CISA Practice Questions I Want to Review Again

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/49

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 4:25 PM on 8/25/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

50 Terms

1
New cards

You are an information system auditor of HDA Inc. You are assessing the performance of a newly implemented system. Which of the following is the best method to measure its performance?

A. Post-implementation review

B. User satisfaction survey

C. System uptime and availability

D. Comparison with industry benchmarks

Correct answer: A. Post-implementation review More details: The best method to measure the performance of a newly implemented system is through a post-implementation review. A post-implementation review assesses the system‘s effectiveness, efficiency, and overall performance after it has been deployed. It involves evaluating factors such as functionality, usability, reliability, performance, and security to determine if the system is meeting the intended objectives and delivering the expected benefits. Option B suggests using a user satisfaction survey. While user satisfaction is an important aspect of system performance, it provides subjective feedback from users and may not provide a comprehensive evaluation of the system‘s overall performance. Option C suggests measuring system uptime and availability. While system uptime and availability are important indicators of system performance, they only provide a limited perspective on performance and do not capture other critical factors such as functionality, usability, or user experience. Option D suggests comparing the system‘s performance with industry benchmarks. While industry benchmarks can provide insights into how the system performs relative to similar systems in the industry, they may not reflect the specific requirements or objectives of the organization. A post-implementation review allows the organization to assess the system‘s performance holistically, considering various factors such as functionality, usability, reliability, performance, and security. It provides an opportunity to identify any issues, gaps, or areas for improvement and enables the organization to take corrective actions if necessary. Therefore, a post-implementation review is the best method to measure the performance of a newly implemented system.

2
New cards

You are an information system auditor of HDA Inc. You are developing a risk-based IS audit program. What should be your primary focus?

A. Technical vulnerabilities in the IT infrastructure

B. Compliance with regulatory requirements

C. Business strategic plans

D. Internal control frameworks

Correct answer: C. Business strategic plans More details: When developing a risk-based IS audit program, an IS auditor‘s primary focus should be on the organization‘s business strategic plans. Business strategic plans outline the organization‘s goals, objectives, and priorities, including its strategic initiatives and projects. By aligning the audit program with the business strategic plans, the auditor can identify the key risks and audit areas that are most critical to the organization‘s success. Option A suggests that the primary focus should be on technical vulnerabilities in the IT infrastructure. While technical vulnerabilities are important considerations in an IS audit program, they are not the primary focus. The focus should be broader, considering the organization‘s strategic objectives and risks. Option B suggests that the primary focus should be on compliance with regulatory requirements. Compliance is an important aspect of an IS audit program, but it may not capture the full scope of risks and priorities that are specific to the organization‘s business strategic plans. Option D suggests that the primary focus should be on internal control frameworks. While internal controls are essential for mitigating risks, they should be aligned with the organization‘s strategic plans and objectives. Therefore, the business strategic plans should take precedence in developing the risk-based IS audit program. By focusing on the organization‘s business strategic plans, the IS auditor can ensure that the audit program addresses the risks and controls that are most relevant to the organization‘s objectives and priorities. It enables the auditor to provide valuable insights and recommendations to support the organization‘s strategic initiatives and enhance its overall performance. Therefore, business strategic plans should be the primary focus when developing a risk-based IS audit program.

3
New cards

You are an information system auditor of HDA Inc. During an external review, you observe an inconsistent approach in classifying system criticality within the organization. What should be recommended as the primary factor to determine system criticality?

A. Number of users affected by system downtime

B. Maximum allowable downtime (MAD)

C. Financial impact of system failure

D. Age of the system

Correct answer: B. Maximum allowable downtime (MAD) More details: When determining system criticality, the primary factor that should be considered is the maximum allowable downtime (MAD). The MAD refers to the maximum duration of acceptable system downtime without causing significant negative consequences to the organization‘s operations or objectives. It represents the time limit within which a system must be restored or made available after an unexpected outage or disruption. Option A suggests that the number of users affected by system downtime should be the primary factor. While the number of affected users can provide insights into the impact of system downtime, it does not necessarily reflect the criticality of the system. A system with a smaller number of users may still be critical to the organization‘s core operations. Option C suggests that the financial impact of system failure should be the primary factor. While the financial impact is an important consideration, it may vary depending on the organization‘s industry, size, and specific circumstances. System criticality should not solely rely on financial impact but also consider other factors. Option D suggests that the age of the system should be the primary factor. While the age of the system can influence its reliability and supportability, it does not directly determine its criticality. A newer system can be critical to the organization, while an older system may still serve vital functions. By considering the maximum allowable downtime (MAD) as the primary factor, the organization can prioritize its systems based on the time sensitivity of their availability. Critical systems, with shorter MADs, would require higher levels of resilience, redundancy, and rapid recovery measures to minimize downtime. This approach ensures that resources and efforts are appropriately allocated to safeguard the most critical systems and maintain business continuity. Therefore, the maximum allowable downtime (MAD) should be recommended as the primary factor to determine system criticality.

4
New cards

You are an information system auditor of HDA Inc. You are conducting an audit to evaluate the effectiveness of a phishing simulation test conducted for staff members. Which of the following findings should raise the highest level of concern?

A. Overall click rate on the phishing link

B. Absence of follow-up training for employees who clicked on the phishing link

C. Number of employees who reported the phishing attempt

D. Accuracy of the phishing email template used

Correct answer: B. Absence of follow-up training for employees who clicked on the phishing link More details: While auditing the effectiveness of a phishing simulation test, the most significant concern for an IS auditor should be the lack of follow-up training provided to employees who clicked on the phishing link. The purpose of conducting a phishing simulation is to assess and enhance employees‘ awareness and response to phishing attacks. Clicking on the phishing link indicates a vulnerability that requires additional training to strengthen their understanding and ability to identify and address future phishing attempts. Option A suggests that the overall click rate on the phishing link is the greatest concern. While a high click rate may indicate the need for improved employee awareness, it is the absence of follow-up training that poses the more critical issue. Without proper training, the organization fails to mitigate the risks associated with employees who fell for the phishing attempt. Option C suggests that the number of employees who reported the phishing attempt is the greatest concern. While reporting is important, the primary focus should be on addressing the employees who clicked on the link, as they require immediate attention to minimize the potential impact and prevent future incidents. Option D suggests that the accuracy of the phishing email template used is the greatest concern. While template accuracy is essential for an effective simulation, the principal concern lies in providing follow-up training to the employees who interacted with the phishing attempt. By neglecting to provide follow-up training to employees who clicked on the phishing link, the organization misses a crucial opportunity to educate and reinforce awareness regarding phishing threats. Follow-up training enables employees to comprehend the risks, learn from their mistakes, and enhance their ability to recognize and appropriately respond to actual phishing attempts. Therefore, the absence of follow-up training for employees who clicked on the phishing link should be the highest cause for concern during the audit.

5
New cards

You work for HDA Inc. as an auditor of their information system. During the course of doing a security audit on an aging program that is due to be shut down in three months, you have discovered that it does not satisfy the security criteria that are outlined in the existing policy. As an auditor, what do you believe to be the MOST effective approach to taking care of this problem?

A. Recommend an immediate upgrade of the legacy application to meet the security requirements.

B. Propose a revision of the security policy to align with the capabilities of the legacy application.

C. Validate whether risk is accepted by the management.

D. Suggest replacing the legacy application with a new system that meets the security requirements.

Correct answer: C. Validate whether risk is accepted by the management. More details: In this situation, the best course of action for the IS auditor is to validate whether the management has accepted the risk associated with the legacy application not meeting the security requirements. Risk acceptance is a valid response when the cost or effort to upgrade or replace the application outweighs the potential impact of the security risks. Option A, recommending an immediate upgrade, may not be feasible due to the limited timeframe for decommissioning the application. It is important to consider the cost, resources, and time required for an upgrade. Option B, proposing a revision of the security policy, is not the best approach because the security policy should ideally align with the organization‘s security objectives, rather than adjusting it to fit the capabilities of a specific application. Option D, suggesting the replacement of the legacy application, may not be practical within the given timeline and budget constraints. The decision to replace an application should involve careful consideration of costs, implementation time, and potential business disruptions. Therefore, the most appropriate action for the IS auditor is to validate whether the management has accepted the risk associated with the legacy application not meeting the security requirements. This validation ensures that the organization‘s decision-makers are aware of the risks and have made an informed decision based on their risk tolerance and business priorities.

6
New cards

You work for HDA Inc. as an auditor of their information system. During an audit, you will evaluate the safeguards that a business has put into place to protect its proprietary code during a collaborative development activity that involves a third party. Which of the following safeguards an organization‘s proprietary code the most effectively, given this scenario?

A. Copyright registration of the code.

B. Nondisclosure agreement (NDA).

C. Encryption of the code.

D. Regular code review and audits.

Correct answer: B. Nondisclosure agreement (NDA). More details: When engaging in a joint-development activity involving a third party, a nondisclosure agreement (NDA) is the best measure to protect an organization‘s proprietary code. An NDA is a legal contract that ensures confidentiality and prohibits the third party from disclosing or using the proprietary code for unauthorized purposes. It establishes a legal framework to protect the organization‘s intellectual property and maintain confidentiality during the joint development process. Option A, copyright registration of the code, provides legal rights and protections for the organization‘s code. However, it does not specifically address the protection of the code during a joint-development activity with a third party. Option C, encryption of the code, can provide additional security to protect the code from unauthorized access or theft. However, it may not fully address the risks associated with joint development, as the third party involved in the activity would still have access to the decrypted code. Option D, regular code review and audits, is an important practice for ensuring code quality and identifying vulnerabilities. While it contributes to code protection, it does not specifically address the protection of the code during joint development with a third party. Therefore, the best measure to protect an organization‘s proprietary code during a joint-development activity involving a third party is to have a nondisclosure agreement (NDA) in place. This legal contract ensures that the third party understands and agrees to maintain the confidentiality of the proprietary code, providing the organization with legal recourse in case of any unauthorized disclosure or use.

7
New cards

You work for HDA Inc. as an auditor of their information system. You have identified a high-risk vulnerability in a web server that is exposed to the public and is utilized for processing payments made by customers online. What ought to be your VERY FIRST move in this situation?

A. Determine if compensating controls exist.

B. Inform the management about the vulnerability.

C. Immediately patch the vulnerability.

D. Conduct a detailed vulnerability assessment.

Correct answer: A. Determine if compensating controls exist. More details: Before taking any action, it is important for the IS auditor to determine if there are any compensating controls in place. Compensating controls are alternative measures that can mitigate the risk posed by a vulnerability when it is not feasible to immediately fix the vulnerability itself. By assessing the presence and effectiveness of compensating controls, the auditor can evaluate if they provide an adequate level of protection against the identified vulnerability. This step is crucial in determining the appropriate actions to be taken, as it helps in understanding the overall risk posture and potential impact on the organization. Based on the findings related to compensating controls, the auditor can then proceed with informing the management, patching the vulnerability, or conducting a detailed vulnerability assessment, as deemed necessary.

8
New cards

You work for HDA Inc. as an auditor of their information system. You have been tasked with providing recommendations on ways in which the organization can enhance its IT governance. Which of the following do you suggest would be the BEST choice?

A. To implement and monitor key performance indicators (KPIs).

B. To conduct regular vulnerability assessments.

C. To establish an incident response team.

D. To update security policies and procedures.

Correct answer: A. To implement and monitor key performance indicators (KPIs). More details: Implementing and monitoring key performance indicators (KPIs) is the best recommendation for improving IT governance. KPIs are quantifiable metrics that help organizations measure and assess their performance in achieving strategic objectives. By implementing relevant KPIs, the organization can monitor and evaluate its IT governance processes, identify areas for improvement, and make informed decisions based on measurable data. KPIs can cover various aspects of IT governance, such as IT service delivery, information security, project management, and IT risk management. Regularly reviewing and analyzing KPI data allows organizations to track their progress, identify trends, and take proactive measures to enhance IT governance effectiveness. While conducting regular vulnerability assessments, establishing an incident response team, and updating security policies and procedures are important activities in maintaining a robust IT governance framework, implementing and monitoring KPIs provide a comprehensive approach for ongoing performance evaluation and improvement.

9
New cards

You are an information system auditor of HDA Inc. Your organization is implementing a new health records system to replace a legacy system. Which of the following options poses the highest risk?

A. Inadequate training provided to staff on using the new system.

B. Technical compatibility issues between the new system and existing infrastructure.

C. Delays in system implementation leading to extended downtime.

D. Data migration issues leading to inaccurate patient records.

Correct answer: D. Data migration issues leading to inaccurate patient records. More details: When transitioning from a legacy health records system to a new system, one of the most significant risks for an IS auditor to consider is data migration issues that could result in inaccurate patient records. Data migration involves transferring data from the old system to the new system, and any errors or inconsistencies during this process can lead to incorrect patient information, which can have severe consequences for patient care and safety. Inaccurate records can impact diagnosis, treatment, medication administration, and overall healthcare decision-making. It can lead to potential legal and regulatory compliance issues as well. Therefore, ensuring the accuracy and integrity of patient data during the migration process is crucial. IS auditors should assess the controls and processes in place to validate and verify the accuracy of data migration, including data mapping, cleansing, transformation, and reconciliation. They should also review the data migration plan and procedures to identify any potential risks and recommend appropriate measures to mitigate them, such as conducting thorough testing, implementing data validation checks, and establishing data quality assurance processes.

10
New cards

You are an information system auditor of HDA Inc. You are reviewing an organization‘s information security management. What would be the MOST critical finding in this review?

A. Inadequate security controls for network infrastructure.

B. Lack of employee awareness training on security policies.

C. Insufficient allocation of budget for security initiatives.

D. Lack of official charter for the information security management system.

Correct answer: D. Lack of official charter for the information security management system. More details: When reviewing an organization‘s information security management, the most critical finding would be the lack of an official charter for the information security management system (ISMS). An ISMS charter provides a formal document that outlines the objectives, scope, responsibilities, and authority of the information security management system within the organization. Option A suggests inadequate security controls for network infrastructure. While this is a significant finding, it may not be the most critical as security controls can be enhanced and improved over time. A formal charter for the ISMS provides the foundation for effective security controls. Option B suggests a lack of employee awareness training on security policies. While employee awareness training is important, it is a specific control measure that can be addressed separately. The absence of an official ISMS charter is a more fundamental concern that affects the overall governance and management of information security. Option C suggests an insufficient allocation of budget for security initiatives. While budget allocation is important, it is not the most critical finding. A lack of an official ISMS charter indicates a deeper issue in the organization‘s commitment to information security management. By identifying the lack of an official charter for the ISMS, the auditor highlights a fundamental gap in the organization‘s approach to information security. The absence of a formal charter may indicate a lack of clear direction, accountability, and governance for managing information security risks. Therefore, the lack of an official charter for the information security management system is the MOST critical finding when reviewing an organization‘s information security management.

11
New cards

Which of the following audit finding should be considered as highest risk in a network audit?

A. Insufficient firewall rule documentation.

B. Weak password policies across user accounts

C. Outdated antivirus software on workstations.

D. Network device inventory is not maintained.

Option D. Network device inventory is not maintained.

From a CISA perspective, the absence of a maintained network device inventory represents the highest risk because the organization cannot fully identify, manage, or secure what it owns. Unknown or unmanaged devices may exist on the network, leading to unauthorized access, unpatched vulnerabilities, ineffective monitoring, and failed incident response. Without an accurate inventory, other security controls cannot be reliably designed, implemented, or audited, making this a foundational and high-impact risk.

Incorrect:

Option A. Insufficient firewall rule documentation.

Poor documentation increases operational and audit risk, but the firewall itself may still be correctly configured and functioning. This issue affects maintainability and governance rather than posing an immediate, enterprise-wide security exposure.

Option B. Weak password policies across user accounts.

Weak password policies are a serious security concern; however, they typically affect authentication controls rather than the entire network infrastructure. Compensating controls such as monitoring or MFA may partially mitigate the risk, making it lower than the absence of a full network inventory.

Option C. Outdated antivirus software on workstations.

Outdated antivirus increases malware risk on endpoints, but the scope is generally limited to workstations. Network-level visibility, segmentation, or other security controls may still reduce the overall impact, making this less critical than not knowing what devices exist on the network.

12
New cards

18. Question

You are an information system auditor of HDA Inc. You noted that a security loop was found in an application and corrected prior to release into production. After the release, the same issue was reported. Which of the following could be the most common cause?

a) Absence of a qualified developer

b) Absence of UAT and business sign-off procedures

c) Inadequate code review process

d) Lack of intrusion detection systems

Correct:

Option B. Absence of UAT and business sign-off procedures

From a CISA exam perspective, if a security loophole was identified and corrected before production, but the same issue appears after release, the most common cause is weak or missing user acceptance testing (UAT) and business sign-off. Without formal UAT and approval, fixes may not be fully validated, may be overwritten by other changes, or the corrected version may not be the one promoted to production. This indicates a breakdown in change management and release controls, which is a key audit concern.

Incorrect:

Option A. Absence of a qualified developer

If the issue was already identified and corrected prior to release, developer qualification is less likely to be the root cause. The problem lies in ensuring the corrected code is properly tested, approved, and migrated to production.

Option C. Inadequate code review process

An inadequate code review process could lead to defects being missed initially. However, in this scenario, the loophole was detected and fixed before production, indicating that review or testing did occur. The recurrence points more strongly to release or acceptance failures rather than code review.

Option D. Lack of intrusion detection systems

Intrusion detection systems help detect attacks and suspicious activity but do not prevent a previously fixed application vulnerability from reappearing in production. This option is not directly related to application development or change management controls.

13
New cards

You work for HDA Inc. as an auditor of their information system. You are doing an analysis of controls in order to reduce the likelihood of illegal access being gained to company-owned mobile devices that have been misplaced. Which of the following controls would be the BEST choice for achieving this goal?

A. Mobile encryption

B. Remote wipe capability

C. Strong passwords/PINs

D. Biometric authentication

Option A. Mobile encryption

Mobile encryption is the best control for reducing the likelihood of illegal access to data on a misplaced or lost mobile device. Even if an unauthorized individual gains physical possession of the device, encryption ensures that the stored data cannot be read without proper credentials. From a CISA perspective, encryption is a strong preventive control that protects confidentiality regardless of whether other controls fail.

Incorrect:

Option B. Remote wipe capability

Remote wipe is a corrective or detective control that works only after the device is reported lost and the wipe command is successfully executed. It does not prevent access during the time between loss and wipe and may fail if the device is offline.

Option C. Strong passwords/PINs

Strong authentication helps limit unauthorized access, but passwords and PINs can be guessed, bypassed, or extracted through technical attacks. Without encryption, data may still be accessed by removing storage media or exploiting system vulnerabilities.

Option D. Biometric authentication

Biometric controls improve user authentication but do not protect data at rest. Biometric mechanisms can sometimes be bypassed, and if the device storage is not encrypted, data may still be accessed by technical means.

14
New cards

You are conducting an audit of an organization’s disposal process and have noted several findings. Which of the following should be your GREATEST concern?

A. Incomplete disposal records for retired IT assets.

B. Inadequate review of disposal procedures.

C. Lack of segregation of duties in the disposal process.

D. Media is not retained till the end of the retention period.

Correct

Option D. Media is not retained till the end of the retention period Correct because failing to retain media until the legally or regulatorily required retention period ends poses the highest risk. This can lead to non-compliance with laws and regulations, potential legal penalties, and loss of critical evidence or business records. In the context of CISA exam questions, compliance and regulatory breaches are considered the greatest concern compared to procedural or documentation gaps.

Incorrect

Option A. Incomplete disposal records for retired IT assets Incorrect because while incomplete records reduce accountability and auditability, they are not as critical as violating retention requirements. This is more of a governance issue than a compliance breach.

Option B. Inadequate review of disposal procedures Incorrect because inadequate review may lead to inefficiencies or overlooked risks, but it does not directly equate to a compliance violation as severe as prematurely disposing of media.

Option C. Lack of segregation of duties in the disposal process Incorrect because lack of segregation increases the risk of fraud or error, but again, it is not as severe as failing to comply with mandatory retention requirements.

15
New cards

You are an information system auditor of HDA Inc. You are performing a risk assessment prior to an audit engagement. Which of the following is MOST important for you to consider?

A. The organization‘s financial statements and accounting practices.

B. The IT department‘s incident response plan.

C. The latest cybersecurity threat landscape.

D. The results of the last audit.

Option D. The results of the last audit

Correct. In CISA exam context, the results of the last audit are the most important input when performing a risk assessment prior to a new audit engagement.

They provide insight into previously identified weaknesses, control gaps, and areas of high risk. This helps the auditor prioritize focus areas and determine whether past issues were remediated.

Reviewing prior audit findings ensures continuity and strengthens the risk‑based audit approach.

Incorrect

Option A. Financial statements and accounting practices

Incorrect. While relevant for financial audits, CISA focuses on information systems. Financial statements are not the primary consideration for risk assessment in an IS audit.

Option B. IT department’s incident response plan

Incorrect. The incident response plan is important for evaluating preparedness, but it is not the most critical factor at the risk assessment stage. It is assessed later during control evaluation.

Option C. Latest cybersecurity threat landscape

Incorrect. Understanding the threat landscape is useful, but risk assessment must first be grounded in the organization’s internal audit history. External threats are considered, but they do not outweigh prior audit findings in importance.

16
New cards

You are an information system auditor of HDA Inc. Your IT team is in process of setting up a data classification procedure. Which of the following is MOST important aspect in in this process?

A. Developing encryption policies

B. Understanding the data classification levels

C. Implementing access control measures

D. Conducting security awareness training

Correct

Option B. Understanding the data classification levels

Correct because the foundation of a data classification procedure is clearly defining and understanding the classification levels (e.g., public, internal, confidential, restricted).

Without this, encryption policies, access controls, or training cannot be applied consistently.

As an auditor, ensuring that classification levels are well‑defined and aligned with business and regulatory needs is the most critical aspect.

Incorrect

Option A. Developing encryption policies

Incorrect because encryption policies are important, but they are secondary controls applied after classification levels are defined.

Encryption is a protection mechanism, not the core of classification itself.

Option C. Implementing access control measures

Incorrect because access controls depend on the classification levels.

You cannot design effective access controls until you know which data is sensitive and how it should be categorized.

Option D. Conducting security awareness training

Incorrect because training is valuable, but it is not the most important aspect during the setup phase of classification.

Training comes after the classification framework is established.

17
New cards

You work for HDA Inc. as an auditor of their information system. You are performing an evaluation of the controls in a system for accounts payable. Within the context of this system, which of the following is an illustration of a preventive control?

A. Vendor will be approved for payment only if they are included in the system‘s master vendor list.

B. Segregation of duties between invoice processing and payment authorization.

C. Regular review and reconciliation of accounts payable balances.

D. Implementation of two-factor authentication for accounts payable system access.

Correct

Option A. Vendor will be approved for payment only if they are included in the system’s master vendor list

Correct because this is a preventive control: it stops unauthorized or fraudulent vendors from being paid by ensuring only pre‑approved vendors exist in the system.

Preventive controls are designed to avoid errors or fraud before they occur, and restricting payments to the master vendor list directly prevents improper transactions.

Incorrect

Option B. Segregation of duties between invoice processing and payment authorization

Incorrect because while segregation of duties is a strong control, it is considered a detective or structural control, not purely preventive.

It reduces risk by ensuring no single individual can complete a fraudulent transaction, but it doesn’t directly prevent vendor approval issues.

Option C. Regular review and reconciliation of accounts payable balances

Incorrect because reconciliation is a detective control. It identifies discrepancies after transactions occur rather than preventing them.

Option D. Implementation of two‑factor authentication for accounts payable system access

Incorrect because 2FA is a technical access control that prevents unauthorized system access, but it does not specifically prevent improper vendor payments in the accounts payable process.

It is preventive in a general sense, but not in the context of vendor approval within accounts payable.

18
New cards

You are an information system auditor of HDA Inc. You suspect that an organization‘s computer are used for illegal activities. What would be your BEST course of action in this situation?

A. Conduct a forensic analysis of the computer system.

B. Report the suspicion to the organization‘s management.

C. Request the incident response team to conduct the investigation.

D. Preserve the computer system and await further instructions.

Correct

Option C. Request the incident response team to conduct the investigation

Correct because as an information system auditor, your role is not to directly perform forensic analysis or act independently.

The incident response team has the expertise, authority, and tools to properly investigate suspected illegal activities while maintaining evidence integrity.

This ensures the investigation follows organizational protocols and legal requirements, minimizing risk of mishandling evidence.

Incorrect

Option A. Conduct a forensic analysis of the computer system

Incorrect because auditors typically do not perform forensic analysis themselves. Doing so could compromise evidence and exceed the auditor’s role.

Option B. Report the suspicion to the organization’s management

Incorrect because while management should eventually be informed, the immediate and best action is to escalate to the incident response team. Management notification comes after proper investigation begins.

Option D. Preserve the computer system and await further instructions

Incorrect because simply preserving the system without escalation delays the investigation. The incident response team should be engaged immediately to take appropriate action.

19
New cards

You work for HDA Inc. as an auditor of their information system. You are thinking about incorporating data analytics strategies into your auditing practices. Why should an information systems auditor make use of data analytics tools in the first place?

  • A. Inherent risk

  • B. Control risk

  • C. Detection risk

  • D. Sampling risk


Correct

Option C. Detection risk

  • Correct because data analytics tools help auditors reduce detection risk.

  • Detection risk is the risk that an auditor fails to detect material errors or irregularities.

  • By using analytics, auditors can examine large volumes of data, identify anomalies, trends, and suspicious transactions more effectively than traditional sampling methods.

  • This improves audit quality and ensures that significant issues are not overlooked.

Incorrect

Option A. Inherent risk

  • Incorrect because inherent risk refers to the natural susceptibility of an account or process to misstatement, regardless of controls.

  • Data analytics does not change the inherent risk; it only helps auditors detect issues more efficiently.

Option B. Control risk

  • Incorrect because control risk is the risk that internal controls fail to prevent or detect misstatements.

  • While analytics can help evaluate controls, it does not directly reduce control risk—it reduces detection risk.

Option D. Sampling risk

  • Incorrect because sampling risk arises when conclusions drawn from a sample differ from those that would be drawn from the entire population.

  • Data analytics often eliminates or reduces sampling risk by allowing auditors to test entire datasets, but the primary exam focus is on detection risk.


20
New cards

You are an information system auditor of HDA Inc. You are planning to schedule a follow-up audit to validate the remediation of reported audit observations. What should be your GREATEST consideration?

a) Availability of audit staff

b) Budget constraints

c) Risk level of the audit observation

d) Timeline specified in the management responses

Correct answer: c) Risk level of the audit observation. More details: The risk level associated with the audit observation is the primary factor to consider when scheduling the follow-up audit. High-risk observations require prompt attention and verification of the effectiveness of the remediation efforts. By prioritizing based on risk level, the IS auditor can focus on critical areas and ensure that potential vulnerabilities or deficiencies have been adequately addressed. Option a) availability of audit staff is important, but it should not take precedence over the risk level of the audit observation. Adequate staff can be allocated based on the urgency and significance of the observations. Option b) budget constraints are also important, but they should be considered alongside the risk level. Higher-risk observations may necessitate a more immediate allocation of resources, while lower-risk observations can be addressed within budgetary constraints. Option d) the timeline specified in the management responses is relevant but should be considered in conjunction with the risk level. Adhering to the specified timeline is important, but if a high-risk observation requires more immediate attention, adjustments can be made to accommodate the criticality of the situation. Therefore, the greatest consideration when scheduling the follow-up audit is the risk level of the audit observation. This ensures that resources are appropriately allocated to address the most critical and high-risk areas of concern.

21
New cards

You are an information system auditor of HDA Inc. Which of the following provides the MOST useful information regarding an organization‘s risk appetite and tolerance?

  • a) Risk assessment reports

  • b) Risk Register

  • c) Risk profile

  • d) Incident response plans


Correct answer: c) Risk profile. More details: A risk profile provides comprehensive information about an organization‘s risk appetite and tolerance. It encompasses an understanding of the organization‘s willingness to take on risks to achieve its objectives and the level of risk it can tolerate. The risk profile considers various factors such as industry norms, regulatory requirements, strategic objectives, and stakeholder expectations. It helps in setting risk management strategies, prioritizing risk responses, and aligning risk-taking decisions with the organization‘s overall goals. Option a) Risk assessment reports focus on evaluating specific risks but may not provide a holistic view of risk appetite and tolerance. Option b) Risk Register is a tool used to document and track identified risks, but it may not explicitly capture information about an organization‘s risk appetite and tolerance. Option d) Incident response plans outline the procedures to address and mitigate specific incidents, but they do not provide comprehensive information about risk appetite and tolerance. Therefore, the risk profile is the most useful source of information for understanding an organization‘s risk appetite and tolerance as it provides a comprehensive assessment of the organization‘s approach to risk management and risk-taking decisions.

22
New cards

You are the information system auditor of HDA Inc. You are reviewing the installation of a new server. You would primarily  ensure that:

  • A) The server hardware meets the organization‘s performance requirements.

  • B) The server is compatible with the existing network infrastructure.

  • C) The server software is properly licensed.

  • D) Security settings are set as per the information security policy of the organization.


Correct answer: D) Security settings are set as per the information security policy of the organization. More details:As an information system auditor, one of the primary objectives during the review of a new server installation is to ensure that security settings are set in accordance with the organization‘s information security policy. Here‘s an explanation of why the other options are not the primary objective: A) The server hardware meets the organization‘s performance requirements: While it is important for the server hardware to meet the organization‘s performance requirements, it is not the primary objective of an information system auditor during the review. The auditor‘s focus is more on the security aspects rather than the hardware‘s performance capabilities. B) The server is compatible with the existing network infrastructure: Compatibility with the existing network infrastructure is indeed important, but it is not the primary objective of an information system auditor. Network compatibility is typically addressed by the IT team responsible for infrastructure management. C) The server software is properly licensed: Ensuring proper software licensing is essential for compliance and avoiding legal issues. However, while important, it is not the primary objective of an information system auditor during a server installation review. License compliance is typically addressed by the organization‘s software asset management team or procurement department. D) Security settings are set as per the information security policy of the organization: This option is the because an information system auditor‘s primary objective is to ensure that the security settings of the new server align with the information security policy of the organization. The auditor verifies that appropriate security configurations, access controls, authentication mechanisms, encryption protocols, and other security measures are in place to safeguard the server and the sensitive data it processes. This objective helps maintain the integrity, confidentiality, and availability of the organization‘s information assets.

23
New cards

You are an information system auditor of HDA Inc. You are assessing the responsibilities of user departments associated with program changes. Which of the following is the MOST important responsibility of user departments?

A. Ensuring proper documentation of program changes.

B. Reporting any program errors or issues promptly.

C. Collaborating with the IT department during the change process.

D. Testing and approving the changes before implementation.

Correct answer: D. Testing and approving the changes before implementation. More details: Among the given options, the most important responsibility of user departments associated with program changes is to test and approve the changes before implementation. User departments play a crucial role in ensuring that program changes are thoroughly tested to verify their functionality, reliability, and compatibility with existing systems and processes. By conducting testing and providing approval, user departments help mitigate the risk of introducing errors, bugs, or system failures that could have adverse impacts on business operations. Their involvement in testing and approval processes helps maintain the integrity and stability of the systems and supports a smooth transition during the implementation of program changes. Options A, B, and C are also important responsibilities of user departments in the context of program changes. Proper documentation of program changes ensures traceability, facilitates future reference, and aids in maintaining an audit trail. Reporting any program errors or issues promptly helps address potential risks and allows for timely resolution. Collaboration with the IT department during the change process ensures effective communication, coordination, and alignment between user departments and the IT team. While all of these responsibilities are important, testing and approving the changes before implementation is the most critical as it directly impacts the reliability and stability of the system. Therefore, the testing and approval of program changes by user departments is the most important responsibility to ensure a smooth and successful implementation of changes in the organization.

24
New cards

You are an information system auditor of HDA Inc. You are determining the primary basis for prioritizing follow-up audits. Which of the following factors should be considered as the PRIMARY basis for prioritization?

A. Severity of the findings.

B. Impact on business operations.

C. Residual risks of the findings.

D. Compliance with regulatory requirements.

Correct answer: C. Residual risks of the findings. More details: When prioritizing follow-up audits, the primary basis should be the residual risks associated with the findings from the previous audit. Residual risk refers to the level of risk that remains after controls have been implemented or modified to address identified risks. By assessing the residual risks of the findings, the auditor can determine the potential impact on the organization and prioritize follow-up audits accordingly. Option A suggests considering the severity of the findings. While severity is an important factor, it primarily reflects the immediate impact of the findings. However, prioritizing based solely on severity may not capture the overall risk profile of the organization if controls have been implemented to mitigate the severity. Option B suggests considering the impact on business operations. While the impact on business operations is relevant, it may not be the primary basis for prioritization. The focus should be on the residual risks of the findings to ensure that significant risks are addressed promptly. Option D suggests considering compliance with regulatory requirements. While compliance is important, it may not always align with the organization‘s risk priorities. Compliance requirements may not capture all the unique risks specific to the organization and its objectives. By prioritizing based on the residual risks of the findings, the auditor can assess the ongoing risks that may still exist despite control implementation. This approach allows the auditor to focus on addressing the most critical and impactful risks to the organization. Therefore, residual risks of the findings should be the PRIMARY basis for prioritizing follow-up audits.

25
New cards

You are an information system auditor at HDA Inc. You are reviewing the organization‘s data migration procedure. Which of the following is the most important action?

  • (A) Availability of migration audit procedure

  • (B) Compliance with data protection regulations.

  • (C) Documentation of project timelines.

  • (D) Availability of a roll-back plan.


Correct answer: (D) Availability of a roll-back plan. More details: When evaluating an organization‘s data conversion and infrastructure migration plan, the availability of a roll-back plan is the most important aspect for an IS auditor to verify. A roll-back plan outlines the procedures and steps to revert to the previous state in case the data conversion or infrastructure migration encounters issues or failures. It is a crucial risk mitigation measure that ensures business continuity and minimizes potential disruptions or data loss during the conversion or migration process. Verifying the availability of a roll-back plan demonstrates that the organization has considered the potential risks and has a contingency strategy in place to address unforeseen issues. Options (B), (C), and (D) are also important considerations, but they are secondary to the availability of a roll-back plan. 

26
New cards

You are an information system auditor at HDA Inc. Your IT head has requested you to suggest the best alternative for backup storage considering the shortage of backup devices. Your best recommendation would be: 

  • (A) Full backup procedure.

  • (B) Differential backup procedure.

  • (C) real time backup procedure.

  • (D) Mirror backup procedure.


Correct answer: (B) Differential backup procedure. More details: When there is a shortage of backup devices, the best alternative for backup storage is the differential backup procedure. In a differential backup approach, only the data that has changed since the last full backup is backed up. This means that each differential backup captures all the changes made to the data since the last full backup, regardless of subsequent backups. This approach allows for a more efficient backup process and reduces the storage space required compared to a full backup procedure. Real-time backup (option C) is not the best recommendation in this scenario, as it requires continuous and immediate backup of data, which may be resource-intensive and not feasible with a shortage of backup devices. The mirror backup procedure (option D) creates an exact copy of the entire data set, which can quickly consume storage space and may not be practical when there is a shortage of backup devices. Therefore, option (B) is the most suitable recommendation for backup storage in this situation.


(A) Full backup

  • Copies all data every time.

  • Requires the most storage space.

  • Not a good choice when backup devices are in short supply.

(B) Differential backup Correct

  • After one full backup, each differential backup copies only the data changed since the last full backup.

  • Uses much less storage than performing full backups every time.

  • Restoration is relatively simple:

    • Last full backup

    • Latest differential backup

This provides a good balance between storage efficiency and recovery speed.

(C) Real-time backup

  • Continuously copies data as it changes.

  • Requires constant storage and network resources.

  • Doesn't address the shortage of backup devices.

(D) Mirror backup

  • Creates an exact copy of the source.

  • Requires essentially the same amount of storage as the original data.

  • If a file is accidentally deleted, the deletion is often mirrored as well.

  • Not ideal when storage is limited.


27
New cards

You are an information system auditor at HDA Inc. You are currently reviewing the capacity management process of the organization. You observed that while determining the IT capacity, the business team is not consulted. Your primary concern would be:

  • (A) IT may not be able to support the future business requirements.

  • (B) Insufficient technical expertise within the business.

  • (C) Inadequate documentation of capacity management processes.

  • (D) Lack of communication and collaboration between IT and the business.


Correct answer: (A) IT may not be able to support the future business requirements. More details: Capacity management involves assessing and planning the resources required to meet the current and future demands of the business. Without involvement from the business, the capacity management activities may not accurately reflect the business requirements and objectives. This misalignment can lead to inefficiencies, ineffective resource allocation, and potentially hinder the system‘s ability to support the business operations effectively. Options (B), (C), and (D) are also important considerations, but they are secondary concerns compared to the lack of alignment with business objectives.

28
New cards

You are an information system auditor at HDA Inc. You highly suspect irregularity in a log application process. You intend to do a detailed investigation if one exception is found. This sampling is known as:

(A) Random sampling.

(B) Scientific sampling

(C) Discovery sampling.

(D) Systematic sampling.

Correct answer: (C) Discovery sampling. More details: Discovery sampling is a non-statistical sampling method that focuses on identifying and investigating specific exceptions or anomalies within a sample. It is used when there is a strong suspicion of irregularities or when the auditor wants to specifically look for specific deviations from normal behavior. It allows for targeted investigation and examination of specific instances that deviate from the expected or standard process. Random sampling (option A) is a statistical sampling method where each item in the population has an equal chance of being selected. Scientific sampling (option B) is a vague term and does not specifically describe a sampling method. Systematic sampling (option D) is a statistical sampling method where items are selected at regular intervals from an ordered list. Discovery sampling, with its focus on investigating exceptions, is the most suitable sampling method in this scenario.

29
New cards

You are an information system auditor of HDA Inc. You are currently evaluating the effectiveness of controls in the company‘s information system. In this context, which of the following options would be the MOST effective method for you to employ in order to assess the adequacy of controls?

  • A) Risk assessment

  • B) Policy review

  • C) Control testing

  • D) Incident response analysis


Correct answer: C) Control testing More details: Control testing refers to the process of evaluating the implementation and functionality of controls within an information system. It involves conducting various tests and procedures to verify whether the controls are operating as intended and effectively mitigating risks. While risk assessment (option A) is an important activity in identifying and prioritizing risks, it does not directly assess the effectiveness of controls. Policy review (option B) involves examining organizational policies and guidelines, which can provide insights into the design of controls, but it does not determine how well those controls are functioning in practice. On the other hand, control testing (option C) is specifically designed to assess the effectiveness of controls by actively testing and evaluating their performance. It helps auditors gather evidence on the adequacy, reliability, and efficiency of controls, ensuring they are functioning as intended and providing the desired level of security. Incident response analysis (option D) focuses on analyzing and responding to security incidents. While incident response is important for managing and mitigating the impact of security breaches, it is not directly related to assessing the effectiveness of controls. Therefore, control testing is the MOST helpful method for an IS auditor to assess the effectiveness of controls, as it directly evaluates their implementation and functionality.

30
New cards

You are the information system auditor of HDA Inc. You are reviewing an organization‘s robotic process automation (RPA) for automating different processes.. What is the MOST important aspect for you to confirm as an IS auditor during this review?

  • A) The technical compatibility of RPA tools with existing systems and applications.

  • B) The cost-effectiveness of implementing RPA compared to manual processes.

  • C) The level of employee training required for using RPA effectively.

  • D) Accountability for each process is clearly defined and documented.


Correct answer: D) Accountability for each process is clearly defined and documented. More details: When reviewing an organization‘s plans to implement RPA, the most important aspect for an IS auditor to confirm is the clarity and documentation of accountability for each process. RPA implementation requires a clear understanding of who is responsible for each automated task, ensuring proper oversight, control, and accountability. Options A, B, and C are also important considerations, but they do not address the central concern of accountability, which is crucial to maintaining a well-controlled and auditable RPA implementation.

31
New cards

You are the information system auditor of HDA Inc. You are conducting a post-implementation review of a critical application of the  HDA. During this review, end users express concerns about the accuracy of the critical transaction processed by the application. What should be your FIRST course of action as an IS auditor?

  • A) Review the system documentation related to the automatic calculations.

  • B) Perform a technical analysis of the ERP system‘s calculation algorithms.

  • C) Conduct interviews with key stakeholders involved in the development of the application

  • D) Evaluate the results of the user acceptance testing (UAT) conducted for the application.


Correct answer: D) Evaluate the results of the user acceptance testing (UAT) conducted for the application. More details: When concerns are raised about the accuracy of critical transactions processed by an application during a post-implementation review, the IS auditor‘s first course of action should be to evaluate the results of the user acceptance testing (UAT) conducted for the application. UAT involves end users testing the application‘s functionality, including transaction processing, to ensure it meets their requirements. Reviewing the UAT results will help assess whether the concerns raised by end users were identified during testing or if there are any discrepancies between the expected and actual behavior of the critical transactions. Options A and B are not directly applicable as they pertain to automatic calculations and calculation algorithms, which may not be relevant to the concerns raised about transaction accuracy. Option C, conducting interviews with key stakeholders, can be a valuable step but may be done in conjunction with reviewing the UAT results to gather additional information.

32
New cards

20. Question

What is the objective of a top-down maturity model?

A) To establish a hierarchy of processes within an organization

B) To identify the processes that need to be improved

C) To assess the industry level performance

D) To standardize processes across different departments

Incorrect

Correct

Option B. To identify the processes that need to be improved

Correct.

A top‑down maturity model is designed to evaluate organizational processes against defined maturity levels.

Its primary objective is to highlight which processes require improvement so that resources can be prioritized effectively.

This aligns with audit and governance practices where the focus is on continuous improvement and risk reduction.

Incorrect

Option A. To establish a hierarchy of processes within an organization

Incorrect.

While maturity models may categorize processes, their purpose is not to create a hierarchy but to assess process effectiveness and improvement needs.

Option C. To assess the industry level performance

Incorrect.

Maturity models are applied internally to an organization’s processes, not to benchmark industry‑wide performance.

Option D. To standardize processes across different departments

Incorrect.

Standardization may be a by‑product of process improvement, but it is not the primary objective of a top‑down maturity model.

33
New cards

You are an information system auditor at HDA Inc. You are reviewing the organization’s data classification scheme. You should primarily determine that:

  • (A). The data classification scheme is reviewed and updated regularly

  • (B). The procedure to protect the information is documented for each type of classification

  • (C). The data classification scheme is aligned with industry standards

  • (D). The data classification scheme is reviewed by an external auditor


Correct

Option B. The procedure to protect the information is documented for each type of classification

  • Correct because the primary objective of a data classification scheme is to ensure that information assets are protected according to their sensitivity and criticality.

  • Documentation of procedures for each classification level ensures that controls (e.g., access restrictions, encryption, handling requirements) are consistently applied.

  • This aligns with governance and compliance requirements, making it the most critical factor for an IS auditor to verify.

Incorrect

Option A. The data classification scheme is reviewed and updated regularly

  • Incorrect because while periodic review is important, it is a secondary control.

  • The primary concern is whether protection procedures are clearly defined and implemented for each classification level.

Option C. The data classification scheme is aligned with industry standards

  • Incorrect because alignment with standards is beneficial, but the core requirement is that the organization has documented procedures to protect its own classified data.

  • Standards provide guidance but do not replace internal documentation and enforcement.

Option D. The data classification scheme is reviewed by an external auditor

  • Incorrect because external review can validate effectiveness, but it is not the primary objective.

  • The auditor’s main focus should be on whether procedures exist and are applied internally.


34
New cards

Which of the following is the MOST significant contribution of audit frameworks ?

A) Establishing audit objectives and scope for specific audits.

B) Streamlining the documentation and reporting of audit findings.

C) Ensuring compliance with relevant laws, regulations, and standards.

D) Providing direction and guidance about audit performance.

Correct

Option D. Providing direction and guidance about audit performance

  • Correct because the primary role of audit frameworks is to establish a structured methodology for conducting audits.

  • Frameworks like COBIT, ISO, and NIST provide guidance, principles, and standardized practices that auditors can follow to ensure consistency, reliability, and quality in audit execution.

  • This contribution is the most significant because it ensures audits are performed systematically, reducing subjectivity and improving comparability across different audits.

Incorrect

Option A. Establishing audit objectives and scope for specific audits

  • Incorrect because while frameworks can help shape objectives and scope, these are typically defined by the audit plan and organizational requirements, not the framework itself.

  • Frameworks provide guidance, but objectives and scope are context‑specific.

Option B. Streamlining the documentation and reporting of audit findings

  • Incorrect because documentation and reporting are outputs of the audit process, not the core contribution of frameworks.

  • Frameworks may suggest reporting formats, but their main value lies in guiding audit performance, not simplifying paperwork.

Option C. Ensuring compliance with relevant laws, regulations, and standards

  • Incorrect because compliance is the responsibility of management and the organization, not directly the audit framework.

  • Frameworks help auditors assess compliance, but they do not themselves ensure compliance.


35
New cards

Identify a relevant contract term to be included in the agreement for a third‑party alternate site BCM arrangements. [BEB]

  • Round the clock guarded security

  • Total number of concurrent users (subscribers)

  • Feedback and references by other industry subscribers

  • Total number of contracted subscribers


Correct

Option B. Total number of concurrent users (subscribers)

  • Correct because in Business Continuity Management (BCM) contracts for alternate sites, it is critical to define how many users can access the site at the same time during a disaster.

  • This ensures capacity planning and prevents oversubscription, which could compromise recovery efforts.

  • Concurrent user limits are a standard and relevant contractual term for BCM arrangements.

Incorrect

Option A. Round the clock guarded security

  • Incorrect because while physical security is important, it is not the primary contractual term for BCM alternate site agreements.

  • Security measures are operational details, not the key contractual clause for capacity and availability.

Option C. Feedback and references by other industry subscribers

  • Incorrect because references or feedback are useful during vendor evaluation but are not contractual terms.

  • They do not guarantee service levels or capacity during a disaster.

Option D. Total number of contracted subscribers

  • Incorrect because the total contracted subscribers does not guarantee how many can use the site simultaneously.

  • BCM contracts must specify concurrent users, not just total subscribers, to ensure fair allocation during a disaster.


36
New cards

Identify a valid statement about disaster recovery testing methods from the following. [BGB]

  • Checklist review is about moving the systems to the alternate processing site and performing processing operations

  • Structured walk-through involves representatives from each of the functional areas coming together to go over the plan

  • Full interruption test is conducted by distributing copies of the plan to the various functional areas for review

  • Structured walk-through involves all employees who participate in the day-to-day operations coming together to practice executing the plan


Option B. Structured walk‑through involves representatives from each of the functional areas coming together to go over the plan.

  • Correct because a structured walk‑through (also called a tabletop exercise) is a low‑cost, low‑risk testing method where representatives from each functional area review the disaster recovery plan.

  • The purpose is to validate completeness, identify gaps, and ensure all stakeholders understand their roles without actually executing recovery procedures.

  • This matches the formal definition of a structured walk‑through in disaster recovery testing.

Incorrect

Option A. Checklist review is about moving the systems to the alternate processing site and performing processing operations.

  • Incorrect because a checklist review is simply a paper‑based validation of the plan against a checklist.

  • It does not involve moving systems or performing operations at an alternate site.

Option C. Full interruption test is conducted by distributing copies of the plan to the various functional areas for review.

  • Incorrect because a full interruption test is the most disruptive test type, requiring actual shutdown of primary systems and recovery at the alternate site.

  • Distributing copies of the plan for review describes a checklist review, not a full interruption test.

Option D. Structured walk‑through involves all employees who participate in day‑to‑day operations coming together to practice executing the plan.

  • Incorrect because structured walk‑throughs involve representatives, not all employees.

  • Involving all employees would be closer to a parallel test or full‑scale test, not a structured walk‑through.


37
New cards

An information systems auditor discovers that some magnetic hard drives disposed of by Guava Trading Inc were not sanitized in a manner that would reasonably ensure the data could not be recovered. In addition, the enterprise does not have a written policy on data disposal. The first step for the auditor to take:

  • Develop an appropriate data disposal policy for the organization

  • Discuss with the business unit head for their view on the data disposal practices

  • Draft an audit finding, and discuss it with the audit leader

  • Determine the sensitivity of the data on the magnetic hard drives


The immediate first step for an auditor will to determine the sensitivity of the data on inadequately disposed of disks.

38
New cards

Upon identification of data mismatch in product profitability reports produced by Guava Trading Inc’s finance and marketing department, the information systems auditor should recommend:

  • standardization of reporting tools

  • establishing and/or enhancing the data governance process

  • conducting a formal user acceptance testing for all reports before productionization

  • obtaining formal management sign-offs for all reports before productionization


  • establishing and/or enhancing the data governance process

  • The mismatch between the product profitability report produced by the two departments of the same organization reflects an underlying weakness in how the data is created and used across the organization which is best addressed by implementing an adequate data governance process in the organization.


39
New cards

The information system auditor discovers that the network diagram used for developing the scope of the audit is not updated recently, and there are network-connected devices that are not reflected in the diagram. The information system auditor must first:

  • expand the audit scope to include the devices that are connected to the network but are missing from the network diagram

  • Note the control deficiency because the network diagram has not been updated

  • evaluate the impact of undocumented on the audit scope

  • plan a follow-up audit for the undocumented devices


  • evaluate the impact of undocumented on the audit scope

  • The auditor must first evaluate the impact of the recent discovery on the audit scope and determine next course of action based on the outcome.


40
New cards

The information system auditor discovers that both the technology and accounting functions are being performed by the same user of the financial system during a compliance audit of a small local cooperative bank. Identify the best supervisor review control from the following:

  • Database table dump containing audit trails of date/time of each transaction

  • Daily summary of number of transactions and sum total of value of each transaction

  • User account administration report

  • Computer log files that show individual transactions in the financial system


Correct

Option D. Computer log files that show individual transactions in the financial system

  • Correct because computer log files provide a detailed audit trail of each transaction performed by the user.

  • This allows supervisors to review who did what, when, and how, ensuring accountability when segregation of duties is weak.

  • In small organizations where one person may perform multiple roles, reviewing transaction logs is the most effective compensating control.

Incorrect

Option A. Database table dump containing audit trails of date/time of each transaction

  • Incorrect because while a raw table dump shows data, it is not practical for supervisors to review.

  • It lacks usability and structured reporting, making it ineffective as a regular supervisory control.

Option B. Daily summary of number of transactions and sum total of value of each transaction

  • Incorrect because summaries provide only aggregate information.

  • They do not show individual user actions, so anomalies or fraudulent activity could go undetected.

Option C. User account administration report

  • Incorrect because this report focuses on account management activities (creation, deletion, privilege changes), not actual financial transactions.

  • It does not help supervisors monitor transaction‑level activity.


41
New cards

Blue Xylo Systems, a software development startup, intends to implement a suitable testing method to test the effectiveness of software program logic and determine the procedural accuracy of a program’s specific logic paths. Identify from following the right testing method to meet this objective. [BIG]

  • Black box test

  • Structured walkthrough

  • White box test

  • Paper test


White box testing is a test type that focuses on the effectiveness of software program logic and uses test data to determine the procedural accuracy of a program’s specific logic paths.

42
New cards

Gimmes often work through:

  • email attachment

  • SMS

  • news

  • file download

  • IRC chat


Option A. Email attachment

  • Correct because “gimmes” (a term often used in the context of social engineering or malware delivery) typically exploit email attachments to trick users into opening malicious files.

  • This is one of the most common attack vectors for phishing and malware distribution.

Incorrect

Option B. SMS

  • Incorrect because while SMS can be used in smishing attacks, it is not the primary method associated with “gimmes.”

Option C. News

  • Incorrect because news articles themselves are not a direct delivery mechanism for gimmes. Attackers may use fake news sites for phishing, but this is not the standard definition.

Option D. File download

  • Incorrect because gimmes are specifically tied to email attachments, not general file downloads. Downloads can be malicious, but they are not the typical “gimme” vector.

Option E. IRC chat

  • Incorrect because IRC chat is not a common or primary delivery method for gimmes. While attackers may use chat systems, gimmes are more closely tied to email attachments.

 

43
New cards

Which of the following refers to a primary component of corporate risk management with the goal of minimizing the risk of prosecution for software piracy due to use of unlicensed software?

  • Software audit

  • Test audit

  • System audit

  • Mainframe audit

  • Application System audit


Software audits are a component of corporate risk management, with the goal of minimizing the risk of prosecution for software piracy due to use of unlicensed software. From time to time internal or external audits may take a forensic approach to establish what is installed on the computers in an organization with the purpose of ensuring that it is all legal and authorized and to ensure that its process of processing transactions or events is correct.

44
New cards

Which of the following refers to the act of creating and using an invented scenario to persuade a target to perform an action?

  • None of the choices.

  • Backgrounding

  • Check making

  • Bounce checking

  • Pretexting


Option E. Pretexting

  • Correct because pretexting is a social engineering technique where an attacker fabricates a false scenario (the “pretext”) to manipulate a target into divulging information or performing an action.

  • Example: An attacker pretends to be from IT support and convinces an employee to reveal login credentials.

  • This directly matches the definition in the question: creating and using an invented scenario to persuade a target.

Incorrect

Option A. None of the choices

  • Incorrect because the correct answer is listed (Pretexting).

Option B. Backgrounding

  • Incorrect because backgrounding refers to gathering information about a target (research phase), not creating a false scenario to manipulate them.

Option C. Check making

  • Incorrect because this is unrelated to social engineering; it refers to fraudulent financial activity, not persuasion through invented scenarios.

Option D. Bounce checking

  • Incorrect because bounce checking is not a recognized social engineering technique. It does not involve fabricated scenarios to manipulate targets.


45
New cards

Which of the following is a tool you can use to simulate a big network structure on a single computer?

  • honeyd

  • None of the choices.

  • honeytube

  • honeymoon

  • honeytrap


Option A. honeyd

  • Correct because Honeyd is a well‑known honeypot framework that can simulate thousands of virtual hosts on a single machine.

  • It allows security professionals and auditors to emulate large network topologies, services, and operating systems for testing, monitoring, and deception purposes.

  • This makes it the right tool for simulating a big network structure on one computer.

Incorrect

Option B. None of the choices

  • Incorrect because the correct answer is listed (Honeyd).

Option C. honeytube

  • Incorrect because “honeytube” is not a recognized tool in network simulation or honeypot frameworks.

Option D. honeymoon

  • Incorrect because “honeymoon” is unrelated to IT or network simulation; it is not a technical tool.

Option E. honeytrap

  • Incorrect because Honeytrap is a honeypot tool used for intrusion detection, but it does not simulate large network structures on a single computer like Honeyd does.

  • Honeytrap focuses on capturing malicious traffic, not emulating entire network environments.


46
New cards

Which of the following types of attack makes use of unfiltered user input as the format string parameter in the printf() function of the C language?

  • format string vulnerabilities

  • command injection

  • buffer overflows

  • code injection

  • integer overflow


Option A. Format string vulnerabilities

  • Correct because this attack occurs when unfiltered user input is passed directly into functions like printf() without proper validation.

  • Attackers can exploit format specifiers (%s, %x, %n, etc.) to read memory, crash programs, or even execute arbitrary code.

  • This is a well‑known vulnerability in C/C++ programs and is specifically tied to improper handling of format strings.

Incorrect

Option B. Command injection

  • Incorrect because command injection involves inserting malicious commands into a program that executes system calls, not exploiting format strings in printf().

Option C. Buffer overflows

  • Incorrect because buffer overflows occur when input exceeds allocated memory buffers, leading to overwriting adjacent memory.

  • While both are memory‑related vulnerabilities, buffer overflow is distinct from format string attacks.

Option D. Code injection

  • Incorrect because code injection generally refers to inserting malicious code into an application (e.g., SQL injection, script injection).

  • Format string vulnerabilities are more specific to C language functions like printf().

Option E. Integer overflow

  • Incorrect because integer overflow occurs when arithmetic operations exceed the maximum value of an integer type.

  • This is unrelated to format string handling in printf().


47
New cards

What is the best defense against Distributed DoS Attack?

  • patch your systems.

  • run a virus checker.

  • find the DoS program and kill it.

  • None of the choices.

  • run an anti-spy software.


Option A. Patch your systems.

  • Correct because keeping systems patched reduces vulnerabilities that attackers exploit to build botnets used in DDoS attacks.

  • While patching alone does not stop incoming traffic floods, it is considered the best proactive defense since it prevents your systems from being compromised and used as part of the attack network.

  • In CISA exam context, patching is emphasized as a preventive control against being part of a DDoS botnet.

Incorrect

Option B. Run a virus checker.

  • Incorrect because antivirus software helps detect malware but does not prevent or mitigate large-scale traffic floods from distributed sources.

Option C. Find the DoS program and kill it.

  • Incorrect because in a distributed attack, the malicious traffic originates from thousands of compromised systems across the internet. Killing one program locally does not stop the attack.

Option D. None of the choices.

  • Incorrect because one choice (patching systems) is indeed a valid defense.

Option E. Run an anti-spy software.

  • Incorrect because anti-spyware tools target spyware/adware, not DDoS traffic floods. They do not mitigate distributed denial-of-service attacks.


48
New cards

The PRIMARY purpose of implementing Redundant Array of Inexpensive Disks (RAID) level 1 in a file server is to:

  •   ensure availability of data.

  •   provide user authentication.

  •   achieve performance improvement.

  • ensure the confidentiality of data.


Ensure availability of data

RAID level 1 provides disk mirroring. Data written to one disk are also written to another disk. Users in the network access data in the first disk; if disk one fails, the second disk takes over. This redundancy ensures the availability of datA. RAID level 1 does not improve performance, has no relevance to authentication and does nothing to provide for data confidentiality.

49
New cards

Which of the following terms is used more generally for describing concealment routines in a malicious program?

  • trojan horse

  • worm

  • rootkits

  • virus

  • spyware


  1. Rootkits can prevent a malicious process from being reported in the process table, or keep its files from being read. Originally, a rootkit was a set of tools installed by a human attacker on a Unix system where the attacker had gained administrator access. Today, the term is used more generally for concealment routines in a malicious program.


50
New cards

Iptables is based on which of the following frameworks?

  • NetDoom

  • NetCheck

  • Netfilter

  • NetSecure

  • None of the choices.


ipchains is a free software based firewall running on earlier Linux. It is a rewrite of ipfwadm but is superseded by iptables in Linux 2.4 and above. Iptables controls the packet filtering and NAT components within the Linux kernel. It is based on Netfilter, a framework which provides a set of hooks within the Linux kernel for intercepting and manipulating network packets.