Topic 6: Exam Pool (Jul-Aug)
To ensure efficient and economic use of limited resources in supporting a local area network (LAN)
infrastructure, it is advisable to:
A.
periodically rotate vendors to obtain the best price-to-performance ratio
B.
standardize on a limited number of device models and software applications.
C.
quickly upgrade to the latest hardware and software versions to take advantage of new features
D.
recommend a variety of products so that user effectiveness and flexibility can be maximized.
standardize on a limited number of device models and software applications.
Which of the following reports can MOST effectively be used to analyze a systems performance problem?
A.
Database usage log
B.
Synchronization report
C.
Console log
D.
Utilization report
Console log
Which of the following has the GREATEST influence on the success of IT governance?
A.
Alignment of IT strategies with the entity's vision
B.
Clear, concise, and enforced IS policies
C.
The CIO is a member of the audit committee
D.
IT strategy is embedded in all risk management processes
Alignment of IT strategies with the entity's vision
Two servers are deployed in a cluster to run a mission-critical application. To determine whether the system
has been designed for optimal efficiency, the IS auditor should verify that:
A.
the security features in the operating system are all enabled
B.
the number of disks in the cluster meets minimum requirements
C.
the two servers are of exactly the same configuration
D.
load balancing between the servers has been implemented
load balancing between the servers has been implemented
In an IS auditor's review of an organization s configuration management practices for software, which of the
following is MOST important?
A.
Post-implementation review reports from development efforts
B.
Service level agreements (SLAs) between the IT function and users
C.
Organizational policies related to release management
D.
Software rental contracts or lease agreements
Organizational policies related to release management
What is the BEST way for an IS auditor to address the risk associated with over-retention of personal data
after identifying a large number of customer records retained beyond the retention period defined by law?
A.
Recommend automatic deletion of records beyond the retention period
B.
Schedule regular internal audits to identify records for deletion
C.
Report the retention period noncompliance to the regulatory authority
D.
Escalate the over-retention issue to the data privacy officer for follow up
Recommend automatic deletion of records beyond the retention period
A new regulation requires organizations to report significant security incidents to the regulator within 24 hours
of identification. Which of the
following is the IS auditor s BEST recommendation to facilitate compliance with the regulation?
A.
Enhance the alert functionality of the intrusion detection system (IDS).
B.
Establish key performance indicators (KPIs) for timely identification of security incidents.
C.
Include the requirement in the incident management response plan.
D.
Engage an external security incident response expert for incident handling.
Include the requirement in the incident management response plan.
The BEST reason for implementing a virtual private network (VPN) is that it:
A.
eases the implementation of data encryption.
B.
allows for public use of private networks.
C.
enables use of existing hardware platforms.
D.
allows for private use of public networks.
allows for private use of public networks.
An IS auditor is planning an audit of an organization s payroll processes. Which of the following is the BEST
procedure to provide assurance
against internal fraud?
A.
Compare employee work contracts against hours entered in the payroll system.
B.
Interview the payroll manager to obtain a detailed process workflow.
C.
Review management's approval of payroll system changes.
D.
Review management's validation of payroll payment recipients.
Compare employee work contracts against hours entered in the payroll system.
Which of the following IS audit findings should be of GREATEST concern when preparing to migrate to a
new core system using a direct cut-over?
A.
informal management approval to 90 live
B.
Lack of a rollback strategy for the system go-live
C.
Plans to use some workarounds for an extended period after go-live
D.
incomplete test cases for some critical reports
Lack of a rollback strategy for the system go-live
Which of the following is an effective way to ensure the integrity of file transfers in a peer-to-peer (P2P)
computing environment?
A.
Connect the client computers in the environment to a jump server.
B.
Ensure the files transferred through an intrusion detection system (IDS).
C.
Encrypt the packets shared between peers within the environment.
D.
Associate a message authentication code with each file transferred.
Encrypt the packets shared between peers within the environment.
Which of the following should be of MOST concern to an IS auditor evaluating a forensics program?
A.
Forensic images are stored on removable media with encryption.
B.
Forensic images are only stored for involuntarily terminated employees.
C.
Forensic images are only maintained for 12 months.
D.
Forensic images are stored on shared disks.
Forensic images are stored on shared disks.
| Page 49 out of 113 Pages |
| 32333435363738394041424344454647484950515253545556575859606162636465 |
| CISA Practice Test Home |
Real-World Scenario Mastery: Our CISA practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.
Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before exam day arrives.
Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive CISA practice exam questions pool covering all topics, the real exam feels like just another practice session.