CISA Exam Details

  • Exam Code
    :CISA
  • Exam Name
    :Certified Information Systems Auditor
  • Certification
    :Isaca Certifications
  • Vendor
    :Isaca
  • Total Questions
    :2178 Q&As
  • Last Updated
    :May 26, 2026

Isaca CISA Online Questions & Answers

  • Question 131:

    What is the GREATEST concern for an IS auditor reviewing contracts for licensed software that executes a critical business process?

    A. The contract does not contain a right-to-audit clause.
    B. An operational level agreement (OLA) was not negotiated.
    C. Several vendor deliverables missed the commitment date.
    D. Software escrow was not negotiated.

  • Question 132:

    Which of the following should be of MOST concern to an IS auditor reviewing the public key infrastructure (PKI) for enterprise email?

    A. The certificate revocation list has not been updated.
    B. The PKI policy has not been updated within the last year.
    C. The private key certificate has not been updated.
    D. The certificate practice statement has not been published

  • Question 133:

    Which of the following areas of responsibility would cause the GREATEST segregation of duties conflict if the individual who performs the related tasks also has approval authority?

    A. Purchase requisitions and purchase orders
    B. Invoices and reconciliations
    C. Vendor selection and statements of work
    D. Good receipts and payments

  • Question 134:

    Which of the following is the BEST metric to measure the alignment of IT and business strategy?

    A. Level of stakeholder satisfaction with the scope of planned IT projects
    B. Percentage of enterprise risk assessments that include IT-related risk
    C. Percentage of stat satisfied with their IT-related roles
    D. Frequency of business process capability maturity assessments

  • Question 135:

    Which of the following should be of GREATEST concern to an IS auditor reviewing an organization's business continuity plan (BCP)?

    A. The BCP's contact information needs to be updated
    B. The BCP is not version controlled.
    C. The BCP has not been approved by senior management.
    D. The BCP has not been tested since it was first issued.

  • Question 136:

    Which of the following performance management tools BEST helps an IS auditor evaluate the success of an organization's IT strategy implementation and execution?

    A. IT benchmarking
    B. Capability maturity model
    C. Six Sigma
    D. IT metrics dashboard

  • Question 137:

    Which of the following is the PRIMARY objective of enterprise architecture (EA)?

    A. Maintaining detailed system documentation
    B. Managing and planning for IT investments
    C. Executing customized development and delivery of projects
    D. Enforcing the IT policy across the organization

  • Question 138:

    Which of the following should an IS auditor recommend as a PRIMARY area of focus when an organization decides to outsource technical support for its external customers?

    A. Align service level agreements (SLAs) with current needs.
    B. Monitor customer satisfaction with the change.
    C. Minimize costs related to the third-party agreement.
    D. Ensure right to audit is included within the contract.

  • Question 139:

    Which of the following BEST mitigates the risk of SQL injection attacks against applications exposed to the internet?

    A. Web application firewall (WAF)
    B. SQL server hardening
    C. Patch management program
    D. SQL server physical controls

  • Question 140:

    IT governance should be driven by:

    A. business unit initiatives.
    B. balanced scorecards.
    C. policies and standards.
    D. organizational strategies.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Isaca exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CISA exam preparations and Isaca certification application, do not hesitate to visit our Vcedump.com to find your solutions here.