Summer Certification Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

CISA Exam Dumps - Certified Information Systems Auditor

Searching for workable clues to ace the Isaca CISA Exam? You’re on the right place! ExamCert has realistic, trusted and authentic exam prep tools to help you achieve your desired credential. ExamCert’s CISA PDF Study Guide, Testing Engine and Exam Dumps follow a reliable exam preparation strategy, providing you the most relevant and updated study material that is crafted in an easy to learn format of questions and answers. ExamCert’s study tools aim at simplifying all complex and confusing concepts of the exam and introduce you to the real exam scenario and practice it with the help of its testing engine and real exam dumps

Go to page:
Question # 105

An organization saves confidential information in a file with password protection and the file is placed in a shared folder. An attacker has stolen this information by obtaining the password through social engineering. Implementing which of the following would BEST enable the organization to prevent this type of incident in the future?

A.

Multi-factor authentication (MFA)

B.

Security awareness programs for employees

C.

Access history log review by the business manager

D.

File encryption along with password protection

Full Access
Question # 106

An IS auditor is reviewing security controls related to collaboration tools for a business unit responsible for intellectual property and patents. Which of the following observations should be of MOST concern to the auditor?

A.

Training was not provided to the department that handles intellectual property and patents

B.

Logging and monitoring for content filtering is not enabled.

C.

Employees can share files with users outside the company through collaboration tools.

D.

The collaboration tool is hosted and can only be accessed via an Internet browser

Full Access
Question # 107

An IS auditor is reviewing an organizations release management practices and observes inconsistent and inaccurate estimation of the size and complexity of business application development projects. Which of the following should the auditor recommend to address this issue?

A.

Critical path methodology

B.

Agile development approach

C.

Function point analysis

D.

Rapid application development

Full Access
Question # 108

Which of the following BEST enables an organization to improve the effectiveness of its incident response team?

A.

Conducting periodic testing and incorporating lessons learned

B.

Increasing the mean resolution time and publishing key performance indicator (KPI) metrics

C.

Disseminating incident response procedures and requiring signed acknowledgment by team members

D.

Ensuring all team members understand information systems technology

Full Access
Question # 109

An IS auditor discovers from patch logs that some in-scope systems are not compliant with the regular patching schedule. What should the auditor do NEXT?

A.

Interview IT management to clarify the current procedure.

B.

Report this finding to senior management.

C.

Review the organization ' s patch management policy.

D.

Request a plan of action to be established as a follow-up item.

Full Access
Question # 110

Which of the following BEST helps monitor and manage operational logs to create value for an organization?

A.

Using automated tools to collect logs and raise alerts based on use cases

B.

Reporting results of log analyses to senior management for review

C.

Selecting logs only from critical operational systems and devices for monitoring

D.

Encrypting logs processed before archiving for defined retention periods

Full Access
Question # 111

Which of the following BEST enables an IS auditor to combine and compare access control lists from various applications and devices?

A.

Integrated test facility (ITF)

B.

Snapshots

C.

Data analytics

D.

Audit hooks

Full Access
Question # 112

Which of the following is BEST supported by enforcing data definition standards within a database?

A.

Data disposal

B.

Data retention

C.

Data formatting

D.

Data confidentiality

Full Access
Go to page: