Topic 6: Exam Pool (Jul-Aug)
At which stage of the software development life cycle should an organization identity privacy considerations?
A.
Design
B.
Testing
C.
Development
D.
Requirements
Requirements
To mitigate the risk of exposing data through application programming interface (API) queries, which of the following design considerations is MOST important?
A.
Data minimalization
B.
Data quality
C.
Data retention
D.
Data integrity
Data integrity
An IS auditor discovered abnormalities in a monthly report generated from a system upgraded six months ago. Which of the following should be the auditor's FIRST course of action?
A.
Inspect source code for proof of abnormalities.
B.
Schedule an access review of the system.
C.
Perform a change management review of the system
D.
Determine the impact of abnormalities in the report
Determine the impact of abnormalities in the report
Which of the following helps to ensure the integrity of data for an interface between a new billing system and
an accounts receivable system?
A.
Data files are encrypted during transmission.
B.
Access to the data requires authentication.
C.
Audit logs are available for 30 days.
D.
Control totals are calculated.
Data files are encrypted during transmission.
An IS auditor found that a company executive is encouraging employee use of social networking sites for
business purposes. Which of the following recommendations would BEST help to reduce the risk of data
leakage?
A.
Providing education and guidelines to employees on use of social networking sites
B.
Requiring policy acknowledgment and nondisclosure agreements signed by employees
C.
Establishing strong access controls on confidential data
D.
Monitoring employees social networking usage
Establishing strong access controls on confidential data
A change to the scope of an IT project has been formally submitted to the project manager. What should the
project manager do NEXT?
A.
Update the project plan to reflect the change in scope
B.
Discuss the change with the project team and determine if it should be approved
C.
Escalate the change to the change advisory board for approval
D.
Determine how the change will affect the schedule and budget
Determine how the change will affect the schedule and budget
An IS auditor is reviewing the results of a business process improvement project. Which of the following should be performed FIRST?
A.
Evaluate control gaps between the old and the new processes.
B.
Develop compensating controls
C.
Document the impact of control weaknesses in the process.
D.
Ensure that lessons learned during the change process are documented
Evaluate control gaps between the old and the new processes.
An audit of the quality management system (QMS) begins with an evaluation of the:
A.
organization’s QMS policy
B.
sequence and interaction of QMS processes
C.
QMS processes and their application
D.
QMS document control procedures
organization’s QMS policy
Which of the following is MOST important for the successful establishment of a security vulnerability
management program?
A.
A comprehensive asset inventory
B.
A tested incident response plan
C.
An approved patching policy
D.
A robust tabletop exercise plan
An approved patching policy
The BEST data backup strategy for mobile users is to:
A.
have them regularly back up data directories onto CD and courier the backups to the head office.
B.
synchronize data directories automatically over the network.
C.
mirror all data to a portable storage device.
D.
have them regularly go to branch offices to perform backups.
synchronize data directories automatically over the network.
Which of the following is the BEST indication that an organization’s vulnerability identification capability has
achieved a high level of maturity?
A.
The organization collaborates with relevant partners to correlate vulnerability data.
B.
Known application vulnerabilities are manually categorized and prioritized.
C.
Vulnerability management tools are tailored for specific operating systems.
D.
Tools are in place to periodically identity new and updated vulnerabilities.
Vulnerability management tools are tailored for specific operating systems.
While reviewing similar issues in an organization s help desk system, an IS auditor finds that they were analyzed independently and resolved differently This situation MOST likely indicates a deficiency in:
A.
problem management
B.
IT service level management
C.
change management
D.
configuration management
problem management
| Page 42 out of 113 Pages |
| 25262728293031323334353637383940414243444546474849505152535455565758 |
| CISA Practice Test Home |
Real-World Scenario Mastery: Our CISA practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.
Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before exam day arrives.
Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive CISA practice exam questions pool covering all topics, the real exam feels like just another practice session.