Certified Information Systems
Auditor CISA Exam Questions and
Answers
InformationMsystemMauditorsMhaveMidentifiedMseparationMofMdutiesMinMenterpriseMreso
urceMplanningM(ERP)Msystems.
WhichMofMtheMfollowingMisMtheMbestMwayMtoMpreventMrepetitiveMconfigurationMfrom
Moccurring?
A.MUseMaMrole-basedMmodelMtoMgrantMuserMaccess
B.MRegularlyMmonitorMaccessMrights
C.MCorrectingMseparationMofMduties
D.MReferenceMstandardMuserMaccessMmatrixM-MAnswerMA.MUseMaMrole-
basedMmodelMtoMgrantMuserMaccess
WhichMofMtheMfollowingMshouldMbeMtheMmostMimportantMfactorMdrivingMaMsingleMap
plicationMavailabilityMrequirementMwhenMdevelopingMaMdisasterMrecoveryMplan?
A.MConfidentialityMofMdataMprocessedMbyMtheMapplication
B.MTheMcriticalityMofMtheMbusinessMprocessesMsupportedMbyMtheMapplication
C.MTotalMcostMofMownershipM(TCO)MofMtheMapplication
D.MSupportMtheMapplication'sMnetworkMbandwidthM-
MAnswerMB.MTheMcriticalityMofMtheMbusinessMprocessesMsupportedMbyMtheMapplication
InMorderMtoMdevelopMaMrobustMdataMsecurityMprogram,MtheMfirstMstepMyouMshould
MtakeMis:
A.MTalkMtoMtheMseniorMmanagementMlevelMofMIT.
B.MImplementMmonitoringMcontrols.
C.MImplementMdataMlossMpreventionMmeasures
D.MPerformMinventoryMofMassetsM-MAnswerMD.MPerformMinventoryMofMassets
heMadvantageMofMobject-orientedMsystemMdevelopmentMisMthatMit:
A.MSuitableMforMdataMwithMcomplexMrelationships
B.MPartitionMtheMsystemMasMaMclientMserverMarchitecture
, C.MEasierMtoMprogramMthanMproceduralMlanguages
D.MReduceMsystemMdocumentationMrequirementsM-
MAnswerMA.MSuitableMforMdataMwithMcomplexMrelationships
SeveralMportableMcomputersMcontainingMcustomer-
sensitiveMdataMwereMstolenMfromMtheMstaff'sMofficeMbecauseMtheyMwereMunattended.
WhichMofMtheMfollowingMisMtheMbestMadviceMforManMinformationMsystemsMauditorMt
oMprotectMdataMwhenMitMpreventsMsimilarMincidentsMfromMhappeningMagain?
A.MEnhanceMphysicalMsecurity
B.MEncryptedMdiskMdrive
C.MRequestMforMdualMcertification
D.MRequiresMtheMuseMofMaMcableMlockM-MAnswerMA.MEnhanceMphysicalMsecurity
DuringMtheMphysicalMsecurityMaudit,MtheMinformationMsystemMauditorMreceivedMaMcont
actlessMproximityMcardMthatMallowedMtoMaccessMtoMthreeMspecificMfloorsMofMtheMcor
porateMofficeMbuilding.
WhichMofMtheMfollowingMquestionsMshouldMbeMtheMbiggestMconcern?
A.MInMtheMfirstMtwoMdaysMofMfieldMworkMofMaudit,MtheMproximityMcardMdidMnotM
work.
B.MNoMfollow-upMwasMmadeMforMunsuccessfulMattemptsMtoMaccessMviolations.
C.MTheMproximityMcardMincorrectlyMgrantsMaccessMtoMtheMrestrictedMzone
D.MNoMescortMrequiredMduringMfieldMwork.M-
MAnswerMC.MTheMproximityMcardMincorrectlyMgrantsMaccessMtoMtheMrestrictedMzone
TheMcompany'sMoperationalMproceduresMrequireMurgentMchangesMtoMbeMapprovedMfor
MbusinessMwithinM7MdaysMofMtheMoccurrence.MTheMInformationMSystemsMAuditorMindi
catesMthatMtheMmanagerMverifiesMprocessMcomplianceMbyMperformingMaMmonthlyMrevi
ewMviaMuncompletedMurgentMchange.
InMthisMcase,MwhichMoneMisMtheMbiggestMrisk?
A.MAuditMrisk
B.MDetectionMrisk
C.MInherentMrisk
D.MControlMriskM-MAnswerMC.MInherentMrisk
Auditor CISA Exam Questions and
Answers
InformationMsystemMauditorsMhaveMidentifiedMseparationMofMdutiesMinMenterpriseMreso
urceMplanningM(ERP)Msystems.
WhichMofMtheMfollowingMisMtheMbestMwayMtoMpreventMrepetitiveMconfigurationMfrom
Moccurring?
A.MUseMaMrole-basedMmodelMtoMgrantMuserMaccess
B.MRegularlyMmonitorMaccessMrights
C.MCorrectingMseparationMofMduties
D.MReferenceMstandardMuserMaccessMmatrixM-MAnswerMA.MUseMaMrole-
basedMmodelMtoMgrantMuserMaccess
WhichMofMtheMfollowingMshouldMbeMtheMmostMimportantMfactorMdrivingMaMsingleMap
plicationMavailabilityMrequirementMwhenMdevelopingMaMdisasterMrecoveryMplan?
A.MConfidentialityMofMdataMprocessedMbyMtheMapplication
B.MTheMcriticalityMofMtheMbusinessMprocessesMsupportedMbyMtheMapplication
C.MTotalMcostMofMownershipM(TCO)MofMtheMapplication
D.MSupportMtheMapplication'sMnetworkMbandwidthM-
MAnswerMB.MTheMcriticalityMofMtheMbusinessMprocessesMsupportedMbyMtheMapplication
InMorderMtoMdevelopMaMrobustMdataMsecurityMprogram,MtheMfirstMstepMyouMshould
MtakeMis:
A.MTalkMtoMtheMseniorMmanagementMlevelMofMIT.
B.MImplementMmonitoringMcontrols.
C.MImplementMdataMlossMpreventionMmeasures
D.MPerformMinventoryMofMassetsM-MAnswerMD.MPerformMinventoryMofMassets
heMadvantageMofMobject-orientedMsystemMdevelopmentMisMthatMit:
A.MSuitableMforMdataMwithMcomplexMrelationships
B.MPartitionMtheMsystemMasMaMclientMserverMarchitecture
, C.MEasierMtoMprogramMthanMproceduralMlanguages
D.MReduceMsystemMdocumentationMrequirementsM-
MAnswerMA.MSuitableMforMdataMwithMcomplexMrelationships
SeveralMportableMcomputersMcontainingMcustomer-
sensitiveMdataMwereMstolenMfromMtheMstaff'sMofficeMbecauseMtheyMwereMunattended.
WhichMofMtheMfollowingMisMtheMbestMadviceMforManMinformationMsystemsMauditorMt
oMprotectMdataMwhenMitMpreventsMsimilarMincidentsMfromMhappeningMagain?
A.MEnhanceMphysicalMsecurity
B.MEncryptedMdiskMdrive
C.MRequestMforMdualMcertification
D.MRequiresMtheMuseMofMaMcableMlockM-MAnswerMA.MEnhanceMphysicalMsecurity
DuringMtheMphysicalMsecurityMaudit,MtheMinformationMsystemMauditorMreceivedMaMcont
actlessMproximityMcardMthatMallowedMtoMaccessMtoMthreeMspecificMfloorsMofMtheMcor
porateMofficeMbuilding.
WhichMofMtheMfollowingMquestionsMshouldMbeMtheMbiggestMconcern?
A.MInMtheMfirstMtwoMdaysMofMfieldMworkMofMaudit,MtheMproximityMcardMdidMnotM
work.
B.MNoMfollow-upMwasMmadeMforMunsuccessfulMattemptsMtoMaccessMviolations.
C.MTheMproximityMcardMincorrectlyMgrantsMaccessMtoMtheMrestrictedMzone
D.MNoMescortMrequiredMduringMfieldMwork.M-
MAnswerMC.MTheMproximityMcardMincorrectlyMgrantsMaccessMtoMtheMrestrictedMzone
TheMcompany'sMoperationalMproceduresMrequireMurgentMchangesMtoMbeMapprovedMfor
MbusinessMwithinM7MdaysMofMtheMoccurrence.MTheMInformationMSystemsMAuditorMindi
catesMthatMtheMmanagerMverifiesMprocessMcomplianceMbyMperformingMaMmonthlyMrevi
ewMviaMuncompletedMurgentMchange.
InMthisMcase,MwhichMoneMisMtheMbiggestMrisk?
A.MAuditMrisk
B.MDetectionMrisk
C.MInherentMrisk
D.MControlMriskM-MAnswerMC.MInherentMrisk