CISA Exam Details

  • Exam Code
    :CISA
  • Exam Name
    :Certified Information Systems Auditor
  • Certification
    :Isaca Certifications
  • Vendor
    :Isaca
  • Total Questions
    :2178 Q&As
  • Last Updated
    :May 26, 2026

Isaca CISA Online Questions & Answers

  • Question 621:

    Which of the following is an example of a preventive control for physical access?

    A. Keeping log entries for all visitors to the building
    B. Implementing a fingerprint-based access control system for the building
    C. Installing closed-circuit television (CCTV) cameras for all ingress and egress points
    D. Implementing a centralized logging server to record instances of staff logging into workstations

  • Question 622:

    Which of the following factor is LEAST important in the measurement of critical success factors of productivity in the SDLC phases?

    A. Dollar Spent per use
    B. Number of transactions per month
    C. Number of transactions per user
    D. Number of occurrences of fraud/misuse detection

  • Question 623:

    Which of the following provides the MOST assurance of the integrity of a firewall log?

    A. The log is reviewed on a monthly basis.
    B. Authorized access is required to view the log.
    C. The log cannot be modified.
    D. The log is retained per policy.

  • Question 624:

    An IS auditor discovers a recurring software control process issue that severely impacts the efficiency of a critical business process. Which of the following is the BEST recommendation?

    A. Replace the malfunctioning system.
    B. Determine the compensating controls.
    C. Identify other impacted processes.
    D. Determine the root cause of the issue.

  • Question 625:

    which of the following is a core functionality of a configuration and release management system?

    A. Managing privileged access to databases servers and infrastructure
    B. Identifying vulnerabilities in configuration settings
    C. Deploying a configuration change to the sandbox environment
    D. Identifying other configuration items that will be impacted by a given change

  • Question 626:

    An IS auditor concludes that a local area network's (LAN's) access security is satisfactory. In reviewing the work, the audit manager should:

    A. re-perform some steps of the audit to verify the quality of the work.
    B. verify that the elements of an agreed-upon audit plan have been addressed.
    C. verify user management's agreement with the findings.
    D. assess whether the auditor had the appropriate skills to perform the work.

  • Question 627:

    A message is being sent with a hash. The risk of an attacker changing the message and generating an authentic hash value can be mitigated by:

    A. requiring the recipient to use a different hash algorithm.
    B. generating hash output that is the same size as the original message.
    C. using a secret key in conjunction with the hash algorithm.
    D. using the sender's public key to encrypt the message.

  • Question 628:

    The purpose of a checksum on an amount field in an electronic data interchange (EDI) communication of financial transactions is to ensure:

    A. nonrepudiation.
    B. authorization,
    C. integrity,
    D. authenticity.

  • Question 629:

    In which of the following sampling methods is the entire sample considered to be irregular if a single error is found?

    A. Discovery sampling
    B. Variable sampling
    C. Stop-or-go sampling
    D. Judgmental sampling

  • Question 630:

    An IS auditor finds that a number of key patches have not been applied in a timely manner due to re-source constraints. Which of the following is the GREATEST risk to the organization in this situation?

    A. Systems may not be supported by the vendor.
    B. Known security vulnerabilities may not be mitigated.
    C. Different systems may not be compatible.
    D. The systems may not meet user requirements.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Isaca exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CISA exam preparations and Isaca certification application, do not hesitate to visit our Vcedump.com to find your solutions here.