
View All CISA Actual Free Exam Questions Nov 11, 2024 Updated
Pass Authentic ISACA CISA with Free Practice Tests and Exam Dumps
NEW QUESTION # 343
An IS auditor may be justified in using a SMALLER sample size under which of the following circumstances?
- A. Higher expected error rate
- B. Higher reliability factor
- C. Lower precision amount
- D. Lower confidence coefficient
Answer: D
NEW QUESTION # 344
Which of the following BEST ensures that only authorized software is moved into a production environment?
- A. Restricting read/write access to production code to computer programmers only
- B. A librarian compiling source code into production after independent testing
- C. Assigning programming managers to transfer tested programs to production
- D. Requiring programming staff to move tested code into production
Answer: B
NEW QUESTION # 345
The MOST important difference between hashing and encryption is that hashing:
- A. is irreversible.
- B. is concerned with integrity and security.
- C. is the same at the sending and receiving end.
- D. output is the same length as the original message.
Answer: A
Explanation:
Section: Protection of Information Assets
Explanation/Reference:
Explanation:
Hashing works one way; by applying a hashing algorithm to a message, a message hash/digest is created.
If the same hashing algorithm is applied to the message digest, it will not result in the original message. As such, hashing is irreversible, while encryption is reversible. This is the basic difference between hashing and encryption. Hashing creates an output that is smaller than the original message, and encryption creates an output of the same length as the original message. Hashing is used to verify the integrity of the message and does not address security. The same hashing algorithm is used at the sending and receiving ends to generate and verify the message hash/digest. Encryption will not necessarily use the same algorithm at the sending and receiving and to encrypt and decrypt.
NEW QUESTION # 346
What can be used to help identify and investigate unauthorized transactions?
- A. Expert systems
- B. Reasonableness checks
- C. Data-mining techniques
- D. Postmortem review
Answer: C
Explanation:
Explanation/Reference:
Explanation:
Data-mining techniques can be used to help identify and investigate unauthorized transactions.
NEW QUESTION # 347
Proper segregation of duties does not prohibit a quality control administrator from also being responsible for change control and problem management. True or false?
- A. True
- B. False
Answer: A
Explanation:
Explanation/Reference:
Proper segregation of duties does not prohibit a quality-control administrator from also being responsible for change control and problem management.
NEW QUESTION # 348
In the development of a new financial application, the IS auditor's FIRST involvement should be in the:
- A. application design.
- B. control design.
- C. system test.
- D. feasibility study.
Answer: D
Explanation:
Explanation
In the development of a new financial application, the IS auditor's first involvement should be in the feasibility study. A feasibility study is a preliminary analysis that evaluates the technical, operational, economic, and legal aspects of a proposed project or system. A feasibility study helps determine whether the project or system is viable, feasible, and desirable for the organization and its stakeholders.
The IS auditor's role in the feasibility study is to provide an independent and objective assessment of the project or system's risks, benefits, costs, and impacts. The IS auditor should also ensure that the feasibility study follows a structured and systematic approach, considers all relevant factors and alternatives, and complies with the organization's policies and standards. The IS auditor should also verify that the feasibility study is documented and communicated to the appropriate decision-makers.
The IS auditor's involvement in the feasibility study is important because it can help:
Identify and mitigate potential risks and issues that could affect the project or system's success Evaluate and justify the project or system's alignment with the organization's strategy, goals, and value proposition Estimate and optimize the project or system's resources, budget, schedule, and quality Assess and enhance the project or system's security, reliability, performance, and usability Ensure that the project or system meets the expectations and requirements of the users and other stakeholders The other three options are not the first involvement of the IS auditor in the development of a new financial application, although they may be part of the subsequent stages of the development process. Control design is the process of defining and implementing controls that ensure the security, integrity, availability, and efficiency of the system. Application design is the process of specifying the functional and technical features of the system. System test is the process of verifying that the system meets the specifications and requirements.
Therefore, feasibility study is the best answer.
References:
[Feasibility Study - ISACA]
[IS Auditing Guideline G13 Performing an IS Audit Engagement - ISACA]
NEW QUESTION # 349
Which of the following attacks targets the Secure Sockets Layer (SSL)?
- A. Man-in-the middle
- B. Phishing
- C. Dictionary
- D. Password sniffing
Answer: A
Explanation:
Explanation/Reference:
Explanation:
Attackers can establish a fake Secure Sockets Layer (SSL) server to accept user's SSL traffic and then route to the real SSL server, so that sensitive information can be discovered. A dictionary attack that has been launched to discover passwords would not attack SSL since SSL does not rely on passwords. SSL traffic is encrypted, thus it is not possible to sniff the password. A phishing attack targets a user and not SSL Phishing attacks attempt to have the user surrender private information by falsely claiming to be a trusted person or enterprise.
NEW QUESTION # 350
Which of the following should be of GREATEST concern to an IS auditor reviewing on-site preventive maintenance for an organization's business critical server hardware?
- A. Preventive maintenance is outsourced to multiple vendors without requiring nondisclosure agreements (NDAs).
- B. Preventive maintenance costs exceed the business allocated budget.
- C. The preventive maintenance schedule is based on mean time between failures (MTBF) parameters
Answer: A
Explanation:
d. Preventive maintenance has not been approved by tie information system owner.
NEW QUESTION # 351
An IS auditor evaluating the change management process must select a sample from the change log. What is the BEST way tor the auditor to confirm the change log is complete?
- A. Take the last change from the system and trace it back to the log.
- B. Take an item from the log and trace it back to the system.
- C. Obtain management attestation of completeness.
- D. Interview change management personnel about completeness.
Answer: A
Explanation:
Taking the last change from the system and tracing it back to the log is the best way for the auditor to confirm the change log is complete, because:
It verifies that the most recent change made to the system is recorded and documented in the change log, which implies that the change log is up to date and accurate12.
It tests the effectiveness of the change management process and controls that ensure that all changes made to the system are authorized, approved, tested, implemented, and monitored123.
It provides evidence of the traceability and accountability of the change management process and personnel, which can help the auditor identify any gaps, errors, or risks in the process123.
NEW QUESTION # 352
Which of the following represents the GREATEST risk created by a reciprocal agreement for disaster
recovery made between two companies?
- A. Resources may not be available when needed.
- B. The security infrastructures in each company may be different.
- C. The recovery plan cannot be tested.
- D. Developments may result in hardware and software incompatibility.
Answer: D
Explanation:
Section: Protection of Information Assets
Explanation:
If one organization updates its hardware and software configuration, it may mean that it is no longer
compatible with the systems of the other party in the agreement. This may mean that each company is
unable to use the facilities at the other company to recover their processing following a disaster. Resources
being unavailable when needed are an intrinsic risk in any reciprocal agreement, but this is a contractual
matter and is not the greatest risk. The plan can be tested by paper-based walkthroughs, and possibly by
agreement between the companies. The difference in security infrastructures, while a risk, is not
insurmountable.
NEW QUESTION # 353
During the planning stage of compliance audit, an IS auditor discovers that the bank's inventory of compliance requirements does not include recent regulatory changes related to managing data risk. What would the auditor do FIRST?
- A. Discuss potential regulatory issues with the legal department
- B. Report the missing regulatory updates to the chief information officer (CIO)
- C. Exclude recent regulatory changes from the audit scope
- D. Ask management why the regulatory changes have not been included
Answer: D
NEW QUESTION # 354
When determining whether a project in the design phase will meet organizational objectives, what is BEST to compare against the business case?
- A. Requirements analysis
- B. Implementation plan
- C. Project budget provisions
- D. Project plan
Answer: A
Explanation:
Section: Information System Acquisition, Development and Implementation Explanation/Reference:
NEW QUESTION # 355
Distributed denial-of-service (DDOS) attacks on Internet sites are typically evoked by hackers using which of the following?
- A. Trojan horses
- B. Logic bombs
- C. Spyware
- D. Phishing
Answer: A
Explanation:
Section: Protection of Information Assets
Explanation:
Trojan horses are malicious or damaging code hidden within an authorized computer program. Hackers use Trojans to mastermind DDOS attacks that affect computers that access the same Internet site at the same moment, resulting in overloaded site servers that may no longer be able to process legitimate requests. Logic bombs are programs designed to destroy or modify data at a specific time in the future.
Phishing is an attack, normally via e-mail, pretending to be an authorized person or organization requesting information. Spyware is a program that picks up information from PC drives by making copies of their contents.
NEW QUESTION # 356
An IS auditor is assigned to review the development of a specific application. Which of the following would be the MOST significant step following the feasibility study?
- A. Review functional design to determine that appropriate controls are planned.
- B. Follow up with project sponsor for project's budgets and actual costs.
- C. Assist users in the design of proper acceptance-testing procedures.
- D. Attend project progress meetings to monitor timely implementation of the application.
Answer: A
NEW QUESTION # 357
A month after a company purchased and implemented system and performance monitoring software, reports were too large and therefore were not reviewed or acted upon The MOST effective plan of action would be to:
- A. use analytical tools to produce exception reports from the system and performance monitoring software
- B. re-install the system and performance monitoring software.
- C. evaluate replacement systems and performance monitoring software.
- D. restrict functionality of system monitoring software to security-related events.
Answer: A
Explanation:
Using analytical tools to produce exception reports from the system and performance monitoring software is the most effective plan of action for a company that purchased and implemented system and performance monitoring software. Exception reports are reports that highlight deviations or anomalies from predefined thresholds or standards. Using analytical tools to produce exception reports can help to reduce the size and complexity of the system and performance monitoring reports, as well as to focus on the most relevant and critical information for review and action. The other options are less effective plans of action, as they may involve unnecessary costs, risks, or efforts. References:
* CISA Review Manual (Digital Version), Chapter 4, Section 4.2.21
* CISA Review Questions, Answers & Explanations Database, Question ID 219
NEW QUESTION # 358
Which of the following types of attack makes use of unfiltered user input as the format string parameter in the printf() function of the C language?
- A. None of the choices.
- B. format string vulnerabilities
- C. command injection
- D. integer overflow
- E. buffer overflows
- F. code injection
Answer: B
Explanation:
Explanation/Reference:
Explanation:
Format string attacks are a new class of vulnerabilities recently discovered. It can be used to crash a program or to execute harmful code. The problem stems from the use of unfiltered user input as the format string parameter in certain C functions that perform formatting, such as printf(). A malicious user may use the %s and %x format tokens, among others, to print data from the stack or possibly other locations in memory. One may also write arbitrary data to arbitrary locations using the %n format token.
NEW QUESTION # 359
During the review of a system disruption incident, an IS auditor notes that IT support staff were put in a position to make decisions beyond their level of authority.
Which of the following is the BEST recommendation to help prevent this situation in the future?
- A. Implement fallback options.
- B. Introduce escalation protocols.
- C. Develop a competency matrix.
- D. Enable an emergency access ID.
Answer: B
Explanation:
Explanation
The best recommendation to help prevent the situation where IT support staff were put in a position to make decisions beyond their level of authority during the review of a system disruption incident is to introduce escalation protocols. Escalation protocols are policies and procedures that define who should be notified, involved, or consulted when an incident occurs, how the communication and handover should take place, and what criteria or triggers should be used to escalate the incident to a higher level of authority or expertise2.
Escalation protocols help to ensure that:
Incidents are handled by the appropriate staff with the required skills, knowledge, and experience Incidents are resolved in a timely and effective manner Incidents are escalated to senior management or specialized teams when necessary Incidents are documented and reported accurately and transparently Incidents are analyzed and learned from to prevent recurrence or mitigate impact Therefore, by introducing escalation protocols, an organization can improve its incident management process and avoid putting IT support staff in a position to make decisions beyond their level of authority.
References:
Escalation policies for effective incident management, Section 1: What is incident escalation?
NEW QUESTION # 360
Which of the following is the MOST reliable network connection medium in an environment where there is strong electromagnetic interface?
- A. Coaxial cable
- B. Fiber optic cable
- C. Shielded twisted-pair cable
- D. Wireless link
Answer: B
NEW QUESTION # 361
Which of the following should be the MOST important consideration when establishing data classification standards?
- A. The standards comply with relevant regulations.
- B. Management supports the newly developed standards
- C. An education campaign is established upon rollout.
- D. Reporting metrics are established.
Answer: A
NEW QUESTION # 362
As part of a quality assurance initiative, an organization has engaged an external auditor to evaluate the internal IS audit function. Which of the following observations should be of MOST concern?
- A. Audit engagements are not risk-based.
- B. The audit team is not sufficiently leveraging data analytics.
- C. Audit reports do not state they are conducted in accordance with industry standards.
- D. Audit reports are not approved by the audit committee.
Answer: A
NEW QUESTION # 363
An organization outsourced its IS functions. To meet its responsibility for disaster recovery, the organization should:
- A. discontinue the maintenance of the disaster recovery plan (DRP).
- B. delegate evaluation of disaster recovery to a third party.
- C. coordinate disaster recovery administration with the outsourcing vendor.
- D. delegate evaluation of disaster recovery to internal audit.
Answer: B
NEW QUESTION # 364
An IS auditor is using a statistical sample to inventory the tape library. What type of test would this be considered?
- A. Integrated
- B. Continuous audit
- C. Substantive
- D. Compliance
Answer: C
Explanation:
Explanation/Reference:
Using a statistical sample to inventory the tape library is an example of a substantive test.
NEW QUESTION # 365
......
ISACA CISA (Certified Information Systems Auditor) Exam is a globally recognized certification program designed for professionals who want to demonstrate their expertise in information systems auditing, control, and security. The CISA certification demonstrates that an individual has the necessary knowledge and skills to assess, control, and monitor an organization's information technology and business systems. Certified Information Systems Auditor certification is highly valued by employers in the field of information technology and cybersecurity.
New CISA Exam Questions Real ISACA Dumps: https://www.examcost.com/CISA-practice-exam.html
Course 2024 CISA Test Prep Training Practice Exam Download: https://drive.google.com/open?id=1M-4UqhlF0WOkIcGlmuLn3IFOG5OWP8oR

