Summer Certification Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

CISA Exam Dumps - Certified Information Systems Auditor

Searching for workable clues to ace the Isaca CISA Exam? You’re on the right place! ExamCert has realistic, trusted and authentic exam prep tools to help you achieve your desired credential. ExamCert’s CISA PDF Study Guide, Testing Engine and Exam Dumps follow a reliable exam preparation strategy, providing you the most relevant and updated study material that is crafted in an easy to learn format of questions and answers. ExamCert’s study tools aim at simplifying all complex and confusing concepts of the exam and introduce you to the real exam scenario and practice it with the help of its testing engine and real exam dumps

Go to page:
Question # 161

During the planning phase of a data loss prevention (DLP) audit, management expresses a concern about mobile computing. Which of the following should the IS auditor identify as the

associated risk?

A.

Increased vulnerability due to anytime, anywhere accessibility

B.

Increased need for user awareness training

C.

The use of the cloud negatively impacting IT availability

D.

Lack of governance and oversight for IT infrastructure and applications

Full Access
Question # 162

Which of the following is the MAIN purpose of an information security management system?

A.

To identify and eliminate the root causes of information security incidents

B.

To enhance the impact of reports used to monitor information security incidents

C.

To keep information security policies and procedures up-to-date

D.

To reduce the frequency and impact of information security incidents

Full Access
Question # 163

During an organization ' s implementation of a data loss prevention (DLP) solution, which of the following activities should be completed FIRST?

A.

Configuring reports

B.

Configuring rule sets

C.

Enabling detection points

D.

Establishing exceptions workflow

Full Access
Question # 164

Which of the following is the MOST important action when populating a project risk register?

A.

Identifying the risk scoring criteria

B.

Assigning risk ownership for identified risk

C.

Creating risk action plans

D.

Conducting process walk-throughs

Full Access
Question # 165

Which of the following is MOST important for an IS auditor to confirm when reviewing an organization ' s incident response management program?

A.

All incidents have a severity level assigned.

B.

All identified incidents are escalated to the CEO and the CISO.

C.

Incident response is within defined service level agreements (SLAs).

D.

The alerting tools and incident response team can detect incidents.

Full Access
Question # 166

Management has agreed to move the organization ' s data center due to recent flood map changes in its current location. Which risk response has been adopted?

A.

Risk elimination

B.

Risk transfer

C.

Risk acceptance

D.

Risk avoidance

Full Access
Question # 167

Which of the following should be the PRIMARY purpose of conducting tabletop exercises when re-viewing a security incident response plan?

A.

To provide efficiencies for alignment with incident response test scenarios

B.

To determine process improvement options for the incident response plan

C.

To gather documentation for responding to security audit inquiries

D.

To confirm that technology is in place to support the incident response plan

Full Access
Question # 168

For an organization that has plans to implement web-based trading, it would be MOST important for an IS auditor to verify the organization ' s information security plan includes:

A.

attributes for system passwords.

B.

security training prior to implementation.

C.

security requirements for the new application.

D.

the firewall configuration for the web server.

Full Access
Go to page: