Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 67 pages
Exam (elaborations)

CISA Studying Questions & 100% Correct Answers

Document preview thumbnail
Preview 4 out of 67 pages

Which of the following BEST describes the purpose of performing a risk assessment in the planning phase of an IS audit? A. To establish adequate staffing requirements to complete the IS audit B. To provide reasonable assurance that all material items will be addressed C. To determine the skills required to perform the IS audit Incorrect D. To develop the audit program and procedures to perform the IS audit :~~ You answered D. The correct answer is B. A. A risk assessment does not directly influence staffing requirements. 2 | P a g e | © copyright 2024/2025 | Grade A+ Master01 | September, 2024/2025 | Latest update B. A risk assessment helps focus the audit procedures on the highest risk areas included in the scope of the audit. The concept of reasonable assurance is important as well. C. A risk assessment does not identify the skills required to perform an IS audit. D. A risk assessment is not used in the development of the audit program and procedures. Which of the following controls would BEST detect intrusion? A. User IDs and user privileges are granted through authorized procedures. B. Automatic logoff is used when a workstation is inactive for a particular period of time. Incorrect C. Automatic logoff of the system occurs after a specified number of unsuccessful attempts. 3 | P a g e | © copyright 2024/2025 | Grade A+ Master01 | September, 2024/2025 | Latest update D. Unsuccessful logon attempts are monitored by the security administrator. :~~ You answered C. The correct answer is D. A. User IDs and the granting of user privileges define a policy. This is a type of administrative or managerial control that may prevent intrusion but would not detect it. B. Automatic logoff is a method of preventing access through unattended or inactive terminals, but is not a detective control. C. Unsuccessful attempts to log on are a method for preventing intrusion, not detecting it. D. Intrusion is detected by the active monitoring and review of unsuccessful logon attempts. Which testing approach is MOST appropriate to ensure that internal application interface errors are identified as soon as possible? A. 4 | P a g e | © copyright 2024/2025 | Grade A+ Master01 | September, 2024/2025 | Latest update Bottom-up testing B. Sociability testing C. Top-down testing Incorrect D.

Content preview

1 | P a g e | © copyright 2024/2025 | Grade A+




CISA Studying Questions & 100%
Correct Answers
Which of the following BEST describes the purpose of performing a risk assessment

in the planning phase of an IS audit?




A.

To establish adequate staffing requirements to complete the IS audit




B.

To provide reasonable assurance that all material items will be addressed




C.

To determine the skills required to perform the IS audit




Incorrect D.

To develop the audit program and procedures to perform the IS audit

✓ :~~ You answered D. The correct answer is B.




A. A risk assessment does not directly influence staffing requirements.




Master01 | September, 2024/2025 | Latest update

, 2 | P a g e | © copyright 2024/2025 | Grade A+


B. A risk assessment helps focus the audit procedures on the highest risk areas

included in the scope of the audit. The concept of reasonable assurance is

important as well.




C. A risk assessment does not identify the skills required to perform an IS audit.




D. A risk assessment is not used in the development of the audit program and

procedures.




Which of the following controls would BEST detect intrusion?




A.

User IDs and user privileges are granted through authorized procedures.




B.

Automatic logoff is used when a workstation is inactive for a particular period of

time.




Incorrect C.

Automatic logoff of the system occurs after a specified number of unsuccessful

attempts.




Master01 | September, 2024/2025 | Latest update

, 3 | P a g e | © copyright 2024/2025 | Grade A+




D.

Unsuccessful logon attempts are monitored by the security administrator.


✓ :~~ You answered C. The correct answer is D.




A. User IDs and the granting of user privileges define a policy. This is a type of

administrative or managerial control that may prevent intrusion but would not

detect it.




B. Automatic logoff is a method of preventing access through unattended or

inactive terminals, but is not a detective control.




C. Unsuccessful attempts to log on are a method for preventing intrusion, not

detecting it.




D. Intrusion is detected by the active monitoring and review of unsuccessful logon

attempts.




Which testing approach is MOST appropriate to ensure that internal application

interface errors are identified as soon as possible?




A.


Master01 | September, 2024/2025 | Latest update

, 4 | P a g e | © copyright 2024/2025 | Grade A+


Bottom-up testing




B.

Sociability testing




C.

Top-down testing




Incorrect D.

System testing

✓ :~~ You answered D. The correct answer is C.




A. A bottom-up approach to testing begins with atomic units, such as programs and

modules, and works upward until a complete system test has taken place.




B. Sociability testing takes place at a later stage in the development process.




C. The top-down approach to testing ensures that interface errors are detected

early and that testing of major functions is conducted early.




D. System tests take place at a later stage in the development process.


Master01 | September, 2024/2025 | Latest update

Document information

Uploaded on
September 9, 2024
Number of pages
67
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$13.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Axpert
3.8
(126)
Sold
560
Followers
167
Items
29320
Last sold
3 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions