Summer Certification Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

CISA Exam Dumps - Certified Information Systems Auditor

Searching for workable clues to ace the Isaca CISA Exam? You’re on the right place! ExamCert has realistic, trusted and authentic exam prep tools to help you achieve your desired credential. ExamCert’s CISA PDF Study Guide, Testing Engine and Exam Dumps follow a reliable exam preparation strategy, providing you the most relevant and updated study material that is crafted in an easy to learn format of questions and answers. ExamCert’s study tools aim at simplifying all complex and confusing concepts of the exam and introduce you to the real exam scenario and practice it with the help of its testing engine and real exam dumps

Go to page:
Question # 217

Which of the following is the BEST control to minimize the risk of unauthorized access to lost company-owned mobile devices?

A.

Password/PIN protection

B.

Device tracking software

C.

Device encryption

D.

Periodic backup

Full Access
Question # 218

During a follow-up audit, an IS auditor finds that some critical recommendations have the IS auditor ' s BEST course of action?

A.

Require the auditee to address the recommendations in full.

B.

Adjust the annual risk assessment accordingly.

C.

Evaluate senior management ' s acceptance of the risk.

D.

Update the audit program based on management ' s acceptance of risk.

Full Access
Question # 219

An IS auditor finds that an organization ' s data loss prevention (DLP) system is configured to use vendor default settings to identify violations. The auditor ' s MAIN concern should be that:

A.

violation reports may not be reviewed in a timely manner.

B.

a significant number of false positive violations may be reported.

C.

violations may not be categorized according to the organization ' s risk profile.

D.

violation reports may not be retained according to the organization ' s risk profile.

Full Access
Question # 220

Which of the following is MOST important to include in a business case for an IT-enabled investment?

A.

Business impact analysis (BIA)

B.

Cost-benefit analysis

C.

Security requirements

D.

Risk assessment

Full Access
Question # 221

In continuous delivery, the critical connector between development and production is:

A.

Release management.

B.

Log management.

C.

DevOps.

D.

Data management.

Full Access
Question # 222

During a follow-up audit, an IS auditor finds that senior management has implemented a different remediation action plan than what was previously agreed upon. Which of the following is the auditor ' s BEST course of action?

A.

Report the deviation by the control owner in the audit report.

B.

Evaluate the implemented control to ensure it mitigates the risk to an acceptable level.

C.

Cancel the follow-up audit and reschedule for the next audit period.

D.

Request justification from management for not implementing the recommended control.

Full Access
Question # 223

Which of the following risk scenarios is BEST addressed by implementing policies and procedures related to full disk encryption?

A.

Data leakage as a result of employees leaving to work for competitors

B.

Noncompliance fines related to storage of regulated information

C.

Unauthorized logical access to information through an application interface

D.

Physical theft of media on which information is stored

Full Access
Question # 224

Which of the following BEST demonstrates alignment of the IT department with the corporate mission?

A.

Analysis of IT department functionality

B.

Biweekly reporting to senior management

C.

Annual board meetings

D.

Quarterly steering committee meetings

Full Access
Go to page: