UPDATED [Oct 04, 2023] Pass Certified Information Systems Auditor Exam with Latest Questions [Q262-Q280]

Share

UPDATED [Oct 04, 2023] Pass Certified Information Systems Auditor Exam with Latest Questions

CISA Exam Practice Questions prepared by ISACA Professionals


Governance & Management of IT: This section is designed to evaluate one’s capability to identify different critical concerns and recommend specific enterprise practices to safeguard and support information governance and related technologies. These include the following:

  • IT Management – IT resource management; service provider management and acquisition; quality management and quality assurance of IT; IT performance reporting and monitoring.
  • IT Governance – IT governance & IT strategy; IT policies, procedures, and standards; IT-related frameworks; organizational and enterprise structures; enterprise risk management; maturity models;

 

NEW QUESTION # 262
Which of the following refers to any program that invites the user to run it but conceals a harmful or malicious payload?

  • A. trojan horse
  • B. worm
  • C. None of the choices.
  • D. virus
  • E. spyware
  • F. rootkits

Answer: A


NEW QUESTION # 263
Which of the following is the MOST important consideration when establishing vulnerability scanning on critical IT infrastructure?

  • A. The scanning will not degrade system performance.
  • B. The scanning will be cost-effective.
  • C. The scanning will be performed during non-peak hours.
  • D. The scanning will be followed by penetration testing.

Answer: C

Explanation:
Section: Information System Acquisition, Development and Implementation Explanation


NEW QUESTION # 264
Which of the following functions should be performed by the application owners to ensure an adequate segregation of duties between IS and end users?

  • A. System analysis
  • B. Data administration
  • C. Authorization of access to data
  • D. Application programming

Answer: C

Explanation:
Explanation/Reference:
Explanation:
The application owner is responsible for authorizing access to data. Application development and programming are functions of the IS department. Similarly, system analysis should be performed by qualified persons in IS who have knowledge of IS and user requirements. Data administration is a specialized function related to database management systems and should be performed by qualified database administrators.


NEW QUESTION # 265
An IS auditor is evaluating management's risk assessment of information systems. The IS auditor should FIRST review:

  • A. the effectiveness of the controls in place.
  • B. the controls already in place.
  • C. the mechanism for monitoring the risks related to the assets.
  • D. the threats/vulnerabilities affecting the assets.

Answer: D

Explanation:
One of the key factors to be considered while assessing the risks related to the use of various information systems is the threats and vulnerabilities affecting the assets. The risks related to the use of information assets should be evaluated in isolation from the installed controls. Similarly, the effectiveness of the controls should be considered during the risk mitigation stage and not during the risk assessment phase A mechanism to continuously monitor the risks related to assets should be put in place during the risk monitoring function that follows the risk assessment phase.


NEW QUESTION # 266
Which of the following is by far the most common prevention system from a network security perspective?

  • A. None of the choices.
  • B. Tripwire
  • C. Firewall
  • D. IDS
  • E. IPS
  • F. Hardened OS

Answer: C

Explanation:
Section: Protection of Information Assets
Explanation:
User account access controls and cryptography can protect systems files and data, respectively. On the other hand, firewalls are by far the most common prevention systems from a network security perspective as they can shield access to internal network services, and block certain kinds of attacks through packet filtering.


NEW QUESTION # 267
Doing which of the following during peak production hours could result in unexpected downtime?

  • A. Performing preventive maintenance on electrical systems
  • B. Promoting applications from development to the staging environment
  • C. Replacing a failed power supply in the core router of the data center
  • D. Performing data migration or tape backup

Answer: A

Explanation:
Choices A and C are processing events which may impact performance, but would not cause downtime. Enterprise-class routers have redundant hot-swappable power supplies, so replacing a failed power supply should not be an issue. Preventive maintenanceactivities should be scheduled for non-peak times of the day, and preferably during a maintenance window time period. A mishap or incident caused by a maintenance worker could result in unplanned downtime.


NEW QUESTION # 268
An IS auditor discovers that developers have operator access to the command line of a production environment operating system. Which of the following controls wou Id BEST mitigate the risk of undetected and unauthorized program changes to the production environment?

  • A. Commands typed on the command line are logged
  • B. Software development tools and compilers have been removed from the production environment
  • C. Access to the operating system command line is granted through an access restriction tool with preapproved rights
  • D. Hash keys are calculated periodically for programs and matched against hash keys calculated for the most recent authorized versions of the programs

Answer: D

Explanation:
The matching of hash keys over time would allow detection of changes to files. Choice A is incorrect because having a log is not a control, reviewing the log is a control. Choice C is incorrect because the access was already granted-it does notmatter how. Choice D is wrong because files can be copied to and from the production environment.


NEW QUESTION # 269
Which of the following should an IS auditor review FIRST during the audit of an organization's business continuity plan (BCP)?

  • A. System recovery manuals and documentation
  • B. List of critical business processes
  • C. System recovery lime objectives (RTOs)
  • D. Frequency of business database replication

Answer: B


NEW QUESTION # 270
.Whenever an application is modified, what should be tested to determine the full impact of the change? Choose the BEST answer.

  • A. All programs, including interface systems with other applications or systems
  • B. Mission-critical functions and any interface systems with other applications or systems
  • C. Interface systems with other applications or systems
  • D. The entire program, including any interface systems with other applications or systems

Answer: D

Explanation:
Whenever an application is modified, the entire program, including any interface systems with other applications or systems, should be tested to determine the full impact of the change.


NEW QUESTION # 271
Minimum password length and password complexity verification are examples of:

  • A. audit objectives.
  • B. control procedures.
  • C. detection controls.
  • D. control objectives.

Answer: B

Explanation:
Section: Protection of Information Assets
Explanation:
Control procedures are practices established by management to achieve specific control objectives.
Password controls are preventive controls, not detective controls. Control objectives are declarations of expected results from implementing controls and audit objectives are the specific goals of an audit.


NEW QUESTION # 272
Why does an IS auditor review an organization chart?

  • A. To optimize the responsibilities and authority of individuals
  • B. To better understand the responsibilities and authority of individuals
  • C. To identify project sponsors
  • D. To control the responsibilities and authority of individuals

Answer: B

Explanation:
Section: Protection of Information Assets
Explanation:
The primary reason an IS auditor reviews an organization chart is to better understand the responsibilities
and authority of individuals.


NEW QUESTION # 273
What type of BCP test uses actual resources to simulate a system crash and validate the plan's
effectiveness?

  • A. Paper
  • B. Walk-through
  • C. Parallel
  • D. Preparedness

Answer: D

Explanation:
Section: Protection of Information Assets
Explanation:
Of the three major types of BCP tests (paper, walk-through, and preparedness), only the preparedness test
uses actual resources to simulate a system crash and validate the plan's effectiveness.


NEW QUESTION # 274
Which of the following is the BEST approach to make strategic information security decisions?

  • A. Establish periodic senior management meetings
  • B. Establish regular information security status reporting
  • C. Establish business unit security working groups
  • D. Establish an information security steering committee

Answer: D

Explanation:
Section: Governance and Management of IT


NEW QUESTION # 275
An IS auditor should be concerned when a telecommunication analyst:

  • A. monitors systems performance and tracks problems resulting from program changes.
  • B. recommends network balancing procedures and improvements.
  • C. reviews network load requirements in terms of current and future transaction volumes.
  • D. assesses the impact of the network load on terminal response times and network data transfer rates.

Answer: A

Explanation:
Explanation/Reference:
Explanation:
The responsibilities of a telecommunications analyst include reviewing network load requirements in terms of current and future transaction volumes {choice B), assessing the impact of network load or terminal response times and network data transferrates (choice C), and recommending network balancing procedures and improvements (choice D). Monitoring systems performance and tracking problems as a result of program changes {choice A) would put the analyst in a self-monitoring role.


NEW QUESTION # 276
Which of the following is the MOST effective control to restrict the use of instant messaging (IM) within an organization?

  • A. Antivirus software
  • B. Intrusion detection system (IDS)
  • C. Application-based firewall
  • D. Packet filtering firewall

Answer: D


NEW QUESTION # 277
Which of the following is MOST effective against system intrusions?

  • A. Penetration testing
  • B. Layered protection
  • C. Two-factor authentication
  • D. Continuous monitoring

Answer: B

Explanation:
Section: Protection of Information Assets


NEW QUESTION # 278
Which of the following is the PRIMARY advantage of using virtualization technology for corporate applications?

  • A. Stronger data security
  • B. Better utilization of resources
  • C. Improved disaster recovery
  • D. Increased application performance

Answer: C


NEW QUESTION # 279
A perpetrator looking to gain access to and gather information about encrypted data being transmitted over the network would use:

  • A. traffic analysis.
  • B. masquerading.
  • C. spoofing.
  • D. eavesdropping.

Answer: A

Explanation:
Explanation/Reference:
Explanation:
In traffic analysis, which is a passive attack, an intruder determines the nature of the traffic flow between defined hosts and through an analysis of session length, frequency and message length, and the intruder is able to guess the type of communication taking place. This typically is used when messages are encrypted and eavesdropping would not yield any meaningful results, in eavesdropping, which also is a passive attack, the intruder gathers the information flowing through the network withthe intent of acquiring and releasing message contents for personal analysis or for third parties. Spoofing and masquerading are active attacks, in spoofing, a user receives an e-mail that appears to have originated from one source when it actually was sent from another source. In masquerading, the intruder presents an identity other than the original identity.


NEW QUESTION # 280
......


ISACA CISA certification is a highly respected and recognized certification in the field of information systems auditing. It is a great way for professionals to enhance their career opportunities, increase their earning potential, and demonstrate their expertise in the field. To obtain the certification, candidates must pass a rigorous exam that covers five domains of information systems auditing, and there are many resources available to help them prepare.

 

CISA Exam Practice Materials Collection: https://www.passsureexam.com/CISA-pass4sure-exam-dumps.html

Use Valid New CISA Questions - Top choice Help You Gain Success: https://drive.google.com/open?id=1eTD0XJtdUKXZSuqQnIUXkuwmFjjx7OBa