Topic 6: Exam Pool (Jul-Aug)
An IS auditor is assigned to review the development of a specific application. Which of the following would
be the MOST significant step following the feasibility study?
A.
Attend project progress meetings to monitor timely implementation of the application.
B.
Assist users in the design of proper acceptance-testing procedures.
C.
Follow up with project sponsor for project's budgets and actual costs.
D.
Review functional design to determine that appropriate controls are planned.
Review functional design to determine that appropriate controls are planned.
During a review of operations, it is noted that during a batch update, an error was detected and the database
initiated a roll-back. An IT operator stopped the roll-back and re-initiated the update. What should the operator
have done PRIOR to re-initiating the update?
A.
Determined the cause of the error
B.
Obtained approval before re-initiating the update
C.
Allowed the roll-back to complete
D.
Scheduled the roll-back for a later time
Allowed the roll-back to complete
An IS auditor attempts to sample for variables in a population of items with wide differences in values but
determines that an unreasonably large number of sample items must be selected to produce the desired
confidence level. In this situation, which of the following is the BEST audit decision?
D18912E1457D5D1DDCBD40AB3BF70D5D
A.
Allow more time and test the required sample
B.
Select a judgmental sample
C.
Select a stratified sample
D.
Lower the desired confidence level
Lower the desired confidence level
Which of the following is the GREATEST risk resulting from conducting periodic reviews of IT over several
years based on the same audit program?
A.
The amount of errors with increase because the routine work promotes r\attentiveness.
B.
Staff turnover in the audit department will increase because fieldwork becomes less interesting.
C.
Detection risk is increased because auditees already know the audit program.
D.
Audit risk is increased because the programs might not be adapted to the organization s current situation.
Audit risk is increased because the programs might not be adapted to the organization s current situation.
Which of the following would be of MOST concern when determining if information assets are adequately
safeguard during transport and disposal?
A.
Lack of password protection
B.
Lack of recent awareness training
C.
Lack of appropriate data classification
D.
Lack of appropriate labeling
Lack of appropriate data classification
Which of the following is the PRIMARY reason for an IS auditor to issue an interim audit report?
A.
To avoid issuing a final audit report
B.
To enable the auditor to complete the engagement in a timely manner
C.
To provide feedback to the auditee for timely remediation
D.
To provide follow-up opportunity during the audit
To provide feedback to the auditee for timely remediation
When physical destruction is not practical, which of the following is the MOST effective measure of disposing
of sensitive data on a hard disk?
A.
Deleting files sequentially
B.
Overwriting multiple times
C.
Recycling the disk
D.
Reformatting
Recycling the disk
Which of the following is the GREATEST advantage of implementing an IT enterprise architecture
framework within an organization?
A.
It reduces the overlap of infrastructure technologies within the organization.
B.
It better equips an organization to adopt innovative and emerging technologies.
C.
It helps to identify security issues in systems across the organization.
D.
It improves the organization's ability to meet service level agreements (SLAs).
It improves the organization's ability to meet service level agreements (SLAs).
Which of the following is the BEST way for an IS auditor to assess the effectiveness of backup procedures?
A.
Review the backup schedule.
B.
Evaluate the latest data restore.
C.
Inspect backup logs.
D.
Interview the data owner.
Evaluate the latest data restore.
An audit report that specifies responsibility for the closure of noncompliance issues is BEST enhanced by
including:
A.
cost estimates for remediation.
B.
a list of audit staff who will oversee remediation.
C.
detailed mitigating steps.
D.
target dates for remediation.
detailed mitigating steps.
An IS auditor is assessing an organization’s implementation of a virtual network. Which of the following
observations should be considered the
MOST significant risk?
A.
Communication performance over the virtual network is not monitored.
B.
Traffic over the virtual network is not visible to security protection devices.
C.
Physical and virtual network configurations are not managed by the same team.
D.
Virtual network devices are replicated and stored in offline mode.
Traffic over the virtual network is not visible to security protection devices.
An internal audit has revealed a large number of incidents for which root cause analysis has not been
performed. Which of the following is MOST
important for the IS auditor to verify to determine whether there is an audit issue?
A.
Cost of resolving the incidents
B.
Time required to resolve the incidents
C.
Seventy level of the incidents
D.
Frequency of the incidents
Seventy level of the incidents
| Page 52 out of 113 Pages |
| 35363738394041424344454647484950515253545556575859606162636465666768 |
| CISA Practice Test Home |
Real-World Scenario Mastery: Our CISA practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.
Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before exam day arrives.
Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive CISA practice exam questions pool covering all topics, the real exam feels like just another practice session.