Summer Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: v4s65

CISA Exam Dumps - Certified Information Systems Auditor

Go to page:
Question # 225

Which of the following metrics is MOST helpful for evaluating the effectiveness of problem management practices?

A.

The number of recurring incidents that cause downtime

B.

The percentage of incidents resolved within a service level agreement (SLA)

C.

The number of incidents investigated and diagnosed

D.

The average time to detect and prioritize an incident

Full Access
Question # 226

An IS auditor is reviewing an organization's incident management processes and procedures. Which of the following observations should be the auditor's GREATEST concern?

A.

Ineffective post-incident review

B.

Ineffective incident prioritization

C.

Ineffective incident detection

D.

Ineffective incident classification

Full Access
Question # 227

Which of the following responses to risk associated with separation of duties would incur the LOWEST initial cost?

A.

Risk mitigation

B.

Risk acceptance

C.

Risk transference

D.

Risk reduction

Full Access
Question # 228

A review of Internet security disclosed that users have individual user accounts with Internet service providers (ISPs) and use these accounts for downloading business data. The organization wants to ensure that only the corporate network is used. The organization should FIRST:

A.

use a proxy server to filter out Internet sites that should not be accessed.

B.

keep a manual log of Internet access.

C.

monitor remote access activities.

D.

include a statement in its security policy about Internet use.

Full Access
Question # 229

Which of the following is the BEST indicator of the effectiveness of an organization's incident response program?

A.

Number of successful penetration tests

B.

Percentage of protected business applications

C.

Financial impact per security event

D.

Number of security vulnerability patches

Full Access
Question # 230

Which of the following is MOST important for an IS auditor to determine during the detailed design phase of a system development project?

A.

Program coding standards have been followed

B.

Acceptance test criteria have been developed

C.

Data conversion procedures have been established.

D.

The design has been approved by senior management.

Full Access
Question # 231

During a follow-up audit, an IS auditor finds that some critical recommendations have the IS auditor's BEST course of action?

A.

Require the auditee to address the recommendations in full.

B.

Adjust the annual risk assessment accordingly.

C.

Evaluate senior management's acceptance of the risk.

D.

Update the audit program based on management's acceptance of risk.

Full Access
Question # 232

In response to an audit finding regarding a payroll application, management implemented a new automated control. Which of the following would be MOST helpful to the IS auditor when evaluating the effectiveness of the new control?

A.

Approved test scripts and results prior to implementation

B.

Written procedures defining processes and controls

C.

Approved project scope document

D.

A review of tabletop exercise results

Full Access
Go to page: