Summer Sale Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: v4s65

CISA Exam Dumps - Certified Information Systems Auditor

Go to page:
Question # 153

What should an IS auditor evaluate FIRST when reviewing an organization's response to new privacy legislation?

A.

Implementation plan for restricting the collection of personal information

B.

Privacy legislation in other countries that may contain similar requirements

C.

Operational plan for achieving compliance with the legislation

D.

Analysis of systems that contain privacy components

Full Access
Question # 154

Which type of review is MOST important to conduct when an IS auditor is informed that a recent internal exploitation of a bug has been discovered in a business application?

A.

Penetration testing

B.

Application security testing

C.

Forensic audit

D.

Server security audit

Full Access
Question # 155

Which of the following would be the GREATEST concern to an IS auditor when reviewing the outsourcing contract for an organization's cloud service provider?

A.

There is no change management process defined in the contract.

B.

There are no procedures for incident escalation.

C.

There is no dispute resolution process defined in the contract.

D.

There is no right-to-audit clause defined in the contract.

Full Access
Question # 156

Which of the following is the MAIN risk associated with adding a new system functionality during the development phase without following a project change

management process?

A.

The added functionality has not been documented.

B.

The new functionality may not meet requirements.

C.

The project may fail to meet the established deadline.

D.

The project may go over budget.

Full Access
Question # 157

An IS auditor has been tasked with auditing the inventory control process for a large organization that processes millions of data transactions. Which of the following is the BEST testing strategy to adopt?

A.

Continuous monitoring

B.

Control self-assessments (CSAs)

C.

Risk assessments

D.

Stop-or-go sampling

Full Access
Question # 158

In which of the following sampling methods is the entire sample considered to be irregular if a single error is found?

A.

Discovery sampling

B.

Variable sampling

C.

Stop-or-go sampling

D.

Judgmental sampling

Full Access
Question # 159

Which of the following should be the FIRST step in a data migration project?

A.

Reviewing decisions on how business processes should be conducted in the new system

B.

Completing data cleanup in the current database to eliminate inconsistencies

C.

Understanding the new system's data structure

D.

Creating data conversion scripts

Full Access
Question # 160

During which phase of the software development life cycle should an IS auditor be consulted to recommend security controls?

A.

Design and development

B.

Final acceptance testing

C.

Implementation of software

D.

Requirements definition

Full Access
Go to page: