• ¿Documento equivocado? Cámbialo gratis
  • Escrito por estudiantes que aprobaron
  • Inmediatamente disponible después del pago
  • Leer en línea o como PDF
Vender
¿Dónde estudias?
Tu idioma
Document preview thumbnail
Vista previa 4 fuera de 48 páginas
Examen

Comprehensive CISA Exam Test Bank with Verified Questions and Answers A+

Document preview thumbnail
Vista previa 4 fuera de 48 páginas

Comprehensive CISA Exam Test Bank with Verified Questions and Answers A+ 1. When auditing the IT governance framework and IT risk management practices that exist within an organization, the IS auditor identified some undefined responsibilities regarding IT management and governance roles. Which of the following recommendations is the MOST appropriate? - ANSWER Implement accountability rules within the organization 2. An IS auditor reviewing an outsourcing contract of IT facilities expects it to define the: - ANSWER ownership of intellectual property. 3. There is a concern that the risk of unauthorized access may increase after implementing a single sign-on process. To prevent unauthorized access, the MOST important action is to: - ANSWER mandate a strong password policy. 4. Which of the following will MOST successfully identify overlapping key controls in business application systems? - ANSWER Replacing manual monitoring with an automated auditing solution 5. An IS auditor reviewing database controls discovered that changes to the database during normal working hours were handled through a standard set of procedures. However, changes made after normal hours required only an abbreviated number of steps. In this situation, which of the following would be considered an adequate set of compensating controls? - ANSWER Use the DBA user account to make changes, log the changes and review the change log the following day. 6. Which of the following is the most important element in the design of a data warehouse? - ANSWER Quality of the metadata 7. Which of the following procedures would MOST effectively detect the loading of illegal software packages onto a network? - ANSWER Periodic checking of hard drives 8. The PRIMARY benefit of implementing a security program as part of a security governance framework is the: - ANSWER enforcement of the management of security risk. 9. To aid management in achieving IT and business alignment, an IS auditor should recommend the use of: - ANSWER an IT balanced scorecard. 10. The MOST serious challenge in the operation of an intrusion detection system is: - ANSWER filtering false positive alerts 11. IT management has decided to install a level 1 Redundant Array of Inexpensive Disks (RAID) system in all servers to compensate for the elimination of offsite backups. The IS auditor should recommend: - ANSWER reinstating the offsite backups. 12. An IS auditor is conducting a compliance test to determine whether controls support management policies and procedures. The test will assist the IS auditor to determine: - ANSWER that the control is operating as designed 13. An IS auditor wants to determine the number of purchase orders not appropriately approved. Which of the following sampling techniques should an IS auditor use to draw such conclusions? - ANSWER attribute 14. The objective of concurrency control in a database system is to: Select an answer: A. restrict updating of the database to authorized users. B. prevent integrity problems when two processes attempt to update the same data at the same time. C. prevent inadvertent or unauthorized disclosure of data in the database. D. ensure the accuracy, completeness and consistency of data. - ANSWER B. prevent integrity problems when two processes attempt to update the same data at the same time. 15. Which of the following security measures BEST ensures the integrity of information stored in a data warehouse? - ANSWER a read-only restriction 16. An organization has just completed its annual risk assessment. Regarding the business continuity plan, what should an IS auditor recommend as the next step for the organization? - ANSWER Review and evaluate the business continuity plan for adequacy 17. An IS auditor discovers that devices connected to the network are not included in a network diagram that had been used to develop the scope of the audit. The chief information officer explains that the diagram is being updated and awaiting final approval. The IS auditor should FIRST: - ANSWER evaluate the impact of the undocumented devices on the audit scope. 18. When auditing the archiving process of emails, the IS auditor should pay the MOST attention to: - ANSWER the existence of a data retention policy. 19. During an audit of an enterprise that is dedicated to e-commerce, the IS manager states that digital signatures are used when receiving communications from customers. To substantiate this, an IS auditor must prove that which of the following is used? - ANSWER A hash of the data that is transmitted and encrypted with the customer's private key 20. A consulting firm has created a File Transfer Protocol (FTP) site for the purpose of receiving financial data and has communicated the site's address, user ID and password to the financial services company in separate email messages. The company is to transmit its data to the FTP site after manually encrypting the data. The IS auditor's GREATEST concern with this process is that: - ANSWER the users may not remember to manually encrypt the data before transmission. 21. Which of the following choices would be the BEST source of information when developing a risk-based audit plan? - ANSWER Senior management identify key business processes. 22. An IS auditor performing a review of application controls would evaluate the: - ANSWER impact of any exposures discovered. 23. An IS auditor is reviewing Secure Sockets Layer enabled web sites for the company. Which of the following choices would be the HIGHEST risk? - ANSWER Self-signed digital certificates 24. A large chain of shops with electronic funds transfer at point-of-sale devices has a central communications processor for connecting to the banking network. Which of the following is the BEST disaster recovery plan for the communications processor? - ANSWER Alternative standby processor at another network node

Vista previa del contenido

1



Comprehensive CISA Exam Test Bank with
Verified Questions and Answers A+
1. When auditing the IT governance framework and IT risk management
practices that exist within an organization, the IS auditor identified some
undefined responsibilities regarding IT management and governance roles.
Which of the following recommendations is the MOST appropriate? -
ANSWER Implement accountability rules within the organization

2. An IS auditor reviewing an outsourcing contract of IT facilities expects it to
define the: - ANSWER ownership of intellectual property.

3. There is a concern that the risk of unauthorized access may increase after
implementing a single sign-on process. To prevent unauthorized access, the
MOST important action is to: - ANSWER mandate a strong password
policy.

4. Which of the following will MOST successfully identify overlapping key
controls in business application systems? - ANSWER Replacing manual
monitoring with an automated auditing solution

5. An IS auditor reviewing database controls discovered that changes to the
database during normal working hours were handled through a standard set
of procedures. However, changes made after normal hours required only an
abbreviated number of steps. In this situation, which of the following would
be considered an adequate set of compensating controls? - ANSWER Use
the DBA user account to make changes, log the changes and review the
change log the following day.

6. Which of the following is the most important element in the design of a data
warehouse? - ANSWER Quality of the metadata

7. Which of the following procedures would MOST effectively detect the
loading of illegal software packages onto a network? - ANSWER Periodic
checking of hard drives

, 2


8. The PRIMARY benefit of implementing a security program as part of a
security governance framework is the: - ANSWER enforcement of the
management of security risk.

9. To aid management in achieving IT and business alignment, an IS auditor
should recommend the use of: - ANSWER an IT balanced scorecard.

10.The MOST serious challenge in the operation of an intrusion detection
system is: - ANSWER filtering false positive alerts

11.IT management has decided to install a level 1 Redundant Array of
Inexpensive Disks (RAID) system in all servers to compensate for the
elimination of offsite backups. The IS auditor should recommend: -
ANSWER reinstating the offsite backups.

12.An IS auditor is conducting a compliance test to determine whether controls
support management policies and procedures. The test will assist the IS
auditor to determine: - ANSWER that the control is operating as designed

13.An IS auditor wants to determine the number of purchase orders not
appropriately approved. Which of the following sampling techniques should
an IS auditor use to draw such conclusions? - ANSWER attribute

14.The objective of concurrency control in a database system is to:
Select an answer:
A. restrict updating of the database to authorized users.
B. prevent integrity problems when two processes attempt to update the
same data at the same time.
C. prevent inadvertent or unauthorized disclosure of data in the database.
D. ensure the accuracy, completeness and consistency of data. -
ANSWER B. prevent integrity problems when two processes attempt
to update the same data at the same time.

15.Which of the following security measures BEST ensures the integrity of
information stored in a data warehouse? - ANSWER a read-only restriction

16.An organization has just completed its annual risk assessment. Regarding
the business continuity plan, what should an IS auditor recommend as the
next step for the organization? - ANSWER Review and evaluate the
business continuity plan for adequacy

, 3



17.An IS auditor discovers that devices connected to the network are not
included in a network diagram that had been used to develop the scope of
the audit. The chief information officer explains that the diagram is being
updated and awaiting final approval. The IS auditor should FIRST: -
ANSWER evaluate the impact of the undocumented devices on the audit
scope.

18.When auditing the archiving process of emails, the IS auditor should pay the
MOST attention to: - ANSWER the existence of a data retention policy.

19.During an audit of an enterprise that is dedicated to e-commerce, the IS
manager states that digital signatures are used when receiving
communications from customers. To substantiate this, an IS auditor must
prove that which of the following is used? - ANSWER A hash of the data
that is transmitted and encrypted with the customer's private key

20.A consulting firm has created a File Transfer Protocol (FTP) site for the
purpose of receiving financial data and has communicated the site's address,
user ID and password to the financial services company in separate email
messages. The company is to transmit its data to the FTP site after manually
encrypting the data. The IS auditor's GREATEST concern with this process
is that: - ANSWER the users may not remember to manually encrypt the
data before transmission.

21.Which of the following choices would be the BEST source of information
when developing a risk-based audit plan? - ANSWER Senior management
identify key business processes.

22.An IS auditor performing a review of application controls would evaluate
the: - ANSWER impact of any exposures discovered.

23.An IS auditor is reviewing Secure Sockets Layer enabled web sites for the
company. Which of the following choices would be the HIGHEST risk? -
ANSWER Self-signed digital certificates

24.A large chain of shops with electronic funds transfer at point-of-sale devices
has a central communications processor for connecting to the banking
network. Which of the following is the BEST disaster recovery plan for the

, 4


communications processor? - ANSWER Alternative standby processor at
another network node

25.Which of the following should an IS auditor review to understand project
progress in terms of time, budget and deliverables for early detection of
possible overruns and for projecting estimates at completion? - ANSWER
earned value analysis
(This is an industry standard method for measuring a project's progress at
any given point in time, forecasting its completion date and final cost, and
analyzing variances in the schedule and budget as the project proceeds. It
compares the planned amount of work with what has actually been
completed to determine if the cost, schedule and work accomplished are
progressing in accordance with the plan. EVA works most effectively if a
well-formed work breakdown structure exists.)

26.The MAIN purpose for periodically testing offsite disaster recovery facilities
is to: - ANSWER ensure the continued compatibility of the contingency
facilities.

27.The success of control self-assessment depends highly on: - ANSWER line
managers assuming a portion of the responsibility for control monitoring
(The primary objective of a control self-assessment (CSA) program is to
leverage the internal audit function by shifting some of the control
monitoring responsibilities to the functional area line managers. The success
of a CSA program depends on the degree to which line managers assume
responsibility for controls. This enables line managers to detect and respond
to control errors promptly.)

28.What is a risk associated with attempting to control physical access to
sensitive areas such as computer rooms using card keys or locks? -
ANSWER Unauthorized individuals wait for controlled doors to open and
walk in behind those authorized.

29.The vice president of human resources has requested an IS audit to identify
payroll overpayments for the previous year. Which would be the BEST audit
technique to use in this situation? - ANSWER Generalized audit software
(This features include mathematical computations, stratification, statistical
analysis, sequence checking, duplicate checking and re-computations. An IS
auditor, using generalized audit software, can design appropriate tests to

Información del documento

Subido en
23 de enero de 2026
Número de páginas
48
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas
$14.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Vendido
4
Seguidores
0
Artículos
222
Última venta
2 días hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes