CISA Exam Details

  • Exam Code
    :CISA
  • Exam Name
    :Certified Information Systems Auditor
  • Certification
    :Isaca Certifications
  • Vendor
    :Isaca
  • Total Questions
    :2178 Q&As
  • Last Updated
    :Jun 03, 2026

Isaca CISA Online Questions & Answers

  • Question 1141:

    Which of the following is the BEST control lo mitigate attacks that redirect Internet traffic to an unauthorized website?

    A. Utilize a network-based firewall.
    B. Conduct regular user security awareness training.
    C. Perform domain name system (DNS) server security hardening.
    D. Enforce a strong password policy meeting complexity requirement.

  • Question 1142:

    Which of the following is MOST important for an IS auditor to look for in a project feasibility study?

    A. An assessment of whether requirements will be fully met
    B. An assessment indicating security controls will operate effectively
    C. An assessment of whether the expected benefits can be achieved
    D. An assessment indicating the benefits will exceed the implement

  • Question 1143:

    An IS auditor is reviewing the key payroll interface that collects wage rates from various business applications to process payroll. Which of the following is MOST likely to cause errors in payroll processing?

    A. User acceptance testing (UAT) has not been properly documented for all changes.
    B. Data conversion procedures did not include all business applications and interfaces.
    C. The payroll processing application does not follow a regularly scheduled patching cycle.
    D. Changes to the interface configuration settings were not adequately tested and approved.

  • Question 1144:

    During a database management evaluation an IS auditor discovers that some accounts with database administrator (DBA) privileges have been assigned a default password with an unlimited number of failed login attempts Which of the following is the auditor's BEST course of action?

    A. Identify accounts that have had excessive failed login attempts and request they be disabled
    B. Request the IT manager to change administrator security parameters and update the finding
    C. Document the finding and explain the risk of having administrator accounts with inappropriate security settings

  • Question 1145:

    Which of the following level in CMMI model focuses on process definition and process deployment?

    A. Level 4
    B. Level 5
    C. Level 3
    D. Level 2

  • Question 1146:

    While planning a security audit, an IS auditor is made aware of a security review carried out by external consultants. It is MOST important for the auditor to:

    A. re-perform the security review.
    B. accept the findings and conclusions of the consultants.
    C. review similar reports issued by the consultants.
    D. assess the objectivity and competence of the consultants.

  • Question 1147:

    An IS auditor observes that a business-critical application does not currently have any level of fault tolerance. Which of the following is the GREATEST concern with this situation?

    A. Degradation of services
    B. Limited tolerance for damage
    C. Decreased mean time between failures (MTBF)
    D. Single point of failure

  • Question 1148:

    A start-up organization wants to develop a data loss prevention program (DLP). The FIRST step should be to implement:

    A. data encryption.
    B. access controls.
    C. data classification.
    D. security awareness training.

  • Question 1149:

    Which type of control has been established when an organization implements a security information and event management (SIEM) system?

    A. Preventive
    B. Detective
    C. Directive
    D. Corrective

  • Question 1150:

    An IS auditor is a member of an application development team that is selecting software. Which of the following would impair the auditor's independence?

    A. Verifying the weighting of each selection criteria
    B. Approving the vendor selection methodology
    C. Reviewing the request for proposal (RFP)
    D. Witnessing the vendor selection process

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Isaca exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CISA exam preparations and Isaca certification application, do not hesitate to visit our Vcedump.com to find your solutions here.