Summer Certification Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

CISA Exam Dumps - Certified Information Systems Auditor

Searching for workable clues to ace the Isaca CISA Exam? You’re on the right place! ExamCert has realistic, trusted and authentic exam prep tools to help you achieve your desired credential. ExamCert’s CISA PDF Study Guide, Testing Engine and Exam Dumps follow a reliable exam preparation strategy, providing you the most relevant and updated study material that is crafted in an easy to learn format of questions and answers. ExamCert’s study tools aim at simplifying all complex and confusing concepts of the exam and introduce you to the real exam scenario and practice it with the help of its testing engine and real exam dumps

Go to page:
Question # 433

During an audit, the IS auditor finds that in many cases excessive rights were not removed from a system. Which of the following is the auditor ' s BEST recommendation?

A.

System administrators should ensure consistency of assigned rights.

B.

IT security should regularly revoke excessive system rights.

C.

Human resources (HR) should delete access rights of terminated employees.

D.

Line management should regularly review and request modification of access rights

Full Access
Question # 434

Management is concerned about sensitive information being intentionally or unintentionally emailed as attachments outside the organization by employees. What is the MOST important task before implementing any associated email controls?

A.

Require all employees to sign nondisclosure agreements (NDAs).

B.

Develop an acceptable use policy for end-user computing (EUC).

C.

Develop an information classification scheme.

D.

Provide notification to employees about possible email monitoring.

Full Access
Question # 435

An organization has implemented a new data classification scheme and asks the IS auditor to evaluate its effectiveness. Which of the following would be of

GREATEST concern to the auditor?

A.

End-user managers determine who should access what information.

B.

The organization has created a dozen different classification categories.

C.

The compliance manager decides how the information should be classified.

D.

The organization classifies most of its information as confidential.

Full Access
Question # 436

An external IS auditor is reviewing the continuous monitoring system for a large bank and notes several potential issues. Which of the following would present the GREATEST concern regarding the reliability of the monitoring system?

A.

The system results are not reviewed by senior management.

B.

The alert threshold is updated periodically.

C.

The monitoring thresholds are not subject to change management.

D.

The monitoring system was configured by a third party.

Full Access
Question # 437

Which of the following IT service monitoring tools is MOST effective in identifying abnormal system events?

A.

System network and administrative logs

B.

System exception and deviation reports

C.

Operator problem reports

D.

Operator work schedules

Full Access
Question # 438

Which of the following should be of GREATEST concern to an IS auditor reviewing system interfaces used to transfer publicly available information?

A.

A system interface tracking program is not enabled.

B.

The data has not been encrypted.

C.

Data is intercepted while in transit between systems.

D.

The data from the originating system differs from the downloaded data.

Full Access
Question # 439

Which of the following helps to ensure the integrity of data for a system interface?

A.

System interface testing

B.

user acceptance testing (IJAT)

C.

Validation checks

D.

Audit logs

Full Access
Question # 440

An IS auditor is assessing an organization ' s DevSecOps approach. Which of the following BEST indicates a proactive approach to identifying vulnerabilities?

A.

Integration of automated security testing tools into the continuous integration/continuous delivery (CI/CD) process

B.

Open-source dependency checks within continuous integration/continuous delivery (CI/CD) process

C.

Use of the most current development frameworks and libraries

D.

Post-implementation vulnerability scans on application deployments

Full Access
Go to page: