Topic 6: Exam Pool (Jul-Aug)
Which of the following methods should be used to effectively erase sensitive data from portable storage
devices that are to be reused?
A.
Using media sanitization software
B.
Exposing the portable device to a magnetic field
C.
Formatting the portable device
D.
Overwriting the sensitive data
Exposing the portable device to a magnetic field
Which of the following is the BEST indication that an organization has achieved legal and regulatory
compliance?
A.
The board of directors and senior management accept responsibility for compliance.
B.
An independent consultant has been appointed to ensure legal and regulatory compliance.
C.
Periodic external and internal audits have not identified instances of noncompliance.
D.
The risk management process incorporates noncompliance as a risk.
Periodic external and internal audits have not identified instances of noncompliance.
The purpose of data migration testing is to validate data:
A.
retention.
B.
completeness.
C.
availability.
D.
confidentiality.
completeness.
Which of the following controls BEST mitigates the impact of a distributed denial of service (DDoS) attack
against the controller in a softwaredefined network (SDN)?
A.
Relocating virtualized network functions to physical infrastructure
B.
Hardening the operating system that hosts the SDN controller
C.
Implementing multiple physical SDN controllers
D.
Implementing configuration management for SDN controllers
Hardening the operating system that hosts the SDN controller
Which of the following test approaches would utilize data analytics to test a dual approval payment control?
A.
Review payments completed in the past month that do not have a unique approver.
B.
Attempt to complete a payment without a secondary approval.
C.
Review users within the payment application who are assigned an approver role.
D.
Evaluate configuration settings for the secondary approval requirements.
Attempt to complete a payment without a secondary approval.
A maturity model can be used to aid the implementation of IT governance by identifying:
A.
improvement opportunities.
B.
accountabilities.
C.
performance drivers.
D.
critical success factors.
improvement opportunities.
An IS auditor is performing a routine procedure to test for the possible existence of fraudulent transactions.
Given there is no reason to suspect the existence of fraudulent transactions, which of the following data
analytics techniques should be employed?
A.
Association analysis
B.
Classification analysis
C.
Anomaly detection analysis
D.
Regression analysis
Anomaly detection analysis
When developing metrics to measure the contribution of IT to the achievement of business goals, the MOST
A.
are used by similar industries to measure the effect of IT on business strategy.
B.
measure the effectiveness of IT controls in the achievement of IT strategy.
C.
provide quantitative measurement of IT initiatives in relation with business targets,
D.
are expressed in terms of how IT risk impacts the achievement of business goals.
provide quantitative measurement of IT initiatives in relation with business targets,
An IT service desk has recorded several incidents related to server downtime following the failure of a
network time protocol (NTP) server. Which of the following is the BEST methodology to help identify the
root cause?
A.
Crow-functional diagram
B.
Data flow diagram
C.
Server architecture diagram
D.
Cause-and-effect diagram
Cause-and-effect diagram
Which of the following is an indication of possible hacker activity involving voice communications?
A.
A significant percentage of lines are busy during early morning and late afternoon hours.
B.
Outbound calls are found to significantly increase in frequency during non-business hours.
C.
Direct inward system access (OISA) is found to be disabled on the company's exchange.
D.
Inbound calls experience significant fluctuations based on time-of-day and day-of-week.
A significant percentage of lines are busy during early morning and late afternoon hours.
An audit group is conducting a risk assessment as part of a risk-based audit strategy. To help ensure the risk
assessment results are relevant to the organization, it is MOST important to:
A.
include operational departments and processes.
B.
determine both the inherent risk and detection risk.
C.
understand the organization's controls.
D.
understand the organization's objectives and risk appetite.
understand the organization's objectives and risk appetite.
Which of the following is the MOST significant obstacle to establishing a new privacy program?
A.
A complex legal and regulatory landscape
B.
Unresolved overlap of security and privacy roles and responsibilities
C.
Failure to perform a business impact analysis (BIA)
D.
An insufficient privacy awareness training program
A complex legal and regulatory landscape
| Page 53 out of 113 Pages |
| 36373839404142434445464748495051525354555657585960616263646566676869 |
| CISA Practice Test Home |
Real-World Scenario Mastery: Our CISA practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.
Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before exam day arrives.
Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive CISA practice exam questions pool covering all topics, the real exam feels like just another practice session.