CISA Free Certification Exam Easy to Download PDF Format 2023
Get 100% Success with Latest Certified Information Systems Auditor CISA Exam Dumps
Registration of CISA exam through Mobile Phone:
You can also register in person through the phone. However, in this case, you need to fork out an additional payment. The ISACA CISA Dumps narrates that you can also be asked to carry another form of ID or proof that you are an individual with authentic information to monitor and assess the exam. Even though you can register for the exam via the phone, it is wise to visit the testing center in person to get registered. This will ensure that you are carrying all that is needed for registering for the exam. If you are not sure whether you have all the necessary documents, call to ask for explanations before coming in person to prepare for your exam.
Information Systems Acquisition, Development, & Implementation: This subject will measure the candidates’ skills in the following subtopics:
- Information system acquisition and development – project management and governance; control identification & design; system development methodologies; business case & feasibility analysis;
- Information systems implementation – testing methodologies; system migration, data conversion, and infrastructure deployment; post-implementation review.
NEW QUESTION # 444
An IS auditor is reviewing a software-based configuration. Which of the following represents the GREATEST vulnerability? The firewall software:
- A. has been configured with rules permitting or denying access to systems or networks.
- B. is configured with an implicit deny rule as the last rule in the rule base.
- C. is configured as a virtual private network (VPN) endpoint.
- D. is installed on an operating system with default settings.
Answer: D
Explanation:
Explanation/Reference:
Explanation:
Default settings are often published and provide an intruder with predictable configuration information, which allows easier system compromise. To mitigate this risk, firewall software should be installed on a system using a hardened operating system that has limited functionality, providing only the services necessary to support the firewall software. Choices A, C and D are normal or best practices for firewall configurations.
NEW QUESTION # 445
An organization is implementing an enterprise resource planning (ERP) application to meet its business objectives. Of the following, who is PRIMARILY responsible for overseeing the project in order to ensure that it is progressing in accordance with the project plan and that it will deliver the expected results?
- A. User project team (UPT)
- B. System development project team (SPDT)
- C. Project steering committee
- D. Project sponsor
Answer: C
Explanation:
Explanation/Reference:
Explanation:
A project steering committee that provides an overall direction for the enterprise resource planning (ERP) implementation project is responsible for reviewing the project's progress to ensure that it will deliver the expected results. A project sponsor is typically the senior manager in charge of the primary business unit that the application will support. The sponsor provides funding for the project and works closely with the project manager to define the critical success factors or metrics for the project. The project sponsor is not responsible for reviewing the progress of the project. A system development project team (SDPT) completes the assigned tasks, works according to the instructions of the project manager and communicates with the user project team. The SDPT is not responsible for reviewing the progress of the project. A user project team (UPT) completes the assigned tasks, communicates effectively with the system development team and works according to the advice of the project manager. A UPT is not responsible for reviewing the progress of the project.
NEW QUESTION # 446
In a multinational organization, local security regulations should be implemented over global security policy because:
- A. business objectives are defined by local business unit managers
- B. requirements of local regulations take precedence
- C. deploying awareness of local regulations is more practical than of global policy
- D. global security policies include unnecessary controls for local businesses
Answer: B
Explanation:
Section: Governance and Management of IT
NEW QUESTION # 447
Which of the following observations should be of concern to an IS auditor performing a review of an organization's IT governance structure?
- A. The chief information officer is prohibited from making capital decisions regarding IT.
- B. There are no IT subject matter expects on the board of directors.
D18912E1457D5D1DDCBD40AB3BF70D5D - C. The chief risk officer is also the chief information officer.
- D. The IT steering committee has oversight of the IT budget.
Answer: C
NEW QUESTION # 448
When planning an audit to assess application controls of a cloud-based system, it is MOST important for
the IS auditor to understand the:
- A. availability reports associated with the cloud-based system.
- B. policies and procedures of the business area being audited.
- C. business process supported by the system.
- D. architecture and cloud environment of the system.
Answer: B
Explanation:
Section: Protection of Information Assets
NEW QUESTION # 449
The MAJOR consideration for an IS auditor reviewing an organization's IT project portfolio is the:
- A. investment plan.
- B. business plan.
- C. IT budget.
- D. existing IT environment.
Answer: B
Explanation:
Section: Protection of Information Assets
Explanation:
One of the most important reasons for which projects get funded is how well a project meets an organization's strategic objectives. Portfolio management takes a holistic view of a company's overall IT strategy. IT strategy should be aligned with the business strategy and, hence, reviewing the business plan should be the major consideration. Choices A, B and D are important but secondary to the importance of reviewing the business plan,
NEW QUESTION # 450
A PRIMARY benefit derived from an organization employing control self-assessment (CSA) techniques is
that it:
- A. allows management to relinquish responsibility for control.
- B. allows IS auditors to independently assess risk.
- C. can be used as a replacement for traditional audits.
- D. can identify high-risk areas that might need a detailed review later.
Answer: D
Explanation:
Section: Protection of Information Assets
Explanation:
CSA is predicated on the review of high-risk areas that either need immediate attention or a more thorough
review at a later date. Choice B is incorrect, because CSA requires the involvement of auditors and line
management. What occurs is that the internal audit function shifts some of the control monitoring
responsibilities to the functional areas. Choice C is incorrect because CSA is not a replacement for
traditional audits. CSA is not intended to replace audit's responsibilities, but to enhance them. Choice D is
incorrect, because CSA does not allow management to relinquish its responsibility for control.
NEW QUESTION # 451
When reviewing capacity monitoring, an IS auditor notices several incidents where storage capacity limits were reached, while the average utilization was below 30%. Which of the following would the IS auditor MOST likely identify as the root cause?
- A. The amount of data produced was unacceptable for operations.
- B. The storage space should have been enlarged in time.
- C. The IT response to the alerts was too slow.
- D. The dynamics of the utilization were not properly taken into account.
Answer: D
Explanation:
Section: The process of Auditing Information System
NEW QUESTION # 452
There are many known weaknesses within an Intrusion Detection System (IDS). Which of the following is NOT a limitation of an IDS?
- A. Detect zero day attack.
- B. Backdoor into application
- C. Application level vulnerability.
- D. Weakness in the identification and authentication scheme.
Answer: A
Explanation:
Explanation/Reference:
Detecting zero day attack is an advantage of IDS system making use of behavior or heuristic detection.
It is important to read carefully the question. The word "NOT" was the key word.
Intrusion Detection System are somewhat limited in scope, they do not address the following:
Weakness in the policy definition
Application-level vulnerability
Backdoor within application
Weakness in identification and authentication schemes
Also, you should know the information below for your CISA exam:
An IDS works in conjunction with routers and firewall by monitoring network usage anomalies.
Broad category of IDS includes:
1. Network Based IDS
2. Host Based IDS
Network Based IDS
They identify attack within the monitored network and issue a warning to the operator.
If a network based IDS is placed between the Internet and the firewall, it will detect all the attack attempts whether or not they enter the firewall Network Based IDS are blinded when dealing with encrypted traffic Host Based IDS They are configured for a specific environment and will monitor various internal resources of the operating system to warn of a possible attack.
They can detect the modification of executable programs, detect the detection of files and issue a warning when an attempt is made to use a privilege account.
They can monitor traffic after it is decrypted and they supplement the Network Based IDS.
Types of IDS includes:
Statistical Based IDS - These system need a comprehensive definition of the known and expected behavior of system Neural Network - An IDS with this feature monitors the general patterns of activity and traffic on the network, and create a database. This is similar to statistical model but with added self-learning functionality.
Signature Based IDS - These IDS system protect against detected intrusion patterns. The intrusive pattern they can identify are stored in the form of signature.
The following were incorrect answers:
The other options mentioned are all limitations of an IDS.
The following reference(s) were/was used to create this question:
CISA review manual 2014 Page number 346 and 347
NEW QUESTION # 453
Which of the following should be an IS auditor's consideration when scheduling follow-up activities for agreed-upon management responses to remediate audit observations?
- A. Risk rating of original findings
- B. Availability of responsible IT personnel
- C. IT budgeting constraints
- D. Business interruption due to remediation
Answer: A
NEW QUESTION # 454
An IS auditor noted that an organization had adequate business continuity plans (BCPs)
for each individual process, but no comprehensive BCP. Which would be the BEST course of action for the IS auditor?
- A. Recommend the creation of a single BCP.
- B. Determine whether the BCPs are consistent.
- C. Accept the BCPs as written.
- D. Recommend that an additional comprehensive BCP be developed.
Answer: B
Explanation:
Depending on the complexity of the organization, there could be more than one plan to address various aspects of business continuity and disaster recovery. These do not necessarily have to be integrated into one single plan; however, each plan should be consistent with other plans to have a viable business continuity planning strategy.
NEW QUESTION # 455
During an audit, which of the following would be MOST helpful in establishing a baseline for measuring data quality?
- A. Built-in data error prevention application controls
- B. Validation of rules by the business
- C. Input from customers
- D. Industry standard business definitions
Answer: B
NEW QUESTION # 456
Categories for classifying an organization's data are BEST determined based on which of the following?
- A. Higher security requirement of personally identifiable data
- B. Transactions processed by senior management
- C. Impact on business due to loss or leakage of data
- D. Critically of business functions
Answer: C
NEW QUESTION # 457
An IS auditor reviewing incident response management processes notices that resolution times for reoccurring incidents have not shown improvement. Which of the following is the auditor's BEST recommendation?
- A. Implement a survey to determine future incident response training needs.
- B. Harden IT system and application components based on best practices.
- C. Introduce problem management into incident response.
- D. Incorporate a security information and event management (SIEM) system into incident response
Answer: C
Explanation:
Explanation
The auditor's best recommendation is D. Introduce problem management into incident response. Problem management is a practice that aims to identify, analyze, and resolve the root causes of recurring incidents, and prevent or reduce their impact in the future1. Problem management can help improve the resolution times for recurring incidents by eliminating or mitigating the underlying problems that cause them, and by providing permanent solutions that can be reused or automated2. Problem management can also help improve the quality and efficiency of incident response by reducing the workload and complexity of dealing with repetitive issues2.
NEW QUESTION # 458
An organization offers an online information security awareness program to employees on an annual basis.
Which of the following findings from an audit of the program should be the IS auditor's GREATEST concern?
- A. New employees are given three months to complete the training.
- B. Training completion is not mandatory for staff
- C. The post-training test content is two years old.
- D. Employees have complained about the length of the program
Answer: B
NEW QUESTION # 459
Which of the following is the MOST effective control to ensure electronic records beyond their retention periods are deleted from IT systems?
- A. Execute all data deletions at a predefined month during the year.
- B. Perform a sample check of current data against the retention schedule.
- C. Review the record retention register regularly to initiate data deletion.
- D. Build in system logic to trigger data deletion at predefined times.
Answer: B
NEW QUESTION # 460
Which of the following term in business continuity determines the maximum tolerable amount of time that is needed to verify the system and/or data integrity?
- A. RTO
- B. MTD
- C. WRT
- D. RPO
Answer: C
Explanation:
Explanation/Reference:
The Work Recovery Time (WRT) determines the maximum tolerable amount of time that is needed to verify the system and/or data integrity. This could be, for example, checking the databases and logs, making sure the applications or services are running and are available. In most cases those tasks are performed by application administrator, database administrator etc. When all systems affected by the disaster are verified and/or recovered, the environment is ready to resume the production again.
For your exam you should know below information about RPO, RTO, WRT and MTD:
Stage 1: Business as usual
Business as usual
Image Reference - http://defaultreasoning.files.wordpress.com/2013/12/bcdr-01.png At this stage all systems are running production and working correctly.
Stage 2: Disaster occurs
Disaster Occurs
Image Reference - http://defaultreasoning.files.wordpress.com/2013/12/bcdr-02.png On a given point in time, disaster occurs and systems needs to be recovered. At this point the Recovery Point Objective (RPO) determines the maximum acceptable amount of data loss measured in time. For example, the maximum tolerable data loss is 15 minutes.
Stage 3: Recovery
Recovery
Image Reference - http://defaultreasoning.files.wordpress.com/2013/12/bcdr-03.png At this stage the system are recovered and back online but not ready for production yet. The Recovery Time Objective (RTO) determines the maximum tolerable amount of time needed to bring all critical systems back online. This covers, for example, restore data from back-up or fix of a failure. In most cases this part is carried out by system administrator, network administrator, storage administrator etc.
Stage 4: Resume Production
Resume Production
Image Reference - http://defaultreasoning.files.wordpress.com/2013/12/bcdr-04.png At this stage all systems are recovered, integrity of the system or data is verified and all critical systems can resume normal operations. The Work Recovery Time (WRT) determines the maximum tolerable amount of time that is needed to verify the system and/or data integrity. This could be, for example, checking the databases and logs, making sure the applications or services are running and are available.
In most cases those tasks are performed by application administrator, database administrator etc. When all systems affected by the disaster are verified and/or recovered, the environment is ready to resume the production again.
MTD
Image Reference - http://defaultreasoning.files.wordpress.com/2013/12/bcdr-05.png The sum of RTO and WRT is defined as the Maximum Tolerable Downtime (MTD) which defines the total amount of time that a business process can be disrupted without causing any unacceptable consequences. This value should be defined by the business management team or someone like CTO, CIO or IT manager.
The following answers are incorrect:
RPO - Recovery Point Objective (RPO) determines the maximum acceptable amount of data loss measured in time. For example, the maximum tolerable data loss is 15 minutes.
RTO - The Recovery Time Objective (RTO) determines the maximum tolerable amount of time needed to bring all critical systems back online. This covers, for example, restore data from back-up or fix of a failure.
In most cases this part is carried out by system administrator, network administrator, storage administrator etc.
MTD - The sum of RTO and WRT is defined as the Maximum Tolerable Downtime (MTD) which defines the total amount of time that a business process can be disrupted without causing any unacceptable consequences. This value should be defined by the business management team or someone like CTO, CIO or IT manager.
The following reference(s) were/was used to create this question:
CISA review manual 2014 page number 284
http://defaultreasoning.com/2013/12/10/rpo-rto-wrt-mtdwth/
NEW QUESTION # 461
In an audit of an inventory application, which approach would provide the BEST evidence that purchase orders are valid?
- A. Comparing receiving reports to purchase order details
- B. Testing whether inappropriate personnel can change application parameters
- C. Tracing purchase orders to a computer listing
- D. Reviewing the application documentation
Answer: B
Explanation:
To determine purchase order validity, testing access controls will provide the best evidence. Choices B and C are based on after-the-fact approaches, while choice D does not serve the purpose because what is in the system documentation may not be thesame as what is happening.
NEW QUESTION # 462
When reviewing input controls, an IS auditor observes that, in accordance with corporate policy, procedures allow supervisory override of data validation edits. The IS auditor should:
- A. verify whether all such overrides are referred to senior management for approval.
- B. ensure that overrides are automatically logged and subject to review.
- C. not be concerned since there may be other compensating controls to mitigate the risks.
- D. recommend that overrides not be permitted.
Answer: B
Explanation:
Explanation/Reference:
Explanation:
If input procedures allow overrides of data validation and editing, automatic logging should occur. A management individual who did not initiate the override should review this log. An IS auditor should not assume that compensating controls exist. Aslong as the overrides are policy-compliant, there is no need for senior management approval or a blanket prohibition.
NEW QUESTION # 463
Vendors have released patches fixing security flaws in their software. Which of the following should an IS auditor recommend in this situation?
- A. Ask the vendors for a new software version with all fixes included.
- B. Decline to deal with these vendors in the future.
- C. install the security patch immediately.
- D. Assess the impact of patches prior to installation.
Answer: D
Explanation:
Explanation/Reference:
Explanation:
The effect of installing the patch should be immediately evaluated and installation should occur based on the results of the evaluation. To install the patch without knowing what it might affect could easily cause problems. New software versions withal fixes included are not always available and a full installation could be time consuming. Declining to deal with vendors does not take care of the flaw.
NEW QUESTION # 464
Which of the following would MOST effectively control the usage of universal storage bus (USB) storage devices?
- A. Policies that require instant dismissal if such devices are found
- B. Administratively disabling the USB port
- C. Software for tracking and managing USB storage devices
- D. Searching personnel for USB storage devices at the facility's entrance
Answer: C
Explanation:
Explanation/Reference:
Explanation:
Software for centralized tracking and monitoring would allow a USB usage policy to be applied to each user based on changing business requirements, and would provide for monitoring and reporting exceptions to management. A policy requiring dismissal may result in increased employee attrition and business requirements would not be properly addressed. Disabling ports would be complex to manage and might not allow for new business needs. Searching of personnel for USB storage devices at the entrance to a facility is not a practical solution since these devices are small and could be easily hidden.
NEW QUESTION # 465
A user of a telephone banking system has forgotten his personal identification number (PIN), after the user has been authenticated, the BEST method of issuing a new pin is to have:
- A. The user enter a new PIN twice
- B. Banking personnel verbally assign a new PIN
- C. A randomly generated pin communicated by banking personnel
- D. Banking personnel assign the user a new PIN via email
Answer: A
NEW QUESTION # 466
MOST critical security weakness of a packet level firewall is that it can be circumvented by:
- A. changing the source address on incoming packets
- B. deciphering the signature information of the packets
- C. intercepting packets and viewing passwords sent in clear text
- D. using a dictionary attack of encrypted passwords.
Answer: B
NEW QUESTION # 467
An IS department is evaluated monthly on its cost-revenue ratio user satisfaction rate, and computer downtime This is BEST zed as an application of.
- A. balanced scorecard
- B. control self-assessment (CSA)
- C. value chain analysis
- D. risk framework
Answer: A
Explanation:
Explanation
A balanced scorecard is a framework that translates the IT strategy into measurable objectives, indicators, targets, and initiatives across four perspectives: financial, customer, internal process, and learning and growth.
A balanced scorecard helps to monitor and evaluate how well the IT function is delivering value to the organization, achieving its strategic goals, and improving its capabilities and competencies. The other options are not the primary uses of a balanced scorecard, because they either focus on specific aspects of IT rather than the overall performance, or they are not directly related to the IT strategy.
NEW QUESTION # 468
......
To prepare for the CISA exam, candidates can take advantage of various resources such as study materials, practice exams, and training courses. ISACA offers a range of resources to help candidates prepare for the exam, including study guides, review courses, and practice exams. Candidates can also take advantage of online forums and study groups to connect with other professionals and share study tips and strategies.
Get Ready to Pass the CISA exam Right Now Using Our Certified Information Systems Auditor Exam Package: https://www.exam4free.com/CISA-valid-dumps.html
The Best CISA Exam Study Material and Preparation Test Question Dumps: https://drive.google.com/open?id=105B8BzpMTJ_xiyA3EYgcp76K-UPndqwD
