Summer Certification Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

CISA Exam Dumps - Certified Information Systems Auditor

Searching for workable clues to ace the Isaca CISA Exam? You’re on the right place! ExamCert has realistic, trusted and authentic exam prep tools to help you achieve your desired credential. ExamCert’s CISA PDF Study Guide, Testing Engine and Exam Dumps follow a reliable exam preparation strategy, providing you the most relevant and updated study material that is crafted in an easy to learn format of questions and answers. ExamCert’s study tools aim at simplifying all complex and confusing concepts of the exam and introduce you to the real exam scenario and practice it with the help of its testing engine and real exam dumps

Go to page:
Question # 289

An organization is concerned about duplicate vendor payments on a complex system with a high volume of transactions. Which of the following would be MOST helpful to an IS auditor to determine whether duplicate vendor payments exist?

A.

Computer-assisted audit technique (CAAT)

B.

Stratified sampling

C.

Statistical sampling

D.

Process walk-through

Full Access
Question # 290

Which of the following applications should an IS auditor consider to be the HIGHEST priority when reviewing disaster recovery planning (DRP) tests for an commerce company?

A.

An application for IT performance monitoring

B.

An application for HR management

C.

An application for financial management

D.

An application for traffic load balancing

Full Access
Question # 291

The performance, risks, and capabilities of an IT infrastructure are BEST measured using a:

A.

risk management review

B.

control self-assessment (CSA).

C.

service level agreement (SLA).

D.

balanced scorecard.

Full Access
Question # 292

An organization allows programmers to change production systems in emergency situations without seeking prior approval. Which of the following controls should an IS auditor consider MOST

important?

A.

Programmers ' subsequent reports

B.

Limited number of super users

C.

Operator logs

D.

Automated log of changes

Full Access
Question # 293

The PRIMARY benefit lo using a dry-pipe fire-suppression system rather than a wet-pipe system is that a dry-pipe system:

A.

is more effective at suppressing flames.

B.

allows more time to abort release of the suppressant.

C.

has a decreased risk of leakage.

D.

disperses dry chemical suppressants exclusively.

Full Access
Question # 294

A cloud access security broker (CASB) administers the user access of a Software as a Service {SaaS) on behalf of the customer organization. When conducting an audit of the service, which of the following is MOST important for the IS auditor to confirm?

A.

The CASB logs the access request as a service record that is reviewed after granting access.

B.

The CASB verifies the access request from a named customer contact before granting access.

C.

The CASB manages secure access to the federated directory service used by the SaaS application.

D.

The CASB conducts periodic audits of access requests to ensure compliance with customer policy.

Full Access
Question # 295

What is BEST for an IS auditor to review when assessing the effectiveness of changes recently made to processes and tools related to an organization ' s business continuity plan (BCP)?

A.

Full test results

B.

Completed test plans

C.

Updated inventory of systems

D.

Change management processes

Full Access
Question # 296

Some control activities have been found to be only partially compliant with the design of the control. Which of the following is an IS auditor’s PRIMARY course of action?

A.

Recommend redesigning control activities to ensure acceptance by users.

B.

Evaluate the impact of the partial compliance.

C.

Discuss partial compliance with control owners.

D.

Include each instance of partial compliance as a finding in the final audit report.

Full Access
Go to page: