
ISACA CISA Practice Test Pdf Exam Material
CISA Answers CISA Free Demo Are Based On The Real Exam
ISACA CISA Exam Certification Details:
| Number of Questions | 150 |
| Books / Training | Virtual Instructor-Led Training In-Person Training & Conferences Customized, On-Site Corporate Training CISA Planning Guide |
| Sample Questions | ISACA CISA Sample Questions |
| Passing Score | 450/800 |
| Duration | 240 mins |
| Exam Code | CISA |
| Exam Name | ISACA Certified Information Systems Auditor (CISA) |
| Exam Price ISACA Nonmember | $760(USD) |
| Schedule Exam | Exam Registration |
Information about the ISACA Certifications
ISACA certifications are recognized around the world as being one of the best credentials for those who want to have an understanding of software, security, and other issues related to information systems. ISACA certified professionals have a broad range of skills that allow them to work in the various aspects of the field. ISACA also offers the CISM (Certified Information Security Manager). It is a vendor-neutral qualification that is designed to measure the skills and knowledge of IT auditors and information system security officers. The exam validates that candidates have the necessary ability and knowledge to plan, implement, evaluate and maintain a company's auditing and security control. It also provides the documentation for independent evaluations.
Candidates can apply to take the exam at any testing center in their home country or around the world and start preparation from different sources like ISACA CISA Dumps. ISACA's certification programs are being developed, by using an exclusive international advisory board that oversees the development of new programs and exam specifications. The certification criteria are based on a combination of experience, education, training, job skills, integrity, and professional conduct.
NEW QUESTION 70
During which of the following phases in system development would user acceptance test plans normally be prepared?
- A. Requirements definition
- B. Feasibility study
- C. implementation planning
- D. Postimplementation review
Answer: A
Explanation:
Section: Protection of Information Assets
Explanation:
During requirements definition, the project team will be working with the users to define their precise objectives and functional needs. At this time, the users should be working with the team to consider and document hot the system functionality can be tested ensure it meets their stated needs. The feasibility study is too early for such detailed user involvement, and the implementation planning and postimplementation review phases are too late. An IS auditor should know at what point user testing should be planned to ensure it is most effective and efficient.
NEW QUESTION 71
An IS auditor conducting audit follow-up activities learns that some previously agreed-upon corrective actions have not been taken and that the associated risk has been accepted by senior management. If the auditor disagrees with management's decision, what is the BEST way to address the situation?
- A. Repeat the audit with audit scope only covering areas with accepted risks
- B. Recommend new corrective actions to mitigate the accepted risk
- C. Report the issue to the chief audit executive for resolution
- D. Take no action since management's decision has been made
Answer: C
Explanation:
Section: The process of Auditing Information System
NEW QUESTION 72
When performing an IS strategy audit, an IS auditor should review both short-term (one- year) and long- term (three-to five-year) IS strategies, interview appropriate corporate management personnel, and ensure that the external environment has been considered. The auditor should especially focus on procedures in an audit of IS strategy. True or false?
- A. False
- B. True
Answer: A
Explanation:
Explanation/Reference:
Explanation:
When performing an IS strategy audit, an IS auditor should review both short-term (one-year) and long- term (three-to five-year) IS strategies, interview appropriate corporate management personnel, and ensure that the external environment has been considered.
NEW QUESTION 73
An advantage of installing a thin client architecture in a local area network (LAN) is that this would:
- A. reduce the risk of a single point of failure
- B. stabilize network bandwidth requirements
- C. facilitate the updating of software versions
- D. ensure application availability when the server is down
Answer: C
Explanation:
Section: Information System Operations, Maintenance and Support
NEW QUESTION 74
What should be an IS auditor s NEXT course of action when a review of an IT organizational structure reveals IT staff members have duties in other departments?
- A. Determine whether any segregation of duties conflicts exist.
- B. Immediately report a potential finding to the audit committee.
- C. Recommend that segregation of duties controls be implemented.
- D. Report the issue to human resources (HR) management
Answer: A
NEW QUESTION 75
Which of the following malware technical fool's malware by appending section of themselves to files -
somewhat in the same way that file malware appends themselves?
- A. Scanners
- B. Behavior blocker
- C. Active Monitors
- D. Immunizer
Answer: D
Explanation:
Section: Protection of Information Assets
Explanation/Reference:
Immunizers defend against malware by appending sections of themselves to files - sometime in the same
way Malware append themselves. Immunizers continuously check a file for changes and report changes as
possible malware behavior. Other type of Immunizers are focused to a specific malware and work by giving
the malware the impression that the malware has already infected to the computer. This method is not
always practical since it is not possible to immunize file against all known malware.
For your exam you should know below mentioned different kinds of malware Controls
A. Scanners- Look for sequences of bit called signature that are typical malware programs.
The two primary types of scanner are
1. Malware mask or Signatures - Anti-malware scanners check files, sectors and system memory for
known and new (unknown to scanner) malware, on the basis of malware masks or signatures. Malware
masks or signature are specific code strings that are recognized as belonging to malware. For polymorphic
malware, the scanner sometimes has algorithms that check for all possible combinations of a signature
that could exist in an infected file.
2. Heuristic Scanner - Analyzes the instructions in the code being scanned and decide on the basis of
statistical probabilities whether it could contain malicious code. Heuristic scanning result could indicate that
malware may be present, that is possibly infected. Heuristic scanner tend to generate a high level false
positive errors (they indicate that malware may be present when, in fact, no malware is present)
Scanner examines memory disk- boot sector, executables, data files, and command files for bit pattern that
match a known malware. Scanners, therefore, need to be updated periodically to remain effective.
B. Immunizers - Defend against malware by appending sections of themselves to files - sometime in the
same way Malware append themselves. Immunizers continuously check a file for changes and report
changes as possible malware behavior. Other type of Immunizers are focused to a specific malware and
work by giving the malware the impression that the malware has already infected to the computer. This
method is not always practical since it is not possible to immunize file against all known malware.
C. Behavior Blocker- Focus on detecting potential abnormal behavior such as writing to the boot sector or
the master boot record, or making changes to executable files. Blockers can potentially detect malware at
an early stage. Most hardware based anti-malware mechanism are based on this concept.
D. Integrity CRC checker- Compute a binary number on a known malware free program that is then stored
in a database file. The number is called Cyclic Redundancy Check (CRC). On subsequent scans, when
that program is called to execute, it checks for changes to the file as compare to the database and report
possible infection if changes have occurred. A match means no infection; a mismatch means change in the
program has occurred. A change in the program could mean malware within it. These scanners are
effective in detecting infection; however, they can do so only after infection has occurred. Also, a CRC
checker can only detect subsequent changes to files, because they assume files are malware free in the
first place. Therefore, they are ineffective against new files that are malware infected and that are not
recorded in the database. Integrity checker take advantage of the fact that executable programs and boot
sectors do not change often, if at all.
E. Active Monitors - Active monitors interpret DOS and read-only memory (ROM) BIOS calls, looking for
malware like actions. Active monitors can be problematic because they can not distinguish between a user
request and a program or a malware request. As a result, users are asked to confirm actions, including
formatting a disk or deleting a file or set of files.
The following were incorrect answers:
Scanners -Look for sequences of bit called signature that are typical malware programs.
Active Monitors - Active monitors interpret DOS and read-only memory (ROM) BIOS calls, looking for
malware like actions. Active monitors can be problematic because they can not distinguish between a user
request and a program or a malware request. As a result, users are asked to confirm actions, including
formatting a disk or deleting a file or set of files.
Behavior Blocker- Focus on detecting potential abnormal behavior such as writing to the boot sector or the
master boot record, or making changes to executable files. Blockers can potentially detect malware at an
early stage. Most hardware based anti-malware mechanism are based on this concept.
The following reference(s) were/was used to create this question:
CISA review manual 2014 Page number 354 and 355
NEW QUESTION 76
An organization has established three IT processing environments: development, test, and production. The MAJOR reason for separating the development and test environments is to:
- A. protect the programs under development from unauthorized testing.
- B. limit the users' access rights to the test environment.
- C. perform testing in a stable environment.
- D. obtain segregation of duties between IT staff and end users.
Answer: C
Explanation:
Section: Protection of Information Assets
Explanation
NEW QUESTION 77
What should an IS auditor do if he or she observes that project-approval procedures do not exist?
- A. Create project-approval procedures for future project implementations
- B. Advise senior management to invest in project-management training for the staff
- C. Assign project leaders
- D. Recommend to management that formal approval procedures be adopted and documented
Answer: D
Explanation:
Explanation/Reference:
If an IS auditor observes that project-approval procedures do not exist, the IS auditor should recommend to management that formal approval procedures be adopted and documented.
NEW QUESTION 78
When reviewing business continuity plan (BCP) test results, it is MOST important for the IS auditor to determine whether the test:
- A. assesses the capability to retrieve vital records.
- B. considers changes to the systems environment
- C. follows up on activities that occurred since the previous test
- D. verifies the ability to resume key business operations.
Answer: D
NEW QUESTION 79
Which of the following is the MOST critical step in planning an audit?
- A. Testing controls
- B. Identifying current controls
- C. Implementing a prescribed auditing framework such as COBIT
- D. Identifying high-risk audit targets
Answer: D
Explanation:
Explanation/Reference:
Explanation:
In planning an audit, the most critical step is identifying the areas of high risk.
NEW QUESTION 80
An organization has performance metrics to track how well IT resources are being used, but there has been little progress on meeting the organization's goals. Which of the following would be MOST helpful to determine the underlying reason?
- A. Re-evaluating key performance indicators (KPls)
- B. Re-evaluating organizational goals
- C. Conducting a root cause analysis
- D. Conducting a business impact analysis (BIA)
Answer: A
NEW QUESTION 81
Which of the following is MOST helpful in preventing a systems failure from occurring when an application is replaced using the abrupt changeover technique?
- A. Threat and risk assessment
- B. Comprehensive documentation
- C. Change management
- D. Comprehensive testing
Answer: C
NEW QUESTION 82
Secure code reviews as part of a continuous deployment program are which type of control?
- A. Logical
- B. Preventive
- C. Corrective
- D. Detective
Answer: C
NEW QUESTION 83
Talking about biometric authentication, which of the following is often considered as a mix of both physical and behavioral characteristics?
- A. None of the choices.
- B. Finger measurement
- C. Signature
- D. Voice
- E. Body measurement
Answer: D
Explanation:
Explanation/Reference:
Explanation:
Biometric authentication refers to technologies that measure and analyze human physical and behavioral characteristics for authentication purposes.
Physical characteristics include fingerprints, eye retinas and irises, facial patterns and hand measurements, while behavioral characteristics include signature, gait and typing patterns. Voice is often considered as a mix of both physical and behavioral characteristics.
NEW QUESTION 84
An organization is experiencing a large number of phishing attacks targeting employees and executives following a press release announcing an acquisition Which of the following would provide the BEST defense against these attacks?
- A. Conduct organization-wide awareness training
- B. Require signed acknowledgment of the organization's security policy
- C. Deploy intrusion detection and prevention systems
- D. Install spam filters on the acquired systems
Answer: A
NEW QUESTION 85
Which of the following is the GREATEST concern when an organization's backup facility is at a warm site?
- A. Timely availability of hardware
- B. Availability of heat, humidity and air conditioning equipment
- C. Effectiveness of the telecommunications network
- D. Adequacy of electrical power connections
Answer: A
Explanation:
A warm site has the basic infrastructure facilities implemented, such as power, air conditioning and networking, but is normally lacking computing equipment. Therefore, the availability of hardware becomes a primary concern.
NEW QUESTION 86
Which of the following controls would be the MOST comprehensive in a remote access network with multiple and diverse subsystems?
- A. Password implementation and administration
- B. Firewall installation
- C. Network administrator
- D. Proxy server
Answer: A
Explanation:
Explanation/Reference:
Explanation:
The most comprehensive control in this situation is password implementation and administration. While firewall installations are the primary line of defense, they cannot protect all access and, therefore, an element of risk remains. A proxy server is a type of firewall installation; thus, the same rules apply. The network administrator may serve as a control, but typically this would not be comprehensive enough to serve on multiple and diverse systems.
NEW QUESTION 87
To protect a VoIP infrastructure against a denial-of-service (DoS) attack, it is MOST important to secure the:
- A. intrusion detection system (IDS).
- B. access control servers.
- C. backbone gateways.
- D. session border controllers.
Answer: D
Explanation:
Explanation/Reference:
Explanation:
Session border controllers enhance the security in the access network and in the core. In the access network, they hide a user's real address and provide a managed public address. This public address can be monitored, minimizing the opportunities for scanning and denial-of-service (DoS) attacks. Session border controllers permit access to clients behind firewalls while maintaining the firewall's effectiveness. In the core, session border controllers protect the users and the network. They hide network topology and users' real addresses. They can also monitor bandwidth and quality of service. Securing the access control server, backbone gateways and intrusion detection systems (IDSs) does not effectively protect against DoS attacks.
NEW QUESTION 88
An IS auditor finds that not all employees are aware of the enterprise's information security policy. The IS auditor should conclude that:
- A. IS audit should provide security training to the employees.
- B. information security is not critical to all functions.
- C. this lack of knowledge may lead to unintentional disclosure of sensitive information.
- D. the audit finding will cause management to provide continuous training to staff.
Answer: C
Explanation:
All employees should be aware of the enterprise's information security policy to prevent unintentional disclosure of sensitive information. Training is a preventive control. Security awareness programs for employees can prevent unintentional disclosure of sensitive information to outsiders.
NEW QUESTION 89
An organization is acquiring a new customer relationship management (CRM) system In which of the following would the IS auditor find the MOST relevant information on projected cost savings?
- A. Request for proposal (RFP)
- B. Feasibility study document
- C. Business case
- D. Results of prototype testing
Answer: C
NEW QUESTION 90
Which of the following is the BEST time for an IS auditor to perform hich of the following is the BEST way to protect the confidentiality of data on a corporate smartphone?
- A. Using remote data wipe capabilities
- B. Using encryption
- C. Disabling public wireless connections
- D. Changing the default PIN for Bluetooth connections
Answer: B
NEW QUESTION 91
Which of the following is MOST important for an organization to review before sharing data with an external business partner via an application programming interface (API)?
- A. The business partner's security practices
- B. The business partner's web application log files
- C. The business partner's data center access logs
- D. The business partner's help desk incident tickets
Answer: B
NEW QUESTION 92
Which of the following is the MOST important incident management consideration for an organization
subscribing to a cloud service?
- A. Expertise of personnel providing incident response
- B. An agreement on the definition of a security incident
- C. Decision on the classification of cloud-hosted data
- D. Implementation of a SIEM in the organization
Answer: B
Explanation:
Section: Information System Operations, Maintenance and Support
NEW QUESTION 93
......
Isaca CISA Practice Test Questions, Isaca CISA Exam Practice Test Questions
The ISACA CISA certification is designed to validate your skills and expertise as an information systems auditor. It is a globally recognized certificate, which is regarded as an achievement standard for the professionals who audit, monitor, assess, and control the business systems and information technology of an organization. This is also a top choice for the individuals looking to explore a new career in the field of IT and those who want to grow in their current company. It validates one’s competence in the information systems auditing process, governance and management of IT, information systems acquisition, development, and implementation, as well as information systems operations, business resilience, and protection of information assets.
CISA [Mar-2022] Newly Released] Exam Questions For You To Pass: https://www.practicedump.com/CISA_actualtests.html
ISACA CISA Exam: Basic Questions With Answers: https://drive.google.com/open?id=1i3KhTZwhWQvxVCv08fGj_TtgXLhTk--Y