Summer Certification Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

CISA Exam Dumps - Certified Information Systems Auditor

Searching for workable clues to ace the Isaca CISA Exam? You’re on the right place! ExamCert has realistic, trusted and authentic exam prep tools to help you achieve your desired credential. ExamCert’s CISA PDF Study Guide, Testing Engine and Exam Dumps follow a reliable exam preparation strategy, providing you the most relevant and updated study material that is crafted in an easy to learn format of questions and answers. ExamCert’s study tools aim at simplifying all complex and confusing concepts of the exam and introduce you to the real exam scenario and practice it with the help of its testing engine and real exam dumps

Go to page:
Question # 457

Which of the following should be of GREATEST concern to an IS auditor performing a review of information security controls?

A.

The information security policy has not been approved by the chief audit executive (CAE).

B.

The information security policy does not include mobile device provisions

C.

The information security policy is not frequently reviewed

D.

The information security policy has not been approved by the policy owner

Full Access
Question # 458

An IS auditor is reviewing the perimeter security design of a network. Which of the following provides the GREATEST assurance outgoing Internet traffic is controlled?

A.

Intrusion detection system (IDS)

B.

Security information and event management (SIEM) system

C.

Stateful firewall

D.

Load balancer

Full Access
Question # 459

The use of control totals satisfies which of the following control objectives?

A.

Transaction integrity

B.

Processing integrity

C.

Distribution control

D.

System recoverability

Full Access
Question # 460

An organization has established hiring policies and procedures designed specifically to ensure network administrators are well qualified Which type of control is in place?

A.

Detective

B.

Compensating

C.

Corrective

D.

Directive

Full Access
Question # 461

Who is accountable for an organization ' s enterprise risk management (ERM) program?

A.

Board of directors

B.

Steering committee

C.

Chief risk officer (CRO)

D.

Executive management

Full Access
Question # 462

Which of the following findings should be an IS auditor’s GREATEST concern when reviewing a project to migrate confidential data backups to a cloud-based solution?

A.

Lack of chain of custody for retired backup media

B.

Insufficient scalability

C.

Insufficient due diligence performed on the vendor

D.

Increased storage cost

Full Access
Question # 463

Which of the following approaches would present the GREATEST concern for the implementation of a quality assurance (QA) function?

A.

Developers introducing the changes will review the work, as they are most familiar with them.

B.

Peer developers from the same development team who are unfamiliar with the changes will review them.

C.

Developers from a separate development team in the organization will review the submitted changes.

D.

Reviewers outside the development group who do not have development roles will review the changes.

Full Access
Question # 464

An IS auditor is reviewing the security of a web-based customer relationship management (CRM) system that is directly accessed by customers via the Internet, which of the following should be a concern for the auditor?

A.

The system is hosted on an external third-party service provider’s server.

B.

The system is hosted in a hybrid-cloud platform managed by a service provider.

C.

The system is hosted within a demilitarized zone (DMZ) of a corporate network.

D.

The system is hosted within an internal segment of a corporate network.

Full Access
Go to page: