لا تريد أن تفوت شيئا؟

نصائح اجتياز امتحان الشهادة

آخر أخبار الامتحانات ومعلومات الخصم

برعاية وحديثة من قبل خبرائنا

نعم، أرسل لي النشرة الإخبارية

خذ اختبارات أخرى عبر الإنترنت

السؤال #1
An IS auditor suspects an organization's computer may have been used to commit a crime. Which ofthe following is the auditor's BEST course of action?
A. xamine the computer to search for evidence supporting the suspicions
B. dvise management of the crime after the investigation
C. ontact the incident response team to conduct an investigation
D. otify local law enforcement of the potential crime before further investigation
عرض الإجابة
اجابة صحيحة: C

View The Updated CISA Exam Questions

SPOTO Provides 100% Real CISA Exam Questions for You to Pass Your CISA Exam!

السؤال #2
Which of the following fire suppression systems needs to be combined with an automatic switch toshut down the electricity supply in the event of activation?
A. arbon dioxide
B. M-200
C. ry pipe
D. alon
عرض الإجابة
اجابة صحيحة: A
السؤال #3
Which of the following should be of GREATEST concern to an IS auditor reviewing a network printer disposal process?
A. Disposal policies and procedures are not consistently implemented
B. Evidence is not available to verify printer hard drives have been sanitized prior to disposal
C. Business units are allowed to dispose printers directly to
D. Inoperable printers are stored in an unsecured area
عرض الإجابة
اجابة صحيحة: B
السؤال #4
From an auditing perspective, which of the following standards most closely maps to a Plan-Do-Check-Act (PDCA) approach?
A. HIPAA
B. ISO 27001
C. Taguchi
D. CMM
عرض الإجابة
اجابة صحيحة: B
السؤال #5
Which database-related term refers to the process of combining several low-sensitivity items to produce a high-sensitivity data item?
A. Relation
B. Aggregation
C. Granularity
D. Foreign key
عرض الإجابة
اجابة صحيحة: B
السؤال #6
An IS audit reveals that an organization is not proactively addressing known vulnerabilities. Which of the following should the IS auditor recommend the organization do FIRST?
A. Verify the disaster recovery plan (DRP) has been tested
B. Ensure the intrusion prevention system (IPS) is effective
C. Assess the security risks to the business
D. Confirm the incident response team understands the issue
عرض الإجابة
اجابة صحيحة: C
السؤال #7
Which of the following is the BEST way to strengthen the security of smart devices to prevent data leakage?
A. Enforce strong security settings on smart devices
B. Require employees to formally acknowledge security procedures
C. Review access logs to the organization's sensitive data in a timely manner
D. Include usage restrictions in bring your own device (BYOD) security procedures
عرض الإجابة
اجابة صحيحة: A
السؤال #8
When a system moves into production and changes are needed, which of the following is the final step in the change control process?
A. Document the new configuration
B. Test the proposed change
C. Implement the change, if approved
D. Present the results to the change-control board
عرض الإجابة
اجابة صحيحة: C
السؤال #9
Which of the following issues associated with a data center's closed circuit television (CCTV) surveillance cameras should be of MOST concern to an IS auditor?
A. CTV recordings are not regularly reviewed
B. CTV records are deleted after one year
C. CTV footage is not recorded 24 x 7
D. CTV cameras are not installed in break rooms
عرض الإجابة
اجابة صحيحة: A
السؤال #10
An organization allows employee use of personal mobile devices for corporate email. Which of the following should be the GREATEST IS audit concern?
A. Email forwarding to private devices requires excessive network bandwidth
B. There is no corporate policy for the acceptable use of private devices
C. There is no adequate tracking of the working time spent out-of-hours
D. The help desk is not able to fully support different kinds of private devices
عرض الإجابة
اجابة صحيحة: B
السؤال #11
Where should an organization keep copies of the business continuity plan?
A. Onsite only
B. Offsite only
C. Both onsite and offsite
D. None of the above
عرض الإجابة
اجابة صحيحة: C
السؤال #12
To confirm integrity for a hashed message, the receiver should use:
A. the same hashing algorithm as the sender's to create a binary image of the file
B. a different hashing algorithm from the sender's to create a numerical representation of the file
C. a different hashing algorithm from the sender's to create a binary image of the file
D. the same hashing algorithm as the sender's to create a numerical representation of the file
عرض الإجابة
اجابة صحيحة: D
السؤال #13
Which of the following should be of GREATEST concern to an IS auditor reviewing an organization's business continuity plan (BCP)?
A. The BCP has not been tested since it was first issued
B. The BCP is not version-controlled
C. The BCP's contact information needs to be updated
D. The BCP has not been approved by senior management
عرض الإجابة
اجابة صحيحة: A
السؤال #14
Which of the following would be MOST useful when analyzing computer performance?
A. uning of system software to optimize resource usage
B. perations report of user dissatisfaction with response time
C. tatistical metrics measuring capacity utilization
D. eport of off-peak utilization and response time
عرض الإجابة
اجابة صحيحة: C
السؤال #15
Which of the following would be MOST useful when analyzing computer performance?
A. Tuning of system software to optimize resource usage
B. Operations report of user dissatisfaction with response time
C. Statistical metrics measuring capacity utilization
D. Report of off-peak utilization and response time
عرض الإجابة
اجابة صحيحة: C
السؤال #16
Which of the following will provide the GREATEST assurance to IT management that a quality management system (QMS) is effective?
A. high percentage of stakeholders satisfied with the quality of IT
B. high percentage of IT processes reviewed by quality assurance (QA)
C. high percentage of incidents being quickly resolved
D. high percentage of IT employees attending quality training
عرض الإجابة
اجابة صحيحة: A
السؤال #17
An organization is implementing a new system that supports a month-end business process. Which of the following implementation strategies would be MOSTefficient to decrease business downtime?
A. Cutover
B. Phased
C. Pilot
D. Parallel
عرض الإجابة
اجابة صحيحة: D
السؤال #18
An IS auditor found that a company executive is encouraging employee use of social networking sites for business purposes. Which of the following recommendations would BEST help to reduce the risk of data leakage?
A. Requiring policy acknowledgment and nondisclosure agreements (NDAs) signed by employees
B. Establishing strong access controls on confidential data
C. Providing education and guidelines to employees on use of social networking sites
D. Monitoring employees' social networking usage
عرض الإجابة
اجابة صحيحة: C
السؤال #19
Which of the following provides the MOST reliable audit evidence on the validity of transactions in a financial application? Substantive testing provides the most reliable audit evidence on the validity of transactions in a financial application. Substantive testing is an audit procedure that examines the financial statements and supporting documentation to see if they contain errors or misstatements. Substantive testing can help to verify that the transactions recorded in the financial applicationare authorized, complete, accurate, and properly classified. Substantive testing can include methods such as vouching, confirmation, analytical procedures, or physical examination.
A. Walk-through reviews
B. Substantive testing
C. Compliance testing
D. Design documentation reviews
عرض الإجابة
اجابة صحيحة: B
السؤال #20
Which of the following issues associated with a data center's closed circuit television (CCTV) surveillance cameras should be of MOST concern to an IS auditor?
A. CCTV recordings are not regularly reviewed
B. CCTV records are deleted after one year
C. CCTV footage is not recorded 24 x 7
D. CCTV cameras are not installed in break rooms
عرض الإجابة
اجابة صحيحة: A
السؤال #21
Which of the following should an IS auditor consider the MOST significant risk associated with a new health records system that replaces a legacy system?
A. taff were not involved in the procurement process, creating user resistance to the new system
B. he deployment project experienced significant overruns, exceeding budget projections
C. ata is not converted correctly, resulting in inaccurate patient records
D. he new system has capacity issues, leading to slow response times for users
عرض الإجابة
اجابة صحيحة: C
السؤال #22
Which of the following is the GREATEST risk if two users have concurrent access to the same database record?
A. ntity integrity
B. vailability integrity
C. eferential integrity
D. ata integrity
عرض الإجابة
اجابة صحيحة: D
السؤال #23
Which of the following is the BEST way to ensure that an application is performing according to its specifications?
A. ilot testing
B. ystem testing
C. ntegration testing
D. nit testing
عرض الإجابة
اجابة صحيحة: B
السؤال #24
Which of the following should be of GREATEST concern to an IS auditor conducting an audit of an organization's backup processes?
A. A written backup policy is not available
B. Backup failures are not resolved in a timely manner
C. The restoration process is slow due to connectivity issues
D. The service levels are not achieved
عرض الإجابة
اجابة صحيحة: D
السؤال #25
An organization is implementing a new system that supports a month-end business process. Which of the following implementation strategies would be MOST efficient to decrease business downtime?
A. utover
B. hased
C. ilot
D. arallel
عرض الإجابة
اجابة صحيحة: D
السؤال #26
Which of the following is the BEST way to ensure that an application is performing according to its specifications?
A. Pilot testing
B. System testing
C. Integration testing
D. Unit testing
عرض الإجابة
اجابة صحيحة: B
السؤال #27
Which of the following is MOST important when creating a forensic image of a hard drive?
A. enerating a content hash of the hard drive
B. ecuring a backup copy of the hard drive
C. equiring an independent third party be present while imaging
D. hoosing an industry-leading forensics software tool
عرض الإجابة
اجابة صحيحة: C
السؤال #28
An IS auditor finds that firewalls are outdated and not supported by vendors. Which of the followingshould be the auditor's NEXT course of action?
A. eport the mitigating controls
B. eport the security posture of the organization
C. etermine the value of the firewall
D. etermine the risk of not replacing the firewall
عرض الإجابة
اجابة صحيحة: D
السؤال #29
Which of the following is MOST important for an IS auditor to assess during a post-implementation review of a newly modified IT application developed in-house? A post-implementation review (PIR) of a newly modified IT application focuses on ensuring that the system meets business and security requirements effectively. The sufficiency of implemented controls (A) is the most critical aspect because it ensures that security, operational, and compliance controls are functioning correctly. These controls include access controls, data integrity checks, and audit logs to prevent unauthorized access, data corruption, or security breaches. Other options: Resource management plan (B) is important for project management but is not the primary concern for an IS auditor in a post-implementation review. Updates required for end-user manuals (C) are necessary for usability but do not impact the security or operational integrity of the system. Rollback plans for changes (D) are important for change management but are typically assessed before deployment, not in a PIR.
A. Sufficiency of implemented controls
B. Resource management plan
C. Updates required for end-user manuals
D. Rollback plans for changes
عرض الإجابة
اجابة صحيحة: A
السؤال #30
Which of the following is MOST helpful for understanding an organization's key driver to modernize application platforms?
A. Vendor software inventories
B. Network architecture diagrams
C. System-wide incident reports
D. Inventory of end-of-life software
عرض الإجابة
اجابة صحيحة: D
السؤال #31
Which of the following is an organization ' s BEST defense against malware?
A. ntrusion detection system (IDS)
B. ntrusion prevention system (IPS)
C. ecurity awareness training
D. ocumented security procedures
عرض الإجابة
اجابة صحيحة: A
السؤال #32
Which of the following is the BEST indication to an IS auditor that management's post-implementation review was effective?
A. Lessons learned were documented and applied
B. Business and IT stakeholders participated in the post-implementation review
C. Post-implementation review is a formal phase in the system development life cycle (SDLC)
D. Internal audit follow-up was completed without any findings
عرض الإجابة
اجابة صحيحة: A
السؤال #33
An IS auditor has been asked to audit the proposed acquisition of new computer hardware. The auditor's PRIMARY concern is that:
A. a clear business case has been established
B. the new hardware meets established security standards
C. a full, visible audit trail will be included
D. the implementation plan meets user requirements
عرض الإجابة
اجابة صحيحة: A

View The Updated ISACA Exam Questions

SPOTO Provides 100% Real ISACA Exam Questions for You to Pass Your ISACA Exam!

عرض الإجابات بعد التقديم

يرجى إرسال البريد الإلكتروني الخاص بك والواتس اب للحصول على إجابات الأسئلة.

ملحوظة: يرجى التأكد من صلاحية معرف البريد الإلكتروني وWhatsApp حتى تتمكن من الحصول على نتائج الاختبار الصحيحة.

بريد إلكتروني:
رقم الواتس اب/الهاتف:
Contact Us