CISA Exam Questions (QAE) With
Correct Answers
An IS auditor finds a small number of user access requests that were not
| | | | | | | | | | | | |
|authorized by managers through the normal predefined workflow steps
| | | | | | | |
|and escalation rules. The IS auditor should - CORRECT
| | | | | | | | |
ANSWER✔✔-:The IS auditor needs to perform substantive testing and | | | | | | | | |
additional analysis to determine why the approval and workflow
| | | | | | | | |
processes are not working as intended. Before making any
| | | | | | | | |
recommendation, the IS auditor should gain a good understanding of | | | | | | | | | |
the scope of the problem and the factors that caused this incident. The
| | | | | | | | | | | | |
IS auditor should identify whether the issue was caused by managers
| | | | | | | | | | |
not following procedures, a problem with the workflow of the
| | | | | | | | | |
automated system or a combination of the two. | | | | | | |
An internal IS audit function is planning a general IS audit. Which of the
| | | | | | | | | | | | | |
following activities takes place during the FIRST step of the planning
| | | | | | | | | | |
phase? - CORRECT ANSWER✔✔-A risk assessment should be performed
| | | | | | | |
|to determine how internal audit resources should be allocated to
| | | | | | | | | |
ensure that all material items will be addressed.
| | | | | | |
During an IS audit, which is the BEST method for an IS auditor to
| | | | | | | | | | | | | |
evaluate the implementation of segregation of duties within an IT
| | | | | | | | | |
department? - CORRECT ANSWER✔✔-Discussing the implementation of | | | | | |
,| segregation of duties with the IT managers is the best way to determine
| | | | | | | | | | | |
| how responsibilities are assigned within the department.
| | | | | |
An IS auditor reviewing a network log discovers that an employee ran
| | | | | | | | | | | |
elevated commands on their PC by invoking the task scheduler to launch
| | | | | | | | | | |
restricted applications. This is an example what type of attack? -
| | | | | | | | | | | |
CORRECT ANSWER✔✔-This is a type of attack where higher-level
| | | | | | | | |
system authority is obtained by various methods. In this example, the
| | | | | | | | | | |
task scheduler service runs with administrator permissions, and a
| | | | | | | | |
security flaw allows programs launched by the scheduler to run at the
| | | | | | | | | | | |
same permission level. | |
An IS auditor reviewing digital rights management applications should
| | | | | | | | |
expect to find an extensive use for which of the following technologies?
| | | | | | | | | | |
|- CORRECT ANSWER✔✔-This is a technique for concealing the existence
| | | | | | | | |
|of messages or information within another message. An increasingly
| | | | | | | | |
important steganographical technique is digital watermarking, which
| | | | | | |
hides data within data (e.g., by encoding rights information in a picture
| | | | | | | | | | | |
or music file without altering the picture or music's perceivable
| | | | | | | | | |
aesthetic qualities). |
An IS auditor recommends that an initial validation control be
| | | | | | | | | |
programmed into a credit card transaction capture application. The
| | | | | | | | |
initial validation process would MOST likely - CORRECT
| | | | | | | |
ANSWER✔✔-:The initial validation should confirm whether the card is | | | | | | | | |
, valid. This validity is established through the card number and personal
| | | | | | | | | | |
identification number entered by the user. | | | | |
Which of the following preventive controls BEST helps secure a web
| | | | | | | | | | |
application? - CORRECT ANSWER✔✔-Of the given choices, teaching | | | | | | | |
developers to write secure code is the best way to secure a web
| | | | | | | | | | | | |
application.
An IS auditor is testing employee access to a large financial system, and
| | | | | | | | | | | | |
the IS auditor selected a sample from the current employee list
| | | | | | | | | | |
provided by the auditee. Which of the following evidence is the MOST
| | | | | | | | | | | |
reliable to support the testing? - CORRECT ANSWER✔✔-The access list
| | | | | | | | | |
generated by the system is the most reliable, because it is the most
| | | | | | | | | | | | |
objective evidence to perform a comparison against the samples
| | | | | | | | |
selected. The evidence is objective, because it was generated by the
| | | | | | | | | | |
system rather than by an individual.| | | | |
While reviewing the process for continuous monitoring of the capacity
| | | | | | | | | |
and performance of IT resources, an IS auditor should PRIMARILY ensure
| | | | | | | | | |
that the process is focused on - CORRECT ANSWER✔✔-:Accurate
| | | | | | | | | |
capacity monitoring of IT resources would be the most critical element
| | | | | | | | | | |
of a continuous monitoring process.
| | | |
Which of the following processes will be MOST effective in reducing the
| | | | | | | | | | | |
risk that unauthorized software on a backup server is distributed to the
| | | | | | | | | | | |
production server? - CORRECT ANSWER✔✔-It is common practice for
| | | | | | | | |
Correct Answers
An IS auditor finds a small number of user access requests that were not
| | | | | | | | | | | | |
|authorized by managers through the normal predefined workflow steps
| | | | | | | |
|and escalation rules. The IS auditor should - CORRECT
| | | | | | | | |
ANSWER✔✔-:The IS auditor needs to perform substantive testing and | | | | | | | | |
additional analysis to determine why the approval and workflow
| | | | | | | | |
processes are not working as intended. Before making any
| | | | | | | | |
recommendation, the IS auditor should gain a good understanding of | | | | | | | | | |
the scope of the problem and the factors that caused this incident. The
| | | | | | | | | | | | |
IS auditor should identify whether the issue was caused by managers
| | | | | | | | | | |
not following procedures, a problem with the workflow of the
| | | | | | | | | |
automated system or a combination of the two. | | | | | | |
An internal IS audit function is planning a general IS audit. Which of the
| | | | | | | | | | | | | |
following activities takes place during the FIRST step of the planning
| | | | | | | | | | |
phase? - CORRECT ANSWER✔✔-A risk assessment should be performed
| | | | | | | |
|to determine how internal audit resources should be allocated to
| | | | | | | | | |
ensure that all material items will be addressed.
| | | | | | |
During an IS audit, which is the BEST method for an IS auditor to
| | | | | | | | | | | | | |
evaluate the implementation of segregation of duties within an IT
| | | | | | | | | |
department? - CORRECT ANSWER✔✔-Discussing the implementation of | | | | | |
,| segregation of duties with the IT managers is the best way to determine
| | | | | | | | | | | |
| how responsibilities are assigned within the department.
| | | | | |
An IS auditor reviewing a network log discovers that an employee ran
| | | | | | | | | | | |
elevated commands on their PC by invoking the task scheduler to launch
| | | | | | | | | | |
restricted applications. This is an example what type of attack? -
| | | | | | | | | | | |
CORRECT ANSWER✔✔-This is a type of attack where higher-level
| | | | | | | | |
system authority is obtained by various methods. In this example, the
| | | | | | | | | | |
task scheduler service runs with administrator permissions, and a
| | | | | | | | |
security flaw allows programs launched by the scheduler to run at the
| | | | | | | | | | | |
same permission level. | |
An IS auditor reviewing digital rights management applications should
| | | | | | | | |
expect to find an extensive use for which of the following technologies?
| | | | | | | | | | |
|- CORRECT ANSWER✔✔-This is a technique for concealing the existence
| | | | | | | | |
|of messages or information within another message. An increasingly
| | | | | | | | |
important steganographical technique is digital watermarking, which
| | | | | | |
hides data within data (e.g., by encoding rights information in a picture
| | | | | | | | | | | |
or music file without altering the picture or music's perceivable
| | | | | | | | | |
aesthetic qualities). |
An IS auditor recommends that an initial validation control be
| | | | | | | | | |
programmed into a credit card transaction capture application. The
| | | | | | | | |
initial validation process would MOST likely - CORRECT
| | | | | | | |
ANSWER✔✔-:The initial validation should confirm whether the card is | | | | | | | | |
, valid. This validity is established through the card number and personal
| | | | | | | | | | |
identification number entered by the user. | | | | |
Which of the following preventive controls BEST helps secure a web
| | | | | | | | | | |
application? - CORRECT ANSWER✔✔-Of the given choices, teaching | | | | | | | |
developers to write secure code is the best way to secure a web
| | | | | | | | | | | | |
application.
An IS auditor is testing employee access to a large financial system, and
| | | | | | | | | | | | |
the IS auditor selected a sample from the current employee list
| | | | | | | | | | |
provided by the auditee. Which of the following evidence is the MOST
| | | | | | | | | | | |
reliable to support the testing? - CORRECT ANSWER✔✔-The access list
| | | | | | | | | |
generated by the system is the most reliable, because it is the most
| | | | | | | | | | | | |
objective evidence to perform a comparison against the samples
| | | | | | | | |
selected. The evidence is objective, because it was generated by the
| | | | | | | | | | |
system rather than by an individual.| | | | |
While reviewing the process for continuous monitoring of the capacity
| | | | | | | | | |
and performance of IT resources, an IS auditor should PRIMARILY ensure
| | | | | | | | | |
that the process is focused on - CORRECT ANSWER✔✔-:Accurate
| | | | | | | | | |
capacity monitoring of IT resources would be the most critical element
| | | | | | | | | | |
of a continuous monitoring process.
| | | |
Which of the following processes will be MOST effective in reducing the
| | | | | | | | | | | |
risk that unauthorized software on a backup server is distributed to the
| | | | | | | | | | | |
production server? - CORRECT ANSWER✔✔-It is common practice for
| | | | | | | | |