Exam Details

  • Exam Code
    :CISA
  • Exam Name
    :Certified Information Systems Auditor
  • Certification
    :CISA Certification
  • Vendor
    :Isaca
  • Total Questions
    :1923 Q&As
  • Last Updated
    :

Isaca CISA Certification CISA Questions & Answers

  • Question 21:

    With regard to resilience, which of the following is the GREATEST risk to an organization that has implemented a new critical system?

    A. A business impact analysis (BIA) has not been performed

    B. Business data is not sanitized in the development environment

    C. There is no plan for monitoring system downtime

    D. The process owner has not signed off on user acceptance testing (UAT)

  • Question 22:

    A web proxy server for corporate connections to external resources reduces organizational risk by:

    A. anonymizing users through changed IP addresses.

    B. providing multi-factor authentication for additional security.

    C. providing faster response than direct access.

    D. load balancing traffic to optimize data pathways.

  • Question 23:

    An IS auditor is reviewing the service agreement with a technology company that provides IT help desk services to the organization. Which of the following monthly performance metrics is the BEST indicator of service quality?

    A. The total number of users requesting help desk services

    B. The average call waiting time on each request

    C. The percent of issues resolved by the first contact

    D. The average turnaround time spent on each reported issue

  • Question 24:

    Which of the following is the MOST important control for virualized environments?

    A. Regular updates of policies for the operation of the virtualized environment

    B. Hardening for the hypervisor and guest machines

    C. Redundancy of hardware resources and network components

    D. Monitoring utilization of resources at the guest operating system level

  • Question 25:

    An IS auditor is performing a follow-up audit for findings identified in an organization's user provisioning process.

    Which of the following is the MOST appropriate population to sample from when testing for remediation?

    A. All users provisioned after the finding was originally identified

    B. All users provisioned after management resolved the audit issue

    C. All users provisioned after the final audit report was issued

    D. All users who have followed user provisioning processes provided by management

  • Question 26:

    During which phase of the software development life cycle is it BEST to initiate the discussion of application controls?

    A. Business case development phase when stakeholders are identified

    B. Application design phase process functionalities are finalized

    C. User acceptance testing (UAT) phase when test scenarios are designed

    D. Application coding phase when algorithms are developed to solve business problems

  • Question 27:

    An IS auditor is reviewing the security of a web-based customer relationship management (CRM) system that is directly accessed by customers via the Internet. Which of the following should be a concern for the auditor?

    A. The system is hosted on an external third-party service provider's servers.

    B. The system is hosted in a hybrid-cloud platform managed by a service provider.

    C. The system is hosted within a demilitarized zone (DMZ) of a corporate network.

    D. The system is hosted within an internal segment of a corporate network.

  • Question 28:

    Which of the following is the MOST important Issue for an IS auditor to consider with regard to Voice-over IP (VoIP) communications?

    A. Continuity of service

    B. Identity management

    C. Homogeneity of the network

    D. Nonrepudiation

  • Question 29:

    An IS auditor is analyzing a sample of accounts payable transactions for a specific vendor and identifies one transaction with a value five times as high as the average transaction. Which of the following should the auditor do NEXT?

    A. Report the variance immediately to the audit committee

    B. Request an explanation of the variance from the auditee

    C. Increase the sample size to 100% of the population

    D. Exclude the transaction from the sample population

  • Question 30:

    Which of the following is the MOST efficient solution for a multi-location healthcare organization that wants to be able to access patient data wherever patients present themselves for care?

    A. Infrastructure as a Service (laaS) provider

    B. Software as a Service (SaaS) provider

    C. Network segmentation

    D. Dynamic localization

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Isaca exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CISA exam preparations and Isaca certification application, do not hesitate to visit our Vcedump.com to find your solutions here.