Summer Certification Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

CISA Exam Dumps - Certified Information Systems Auditor

Searching for workable clues to ace the Isaca CISA Exam? You’re on the right place! ExamCert has realistic, trusted and authentic exam prep tools to help you achieve your desired credential. ExamCert’s CISA PDF Study Guide, Testing Engine and Exam Dumps follow a reliable exam preparation strategy, providing you the most relevant and updated study material that is crafted in an easy to learn format of questions and answers. ExamCert’s study tools aim at simplifying all complex and confusing concepts of the exam and introduce you to the real exam scenario and practice it with the help of its testing engine and real exam dumps

Go to page:
Question # 225

When reviewing an organization’s enterprise architecture (EA), which of the following is an IS auditor MOST likely to find within the EA documentation?

A.

Contact information for key resources within the IT department

B.

Detailed encryption standards

C.

Roadmaps showing the evolution from current state to future state

D.

Protocols used to communicate between systems

Full Access
Question # 226

Which of the following should be the FIRST step when planning an IS audit of a third-party service provider that monitors network activities?

A.

Review the third party ' s monitoring logs and incident handling

B.

Review the roles and responsibilities of the third-party provider

C.

Evaluate the organization ' s third-party monitoring process

D.

Determine if the organization has a secure connection to the provider

Full Access
Question # 227

Which of the following should an IS auditor consider FIRST when evaluating firewall rules?

A.

The organization ' s security policy

B.

The number of remote nodes

C.

The firewalls ' default settings

D.

The physical location of the firewalls

Full Access
Question # 228

Which of the following findings from a database security audit presents the GREATEST risk of critical security exposures?

A.

Legacy data has not been purged.

B.

Admin account passwords are not set to expire.

C.

Default settings have not been changed.

D.

Database activity logging is not complete.

Full Access
Question # 229

Which of the following measures BEST mitigates the risk of data exfiltration during a cyberattack?

A.

Data loss prevention (DLP) system

B.

Network access controls (NAC)

C.

Perimeter firewall

D.

Hashing of sensitive data

Full Access
Question # 230

A system experiences multiple recurring processing errors. Which of the following is the PRIMARY concern for an IS auditor?

A.

Inefficient incident management

B.

Lack of problem management

C.

Lack of change management

D.

Inefficient project management

Full Access
Question # 231

When evaluating information security governance within an organization, which of the following findings should be of MOST concern to an IS auditor?

A.

The information security department has difficulty filling vacancies

B.

An information security governance audit was not conducted within the past year

C.

The data center manager has final sign-off on security projects

D.

Information security policies are updated annually

Full Access
Question # 232

An IS auditor determines elevated administrator accounts for servers that are not properly checked out and then back in after each use. Which of the following is the MOST appropriate sampling technique to determine the scope of the problem?

A.

Haphazard sampling

B.

Random sampling

C.

Statistical sampling

D.

Stratified sampling

Full Access
Go to page: