Topic 6: Exam Pool (Jul-Aug)
While following up on a prior audit report, an IS auditor determines that a number of recommendations to
address critical findings have not been implemented as agreed. What is the BEST course of action for the
auditor?
A.
Reclassify the risk ratings of the original findings.
B.
Propose revised implementation timelines.
C.
Escalate to the appropriate level of management.
D.
Revise the scope of the follow-up audit
Escalate to the appropriate level of management.
Which of the following projects would be MOST important to review in an audit of an organizations financial
statements?
A.
Automation of operational risk management processes
B.
Resource optimization of the enterprise resource planning (ERP) system
C.
Security enhancements to the customer relationship database
D.
Outsourcing of the payroll system to an external service provider
Outsourcing of the payroll system to an external service provider
An IS auditor finds that one employee has unauthorized access to confidential data. The IS auditor’s BEST
recommendation should be to:
A.
reclassify the data to a lower level of confidentiality.
B.
recommend corrective actions to be taken by the security administrator.
C.
implement a strong password schema for users
D.
require the business owner to conduct regular access reviews.
require the business owner to conduct regular access reviews.
Which of the following is the BEST indication that an information security program is effective?
A.
The number of reported and confirmed security incidents has increased after awareness training.
B.
The security awareness program was developed following industry best practices.
C.
The security team has performed a risk assessment to understand the organization’s risk appetite.
D.
The security team is knowledgeable and uses the best available tools.
The number of reported and confirmed security incidents has increased after awareness training.
An IS auditor is asked to review a large organization's change management process. Which of the following
practices presents the GREATEST risk?
A.
Change management tickets do not contain specific documentation.
B.
Emergency code changes are promoted without user acceptance testing.
C.
Transaction data changes can be made by a senior developer.
D.
A system administrator performs code migration on planned downtime.
A system administrator performs code migration on planned downtime.
A CIO has asked an IS to implement several security controls for an organization’s IT process and system. The
auditor should:
A.
Obtain approval from execute management for the implementation.
B.
Communicate the conflict of interest to audit management.
C.
Refuse due to independence issue
D.
Perform the assignment and future audits with the due professional care.
Communicate the conflict of interest to audit management.
A security regulation requires the disabling of direct administrator access. Such access must occur through an
intermediate server that holds administrator passwords for all systems d records all actions. An IS auditor s
PRIMARY concern with this solution would be that:
A.
it represents a single point of failure
B.
segregation of duties is not observed.
C.
it is not feasible to implement
D.
access logs may not be maintained
it represents a single point of failure
An organization has implemented a control to help ensure databases containing personal information will not
be updated with online transactions that are incomplete due to connectivity issues. Which of the following
information attributes is PRIMARILY addressed by this control?
A.
Availability
B.
Compliance
C.
Confidentiality
D.
integrity
integrity
When an intrusion into an organizations network is detected, which of the foflomng should be performed
FIRST?
A.
Identify nodes that have been compromised
B.
Block all compromised network nodes
C.
Develop a response to the incident
D.
Protect information in the compromised systems
Protect information in the compromised systems
select a sample for testing, which must include the 80 largest client balances and a random sample of the rest,
the IS auditor should recommend:
A.
use of generalized audit software.
B.
development of an integrated test facility (ITF).
C.
applying attribute sampling using software.
D.
sorting the file with a utility Release management
applying attribute sampling using software.
Which of the following activities should occur after a business impact analysis (BIA)?
A.
Identify threats to the IT environment
B.
Identify critical applications
C.
Analyze recovery options
D.
Review the computing and user environment
Analyze recovery options
An IS auditor is planning on utilizing attribute sampling to determine the error rate for health care claims
processed. Which of the following factors will cause the sample size to decrease?
A.
Tolerable error rate increase
B.
Acceptable risk level decrease
C.
Expected error rate increase
D.
Population size increase
Tolerable error rate increase
| Page 47 out of 113 Pages |
| 30313233343536373839404142434445464748495051525354555657585960616263 |
| CISA Practice Test Home |
Real-World Scenario Mastery: Our CISA practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.
Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before exam day arrives.
Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive CISA practice exam questions pool covering all topics, the real exam feels like just another practice session.