Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

CISA Exam Dumps - Isaca Certification Questions and Answers

Question # 354

Which of the following is the GREATEST benefit of adopting an international IT governance framework rather than establishing a new framework based on the actual situation of a specific organization1?

Options:

A.

Readily available resources such as domains and risk and control methodologies

B.

Comprehensive coverage of fundamental and critical risk and control areas for IT governance

C.

Fewer resources expended on trial-and-error attempts to fine-tune implementation methodologies

D.

Wide acceptance by different business and support units with IT governance objectives

Buy Now
Question # 355

Which of the following is the PRIMARY role of the IT steering committee?

Options:

A.

Granting authorization for periodic IT audits

B.

Periodically reporting to business units about IT performance

C.

Facilitating collaboration between business and IT

D.

Ensuring business units are supporting IT objectives

Buy Now
Question # 356

Which of the following features of a library control software package would protect against unauthorized updating of source code?

Options:

A.

Required approvals at each life cycle step

B.

Date and time stamping of source and object code

C.

Access controls for source libraries

D.

Release-to-release comparison of source code

Buy Now
Question # 357

Which of the following should be the PRIMARY purpose of conducting tabletop exercises when re-viewing a security incident response plan?

Options:

A.

To provide efficiencies for alignment with incident response test scenarios

B.

To determine process improvement options for the incident response plan

C.

To gather documentation for responding to security audit inquiries

D.

To confirm that technology is in place to support the incident response plan

Buy Now
Question # 358

Which of the following is the BEST way to mitigate the impact of ransomware attacks?

Options:

A.

Invoking the disaster recovery plan (DRP)

B.

Backing up data frequently

C.

Paying the ransom

D.

Requiring password changes for administrative accounts

Buy Now
Question # 359

When planning an audit, it is acceptable for an IS auditor to rely on a third-party provider’s external audit report on service level management when the

Options:

A.

scope and methodology meet audit requirements

B.

service provider is independently certified and accredited

C.

report confirms that service levels were not violated

D.

report was released within the last 12 months

Buy Now
Question # 360

Which of the following is the MOST effective method to identify new errors introduced as a result of program changes?

Options:

A.

Unit testing.

B.

Interface testing.

C.

Integration testing.

D.

Regression testing.

Buy Now
Question # 361

In a small IT web development company where developers must have write access to production, the BEST recommendation of an IS auditor would be to:

Options:

A.

hire another person to perform migration to production.

B.

implement continuous monitoring controls.

C.

remove production access from the developers.

D.

perform a user access review for the development team

Buy Now
Question # 362

An IS auditor is reviewing an organization ' s primary router access control list. Which of the following should result in a finding?

Options:

A.

There are conflicting permit and deny rules for the IT group.

B.

The network security group can change network address translation (NAT).

C.

Individual permissions are overriding group permissions.

D.

There is only one rule per group with access privileges.

Buy Now
Question # 363

An IS auditor Is reviewing a recent security incident and is seeking information about me approval of a recent modification to a database system ' s security settings Where would the auditor MOST likely find this information?

Options:

A.

System event correlation report

B.

Database log

C.

Change log

D.

Security incident and event management (SIEM) report

Buy Now
Question # 364

The BEST way to evaluate the effectiveness of a newly developed application is to:

Options:

A.

perform a post-implementation review-

B.

analyze load testing results.

C.

perform a secure code review.

D.

review acceptance testing results.

Buy Now
Question # 365

Which of the following network communication protocols is used by network devices such as routers to send error messages and operational information indicating success or failure when communicating with another IP address?

Options:

A.

Transmission Control Protocol/Internet Protocol (TCP/IP)

B.

Internet Control Message Protocol

C.

Multipurpose Transaction Protocol

D.

Point-to-Point Tunneling Protocol

Buy Now
Question # 366

A new regulation has been enacted that mandates specific information security practices for the protection of customer data. Which of the following is MOST useful for an IS auditor to review when auditing against the regulation?

Options:

A.

Compliance gap analysis

B.

Customer data protection roles and responsibilities

C.

Customer data flow diagram

D.

Benchmarking studies of adaptation to the new regulation

Buy Now
Question # 367

During the review of a system disruption incident, an IS auditor notes that IT support staff were put in a position to make decisions beyond their level of authority.

Which of the following is the BEST recommendation to help prevent this situation in the future?

Options:

A.

Introduce escalation protocols.

B.

Develop a competency matrix.

C.

Implement fallback options.

D.

Enable an emergency access ID.

Buy Now
Question # 368

A transaction processing system interfaces with the general ledger. Data analytics has identified that some transactions are being recorded twice in the general ledger. While management states a system fix has been implemented, what should the IS auditor recommend to validate the interface is working in the future?

Options:

A.

Perform periodic reconciliations.

B.

Ensure system owner sign-off for the system fix.

C.

Conduct functional testing.

D.

Improve user acceptance testing (UAT).

Buy Now
Question # 369

The business case for an information system investment should be available for review until the:

Options:

A.

information system investment is retired.

B.

information system has reached end of life.

C.

formal investment decision is approved.

D.

benefits have been fully realized.

Buy Now
Question # 370

Which of the following provides the MOST useful information regarding an organization ' s risk appetite and tolerance?

Options:

A.

Gap analysis

B.

Audit reports

C.

Risk profile

D.

Risk register

Buy Now
Question # 371

Which type of threat can utilize a large group of automated social media accounts to steal data, send spam, or launch distributed denial of service (DDoS) attacks?

Options:

A.

Botnet attack

B.

Data mining

C.

Phishing attempt

D.

Malware sharing

Buy Now
Question # 372

During the implementation of an enterprise resource planning (ERP) system, an IS auditor is reviewing the results of user acceptance testing (UAT). Which of the following should be the auditor’s PRIMARY focus?

Options:

A.

Confirm that all errors have been communicated to end users.

B.

Determine if the business process owner has signed off on the results.

C.

Verify that system integration testing was performed.

D.

Determine if application interfaces have been satisfactorily tested.

Buy Now
Question # 373

Which of the following provides IS audit professionals with the BEST source of direction for performing audit functions?

Options:

A.

Audit charter

B.

IT steering committee

C.

Information security policy

D.

Audit best practices

Buy Now
Question # 374

When planning an audit to assess application controls of a cloud-based system, it is MOST important tor the IS auditor to understand the.

Options:

A.

architecture and cloud environment of the system.

B.

business process supported by the system.

C.

policies and procedures of the business area being audited.

D.

availability reports associated with the cloud-based system.

Buy Now
Question # 375

An IS auditor is performing a follow-up audit and notes that some critical deficiencies have not been addressed. The auditor ' s BEST course of action is to:

Options:

A.

document management ' s reasons for not addressing deficiencies.

B.

postpone the audit until the deficiencies are addressed.

C.

assess the impact of not addressing deficiencies.

D.

provide new recommendations.

Buy Now
Question # 376

Which of the following is the MOST important consideration when relying on the work of the prior auditor?

Options:

A.

Qualifications of the prior auditor

B.

Management agreement with recommendations

C.

Duration of the prior audit

D.

Number of findings identified by the prior auditor

Buy Now
Question # 377

An IS auditor finds that a new network connection allows communication between the Internet and the internal enterprise resource planning (ERP) system. Which of the following is the PRIMARY business impact to include when presenting this observation to management?

Options:

A.

An increase to the threat landscape

B.

A decrease in data quality in the ERP system

C.

A decrease in network performance

D.

An increase in potential fines from regulators

Buy Now
Question # 378

Which of the following would be of MOST concern to an IS auditor reviewing a data loss prevention (DLP) solution implementation for endpoints?

Options:

A.

The DLP solution does not support all types of servers.

B.

The solution has been implemented in blocking mode prior to performing tuning.

C.

The organization has never finished tuning the solution.

D.

The solution does not prevent data leakage because it is still in the monitoring phase.

Buy Now
Question # 379

An IS auditor reviewing the database controls for a new e-commerce system discovers a security weakness in the database configuration. Which of the following should be the IS auditor ' s NEXT course of action?

Options:

A.

Identify existing mitigating controls.

B.

Disclose the findings to senior management.

C.

Assist in drafting corrective actions.

D.

Attempt to exploit the weakness.

Buy Now
Question # 380

A project team has decided to switch to an agile approach to develop a replacement for an existing business application. Which of the following should an IS auditor do FIRST to ensure the effectiveness of the protect audit?

Options:

A.

Compare the agile process with previous methodology.

B.

Identify and assess existing agile process control

C.

Understand the specific agile methodology that will be followed.

D.

Interview business process owners to compile a list of business requirements

Buy Now
Question # 381

An IS auditor identifies that a legacy application to be decommissioned in three months cannot meet the security requirements established by the current policy. What is the BEST way (or the auditor to address this issue?

Options:

A.

Recommend the application be patched to meet requirements.

B.

Inform the IT director of the policy noncompliance.

C.

Verify management has approved a policy exception to accept the risk.

D.

Take no action since the application will be decommissioned in three months.

Buy Now
Question # 382

An organization has partnered with a third party to transport backup drives to an offsite storage facility. Which of the following is MOST important before sending the drives?

Options:

A.

Creating a chain of custody to accompany the drive in transit

B.

Ensuring data protection is aligned with the data classification policy

C.

Encrypting the drive with strong protection standards

D.

Ensuring the drive is placed in a tamper-evident mechanism

Buy Now
Question # 383

Which of the following is the PRIMARY reason an IS auditor should discuss observations with management before delivering a final report?

Options:

A.

Validate the audit observations_

B.

Identify business risks associated with the observations.

C.

Assist the management with control enhancements.

D.

Record the proposed course of corrective action.

Buy Now
Question # 384

Which of the following is MOST important to define within a disaster recovery plan (DRP)?

Options:

A.

Business continuity plan (BCP)

B.

Test results for backup data restoration

C.

A comprehensive list of disaster recovery scenarios and priorities

D.

Roles and responsibilities for recovery team members

Buy Now
Question # 385

Which of the following MUST be performed by senior audit leadership prior to starting an IS audit project?

Options:

A.

Signoff on the audit scope.

B.

Attend planning walk-throughs.

C.

Review audit planning documents.

D.

Meet with auditee leadership.

Buy Now
Question # 386

An IS auditor has been asked to review an event log aggregation system to ensure risk management practices have been applied. Which of the following should be of MOST concern to the auditor?

Options:

A.

The log data is not normalized.

B.

Log feeds are uploaded via batch process.

C.

Data Encryption Standards (DESs) have not been considered.

D.

Completeness testing has not been performed on the log data.

Buy Now
Question # 387

Which of the following indicates that an internal audit organization is structured to support the independence and clarity of the reporting process?

Options:

A.

Auditors are responsible for performing operational duties or activities.

B.

The internal audit manager reports functionally to a senior management official.

C.

The internal audit manager has a reporting line to the audit committee.

D.

Auditors are responsible for assessing and operating a system of internal controls.

Buy Now
Question # 388

Which of the following is MOST important when planning a network audit?

Options:

A.

Determination of IP range in use

B.

Analysis of traffic content

C.

Isolation of rogue access points

D.

Identification of existing nodes

Buy Now
Question # 389

Which of the following is MOST important to consider when evaluating a reciprocal arrangement as a recovery strategy?

Options:

A.

Differences in infrastructure capabilities.

B.

Differences in security policies and procedures.

C.

Differences in service level expectations.

D.

Differences in skills and resource competencies.

Buy Now
Question # 390

Which of the following findings from a database security audit presents the GREATEST risk of critical security exposures?

Options:

A.

Legacy data has not been purged.

B.

Admin account passwords are not set to expire.

C.

Default settings have not been changed.

D.

Database activity logging is not complete.

Buy Now
Question # 391

Job scheduling impacts system availability and reliability by:

Options:

A.

Reducing system downtime.

B.

Ensuring flexibility and scalability.

C.

Optimizing resource utilization.

D.

Decreasing system complexity.

Buy Now
Question # 392

Which of the following is the BEST way to detect unauthorized copies of licensed software on systems?

Options:

A.

Implement controls to prohibit downloads of unauthorized software.

B.

Conduct periodic software scanning.

C.

Perform periodic counting of licenses.

D.

Require senior management approval when installing licenses.

Buy Now
Question # 393

Due to a recent business divestiture, an organization has limited IT resources to deliver critical projects Reviewing the IT staffing plan against which of the following would BEST guide IT management when estimating resource requirements for future projects?

Options:

A.

Human resources (HR) sourcing strategy

B.

Records of actual time spent on projects

C.

Peer organization staffing benchmarks

D.

Budgeted forecast for the next financial year

Buy Now
Question # 394

During a pre-implementation review, an IS auditor notes that some scenarios have not been tested. Management has indicated that the project is critical and cannot be postponed. Which of the following is the auditor ' s BEST course of action?

Options:

A.

Determine whether the tested scenarios covered the most significant project risks.

B.

Help management complete remaining scenario testing before implementation.

C.

Recommend project implementation be postponed until all scenarios have been tested.

D.

Perform remaining scenario testing in the production environment post implementation.

Buy Now
Question # 395

Which of the following methods provides the MOST reliable audit evidence?

Options:

A.

Inquiry

B.

Management attestation

C.

Re-performance of controls

D.

Observation

Buy Now
Question # 396

Which of the following is the MOST effective control over visitor access to highly secured areas?

Options:

A.

Visitors are required to be escorted by authorized personnel.

B.

Visitors are required to use biometric authentication.

C.

Visitors are monitored online by security cameras

D.

Visitors are required to enter through dead-man doors.

Buy Now
Question # 397

Management has learned the implementation of a new IT system will not be completed on time and has requested an audit. Which of the following audit findings should be of GREATEST concern?

Options:

A.

The actual start times of some activities were later than originally scheduled.

B.

Tasks defined on the critical path do not have resources allocated.

C.

The project manager lacks formal certification.

D.

Milestones have not been defined for all project products.

Buy Now
Question # 398

Which of the following is the STRONGEST indication of a mature risk management program?

Options:

A.

Risk assessment results are used for informed decision-making.

B.

All attributes of risk are evaluated by the risk owner.

C.

A metrics dashboard has been approved by senior management.

D.

The risk register is regularly updated by risk practitioners.

Buy Now
Question # 399

The BEST way for an IS auditor to validate that separation of duties has been implemented is to perform:

Options:

A.

A review of personnel files.

B.

An analysis of documented job descriptions.

C.

A review of the organizational chart.

D.

A walk-through of job functions.

Buy Now
Question # 400

Which of the following should be an IS auditor ' s PRIMARY focus when developing a risk-based IS audit program?

Options:

A.

Portfolio management

B.

Business plans

C.

Business processes

D.

IT strategic plans

Buy Now
Question # 401

An IS auditor is reviewing job scheduling software and notes instances of delayed processing time, unexpected job interruption, and out-of-sequence job execution. Which of the following should the auditor examine FIRST to help determine the reasons for these instances?

Options:

A.

System schedule

B.

Job schedule

C.

Exception log

D.

Change log

Buy Now
Question # 402

A web proxy server for corporate connections to external resources reduces organizational risk by:

Options:

A.

anonymizing users through changed IP addresses.

B.

providing multi-factor authentication for additional security.

C.

providing faster response than direct access.

D.

load balancing traffic to optimize data pathways.

Buy Now
Question # 403

Which type of risk would MOST influence the selection of a sampling methodology?

Options:

A.

Inherent

B.

Residual

C.

Control

D.

Detection

Buy Now
Exam Code: CISA
Exam Name: Certified Information Systems Auditor
Last Update: Jul 14, 2026
Questions: 1598
CISA pdf

CISA PDF

$59.7  $199
CISA Engine

CISA Testing Engine

$67.5  $225
CISA PDF + Engine

CISA PDF + Testing Engine

$74.7  $249