Summer Certification Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

CISA Exam Dumps - Certified Information Systems Auditor

Searching for workable clues to ace the Isaca CISA Exam? You’re on the right place! ExamCert has realistic, trusted and authentic exam prep tools to help you achieve your desired credential. ExamCert’s CISA PDF Study Guide, Testing Engine and Exam Dumps follow a reliable exam preparation strategy, providing you the most relevant and updated study material that is crafted in an easy to learn format of questions and answers. ExamCert’s study tools aim at simplifying all complex and confusing concepts of the exam and introduce you to the real exam scenario and practice it with the help of its testing engine and real exam dumps

Go to page:
Question # 249

Which of the following is MOST important to determine during the planning phase of a cloud-based messaging and collaboration platform acquisition?

A.

Role-based access control policies

B.

Types of data that can be uploaded to the platform

C.

Processes for on-boarding and off-boarding users to the platform

D.

Processes for reviewing administrator activity

Full Access
Question # 250

The purpose of a checksum on an amount field in an electronic data interchange (EDI) communication of financial transactions is to ensure:

A.

nonrepudiation.

B.

authorization,

C.

integrity,

D.

authenticity.

Full Access
Question # 251

The GREATEST concern for an IS auditor reviewing vulnerability assessments by the auditee would be if the assessments are:

A.

Conducted once per year just before system audits are scheduled.

B.

Conducted by the internal technical team instead of external experts.

C.

Performed for critical systems, not for the entire infrastructure.

D.

Performed using open-source testing tools.

Full Access
Question # 252

How does a continuous integration/continuous development (CI/CD) process help to reduce software failure risk?

A.

Easy software version rollback

B.

Smaller incremental changes

C.

Fewer manual milestones

D.

Automated software testing

Full Access
Question # 253

Which of the following is an example of a passive attack method?

A.

Keystroke logging

B.

Piggybacking

C.

Eavesdropping

D.

Phishing

Full Access
Question # 254

Which audit approach is MOST helpful in optimizing the use of IS audit resources?

A.

Agile auditing

B.

Continuous auditing

C.

Outsourced auditing

D.

Risk-based auditing

Full Access
Question # 255

Which of the following observations regarding change management should be considered the MOST serious risk by an IS auditor?

A.

There is no software used to track change management.

B.

The change is not approved by the business owners.

C.

The change is deployed two weeks after approval.

D.

The development of the change is not cost-effective.

Full Access
Question # 256

A secure server room has a badge reader system that records name, date, and time information whenever a staff member uses a badge to enter or exit. When reviewing the system logs, an IS auditor notices records for some employees entering, but not exiting, the room. Which of the following would be the MOST effective compensating control to recommend?

A.

Installing security cameras at the doors

B.

Changing to a biometric access control system

C.

Implementing a monitored mantrap at entrance and exit points

D.

Requiring two-factor authentication at entrance and exit points

Full Access
Go to page: