Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

CISA Exam Dumps - Isaca Certification Questions and Answers

Question # 54

The PRIMARY purpose of an incident response plan is to:

Options:

A.

reduce the impact of an adverse event on information assets.

B.

increase the effectiveness of preventive controls.

C.

reduce the maximum tolerable downtime (MTD) of impacted systems.

D.

increase awareness of impacts from adverse events to IT systems.

Buy Now
Question # 55

Which of the following staff should an IS auditor interview FIRST to obtain a general overview of the various technologies used across different programs?

Options:

A.

Technical architect

B.

Enterprise architect

C.

Program manager

D.

Solution architect

Buy Now
Question # 56

Which of the following is the MOST important Issue for an IS auditor to consider with regard to Voice-over IP (VoIP) communications?

Options:

A.

Continuity of service

B.

Identity management

C.

Homogeneity of the network

D.

Nonrepudiation

Buy Now
Question # 57

Having knowledge in which of the following areas is MOST relevant for an IS auditor reviewing public key infrastructure (PKI)?

Options:

A.

Design and application of key controls in public audit

B.

Security strategy in public cloud Infrastructure as a Service (IaaS)

C.

Modern encoding methods for digital communications

D.

Technology and process life cycle for digital certificates and key pairs

Buy Now
Question # 58

The use of which of the following is an inherent risk in the application container infrastructure?

Options:

A.

Shared registries

B.

Host operating system

C.

Shared data

D.

Shared kernel

Buy Now
Question # 59

The purpose of a checksum on an amount field in an electronic data interchange (EDI) communication of financial transactions is to ensure:

Options:

A.

nonrepudiation.

B.

authorization,

C.

integrity,

D.

authenticity.

Buy Now
Question # 60

Which of the following should be used to evaluate an IT development project before an investment is committed?

Options:

A.

Earned value analysis (EVA)

B.

Rapid application development

C.

Function point analysis

D.

Feasibility study

Buy Now
Question # 61

In which phase of penetration testing would host detection and domain name system (DNS) interrogation be performed?

Options:

A.

Discovery

B.

Attacks

C.

Planning

D.

Reporting

Buy Now
Question # 62

Which of the following is MOST important for an IS auditor to verify when reviewing the planned use of Benford ' s law as a data analytics technique to detect fraud in a set of credit card transactions?

Options:

A.

The transactions are in double integer format.

B.

The transaction amounts are selected randomly without restriction.

C.

The transaction analysis is limited to transactions within standard deviation.

D.

The transactions are all in the same currency.

Buy Now
Question # 63

Following a discussion on the results of a recent audit engagement, the process owner of the audited area has provided an action plan addressing the gaps and recommendations. The auditor disagrees with some of the responses where the process owner is accepting a level of residual risk that is not within the organization ' s risk appetite. What is the auditor ' s BEST course of action?

Options:

A.

Include the issue in the next report to the audit committee.

B.

Inform executive management of the residual risk.

C.

Accept the action plan proposed by the process owner.

D.

Escalate the situation to audit management.

Buy Now
Question # 64

Which of the following BEST supports the effectiveness of a compliance program?

Options:

A.

Implementing an awareness plan regarding compliance regulation requirements

B.

Implementing a governance, risk, and compliance (GRC) tool to track compliance to regulations

C.

Assessing and tracking all compliance audit findings

D.

Monitoring which compliance regulations apply to the organization

Buy Now
Question # 65

In an IT organization where many responsibilities are shared which of the following is the BEST control for detecting unauthorized data changes?

Options:

A.

Users are required to periodically rotate responsibilities

B.

Segregation of duties conflicts are periodically reviewed

C.

Data changes are independently reviewed by another group

D.

Data changes are logged in an outside application

Buy Now
Question # 66

An IS audit manager was temporarily tasked with supervising a project manager assigned to the organization ' s payroll application upgrade. Upon returning to the audit department, the audit manager has been asked to perform an audit to validate the implementation of the payroll application. The audit manager is the only one in the audit department with IT project management

experience. What is the BEST course of action?

Options:

A.

Transfer the assignment to a different audit manager despite lack of IT project management experience.

B.

Outsource the audit to independent and qualified resources.

C.

Manage the audit since there is no one else with the appropriate experience.

D.

Have a senior IS auditor manage the project with the IS audit manager performing final review.

Buy Now
Question # 67

Which of the following is the PRIMARY purpose of batch processing monitoring?

Options:

A.

To comply with security standards

B.

To summarize the batch processing reporting

C.

To log error events in batch processing

D.

To prevent an incident that may result from batch failure

Buy Now
Question # 68

Which of the following risks is BEST mitigated by implementing an automated three-way match?

Options:

A.

Inaccurate customer records

B.

Purchase order delays

C.

lnaccurate customer discounts

D.

Invalid payment processing

Buy Now
Question # 69

Which type of control is being implemented when a biometric access device is installed at the entrance to a facility?

Options:

A.

Preventive

B.

Deterrent

C.

Corrective

D.

Detective

Buy Now
Question # 70

Who should be the FIRST to evaluate an audit report prior to issuing it to the project steering committee?

Options:

A.

IS audit manager

B.

Audit committee

C.

Business owner

D.

Project sponsor

Buy Now
Question # 71

An IS auditor is reviewing how password resets are performed for users working remotely. Which type of documentation should be requested to understand the detailed steps required for this activity?

Options:

A.

Standards

B.

Guidelines

C.

Policies

D.

Procedures

Buy Now
Question # 72

When classifying information, it is MOST important to align the classification to:

Options:

A.

business risk

B.

security policy

C.

data retention requirements

D.

industry standards

Buy Now
Question # 73

An IS auditor has been asked to review the integrity of data transfer between two business-critical systems that have not been tested since implementation. Which of the following would provide the MOST useful information to plan an audit?

Options:

A.

Quality assurance (QA) testing

B.

System change logs

C.

IT testing policies and procedures

D.

Previous system interface testing records

Buy Now
Question # 74

Which of the following should be GREATEST concern to an IS auditor reviewing data conversion and migration during the implementation of a new application system?

Options:

A.

Data conversion was performed using manual processes.

B.

Backups of the old system and data are not available online.

C.

Unauthorized data modifications occurred during conversion.

D.

The change management process was not formally documented

Buy Now
Question # 75

Following an IT audit, management has decided to accept the risk highlighted in the audit report. Which of the following would provide the MOST assurance to the IS auditor that management

is adequately balancing the needs of the business with the need to manage risk?

Options:

A.

A communication plan exists for informing parties impacted by the risk.

B.

Potential impact and likelihood are adequately documented.

C.

Identified risk is reported into the organization ' s risk committee.

D.

Established criteria exist for accepting and approving risk.

Buy Now
Question # 76

Which task should an IS auditor complete FIRST during the preliminary planning phase of a database security review?

Options:

A.

Perform a business impact analysis (BIA).

B.

Determine which databases will be in scope.

C.

Identify the most critical database controls.

D.

Evaluate the types of databases being used

Buy Now
Question # 77

When selecting a new data loss prevention (DLP) solution, the MOST important consideration is that the solution:

Options:

A.

is cost effective and meets proposed return on investment (ROI) criteria.

B.

provides comprehensive reporting and alerting features with detailed insights on data movements.

C.

is compatible with legacy IT infrastructure and integrates with other security tools.

D.

identifies and safeguards confidential information from unauthorized transmission.

Buy Now
Question # 78

Which of the following is the BEST recommendation to include in an organization ' s bring your own device (BYOD)

policy to help prevent data leakage?

Options:

A.

Require employees to waive privacy rights related to data on BYOD devices.

B.

Require multi-factor authentication on BYOD devices,

C.

Specify employee responsibilities for reporting lost or stolen BYOD devices.

D.

Allow only registered BYOD devices to access the network.

Buy Now
Question # 79

During an IS audit of a data center, it was found that programmers are allowed to make emergency fixes to operational programs. Which of the following should be the IS auditor ' s PRIMARY recommendation?

Options:

A.

Programmers should be allowed to implement emergency fixes only after obtaining verbal agreement from the application owner.

B.

Emergency program changes should be subject to program migration and testing procedures before they are applied to operational systems.

C.

Bypass user ID procedures should be put in place to ensure that the changes are subject to after-the-event approval and testing.

Buy Now
Question # 80

The MOST important objective of a post-implementation audit is to:

Options:

A.

Address lessons learned from the project.

B.

Determine whether the required objectives were met.

C.

Develop a process for continuous improvement.

D.

Seek approval for the next implementation phase.

Buy Now
Question # 81

Which of the following is the MOST important consideration when an organization is performing a business impact analysis (BIA)?

Options:

A.

Focusing on the impact of disruptions caused by technological risks.

B.

Validating recovery time objectives (RTOs) set by IT management.

C.

Involving process owners from various departments.

D.

Identifying hardware that is critical for meeting regulatory requirements.

Buy Now
Question # 82

Which of the following should an organization do FIRST when an employee is terminated for fraudulent activity?

Options:

A.

Review transactions approved by the employee.

B.

Escort the employee off the premises.

C.

Disable the employee’s logical access.

D.

Back up the employee’s hard drive.

Buy Now
Question # 83

Which of the following provides an IS auditor assurance that the interface between a point-of-sale (POS) system and the general ledger is transferring sales data completely and accurately?

Options:

A.

Electronic copies of customer sales receipts are maintained.

B.

Monthly bank statements are reconciled without exception.

C.

Nightly batch processing has been replaced with real-time processing.

D.

The data transferred over the POS interface is encrypted.

Buy Now
Question # 84

Which of the following observations should be of GREATEST concern to an IS auditor assessing access controls for the accounts payable module of a finance system?

Options:

A.

Payment files are stored on a shared drive in a writable format prior to processing.

B.

Accounts payable staff have access to update vendor bank account details.

C.

The IS auditor was granted access to create purchase orders.

D.

Configured delegation limits do not align to the organization ' s delegation’s policy.

Buy Now
Question # 85

Which of the following should be of GREATEST concern to an IS auditor assessing the effectiveness of an organization ' s vulnerability scanning program ' '

Options:

A.

Steps taken to address identified vulnerabilities are not formally documented

B.

Results are not reported to individuals with authority to ensure resolution

C.

Scans are performed less frequently than required by the organization ' s vulnerability scanning schedule

D.

Results are not approved by senior management

Buy Now
Question # 86

During an audit of a financial application, it was determined that many terminated users ' accounts were not disabled. Which of the following should be the IS auditor ' s NEXT step?

Options:

A.

Perform substantive testing of terminated users ' access rights.

B.

Perform a review of terminated users ' account activity

C.

Communicate risks to the application owner.

D.

Conclude that IT general controls ate ineffective.

Buy Now
Question # 87

The IS quality assurance (OA) group is responsible for:

Options:

A.

ensuring that program changes adhere to established standards.

B.

designing procedures to protect data against accidental disclosure.

C.

ensuring that the output received from system processing is complete.

D.

monitoring the execution of computer processing tasks.

Buy Now
Question # 88

A characteristic of a digital signature is that it

Options:

A.

is under control of the receiver

B.

is unique to the message

C.

is validated when data are changed

D.

has a reproducible hashing algorithm

Buy Now
Question # 89

What is the PRIMARY benefit of using one-time passwords?

Options:

A.

An intercepted password cannot be reused

B.

Security for applications can be automated

C.

Users do not have to memorize complex passwords

D.

Users cannot be locked out of an account

Buy Now
Question # 90

In the case of a disaster where the data center is no longer available, which of the following tasks should be done FIRST?

Options:

A.

Perform data recovery.

B.

Arrange for a secondary site.

C.

Analyze risk.

D.

Activate the call tree.

Buy Now
Question # 91

An IS auditor finds that a number of key patches have not been applied in a timely manner due to re-source constraints. Which of the following is the GREATEST risk to the organization in this

situation?

Options:

A.

Systems may not be supported by the vendor.

B.

Known security vulnerabilities may not be mitigated.

C.

Different systems may not be compatible.

D.

The systems may not meet user requirements.

Buy Now
Question # 92

Which of the following should be the GREATEST concern to an IS auditor reviewing an organization ' s method to transport sensitive data between offices?

Options:

A.

The method relies exclusively on the use of public key infrastructure (PKI).

B.

The method relies exclusively on the use of digital signatures.

C.

The method relies exclusively on the use of asymmetric encryption algorithms.

D.

The method relies exclusively on the use of 128-bit encryption.

Buy Now
Question # 93

Which of the following is the BEST sampling method to use when relatively few errors are expected to be found in a population?

Options:

A.

Variable sampling

B.

Judgmental sampling

C.

Stop-or-go sampling

D.

Discovery sampling

Buy Now
Question # 94

Which of the following security measures will reduce the risk of propagation when a cyberattack occurs?

Options:

A.

Perimeter firewall

B.

Data loss prevention (DLP) system

C.

Network segmentation

D.

Web application firewall (WAF)

Buy Now
Question # 95

Which of the following documents would be MOST useful in detecting a weakness in segregation of duties?

Options:

A.

System flowchart

B.

Data flow diagram

C.

Process flowchart

D.

Entity-relationship diagram

Buy Now
Question # 96

In an environment where data virtualization is used, which of the following provides the BEST disaster recovery solution?

Options:

A.

Onsite disk-based backup systems

B.

Tape-based backup systems

C.

Virtual tape library

D.

Redundant array of independent disks (RAID)

Buy Now
Question # 97

During a security audit, an IS auditor is tasked with reviewing log entries obtained from an enterprise intrusion prevention system (IPS). Which type of risk would be associated with the potential for the auditor to miss a sequence of logged events that could indicate an error in the IPS configuration?

Options:

A.

Sampling risk

B.

Detection risk

C.

Control risk

D.

Inherent risk

Buy Now
Question # 98

Which of the following should be the GREATEST concern for an IS auditor reviewing recent disaster recovery operations?

Options:

A.

The recovery point objective (RPO) was not defined.

B.

Test data was lost during a recovery operation.

C.

A warm site was used as a recovery strategy.

D.

A full backup was only performed once a week.

Buy Now
Question # 99

Which of the following is the MOST effective way to detect as many abnormalities as possible during an IS audit?

Options:

A.

Conduct a walk-through of the process.

B.

Perform substantive testing on sampled records.

C.

Perform judgmental sampling of key processes.

D.

Use a data analytics tool to identify trends.

Buy Now
Question # 100

The due date of an audit project is approaching, and the audit manager has determined that only 60% of the audit has been completed. Which of the following should the audit manager do FIRST?

Options:

A.

Determine where delays have occurred

B.

Assign additional resources to supplement the audit

C.

Escalate to the audit committee

D.

Extend the audit deadline

Buy Now
Question # 101

Which of the following is MOST useful when planning to audit an organization ' s compliance with cybersecurity regulations in foreign countries?

Options:

A.

Prioritize the audit to focus on the country presenting the greatest amount of operational risk.

B.

Follow the cybersecurity regulations of the country with the most stringent requirements.

C.

Develop a template that standardizes the reporting of findings from each country ' s audit team

D.

Map the different regulatory requirements to the organization ' s IT governance framework

Buy Now
Question # 102

Which type of attack targets security vulnerabilities in web applications to gain access to data sets?

Options:

A.

Denial of service (DOS)

B.

SQL injection

C.

Phishing attacks

D.

Rootkits

Buy Now
Question # 103

Who is PRIMARILY responsible for the design of IT controls to meet control objectives?

Options:

A.

Risk management

B.

Business management

C.

IT manager

D.

Internal auditor

Buy Now
Exam Code: CISA
Exam Name: Certified Information Systems Auditor
Last Update: Jul 14, 2026
Questions: 1598
CISA pdf

CISA PDF

$59.7  $199
CISA Engine

CISA Testing Engine

$67.5  $225
CISA PDF + Engine

CISA PDF + Testing Engine

$74.7  $249