ISACA CISA Practice Test Pdf Exam Material [Q191-Q211]

Share

ISACA CISA Practice Test Pdf Exam Material

CISA Answers CISA Free Demo Are Based On The Real Exam


ISACA CISA exam is a challenging but rewarding certification that can help IT professionals advance their careers in the field of information security. Certified Information Systems Auditor certification demonstrates that the candidate has the necessary knowledge, skills, and experience to identify, assess, and evaluate IT and business systems to ensure that they are secure and compliant with industry standards and regulations. It is a must-have for anyone who wants to work in the field of information security and is recognized by many organizations around the world.

 

NEW QUESTION # 191
In response to an audit finding regarding a payroll application, management implemented a new automated control. Which of the following would be MOST helpful to the IS auditor when evaluating the effectiveness of the new control?

  • A. A review of tabletop exercise results
  • B. Approved project scope document
  • C. Approved test scripts and results prior to implementation
  • D. Written procedures defining processes and controls

Answer: D

Explanation:
Explanation
The best way to evaluate the effectiveness of a new automated control is to review the written procedures that define the processes and controls. This will help the IS auditor to understand the objectives, scope, roles, responsibilities, and expected outcomes of the control. The written procedures will also provide a basis for testing the control and verifying its compliance with the audit finding recommendations. References:
ISACA Frameworks: Blueprints for Success
CISA Review Manual (Digital Version)


NEW QUESTION # 192
Which of the following would BEST prevent data from being orphaned?

  • A. Referential integrity
  • B. Input validation checks
  • C. Table indexes
  • D. Table partitioning

Answer: A


NEW QUESTION # 193
Which of the following is the GREATEST risk associated with storing customer data on a web server?

  • A. Data integrity
  • B. Data redundancy
  • C. Data confidentiality
  • D. Data availability

Answer: C


NEW QUESTION # 194
Which of the following should be included in a feasibility study for a project to implement an EDI process?

  • A. The proposed trusted third-party agreement
  • B. The necessary communication protocols
  • C. The detailed internal control procedures
  • D. The encryption algorithm format

Answer: B

Explanation:
Explanation/Reference:
Explanation:
Encryption algorithms, third-party agreements and internal control procedures are too detailed for this phase. They would only be outlined and any cost or performance implications shown. The communications protocols must be included, as there may be significant cost implications if new hardware and software are involved, and risk implications if the technology is new to the organization.


NEW QUESTION # 195
A computer program used by multiple departments has data quality issues. There is no agreement as to who should be responsible for corrective action. Which of the following is an IS auditor's BEST course of action?

  • A. Recommend the IT department be assigned data cleansing responsibility.
  • B. Modify the program to automatically cleanse the data and close the issue.
  • C. Note the disagreement and recommend establishing data governance.
  • D. Assign responsibility to the primary department using the program.

Answer: C

Explanation:
Section: Protection of Information Assets


NEW QUESTION # 196
Which of the following IT governance best practices improves strategic alignment?

  • A. A structure is provided that facilitates the creation and sharing of business information.
  • B. A knowledge base on customers, products, markets and processes is in place.
  • C. Supplier and partner risks are managed.
  • D. Top management mediate between the imperatives of business and technology.

Answer: D

Explanation:
Explanation/Reference:
Explanation:
Top management mediating between the imperatives of business and technology is an IT strategic alignment best practice. Supplier and partner risks being managed is a risk management best practice. A knowledge base on customers, products, markets and processes being in place is an IT value delivery best practice. An infrastructure being provided to facilitate the creation and sharing of business information is an IT value delivery and risk management best practice.


NEW QUESTION # 197
IT operations for a large organization have been outsourced. An IS auditor reviewing the outsourced operation should be MOST concerned about which of the following findings?

  • A. The outsourcing contract does not cover disaster recovery for the outsourced IT operations.
  • B. Recently a corrupted database could not be recovered because of library management problems.
  • C. The service provider does not have incident handling procedures.
  • D. incident logs are not being reviewed.

Answer: A

Explanation:
Explanation/Reference:
Explanation:
The lack of a disaster recovery provision presents a major business risk. Incorporating such a provision into the contract will provide the outsourcing organization leverage over the service provider. Choices B, C and D are problems that should be addressed by the service provider, but are not as important as contract requirements for disaster recovery.


NEW QUESTION # 198
Which of the following BEST ensures that effective change management is in place in an IS environment?

  • A. User authorization procedures for application access are well established.
  • B. Access to production source and object programs is well controlled.
  • C. Adequate testing was carried out by the development team.
  • D. User-prepared detailed test criteria for acceptance testing of the software.

Answer: A

Explanation:
Section: Protection of Information Assets


NEW QUESTION # 199
..control that MOST effectively addresses the risk of piggybackingAailgating into a restricted area without a dead-man door is:

  • A. using two-factor authentication
  • B. security awareness training
  • C. using biometric door locks.
  • D. requiring employees to wear ID badges

Answer: C


NEW QUESTION # 200
A PRIMARY benefit derived by an organization employing control self-assessment (CSA) techniques is that CSA

  • A. allows management to relinquish responsibility for control.
  • B. can identify high-risk areas for detailed review
  • C. can be used as a replacement for traditional audits.
  • D. allows IS auditors to independently assess risk

Answer: B


NEW QUESTION # 201
An IS auditor is conducting a follow-up internal IS audit and determines that several recommendations from
the prior year have not been implemented. Which of the following should be the auditor's FIRST course of
action?

  • A. Add unimplemented recommendations as findings for the new audit.
  • B. Request management implement recommendations from the prior year.
  • C. Continue the audit and disregard prior audit recommendations.
  • D. Evaluate the recommendations in context of the current IT environment.

Answer: A

Explanation:
Section: Protection of Information Assets


NEW QUESTION # 202
Which of the following a recent internal data breach, an IS auditor was asked to evaluate information security practices within the organization. Which of the following findings would be MOST important to report to senior management?

  • A. Desktop passwords do not require special characters
  • B. Security education and awareness workshops have not been completed
  • C. Users lack technical knowledge related to security and data protection
  • D. Employees are not required to sign a non-compete agreement.

Answer: B


NEW QUESTION # 203
Which of the following BEST describes the concept of ""defense in depth""?

  • A. multiple firewalls and multiple network OS are implemented.
  • B. None of the choices.
  • C. more than one subsystem needs to be compromised to compromise the security of the system and the information it holds.
  • D. intrusion detection and firewall filtering are required.
  • E. multiple firewalls are implemented.

Answer: C

Explanation:
Section: Protection of Information Assets
Explanation:
"With 0""defense in depth"", more than one subsystem needs to be compromised to compromise the security of the system and the information it holds. Subsystems should default to secure settings, and wherever possible should be designed to ""fail secure"" rather than ""fail insecure""."


NEW QUESTION # 204
Which of the following data validation edits is effective in detecting transposition and transcription errors?

  • A. Check digit
  • B. Range check
  • C. Duplicate check
  • D. Validity check

Answer: A

Explanation:
Explanation/Reference:
Explanation:
A check digit is a numeric value that is calculated mathematically and is appended to data to ensure that the original data have not been altered or an incorrect, but valid, value substituted. This control is effective in detecting transposition and transcription errors.
Incorrect answers:
A. A range check is checking data that matches a predetermined range of values.
C. A validity check is programmed checking of the data validity in accordance with predetermined criteriA.
D. In a duplicate check, new or fresh transactions are matched to those previously entered to ensure that they are not already in the system.


NEW QUESTION # 205
The BEST filter rule for protecting a network from being used as an amplifier in a denial of service (DoS) attack is to deny all:

  • A. incoming traffic with discernible spoofed IP source addresses.
  • B. incoming traffic to critical hosts.
  • C. incoming traffic with IP options set.
  • D. outgoing traffic with IP source addresses externa! to the network.

Answer: D

Explanation:
Explanation/Reference:
Explanation:
Outgoing traffic with an IP source address different than the IP range in the network is invalid, in most of the cases, it signals a DoS attack originated by an internal user or by a previously compromised internal machine; in both cases, applying this filter will stop the attack.


NEW QUESTION # 206
Which of the following is the FIRST step when conducting a business impact analysis?

  • A. Identifying events impacting continuity of operations
  • B. identifying critical information resources
  • C. Creating a data classification scheme
  • D. Analyzing past transaction volumes

Answer: B


NEW QUESTION # 207
Which of the following is MOST important when an incident may lead to prosecution?

  • A. Independent assessment
  • B. Preservation of evidence
  • C. Impact analysis
  • D. Timely incident detection

Answer: B

Explanation:
Section: Information System Operations, Maintenance and Support


NEW QUESTION # 208
Which of the following is the PRIMARY advantage of using virtualization technology for corporate applications?

  • A. Improved disaster recovery
  • B. Better utilization of resources
  • C. Stronger data security
  • D. Increased application performance

Answer: A


NEW QUESTION # 209
Which of the following provides the MOST useful information to an IS auditor when selecting projects for inclusion in an IT audit plan?

  • A. Project business case
  • B. Project issue log
  • C. Project plan
  • D. Project charter

Answer: A

Explanation:
The project business case provides the IS auditor with information on the purpose and objectives of the project, the expected costs and benefits of the project, and the possible risks associated with the project. This information can be used to help the IS auditor determine if the project is worth including in the IT audit plan. For more information, please refer to the ISACA CISA Study Guide section 4.12.2.1.


NEW QUESTION # 210
An IS auditor is following up on prior period items and finds management did not address an audit finding.
Which of the following should be the IS auditor's NEXT course of action?

  • A. Conduct a risk assessment of the repeat finding.
  • B. Recommend alternative solutions to address the repeat finding.
  • C. Interview management to determine why the finding was not addressed.
  • D. Note the exception in a new report as the item was not addressed by management.

Answer: C

Explanation:
Explanation
If an IS auditor finds that management did not address a prior period audit finding, the next course of action should be to interview management to determine why the finding was not addressed, as this would help to understand the root cause, the impact, and the risk level of the issue. Noting the exception in a new report, recommending alternative solutions, or conducting a risk assessment are possible subsequent steps, but they should not precede interviewing management. References: CISA Review Manual (Digital Version), Chapter 1, Section 1.6


NEW QUESTION # 211
......


The Certified Information Systems Auditor (CISA) Exam is a globally recognized certification offered by the Information Systems Audit and Control Association (ISACA). CISA exam is designed to test the knowledge and skills of professionals in the field of information systems auditing, control, and security. The CISA certification is highly valued in the industry, and is often required for IT auditors, information security professionals, and other professionals who work with IT systems.

 

CISA [May-2024] Newly Released] Exam Questions For You To Pass: https://www.trainingdump.com/ISACA/CISA-practice-exam-dumps.html

ISACA CISA Exam: Basic Questions With Answers: https://drive.google.com/open?id=1fSrtZZvMPV4A_snhwl_GPIHxE7ISEs7X

0
0
0
0