Summer Certification Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

CISA Exam Dumps - Certified Information Systems Auditor

Searching for workable clues to ace the Isaca CISA Exam? You’re on the right place! ExamCert has realistic, trusted and authentic exam prep tools to help you achieve your desired credential. ExamCert’s CISA PDF Study Guide, Testing Engine and Exam Dumps follow a reliable exam preparation strategy, providing you the most relevant and updated study material that is crafted in an easy to learn format of questions and answers. ExamCert’s study tools aim at simplifying all complex and confusing concepts of the exam and introduce you to the real exam scenario and practice it with the help of its testing engine and real exam dumps

Go to page:
Question # 113

Which of the following would MOST likely impair the independence of the IS auditor when performing a post-implementation review of an application system?

A.

The IS auditor provided consulting advice concerning application system best practices.

B.

The IS auditor participated as a member of the application system project team, but did not have operational responsibilities.

C.

The IS auditor designed an embedded audit module exclusively for auditing the application system.

D.

The IS auditor implemented a specific control during the development of the application system.

Full Access
Question # 114

The PRIMARY goal of capacity management is to:

A.

minimize data storage needs across the organization.

B.

provide necessary IT resources to meet business requirements.

C.

minimize system idle time to optimize cost.

D.

ensure that IT teams have sufficient personnel.

Full Access
Question # 115

Which of the following non-audit activities may impair an IS auditor ' s independence and objectivity?

A.

Evaluating a third-party customer satisfaction survey

B.

Providing advice on an IT project management framework

C.

Designing security controls for a new cloud-based workforce management system

D.

Reviewing secure software development guidelines adopted by an organization

Full Access
Question # 116

Which of the following is the BEST reason for software developers to use automated testing versus manual testing?

A.

CAATs are easily developed

B.

Improved regression testing

C.

Ease of maintaining automated test scripts

D.

Reduces the scope of acceptance testing

Full Access
Question # 117

During the discussion of a draft audit report. IT management provided suitable evidence fiat a process has been implemented for a control that had been concluded by the IS auditor as Ineffective. Which of the following is the auditor ' s BEST action?

A.

Explain to IT management that the new control will be evaluated during follow-up

B.

Re-perform the audit before changing the conclusion.

C.

Change the conclusion based on evidence provided by IT management.

D.

Add comments about the action taken by IT management in the report.

Full Access
Question # 118

An organization allows employees to retain confidential data on personal mobile devices. Which of the following is the BEST recommendation to mitigate the risk of data leakage from lost or stolen devices?

A.

Require employees to attend security awareness training.

B.

Password protect critical data files.

C.

Configure to auto-wipe after multiple failed access attempts.

D.

Enable device auto-lock function.

Full Access
Question # 119

Which of the following data would be used when performing a business impact analysis (BIA)?

A.

Projected impact of current business on future business

B.

Cost-benefit analysis of running the current business

C.

Cost of regulatory compliance

D.

Expected costs for recovering the business

Full Access
Question # 120

Which of the following is the MOST important consideration when an organization is performing a business impact analysis (BIA)?

A.

Focusing on the impact of disruptions caused by technological risks.

B.

Validating recovery time objectives (RTOs) set by IT management.

C.

Involving process owners from various departments.

D.

Identifying hardware that is critical for meeting regulatory requirements.

Full Access
Go to page: