Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 38 pages
Exam (elaborations)

CISA Study Notes Questions & 100% Correct Answers

Document preview thumbnail
Preview 4 out of 38 pages

Who is responsible for imposing an IT governance model encompassing IT strategy, information security, and formal enterprise architectural mandates? :~~ IT executives and the Board of Directors The party that performs strategic planning, addresses near-term and long-term requirements aligning business objectives, and technology strategies. :~~ The Steering Committee What three elements allow validation of business practices against acceptable measures of regulatory compliance, performance, and standard operational guidelines. :~~ (1.) Polices (2.) Procedures (3.) Standards What activity involves the identification of potential risk and the appropriate response for each threat based on impact assessment using qualitative and/or quantitative measures for an enterprise-wide risk management strategy? :~~ Risk Management IT Governance is most concerned with.... 2 | P a g e | © copyright 2024/2025 | Grade A+ Master01 | September, 2024/2025 | Latest update :~~ IT Strategy Describe the advantages of outsourcing. :~~ Outsourcing is an opportunity for the organization to focus on core competencies. When an organization oursources a business function, it no longer needs to be concerned about training employees in that function. Outsources does not always reduce costs, because cost reduction is not always the primary goal of oursourcing. An external IS auditor has discovered a segregation of duties issue in a high value process. What is the best action for the auditor to take? :~~ The external auditor can only document the finding in the audit report. An external auditor is not in a position to implement controls. An organization has chosen to open a business office in another country where labor costs are lower and has hired workers to perform business functions there. This organization has done what? :~~ The organization is insourcing - while they may have opened the office in a foreign country, they have hired locals to do the work as opposed to contracting with a third party. An organization has discovered that some of its employees have criminal records. What is the best course of action for the organization to take? 3 | P a g e | © copyright 2024/2025 | Grade A+ Master01 | September, 2024/2025 | Latest update :~~ The organization should have background checks performed on all of its existing employees and also begin instituting background checks of all newhires. It is not necessarily required to terminate the employees - their offenses may not warrant termination. The options for Risk Treatment are: :~~ Risk Mitigation Risk Avoidance Risk Transfer Risk Acceptance Annualized Loss Expectance (ALE) is defined as: :~~ ALE is the annual expected loss to an asset. It is calculated as the single loss expectancy (SLE) X the annualized rate of occurrence (ARO.) A quantitative risk analysis is more difficult to perform because: :~~ It is difficult to get accurate figures on the frequency of specific threats. It is difficult to determine the probability that a threat will be realized. It is relatively easy to determine the value of an asset and the impact of a threat event. An IS auditor is examining the IT standards document for an organization that was last reviewed two years earlier. The best course of action for the IS auditor is: :~~ Report that the IT standards are not being reviewed often enough. Two years is far too long between reviews of IT standards. 4 | P a g e | © copyright 2024/2025 | Grade A+ Master01 | September, 2024/2025 | Latest update The purpose of a Balanced Scorecard is: :~~ To measure organizational performance and effectiveness against strategic goals. The 4-item focus of a Balanced Scorecard is: :~~ (1.) Financial (2.) Customer (3.) Internal processes (4.) Innovation / Learning The audit program is an audit strategy and plans that include: :~~ (1.) Scope (2.) Objectives (3.) Resources (4.) Procedures used to evaluation controls and processes IS auditors can stay current with technology through the following means: :~~ (1.) training courses (2.) webinars (3.) ISACA chapter training events (4.) Industry conferences Name the three Types of

Content preview

1 | P a g e | © copyright 2024/2025 | Grade A+




CISA Study Notes Questions & 100%
Correct Answers
Who is responsible for imposing an IT governance model encompassing IT strategy,

information security, and formal enterprise architectural mandates?

✓ :~~ IT executives and the Board of Directors




The party that performs strategic planning, addresses near-term and long-term

requirements aligning business objectives, and technology strategies.

✓ :~~ The Steering Committee




What three elements allow validation of business practices against acceptable

measures of regulatory compliance, performance, and standard operational

guidelines.

✓ :~~ (1.) Polices (2.) Procedures (3.) Standards




What activity involves the identification of potential risk and the appropriate

response for each threat based on impact assessment using qualitative and/or

quantitative measures for an enterprise-wide risk management strategy?


✓ :~~ Risk Management




IT Governance is most concerned with....




Master01 | September, 2024/2025 | Latest update

, 2 | P a g e | © copyright 2024/2025 | Grade A+


✓ :~~ IT Strategy




Describe the advantages of outsourcing.


✓ :~~ Outsourcing is an opportunity for the organization to focus on core

competencies. When an organization oursources a business function, it no

longer needs to be concerned about training employees in that function.

Outsources does not always reduce costs, because cost reduction is not

always the primary goal of oursourcing.




An external IS auditor has discovered a segregation of duties issue in a high value

process. What is the best action for the auditor to take?

✓ :~~ The external auditor can only document the finding in the audit report.

An external auditor is not in a position to implement controls.




An organization has chosen to open a business office in another country where

labor costs are lower and has hired workers to perform business functions there.

This organization has done what?

✓ :~~ The organization is insourcing - while they may have opened the office

in a foreign country, they have hired locals to do the work as opposed to

contracting with a third party.




An organization has discovered that some of its employees have criminal records.

What is the best course of action for the organization to take?


Master01 | September, 2024/2025 | Latest update

, 3 | P a g e | © copyright 2024/2025 | Grade A+


✓ :~~ The organization should have background checks performed on all of its

existing employees and also begin instituting background checks of all new-

hires. It is not necessarily required to terminate the employees - their

offenses may not warrant termination.




The options for Risk Treatment are:

✓ :~~ Risk Mitigation Risk Avoidance Risk Transfer Risk Acceptance




Annualized Loss Expectance (ALE) is defined as:


✓ :~~ ALE is the annual expected loss to an asset. It is calculated as the

single loss expectancy (SLE) X the annualized rate of occurrence (ARO.)




A quantitative risk analysis is more difficult to perform because:

✓ :~~ It is difficult to get accurate figures on the frequency of specific

threats. It is difficult to determine the probability that a threat will be

realized. It is relatively easy to determine the value of an asset and the

impact of a threat event.




An IS auditor is examining the IT standards document for an organization that was

last reviewed two years earlier. The best course of action for the IS auditor is:

✓ :~~ Report that the IT standards are not being reviewed often enough. Two

years is far too long between reviews of IT standards.




Master01 | September, 2024/2025 | Latest update

, 4 | P a g e | © copyright 2024/2025 | Grade A+


The purpose of a Balanced Scorecard is:

✓ :~~ To measure organizational performance and effectiveness against

strategic goals.




The 4-item focus of a Balanced Scorecard is:


✓ :~~ (1.) Financial (2.) Customer (3.) Internal processes (4.) Innovation /

Learning




The audit program is an audit strategy and plans that include:

✓ :~~ (1.) Scope (2.) Objectives (3.) Resources (4.) Procedures used to

evaluation controls and processes




IS auditors can stay current with technology through the following means:

✓ :~~ (1.) training courses (2.) webinars (3.) ISACA chapter training events

(4.) Industry conferences




Name the three Types of Controls

✓ :~~ (1.) Physical (2.) Technical (4.) Administrative




Name the two Categories of Controls

✓ :~~ (1.) Automatic (2.) Manual




Master01 | September, 2024/2025 | Latest update

Document information

Uploaded on
September 9, 2024
Number of pages
38
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$13.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Axpert
3.8
(126)
Sold
560
Followers
167
Items
29320
Last sold
3 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions