CISA: Certified Information Systems Auditor Isaca Practice Exam
QuestionQ1
Protection of Information Assets
Save question
A business unit received an audit finding after an administrator made unauthorized emergency changes to a critical system. Which of the following would BEST prevent unauthorized changes in the future?
ATwo-factor authentication on emergency access accounts
BUpdated emergency change management procedures
CRegular emergency change-control log reviews
DDual-control temporary emergency access accounts
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ2
Protection of Information Assets
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ3
Protection of Information Assets
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ4
Protection of Information Assets
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ5
Information Systems Operations and Business Resilience
0
Community Discussion
No comments yet. Be the first to start the discussion!
It's free
100% of the questions are free for all users. No strings attached.
Information System Auditing ProcessGovernance and Management of ITInformation Systems Acquisition, Development and ImplementationInformation Systems Operations and Business ResilienceProtection of Information Assets
An employee misplaces a mobile device, resulting in the loss of sensitive corporate data. Which of the following would have BEST prevented data leakage?
AData encryption on the mobile device
BThe triggering of remote data wipe capabilities
CAwareness training for mobile device users
DComplex password policy for mobile devices
What is the first step in creating a data-classification program?
ADevelop a policy.
BDevelop data process maps.
CCategorize and prioritize data.
DCategorize information by owner.
The process of applying a hash function to a message, obtaining a digest, and ciphering that digest refers to:
Adigital signatures.
Bpublic key infrastructure (PKI).
Cauthentication.
Ddigital certificates.
As part of virtualized-environment architecture, a bare-metal or native virtualization hypervisor operates without:
Aany applications on the guest operating system.
Ba guest operating system.
Cany applications on the host operating system.
Da host operating system.
QuestionQ6
Governance and Management of IT
0
Community Discussion
No comments yet. Be the first to start the discussion!
QuestionQ7
Protection of Information Assets
QuestionQ8
Protection of Information Assets
QuestionQ9
Governance and Management of IT
QuestionQ10
Information Systems Acquisition, Development and Implementation
QuestionQ11
Governance and Management of IT
QuestionQ12
Information Systems Operations and Business Resilience
QuestionQ13
Information Systems Acquisition, Development and Implementation
QuestionQ14
Protection of Information Assets
QuestionQ15
Governance and Management of IT
QuestionQ16
Information System Auditing Process
QuestionQ17
Information System Auditing Process
QuestionQ18
Protection of Information Assets
QuestionQ19
Information Systems Operations and Business Resilience
QuestionQ20
Information Systems Operations and Business Resilience
QuestionQ21
Protection of Information Assets
QuestionQ22
Information Systems Operations and Business Resilience
QuestionQ23
Protection of Information Assets
QuestionQ24
Protection of Information Assets
QuestionQ25
Information Systems Operations and Business Resilience
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Ad
Want a break from the ads?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
When determining whether an organization's IT performance measures are comparable with those of other organizations in the same industry, which of the following would be MOST helpful to review?
ABalanced scorecard
BIT governance frameworks
CBenchmarking surveys
DUtilization reports
If it is enabled in firewall rules, which of the following services poses the GREATEST risk?
AFile transfer protocol (FTP)
BSimple object access protocol (SOAP)
CHypertext transfer protocol (HTTP)
DSimple mail transfer protocol (SMTP)
Which of the following BEST enables an organization to identify potential security threats related to a virtualization technique proposed by the vendor of a widely used virtual machine (VM) system?
AArchitecture design
BFunctional specifications
CRisk assessment
DHypervisor logs
Who is accountable for ensuring that the major stakeholders involved in a project are represented?
AChange control board
BSteering committee
CProject management office (PMO)
DProject manager
A request for proposal (RFP) to acquire computer hardware should include:
Asupport and maintenance requirements.
Bdetailed specification of the current hardware infrastructure.
Cthe requirement that the supplier allow a right of audit.
Dmaximum cost restriction
An organization’s information security policies should be developed primarily based on:
Aindustry best practices.
Benterprise architecture (EA).
Ca risk management process.
Dpast information security incidents.
Which of the following BEST allows an organization to quantify acceptable data loss if a disaster occurs?
ARecovery time objective (RTO)
BRecovery point objective (RPO)
CAvailability of backup software
DMean time to recover (MTTR)
An organization is prepared to implement a new IT solution that consists of multiple modules. The final module updates the processed data in the database. Which of the following findings should be of MOST concern to the IS auditor?
AAbsence of a formal change approval process
BLack of input validation
CLack of a data dictionary
DUse of weak encryption
Which option is the BEST way to ensure that an organization’s data-classification policies remain intact throughout data transformation?
AConduct a data discovery exercise across all business applications.
BControl access to extract, transform, and load (ETL) tools.
CImplement classification labels in metadata during data creation.
DMap data classification controls to data sets.
Which of the following is the BEST criterion for monitoring an IT vendor’s service levels?
APerformance metrics
BSurprise visit to vendor
CService auditor’s report
DInterview with vendor
After completing audit work, an IS auditor should:
Aprovide a report to the auditee stating the initial findings.
Bprovide a report to senior management prior to discussion with the auditee.
Cdistribute a summary of general findings to the members of the auditing team.
Dreview the working papers with the auditee.
While performing fieldwork, an internal IS auditor identifies a critical vulnerability in a newly deployed application. What is the auditor's BEST action?
ADocument the finding in the report.
BIdentify other potential vulnerabilities.
CNotify IT management.
DReport the finding to the external auditors.
Which of the following is the BEST recommendation for mitigating the risk associated with remote access via the hypervisor interface?
APresentation-layer and application-layer controls
BEnterprise security policies and controls
CSecure configuration of guest systems
DNetwork-layer and transport-layer controls
What should be an IS auditor’s PRIMARY focus when auditing implementation of a new IT operations performance-monitoring system?
AValidating whether baselines have been established
BReviewing whether all changes have been implemented
CDetermining whether there is a process for annual review of the maintenance manual
DConfirming whether multi-factor authentication (MFA) is deployed as part of the operational enhancements
An organization wants to manage storage-media costs across the information life cycle while continuing to satisfy business and regulatory requirements.
Which of the following is the BEST way to accomplish this objective?
APerform periodic tape backups.
BUtilize solid state memory.
CStream backups to the cloud.
DImplement a data retention policy
An organization has implemented hiring policies and procedures specifically intended to ensure that network administrators are appropriately qualified. Which type of control is in place?
ADirective
BDetective
CCompensating
DCorrective
An IS audit manager is reviewing the workpapers for a recently completed audit of the corporate disaster recovery test. Which item should the IS audit manager specifically examine to substantiate the conclusions?
AOverviews of interviews between data center personnel and the auditor
CDetailed evidence of the successes and weaknesses of all contingency testing
DPrior audit reports involving other corporate disaster recovery audits
Which finding from a database security audit poses the GREATEST risk of critical security exposure?
ADefault settings have not been changed.
BAdmin account passwords are not set to expire.
CLegacy data has not been purged.
DDatabase activity logging is not complete.
Spreadsheets are used to calculate project cost estimates. The totals for each cost category are then entered into the job-costing system. What is the BEST control to ensure that data is entered into the system accurately?
ADisplay back of project detail after entry
BReconciliation of total amounts by project
CReasonableness checks for each cost type
DValidity checks, preventing entry of character data
What is the BEST approach for identifying unforeseen risks that could affect IT processes?
AReview metrics and historical incident response reports.
BPerform application control self-assessments (CSAs).
Community Discussion