Isaca CISA - Questions & Answers
Free preview · every answer includes a full explanation
Product page: https://prepkeys.com/cisa.html
An organization allows employees to retain confidential data on personal mobile devices.
Which of the following is the BEST recommendation to mitigate the risk of data leakage from lost or stolen devices?
Require employees to attend security awareness training.
Password protect critical data files.
Configure to auto-wipe after multiple failed access attempts.
Enable device auto-lock function.
The best recommendation to mitigate the risk of data leakage from lost or stolen devices that contain confidential data is to configure them to auto-wipe after multiple failed access attempts, as this would prevent unauthorized access and erase sensitive information from the device. Requiring employees to attend security awareness training, password protecting critical data files, or enabling device auto-lock function are also good practices, but they may not be sufficient or effective in preventing data leakage from lost or stolen devices.
References:
CISA Review Manual (Digital Version), Chapter 5, Section 5.3
During a review of a production schedule, an IS auditor observes that a staff member is not complying with mandatory operational procedures. The auditor's NEXT step should be to:
note the noncompliance in the audit working papers.
issue an audit memorandum identifying the noncompliance.
include the noncompliance in the audit report.
determine why the procedures were not followed.
An IS auditor is reviewing an organization's information asset management process.
Which of the following would be of GREATEST concern to the auditor?
The process does not require specifying the physical locations of assets.
Process ownership has not been established.
The process does not include asset review.
Identification of asset value is not included in the process.
An IS auditor would be most concerned if process ownership has not been established for the information asset management process, as this would indicate a lack of accountability, responsibility, and authority for managing the assets throughout their lifecycle. The process owner should also ensure that the process is aligned with the organization's objectives, policies, and standards. The process should require specifying the physical locations of assets, include asset review, and identify asset value, but these are less critical than establishing process ownership.
References:
CISA Review Manual (Digital Version), Chapter 3, Section 3.3
When an intrusion into an organization network is deleted, which of the following should be done FIRST?
Block all compromised network nodes.
Contact law enforcement.
Notify senior management.
Identity nodes that have been compromised.
The first thing that should be done when an intrusion into an organization network is detected is to identify nodes that have been compromised. Identifying nodes that have been compromised is a critical step in responding to an intrusion, as it helps determine the scope, impact, and source of the attack, and enables the implementation of appropriate containment and recovery measures. The other options are not the first things that should be done when an intrusion into an organization network is detected, as they may be premature or ineffective without identifying nodes that have been compromised. Blocking all compromised network nodes is a containment measure that can help isolate and prevent the spread of the attack, but it may not be possible or feasible without identifying nodes that have been compromised. Contacting law enforcement is a reporting measure that can help seek external assistance and comply with legal obligations, but it may not be necessary or appropriate without identifying nodes that have been compromised. Notifying senior management is a communication measure that can help inform and escalate the incident, but it may not be urgent or accurate without identifying nodes that have been compromised.
References:
CISA Review Manual (Digital Version), Chapter 4, Section 4.2.2
Which of the following would BEST demonstrate that an effective disaster recovery plan (DRP) is in place?
Frequent testing of backups
Annual walk-through testing
Periodic risk assessment
Full operational test
A disaster recovery plan (DRP) is a set of procedures and resources that enable an organization to restore its critical operations, data, and applications in the event of a disaster. A DRP should be aligned with the organization's business continuity plan (BCP), which defines the strategies and objectives for maintaining business functions during and after a disaster. To ensure that a DRP is effective, it should be tested regularly and thoroughly to identify and resolve any issues or gaps that might hinder its execution. Testing a DRP can help evaluate its feasibility, validity, reliability, and compatibility with the organization's environment and needs 4. Testing can also help prepare the staff, stakeholders, and vendors involved in the DRP for their roles and responsibilities during a disaster. There are different methods and levels of testing a DRP, depending on the scope, complexity, and objectives of the test 4. Some of the common testing methods are: Walkthrough testing: This is a step-by-step review of the DRP by the disaster recovery team and relevant stakeholders. It aims to verify the completeness and accuracy of the plan, as well as to clarify any doubts or questions among the participants.
Simulation testing: This is a mock exercise of the DRP in a simulated disaster scenario. It aims to assess the readiness and effectiveness of the plan, as well as to identify any challenges or weaknesses that might arise during a real disaster. Checklist testing: This is a verification of the availability and functionality of the resources and equipment required for the DRP. It aims to ensure that the backup systems, data, and documentation are accessible and up-to-date 45. Full interruption testing: This is the most realistic and rigorous method of testing a DRP. It involves shutting down the primary site and activating the backup site for a certain period of time. It aims to measure the actual impact and performance of the DRP under real conditions.
Parallel testing: This is a less disruptive method of testing a DRP. It involves running the backup site in parallel with the primary site without affecting the normal operations. It aims to compare and validate the results and outputs of both sites 45. Among these methods, full interruption testing would best demonstrate that an effective DRP is in place, as it provides the most accurate and comprehensive evaluation of the plan's capabilities and limitations 4. Full interruption testing can reveal any hidden or unforeseen issues or risks that might affect the recovery process, such as data loss, system failure, compatibility problems, or human errors 4. Full interruption testing can also verify that the backup site can support the critical operations and services of the organization without compromising its quality or security 4. However, full interruption testing also has some drawbacks, such as being costly, time-consuming, risky, and disruptive to the normal operations 4. Therefore, it should be planned carefully and conducted periodically with proper coordination and communication among all parties involved. The other options are not as effective as full interruption testing in demonstrating that an effective DRP is in place. Frequent testing of backups is only one aspect of checklist testing, which does not cover other components or scenarios of the DRP4. Annual walk-through testing is only a theoretical review of the DRP, which does not test its practical implementation or outcomes 4. Periodic risk assessment is only a preparatory step for developing or updating the DRP, which does not test its functionality or performance.
References:
2: Best Practices For Disaster Recovery Testing | Snyk
3: Disaster Recovery Plan (DR) Testing -- Methods and Must-haves -
US Signal 4: Disaster Recovery Testing:
5: Disaster Recovery Testing Best Practices - MSP360
1: How to Test a Disaster Recovery Plan - Abacus
An IS auditor found that a company executive is encouraging employee use of social networking sites for business purposes.
Which of the following recommendations would BEST help to reduce the risk of data leakage?
Requiring policy acknowledgment and nondisclosure agreements (NDAs) signed by employees
Establishing strong access controls on confidential data
Providing education and guidelines to employees on use of social networking sites
Monitoring employees' social networking usage
The best recommendation to reduce the risk of data leakage from employee use of social networking sites for business purposes is to provide education and guidelines to employees on use of social networking sites. Education and guidelines can help employees understand the benefits and risks of using social media for business purposes, such as enhancing brand awareness, engaging with customers, or sharing industry insights. They can also inform employees about the dos and don'ts of social media etiquette, such as respecting privacy, protecting intellectual property, avoiding conflicts of interest, or complying with legal obligations. Education and guidelines can also raise awareness of potential data leakage scenarios, such as phishing attacks, malicious links, fake profiles, or oversharing sensitive information, and provide tips on how to prevent or respond to them.
Which of the following would MOST likely impair the independence of the IS auditor when performing a post-implementation review of an application system?
The IS auditor provided consulting advice concerning application system best practices.
The IS auditor participated as a member of the application system project team, but did not have operational responsibilities.
The IS auditor designed an embedded audit module exclusively for auditing the application system.
The IS auditor implemented a specific control during the development of the application system.
The IS auditor's independence would be most likely impaired if they implemented a specific control during the development of an application system. This is because the IS auditor would be auditing their own work, which creates a self-review threat that could compromise their objectivity and impartiality. The IS auditor should avoid participating in any operational or management activities that could affect their ability to perform an unbiased audit. The other options do not pose a significant threat to the IS auditor's independence, as long as they follow the ethical standards and guidelines of the profession.
An IS auditor is planning an audit of an organization's accounts payable processes.
Which of the following controls is MOST important to assess in the audit?
Segregation of duties between issuing purchase orders and making payments.
Segregation of duties between receiving invoices and setting authorization limits
Management review and approval of authorization tiers
Management review and approval of purchase orders
The most important control to assess in an audit of an organization's accounts payable processes is segregation of duties between issuing purchase orders and making payments. Segregation of duties is a principle that requires different individuals or departments to perform different tasks or functions within a process, in order to prevent fraud, errors, or conflicts of interest. In the accounts payable process, segregation of duties between issuing purchase orders and making payments ensures that no one person can initiate and complete a transaction without proper authorization and verification. This reduces the risk of duplicate payments, overpayments, unauthorized payments, or payments to fictitious vendors.
References:
Accounts payable controls
Accounts Payable Internal Controls: A Simple Checklist
Which of the following is an executive management concern that could be addressed by the implementation of a security metrics dashboard?
Effectiveness of the security program
Security incidents vs. industry benchmarks
Total number of hours budgeted to security
Total number of false positives
The executive management concern that could be addressed by the implementation of a security metrics dashboard is the effectiveness of the security program. A security metrics dashboard is a tool that provides a visual representation of key performance indicators (KPIs) and key risk indicators (KRIs) related to the organization's information security objectives and activities. A security metrics dashboard can help executive management monitor and evaluate the performance and value delivery of the security program, identify strengths and weaknesses, assess compliance with policies and standards, and support decision making and improvement initiatives. Security incidents vs. industry benchmarks, total number of hours budgeted to security, and total number of false positives are not executive management concerns that could be addressed by the implementation of a security metrics dashboard. These are more operational or technical aspects of information security that could be measured and reported by other means, such as incident reports, budget reports, or log analysis.
References:
[ISACA CISA Review Manual 27th Edition], page 302
Spreadsheets are used to calculate project cost estimates. Totals for each cost category are then keyed into the job-costing system.
What is the BEST control to ensure that data is accurately entered into the system?
Reconciliation of total amounts by project
Validity checks, preventing entry of character data
Reasonableness checks for each cost type
Display the back of the project detail after the entry
Reconciliation of total amounts by project is the best control to ensure that data is accurately entered into the job-costing system from spreadsheets. Reconciliation is a process of comparing two sets of data to identify any differences or discrepancies between them. By reconciling the total amounts by project from spreadsheets with those from the job-costing system, any errors or omissions in data entry can be detected and corrected. Validity checks are controls that verify that data conforms to predefined formats or ranges. They can prevent entry of character data into numeric fields, but they cannot ensure that the numeric data is correct or complete. Reasonableness checks are controls that verify that data is within expected or acceptable limits. They can detect outliers or anomalies in data, but they cannot ensure that the data matches the source. Display back of project detail after entry is a control that allows the user to review and confirm the data entered into the system. It can help reduce human errors, but it cannot guarantee that the data is accurate or consistent with the source.
References:
Information Systems Operations and Business Resilience, CISA Review Manual (Digital Version)
Showing 10 of 2,178 questions · Unlock the full set