Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 137 pages
Exam (elaborations)

CISA Domain 4 Actual Review Questions, Answers & Explanations Manual, 12th Edition Test Bank Recently Updated Complete Solution.pdf

Document preview thumbnail
Preview 4 out of 137 pages

CISA Domain 4 Actual Review Questions, Answers & Explanations Manual, 12th Edition Test Bank Recently Updated Complete S

Content preview

CISA Domain 4 Actual Review Questions, Answers & Explanations Manual, 12th Edition Test Bank Recently Updated
Complete Solution


CISA Domain 4 Actual Review Questions,
Answers & Explanations Manual, 12th
Edition Test Bank Recently Updated
Complete Solution

A4-1 An organization is considering using a new IT service provider. From an audit perspective, which of
the following would be the MOST important item to review?
A. References from other clients for the service provider
B. The physical security of the service provider site
C. The proposed service level agreement with the service provider

D. Background checks of the service provider's employees - ✔✔✔ - C is the correct answer. Justification:
A. A due diligence activity such as reviewing references from other clients is a good practice, but the
service level agreement (SLA) would be most critical because it would define what specific levels of
performance would be required and make the provider contractually obligated to deliver what was
promised.
B. A due diligence activity such as reviewing physical security controls is a good practice, but the SLA
would be most critical because it would define what specific levels of security would be required and
make the provider contractually obligated to deliver what was promised.
C. When contracting with a service provider, it is a good practice to enter into an SLA with the provider.
An SLA is a guarantee that the provider will deliver the services according to the contract. The IS auditor
will want to ensure that performance and security requirements are clearly stated in the SLA.
D. A due diligence activity such as the use of background checks for the service provider's employees is a
good practice, but the SLA would be most critical because it would define what specific levels of security
and labor practices would be required and make the provider contractually obligated to deliver what
was promised.




A4-2 An IS auditor is to assess the suitability of a service level agreement (SLA) between the organization
and the supplier of outsourced services. To which of the following observations should the IS auditor
pay the MOST attention? The SLA does not contain a:
A. transition clauses from the old supplier to a new supplier or back to internal in the case of expiration
or termination.
B. late payment clause between the customer and the supplier.

1
©™

, CISA Domain 4 Actual Review Questions, Answers & Explanations Manual, 12th Edition Test Bank Recently Updated
Complete Solution

C. contractual commitment for service improvement.

D. dispute resolution procedure between the contracting parties. - ✔✔✔ - A is the correct answer.
Justification:
A. The delivery of IT services for a specific customer always implies a dose linkage between the client
and the supplier of the service. If there are no contract terms to specify how the transition to a new
supplier may be performed, there is the risk that the old supplier may simply "pull the plug" if the
contract expires or is terminated or may not make data available to the outsourcing organization or new
supplier. This would be the greatest risk to the organization.
B. Contractual issues regarding payment, service improvement and dispute resolution are important but
not as critical as ensuring that service disruption, data loss, data retention, or other significant events
occur in the event that the organization switches to a new firm providing outsourced services.
C. The service level agreement (SLA) should address performance requirements and metrics to report on
the status of services provided; it's nice to have commitment for performance improvement, although
it's not mandated.
D. The SLA should address a dispute resolution procedure and specify the jurisdiction in case of a legal
dispute, but this is not the most critical part of an SLA.




A4-3 An IS auditor reviewing a new outsourcing contract with a service provider would be MOST
concerned if which of the following was missing?
A. A clause providing a "right to audit" the service provider
B. A clause defining penalty payments for poor performance
C. Predefined service level report templates

D. A clause regarding supplier limitation of liability - ✔✔✔ - A is the correct answer. Justification:
A. The absence of a "right to audit" clause or other form of attestation that the supplier was compliant
with a certain standard would potentially prevent the IS auditor from investigating any aspect of
supplier performance moving forward, including control deficiencies, poor performance and adherence
to legal requirements. This would be a major concern for the IS auditor because it would be difficult for
the organization to assess whether the appropriate controls had been put in place.
B. While a clear definition of penalty payment terms is desirable, not all contracts require the payment
of penalties for poor performance, and when performance penalties are required, these penalties are
often subject to negotiation on a case-by-case basis. As such, the absence of this information would not
be as significant as a lack of right to audit.
C. While the inclusion of service level report templates would be desirable, as long as the requirement
for service level reporting is included in the contract, the absence of predefined templates for reporting
is not a significant concern.




2
©™

, CISA Domain 4 Actual Review Questions, Answers & Explanations Manual, 12th Edition Test Bank Recently Updated
Complete Solution

D. The absence of a limitation of liability clause for the service provider would, theoretically, expose the
provider to unlimited liability. This would be to the advantage of the outsourcing company so, while the
IS auditor might highlight the absence of such a clause, it would not constitute a major concern.




A4-4 When reviewing the desktop software compliance of an organization, the IS auditor should be
MOST concerned if the installed software:
A. was installed, but not documented in the IT department records.
B. was being used by users not properly trained in its use.
C. is not listed in the approved software standards document.

D. license will expire in the next 15 days. - ✔✔✔ - C is the correct answer. Justification:
A. All software, including licenses, should be documented in IT department records, but this is not as
serious as the violation of policy in installing unapproved software.
B. Discovering that users have not been formally trained in the use of a software product is common,
and while not ideal, most software includes help files and other tips that can assist in learning how to
use the software effectively.
C. The installation of software that is not allowed by policy is a serious violation and could put the
organization at security, legal and financial risk. Any software that is allowed should be part of a
standard software list. This is the first thing to review because this would also indicate compliance with
policies.
D. A software license that is about to expire is not a risk if there is a-process in place to renew it.




A4-5 An IS auditor of a health care organization is reviewing contractual terms and conditions of a third-
party cloud provider being considered to host patient health information. Which of the follow
contractual terms would be the GREATEST risk to the customer organization?
A. Data ownership is retained by the customer organization.
B. The third-party provider reserves the right to access data to perform certain operations.
C. Bulk data withdrawal mechanisms are undefined.

D. The customer organization is responsible for backup, archive and restore. - ✔✔✔ - B is the correct
answer. Justification:
A. The customer organization would want to retain data ownership and, therefore, this would not be a
risk.
B. Some service providers reserve the right to access customer information (third-party access) to
perform certain transactions and provide certain services. In the case of protected health information,


3
©™

, CISA Domain 4 Actual Review Questions, Answers & Explanations Manual, 12th Edition Test Bank Recently Updated
Complete Solution

regulations may restrict certain access. Organizations must review the regulatory environment in which
the cloud provider operates because it may have requirements or restrictions of its own. Organizations
must then determine whether the cloud provider provides appropriate controls to ensure that data are
appropriately secure.
C. An organization may eventually wish to discontinue its service with a third-party cloud-based
provider. The organization would then want to remove its data from the system and ensure that the
service provider clears the system (including any backups) of its data. Some providers do not offer
automated or bulk data withdrawal mechanisms, which the organization needs to migrate its data.
These aspects should be clarified prior to using a third-party provider.
D. An organization may need to plan its own data recovery processes and procedures if the service
provider does not make this available or the organization has doubts about the service provider's
processes. This would only be a risk if the customer organization was unable to perform these activities
itself.




Which of the following recovery strategies is MOST appropriate for a business having multiple offices
within a region and a limited recovery budget?
A. A hot site maintained by the business
B. A commercial cold site
C. A reciprocal arrangement between its offices

D. A third-party hot site - ✔✔✔ - C is the correct answer. Justification:
A. A hot site maintained by the business would be a costly solution but would provide a high degree of
confidence.
B. Multiplecold sites leased for the multiple offices would lead to an ineffective solution with poor
availability.
C. For a business having many offices within a region, a reciprocal arrangement among its offices would
be most appropriate. Each office could be designated as a recovery site for some other office. This
would be the least expensive approach and would provide an acceptable level of confidence.
D. A third-party facility for recovery is provided by a traditional hot site. This would be a costly approach
providing a high degree of confidence.




A4-7 During an application audit, an IS auditor is asked to provide assurance of the database referential
integrity. Which of the following should be reviewed?
A. Field definition
B. Master table definition


4
©™

Document information

Uploaded on
March 7, 2025
Number of pages
137
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$12.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
LearnSphere
4.0
(84)
Sold
405
Followers
321
Items
3757
Last sold
2 months ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions