
Ultimate Guide to Prepare Free ISACA CISA Exam Questions & Answer
Pass ISACA CISA Tests Engine pdf - All Free Dumps
Who Should Take CISA Certification Exam?
The ISACA CISA certification exam is suitable for anyone who wants to develop skills in auditing, controlling, and keeping the highest standards in information security. This exam was designed for IT and IS auditors who want to take a step further in their careers. It was also developed for assurance, control, and information security specialists. When it comes to eligibility requirements, ISACA is very clear in offering the right information. Therefore, candidates should demonstrate that they should have a minimum of 5 years of experience in IT or IS audit. They should also be skilled in control, assurance, or security. Besides, experience waivers are also possible and they can be of a maximum of 3 years.
As a renowned validation among tech specialists, the Isaca CISA exam can strategically help in plotting your career goals. This certification test is designed to fortify your command in information systems and management. It’s one of the most practical validations for mid-career individuals eyeing to take the next step in their careers.
NEW QUESTION 489
Which of the following is widely accepted as one of the critical components in networking management?
- A. Application of monitoring tools
- B. Topological mappings
- C. Proxy server troubleshooting
- D. Configuration management
Answer: D
Explanation:
Explanation/Reference:
Explanation:
Configuration management is widely accepted as one of the key components of any network, since it establishes how the network will function internally and externally, it also deals with the management of configuration and monitoring performance. Topological mappings provide outlines of the components of the network and its connectivity. Application monitoring is not essential and proxy server troubleshooting is used for troubleshooting purposes.
NEW QUESTION 490
Which of the following is a distinguishing feature at the highest level of a maturity model?
D18912E1457D5D1DDCBD40AB3BF70D5D
- A. Projects are controlled with management supervision.
- B. A continuous improvement process is applied.
- C. There are formal standards and procedures.
- D. Processes are monitored continuously.
Answer: B
NEW QUESTION 491
Email required for business purposes is being stored on employees' personal devices. Which of the
following is an IS auditor's BEST recommendation?
- A. Require employees to utilize passwords on personal devices.
- B. Implement an email containerization solution on personal devices
- C. Prohibit employees from storing company email on personal devices.
- D. Ensure antivirus to utilize passwords on personal devices.
Answer: A
Explanation:
Section: Protection of Information Assets
NEW QUESTION 492
A financial institution has a system interface that is used by its branches to obtain applicable currency exchange rates when processing transactions Which of the following should be the PRIMARY control objective for maintaining the security of the system interface?
- A. Ensuring the availability of the data being transferred
- B. Ensuring the integrity of the data being transferred
- C. Preventing unauthorized access to the data via interception
- D. Preventing unauthorized access to the data via malicious activity
Answer: B
NEW QUESTION 493
Business units are concerned about the performance of a newly implemented system. Which of the following should an IS auditor recommend?
- A. implement the changes users have suggested.
- B. Develop a baseline and monitor system usage.
- C. Define alternate processing procedures.
- D. Prepare the maintenance manual.
Answer: B
Explanation:
Explanation/Reference:
Explanation:
An IS auditor should recommend the development of a performance baseline and monitor the system's performance, against the baseline, to develop empirical data upon which decisions for modifying the system can be made. Alternate processing proceduresand a maintenance manual will not alter a system's performance. Implementing changes without knowledge of thecause(s)forthe perceived poor performance may not result in a more efficient system.
NEW QUESTION 494
In a public key infrastructure (PKI), the authority responsible for the identification and authentication of an applicant for a digital certificate (i.e., certificate subjects) is the:
- A. issuing certification authority (CA).
- B. registration authority (RA).
- C. policy management authority.
- D. subject CA.
Answer: B
Explanation:
Explanation/Reference:
Explanation:
A RA is an entity that is responsible for identification and authentication of certificate subjects, but the RA does not sign or issue certificates. The certificate subject usually interacts with the RA for completing the process of subscribing to the services of the certification authority in terms of getting identity validated with standard identification documents, as detailed in the certificate policies of the CA. In the context of a particular certificate, the issuing CA is the CA that issued the certificate. In the context of a particular CA certificate, the subject CA is the CA whose public key is certified in the certificate.
NEW QUESTION 495
A company has implemented a new client-server enterprise resource planning (ERP) system. Local branches transmit customer orders to a central manufacturing facility. Which of the following would BEST ensure that the orders are entered accurately and the corresponding products are produced?
- A. Using hash totals in the order transmitting process
- B. Logging all customer orders in the ERP system
- C. Verifying production to customer orders
- D. Approving (production supervisor) orders prior to production
Answer: C
Explanation:
Explanation/Reference:
Explanation:
Verification will ensure that production orders match customer orders. Logging can be used to detect inaccuracies, but does not in itself guarantee accurate processing. Hash totals will ensure accurate order transmission, but not accurate processing centrally. Production supervisory approval is a time consuming, manual process that does not guarantee proper control.
NEW QUESTION 496
Which of the following BEST limits the impact of server failures in a distributed environment?
- A. Clustering
- B. Dial backup lines
- C. Redundant pathways
- D. Standby power
Answer: A
Explanation:
Explanation/Reference:
Explanation:
Clustering allows two or more servers to work as a unit, so that when one of them fails, the other takes over. Choices A and C are intended to minimize the impact of channel communications failures, but not a server failure. Choice D provides an alternative power source in the event of an energy failure.
NEW QUESTION 497
An organization can ensure that the recipients of e-mails from its employees can authenticate the identity of the sender by:
- A. encrypting all e-mail messages.
- B. digitally signing all e-mail messages.
- C. password protecting all e-mail messages.
- D. compressing all e-mail messages.
Answer: B
Explanation:
By digitally signing all e-mail messages, the receiver will be able to validate the authenticity of the sender. Encrypting all e-mail messages would ensure that only the intended recipient will be able to open the message; however, it would not ensure the authenticity of the sender. Compressing all e-mail messages would reduce the size of the message, but would not ensure the authenticity.
Password protecting all e-mail messages would ensure that only those who have the password would be able toopen the message; however, it would not ensure the authenticity of the sender.
NEW QUESTION 498
Which of the following is the MOST important reason for performing vulnerability assessments periodically?
- A. Technology risks must be mitigated.
- B. The current threat levels are being assessed.
- C. The environment changes constantly.
- D. Management requires regular reports.
Answer: C
Explanation:
Section: Protection of Information Assets
NEW QUESTION 499
Which of the following provides the MOST comprehensive understanding of an organizations information security posture?
- A. Risk management metrics
- B. External audit findings
- C. Results of vulnerability assessments
- D. The organizationEtms security incident trends
Answer: A
NEW QUESTION 500
Which of the following provides the MOST comprehensive understanding of an organizations information security posture?
- A. Risk management metrics
- B. The organization's security incident trends
- C. External audit findings
- D. Results of vulnerability assessments
Answer: A
NEW QUESTION 501
To develop a successful business continuity plan, end user involvement is critical during which of the following phases?
- A. Detailed plan development
- B. Business impact analysis (BIA)
- C. Business recovery strategy
- D. Testing and maintenance
Answer: B
Explanation:
Section: Protection of Information Assets
Explanation:
End user involvement is critical in the BIA phase. During this phase the current operations of the business needs to be understood and the impact on the business of various disasters must be evaluated. End users are the appropriate persons to provide relevant information for these tasks, inadequate end user involvement in this stage could result in an inadequate understanding of business priorities and the plan not meeting the requirements of the organization.
NEW QUESTION 502
An auditor observes that time to complete routine backups of operational databases is steadily increasing. When of the following would MOST effectively help to reduce backup and recovery times for operational databases?
- A. Utilizing efficient database backup technologies to achieve efficiencies
- B. Using sold storage device (SSD) media
- C. Requiring daily full backups
- D. Archiving data in accordance with the data retention policy
Answer: D
NEW QUESTION 503
What is used to provide authentication of the website and can also be used to successfully authenticate
keys used for data encryption?
- A. A user certificate
- B. A website certificate
- C. An organizational certificate
- D. Authenticode
Answer: B
Explanation:
Section: Protection of Information Assets
Explanation:
A website certificate is used to provide authentication of the website and can also be used to successfully
authenticate keys used for data encryption.
NEW QUESTION 504
Which of the following should be of GREATEST concern to an IS auditor conducting an audit of an organization's backup processes?
- A. The restoration process is slow due to connectivity issues.
- B. The service levels are not achieved.
- C. Backup failures are not resolved in a timely manner.
- D. A written backup policy is not available.
Answer: B
Explanation:
Section: The process of Auditing Information System
Explanation/Reference:
NEW QUESTION 505
When protecting an organization's IT systems, which of the following is normally the next line of defense after the network firewall has been compromised?
- A. Antivirus programs
- B. Virtual local area network (VLAN) configuration
- C. Personal firewall
- D. Intrusion detection system (IDS)
Answer: D
Explanation:
An intrusion detection system (IDS) would be the next line of defense after the firewall. It would detect anomalies in the network/server activity and try to detect the perpetrator. Antivirus programs, personal firewalls and VI_AN configurations would be later in the line of defense.
NEW QUESTION 506
The PRIMARY reason an IS department should analyze past incidents and problems is to:
- A. determine if all incidents and problems are reported.
- B. identify the causes of recurring incidents and problems.
- C. assess help desk performance.
- D. assign responsibility for problems.
Answer: B
Explanation:
Section: Protection of Information Assets
NEW QUESTION 507
Which of the following encryption techniques will BEST protect a wireless network from a man-in-the- middle attack?
- A. Randomly generated pre-shared key (PSKJ)
- B. 128-bit wired equivalent privacy (WEP)
- C. Alphanumeric service set identifier (SSID)
- D. MAC-basedpre-sharedkey (PSK)
Answer: A
Explanation:
Explanation/Reference:
Explanation:
A randomly generated PSK is stronger than a MAC-based PSK, because the MAC address of a computer is fixed and often accessible. WEP has been shown to be a very weak encryption technique and can be cracked within minutes. The SSID is broadcast on the wireless network in plaintext.
NEW QUESTION 508
......
Certified Information Systems Auditor Practice Tests 2021 | Pass CISA with confidence!: https://drive.google.com/open?id=1ykcxP0fRt6cf78EhiNZ5G4e02Tb1uoG2
Online Exam Practice Tests with detailed explanations!: https://www.passsureexam.com/CISA-pass4sure-exam-dumps.html