Summer Certification Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

CISA Exam Dumps - Certified Information Systems Auditor

Searching for workable clues to ace the Isaca CISA Exam? You’re on the right place! ExamCert has realistic, trusted and authentic exam prep tools to help you achieve your desired credential. ExamCert’s CISA PDF Study Guide, Testing Engine and Exam Dumps follow a reliable exam preparation strategy, providing you the most relevant and updated study material that is crafted in an easy to learn format of questions and answers. ExamCert’s study tools aim at simplifying all complex and confusing concepts of the exam and introduce you to the real exam scenario and practice it with the help of its testing engine and real exam dumps

Go to page:
Question # 353

An IS auditor is concerned that unauthorized access to a highly sensitive data center might be gained by piggybacking or tailgating. Which of the following is the BEST recommendation? (Choose Correct answer and give explanation from CISA Certification - Information Systems Auditor official book)

A.

Biometrics

B.

Procedures for escorting visitors

C.

Airlock entrance

D.

Intruder alarms

Full Access
Question # 354

To ensure the organization is able to centrally manage mobile devices to protect against data disclosure, it is MOST important for an IS auditor to determine whether:

A.

A mobile security awareness training program exists.

B.

Incident statistics are regularly provided to management.

C.

Remote wipe functionality is enabled on mobile devices.

D.

Lost mobile devices can be located remotely.

Full Access
Question # 355

Which of the following is the PRIMARY purpose of obtaining a baseline image during an operating system audit?

A.

To identify atypical running processes

B.

To verify antivirus definitions

C.

To identify local administrator account access

D.

To verify the integrity of operating system backups

Full Access
Question # 356

Secure code reviews as part of a continuous deployment program are which type of control?

A.

Detective

B.

Logical

C.

Preventive

D.

Corrective

Full Access
Question # 357

Which of the following provides an IS auditor the BEST evidence that a third-party service provider ' s information security controls are effective?

A.

Documentation of the service provider’s security configuration controls

B.

A review of the service provider ' s policies and procedures

C.

An audit report of the controls by an external auditor

D.

An interview with the service provider ' s senior management

Full Access
Question # 358

An IS auditor finds a high-risk vulnerability in a public-facing web server used to process online customer payments. The IS auditor should FIRST

A.

document the exception in an audit report.

B.

review security incident reports.

C.

identify compensating controls.

D.

notify the audit committee.

Full Access
Question # 359

Which of the following is the PRIMARY advantage of a decentralized database architecture over a centralized architecture?

A.

The risk and the impact of a denial of service (DoS) attack is reduced.

B.

Data can be more easily synchronized in real time over public networks.

C.

Transactions performed in a decentralized environment are more consistent.

D.

Uniform security policies can be applied more easily.

Full Access
Question # 360

Which of the following should be of GREATEST concern to an IS auditor conducting an audit of an organization that recently experienced a ransomware attack?

A.

Antivirus software was unable to prevent the attack even though it was properly updated

B.

The most recent security patches were not tested prior to implementation

C.

Backups were only performed within the local network

D.

Employees were not trained on cybersecurity policies and procedures

Full Access
Go to page: