Topic 6: Exam Pool (Jul-Aug)
A retailer normally uses a scanner to read product labels and input product codes and prices. The unit is not functioning and staff are keying information manually. With respect to the accuracy of the input, it is likely that:
A.
audit risk has increased.
B.
control risk has increased.
C.
inherent risk has decreased.
D.
detection risk has decreased.
control risk has increased.
An IS auditor is evaluating the access controls at a multinational company with a shared network
infrastructure. Which of the following is MOST important?
A.
Simplicity of end-to-end communication paths
B.
Common security policies
C.
Remote network administration
D.
Logging of network information at user level
Common security policies
Which of the following should be the PRIMARY basis for planning and prioritizing IT infrastructure security audits?
A.
Asset value to the organization
B.
Management requests
C.
The organization's risk appetite
D.
Security best practice
Asset value to the organization
Which of the following is the MAIN purpose of implementing an incident response process?
A.
Assign roles and responsibilities
B.
Comply with policies and procedures.
C.
Provide substantial audit-trail evidence.
D.
Manage impact due to breaches.
Manage impact due to breaches.
Which of the following threats is MOST effectively controlled by a firewall?
A.
Network congestion
B.
Denial of service (DoS) attack
C.
Network sniffing
D.
Password cracking
Denial of service (DoS) attack
An organization has recently acquired and implemented intelligent-agent software for granting loans to
customers. During the post implementation review, which of the following would be the KEY procedure for
the IS auditor to perform?
A.
Review system documentation to ensure completeness.
B.
Ensure that a detection system designed to verify transaction accuracy is included.
C.
Review input and output control reports to verify the accuracy of the system decisions.
D.
Review signed approvals to ensure responsibilities for decisions of the system are welldefined.
Review input and output control reports to verify the accuracy of the system decisions.
A multinational organization is integrating its existing payroll system with a human resource information
system. Which of the following should be of GREATEST concern to the IS auditor?
A.
Application interfaces
B.
Scope creep
C.
System documentation
D.
Currency conversion
Application interfaces
An IS auditor previously worked in an organization s IT department and was involved with the design of the
business continuity plan (BCP). The IS
auditor has now been asked to review this same BCP. The auditor should FIRST.
A.
document the conflict in the audit report.
B.
decline the audit assignment.
C.
communicate the conflict of interest to the audit manager prior to starting the assignment.
D.
communicate the conflict ofinterest to the audit committee prior to starting the assignment
communicate the conflict ofinterest to the audit committee prior to starting the assignment
Which of the following tools is MOST helpful in estimating budgets for tasks within a large IT business
application project?
A.
Ganttchart
B.
Balanced scorecard
C.
Critical path methodology (CPM)
D.
Function point analysis (FPA)
Function point analysis (FPA)
To preserve chain-of-custody following an internal server compromise, which of the following should be the
FIRST step?
A.
Trace the attacking route.
B.
Replicate the attack using the remaining evidence.
C.
Take a system image including memory dump.
D.
Safely shut down the server.
Take a system image including memory dump.
The drives of a tile server are backed up at a hot site. Which of the following is the BEST way to duplicate the
files stored on the server for forensic analysis?
A.
Capture a bit-by-bit image of the file server's drives.
B.
Run forensic analysis software on the backup drive.
C.
Create a logical copy of the file server’s drives.
D.
Replicate the server's volatile data to another drive.
D18912E1457D5D1DDCBD40AB3BF70D5D
Capture a bit-by-bit image of the file server's drives.
When removing a financial application system from production, which of the following is MOST important?
D18912E1457D5D1DDCBD40AB3BF70D5D
A.
Media used by the retired system has been sanitized.
B.
Data retained for regulatory purposes can be retrieved.
C.
End-user requests for changes are recorded and tracked.
D.
Software license agreements are retained.
Media used by the retired system has been sanitized.
| Page 45 out of 113 Pages |
| 28293031323334353637383940414243444546474849505152535455565758596061 |
| CISA Practice Test Home |
Real-World Scenario Mastery: Our CISA practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.
Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before exam day arrives.
Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive CISA practice exam questions pool covering all topics, the real exam feels like just another practice session.