Topic 1: Exam Pool A
Which of the following would represent an acceptable test of an organization s business continuity plan?
A.
Full test of computer operations at an emergency site
B.
Paper test involving functional areas
C.
Benchmarking the plan against similar organizations
D.
Walk-through of the plan with technology suppliers
Full test of computer operations at an emergency site
Which of the following is a key success factor for implementing IT governance?
A.
Establishing an IT governance committee
B.
Delivering IT projects within budget
C.
Embedding quality assurance processes
D.
Aligning IT and business strategies
Aligning IT and business strategies
Which of the following could an IS auditor recommend to improve the estimated resources required in system development?
A.
Prototyping
B.
Function point analysis
C.
Business areas involvement
D.
CASE tools
CASE tools
Which of the following is corrective control?
A.
Separating equipment development testing and production
B.
Reviewing user access rights for segregation of duties
C.
Verifying duplicate calculations in data processing
D.
Executing emergency response plans
Executing emergency response plans
Reviewing which of the following would be MOST helpful in assessing whether an organization s IT performance measures are comparable to other organizations in the same industry?
A.
Maturity models for IT processes
B.
Employee satisfaction surveys
C.
Key performance indicators (KPIs) for IT processes
D.
Reputable IT governance frameworks
Key performance indicators (KPIs) for IT processes
Which of the following would be the MOST effective method to address software license violations on employee workstations?
A.
Implementing real-time monitoring software on employee workstations
B.
Restricting administrative rights on employee workstations
C.
Scanning of workstation daily for unauthorized software use
D.
Required automated installation of software.
Implementing real-time monitoring software on employee workstations
The maturity level of an organization s problem management support function is optimized when the function
A.
has formally documented the escalation process.
B.
proactively provides solutions
C.
resolves requests in a timely manner
D.
analyzes critical incidents to identify root cause
proactively provides solutions
Which of the following is MOST likely to be prevented by a firewall connected to the Internet?
A.
Disclosure of public key infrastructure (PKI) keys
B.
Alteration of email message content
C.
Dial-m penetration attacks
D.
External spoofing of internal addresses
External spoofing of internal addresses
An IS auditor has assessed a payroll service provider’s security policy and finds significant topics are missing. Which of the following is the auditor’s BEST course of action?
A.
Recommend the service provider update their policy
B.
Report the risk to internal management
C.
Notify the service provider of the discrepancies.
D.
Recommend replacement of the service provider
Report the risk to internal management
The FIRST step in establishing a firewall security policy is to determine the:
A.
expected data Throughput.
B.
business requirements,
C.
existing firewall configuration,
D.
necessary logical access rights
business requirements,
An organization is in the process of deciding whether to allow a bring your own device (BYOD) program. If approved, which of the following should be the FIRST control required before implementation?
A.
An accept able use policy
B.
Device registration
C.
Device baseline configurations
D.
An awareness program
An accept able use policy
Which of the following group is MOST likely responsible for the implementation of IT projects?
A.
IT steering committee
B.
IT strategy committee
C.
IT compliance committee
D.
IT governance committee
IT steering committee
| Page 1 out of 85 Pages |
| 1234567891011121314151617181920212223242526 |
Real-World Scenario Mastery: Our CISA practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.
Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before exam day arrives.
Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive CISA practice exam questions pool covering all topics, the real exam feels like just another practice session.