Authentic Best resources for CISA Test Engine Practice Exam [Q230-Q255]

Share

Authentic Best resources for CISA Test Engine Practice Exam

[2023] CISA PDF Questions - Perfect Prospect To Go With ActualTestsQuiz Practice Exam


The ISACA CISA (Certified Information Systems Auditor) exam is a globally recognized certification program designed for professionals who aspire to become information systems auditors. This certification validates the knowledge and expertise of individuals in the areas of auditing, monitoring, and controlling information technology and business systems. It is an essential certification for professionals who want to advance their careers in the field of information systems auditing.


What Are Details of CISA Certification Exam?

All certification tests developed by ISACA have a standard structure. They include 150 questions that have a multiple-choice format. Candidates will have 240 minutes to answer as many questions as possible correctly. The exam fees are different and based on the applicants' membership. For instance, an ISACA member will pay $575 to register for the CISA exam. In case they are non-members, the registration fee becomes $760. It is essential to mention that all exam fees are non-refundable. To know more, this exam is available in different languages. Thus, examinees can take it in Chinese Traditional or Simplified, German, English, French, Italian, Japanese, Italian, Korean, Spanish, and Turkish. Before registering for the CISA, candidates need to know that this test is computer-based and is administered by PSI testing centers anywhere in the world. The registration process is continuous, which allows candidates to register without restrictions anytime. Also, the vendor recommends that applicants should schedule a testing appointment 48 hours after the candidate finalized the registration process. Once the registration is complete, exam-takers can take their test within one year after they register. Besides, an important step that examinees shouldn't forget is checking which is the nearest PSI test site to their home place.


The CISA certification is highly respected in the IT industry and is recognized by many organizations around the world, including government agencies, financial institutions, and multinational corporations. It is also a mandatory requirement for many information security positions and is often used as a benchmark for hiring and promotion decisions.

 

NEW QUESTION # 230
Which of the following areas of responsibility would cause the GREATEST segregation of duties conflict if
the individual who performs the related tasks also has approval authority?

  • A. Good receipts and payments
  • B. Purchase requisitions and purchase orders
  • C. Vendor selection and statements of work
  • D. Invoices and reconciliations

Answer: A

Explanation:
Section: Information System Operations, Maintenance and Support


NEW QUESTION # 231
A warehouse employee of a retail company has been able to conceal the theft of inventory items by entering adjustments of either damaged or lost stock items lo the inventory system. Which control would have BEST prevented this type of fraud in a retail environment?

  • A. Statistical sampling of adjustment transactions
  • B. Separate authorization for input of transactions
  • C. An edit check for the validity of the inventory transaction
  • D. Unscheduled audits of lost stock lines

Answer: B


NEW QUESTION # 232
An organization is using symmetric encryption. Which of the following would be a valid reason for moving to asymmetric encryption? Symmetric encryption:

  • A. provides authenticity.
  • B. is faster than asymmetric encryption.
  • C. requires a relatively simple algorithm.
  • D. can cause key management to be difficult.

Answer: D

Explanation:
Explanation/Reference:
Explanation:
In a symmetric algorithm, each pair of users needs a unique pair of keys, so the number of keys grows and key management can become overwhelming. Symmetric algorithms do not provide authenticity, and symmetric encryption is faster than asymmetric encryption. Symmetric algorithms require mathematical calculations, but they are not as complex as asymmetric algorithms.


NEW QUESTION # 233
An IS auditor finds that a key Internet-facing system is vulnerable to attack and that patches are not available. What should the auditor recommend be done FIRST?

  • A. Implement additional firewalls to protect the system.
  • B. Decommission the server.
  • C. Implement a new system that can be patched.
  • D. Evaluate the associated risk.

Answer: D


NEW QUESTION # 234
A USB device containing sensitive production data was lost by an employee and its contents were subsequently found published online Which of the following controls is the BEST recommendation to prevent a similar recurrence?

  • A. Monitoring data being downloaded on USB devices
  • B. Training users on USB device security
  • C. Electronically tracking portable devices
  • D. Using a strong encryption algorithm

Answer: D


NEW QUESTION # 235
When reviewing an organization's logical access security, which of the following should be of MOST concern to an IS auditor?

  • A. Passwords are not shared.
  • B. Redundant logon IDs are deleted.
  • C. The allocation of logon IDs is controlled.
  • D. Password files are not encrypted.

Answer: D

Explanation:
When evaluating the technical aspects of logical security, unencrypted files represent the greatest risk. The sharing of passwords, checking for the redundancy of logon IDs and proper logon ID procedures are essential, but they are less important than ensuring that the password files are encrypted.


NEW QUESTION # 236
During the implementation of a new system, an IS auditor must assess whether certain automated calculations comply with the regulatory requirements. Which of the following is the BEST way to obtain this assurance?

  • A. Review the source code related to the calculation.
  • B. Review sign-off documentation.
  • C. Re-perform the calculation with audit software.
  • D. Inspect user acceptance test results.

Answer: C

Explanation:
Section: The process of Auditing Information System
Explanation


NEW QUESTION # 237
.What are used as the framework for developing logical access controls?

  • A. Information systems security policies
  • B. Organizational charts for identifying roles and responsibilities
  • C. Access Control Lists (ACL)
  • D. Organizational security policies

Answer: A

Explanation:
Information systems security policies are used as the framework for developing logical access controls.


NEW QUESTION # 238
Which of the following is a continuity plan test that uses actual resources to simulate a system crash to cost-effectively obtain evidence about the plan's effectiveness?

  • A. Walk-through
  • B. Post test
  • C. Preparedness test
  • D. Paper test

Answer: C

Explanation:
Explanation/Reference:
Explanation:
A preparedness test is a localized version of a full test, wherein resources are expended in the simulation of a system crash. This test is performed regularly on different aspects of the plan and can be a cost- effective way to gradually obtain evidence about the plan's effectiveness. It also provides a means to improve the plan in increments.
Incorrect answers:
A. A paper test is a walkthrough of the plan, involving major players in the plan's execution who attempt to determine what might happen in a particular type of service disruption. A paper test usually precedes the preparedness test.
B. A post-test is actually a test phase and is comprised of a group of activities, such as returning all resources to their proper place, disconnecting equipment, returning personnel and deleting all company data from third- party systems.
D. A walk-through is a test involving a simulated disaster situation that tests the preparedness and understanding of management and staff, rather than the actual resources.


NEW QUESTION # 239
Which of the following would MOST likely impact the integrity of a database backup?

  • A. Open database files during backup
  • B. Relational database model used
  • C. Backing up the database to an optical disk
  • D. Record fields contain null information

Answer: A


NEW QUESTION # 240
Which of the following is an example of audit risk?

  • A. Sampling methods may not detect a material error.
  • B. Newer auditors may require additional supervision and training.
  • C. Management may disagree with audit conclusions.
  • D. Audit work may be lost due to a malware attack.

Answer: A

Explanation:
Section: Protection of Information Assets


NEW QUESTION # 241
An organization is replacing its financial processing system. To help ensure that transactions in the new system are processed accurately, which of the following is MOST appropriate?

  • A. Document and test internal controls over the conversion.
  • B. Reconcile results of parallel processing.
  • C. Review data file conversion procedures.
  • D. Compare year-to-date balances between the systems.

Answer: B

Explanation:
Section: Protection of Information Assets


NEW QUESTION # 242
Which of the following is the BEST way to identify the potential impact of a successful attack on an organization's mission critical applications?

  • A. Execute regular vulnerability scans
  • B. Perform an independent code review
  • C. Perform an application vulnerability review
  • D. Conduct penetration testing

Answer: D

Explanation:
Section: Protection of Information Assets


NEW QUESTION # 243
An IS auditor selects a server for a penetration test that will be carried out by a technical specialist. Which of the following is MOST important?

  • A. Permission from the data owner of the server
  • B. The tools used to conduct the test
  • C. An intrusion detection system (IDS) is enabled
  • D. Certifications held by the IS auditor

Answer: A

Explanation:
Explanation/Reference:
Explanation:
The data owner should be informed of the risks associated with a penetration test, what types of tests are to be conducted and other relevant details. All other choices are not as important as the data owner's responsibility for the security of the data assets.


NEW QUESTION # 244
Which of the following statement INCORRECTLY describes the Control self-assessment (CSA) approach?

  • A. CSA is policy or rule driven
  • B. In CSA, Staffs at all level, in all functions, are the primary control analyst.
  • C. CSA Empowered/accountable employees
  • D. CSA focuses on continuous improvement/learning curve

Answer: A

Explanation:
Section: The process of Auditing Information System
Explanation:
The word INCORRECTLY is the keyword used in the question. You need to find out an option which
incorrectly describes Control Self-assessment.
For your exam you should know the information below about control self-assessment:
Control self-assessment is an assessment of controls made by the staff and management of the unit or
units involved. It is a management technique that assures stakeholders, customers and other parties that
the internal controls of the organization are reliable.
Benefits of CSA
Early detection of risk
More efficient and improved internal controls
Creation of cohesive teams through employee involvement
Developing a sense of ownership of the controls in the employees and process owners, and reducing their
resistance to control improvement initiatives
Increased employee awareness of organizational objectives, and knowledge of risk and internal controls
Highly motivated employees
Improved audit training process
Reduction in control cost
Assurance provided to stakeholders and customers
Traditional and CSA attributes
Traditional Historical CSA
Assign duties/supervises staff Empowered/accountable employees
Policy/rule driven Continuous improvement/learning curve
Limited employee participation Extensive employee participation and training
Narrow stakeholders focus Broad stakeholders focus
Auditors and other specialist Staff at all level, in all functions, are the primary control analysts
The following answers are incorrect:
The other options specified are correctly describes about CSA.
The following reference(s) were/was used to create this question:
CISA review manual 2014 page number 61, 62 and 63


NEW QUESTION # 245
Which of the following should an IS auditor recommend for the protection of specific sensitive information stored in the data warehouse?

  • A. Enhance user authentication via strong passwords
  • B. implement column- and row-level permissions
  • C. Log user access to the data warehouse
  • D. Organize the data warehouse into subject matter-specific databases

Answer: B

Explanation:
Choice A specifically addresses the question of sensitive data by controlling what information users can access. Column-level security prevents users from seeing one or more attributes on a table. With row-level security a certain grouping of information on a table is restricted; e.g., if a table held details of employee salaries, then a restriction could be put in place to ensure that, unless specifically authorized, users could not view the salaries of executive staff. Column- and row-level security can be achieved in a relational database by allowing users to access logical representations of data rather than physical tables. This 'fine-grained' security model is likely to offer the best balance between information protection while still supporting a wide range of analytical and reporting uses. Enhancing user authentication via strong passwords is a security control that should apply to all users of the data warehouse and does not specifically address protection of sensitive datA . Organizing a data warehouse into subject-specific databases is a potentially useful practice but, in itself, does not adequately protect sensitive datA . Database-level security is normally too 'coarse' a level to efficiently and effectively protect information. For example, one database may hold information that needs to be restricted such as employee salary and customer profitability details while other information such as employee department may need to be legitimately a


NEW QUESTION # 246
What should an IS auditor do FIRST upon discovering that a service provider did not notify its customers of a security breach?

  • A. Notify audit management of the finding.
  • B. Require the third party to notify customers.
  • C. The audit report with a significant finding.
  • D. Notify law enforcement of the finding.

Answer: A


NEW QUESTION # 247
Which of the following BEST protects evidence in a forensic investigation?

  • A. imaging the affected system
  • B. Powering down the affected system
  • C. Protecting the hardware of the affected system
  • D. Rebooting the affected system

Answer: A

Explanation:
This creates a duplicate copy of the data that can be used for examination, while preserving the original evidence in its original state. This helps to ensure that the data is not altered or corrupted during the examination process and the integrity of the evidence is maintained.


NEW QUESTION # 248
An IS auditor is performing a routine procedure to test for the possible existence of fraudulent transactions.
Given there is no reason to suspect the existence of fraudulent transactions, which of the following data analytics techniques should be employed?

  • A. Regression analysis
  • B. Anomaly detection analysis
  • C. Classification analysis
  • D. Association analysis

Answer: B


NEW QUESTION # 249
An organization's IT security policy states that user ID's must uniquely identify individual's and that user should not disclose their passwords. An IS auditor discovers that several generic user ID's are being used.
Which of the following is the MOST appropriate course of action for the auditor?

  • A. Recommend disciplinary action.
  • B. Recommend a change in security policy.
  • C. Investigate the noncompliance.
  • D. Include the finding in the final audit report.

Answer: B


NEW QUESTION # 250
Which of the following should be reviewed FIRST when assessing the effectiveness of an organization's
network security procedures and controls?

  • A. Inventory of authorized devices
  • B. Data recovery capability
  • C. Malware defenses
  • D. Vulnerability remediation

Answer: A

Explanation:
Section: Information System Acquisition, Development and Implementation


NEW QUESTION # 251
Which of the following provides the GREATEST assurance of message authenticity?

  • A. Theprehash code is derived mathematically from the message being sent.
  • B. The sender attains the recipient's public key and verifies the authenticity of its digital certificate with a certificate authority.
  • C. Theprehash code and the message are encrypted using the secret key.
  • D. Theprehash code is encrypted using the sender's private key.

Answer: D

Explanation:
Encrypting the prehash code using the sender's private key provides assurance of the authenticity of the message. Mathematically deriving the prehash code provides integrity to the message. Encrypting the prehash code and the message using the secretkey provides confidentiality.


NEW QUESTION # 252
Digital signatures are an effective control method for information exchange over an insecure network because they:

  • A. authenticate the user biometrically.
  • B. are under the sole custody of the receiver.
  • C. enable nonrepudiation.
  • D. are constant over time.

Answer: C

Explanation:
Section: Protection of Information Assets


NEW QUESTION # 253
Which of the following is the BEST way to address segregation of duties issues in an organization with budget constraints?

  • A. Perform an independent audit.
  • B. Rotate job duties periodically.
  • C. Implement compensating controls.
  • D. Hire temporary staff.

Answer: C


NEW QUESTION # 254
Which of the following procedures would MOST effectively detect the loading of illegal software packages onto a network?

  • A. Policies that result in instant dismissal if violated
  • B. The use of diskless workstations
  • C. Periodic checking of hard drives
  • D. The use of current antivirus software

Answer: C

Explanation:
The periodic checking of hard drives would be the most effective method of identifying illegal software packages loaded to the network. Antivirus software will not necessarily identify illegal software, unless the software contains a virus. Disklessworkstations act as a preventive control and are not effective, since users could still download software from other than diskless workstations. Policies lay out the rules about loading the software, but will not detect the actual occurrence.


NEW QUESTION # 255
......

Best updated resource for CISA Online Practice Exam: https://www.actualtestsquiz.com/CISA-test-torrent.html

Realistic Practice CISA Certified Information Systems Auditor Exam Braindumps: https://drive.google.com/open?id=1OM_hZTI0PIVxTAJw3sHvWDfig3uQBJkq