Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

CISA Exam Dumps - Isaca Certification Questions and Answers

Question # 304

An organization outsourced its IS functions to meet its responsibility for disaster recovery, the organization should:

Options:

A.

discontinue maintenance of the disaster recovery plan (DRP >

B.

coordinate disaster recovery administration with the outsourcing vendor

C.

delegate evaluation of disaster recovery to a third party

D.

delegate evaluation of disaster recovery to internal audit

Buy Now
Question # 305

What is the FIRST step when creating a data classification program?

Options:

A.

Categorize and prioritize data.

B.

Develop data process maps.

C.

Categorize information by owner.

D.

Develop a policy.

Buy Now
Question # 306

Which of the following is the BEST way to prevent social engineering incidents?

Options:

A.

Maintain an onboarding and annual security awareness program.

B.

Ensure user workstations are running the most recent version of antivirus software.

C.

Include security responsibilities in job descriptions and require signed acknowledgment.

D.

Enforce strict email security gateway controls

Buy Now
Question # 307

A now regulation requires organizations to report significant security incidents to the regulator within 24 hours of identification. Which of the following is the IS auditor’s BEST recommendation to facilitate compliance with the regulation?

Options:

A.

Establish key performance indicators (KPls) for timely identification of security incidents.

B.

Engage an external security incident response expert for incident handling.

C.

Enhance the alert functionality of the intrusion detection system (IDS).

D.

Include the requirement in the incident management response plan.

Buy Now
Question # 308

A network analyst is monitoring the network after hours and detects activity that appears to be a brute-force attempt to compromise a critical server. After reviewing the alerts to ensure their accuracy, what should be done NEXT?

Options:

A.

Perform a root cause analysis.

B.

Document all steps taken in a written report.

C.

Isolate the affected system.

D.

Invoke the incident response plan.

Buy Now
Question # 309

Which of the following would MOST effectively ensure the integrity of data transmitted over a network?

Options:

A.

Message encryption

B.

Certificate authority (CA)

C.

Steganography

D.

Message digest

Buy Now
Question # 310

Which of the following would be of GREATEST concern to an IS auditor reviewing the resiliency of an organizational network that has two internet connections?

Options:

A.

Network capacity testing has not been performed.

B.

The business continuity plan (BCP) has not been tested in the past six months.

C.

Non-critical applications are also connected to both connections.

D.

Both connections are from the same provider.

Buy Now
Question # 311

An IS auditor is reviewing processes for importing market price data from external data providers. Which of the following findings should the auditor consider MOST critical?

Options:

A.

The transfer protocol does not require authentication.

B.

The quality of the data is not monitored.

C.

Imported data is not disposed of frequently.

D.

The transfer protocol is not encrypted.

Buy Now
Question # 312

Which of the following should be the FIRST step in a data migration project?

Options:

A.

Reviewing decisions on how business processes should be conducted in the new system

B.

Completing data cleanup in the current database to eliminate inconsistencies

C.

Understanding the new system ' s data structure

D.

Creating data conversion scripts

Buy Now
Question # 313

Which of the following should be of GREATEST concern to an IS auditor when using data analytics?

Options:

A.

The data source lacks integrity.

B.

The data analytics software is open source.

C.

The data set contains irrelevant fields.

D.

The data was not extracted by the auditor.

Buy Now
Question # 314

Which of the following is the PRIMARY objective of a control self-assessment (CSA)?

Options:

A.

To shift some control monitoring responsibilities to functional areas

B.

To create cohesive teams through employee involvement

C.

To improve the audit rating process

D.

To reduce control costs associated with a specific function

Buy Now
Question # 315

IT disaster recovery time objectives (RTOs) should be based on the:

Options:

A.

maximum tolerable loss of data.

B.

nature of the outage

C.

maximum tolerable downtime (MTD).

D.

business-defined criticality of the systems.

Buy Now
Question # 316

Which of the following is MOST helpful in identifying system performance constraints?

Options:

A.

Security logs

B.

Directory service logs

C.

Proxy logs

D.

Operational logs

Buy Now
Question # 317

A senior auditor is reviewing work papers prepared by a junior auditor indicating that a finding was removed after the auditee said they corrected the problem. Which of the following is the senior auditor s MOST appropriate course of action?

Options:

A.

Ask the auditee to retest

B.

Approve the work papers as written

C.

Have the finding reinstated

D.

Refer the issue to the audit director

Buy Now
Question # 318

An organization has shifted from a bottom-up approach to a top-down approach in the development of IT policies. This should result in:

Options:

A.

greater consistency across the organization.

B.

a synthesis of existing operational policies.

C.

a more comprehensive risk assessment plan.

D.

greater adherence to best practices.

Buy Now
Question # 319

An IS auditor is verifying the adequacy of an organization ' s internal controls and is concerned about potential circumvention of regulations. Which of the following is the BEST sampling method to use?

Options:

A.

Variable sampling

B.

Random sampling

C.

Cluster sampling

D.

Attribute sampling

Buy Now
Question # 320

An IS auditor finds the log management system is overwhelmed with false positive alerts. The auditor ' s BEST recommendation would be to:

Options:

A.

establish criteria for reviewing alerts.

B.

recruit more monitoring personnel.

C.

reduce the firewall rules.

D.

fine tune the intrusion detection system (IDS).

Buy Now
Question # 321

The PRIMARY responsibility of a project steering committee is to:

Options:

A.

sign off on the final build document.

B.

ensure that each project deadline is met.

C.

ensure that developed systems meet business needs.

D.

provide regular project updates and oversight.

Buy Now
Question # 322

Which of the following is the BEST source of information tor an IS auditor to use when determining whether an organization ' s information security policy is adequate?

Options:

A.

Information security program plans

B.

Penetration test results

C.

Risk assessment results

D.

Industry benchmarks

Buy Now
Question # 323

Which of the following is the GREATEST concern associated with a high number of IT policy exceptions approved by management?

Options:

A.

The exceptions are likely to continue indefinitely.

B.

The exceptions may result in noncompliance.

C.

The exceptions may elevate the level of operational risk.

D.

The exceptions may negatively impact process efficiency.

Buy Now
Question # 324

Which of the following would be the MOST useful metric for management to consider when reviewing a project portfolio?

Options:

A.

Cost of projects divided by total IT cost

B.

Expected return divided by total project cost

C.

Net present value (NPV) of the portfolio

D.

Total cost of each project

Buy Now
Question # 325

Which of the following is a social engineering attack method?

Options:

A.

An unauthorized person attempts to gam access to secure premises by following an authonzed person through a secure door.

B.

An employee is induced to reveal confidential IP addresses and passwords by answering questions over the phone.

C.

A hacker walks around an office building using scanning tools to search for a wireless network to gain access.

D.

An intruder eavesdrops and collects sensitive information flowing through the network and sells it to third parties.

Buy Now
Question # 326

Which of the following should be of GREATEST concern to an IS auditor reviewing an organization ' s mobile device policies and controls in its corporate environment?

Options:

A.

The mobile authentication policy requires biometrics.

B.

The virtual private network (VPN) policy is not enabled for the internal corporate network.

C.

Not all active devices are enrolled in mobile device management (MDM).

D.

Remote wipe and lock features are only available with access to the internet.

Buy Now
Question # 327

Which of the following will MOST likely compromise the control provided By a digital signature created using RSA encryption?

Options:

A.

Reversing the hash function using the digest

B.

Altering the plaintext message

C.

Deciphering the receiver ' s public key

D.

Obtaining the sender ' s private key

Buy Now
Question # 328

Which of the following is the BEST way to help ensure new IT implementations align with enterprise architecture (EA) principles and requirements?

Options:

A.

Document the security view as part of the EA

B.

Consider stakeholder concerns when defining the EA

C.

Perform mandatory post-implementation reviews of IT implementations

D.

Conduct EA reviews as part of the change advisory board

Buy Now
Question # 329

During an organization ' s implementation of a data loss prevention (DLP) solution, which of the following activities should be completed FIRST?

Options:

A.

Configuring reports

B.

Configuring rule sets

C.

Enabling detection points

D.

Establishing exceptions workflow

Buy Now
Question # 330

Which of the following is the PRIMARY benefit of effective implementation of appropriate data classification?

Options:

A.

Ability to meet business requirements

B.

Assurance that sensitive data is encrypted

C.

Increased accuracy of sensitive data

D.

Management of business risk to sensitive data

Buy Now
Question # 331

An IS auditor is asked to provide feedback on the systems options analysis for a new project. The BEST course of action for the IS auditor would be to:

Options:

A.

Identify the best alternative.

B.

Retain comments as findings for the audit report.

C.

Comment on the criteria used to assess the alternatives.

D.

Request at least one other alternative.

Buy Now
Question # 332

Which of the following controls is MOST effective at preventing system failures when implementing a new web application?

Options:

A.

System recovery plan

B.

System testing

C.

Business continuity plan (BCP)

D.

Transaction monitoring

Buy Now
Question # 333

An IS auditor is reviewing a bank’s service level agreement (SLA) with a third-party provider that hosts the bank’s secondary data center. Which of the following findings should be of GREATEST concern to the auditor?

Options:

A.

The recovery time objective (RTO) has a longer duration than documented in the disaster recovery plan (DRP).

B.

The SLA has not been reviewed in more than a year.

C.

The recovery point objective (RPO) has a shorter duration than documented in the disaster recovery plan (DRP).

D.

Backup data is hosted online only.

Buy Now
Question # 334

Which of the following is an IS auditor ' s BEST course of action when the auditee indicates that a corrective action plan for a high-risk finding will take longer than expected?

Options:

A.

Accept the longer target date and document it in the audit system.

B.

Determine if an interim compensating control has been implemented.

C.

Escalate the overdue finding to the audit committee.

D.

Require that remediation is completed in the agreed timeframe.

Buy Now
Question # 335

Which of the following is MOST effective in keeping a database management system (DBMS) at maximum performance?

Options:

A.

Periodic database maintenance.

B.

Data consistency control.

C.

Database logging.

D.

Data model normalization.

Buy Now
Question # 336

Which of the following should be done FIRST when planning a penetration test?

Options:

A.

Execute nondisclosure agreements (NDAs).

B.

Determine reporting requirements for vulnerabilities.

C.

Define the testing scope.

D.

Obtain management consent for the testing.

Buy Now
Question # 337

From a risk management perspective, which of the following is the BEST approach when implementing a large and complex data center IT infrastructure?

Options:

A.

A big bang deployment with a successful proof of concept

B.

Simulating the new infrastructure before deployment

C.

Prototyping and a one-phase deployment

D.

A deployment plan based on sequenced phases

Buy Now
Question # 338

Which of the following is an IS auditor ' s BEST recommendation for mitigating risk associated with inadvertent disclosure of sensitive information by employees?

Options:

A.

Intrusion prevention system (IPS) and firewalls

B.

Data loss prevention (DLP) technologies

C.

Cryptographic protection

D.

Email phishing simulation exercises

Buy Now
Question # 339

An employee approaches an IS auditor and expresses concern about a critical security issue in a newly installed application. Which of the following should the auditor do FIRST?

Options:

A.

Recommend reverting to the previous application.

B.

Discuss the concern with audit management.

C.

Conduct a review of the application.

D.

Disclose the concern to legal counsel.

Buy Now
Question # 340

Which of the following BEST mitigates the risk associated with the deployment of a new production system?

Options:

A.

Problem management

B.

Incident management

C.

Configuration management

D.

Release management

Buy Now
Question # 341

An IS auditor notes the transaction processing times in an order processing system have significantly increased after a major release. Which of the following should the IS auditor review FIRST?

Options:

A.

Capacity management plan

B.

Training plans

C.

Database conversion results

D.

Stress testing results

Buy Now
Question # 342

Which of the following is the PRIMARY purpose of conducting a control self-assessment (CSA)?

Options:

A.

To replace audit responsibilities

B.

To reduce control costs

C.

To promote control ownership

D.

To enable early detection of risks

Buy Now
Question # 343

Which of the following is MOST important to consider when defining disaster recovery strategies?

Options:

A.

Maximum tolerable downtime (MTD)

B.

Mean time to restore (MTTR)

C.

Mean time to acknowledge

D.

Maximum time between failures (MTBF)

Buy Now
Question # 344

Which of the following should be the PRIMARY basis for prioritizing follow-up audits?

Options:

A.

Audit cycle defined in the audit plan

B.

Complexity of management ' s action plans

C.

Recommendation from executive management

D.

Residual risk from the findings of previous audits

Buy Now
Question # 345

An IS department is evaluated monthly on its cost-revenue ratio user satisfaction rate, and computer downtime This is BEST zed as an application of.

Options:

A.

risk framework

B.

balanced scorecard

C.

value chain analysis

D.

control self-assessment (CSA)

Buy Now
Question # 346

An organization establishes capacity utilization thresholds and monitors for instances when thresholds are exceeded. Which of the following is BEST supported by this activity?

Options:

A.

Integrity

B.

Availability

C.

Confidentiality

D.

Nonrepudiation

Buy Now
Question # 347

Which of the following is the BEST recommendation to prevent fraudulent electronic funds transfers by accounts payable employees?

Options:

A.

Periodic vendor reviews

B.

Dual control

C.

Independent reconciliation

D.

Re-keying of monetary amounts

E.

Engage an external security incident response expert for incident handling.

Buy Now
Question # 348

A system performance dashboard indicates several application servers are reaching the defined threshold for maximum CPU allocation. Which of the following would be the IS auditor ' s BEST recommendation for the IT department?

Options:

A.

Increase the defined processing threshold to reflect capacity consumption during normal operations.

B.

Notify end users of potential disruptions caused by degradation of servers.

C.

Terminate both ingress and egress connections of these servers to avoid overload.

D.

Validate the processing capacity of these servers is adequate to complete computing tasks.

Buy Now
Question # 349

An IS auditor finds that a key Internet-facing system is vulnerable to attack and that patches are not available. What should the auditor recommend be done FIRST?

Options:

A.

Implement a new system that can be patched.

B.

Implement additional firewalls to protect the system.

C.

Decommission the server.

D.

Evaluate the associated risk.

Buy Now
Question # 350

A new regulation in one country of a global organization has recently prohibited cross-border transfer of personal data. An IS auditor has been asked to determine the organization ' s level of exposure In the affected country. Which of the following would be MOST helpful in making this assessment?

Options:

A.

Developing an inventory of all business entities that exchange personal data with the affected jurisdiction

B.

Identifying data security threats in the affected jurisdiction

C.

Reviewing data classification procedures associated with the affected jurisdiction

D.

Identifying business processes associated with personal data exchange with the affected jurisdiction

Buy Now
Question # 351

Which of the following is an analytical review procedure for a payroll system?

Options:

A.

Performing reasonableness tests by multiplying the number of employees by the average wage rate

B.

Evaluating the performance of the payroll system using benchmarking software

C.

Performing penetration attempts on the payroll system

D.

Testing hours reported on time sheets

Buy Now
Question # 352

A programmer has made unauthorized changes lo key fields in a payroll system report. Which of the following control weaknesses would have contributed MOST to this problem?

Options:

A.

The programmer did not involve the user in testing

B.

The user requirements were not documented

C.

The programmer has access to the production programs

D.

Payroll files were not under the control of a librarian

Buy Now
Question # 353

Which of the following is the BEST method to safeguard data on an organization ' s laptop computers?

Options:

A.

Disabled USB ports

B.

Full disk encryption

C.

Multi-factor authentication (MFA)

D.

Passkey phrases

Buy Now
Exam Code: CISA
Exam Name: Certified Information Systems Auditor
Last Update: Jul 14, 2026
Questions: 1598
CISA pdf

CISA PDF

$59.7  $199
CISA Engine

CISA Testing Engine

$67.5  $225
CISA PDF + Engine

CISA PDF + Testing Engine

$74.7  $249