CISA - EXAM 2 Questions and
Answers Updated 2026
Q1)MWhichMofMtheMfollowingMisMtheMMOSTMefficientMandMsufficientlyMreliableMwayMt
oMtestMtheMdesignMeffectivenessMofMaMchangeMcontrolMprocess?
A)MInterviewMpersonnelMinMchargeMofMtheMchangeMcontrolMprocess
B)MPerformManMend-to-endMwalk-throughMofMtheMprocess
C)MTestMaMsampleMofMauthorizedMchanges
D)MTestMaMsampleMpopulationMofMchangeMrequestsM-MAnswerMB)MPerformManMend-
to-endMwalk-
throughMofMtheMprocessMisMcorrect.MObservationMisMtheMbestMandMmostMeffectiveM
methodMtoMtestMchangesMtoMensureMthatMtheMprocessMisMeffectivelyMdesigned.
D)MTestMaMsampleMpopulationMofMchangeMrequestsMisMincorrect.MTestingMaMsampleM
populationMofMchangesMisMaMtestMofMcomplianceMandMoperatingMeffectivenessMtoMens
ureMthatMusersMsubmittedMtheMproperMdocumentation/requests.MItMdoesMnotMtestMthe
MeffectivenessMofMtheMdesign.M
C)MTestMaMsampleMofMauthorizedMchangesMisMincorrect.MTestingMchangesMthatMhaveM
beenMauthorizedMmayMnotMprovideMsufficientMassuranceMofMtheMentireMprocessMbecau
seMitMdoesMnotMtestMtheMelementsMofMtheMprocessMrelatedMtoMauthorizationMorMde
tectMchangesMthatMbypassedMtheMcontrols.M
A)MInterviewMpersonnelMinMchargeMofMtheMchangeMcontrolMprocessMisMincorrect.MThis
MisMnotMasMeffectiveMasMaMwalk-
throughMofMtheMchangeMcontrolsMprocessMbecauseMpeopleMmayMknowMtheMprocessM
butMnotMfollowMit.
Q2)MAnMorganizationMprovidesMinformationMtoMitsMsupplyMchainMpartnersMandMcustom
ersMthroughManMextranetMinfrastructure.MWhichMofMtheMfollowingMshouldMbeMtheMGR
EATESTMconcernMtoManMISMauditorMreviewingMtheMfirewallMsecurityMarchitecture?
,A)MInboundMtrafficMisMblockedMunlessMtheMtrafficMtypeMandMconnectionsMhaveMbeen
MspecificallyMpermitted.M
B)MAMSecureMSocketsMLayerMhasMbeenMimplementedMforMuserMauthenticationMandMre
moteMadministrationMofMtheMfirewall.
C)MTheMfirewallMisMplacedMonMtopMofMtheMcommercialMoperatingMsystemMwithMallM
defaultMinstillationMoptions.
D)MFirewallMpoliciesMareMupdatedMonMtheMbasisMofMchangingMrequirementsM-
MAnswerMC)MTheMfirewallMisMplacedMonMtopMofMtheMcommercialMoperatingMsystemM
withMallMdefaultMinstallationMoptionsMisMcorrect.MTheMgreatestMconcernMwhenMimplem
entingMfirewallsMonMtopMofMcommercialMoperatingMsystemsMisMtheMpotentialMpresence
MofMvulnerabilitiesMthatMcouldMundermineMtheMsecurityMpostureMofMtheMfirewallMplatf
ormMitself.MInMmostMcircumstances,MwhenMcommercialMfirewallsMareMbreached,MthatM
breachMisMfacilitatedMbyMvulnerabilitiesMinMtheMunderlyingMoperatingMsystem.MKeeping
MallMinstallationMoptionsMavailableMonMtheMsystemMfurtherMincreasesMtheMriskMofMvul
nerabilitiesMandMexploits.M
B)MAMSecureMSocketsMLayerMhasMbeenMimplementedMforMuserMauthenticationMandMre
moteMadministrationMofMtheMfirewallMisMincorrect.MUsingMSecureMSocketsMLayerMforMf
irewallMadministrationMisMimportantMbecauseMchangesMinMuserMandMsupplyMchainMpart
ners'MrolesMandMprofilesMwillMbeMdynamic.
M
D)MFirewallMpoliciesMareMupdatedMonMtheMbasisMofMchangingMrequirementsMisMincorr
ect.MItMisMappropriateMtoMmaintainMtheMfirewallMpoliciesMasMneeded.M
A)MInboundMtrafficMisMblockedMunlessMtheMtrafficMtypeMandMconnectionsMhaveMbeen
MspecificallyMpermittedMisMincorrect.MItMisMprudentMtoMblockMallMinboundMtrafficMto
ManMextranetMunlessMpermitted.
Q3)MWhichMofMtheMfollowingMchoicesMwouldMbeMtheMBESTMsourceMofMinformationM
whenMdevelopingMaMrisk-basedMauditMplan?
A)MSystemMcustodiansMidentifyMvulnerabilities.
,B)ProcessMownersMidentifyMkeyMcontrols.
C)MSeniorMmanagementMidentifyMkeyMbusinessMprocesses.
D)MPeerMauditorsMunderstandMpreviousMauditMresults.M-
MAnswerMC)MSeniorMmanagementMidentifyMkeyMbusinessMprocessesMisMcorrect.MDevelo
pingMaMrisk-
basedMauditMplanMmustMstartMwithMtheMidentificationMofMkeyMbusinessMprocesses,Mw
hichMdetermineMandMidentifyMtheMriskMthatMneedsMtoMbeMaddressed.M
B)MProcessMownersMidentifyMkeyMcontrolsMisMincorrect.MAlthoughMprocessMownersMsho
uldMbeMconsultedMtoMidentifyMkeyMcontrols,MseniorMmanagementMisMaMbetterMsource
MtoMidentifyMbusinessMprocesses,MwhichMareMmoreMimportant.MSystemMcustodiansMide
ntifyMvulnerabilitiesMisMincorrect.M
A)MSystemMcustodiansMareMaMgoodMsourceMtoMbetterMunderstandMtheMriskMandMcon
trolsMasMtheyMapplyMtoMspecificMapplications;Mhowever,MseniorMmanagementMisMaMbe
tterMsourceMtoMidentifyMbusinessMprocesses,MwhichMareMmoreMimportant.M
D)MPeerMauditorsMunderstandMpreviousMauditMresultsMisMincorrect.MTheMreviewMofMpr
eviousMauditMresultsMisMoneMinputMintoMtheMauditMplanningMprocess;Mhowever,MifMp
reviousMauditsMfocusedMonMaMlimitedMorMaMrestrictedMscopeMorMifMtheMkeyMbusines
sMprocessesMhaveMchangedMand/orMnewMbusinessMprocessesMhaveMbeenMintroduced,M
thenMthisMdoesMcontributeMtoMtheMdevelopmentMofMaMrisk-basedMauditMplan.
Q4)MWhichMofMtheMfollowingMinputsMaddsMtheMMOSTMvalueMtoMtheMstrategicMITMini
tiativeMdecision-makingMprocess?
A)TheMmaturityMofMtheMprojectMmanagementMprocess
B)MTheMregulatoryMenvironment
C)MPastMauditMfindings
, D)MTheMITMprojectMportfolioManalysisM-
MAnswerMD)MTheMITMprojectMportfolioManalysisMisMcorrect.MPortfolioManalysisMprovide
sMtheMbestMinputMintoMtheMdecision-
makingMprocessMrelatingMtoMplanningMstrategicMITMinitiatives.MAnManalysisMofMtheMIT
MportfolioMprovidesMcomparableMinformationMofMplannedMinitiatives,MprojectsMandMong
oingMITMservices,MwhichMallowsMtheMITMstrategyMtoMbeMalignedMwithMtheMbusinessM
strategy.M
A)MTheMmaturityMofMtheMprojectMmanagementMprocessMisMincorrect.MTheMmaturityMo
fMtheMprojectMmanagementMprocessMisMmoreMimportantMwithMrespectMtoMmanagingM
theMday-to-dayMoperationsMofMITMversusMperformingMstrategicMplanning.M
B)MTheMregulatoryMenvironmentMisMincorrect.MRegulatoryMrequirementsMmayMdriveMinv
estmentMinMcertainMtechnologiesMandMinitiatives;Mhowever,MhavingMtoMmeetMregulatory
MrequirementsMisMnotMtypicallyMtheMmainMfocusMofMtheMITMandMbusinessMstrategy.M
C)MPastMauditMfindingsMisMincorrect.MPastMauditMfindingsMmayMdriveMinvestmentMinM
certainMtechnologiesMandMinitiatives;Mhowever,MhavingMtoMremediateMpastMauditMfindin
gsMisMnotMtheMmainMfocusMofMtheMITMandMbusinessMstrategy.
Q5)MTheMimplementationMofMwhichMofMtheMfollowingMwouldMMOSTMeffectivelyMpreve
ntMunauthorizedMaccessMtoMaMsystemMadministrationMaccountMonMaMwebMserver?
A)MPasswordMexpirationMandMlockoutMpolicy
B)MPasswordMcomplexityMrules
C)MHostMintrusionMdetectionMsoftwareMinstalledMonMaMserver
D)MTwo-factorMauthenticationM-MAnswerMD)MTwo-
factorMauthenticationMisMcorrect.MThisMrequiresMaMuserMtoMuseMaMpasswordMinMcom
binationMwithManotherMidentificationMfactorMthatMisMnotMeasilyMstolenMorMguessedMb
yManMattacker.MTypesMofMtwo-
factorMauthenticationMincludeMelectronicMaccessMtokensMthatMshowMone-
timeMpasswordsMonMtheirMdisplayMpanelsMorMbiometricMauthenticationMsystems.M
Answers Updated 2026
Q1)MWhichMofMtheMfollowingMisMtheMMOSTMefficientMandMsufficientlyMreliableMwayMt
oMtestMtheMdesignMeffectivenessMofMaMchangeMcontrolMprocess?
A)MInterviewMpersonnelMinMchargeMofMtheMchangeMcontrolMprocess
B)MPerformManMend-to-endMwalk-throughMofMtheMprocess
C)MTestMaMsampleMofMauthorizedMchanges
D)MTestMaMsampleMpopulationMofMchangeMrequestsM-MAnswerMB)MPerformManMend-
to-endMwalk-
throughMofMtheMprocessMisMcorrect.MObservationMisMtheMbestMandMmostMeffectiveM
methodMtoMtestMchangesMtoMensureMthatMtheMprocessMisMeffectivelyMdesigned.
D)MTestMaMsampleMpopulationMofMchangeMrequestsMisMincorrect.MTestingMaMsampleM
populationMofMchangesMisMaMtestMofMcomplianceMandMoperatingMeffectivenessMtoMens
ureMthatMusersMsubmittedMtheMproperMdocumentation/requests.MItMdoesMnotMtestMthe
MeffectivenessMofMtheMdesign.M
C)MTestMaMsampleMofMauthorizedMchangesMisMincorrect.MTestingMchangesMthatMhaveM
beenMauthorizedMmayMnotMprovideMsufficientMassuranceMofMtheMentireMprocessMbecau
seMitMdoesMnotMtestMtheMelementsMofMtheMprocessMrelatedMtoMauthorizationMorMde
tectMchangesMthatMbypassedMtheMcontrols.M
A)MInterviewMpersonnelMinMchargeMofMtheMchangeMcontrolMprocessMisMincorrect.MThis
MisMnotMasMeffectiveMasMaMwalk-
throughMofMtheMchangeMcontrolsMprocessMbecauseMpeopleMmayMknowMtheMprocessM
butMnotMfollowMit.
Q2)MAnMorganizationMprovidesMinformationMtoMitsMsupplyMchainMpartnersMandMcustom
ersMthroughManMextranetMinfrastructure.MWhichMofMtheMfollowingMshouldMbeMtheMGR
EATESTMconcernMtoManMISMauditorMreviewingMtheMfirewallMsecurityMarchitecture?
,A)MInboundMtrafficMisMblockedMunlessMtheMtrafficMtypeMandMconnectionsMhaveMbeen
MspecificallyMpermitted.M
B)MAMSecureMSocketsMLayerMhasMbeenMimplementedMforMuserMauthenticationMandMre
moteMadministrationMofMtheMfirewall.
C)MTheMfirewallMisMplacedMonMtopMofMtheMcommercialMoperatingMsystemMwithMallM
defaultMinstillationMoptions.
D)MFirewallMpoliciesMareMupdatedMonMtheMbasisMofMchangingMrequirementsM-
MAnswerMC)MTheMfirewallMisMplacedMonMtopMofMtheMcommercialMoperatingMsystemM
withMallMdefaultMinstallationMoptionsMisMcorrect.MTheMgreatestMconcernMwhenMimplem
entingMfirewallsMonMtopMofMcommercialMoperatingMsystemsMisMtheMpotentialMpresence
MofMvulnerabilitiesMthatMcouldMundermineMtheMsecurityMpostureMofMtheMfirewallMplatf
ormMitself.MInMmostMcircumstances,MwhenMcommercialMfirewallsMareMbreached,MthatM
breachMisMfacilitatedMbyMvulnerabilitiesMinMtheMunderlyingMoperatingMsystem.MKeeping
MallMinstallationMoptionsMavailableMonMtheMsystemMfurtherMincreasesMtheMriskMofMvul
nerabilitiesMandMexploits.M
B)MAMSecureMSocketsMLayerMhasMbeenMimplementedMforMuserMauthenticationMandMre
moteMadministrationMofMtheMfirewallMisMincorrect.MUsingMSecureMSocketsMLayerMforMf
irewallMadministrationMisMimportantMbecauseMchangesMinMuserMandMsupplyMchainMpart
ners'MrolesMandMprofilesMwillMbeMdynamic.
M
D)MFirewallMpoliciesMareMupdatedMonMtheMbasisMofMchangingMrequirementsMisMincorr
ect.MItMisMappropriateMtoMmaintainMtheMfirewallMpoliciesMasMneeded.M
A)MInboundMtrafficMisMblockedMunlessMtheMtrafficMtypeMandMconnectionsMhaveMbeen
MspecificallyMpermittedMisMincorrect.MItMisMprudentMtoMblockMallMinboundMtrafficMto
ManMextranetMunlessMpermitted.
Q3)MWhichMofMtheMfollowingMchoicesMwouldMbeMtheMBESTMsourceMofMinformationM
whenMdevelopingMaMrisk-basedMauditMplan?
A)MSystemMcustodiansMidentifyMvulnerabilities.
,B)ProcessMownersMidentifyMkeyMcontrols.
C)MSeniorMmanagementMidentifyMkeyMbusinessMprocesses.
D)MPeerMauditorsMunderstandMpreviousMauditMresults.M-
MAnswerMC)MSeniorMmanagementMidentifyMkeyMbusinessMprocessesMisMcorrect.MDevelo
pingMaMrisk-
basedMauditMplanMmustMstartMwithMtheMidentificationMofMkeyMbusinessMprocesses,Mw
hichMdetermineMandMidentifyMtheMriskMthatMneedsMtoMbeMaddressed.M
B)MProcessMownersMidentifyMkeyMcontrolsMisMincorrect.MAlthoughMprocessMownersMsho
uldMbeMconsultedMtoMidentifyMkeyMcontrols,MseniorMmanagementMisMaMbetterMsource
MtoMidentifyMbusinessMprocesses,MwhichMareMmoreMimportant.MSystemMcustodiansMide
ntifyMvulnerabilitiesMisMincorrect.M
A)MSystemMcustodiansMareMaMgoodMsourceMtoMbetterMunderstandMtheMriskMandMcon
trolsMasMtheyMapplyMtoMspecificMapplications;Mhowever,MseniorMmanagementMisMaMbe
tterMsourceMtoMidentifyMbusinessMprocesses,MwhichMareMmoreMimportant.M
D)MPeerMauditorsMunderstandMpreviousMauditMresultsMisMincorrect.MTheMreviewMofMpr
eviousMauditMresultsMisMoneMinputMintoMtheMauditMplanningMprocess;Mhowever,MifMp
reviousMauditsMfocusedMonMaMlimitedMorMaMrestrictedMscopeMorMifMtheMkeyMbusines
sMprocessesMhaveMchangedMand/orMnewMbusinessMprocessesMhaveMbeenMintroduced,M
thenMthisMdoesMcontributeMtoMtheMdevelopmentMofMaMrisk-basedMauditMplan.
Q4)MWhichMofMtheMfollowingMinputsMaddsMtheMMOSTMvalueMtoMtheMstrategicMITMini
tiativeMdecision-makingMprocess?
A)TheMmaturityMofMtheMprojectMmanagementMprocess
B)MTheMregulatoryMenvironment
C)MPastMauditMfindings
, D)MTheMITMprojectMportfolioManalysisM-
MAnswerMD)MTheMITMprojectMportfolioManalysisMisMcorrect.MPortfolioManalysisMprovide
sMtheMbestMinputMintoMtheMdecision-
makingMprocessMrelatingMtoMplanningMstrategicMITMinitiatives.MAnManalysisMofMtheMIT
MportfolioMprovidesMcomparableMinformationMofMplannedMinitiatives,MprojectsMandMong
oingMITMservices,MwhichMallowsMtheMITMstrategyMtoMbeMalignedMwithMtheMbusinessM
strategy.M
A)MTheMmaturityMofMtheMprojectMmanagementMprocessMisMincorrect.MTheMmaturityMo
fMtheMprojectMmanagementMprocessMisMmoreMimportantMwithMrespectMtoMmanagingM
theMday-to-dayMoperationsMofMITMversusMperformingMstrategicMplanning.M
B)MTheMregulatoryMenvironmentMisMincorrect.MRegulatoryMrequirementsMmayMdriveMinv
estmentMinMcertainMtechnologiesMandMinitiatives;Mhowever,MhavingMtoMmeetMregulatory
MrequirementsMisMnotMtypicallyMtheMmainMfocusMofMtheMITMandMbusinessMstrategy.M
C)MPastMauditMfindingsMisMincorrect.MPastMauditMfindingsMmayMdriveMinvestmentMinM
certainMtechnologiesMandMinitiatives;Mhowever,MhavingMtoMremediateMpastMauditMfindin
gsMisMnotMtheMmainMfocusMofMtheMITMandMbusinessMstrategy.
Q5)MTheMimplementationMofMwhichMofMtheMfollowingMwouldMMOSTMeffectivelyMpreve
ntMunauthorizedMaccessMtoMaMsystemMadministrationMaccountMonMaMwebMserver?
A)MPasswordMexpirationMandMlockoutMpolicy
B)MPasswordMcomplexityMrules
C)MHostMintrusionMdetectionMsoftwareMinstalledMonMaMserver
D)MTwo-factorMauthenticationM-MAnswerMD)MTwo-
factorMauthenticationMisMcorrect.MThisMrequiresMaMuserMtoMuseMaMpasswordMinMcom
binationMwithManotherMidentificationMfactorMthatMisMnotMeasilyMstolenMorMguessedMb
yManMattacker.MTypesMofMtwo-
factorMauthenticationMincludeMelectronicMaccessMtokensMthatMshowMone-
timeMpasswordsMonMtheirMdisplayMpanelsMorMbiometricMauthenticationMsystems.M