Summer Certification Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

CISA Exam Dumps - Certified Information Systems Auditor

Searching for workable clues to ace the Isaca CISA Exam? You’re on the right place! ExamCert has realistic, trusted and authentic exam prep tools to help you achieve your desired credential. ExamCert’s CISA PDF Study Guide, Testing Engine and Exam Dumps follow a reliable exam preparation strategy, providing you the most relevant and updated study material that is crafted in an easy to learn format of questions and answers. ExamCert’s study tools aim at simplifying all complex and confusing concepts of the exam and introduce you to the real exam scenario and practice it with the help of its testing engine and real exam dumps

Go to page:
Question # 305

An IS auditor reviewing database security should be MOST concerned if the database administrator (DBA):

A.

approves access roles.

B.

resolves database locks.

C.

executes recovery procedures.

D.

assesses database performance.

Full Access
Question # 306

An IT governance body wants to determine whether IT service delivery is based on consistently effective processes. Which of the following is the BEST approach?

A.

Evaluate key performance indicators (KPIs).

B.

Conduct a gap analysis.

C.

Develop a maturity model.

D.

Implement a control self-assessment (CSA).

Full Access
Question # 307

In a high-volume, real-time system, the MOST effective technique by which to continuously monitor and analyze transaction processing is:

A.

integrated test facility (ITF).

B.

parallel simulation.

C.

transaction tagging.

D.

embedded audit modules.

Full Access
Question # 308

During the discussion of a draft audit report IT management provided suitable evidence that a process has been implemented for a control that had been concluded by the IS auditor as ineffective Which of the following is the auditor ' s BEST action?

A.

Explain to IT management that the new control will be evaluated during follow-up

B.

Add comments about the action taken by IT management in the report

C.

Change the conclusion based on evidence provided by IT management

D.

Re-perform the audit before changing the conclusion

Full Access
Question # 309

A programmer has made unauthorized changes lo key fields in a payroll system report. Which of the following control weaknesses would have contributed MOST to this problem?

A.

The programmer did not involve the user in testing

B.

The user requirements were not documented

C.

The programmer has access to the production programs

D.

Payroll files were not under the control of a librarian

Full Access
Question # 310

Which of the following is the MOST effective method to identify new errors introduced as a result of program changes?

A.

Unit testing.

B.

Interface testing.

C.

Integration testing.

D.

Regression testing.

Full Access
Question # 311

Which of the following is MOST important to include in security awareness training?

A.

How to respond to various types of suspicious activity

B.

The importance of complex passwords

C.

Descriptions of the organization ' s security infrastructure

D.

Contact information for the organization ' s security team

Full Access
Question # 312

Which of the following should be an IS auditor ' s PRIMARY focus when developing a risk-based IS audit program?

A.

Portfolio management

B.

Business plans

C.

Business processes

D.

IT strategic plans

Full Access
Go to page: