Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 5 pages
Exam (elaborations)

Certified Information Systems Auditor CISA Exam Questions

Document preview thumbnail
Preview 2 out of 5 pages

Certified Information Systems Auditor CISA Exam Questions 1. Information system auditors identified separation of duties in ERP systems. What is the most effective way to avoid repetitive configurations? - A. Implement a role-based model to manage user access - B. Routinely review access permissions - C. Rectify separation of duties - D. Use a standard user access matrix ️ A. Implement a role-based model to manage user access 2. When creating a disaster recovery plan, which factor should primarily determine the availability requirement of a single application? - A. Data confidentiality handled by the application - B. The importance of the business processes that the application supports - C. The total cost of ownership (TCO) associated with the application - D. Network bandwidth requirements for the application ️ B. The importance of the business processes that the application supports 3. What is the initial step to establish a comprehensive data security program? - A. Consult with senior IT management - B. Set up monitoring controls - C. Enact data loss prevention strategies - D. Conduct an asset inventory ️ D. Conduct an asset inventory 4. What is a primary benefit of using object-oriented system development? - A. It is effective for data with intricate relationships - B. It allows partitioning of the system in a client-server architecture - C. It is simpler to code than procedural languages - D. It decreases the necessity for system documentation ️ A. It is effective for data with intricate relationships 5. Following a theft of portable computers with customer sensitive data, what should the information systems auditor recommend to prevent future incidents? - A. Improve physical security measures - B. Utilize encrypted disk drives - C. Require dual certifications - D. Use cable locks ️ A. Improve physical security measures 6. During an audit of physical security, a contactless proximity card was provided that allows access to three floors. Which issue should raise the most concern? - A. The card did not function during the audit's initial days - B. Failed access attempts were not investigated - C. The card mistakenly permits access to restricted areas - D. No escort was needed during the audit ️ C. The card mistakenly permits access to restricted areas 7. A company's procedures necessitate urgent change approvals within 7 days. The auditor notes that the manager checks compliance by reviewing outstanding urgent changes monthly. What is the biggest risk in this situation? - A. Audit risk - B. Detection risk - C. Inherent risk - D. Control risk ️ C. Inherent risk 8. An information system auditor attending an application development meeting may compromise their independence by: - A. Helping in the development of integrated testing equipment - B. Re-running the tests conducted by the development team - C. Crafting and executing the user acceptance test plan - D. Reviewing the results of system tests conducted by the team ️ C. Crafting and executing the user acceptance test plan 9. An accounts payable clerk has access to a file post-generation of the payment file. The primary risk to the organization is that money could be: - A. Altered - B. Rejected - C. Delayed to the customer - D. Duplication ️ A. Altered 10. Which type of attack is most effectively monitored by Intrusion Detection Systems (IDS)? - A. Spoofing - B. System scanning - C. Logic bomb - D. Spamming ️ B. System scanning 11. A company is planning automated data transfers from third-party providers int

Content preview

Certified Information Systems Auditor CISA Exam Questions


1. Information system auditors identified separation of duties in ERP systems. What is the most effective
way to avoid repetitive configurations?

- A. Implement a role-based model to manage user access

- B. Routinely review access permissions

- C. Rectify separation of duties

- D. Use a standard user access matrix



✔️ A. Implement a role-based model to manage user access



2. When creating a disaster recovery plan, which factor should primarily determine the availability
requirement of a single application?

- A. Data confidentiality handled by the application

- B. The importance of the business processes that the application supports

- C. The total cost of ownership (TCO) associated with the application

- D. Network bandwidth requirements for the application



✔️ B. The importance of the business processes that the application supports



3. What is the initial step to establish a comprehensive data security program?

- A. Consult with senior IT management

- B. Set up monitoring controls

- C. Enact data loss prevention strategies

- D. Conduct an asset inventory



✔️ D. Conduct an asset inventory



4. What is a primary benefit of using object-oriented system development?

, - A. It is effective for data with intricate relationships

- B. It allows partitioning of the system in a client-server architecture

- C. It is simpler to code than procedural languages

- D. It decreases the necessity for system documentation



✔️ A. It is effective for data with intricate relationships



5. Following a theft of portable computers with customer sensitive data, what should the information
systems auditor recommend to prevent future incidents?

- A. Improve physical security measures

- B. Utilize encrypted disk drives

- C. Require dual certifications

- D. Use cable locks



✔️ A. Improve physical security measures



6. During an audit of physical security, a contactless proximity card was provided that allows access to
three floors. Which issue should raise the most concern?

- A. The card did not function during the audit's initial days

- B. Failed access attempts were not investigated

- C. The card mistakenly permits access to restricted areas

- D. No escort was needed during the audit



✔️ C. The card mistakenly permits access to restricted areas



7. A company's procedures necessitate urgent change approvals within 7 days. The auditor notes that
the manager checks compliance by reviewing outstanding urgent changes monthly. What is the biggest
risk in this situation?

- A. Audit risk

- B. Detection risk

Document information

Uploaded on
September 7, 2024
Number of pages
5
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$9.89

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
CertifiedGrades
3.9
(38)
Sold
146
Followers
61
Items
8739
Last sold
2 months ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions