Topic 6: Exam Pool (Jul-Aug)
Following an IT audit, management has decided to accept the risk highlighted in the audit report. Which of the
following would provide the MOST assurance to the IS auditor that management is adequately balancing the
needs of the business with the need to manage risk?
A.
Established criteria exist for accepting and approving risk.
B.
Identified risk is reported into the organization’s risk committee.
C.
Potential impact and likelihood is adequately documented.
D.
A communication plan exists for informing parties impacted by the risk.
Identified risk is reported into the organization’s risk committee.
An IS auditor concludes that a local area network (LAN) access security satisfactory. In reviewing the work,
the audit manager should
A.
Verify user management’s agreement with the findings
B.
Assess whether the auditor had the appropriate skills to perform the work
C.
Verify that the elements of an agreed upon audit plan have been addressed
D.
Re-perform some steps of the audit to verify the quality of the work
Verify that the elements of an agreed upon audit plan have been addressed
An organization is developing a web portal using some external components. Which of the following should
be of MOST concern to an IS auditor?
A.
Some of the developers are located in another country.
The organization has not reviewed the components for known exploits.
B.
Open-source components were integrated during development.
C.
Staff require additional training in order to perform cede review.
Open-source components were integrated during development.
What is the PRIMARY objective of implementing data classification?
A.
Establish appropriate encryption methods.
B.
Establish appropriate data protection methods.
C.
Employ data leakage prevention tools.
D.
Create awareness among users.
Establish appropriate data protection methods.
Which of the following is the BEST way to transmit documents classified as confidential over the Internet?
A.
Hashing the document contents and destroying the hash value
B.
Sending documents as multiple packets over different network routes
C.
Converting documents to proprietary format before transmission
D.
Using a virtual private network (VPN)
Using a virtual private network (VPN)
Which of the following would be considered a corrective control when designing the security of a data center?
A.
Security guards
B.
Perimeter fence
C.
Closed-circuit television (CCTV)
D.
Fire extinguisher
Fire extinguisher
An IS auditor has identified that some IT staff have administrative access to the enterprise resource planning
(ERP) application, database, and
server. IT management has responded that due to limited resources, the same IT staff members have to support
all three layers of the ERP
application. Which of the following would be the auditor's BEST recommendation to management?
A.
Monitor activities of the associated IT staff members by reviewing system-generated logs weekly.
B.
Request funding to hire additional IT staff to enable segregation of duties.
C.
Remove some of the administrative access of the associated IT staff members.
D.
Leverage business unit personnel to serve as administrators of the application.
Monitor activities of the associated IT staff members by reviewing system-generated logs weekly.
Inherent risk rating are determined by assessing the impact and likelihood of a threat or vulnerability
occurring:
A.
Before the risk appetite Is established
B.
After compensating have been applied
C.
After internal controls are taken into account.
D.
Before internal controls are taken into account.
Before internal controls are taken into account.
Which of the following would BEST help in classifying an organization s data?
A.
Analysis of existing data handling procedures
B.
Industry best practices for data classification
C.
Impact of data loss or disclosure
D.
Data retention requirements
Impact of data loss or disclosure
The MOST effective method for an IS auditor to determine which controls are functioning in an operating
system is to:
A.
Compare the current configuration to the corporate standard
B.
Consult with the vendor of the system
C.
Compare the current configuration to the default configuration
D.
Consult with the systems programmer
Compare the current configuration to the corporate standard
Which of the following is the GREATEST benefit of implementing an IT governance strategy within an
organization?
A.
IT projects are delivered on time and under budget
B.
Management is aware of IT-related risks.
C.
Employees understand roles and responsibilities
D.
Reporting and metrics become higher priority.
IT projects are delivered on time and under budget
Which of the following controls BEST ensures appropriate segregation of duties within an accounts payable department?
A.
Ensuring that audit trails exist for transactions
B.
Restricting access to update programs to accounts payable staff only
C.
Restricting program functionality according to user security profiles
D.
Including the creator’s user ID as a field in every transaction record created
Ensuring that audit trails exist for transactions
| Page 46 out of 113 Pages |
| 29303132333435363738394041424344454647484950515253545556575859606162 |
| CISA Practice Test Home |
Real-World Scenario Mastery: Our CISA practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.
Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before exam day arrives.
Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive CISA practice exam questions pool covering all topics, the real exam feels like just another practice session.