CISA Exam Details

  • Exam Code
    :CISA
  • Exam Name
    :Certified Information Systems Auditor
  • Certification
    :Isaca Certifications
  • Vendor
    :Isaca
  • Total Questions
    :2178 Q&As
  • Last Updated
    :May 26, 2026

Isaca CISA Online Questions & Answers

  • Question 191:

    Which of the following provides the MOST reliable method of preventing unauthonzed logon?

    A. issuing authentication tokens
    B. Reinforcing current security policies
    C. Limiting after-hours usage
    D. Installing an automatic password generator

  • Question 192:

    Which type of threat can utilize a large group of automated social media accounts to steal data, send spam, or launch distributed denial of service (DDoS) attacks?

    A. Botnet attack
    B. Data mining
    C. Phishing attempt
    D. Malware sharing

  • Question 193:

    An IS auditor is asked to provide feedback on the systems options analysis for a new project. The BEST course of action for the IS auditor would be to:

    A. Identify the best alternative.
    B. Retain comments as findings for the audit report.
    C. Comment on the criteria used to assess the alternatives.
    D. Request at least one other alternative.

  • Question 194:

    An IS auditor previously worked in an organization s IT department and was involved with the design of the business continuity plan (BCP). The IS auditor has now been asked to review this same BCP. The auditor should FIRST.

    A. document the conflict in the audit report.
    B. decline the audit assignment.
    C. communicate the conflict of interest to the audit manager prior to starting the assignment.
    D. communicate the conflict of interest to the audit committee prior to starting the assignment

  • Question 195:

    Which of the following is MOST important to define within a disaster recovery plan (DRP)?

    A. Business continuity plan (BCP)
    B. Test results for backup data restoration
    C. A comprehensive list of disaster recovery scenarios and priorities
    D. Roles and responsibilities for recovery team members

  • Question 196:

    Which of the following would lead an IS auditor to conclude that the evidence collected during a digital forensic investigation would not be admissible in court?

    A. The person who collected the evidence is not qualified to represent the case.
    B. The logs failed to identify the person handling the evidence.
    C. The evidence was collected by the internal forensics team.
    D. The evidence was not fully backed up using a cloud-based solution prior to the trial.

  • Question 197:

    Which of the following would be MOST critical for an IS auditor to look for when evaluating fire precautions in a manned data center located in the upper floor of a multi-story building?

    A. Existence of handheld fire extinguishers in highly visible locations
    B. Documentation of regular inspections by the local fire department
    C. Adequacy of the HVAC system throughout the facility
    D. Documentation of tested emergency evacuation plans

  • Question 198:

    A small organization is experiencing rapid growth and plans to create a new information security policy. Which of the following is MOST relevant to creating the policy?

    A. Business objectives
    B. Business impact analysis (BIA)
    C. Enterprise architecture (EA)
    D. Recent incident trends

  • Question 199:

    Which of the following access rights presents the GREATEST risk when granted to a new member of the system development staff?

    A. Write access to production program libraries
    B. Write access to development data libraries
    C. Execute access to production program libraries
    D. Execute access to development program libraries

  • Question 200:

    Which of the following access control situations represents the MOST serious control weakness?

    A. Computer operators have access to system level flowcharts.
    B. Programmers have access to development hardware.
    C. End users have access to program development tools.
    D. System developers have access to production data.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Isaca exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CISA exam preparations and Isaca certification application, do not hesitate to visit our Vcedump.com to find your solutions here.