• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 124 pages
Exam (elaborations)

CISA Questions 201 – 300 Exam #Questions with correct answers

Document preview thumbnail
Preview 4 out of 124 pages

CISA Questions 201 – 300 Exam #Questions with correct answers

Content preview

CISA Questions 201 – 300 Exam #Questions with correct
answers
An IS auditor reviewing an outsourcing contract of IT facilities would expect it to
define the:


Select an answer:
A.
hardware configuration.


B.
access control software.


C.
ownership of intellectual property.


D.

application development methodology. - ✔✔You are correct, the answer is C.


A. The hardware configuration is generally irrelevant as long as the functionality,
availability and security can be affected, which are specific contractual
obligations.


B. The access control software is generally irrelevant as long as the functionality,
availability and security can be affected, which are specific contractual
obligations.

,C. The contract must specify who owns the intellectual property (i.e., information
being processed, application programs). Ownership of intellectual property will
have a significant cost and is a key aspect to be defined in an outsourcing
contract.


D. The development methodology should be of no real concern in an outsourcing
contract.


An IS auditor has been assigned to review IT structures and activities recently
outsourced to various providers. Which of the following should the IS auditor
determine FIRST?


Select an answer:
A.
An audit clause is present in all contracts.


B.
The service level agreement (SLA) of each contract is substantiated by appropriate
key performance indicators (KPIs).


C.
The contractual warranties of the providers support the business needs of the
organization.


D.
At contract termination, support is guaranteed by each outsourcer for new
outsourcers. - ✔✔You answered A. The correct answer is C.

,A. All other choices are important, but the first step is to ensure that the contracts
support the business—only then can an audit process be valuable.


B. All service level agreements (SLAs) should be measureable and reinforced
through key performance indicators (KPIs)—but the first step is to ensure that the
SLAs are aligned with business requirements.


C. The primary requirement is for the services provided by the outsource supplier
to meet the needs of the business.


D. Having appropriate controls in place for contract termination are important,
but first the IS auditor must be focused on the requirement of the supplier to
meet business needs.


With respect to the outsourcing of IT services, which of the following conditions
should be of GREATEST concern to an IS auditor?


Select an answer:
A.
Core activities that provide a differentiated advantage to the organization have
been outsourced.


B.
Periodic renegotiation is not specified in the outsourcing contract.


C.

, The outsourcing contract fails to cover every action required by the business.


D.

Similar activities are outsourced to more than one vendor. - ✔✔You answered C.
The correct answer is A.


A. An organization's core activities generally should not be outsourced because
they are what the organization does best; an IS auditor observing that should be
concerned.


B. An IS auditor should not be concerned about periodic renegotiation in the
outsourcing contract because that is dependent on the term of the contract.


C. Outsourcing contracts cannot be expected to cover every action and detail
expected of the parties involved, but should cover business requirements.


D. Multisourcing is an acceptable way to reduce risk associated with a single point
of failure.


While conducting an audit of a service provider, an IS auditor observes that the
service provider has outsourced a part of the work to another provider. Because
the work involves confidential information, the IS auditor's PRIMARY concern
should be that the:


A.
requirement for protecting confidentiality of information could be compromised.

Document information

Uploaded on
July 17, 2026
Number of pages
124
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$13.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
0
Followers
0
Items
1205
Last sold
-



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions