Summer Certification Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

CISA Exam Dumps - Certified Information Systems Auditor

Searching for workable clues to ace the Isaca CISA Exam? You’re on the right place! ExamCert has realistic, trusted and authentic exam prep tools to help you achieve your desired credential. ExamCert’s CISA PDF Study Guide, Testing Engine and Exam Dumps follow a reliable exam preparation strategy, providing you the most relevant and updated study material that is crafted in an easy to learn format of questions and answers. ExamCert’s study tools aim at simplifying all complex and confusing concepts of the exam and introduce you to the real exam scenario and practice it with the help of its testing engine and real exam dumps

Go to page:
Question # 185

Which of the following is the PRIMARY reason an IS auditor should recommend that management create an IT risk register?

A.

To document root causes of IT-related risk events and lessons learned

B.

To ensure there is appropriate funding for IT risk mitigation efforts

C.

To ensure an inventory of potential IT risks is maintained and reported

D.

To facilitate internal audit ' s testing of IT-risk-related controls

Full Access
Question # 186

During an audit of payment services of a branch based in a foreign country, a large global bank ' s audit team identifies an opportunity to use data analytics techniques to identify abnormal payments. Which of the following is the team ' s MOST important course of action?

A.

Consult the legal department to understand the procedure for requesting data from a different jurisdiction.

B.

Conduct a walk through of the analytical strategy with stakeholders of the audited branch to obtain their buy-in.

C.

Request the data from the branch as the team audit charter covers the country where it is based.

D.

Agree on a data extraction and sharing strategy with the IT team of the audited branch.

Full Access
Question # 187

Which of the following is the GREATEST concern when applying emergency patches?

A.

A change record may not be properly maintained.

B.

Temporary administrative permissions may be needed to apply patches.

C.

Patch-related risk may not be adequately assessed.

D.

Documented approvals may not be required before applying the emergency patch.

Full Access
Question # 188

During planning for a cloud service audit, audit management becomes aware that the assigned IS auditor is unfamiliar with the technologies in use and their associated risks to the business. To ensure audit quality, which of the following actions should audit management consider FIRST?

A.

Conduct a follow-up audit after a suitable period has elapsed.

B.

Reschedule the audit assignment for the next financial year.

C.

Reassign the audit to an internal audit subject matter expert.

D.

Extend the duration of the audit to give the auditor more time.

Full Access
Question # 189

An organization recently migrated Us data warehouse from a legacy system to a different architecture in the cloud. Which of the following should be of GREATEST concern to the IS auditor reviewing the new data architecture?

A.

The data was not cleansed before moving to the cloud data warehouse.

B.

The cloud data warehouse uses a hybrid cloud architecture.

C.

The migration analyst is not fully trained on the new tools.

D.

The data is stored in a multi-tenant environment.

Full Access
Question # 190

Which of the following management decisions presents the GREATEST risk associated with data leakage?

A.

There is no requirement for desktops to be encrypted

B.

Staff are allowed to work remotely

C.

Security awareness training is not provided to staff

D.

Security policies have not been updated in the past year

Full Access
Question # 191

The MOST effective way to reduce sampling risk is to increase:

A.

confidence interval.

B.

population.

C.

audit sampling training.

D.

sample size.

Full Access
Question # 192

Which of the following controls BEST provides confidentiality and nonrepudiation for an online business looking for digital payment data security?

A.

Data Encryption Standard (DES)

B.

Advanced Encryption Standard (AES)

C.

Public Key Infrastructure (PKI)

D.

Virtual Private Network (VPN)

Full Access
Go to page: