidance on enterprise architecture and business alignment.
Question 23
Single choice
An organization ' s information security policies should be developed PRIMARILY on the basis of:
-
A
enterprise architecture (EA).
-
B
-
C
a risk management process.
-
D
past information security incidents.
Reveal answer details
Close answer details
Question 24
Single choice
Which of the following is the MOST reliable way for an IS auditor to evaluate the operational effectiveness of an organization ' s data loss prevention (DLP) controls?
-
A
Review data classification levels based on industry best practice
-
B
Verify that current DLP software is installed on all computer systems.
-
C
Conduct interviews to identify possible data protection vulnerabilities.
-
D
Verify that confidential files cannot be transmitted to a personal USB device.
Reveal answer details
Close answer details
Correct answerD
ExplanationThe most reliable way for an IS auditor to evaluate the operational effectiveness of an organization's data loss prevention (DLP) controls is to verify that confidential files cannot be transmitted to a personal USB device. This is because DLP controls are designed to prevent the loss, leakage or misuse of sensitive data through breaches, ex-filtration transmissions and unauthorized use 1. A personal USB device is a common way for data to be stolen or compromised, as it can bypass network security measures and allow unauthorized access to confidential files. Therefore, testing the DLP controls by attempting to copy or transfer confidential files to a personal USB device can provide a direct and objective evidence of whether the DLP controls are working as intended or not. The other options are less reliable ways for an IS auditor to evaluate the operational effectiveness of an organization's DLP controls. Reviewing data classification levels based on industry best practice is a way to assess the adequacy of the organization's data protection policies, but it does not measure how well the DLP controls are implemented or enforced in practice. Verifying that current DLP software is installed on all computer systems is a way to check the technical configuration of the DLP solution, but it does not test how well the DLP software detects and prevents data loss incidents in real scenarios. Conducting interviews to identify possible data protection vulnerabilities is a way to gather qualitative information from stakeholders, but it does not provide quantitative or empirical data on the actual performance of the DLP controls. References: What is Data Loss Prevention (DLP)? [Guide] - CrowdStrike
Question 25
Single choice
An IS auditor reviewing an organization's online payment system finds that the system sometimes duplicates payments. Which control will BEST compensate for this weakness?
-
A
Manually receipting payments.
-
B
-
C
-
D
Performing a bank reconciliation.
Reveal answer details
Close answer details
Correct answerD
ExplanationThe correct answer is D. Performing a bank reconciliation. A duplicate payment is a transaction-processing error that affects financial completeness and accuracy. A bank reconciliation is the best compensating control among the options because it compares the organization's payment records with actual bank activity and helps identify duplicate or incorrect payments after processing. Option A is not the best answer because manually receipting payments is inefficient and does not reliably detect duplicate outgoing payments. Option B is not correct because hash totals are usually nonfinancial totals used to check processing completeness, such as account number totals, and would not effectively identify duplicate payments. Option C may help detect differences in batch totals, but duplicate online payments can still occur unless the reconciliation identifies the actual duplicate disbursement or settlement. ISACA has discussed duplicate payment detection as an internal control concern and notes that automated controls can detect duplicate and fraudulent transactions across complete data sets. That supports the control principle that duplicate payments require detective/reconciliation controls, not merely basic totals. References: ISACA CISA Exam Content Outline, Domain 3 ISACA Journal, automated internal controls and duplicate payment detection.
Question 26
Single choice
An IS auditor discovers that validation controls m a web application have been moved from the server side into the browser to boost performance. This would MOST likely increase the risk of a successful attack by.
-
A
-
B
-
C
structured query language (SQL) injection
-
D
Reveal answer details
Close answer details
Question 27
Single choice
Which of the following is MOST important to include in a business case for an IT-enabled investment?
-
A
Business impact analysis (BIA)
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 28
Single choice
Which of the following is an objective of IT project portfolio management?
-
A
Successful implementation of projects
-
B
Selection of sound, strategically aligned investment opportunities
-
C
Validation of business case benefits
-
D
Establishment of tracking mechanisms
Reveal answer details
Close answer details
Question 29
Single choice
An organization allows employees to retain confidential data on personal mobile devices. Which of the following is the BEST recommendation to mitigate the risk of data leakage from lost or stolen devices?
-
A
Require employees to attend security awareness training.
-
B
Password protect critical data files.
-
C
Configure to auto-wipe after multiple failed access attempts.
-
D
Enable device auto-lock function.
Reveal answer details
Close answer details
Correct answerC
ExplanationThe best recommendation to mitigate the risk of data leakage from lost or stolen devices that contain confidential data is to configure them to auto-wipe after multiple failed access attempts, as this would prevent unauthorized access and erase sensitive information from the device. Requiring employees to attend security awareness training, password protecting critical data files, or enabling device auto-lockfunction are also good practices, but they may not be sufficient oreffective in preventing data leakage from lost or stolen devices. References: CISA Review Manual (Digital Version), Chapter 5, Section 5.3
Question 30
Single choice
A checksum is classified as which type of control?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationA checksum is classified as a detective control. A checksum is a mathematical value that is calculated from a data set and used to verify the integrity of the data. A checksum can detect if the data has been altered or corrupted during transmission or storage. A checksum does not prevent or correct the data corruption, but it alerts the user or system of the problem. Therefore, it is a detective control. A preventive control is a control that prevents an error or incident from occurring. A corrective control is a control that restores normal operations after an error or incident has occurred. Anadministrative control is a controlthat involves policies, procedures, standards, guidelines, or organizational structures. References: CISA Review Manual (Digital Version)1, page 439.
Question 31
Single choice
An IS auditor decides to review a data inventory list captured directly from a system instead of relying on an interview with the system owner. Which of the following provides the BEST justification for the auditor ' s decision?
-
A
Independence of the evidence provider
-
B
Qualification of the evidence provider
-
C
Reliability of the evidence
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationSystem-generated data is generally more reliable than interview evidence, which is subjective and prone to bias. Audit standards emphasize evidence that is sufficient and appropriate, where appropriateness relates to relevance and reliability. References (ISACA): ISACA Audit Standards - Evidence Collection.
Question 32
Single choice
Which of the following types of environmental equipment will MOST likely be deployed below the floor tiles of a data center?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationWater sensors are devices that can detect the presence of water or moisture in a given area. They are often deployed below the floor tiles of a data center to monitor for any water leaks that may damage the equipment or cause electrical hazards. Water sensors can alert the data center staff or trigger an automatic response to prevent or mitigate the water leakage. The other options are not likely to be deployed below the floor tiles of a data center. Temperature sensors and humidity sensors are usually deployed above the floor tiles to measure the ambient conditions of the data center and ensure optimal cooling and ventilation. Air pressure sensors are typically deployed at the air vents or ducts to monitor the airflow and pressure distribution in the data center. References: Data Center Environmental Monitoring Water Detection in Data Centers
Question 33
Single choice
In a review of the organization standards and guidelines for IT management, which of the following should be included in an IS development methodology?
-
A
Value-added activity analysis
-
B
Risk management techniques
-
C
-
D
Incident management techniques
Reveal answer details
Close answer details
Correct answerB
ExplanationRisk management techniques should be included in an IS development methodology. An IS development methodology is a set of guidelines, standards, and procedures that provide a structured and consistent approach to developinginformation systems. A good IS development methodology should cover all the phases of the system development life cycle (SDLC), from planning and analysis to design, implementation, testing, and maintenance 1. Risk management techniques are an essential part of an IS development methodology, as they help to identify, assess, prioritize, mitigate, monitor, and communicate the risks that may affect the success of the system development project. Risk management techniques can also help to ensure that the system meets the requirements and expectations of the stakeholders, complies with the relevant laws and regulations, and delivers value to the organization 2. The other options are not as relevant or appropriate as risk management techniques for an IS development methodology. Value-added activity analysis is a technique for evaluating the efficiency and effectiveness of business processes, but it is not specific to IS development 3. Access control rules are policies and mechanisms for restricting or granting access to information systems and resources, but they are more related to security management than IS development 4. Incident management techniques are methods for handling and resolving incidents that disrupt the normal operation of information systems and services, but they are more related to service management than IS development 5. References: ISACA, CISA Review Manual, 27th Edition, 2019, p. 1911 ISACA, CISA Review Manual, 27th Edition, 2019, p. 1942 Value-Added Activity Analysis3 Access Control Rules4 Incident Management Techniques5
Question 34
Single choice
A national bank recently migrated a large number of business-critical applications to the cloud. Which of the following is MOST important to ensuring the resiliency of the applications?
-
A
Negotiating a nondisclosure agreement (NDA) with the provider
-
B
Conducting periodic system stress testing
-
C
Creating restore points for critical applications
-
D
Using a monitoring tool to assess uptime
Reveal answer details
Close answer details
Question 35
Single choice
An organization has initiated a project to migrate to a new accounts payable system. Which of the following responsibilities is MOST important to assign to the accounts payable business process owner working on this project?
-
A
Identifying functional requirements the new system must meet.
-
B
Ensuring the migration project is delivered on time and on budget.
-
C
Monitoring resource utilization on the new system.
-
D
Ensuring the supporting infrastructure is secure.
Reveal answer details
Close answer details
Correct answerA
ExplanationThe correct answer is A. Identifying functional requirements the new system must meet. The accounts payable business process owner understands how the accounts payable process works, what business rules must be followed, what approvals are required, what reports are needed, what controls are required, and what exceptions must be handled. Therefore, the business process owner's most important project responsibility is to identify and validate the functional requirements the new system must meet. Functional requirements describe what the system is supposed to accomplish. ISACA describes functional requirements as being focused on system functionality, while performance requirements address areas such as transaction speed, scalability, and related system characteristics. Option B is not the best answer because delivering the project on time and on budget is mainly the responsibility of the project manager and project governance structure. Option C is not the best answer because monitoring resource utilization is an IT operations or capacity management responsibility. Option D is not the best answer because infrastructure security is primarily the responsibility of IT/security teams, although the business owner should help identify business control and data protection needs. This question maps to Information Systems Acquisition, Development and Implementation because requirements definition, business participation, and implementation readiness are core system acquisition and implementation topics in Domain 3 of the CISA Exam Content Outline. References: ISACA CISA Exam Content Outline, Domain 3 ISACA Journal, An Evolutionary Strategy for Leveraging Data Risk-Based Software Development for Data Integrity.
Question 36
Single choice
An IS auditor has identified deficiencies within the organization ' s software development life cycle policies. Which of the following should be done NEXT?
-
A
Document the findings in the audit report.
-
B
Identify who approved the policies.
-
C
Escalate the situation to the lead auditor.
-
D
Communicate the observation to the auditee.
Reveal answer details
Close answer details
Correct answerD
ExplanationAn IS auditor has identified deficiencies within the organization's software development life cycle (SDLC) policies. The SDLC is the process of planning, developing, testing, and deploying software applications 1. SDLC policies are the guidelines and standards that govern the SDLC process and ensure its quality, security, and compliance 2. Deficiencies in SDLC policies can lead to various risks, such as: Software errors, bugs, or vulnerabilities that can affect the functionality, reliability, or security of the applications3 Software failures, delays, or overruns that can affect the delivery, performance, or customer satisfaction of the applications3 Software non-compliance that can result in legal, regulatory, or contractual violations or penalties3 The next step that the IS auditor should do after identifying deficiencies in SDLC policies is to communicate the observation to the auditee. The auditee is the person or entity that is subject to the audit and is responsible for the area being audited 4. In this case, the auditee could be the software development manager, the project manager, or the senior management of the organization. Communicating the observation to the auditee is important for several reasons: It allows the IS auditor to verify the accuracy and validity of the observation and gather additional evidence or information from the auditee4 It gives the auditee an opportunity to respond to the observation and provide their perspective, explanation, or justification for the deficiencies4 It enables the IS auditor to discuss with the auditee the potential impact, root cause, and remediation plan for the deficiencies4 It fosters a collaborative and constructive relationship between the IS auditor and the auditee and promotes transparency and accountability in the audit process4 The other options are not as appropriate as communicating the observation to the auditee. Documenting the findings in the audit report is a later stepthat should be done after communicating with the auditee and finalizing the observation. Identifying who approved the policies is not relevant for addressing the deficiencies and may imply blame or fault on a specific person or group. Escalating the situation to the lead auditor is not necessary unless there is a serious disagreement or conflict with the auditee that cannot be resolved by normal communication. Therefore, option D is the correct answer. References: What Is The Software Development Life Cycle? | PagerDuty Software Development Life Cycle (SDLC) Policy | StrongDM What Is SDLC? Best Phases, Methodologies, and Benefits Revealed - Kellton Communicating Audit Findings
Question 37
Single choice
What should an IS auditor do FIRST when management responses to an in-person internal control questionnaire indicate a key internal control is no longer effective?
-
A
Determine the resources required to make the controleffective.
-
B
Validate the overall effectiveness of the internal control.
-
C
Verify the impact of the control no longer being effective.
-
D
Ascertain the existence of other compensating controls.
Reveal answer details
Close answer details
Correct answerD
ExplanationThe first thing that an IS auditor should do when management responses to an in-person internal control questionnaire indicate a key internal control is no longer effective is to ascertain the existence of other compensating controls. Compensating controls are alternative controls that provide reasonable assurance of achieving the same objective as the original control. The IS auditor should verify whether there are any compensating controls in place that can mitigate the risk of the key control being ineffective, and evaluate their adequacy and effectiveness. The other options are not the first steps, because theyeither require more information about the compensating controls, or they are actions to be taken after identifying and assessing the compensating controls. References: CISA Review Manual (Digital Version)1, Chapter 2, Section 2.2.3
Question 38
Single choice
Which of the following should be of GREATEST concern to an IS auditor assessing the effectiveness of an organization ' s information security governance?
-
A
Risk assessments of information assets are not periodically performed.
-
B
-
C
The information security policy does not extend to service providers.
-
D
There is no process to measure information security performance.
-
E
The information security policy is not reviewed by executive management.
Reveal answer details
Close answer details
Question 39
Single choice
When auditing an organization ' s software acquisition process the BEST way for an IS auditor to understand the software benefits to the organization would be to review the
-
A
-
B
-
C
request for proposal (RFP)
-
D
alignment with IT strategy
Reveal answer details
Close answer details
Correct answerB
ExplanationThe best way for an IS auditor to understand the software benefits to the organization would be to review the business case, which is a document that provides the justification and rationale for acquiring a software solution based on its expected costs, benefits, risks, and alignment with the organization's goals and strategies. The business case helps to evaluate the feasibility and viability of the software acquisition and to support the decision-making process. A feasibility study is a document that analyzes the technical, operational, economic, legal, and social aspects of a software solution to determine its feasibility and suitability for the organization's needs, but it does not necessarily provide a clear indication of the software benefits to the organization. A request for proposal (RFP) is a document that solicits proposals from potential vendors or suppliers for a software solution based on the organization's requirements and specifications, but it does not necessarily provide a clear indication of the software benefits to the organization. The alignment with IT strategy is a factor that influences the software acquisition processand ensures that the software solution supports and enables the organization's IT strategy, but it is not a document that can be reviewed by an IS auditor to understand the software benefits to the organization. References: CISA Review Manual (Digital Version), Chapter 3: Information Systems Acquisition, Development and Implementation, Section 3.1: Business Case Development
Question 40
Single choice
Which of the following should an organization do to anticipate the effects of a disaster?
-
A
Define recovery point objectives (RPO)
-
B
Simulate a disaster recovery
-
C
Develop a business impact analysis (BIA)
-
D
Analyze capability maturity model gaps
Reveal answer details
Close answer details
Correct answerC
ExplanationA business impact analysis (BIA) is the process of identifying and assessing the potential impacts a disruption or incident could have on an organization. A BIA helps organizations understand and prepare for these potential obstacles, so they can act quickly and face challenges head-on when they arise. A BIA tells the organization what to expect when unforeseen roadblocks occur, so they can make a plan to get their business back on track as quickly as possible. Therefore, a BIA is the best option to anticipate the effects of a disaster. References: 10: Business Impact Analysis (BIA): Prepare for Anything [2023] - Asana 11: Definition of Business Impact Analysis (BIA) - IT Glossary | Gartner Information Technology 12: Business impact analysis (BIA) is a method to predict the consequences of disruptions to a business, its processes and systems by collecting relevant data.
Question 41
Single choice
A financial group recently implemented new technologies and processes, Which type of IS audit would provide the GREATEST level of assurance that the department ' s objectives have been met?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationThe type of IS audit that would provide the greatest level of assurance that the department's objectives have been met after implementing new technologies and processes is an integrated audit. An integrated audit is an audit that combines financial, operational, compliance, and IT auditing aspects to provide a holistic view of the organization's performance and risks. An integrated audit can evaluate whether the new technologies and processes are aligned with the organization's goals, strategies, policies, and controls, and whether they are delivering value, efficiency, effectiveness, and reliability. The other types of IS audits (A, C and D) would not provide the same level of assurance, as they would only focus on specific aspects of the organization's activities, such as performance, cyber security, or financial reporting, which may not capture the full impact of the new technologies and processes. References: CISA Certification | Certified Information Systems Auditor | ISACA, CISA Review Manual (Digital Version), Chapter 1: The Process of Auditing Information Systems, Section 1.2: Types of IS Audit Engagements
Question 42
Single choice
Which of the following is the PRIMARY role of the release plan?
-
A
It identifies all configuration items within an IT environment.
-
B
It provides a timeline and schedule for deploying new releases into production.
-
C
It outlines the steps for database integration.
-
D
It evaluates the impact of proposed changes and updates to IT systems.
Reveal answer details
Close answer details
Correct answerB
ExplanationThe best answer is B. It provides a timeline and schedule for deploying new releases into production. ISACA release and change guidance explains that successful deployment requires scrutiny over change and release, including scheduling, coordination among parties, and validation before implementation. That aligns directly with the role of a release plan: organizing when and how releases move into production. Option A is more closely related to configuration management. Option C is too narrow because release plans cover much more than database integration. Option D is more closely associated with change evaluation and impact assessment before approval. The release plan's main function is the coordinated timeline and schedule for production rollout. References (Official ISACA): ISACA Journal, Implementing Emerging Technologies ISACA Journal, Speeding Up Software Delivery With Effective Change Management
Question 43
Single choice
What is the PRIMARY purpose of performing a parallel run of a now system?
-
A
To train the end users and supporting staff on the new system
-
B
To verify the new system provides required business functionality
-
C
To reduce the need for additional testing
-
D
To validate the new system against its predecessor
Reveal answer details
Close answer details
Correct answerD
ExplanationThe primary purpose of performing a parallel run of a new system is to validate the new system against its predecessor. A parallel run is a strategy for system changeover where a new system slowly assumes the roles of the older system while both systems operate simultaneously. This allows for comparison of the results and outputs of both systems to ensure that the new system is working correctly and reliably. A parallel run can also help identify and resolve any errors, discrepancies, or inconsistencies in the new system before the old system is discontinued. The other options are not the primary purpose of performing a parallel run of a new system. A. To train the end users and supporting staff on the new system. Training is an important part of s ystem implementation, but it is not the main reason for doing a parallel run. Training can be done before, during, or after the parallel run, depending on the needs and preferences of the organization. B. To verify the new system provides required business functionality. Verifying the business functionality of the new system is part of user acceptance testing (UAT), which is a formal and structured process of testing whether the new system meets the specifications and expectations of the users and stakeholders. UAT is usually done before the parallel run, as a prerequisite for system changeover. C. To reduce the need for additional testing. Reducing the need for additional testing is not the primary purpose of performing a parallel run, but rather a possible benefit or outcome of doing so. A parallel run can help ensure that the new system is thoroughly tested and validated in a real-worldenvironment, which may reduce the likelihood of encountering major issues or defects later on. However, additional testing may still be needed after the parallel run, depending on the feedback and evaluation of the users and stakeholders. References: ISACA, CISA Review Manual, 27th Edition, 2019, p. 2471 IS
Question 44
Single choice
An organization is disposing of removable onsite media which contains sensitive information. Which of the following is the MOST effective method to prevent disclosure of sensitive data?
-
A
Encrypting and destroying keys
-
B
-
C
-
D
Wiping and rewriting three times
Reveal answer details
Close answer details
Correct answerB
ExplanationMachine shredding is the process of using a shredding machine to physically destroy the media and make the data unrecoverable. This is more effective than software formatting, which only erases the data logically and may leave traces that can be recovered by special tools 1. Encrypting and destroying keys may prevent unauthorized access to the data, but it does not erase the data from the media. Wiping and rewriting three times is unnecessary and may reduce the lifespan of the media, especially for solid state drives 2. Machine shredding is also recommended by various security standards and guidelines for media disposal 345.
Question 45
Single choice
The PRIMARY purpose of a configuration management system is to:
-
A
-
B
define baselines for software.
-
C
support the release procedure.
-
D
standardize change approval.
Reveal answer details
Close answer details
Correct answerB
ExplanationA configuration management system is a process that establishes and maintains the consistency of a product's attributes throughout its life cycle. It helps to identify and control the functional and physical characteristics of a product, and to record and report any changes to those characteristics. A configuration management system also supports the audit of the product to verify its conformance to requirements. One of the key activities of a configuration management system is to define baselines for software. A baseline is a fixed reference point that serves as a basis for comparison and measurement. A baseline can be established for any configuration item, such as a requirement, a design document, a test plan, or a software component. A baseline helps to ensure that the software product meets its intended purpose and quality standards, and that any changes to the software are controlled and documented. A configuration management system also supports other activities, such as tracking software updates, supporting the release procedure, and standardizing change approval, but these are not its primary purpose. Therefore, the other options are incorrect. References: : What is configuration management - Red Hat: Configuration Management | Definition, Importance and Benefits - ServerWatch
Question 46
Single choice
An IS auditor notes the transaction processing times in an order processing system have significantly increased after a major release. Which of the following should the IS auditor review FIRST?
-
A
-
B
-
C
Database conversion results
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationThe first thing that an IS auditor should review when finding that transaction processing times in an order processing system have significantly increased after a major release is stress testing results. Stress testing is a type of testing that evaluates how a system performs under extreme or abnormal conditions, such as high volume, load, or concurrency of transactions. Stress testing results can help explain why transaction processing times in an order processing system have significantly increased after a major release by revealing any bottlenecks, limitations, or errors in the system's capacity, performance, or functionality under stress. The other options are not as relevant as stress testing results in explaining why transaction processing times in an order processing system have significantly increased after a major release, as they do not directly measure how the systemperforms under extreme or abnormal conditions. Capacity management plan is a document that defines and implements the processes and activities for ensuring that the system has adequate resources and capabilities to meet current and future demands. Training plans are documents that define and implement the processes and activities for ensuring that the system users have adequate skills and knowledge to use the system effectively and efficiently. Database conversion results are outcomes or outputs of transforming data from one format or structure to another to suit the system's requirements or specifications. References: CISA Review Manual (DigitalVersion), Chapter 3, Section 3.3
Question 47
Single choice
What Is the BEST method to determine if IT resource spending is aligned with planned project spending?
-
A
Earned value analysis (EVA)
-
B
Return on investment (ROI) analysis
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationThe best method to determine if IT resource spending is aligned with planned project spending is earned value analysis (EVA). EVA is a technique that compares the actual cost, schedule, and scope of a project with the planned or budgeted values. EVA can help to measure the project progress and performance, and identify any variances or deviations from the baseline plan 1. EVA uses three basic values to calculate the project status: planned value (PV), earned value (EV), and actual cost (AC). PV is the amount of work that was expected to be completed by a certain date, according to the project plan. EV is the amount of work that was actually completed by that date,measured in terms of the budgeted cost. AC is the amount of money that was actually spent to complete the work by that date 1. By comparing these values, EVA can determine if the project is on track, ahead, or behind schedule and budget. EVA can also calculate various indicators, such as cost variance (CV), schedule variance (SV), cost performance index (CPI), and schedule performance index (SPI), to quantify the magnitude and direction of the variances. EVA can also forecast the future performanceand completion of the project, based on the current trends and assumptions 1. The other options are not as effective as EVA in determining if IT resource spending is aligned with planned project spending. Option B, return on investment (ROI) analysis, is a technique that evaluates the profitability or efficiency of an investment, by comparing the benefits or revenues with the costs. ROI analysis can help to justify or prioritize a project, but it does not measure the actual progress or performance of the project against the plan 2. Option C, Gantt chart, is a tool that displays the tasks, durations, dependencies, and milestones of a project in a graphical format. Gantt chart can help to plan and monitor a project schedule, but it does not show the actual cost or scope of the project 3. Option D, critical path analysis, is a technique that identifies the longest sequence of tasks or activities that must be completed on time for the project to finish on schedule. Critical path analysis can help to optimize and control a project schedule, but it does not account for the actual cost or scope of the project 4. References: Earned Value Analysis and Management (EVA/EVM) - Definitionand Formulae1 Return on Investment (ROI) Formula2 What Is a Gantt Chart?3 Critical Path Method for Project Management
Question 48
Single choice
Which of the following is the MOST important regulatory consideration for an organization determining whether to use its customer data to train AI algorithms?
-
A
Documentation of AI algorithm accuracy during the training process
-
B
Ethical and optimal utilization of data computing resources
-
C
Collection of data and obtaining data subject consent
-
D
Continuous monitoring of AI algorithm performance
Reveal answer details
Close answer details
Correct answerC
ExplanationData collection and obtaining consentis themost critical regulatory requirementwhen using customer data for AI training, especially under laws likeGDPR, CCPA, and ISO 27701. Collection of Data and Obtaining Consent (Correct Answer - C) Ensures compliance withprivacy lawsthat require explicit customer consent. Example:UnderGDPR, companies mustinform usershow their data will be used and allow them toopt out. AI Algorithm Accuracy (Incorrect - A) Important formodel performancebutnot a primary legal concern. Ethical Use of Computing Resources (Incorrect - B) Ethical considerations are valuable butnot a regulatory priority. Continuous Monitoring of AI (Incorrect - D) Ensuresperformance, butregulatory compliance focuses on data privacy. References: ISACA CISA Review Manual GDPR and CCPA Compliance Guidelines ISO 27701 (Privacy Information Management System)
Question 49
Single choice
Which of the following should be an IS auditor ' s GREATEST concern when assessing an IT service configuration database?
-
A
The database is read-accessible for all users.
-
B
The database is write-accessible for all users.
-
C
The database is not encrypted at rest.
-
D
The database is executable for all users.
Reveal answer details
Close answer details
Question 50
Single choice
Which of the following is the GREATEST risk related to the use of virtualized environments?
-
A
The host may be a potential single point of failure within the system.
-
B
There may be insufficient processing capacity to assign to guests.
-
C
There may be increased potential for session hijacking.
-
D
Ability to change operating systems may be limited.
Reveal answer details
Close answer details
Question 51
Single choice
Spreadsheets are used to calculate project cost estimates. Totals for each cost category are then keyed into the job-costing system. What is the BEST control to ensure that data is accurately entered into the system?
-
A
Reconciliation of total amounts by project
-
B
Validity checks, preventing entry of character data
-
C
Reasonableness checks for each cost type
-
D
Display the back of the project detail after the entry
Reveal answer details
Close answer details
Question 52
Single choice
What is the BEST control to address SQL injection vulnerabilities?
-
A
-
B
Secure Sockets Layer (SSL) encryption
-
C
-
D
Reveal answer details
Close answer details
Question 53
Single choice
What should an IS auditor do FIRST when a follow-up audit reveals some management action plans have not been initiated?
-
A
Confirm whether the identified risks are still valid.
-
B
Provide a report to the audit committee.
-
C
Escalate the lack of plan completion to executive management.
-
D
Request an additional action plan review to confirm the findings.
Reveal answer details
Close answer details
Correct answerA
ExplanationThe first thing that an IS auditor should do when a follow-up audit reveals some management action plans have not been initiated is to escalate the lack of plan completion to executive management. This is because the failure to implement the agreed management action plans may indicate that the management is not taking the audit findings and recommendations seriously, or that they are accepting too much risk by not addressing the identified issues. Escalating the lack of plan completion to executive management can help to raise awareness and accountability, as well as to seek support and intervention to ensure that the management action plans are executed in a timely and effective manner 12. Confirming whether the identified risks are still valid is not the first thing to do, although it may be a useful step to reassess the current situation and the potential impact of not implementing the management action plans. However,confirming the validity of the risks does not address the root causeof why the management action plans have not been initiated, nor does it provide any assurance or remediation for the unresolved issues 34. Providing a report to the audit committee is not the first thing to do, although it may be a necessary step to communicate and document the results of the follow-up audit. However, providing a report to the audit committee does not guarantee that the management action plans will be initiated, nor does it resolve any conflicts or challenges that may prevent the management from implementing them 34. Requesting an additional action plan review to confirm the findings is not the first thing to do, although it may be a prudent step to verify and validate the accuracy and completeness of the follow-up audit. However, requesting an additional review may delay or defer the implementation of the management action plans, as well as consume more internalaudit resources and time
Question 54
Single choice
Which of the following is MOST important to ensure when planning a black box penetration test?
-
A
The management of the client organization is aware of the testing.
-
B
The test results will be documented and communicated to management.
-
C
The environment and penetration test scope have been determined.
-
D
Diagrams of the organization's network architecture are available.
Reveal answer details
Close answer details
Question 55
Single choice
An organization is migrating its HR application to an Infrastructure as a Service (laaS) model in a private cloud. Who is PRIMARILY responsible for the security configurations of the deployed application ' s operating system?
-
A
The cloud provider ' s external auditor
-
B
-
C
The operating system vendor
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationThe organization is primarily responsible for the security configurations of the deployed application's operating system when migrating its HR application to an Infrastructure as a Service (IaaS) model in a private cloud. This is because in an IaaS model, the cloud provider is responsible for the security of the underlying infrastructure that they lease to their customers, such as servers, storage, and networks, while the customer is responsible for the security of the areas of the cloud infrastructure over which they have control, such as operating systems, middleware, and applications. Therefore, the organization needs to ensure that the operating system is properly configured, patched, hardened, and monitored to protect the HR application from unauthorized access or malicious attacks. The other options are not primarily responsible for the security configurations of the deployed application's operating system. The cloud provider's external auditor is not responsible for any security configurations, but rather for verifying and reporting on the cloud provider's compliance with relevant standards and regulations. The cloud provider is responsible for the security of the underlying infrastructure, but not for the operating system or any software installed on it by the customer. The operating system vendor is responsible for providing updates and patches for the operating system, but not for configuring or securing it according to the customer's needs. References: 11: What Is IaaS (Infrastructure As A Service)? - Forbes 12: What is Shared Responsibility Model? - Check Point Software 13: Who Is Responsible for Cloud Security? - Security Intelligence
Question 56
Single choice
Which of the following should an IS auditor review FIRST when planning a customer data privacy audit?
-
A
Legal and compliance requirements
-
B
-
C
-
D
Organizational policies and procedures
Reveal answer details
Close answer details
Correct answerD
ExplanationThe organizational policies and procedures are the first source of guidance for an IS auditor when planning a customer data privacy audit. They provide the framework and objectives for ensuring compliance with legal and regulatory requirements, customer agreements and data classification. The IS auditor should review them first to understand the scope, roles and responsibilities, standards and controls related to customer data privacy in the organization. The other options are also important, but they are secondary sources of information thatshould be reviewed after the organizational policies and procedures. References: CISA Review Manual (Digital Version) 1, Chapter 2: Governance and Management of Information Technology, Section 2.5: Privacy Principles and Policies.
Question 57
Single choice
Which of the following controls is MOST crucial to ensure an organization will be able to recover its data from backup media in the event of a disaster?
-
A
Storing backup media at an offsite facility
-
B
Keeping a current inventory of backup media
-
C
Periodically restoring backup media for key databases
-
D
Encrypting data on backup media
Reveal answer details
Close answer details
Correct answerC
ExplanationThe best answer is C. Periodically restoring backup media for key databases. ISACA guidance is very clear that backup restoration should be tested periodically. A backup is only useful if it can actually be restored successfully within business needs. Organizations sometimes assume that because backups exist, recovery is assured, but ISACA specifically warns that recovery procedures and restoration capability must be tested. Option A is important for resilience, but offsite storage does not prove the backup is recoverable. Option B helps administration and tracking, but inventory alone does not validate restorability. Option D protects confidentiality of backup data, but it does not ensure successful recovery. The strongest control for recoverability is periodic test restoration. References (Official ISACA): ISACA, Ensuring Data Security: The Importance of Cloud Backups and Drill Testing ISACA Journal, Governance of Key Aspects of System Patch Management - recommends periodic testing of backup restoration. ISACA Journal, IS Audit Basics: Backup and Recovery
Question 58
Single choice
Which of the following provides the BEST evidence that system requirements are met when evaluating a project before implementation?
-
A
Integration testing results
-
B
Sign-off from senior management
-
C
User acceptance testing (UAT) results
-
D
Regression testing results
Reveal answer details
Close answer details
Question 59
Single choice
Which of the following is the BEST testing approach to facilitate rapid identification of application interface errors?
-
A
-
B
-
C
-
D
User acceptance testing (UAT)
Reveal answer details
Close answer details
Correct answerC
ExplanationThe best testing approach to facilitate rapid identification of application interface errors is automated testing. Automated testing is the use of software tools or scripts to execute predefined test cases, compare expected and actual outcomes, and report any discrepancies. Automated testing can help to speed up the testing process, increase test coverage, reduce human errors, and improve test accuracy and consistency. Automated testing can also help to detect interface errors that may occur due to incompatible data formats, communication protocols, or system configurations. References: CISA Review Manual (Digital Version), Chapter 3, Section 3.3.11 CISA OnlineReview Course, Domain 2, Module 2, Lesson 1
Question 60
Single choice
Which of the following would an IS auditor recommend as the MOST effective preventive control to reduce the risk of data leakage?
-
A
Ensure that paper documents arc disposed security.
-
B
Implement an intrusion detection system (IDS).
-
C
Verify that application logs capture any changes made.
-
D
Validate that all data files contain digital watermarks
Reveal answer details
Close answer details
Correct answerD
ExplanationDigital watermarks are hidden marks or codes that can be embedded into digital files, such as images, videos, audio, or documents. They can be used to identify the source, owner, or authorized user of the data, as well as to track any unauthorized copying or distribution of the data. Digital watermarks can help prevent data leakage by deterring potential leakers from sharing sensitive data or by providing evidence of data leakage if it occurs. The other options are not as effective as digital watermarks in preventing data leakage. Ensuring that paper documents are disposed securely can reduce the risk of physical data leakage, but it does not address the digital data leakage that is more prevalent in today's environment. Implementing an intrusion detection system (IDS) can help detect and respond to cyberattacks that may cause data leakage, but it does not prevent data leakage from insiders or authorized users who have legitimate access to the data. Verifying that application logs capture any changes made can help audit and investigate data leakage incidents, but it does not prevent them from happening in the first place. References: What is Data Leakage? What is Digital Watermarking?
Question 61
Single choice
Which of the following attack techniques will succeed because of an inherent security weakness in an Internet firewall?
-
A
-
B
Using a dictionary attack of encrypted passwords
-
C
Intercepting packets and viewing passwords
-
D
Flooding the site with an excessive number of packets
Reveal answer details
Close answer details
Question 62
Single choice
Following the sale of a business division, employees will be transferred to a new organization, but they will retain access to IT equipment from the previous employer. An IS auditor has recommended that both organizations agree to and document an acceptable use policy for the equipment. What type of control has been recommended?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationAn acceptable use policy (AUP) is a preventive control that sets out rules and guidelines for using an organization's IT resources, including networks, devices, and software 1. It defines acceptable and prohibited behaviors, aiming to protect assets, ensure security, and maintain a productive work environment 1. By agreeing to and documenting an AUP for the equipment, both organizations can prevent potential misuse of IT resources2345. References: ISO 27001 Acceptable Use Policy Beginner's Guide - High Table Acceptable Use Policy for Information Technology Resources Acceptable Use Policies for Workplace Technology | Verizon IT Governance: Your Must-Have Policies - How-To Geek Acceptable use policy template - Workable
Question 63
Single choice
An IS auditor is planning an audit of an organization's accounts payable processes. Which of the following controls is MOST important to assess in the audit?
-
A
Segregation of duties between issuing purchase orders and making payments.
-
B
Segregation of duties between receiving invoices and setting authorization limits
-
C
Management review and approval of authorization tiers
-
D
Management review and approval of purchase orders
Reveal answer details
Close answer details
Question 64
Single choice
When conducting an audit of an organization ' s use of AI in its customer service chatbots, an IS auditor should PRIMARILY focus on the:
-
A
Safeguarding of personal data processing by the AI system.
-
B
AI system ' s compliance with industry security standards.
-
C
Speed and accuracy of chatbot responses to customer queries.
-
D
AI system ' s ability to handle multiple customer queries at once.
Reveal answer details
Close answer details
Correct answerA
ExplanationTheprimary concernwhen auditing an AI-powered chatbot is ensuring thesafeguarding of personal datato comply with privacy regulations such asGDPR, CCPA, and ISO 27701. AI chatbots process customer inquiries, often handling sensitive personal data. Safeguarding of Personal Data (Correct Answer - A) Ensures compliance with data protection laws. Reduces the risk of unauthorized access or data leakage. Example:An AI chatbot collecting customer financial information must follow encryption and access control policies. Compliance with Industry Standards (Incorrect - B) Important, but protecting customer data takes priority over general compliance. Speed and Accuracy of Chatbot Responses (Incorrect - C) A performance metric, but not a primary audit focus. AI's Ability to Handle Multiple Queries (Incorrect - D) Efficiency metric, but does not address security risks. References: ISACA CISA Review Manual ISO 27701 (Privacy Information Management System) GDPR and CCPA Compliance Guidelines
Question 65
Single choice
An organization conducted an exercise to test the security awareness level of users by sending an email offering a cash reward 10 those who click on a link embedded in the body of the email. Which of the following metrics BEST indicates the effectiveness of awareness training?
-
A
The number of users deleting the email without reporting because it is a phishing email
-
B
The number of users clicking on the link to learn more about the sender of the email
-
C
The number of users forwarding the email to their business unit managers
-
D
The number of users reporting receipt of the email to the information security team
Reveal answer details
Close answer details
Correct answerD
ExplanationThe metric that best indicates the effectiveness of awareness training is the number of users reporting receipt of the email to the information security team. This shows that the users are able to recognize and report a phishing email, which is a common social engineering technique used by attackers to trick users into revealing sensitive information or installing malicious software. The other metrics do not demonstrate a high level of security awareness, as they either ignore, follow, or forward the phishing email, which could expose the organization to potential risks. References: CISA Review Manual, 27th Edition, page 326
Question 66
Single choice
A programmer has made unauthorized changes to key fields in a payroll system report. Which of the following control weaknesses would have contributed MOST to this problem?
-
A
The programmer did not involve the user in testing.
-
B
The user requirements were not documented.
-
C
Payroll files were not under the control of a librarian.
-
D
The programmer has access to the production programs.
Reveal answer details
Close answer details
Correct answerD
ExplanationThe programmer having access to the production programs is the most likely control weakness that would have contributed to the unauthorized changes to the payroll system report. This is because the programmer could modify the production code without proper authorization, documentation, or testing, and bypass the change management process. This could result in errors, fraud, or data integrity issues in the payroll system. The programmer should only have access to the development or test environment, and the production programs should be under the control of a librarian or a change manager. References: ISACA CISA Review Manual, 27th Edition, page 254 4 Types of Internal Control Weaknesses ACCT 4631 - Internal Auditing: CIA Quiz Topic 6 Flashcards
Question 67
Single choice
A new system is being developed externally for an organization. Which of the following is the MOST important requirement to include in the vendor contract to ensure service continuity?
-
A
Support documentation must be provided by the vendor.
-
B
The vendor must have a documented disaster recovery plan (DRP) in place.
-
C
Source code for the software must be placed in escrow.
-
D
The vendor must train the organization's staff to manage the new software.
Reveal answer details
Close answer details
Correct answerC
ExplanationThe best answer is C: Source code for the software must be placed in escrow. When an organization has a system developed by an external vendor, one of the key continuity risks is vendor dependency. If the vendor goes out of business, refuses support, becomes insolvent, or fails to meet contractual obligations, the organization may lose the ability to maintain, modify, or recover the software. A source code escrow agreement reduces this risk by requiring the vendor to deposit the source code with a trusted third party. The organization can access the source code if specific contractual trigger events occur, such as vendor bankruptcy, nonperformance, or failure to support the system. This is the most important control because it directly protects the organization's ability to continue using and maintaining the application even if the vendor is no longer available. ISACA's own CISA practice quiz states that a source code escrow agreement is recommended to protect the enterprise's software investment because the source code is held by a trusted third party and can be retrieved if the vendor goes out of business. Option A is not the best answer because support documentation is useful, but documentation alone does not allow the organization to maintain or modify the application if the vendor fails and the source code is unavailable. Option B is not the best answer because a vendor disaster recovery plan is important when the vendor is providing an ongoing operational or hosted service. However, the question focuses on a system being developed externally and asks what should be included in the vendor contract to ensure service continuity. A DRP does not guarantee the organization can maintain the software if the vendor becomes insolvent or stops supporting the system. Option D is not the best answer because training the organization's staff helps internal capability, but trained staff still cannot effectively maintain or modify the application without access to the source code and related rights. This question belongs mainly to Information Systems Acquisition, Development and Implementation because it concerns controls and contractual requirements during external system development/acquisition. ISACA's current CISA Exam Content Outline includes "Information Systems Acquisition, Development, and Implementation" as Domain 3, covering acquisition/development and control identification/design. ISACA also discusses escrow as a way to address vendor continuity risk, especially for software, where assets or software code are deposited with a third party and released under defined contractual conditions.
Question 68
Single choice
Which of the following system redundancy configurations BEST improves system resiliency and reduces the possibility of a single cause of failure impacting system dependability?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 69
Single choice
A new system development project is running late against a critical implementation deadline. Which of the following is the MOST important activity?
-
A
Ensure that code has been reviewed.
-
B
Perform user acceptance testing (UAT).
-
C
Document last-minute enhancements.
-
D
Perform a pre-implementation audit.
Reveal answer details
Close answer details
Question 70
Single choice
An IS auditor finds that an organization ' s data loss prevention (DLP) system is configured to use vendor default settings to identify violations. The auditor ' s MAIN concern should be that:
-
A
violation reports may not be reviewed in a timely manner.
-
B
a significant number of false positive violations may be reported.
-
C
violations may not be categorized according to the organization ' s risk profile.
-
D
violation reports may not be retained according to the organization ' s risk profile.
Reveal answer details
Close answer details
Question 71
Single choice
Which of the following is MOST important for an IS auditor to verify when evaluating an organization ' s firewall?
-
A
Logs are being collected in a separate protected host
-
B
Automated alerts are being sent when a risk is detected
-
C
Insider attacks are being controlled
-
D
Access to configuration files Is restricted.
Reveal answer details
Close answer details
Correct answerA
ExplanationA firewall is a device or software that monitors and controls the incoming and outgoing network traffic based on predefined rules. A firewall can help protect an organization's network and information systems from unauthorized or malicious access, by filtering or blocking unwanted or harmful packets. The most important thing for an IS auditor to verify when evaluating an organization's firewall is that the logs are being collected in a separate protected host. Logs are records of events or activities that occur on a system or network, such as connections, requests, responses, errors, and alerts. Logs can provide valuable information for auditing, monitoring, troubleshooting, and investigating security incidents. However, logs can also be tampered with, deleted, or corrupted by attackers or insiders who want to hide their tracks or evidence of their actions. Therefore, it is essential that logs are stored in a separate host that is isolated and secured from the network and the firewall itself, to prevent unauthorized access or modification of the logs. Automated alerts are being sent when a risk is detected is a good practice for enhancing the security and efficiency of a firewall, but it is not the most important thing for an IS auditor to verify, as alerts may not always be accurate, timely, or actionable. Insider attacks are being controlled is a desirable outcome for a firewall, but it is not the most important thing for an IS auditor to verify, as insider attacks may involve other factors or methods that bypass or compromise the firewall, such as social engineering, credential theft, or physical access. Access to configuration files is restricted is a critical control for ensuring the security and integrity of a firewall, but it is not the most important thing for an IS auditor to verify, as configuration files may not reflect the actual state or performance of the firewall.
Question 72
Single choice
An IS auditor is reviewing the security of a web-based customer relationship management (CRM) system that is directly accessed by customers via the Internet, which of the following should be a concern for the auditor?
-
A
The system is hosted on an external third-party service provider's server.
-
B
The system is hosted in a hybrid-cloud platform managed by a service provider.
-
C
The system is hosted within a demilitarized zone (DMZ) of a corporate network.
-
D
The system is hosted within an internal segment of a corporate network.
Reveal answer details
Close answer details
Correct answerD
ExplanationA web-based CRM system that is directly accessed by customers via the Internet should be hosted in a secure and isolated environment to protect it from external threats and unauthorized access. A web-based CRM system should also be reliable, trusted, and backedup regularly 1. Hosting the system on an external third-party service provider's servers (A) or a hybrid-cloud platform managed by a service provider (B) may not be a concern for the auditor if the service provider has adequate security measures and service level agreements in place. The auditor should verify the security controls and contractual terms of the service provider before trusting them with the CRM data 23. Hosting the system within a demilitarized zone (DMZ) of a corporate network (C) is a common practice to provide an extra layer of security to the CRM system from untrusted networks, such as the Internet. A DMZ is a perimeter network that isolates the CRM system from the internal network and filters the incoming traffic from the external network using a security gateway4567. Hosting the system within an internal segment of a corporate network (D) is a concern for the auditor because it exposes the CRM system and the internal network to potential attacks from the Internet. The CRM system should not be directly accessible from the Internet without a DMZ or a firewall to protect it. This could compromise the confidentiality, integrity, and availability of the CRM data and the internal network 78.
Question 73
Single choice
Which of the following is the GREATEST risk associated with hypervisors in virtual environments?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationA single point of failure is a component or system that, if it fails, will cause the entire system to stop functioning. In virtual environments, the hypervisor is the software layer that enables multiple virtual machines to run on a single physical host. If the hypervisor is compromised, corrupted, or unavailable, all the virtual machines running on that host will be affected. This can result in data loss, downtime, or security breaches. References: ISACA CISA Review Manual, 27th Edition, page 254 Virtualization: What are the security risks? What Is a Hypervisor? (Definition, Types, Risks)
Question 74
Single choice
Which of the following is the MOST important reason to classify a disaster recovery plan (DRP) as confidential?
-
A
Ensure compliance with the data classification policy.
-
B
Protect the plan from unauthorized alteration.
-
C
Comply with business continuity best practice.
-
D
Reduce the risk of data leakage that could lead to an attack.
Reveal answer details
Close answer details
Correct answerD
ExplanationThe most important reason to classify a disaster recovery plan (DRP) as confidential is to reduce the risk of data leakage that could lead to an attack. A DRP contains sensitive information about the organization's IT infrastructure, systems, processes, and procedures for recovering from a disaster. If this information falls into the wrong hands, it could be exploited by malicious actors to launch targeted attacks, sabotage recovery efforts, or extort ransom. Therefore, a DRP should be protected from unauthorized access, disclosure, modification, or destruction. The other options are not as important as reducing the risk of data leakage that could lead to an attack: Ensuring compliance with the data classification policy is a good practice, but it is not a sufficient reason to classify a DRP as confidential. The data classification policy should reflect the level of risk and impact associated with each type of data, and a DRP should be classified as confidential based on its potential harm if compromised. Protecting the plan from unauthorized alteration is a valid concern, but it is not a primary reason to classify a DRP as confidential. A DRP should be protected from unauthorized alteration by implementing access controls, audit trails, version control, and change management processes. Classifying a DRP as confidential may deter some unauthorized alterations, but it does not prevent them. Complying with business continuity best practice is a desirable goal, but it is not a compelling reason to classify a DRP as confidential. Business continuity best practice may recommend classifying a DRP as confidential, but it does not mandate it. The decision to classify a DRP as confidential should be based on a risk assessment and a cost-benefit analysis.
Question 75
Single choice
An IS auditor is reviewing a decision to consolidate processing for multiple applications onto a single large server. Which of the following is the MOST significant impact from this decision?
-
A
Higher operating system license fees
-
B
More applications affected by a server outage
-
C
Simplified asset management
-
D
Fewer application servers requiring vulnerability scans
Reveal answer details
Close answer details
Correct answerB
ExplanationConsolidating multiple applications on asingle serverincreases the risk that aserver outagewillimpact multiple applicationssimultaneously. More Applications Affected by Outage (Correct Answer - B) Asingle point of failurecoulddisrupt multiple services. Example:If aconsolidated server crashes, all hosted applications gooffline. Higher OS License Fees (Incorrect - A) License feesmay increase, butdowntime risk is a greater concern. Simplified Asset Management (Incorrect - C) True, butdoes not outweigh the availability risk. Fewer Vulnerability Scans (Incorrect - D) Reducing the number of serversdoes not reduce security risks. References: ISACA CISA Review Manual NIST 800-160 (System Security Engineering)
Question 76
Single choice
An IS auditor finds that some employees are using public cloud-based AI tools. Which of the following presents the GREATEST concern?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationThe best answer is D. ISACA guidance on shadow AI and emerging technology risk highlights data breaches, privacy risk, and data leakage as major concerns when employees use unapproved public AI tools. Public cloud AI use can expose sensitive data through prompts, uploads, or output handling, making data leakage the greatest immediate concern from an audit and control perspective. Option A is a concern because AI outputs can be inaccurate, but poor reliability usually does not create the same immediate confidentiality exposure as leaking internal data. Option B is less severe. Option C can matter in some use cases, but the most significant enterprise risk identified in ISACA's public guidance is unauthorized disclosure of data. References (Official ISACA): ISACA, From Shadow IT to Shadow AI: Navigating the New Frontier of Enterprise Risk. ISACA, Navigating the Hype and Risk of Emerging Technologies. ISACA, Collaboration and the New Triad of AI Governance.
Question 77
Single choice
Which of the following is MOST important to include in security awareness training?
-
A
How to respond to various types of suspicious activity
-
B
The importance of complex passwords
-
C
Descriptions of the organization ' s security infrastructure
-
D
Contact information for the organization ' s security team
Reveal answer details
Close answer details
Correct answerA
ExplanationThe most important thing to include in security awareness training is how to respond to various types of suspicious activity. Security awareness training is a program that educates employees about the importance of security and how to avoid common threats and risks. One of the main objectives of security awareness training is to enable employees to recognize and report any signs of malicious or unauthorized activity, such as phishing emails, malware infections, data breaches, or social engineering attempts. By teaching employees how to respond to various types of suspicious activity, security awareness training can help to prevent or mitigate the impact of security incidents, protect the organization's assets and reputation, and comply with legal and regulatory requirements. The other options are not as important as option A. The importance of complex passwords is a useful topic, but not the most important thing to include in security awareness training. Complex passwords are passwords that are hard to guess or crack by using a combination of letters, numbers, symbols, and cases. Complex passwords can help to protect user accounts and data from unauthorized access, but they are not sufficient to prevent all types of security incidents. Moreover, complex passwords may be difficult to remember or manage by users, and may require additional measures such as password managers or multi-factor authentication. Descriptions of the organization's security infrastructure is a technical topic, but not the most important thing to include in security awareness training. Security infrastructure is the set of hardware, software, policies, and procedures that provide the foundation for the organization's security posture and capabilities. Security infrastructure may include firewalls, antivirus software, encryption tools, access control systems, backup systems, etc. Descriptions of the organization's security infrastructure may be relevant for some employees who are involved in security operations or administration, but they may not be necessary or understandable for all employees who need security awareness training. Contact information for the organization's security team is a practical detail, but not the most important thing to include in security awareness training. Security team is the group of people who are responsible for planning, implementing, monitoring, and improving the organization's security strategy and activities. Contact information for the organization's security team may be useful for employees who need to report or escalate a security issue or request a security service or support. However, contact information for the organization's security team is not enough to ensure that employees know how to respond to various types of suspicious activity. References: Security Awareness Training | SANS Security Awareness, Security AwarenessTraining | KnowBe4, SecurityAwareness Training Course (ISC)2 | Coursera
Question 78
Single choice
In order to be useful, a key performance indicator (KPI) MUST
-
A
be approved by management.
-
B
be measurable in percentages.
-
C
be changed frequently to reflect organizational strategy.
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationA key performance indicator (KPI) is a quantifiable measure of performance over time for a specific objective 1. KPIs help organizations and teams track their progress and achievements towards their strategic goals. To be useful, a KPI must have a target value, which is the desired level of performance or outcome that the organization or team aims to achieve. A target value provides a clear direction and a benchmark for measuring success or failure. Without a target value, a KPI is meaningless, as it does not indicate whether the performance is good or bad, or how far or close the organization or team is from reaching their objective.
Question 79
Single choice
An IS auditor observes that an organization ' s systems are being used for cryptocurrency mining on a regular basis. Which of the following is the auditor ' s FIRST course of action?
-
A
Report the incident immediately.
-
B
Recommend changing the organization ' s firewall settings.
-
C
Consult the organization ' s acceptable use policy.
-
D
Require mining software to be uninstalled.
Reveal answer details
Close answer details
Question 80
Single choice
Which of the following is the MOST effective method to identify new errors introduced as a result of program changes?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationThe correct answer is D. Regression testing. Regression testing is specifically designed to determine whether program changes have unintentionally introduced new errors or caused previously working functions to fail. After a system change, regression testing retests affected and related functions to confirm that the modified application still works as expected. ISACA's glossary defines regression analysis and testing as a software verification and validation task used to determine the extent of analysis and testing that must be repeated when changes are made to previously examined software products. It also defines regression testing as a technique used to retest earlier program abends or logical errors that occurred during the initial testing phase. Option A is not the best answer because unit testing verifies individual program modules or components. It is useful, but it does not provide the same assurance that a change has not affected existing functionality elsewhere. Option B is not the best answer because interface testing focuses on data exchange and communication between systems or components. Option C is not the best answer because integration testing verifies that components work together, but regression testing is the specific method for detecting unintended effects of changes. This question maps to Information Systems Acquisition, Development and Implementation because ISACA's CISA Exam Content Outline includes system development methodologies, system readiness, implementation testing, and controls throughout the system development life cycle. References: ISACA CISA Exam Content Outline, Domain 3 ISACA Interactive Glossary, "Regression analysis and testing" and "Regression testing."
Question 81
Single choice
An incorrect version of the source code was amended by a development team. This MOST likely indicates a weakness in:
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationA weakness in change management is the most likely cause of an incorrect version of source code being amended by a development team. Change management is the process of controlling and documenting changes to IT systems and software. It ensures that changes are authorized, tested, and implemented in a controlled manner. If change management is weak, there is a risk of using outdated or incorrect versions of source code, which can lead to errors, defects, or security vulnerabilities in the software.
Question 82
Single choice
Which of the following is the PRIMARY purpose of enterprise architecture (EA) within an organization?
-
A
To design and implement individual IT systems
-
B
To oversee network security protocols
-
C
To design and manage day-to-day IT operations
-
D
To structure IT projects to achieve desired business results
Reveal answer details
Close answer details
Correct answerD
ExplanationThe best answer is D. To structure IT projects to achieve desired business results. ISACA guidance describes enterprise architecture as a top-down, business-driven discipline focused on business capabilities, strategy, and alignment of people, process, and technology. Enterprise architecture is not primarily about individual systems or day-to-day operations. Its purpose is to ensure that change initiatives and IT investments are organized in a way that supports the enterprise's strategic and business outcomes. Option A is too narrow because EA is broader than designing single systems. Option B is only one specialized area within the overall architecture landscape. Option C is more aligned with operations management than enterprise architecture. The strongest answer is the one linking EA to business-driven structuring of initiatives and results. Therefore, the correct answer is D, because enterprise architecture exists to align and structure IT initiatives so the organization can achieve desired business results. References (Official ISACA): ISACA, Developing Business Capabilities Using COBIT 5 - enterprise architecture focuses on business capabilities supporting strategy. ISACA Journal, Enterprise Security Architecture-A Top-down Approach - architecture bridges business risk, process requirements, and technical issues. ISACA Journal, Information Security Architecture: Gap Assessment and Prioritization - supports business-driven architectural alignment. ISACA, Using COBIT 2019 to Plan and Execute an Organization Transformation Strategy - IT governance and management should create value from IT initiatives.
Question 83
Single choice
During a follow-up audit, an IS auditor finds that senior management has implemented a different remediation action plan than what was previously agreed upon. Which of the following is the auditor ' s BEST course of action?
-
A
Report the deviation by the control owner in the audit report.
-
B
Evaluate the implemented control to ensure it mitigates the risk to an acceptable level.
-
C
Cancel the follow-up audit and reschedule for the next audit period.
-
D
Request justification from management for not implementing the recommended control.
Reveal answer details
Close answer details
Correct answerB
ExplanationThe IS auditor's best course of action is to evaluate the implemented control to ensure it mitigates the risk to an acceptable level. This is because the objective of a follow-up audit is to verify that corrective actions have been accomplished as scheduled and that theyare effective in preventing orminimizing future recurrence 1. If senior management has implemented a different remediation action plan than what was previously agreed upon, the IS auditor should assess whether the alternative control is adequate and appropriate for the situation. Requesting justification from management for not implementing the recommended control (option D) may be a secondary step, but it is not the best course of action. Reporting the deviation by the control owner in the audit report (option A) may be premature and unnecessary if the implemented control is satisfactory. Canceling the follow-up audit and rescheduling for the next audit period (option C) is not advisable, as it would delay the verification of the effectiveness of the implemented control and potentially expose the organization to further risks. References: 1: Follow-up Audits - Canadian Audit and Accountability Foundation
Question 84
Single choice
Afire alarm system has been installed in the computer room The MOST effective location for the fire alarm control panel would be inside the
-
A
computer room closest to the uninterruptible power supply (UPS) module
-
B
computer room closest to the server computers
-
C
system administrators' office
-
D
booth used by the building security personnel
Reveal answer details
Close answer details
Correct answerD
ExplanationA fire alarm system is a device that detects and alerts people of the presence of fire or smoke in a building. A fire alarm control panel is the central unit that monitors and controls the fire alarm system. The most effective location for the fire alarm control panel would be inside the booth used by the building security personnel. This is because: The security personnel can quickly and easily access the fire alarm control panel in case of an emergency, and take appropriate actions such as notifying the fire department, evacuating the building, or resetting the system. The fire alarm control panel can be protected from unauthorized access, tampering, or damage by the security personnel, who can also monitor its status and performance regularly. The fire alarm control panel can be isolated from the computer room, which may be exposed to higher risks of fire or smoke due to the presence of electrical equipment, such as uninterruptible power supply (UPS) modules or server computers. The fire alarm control panel can be connected to the computer room through a dedicated communication line, which can ensure reliable and timely transmission of signals and information between the two locations. References:
[1]: Fire Alarm Control Panel - an overview | ScienceDirect Topics
[2]: Fire Alarm Control Panel - What is it and how does it work? | Fire Protection Online
[3]: Fire Alarm Control Panel Installation Guide - XLS3000 - Honeywell
Question 85
Single choice
Which of the following areas of responsibility would cause the GREATEST segregation of duties conflict if the individual who performs the related tasks also has approval authority?
-
A
Purchase requisitions and purchase orders
-
B
Invoices and reconciliations
-
C
Vendor selection and statements of work
-
D
Good receipts and payments
Reveal answer details
Close answer details
Correct answerD
ExplanationThe greatest segregation of duties conflict would occur if the individual who performs the related tasks also has approval authority for purchase requisitions and purchase orders. This is because these two tasks are directly related to each other and involve financial transactions. If the same person is responsible for both tasks, it could lead to potential fraud or error 12. For instance, the individual could approve a purchase order for a personal need and then also approve the payment for it, leading to misuse of company funds 12. References: Segregation of Duties: Examples of Roles, Duties and Violations - Pathlock Functions in the Purchasing Process and how to Segregate Purchasing Duties
Question 86
Single choice
Which of the following is the BEST indication that a software development project is on track to meet its completion deadline?
-
A
Technical specifications and development requirements have been agreed upon and formally recorded.
-
B
Project plan due dates have been documented for each phase of the software development life cycle.
-
C
Issues identified during user acceptance testing (UAT) have been addressed prior to the original implementation date.
-
D
The planned software go-live date has been communicated in advance to end users and stakeholders.
Reveal answer details
Close answer details
Question 87
Single choice
An IS auditor is examining a front-end subledger and a main ledger. Which of the following would be the GREATEST concern if there are flaws in the mapping of accounts between the two systems?
-
A
Double-posting of a single journal entry
-
B
Inability to support new business transactions
-
C
Unauthorized alteration of account attributes
-
D
Inaccuracy of financial reporting
Reveal answer details
Close answer details
Question 88
Single choice
Which of the following is MOST important to ensure when developing an effective security awareness program?
-
A
Training personnel are information security professionals.
-
B
Outcome metrics for the program are established.
-
C
Security threat scenarios are included in the program content.
-
D
Phishing exercises are conducted post-training
Reveal answer details
Close answer details
Correct answerB
ExplanationThe most important factor to ensure when developing an effective security awareness program is B. Outcome metrics for the program are established. This is because outcome metrics are measures that evaluate the impact and results of the security awareness program on the behavior and performance of the users, and the security posture and objectives of the organization 1. Outcome metrics can help ensure the effectiveness of the security awareness program by: Providing feedback and evidence on whether the security awareness program is achieving its goals and expectations, such as reducing the number of incidents, improving the compliance rate, or increasing the reporting rate 1. Identifying and quantifying the strengths and weaknesses of the security awareness program, and enabling continuous improvement and optimization of the program content, delivery, and frequency 1. Demonstrating and communicating the value and return on investment of the security awareness program to the stakeholders and management, and securing their support and commitment for the program 1.
Question 89
Single choice
An organization that has suffered a cyber-attack is performing a forensic analysis of the affected users ' computers. Which of the following should be of GREATEST concern for the IS auditor reviewing this process?
-
A
An imaging process was used to obtain a copy of the data from each computer.
-
B
The legal department has not been engaged.
-
C
The chain of custody has not been documented.
-
D
Audit was only involved during extraction of the Information
Reveal answer details
Close answer details
Correct answerC
ExplanationThe chain of custody has not been documented is a finding that should be of greatest concern for an IS auditor reviewing a forensic analysis process of an organization that has suffered a cyber attack. The chain of custody is a record of who handled, accessed, or modified the evidence during a forensic investigation. Documenting the chain of custody is essential to preserve the integrity, authenticity, and admissibility of the evidence in a court of law. The other options are less concerning findings that may not affect the validity or reliability of the forensic analysis process. References: CISAReview Manual (Digital Version), Chapter 7, Section 7.51 CISA Review Questions, Answers andExplanations Database, Question ID 220
Question 90
Single choice
Which of the following is an IS auditor's BEST recommendation for conducting a forensic investigation of the contents on a hard drive?
-
A
Make an image of the hard drive for investigation and save the original drive in a secure place.
-
B
Investigate the original hard drive to ensure it has not been tampered with.
-
C
Ask the user of the endpoint to make a copy of the hard drive and provide it to the auditor for investigation.
-
D
Shut down the computer in order to preserve the evidence, disconnect it from the network, and restart.
Reveal answer details
Close answer details
Correct answerA
ExplanationThe correct answer is A. Make an image of the hard drive for investigation and save the original drive in a secure place. In a forensic investigation, the original evidence must be preserved. The investigator should create a forensic image of the hard drive and perform the investigation on the copy, not the original. This protects the integrity of the original evidence and supports admissibility, reliability, and repeatability of the investigation. Option B is incorrect because investigating the original hard drive may alter metadata, file access times, temporary files, or system state. Option C is inappropriate because the user should not be responsible for copying potential evidence. That would weaken evidence reliability and chain of custody. Option D is risky because restarting the computer may change evidence. Depending on the case, volatile evidence may need to be captured before shutdown. ISACA's glossary defines chain of custody as the process for maintaining and documenting evidence handling, including who handled the evidence and when. ISACA also defines hashing as a cryptographic process used to support integrity. These concepts support preserving the original evidence and working from a verified forensic image. References: ISACA CISA Exam Content Outline, Domain 1 ISACA Interactive Glossary, "Chain of custody" and "Hashing."
Question 91
Single choice
Which of the following should be an IS auditor ' s PRIMARY focus when auditing the implementation of a new IT operations performance monitoring system?
-
A
Reviewing whether all changes have been implemented
-
B
Validating whether baselines have been established
-
C
Confirming whether multi-factor authentication (MFA) is deployed as part of the operational enhancements
-
D
Determining whether there is a process for annual review of the maintenance manual
Reveal answer details
Close answer details
Question 92
Single choice
Cross-site scripting (XSS) attacks are BEST prevented through:
-
A
application firewall policy settings.
-
B
a three-tier web architecture.
-
C
-
D
use of common industry frameworks.
Reveal answer details
Close answer details
Correct answerC
ExplanationSecure coding practices are the best way to prevent cross-site scripting (XSS) attacks, because they can ensure that the web application validates and sanitizes user input and output data to prevent malicious scripts from being executed on the web browser. XSS attacks are a type of web application vulnerability that exploit the lack of input validation or output encoding in webpages that accept user input or display dynamic content. Application firewall policy settings, a three-tier web architecture, and use of common industry frameworks are not effective controlsto prevent XSS attacks, because they do not address the root cause of the vulnerability in the web application code. References: CISA Review Manual (Digital Version), Chapter 5, Section 5.4.2
Question 93
Single choice
Which of the following is the BEST indication of effective IT investment management?
-
A
IT investments are implemented and monitored following a system development life cycle (SDLC)
-
B
IT investments are mapped to specific business objectives
-
C
Key performance indicators (KPIs) are defined for each business requiring IT Investment
-
D
The IT Investment budget is significantly below industry benchmarks
Reveal answer details
Close answer details
Correct answerB
ExplanationThis means that the IT investments are aligned with the strategic goals and priorities of the organization, and that they deliver value and benefits to the business. Mapping IT investments to specific business objectives can help ensure that the IT investments are relevant, justified, and measurable, and that they support the organization's mission and vision. IT investments are implemented and monitored following a system development life cycle (SDLC) is an indication of effective IT project management, but not necessarily of effective IT investment management. The SDLC is a framework that guides the development and implementation of IT systemsand applications, but it does not address the alignment, justification, or measurement of the IT investments. Key performance indicators (KPIs) are defined for each business requiring IT investment is an indication of effective IT performance management, but not necessarily of effective IT investment management. KPIs are metrics that measure the outcomes and results of IT activities and processes, but they do not address the alignment, justification, or value of the IT investments. The IT investment budget is significantly below industry benchmarks is not an indication of effective IT investment management, but rather of low IT spending. The IT investment budget should be based on the organization's needs and capabilities, and not on external comparisons. A low IT investment budget may indicate that the organization is underinvesting in IT, which could limit its potential for growth and innovation.
Question 94
Single choice
Which of the following should be the PRIMARY objective of conducting an audit follow-up of management action plans?
-
A
To verify that risks listed in the audit report have been properly mitigated
-
B
To identify new risks and controls for the organizationTo ensure senior management is aware of the audit findingsTo align the management action plans with business requirements
Reveal answer details
Close answer details
Question 95
Single choice
An organization has moved all of its infrastructure to the cloud. Which of the following would be an IS auditor's GREATEST concern related to the organization's ability to continue operations in case of a disaster?
-
A
There is no evidence that disaster recovery plan (DRP) testing was performed after the migration.
-
B
Only business-critical servers were configured with redundancy services on the cloud service provider.
-
C
The previous infrastructure was not retained to support business operations in case of a disaster.
-
D
The step-by-step recovery process was not updated in the disaster recovery plan (DRP) after the migration.
Reveal answer details
Close answer details
Correct answerA
ExplanationAfter migrating infrastructure to the cloud, it ' s imperative to test the disaster recovery plan (DRP) to ensure its effectiveness in the new environment. Without evidence of DRP testing post-migration, the organization cannot be certain that it can recover and continue operations during a disaster. While updating the DRP and configuring redundancy are essential steps, their effectiveness can only be validated through rigorous testing. Retaining previous infrastructure is less relevant if the cloud environment is properly configured and tested for disaster recovery. References: ISACA CISA Review Manual, 28th Edition, Chapter 4: Information Systems Operations and Business Resilience.
Question 96
Single choice
Management has requested a post-implementation review of a newly implemented purchasing package to determine to what extent business requirements are being met. Which of the following is MOST likely to be assessed?
-
A
Purchasing guidelines and policies
-
B
Implementation methodology
-
C
Results of line processing
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationA post-implementation review is a process of evaluating the outcome and benefits of a project or a system after it has been implemented. The main purpose of a post-implementation review is to determine to what extent the business requirements are being met by the new system. Therefore, the most likely aspect to be assessed is the results of line processing, which refers to the actual performance and functionality of the system in the operational environment.
Question 97
Single choice
An organization using a cloud provider for its online billing system requires the website to be accessible to customers at all times. What is the BEST way to verify the organization ' s business requirements are met?
-
A
Invoke the right-to-audit clause.
-
B
Require the vendor to report any outages longer than five minutes
-
C
Monitor the service level agreement (SLA) with the vendor.
-
D
Agree on periodic performance discussions with the vendor
Reveal answer details
Close answer details
Question 98
Single choice
Which of the following should be the FIRST step when planning an IS audit of a third-party service provider that monitors network activities?
-
A
Review the third party ' s monitoring logs and incident handling
-
B
Review the roles and responsibilities of the third-party provider
-
C
Evaluate the organization ' s third-party monitoring process
-
D
Determine if the organization has a secure connection to the provider
Reveal answer details
Close answer details
Correct answerB
ExplanationThe first step when planning an IS audit of a third-party service provider that monitors network activities is to review the roles and responsibilities of the third-party provider. This will help to establish the scope, objectives, and expectations of the audit, as well as to identify any potential risks, issues, or gaps in the service level agreement (SLA) between the organization and the provider. Reviewing the third party's monitoring logs and incident handling, evaluating the organization's third-party monitoring process, and determining if the organization has a secure connection to the provider are important steps, but they should be performed after reviewing the roles and responsibilities of the provider. References: CISA Review Manual (Digital Version)1, page 269.
Question 99
Single choice
Which of the following backup methods is MOST appropriate when storage space is limited?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationWhen storage space is limited,incremental backupsare the most efficient because they store only the changes made since the last backup, reducing storage requirements. Option A (Correct):Incremental backupsonly store data that has changed since the last backup, significantly reducing storage usage while maintaining a historical record of changes. Option B (Incorrect):Mirror backupscreate an exact copy of the entire system, consuming significant storage space andnot retaining historical versions. Option C (Incorrect):Full backupscapture everything and require large amounts of storage, making them impractical for space-constrained environments. Option D (Incorrect):Annual backupsrefer to frequency rather than method. They do not inherently optimize storage usage. References: ISACA CISA Review Manual -Domain 4: Information Systems Operations and Business Resilience-Covers backup strategies, storage management, and disaster recovery.
Question 100
Single choice
Which of the following is an audit reviewer's PRIMARY role with regard to evidence?
-
A
Ensuring unauthorized individuals do not tamper with evidence after it has been captured
-
B
Ensuring evidence is sufficient to support audit conclusions
-
C
Ensuring appropriate statistical sampling methods were used
-
D
Ensuring evidence is labeled to show it was obtained from an approved source
Reveal answer details
Close answer details
|