Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

CISA Exam Dumps - Isaca Certification Questions and Answers

Question # 4

Which of the following strategies BEST optimizes data storage without compromising data retention practices?

Options:

A.

Limiting the size of file attachments being sent via email

B.

Automatically deleting emails older than one year

C.

Moving emails to a virtual email vault after 30 days

D.

Allowing employees to store large emails on flash drives

Buy Now
Question # 5

Which of the following BEST mitigates the risk of SQL injection attacks against applications exposed to the internet?

Options:

A.

Web application firewall (WAF)

B.

SQL server hardening

C.

Patch management program

D.

SQL server physical controls

Buy Now
Question # 6

Which of the following would be the BEST criteria for monitoring an IT vendor ' s service levels?

Options:

A.

Service auditor ' s report

B.

Performance metrics

C.

Surprise visit to vendor

D.

Interview with vendor

Buy Now
Question # 7

Which of the following observations should be of GREATEST concern to an IS auditor reviewing an organization ' s enterprise architecture (EA) program?

Options:

A.

IT application owners have sole responsibility for architecture approval.

B.

The architecture review board is chaired by the CIO.

C.

Information security requirements are reviewed by the EA program.

D.

The EA program governs projects that are not IT-related.

Buy Now
Question # 8

An IS auditor is reviewing security controls related to collaboration tools for a business unit responsible for intellectual property and patents. Which of the following observations should be of MOST concern to the auditor?

Options:

A.

Training was not provided to the department that handles intellectual property and patents

B.

Logging and monitoring for content filtering is not enabled.

C.

Employees can share files with users outside the company through collaboration tools.

D.

The collaboration tool is hosted and can only be accessed via an Internet browser

Buy Now
Question # 9

Which of the following is the GREATEST risk of project dashboards being set without sufficiently defined criteria?

Options:

A.

Adverse findings from internal and external auditors

B.

Lack of project portfolio status oversight

C.

Lack of alignment of project status reports

D.

Inadequate decision-making and prioritization

Buy Now
Question # 10

An organization ' s business continuity plan (BCP) should be:

Options:

A.

updated before an independent audit review.

B.

tested after an intrusion attempt into the organization ' s hot site.

C.

tested whenever new applications are implemented.

D.

updated based on changes to personnel and environments.

Buy Now
Question # 11

Which of the following would BEST determine whether a post-implementation review (PIR) performed by the project management office (PMO) was effective?

Options:

A.

Lessons learned were implemented.

B.

Management approved the PIR report.

C.

The review was performed by an external provider.

D.

Project outcomes have been realized.

Buy Now
Question # 12

During an information security review, an IS auditor learns an organizational policy requires all employ-ees to attend information security training during the first week of each new year. What is

the auditor ' s BEST recommendation to ensure employees hired after January receive adequate guid-ance regarding security awareness?

Options:

A.

Ensure new employees read and sign acknowledgment of the acceptable use policy.

B.

Revise the policy to include security training during onboarding.

C.

Revise the policy to require security training every six months for all employees.

D.

Require management of new employees to provide an overview of security awareness.

Buy Now
Question # 13

Which of the following is MOST important to consider when developing a service level agreement (SLAP)?

Options:

A.

Description of the services from the viewpoint of the provider

B.

Detailed identification of work to be completed

C.

Provisions for regulatory requirements that impact the end users ' businesses

D.

Description of the services from the viewpoint of the client organization

Buy Now
Question # 14

Which of the following recommendations would BEST prevent the implementation of IT projects without collaborating with the business?

Options:

A.

Partner with the business units to evaluate IT projects.

B.

Review the projects to identify similarities and eliminate duplication.

C.

Periodically review the projects ' return on investment (ROI).

D.

Prioritize protects based on business and IT resource availability.

Buy Now
Question # 15

Which of the following provides an IS auditor the BEST evidence that a third-party service provider ' s information security controls are effective?

Options:

A.

Documentation of the service provider’s security configuration controls

B.

A review of the service provider ' s policies and procedures

C.

An audit report of the controls by an external auditor

D.

An interview with the service provider ' s senior management

Buy Now
Question # 16

Which of the following should be done FIRST when planning to conduct internal and external penetration testing for a client?

Options:

A.

Establish the timing of testing.

B.

Identify milestones.

C.

Determine the test reporting

D.

Establish the rules of engagement.

Buy Now
Question # 17

During an audit of a reciprocal disaster recovery agreement between two companies, the IS auditor would be MOST concerned with the:

Options:

A.

allocation of resources during an emergency.

B.

frequency of system testing.

C.

differences in IS policies and procedures.

D.

maintenance of hardware and software compatibility.

Buy Now
Question # 18

Which of the following groups is PRIMARILY accountable for establishing a culture that facilitates an effective and efficient internal control system?

Options:

A.

HR

B.

Senior management

C.

Line management

D.

Internal audit

Buy Now
Question # 19

During a follow-up audit, an IS auditor finds that senior management has implemented a different remediation action plan than what was previously agreed upon. Which of the following is the auditor ' s BEST course of action?

Options:

A.

Report the deviation by the control owner in the audit report.

B.

Evaluate the implemented control to ensure it mitigates the risk to an acceptable level.

C.

Cancel the follow-up audit and reschedule for the next audit period.

D.

Request justification from management for not implementing the recommended control.

Buy Now
Question # 20

The PRIMARY purpose of a vulnerability assessment in a cybersecurity program is to:

Options:

A.

Enhance the security awareness of employees and other internal stakeholders.

B.

Identify known security exposures before attackers find them.

C.

Improve the overall security posture of the organization.

D.

Protect the organization’s IT assets against external cyberthreats.

Buy Now
Question # 21

Which of the following should an IS auditor use when verifying a three-way match has occurred in an enterprise resource planning (ERR) system?

Options:

A.

Bank confirmation

B.

Goods delivery notification

C.

Purchase requisition

D.

Purchase order

Buy Now
Question # 22

Which of the following is the BEST approach for determining the overall IT risk appetite of an organization when business units use different methods for managing IT risks?

Options:

A.

Establish a weighted score based on business unit criticality.

B.

Identify the highest-rated IT risk level among the business units.

C.

Average the business units’ IT risk levels.

D.

Establish a global IT risk scoring criteria.

Buy Now
Question # 23

Which of the following should an IS auditor expect to find when reviewing an IT metrics dashboard?

Options:

A.

An assessment of how senior management evaluates the IT department.

B.

An assessment of how senior management evaluates IT portfolio performance.

C.

An assessment of controls needed to mitigate risks.

D.

An assessment of business processes.

Buy Now
Question # 24

In which phase of the audit life cycle process should an IS auditor initially discuss observations with management?

Options:

A.

Planning phase

B.

Reporting phase

C.

Follow-up phase

D.

Fieldwork phase

Buy Now
Question # 25

An IS auditor finds that a recently deployed application has a number of developers with inappropriate update access left over from the testing environment. Which of the following would have BEST prevented the update access from being migrated?

Options:

A.

Establishing a role-based matrix for provisioning users

B.

Re-assigning user access rights in the quality assurance (QA) environment

C.

Holding the application owner accountable for application security

D.

Including a step within the system development life cycle (SDLC) to clean up access prior to go-live

Buy Now
Question # 26

The PRIMARY advantage of using open-source-based solutions is that they:

Options:

A.

Have well-defined support levels.

B.

Are easily implemented.

C.

Reduce dependence on vendors.

D.

Offer better security features.

Buy Now
Question # 27

Which of the following BEST demonstrates alignment of the IT department with the corporate mission?

Options:

A.

Analysis of IT department functionality

B.

Biweekly reporting to senior management

C.

Annual board meetings

D.

Quarterly steering committee meetings

Buy Now
Question # 28

An organization performs virtual machine (VM) replication instead of daily backups of its critical servers. Which of the following is MOST important to validate when evaluating the adequacy of recovery procedures?

Options:

A.

Replication servers are located offsite.

B.

Periodic testing of VM replication is completed.

C.

VM load balancing is configured.

D.

Internet access is restricted for VM backup administrators.

Buy Now
Question # 29

Visitors to a data center are required to present an ID and pre-approved documents. Which type of control has been implemented?

Options:

A.

Administrative control

B.

Preventive control

C.

Corrective control

D.

Detective control

Buy Now
Question # 30

Which of the following BEST reflects a mature strategic planning process?

Options:

A.

Action plans with IT requirements built into all projects

B.

An IT strategic plan with specifications of controls and safeguards

C.

An IT strategic plan that supports the corporate strategy

D.

IT projects from the strategic plan are approved by management

Buy Now
Question # 31

Which of the following is the GREATEST risk related to the use of virtualized environments?

Options:

A.

The host may be a potential single point of failure within the system.

B.

There may be insufficient processing capacity to assign to guests.

C.

There may be increased potential for session hijacking.

D.

Ability to change operating systems may be limited.

Buy Now
Question # 32

Which of the following provides the MOST useful information for performing a business impact analysis (B1A)?

Options:

A.

inventory of relevant business processes

B.

Policies for business procurement

C.

Documentation of application configurations

D.

Results of business resumption planning efforts

Buy Now
Question # 33

Which of the following MUST be completed as part of the annual audit planning process?

Options:

A.

Business continuity analysis

B.

Industry benchmarking

C.

Risk assessment

D.

Risk control matrix

Buy Now
Question # 34

Which of the following is the BEST method to delete sensitive information from storage media that will be reused?

Options:

A.

Cross-cut shredding.

B.

Multiple overwriting.

C.

Repartitioning.

D.

Reformatting.

Buy Now
Question # 35

Which of the following BEST helps to establish that digital evidence is in its original form and has not been tampered with?

Options:

A.

Imaging of digital media.

B.

Write-protecting media.

C.

Hash values.

D.

Chain of custody.

Buy Now
Question # 36

Following a breach, what is the BEST source to determine the maximum amount of time before customers must be notified that their personal information may have been compromised?

Options:

A.

Industry regulations

B.

Industry standards

C.

Incident response plan

D.

Information security policy

Buy Now
Question # 37

An IS auditor reviewing an organization’s online payment system finds that the system sometimes duplicates payments. Which control will BEST compensate for this weakness?

Options:

A.

Manually receipting payments.

B.

Using hash totals.

C.

Using control totals.

D.

Performing a bank reconciliation.

Buy Now
Question # 38

An IS auditor reviewing security incident processes realizes incidents are resolved and closed, but root causes are not investigated. Which of the following should be the MAJOR concern with this situation?

Options:

A.

Abuses by employees have not been reported.

B.

Lessons learned have not been properly documented

C.

vulnerabilities have not been properly addressed

D.

Security incident policies are out of date.

Buy Now
Question # 39

If a source code is not recompiled when program changes are implemented, which of the following is a compensating control to ensure synchronization of source and object?

Options:

A.

Comparison of object and executable code

B.

Review of audit trail of compile dates

C.

Comparison of date stamping of source and object code

D.

Review of developer comments in executable code

Buy Now
Question # 40

When reviewing an organization ' s information security policies, an IS auditor should verify that the policies have been defined PRIMARILY on the basis of:

Options:

A.

a risk management process.

B.

an information security framework.

C.

past information security incidents.

D.

industry best practices.

Buy Now
Question # 41

The charging method that effectively encourages the MOST efficient use of IS resources is:

Options:

A.

specific charges that can be tied back to specific usage.

B.

total utilization to achieve full operating capacity.

C.

residual income in excess of actual incurred costs.

D.

allocations based on the ability to absorb charges.

Buy Now
Question # 42

What is MOST important to verify during an external assessment of network vulnerability?

Options:

A.

Update of security information event management (SIEM) rules

B.

Regular review of the network security policy

C.

Completeness of network asset inventory

D.

Location of intrusion detection systems (IDS)

Buy Now
Question # 43

Which of the following BEST ensures that effective change management is in place in an IS environment?

Options:

A.

User authorization procedures for application access are well established.

B.

User-prepared detailed test criteria for acceptance testing of the software.

C.

Adequate testing was carried out by the development team.

D.

Access to production source and object programs is well controlled.

Buy Now
Question # 44

Which of the following BEST helps to ensure data integrity across system interfaces?

Options:

A.

Environment segregation

B.

Reconciliation

C.

System backups

D.

Access controls

Buy Now
Question # 45

Which type of review is MOST important to conduct when an IS auditor is informed that a recent internal exploitation of a bug has been discovered in a business application?

Options:

A.

Penetration testing

B.

Application security testing

C.

Forensic audit

D.

Server security audit

Buy Now
Question # 46

An organization using a cloud provider for its online billing system requires the website to be accessible to customers at all times. What is the BEST way to verify the organization ' s business requirements are met?

Options:

A.

Invoke the right-to-audit clause.

B.

Require the vendor to report any outages longer than five minutes

C.

Monitor the service level agreement (SLA) with the vendor.

D.

Agree on periodic performance discussions with the vendor

Buy Now
Question # 47

Which of the following activities is MOST likely to increase internal audit quality?

Options:

A.

Increasing audit staff training

B.

Outsourcing the internal audit function

C.

Increasing the number of planned audits

D.

Conducting client surveys

Buy Now
Question # 48

Which of the following is MOST important for an IS auditor to verify when evaluating an organization ' s firewall?

Options:

A.

Logs are being collected in a separate protected host

B.

Automated alerts are being sent when a risk is detected

C.

Insider attacks are being controlled

D.

Access to configuration files Is restricted.

Buy Now
Question # 49

What is the purpose of hashing a document?

Options:

A.

To prevent unauthorized disclosure of the contents

B.

To validate the integrity of the file contents

C.

To classify the file for internal use only

D.

To compress the size of the file

Buy Now
Question # 50

An IS auditor reviewing a job scheduling tool notices performance and reliability problems. Which of the following is MOST likely affecting the tool?

Options:

A.

Administrator passwords do not meet organizational security and complexity requirements.

B.

The number of support staff responsible for job scheduling has been reduced.

C.

The scheduling tool was not classified as business-critical by the IT department.

D.

Maintenance patches and the latest enhancement upgrades are missing.

Buy Now
Question # 51

A disaster recovery plan (DRP) should include steps for:

Options:

A.

assessing and quantifying risk.

B.

negotiating contracts with disaster planning consultants.

C.

identifying application control requirements.

D.

obtaining replacement supplies.

Buy Now
Question # 52

Which of the following should be used as the PRIMARY basis for prioritizing IT projects and initiatives?

Options:

A.

Estimated cost and time

B.

Level of risk reduction

C.

Expected business value

D.

Available resources

Buy Now
Question # 53

An IS auditor reviewing an information processing environment decides to conduct external penetration testing. Which of the following is MOST appropriate to include in the audit scope for the organization to distinguish between the auditor ' s penetration attacks and actual attacks?

Options:

A.

Restricted host IP addresses of simulated attacks

B.

Testing techniques of simulated attacks

C.

Source IP addresses of simulated attacks

D.

Timing of simulated attacks

Buy Now
Exam Code: CISA
Exam Name: Certified Information Systems Auditor
Last Update: Aug 11, 2026
Questions: 1598
CISA pdf

CISA PDF

$59.7  $199
CISA Engine

CISA Testing Engine

$67.5  $225
CISA PDF + Engine

CISA PDF + Testing Engine

$74.7  $249