Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

CISA Exam Dumps - Isaca Certification Questions and Answers

Question # 454

When reviewing whether IT investments are meeting business objectives, which of the following evaluations would be MOST useful?

Options:

A.

A break-even analysis

B.

Realized return on investment (ROI) versus projected ROI

C.

Budgeted spend versus actual spend

D.

Actual return on investment (ROI) versus industry average ROI

Buy Now
Question # 455

An IS auditor is reviewing the service management of an outsourced help desk. Which of the following is the BEST indicator of how effectively the service provider is performing this function?

Options:

A.

Average ticket age

B.

Number of calls worked

C.

Customer satisfaction ratings

D.

Call transcript reviews

Buy Now
Question # 456

Which of the following are examples of corrective controls?

Options:

A.

Implementing separation of duties and hash totals

B.

Performing internal audit reviews and remediation activities

C.

Applying rollback scripts and backup procedures

D.

Enforcing disciplinary action and termination procedures

Buy Now
Question # 457

A steering committee established to oversee an organization’s digital transformation program is MOST likely to be involved with which of the following activities?

Options:

A.

Designing interface controls.

B.

Documenting requirements.

C.

Reviewing escalated project issues.

D.

Preparing project status reports.

Buy Now
Question # 458

What should an IS auditor do FIRST when a follow-up audit reveals some management action plans have not been initiated?

Options:

A.

Confirm whether the identified risks are still valid.

B.

Provide a report to the audit committee.

C.

Escalate the lack of plan completion to executive management.

D.

Request an additional action plan review to confirm the findings.

Buy Now
Question # 459

A financial accounting system audit determined that audit logging of transactions had been disabled by a finance employee. The IS auditor recommended that finance personnel no longer have the capability to change audit logging settings. Which of the following is MOST important to verify during the follow-up?

Options:

A.

Finance personnel receive security awareness training.

B.

Audit logs of transactions are reviewed.

C.

Changes to configurations are documented.

D.

Least privilege access is being enforced.

Buy Now
Question # 460

An organization has implemented a distributed security administration system to replace the previous centralized one. Which of the following presents the GREATEST potential concern?

Options:

A.

Security procedures may be inadequate to support the change

B.

A distributed security system is inherently a weak security system

C.

End-user acceptance of the new system may be difficult to obtain

D.

The new system will require additional resources

Buy Now
Question # 461

Which of the following provides the GREATEST assurance that an organization has effective controls preventing connection of unauthorized Internet of Things (IoT) devices to the corporate network?

Options:

A.

Reviewing authenticated network vulnerability scan results

B.

Assessing as-implemented IoT device configurations

C.

Assessing network access control (NAC) configurations

D.

Reviewing IT policies covering IoT authorizations

Buy Now
Question # 462

Which of the following security risks can be reduced by a property configured network firewall?

Options:

A.

SQL injection attacks

B.

Denial of service (DoS) attacks

C.

Phishing attacks

D.

Insider attacks

Buy Now
Question # 463

Which of the following documents should specify roles and responsibilities within an IT audit organization?

Options:

A.

Organizational chart

B.

Audit charier

C.

Engagement letter

D.

Annual audit plan

Buy Now
Question # 464

An organization has recently moved to an agile model for deploying custom code to its in-house accounting software system. When reviewing the procedures in place for production code deployment, which of the following is the MOST significant security concern to address?

Options:

A.

Software vulnerability scanning is done on an ad hoc basis.

B.

Change control does not include testing and approval from quality assurance (QA).

C.

Production code deployment is not automated.

D.

Current DevSecOps processes have not been independently verified.

Buy Now
Question # 465

Which of the following should be an IS auditor ' s GREATEST concern when an international organization intends to roll out a global data privacy policy?

Options:

A.

Requirements may become unreasonable.

B.

The policy may conflict with existing application requirements.

C.

Local regulations may contradict the policy.

D.

Local management may not accept the policy.

Buy Now
Question # 466

Which of the following provides the BEST evidence that a third-party service provider ' s information security controls

are effective?

Options:

A.

An audit report of the controls by the service provider ' s external auditor

B.

Documentation of the service provider ' s security configuration controls

C.

An interview with the service provider ' s information security officer

D.

A review of the service provider ' s policies and procedures

Buy Now
Question # 467

Which of the following tasks would cause the GREATEST segregation of duties (SoD) concern if performed by the person who reconciles the organization ' s device inventory?

Options:

A.

Tracking devices used for spare parts

B.

Creating the device policy

C.

vIssuing devices to employees

D.

Approving the issuing of devices

Buy Now
Question # 468

An organization has assigned two now IS auditors to audit a now system implementation. One of the auditors has an IT-related degree, and one has a business degree. Which ol the following is MOST important to meet the IS audit standard for proficiency?

Options:

A.

The standard is met as long as one member has a globally recognized audit certification.

B.

Technical co-sourcing must be used to help the new staff.

C.

Team member assignments must be based on individual competencies.

D.

The standard is met as long as a supervisor reviews the new auditors ' work.

Buy Now
Question # 469

An IS auditor should be MOST concerned if which of the following fire suppression systems is utilized to protect an asset storage closet?

Options:

A.

Deluge system

B.

Wet pipe system

C.

Preaction system

D.

CO2 system

Buy Now
Question # 470

Which of the following should be performed FIRST before key performance indicators (KPIs) can be implemented?

Options:

A.

Analysis of industry benchmarks

B.

Identification of organizational goals

C.

Analysis of quantitative benefits

D.

Implementation of a balanced scorecard

Buy Now
Question # 471

An IS auditor reviewing the system development life cycle (SDLC) finds there is no requirement for business cases. Which of the following should be offGREATEST concern to the organization?

Options:

A.

Vendor selection criteria are not sufficiently evaluated.

B.

Business resources have not been optimally assigned.

C.

Business impacts of projects are not adequately analyzed.

D.

Project costs exceed established budgets.

Buy Now
Question # 472

Which of the following controls is the BEST recommendation to prevent the skimming of debit or credit card data in point of sale (POS) systems?

Options:

A.

Encryption

B.

Chip and PIN

C.

Hashing

D.

Biometric authentication

Buy Now
Question # 473

Which of the following is the PRIMARY advantage of parallel processing for a new system implementation?

Options:

A.

Assurance that the new system meets functional requirements

B.

More time for users to complete training for the new system

C.

Significant cost savings over other system implemental or approaches

D.

Assurance that the new system meets performance requirements

Buy Now
Question # 474

Which of the following is the BEST approach for determining the overall IT risk appetite of an organization when business units use different methods formanaging IT risks?

Options:

A.

Average the business units’ IT risk levels

B.

Identify the highest-rated IT risk level among the business units

C.

Prioritize the organization ' s IT risk scenarios

D.

Establish a global IT risk scoring criteria

Buy Now
Question # 475

Data centers that want to prevent unauthorized personnel from entering during a power outage should ensure external access doors:

Options:

A.

Have physical key backup.

B.

Operate in fail-safe mode.

C.

Operate in fail-secure mode.

D.

Are alarmed and monitored.

Buy Now
Question # 476

An IS auditor is reviewing the disaster recovery plan (DRP) of an organization with offices across multiple regions. Which of the following should be the auditor ' s PRIMARY focus?

Options:

A.

Recovery point objective (RPO) monitoring

B.

Processes and system dependencies

C.

Disaster recovery training

D.

Data backup and storage changes

Buy Now
Question # 477

An IS auditor found that operations personnel failed to run a script contributing to year-end financial statements. Which of the following is the BEST recommendation?

Options:

A.

Retrain operations personnel.

B.

Implement a closing checklist.

C.

Update the operations manual.

D.

Bring staff with financial experience into operations.

Buy Now
Question # 478

An IS auditor is reviewing a machine learning model that predicts the likelihood that a user will watch a certain movie. Which of the following would be of GREATEST concern to the auditor?

Options:

A.

When the model was tested with data drawn from a different population, the accuracy decreased.

B.

The data set for training the model was obtained from an unreliable source.

C.

An open-source programming language was used to develop the model.

D.

The model was tested with data drawn from the same population as the training data.

Buy Now
Question # 479

A job is scheduled to transfer data from a transactional system database to a data lake for reporting purposes. Which of the following would be of GREATEST concern to an IS auditor?

Options:

A.

The inventory of scheduled jobs is not periodically reviewed

B.

Automated support ticket creation has not been implemented for job failures and errors

C.

Access to scheduling changes is restricted to job operators

D.

Notification alerts are configured to be sent to a support distribution group

Buy Now
Question # 480

Which of the following BEST describes the role of a document owner when implementing a data classification policy in an organization?

Options:

A.

Classifies documents to correctly reflect the level of sensitivity of information they contain

B.

Defines the conditions under which documents containing sensitive information may be transmitted

C.

Classifies documents in accordance with industry standards and best practices

D.

Ensures documents are handled in accordance With the sensitivity of information they contain

Buy Now
Question # 481

Which of the following BEST describes the concept of fault tolerance in system resiliency?

Options:

A.

It enables switching to redundant systems in case of faults.

B.

It minimizes downtime and ensures continuous operations.

C.

It allows systems to continue operating in the presence of faults.

D.

It distributes workloads across multiple servers to prevent overload.

Buy Now
Exam Code: CISA
Exam Name: Certified Information Systems Auditor
Last Update: Jul 14, 2026
Questions: 1598
CISA pdf

CISA PDF

$59.7  $199
CISA Engine

CISA Testing Engine

$67.5  $225
CISA PDF + Engine

CISA PDF + Testing Engine

$74.7  $249