Topic 6: Exam Pool (Jul-Aug)
Which of the following is the BEST way to mitigate the impact of ransomware attacks?
A.
Backing up data frequently
B.
Invoking the disaster recovery plan (DRP)
C.
Requiring password changes for administrative accounts
D.
Paying the ransom
Requiring password changes for administrative accounts
Which of the following tools are MOST helpful for benchmarking an existing IT capability?
A.
IT balanced scorecards
B.
Risk assessments
C.
IT matunty models
D.
Prior IS audit reports
IT matunty models
In the review of a feasibility study for an IS acquisition, the MOST important step is to:
A.
determine whether the cost-benefits are achievable.
B.
ensure that a contingency plan is in place should the project fail.
C.
ensure that the right to audit the vendor has been considered.
D.
determine whether security and control requirements have been specified.
ensure that the right to audit the vendor has been considered.
An IS auditor is reviewing standards and compliance requirements related to an upcoming systems audit. The
auditor notes that the industry
standards are less stringent than local regulatory standards. How should the auditor proceed?
A.
Audit to the policies and procedures of the organization.
B.
Coordinate with regulatory officers to determine necessary requirements.
C.
Audit exclusively to the industry standards.
D.
Audit to the standards with the highest requirements.
Audit to the standards with the highest requirements.
The IS security group is planning to implement single sign-on. What is the IS auditor's PRIMARY concern?
A.
Integrated access rules will increase users’ access privileges.
B.
Integrated access rules will restrict users' access privileges.
C.
Managing user IDs/passwords will require increased efforts.
D.
Compromise of a use' !D/password will yield more privileges
Compromise of a use' !D/password will yield more privileges
During an audit of the organization's data privacy policy, the IS auditor identified that only some IT
application databases have encryption in place. What should be the auditors FIRST action?
A.
Assess the resources required to implement encryption to unencrypted databases.
B.
Review the most recent database penetration testing results.
C.
Determine whether compensating controls are in place
D.
Review a comprehensive list of databases with the information they contain.
Review a comprehensive list of databases with the information they contain.
In which of the following cloud service models does the user organization have the GREATEST control over
the accuracy of configuration items in
its configuration management database (CMDB)?
A.
Software as a Service (SaaS)
B.
Database as a Service (DbaaS)
C.
Infrastructure as a Service (laaS)
D.
Platform as a Service (PaaS)
Infrastructure as a Service (laaS)
Reviewing project plans and status reports throughout the development life cycle will:
A.
facilitate the optimal use of resources over the life of the project.
B.
eliminate the need to perform a risk assessment.
C.
postpone documenting the project's progress until the final phase.
D.
guarantee that the project will meet its intended deliverables.
guarantee that the project will meet its intended deliverables.
Which of the following IT processes is likely to have the GREATEST inherent regulatory risk?
A.
IT project management
B.
Data management
C.
Capacity management
D.
IT resource management
Data management
Which of the following activities provides an IS auditor with the MOST insight regarding potential single
person
dependencies that might exist withing the organization?
A.
Reviewing user activity logs
B.
Mapping IT processes to roles
C.
Reviewing vacation patterns
D.
Interviewing senior IT management
Mapping IT processes to roles
Which of the following is a distinguishing feature at the highest level of a maturity model?
D18912E1457D5D1DDCBD40AB3BF70D5D
A.
There are formal standards and procedures.
B.
Projects are controlled with management supervision.
C.
A continuous improvement process is applied.
D.
Processes are monitored continuously.
A continuous improvement process is applied.
An audit report notes that terminated employees have been retaining their access rights after their departure.
Which of the following strategies would BEST ensure that obsolete access rights are identified in a timely manner?
A.
Delete user IDs at a predetermined date after their creation.
B.
Automatically delete user IDs after they are unused for a predetermined time.
C.
Implement an automated interface with the organization’s human resources system.
D.
Require local supervisors to initiate connection.
Implement an automated interface with the organization’s human resources system.
| Page 44 out of 113 Pages |
| 27282930313233343536373839404142434445464748495051525354555657585960 |
| CISA Practice Test Home |
Real-World Scenario Mastery: Our CISA practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.
Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before exam day arrives.
Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive CISA practice exam questions pool covering all topics, the real exam feels like just another practice session.