Font size
S
M
L
XL
WorksheetsRevision Test 4
Total questions: 157
Worksheet time: 2hrs 58mins
Name
Class
Date
1.
This model is especially useful for resolving unclear objectives and<br /> requirements; developing and validating user requirements; experimenting with or<br /> comparing various design solutions, or investigating both performance and the<br />human computer interface.<br />
a)
Waterfall model
b)
Prototyping model
c)
Spiral Model
d)
Incremental model
2.
ISO 38500 asssist the organisation staff at
a)
middle level
b)
highest level
c)
low level
d)
All of above
3.
ISO 38500 applies to the governance of ----------- use of IT
a)
Current Use
b)
Future Use
c)
both of above
4.
Which of the following are not a key component of effective I&T governance structure
a)
Enterprises Risk Management
b)
I&T Risk Management
c)
Ensured Risk Optimisation
d)
All of above
5.
This questions refers to the following information. An IS auditor conducting a review of disaster recovery planning at a financial processing organization has discovered the following: The existing disaster recovery plan was compiled two years earlier by a systems analyst in the organization's IT department using transaction flow projections from the operations department. The plan was presented to the deputy CEO for approval and formal issue, but it is still awaiting his/her attention. The plan has never been updated, tested or circulated to key management and staff, though interviews show that each would know what action to take for its area in the event of a disruptive incident. The basis of an organization's disaster recovery plan is to reestablish live processing at <br />an alternative site where a similar, but not identical, hardware configuration is already <br />established. The IS auditor should:
a)
take no action as the lack of a current plan is the only significant finding
b)
recommend that the hardware configuration at each site is identical
c)
perform a review to verify that the second configuration can support live processing.
d)
report that the financial expenditure on the alternative site is wasted without an effective plan
6.
.............. Is not at type of application software
a)
Package Software
b)
Engineering Software
c)
Communication software
d)
Knowledge Software
e)
None of the Option
7.
The process of allotting weight-age for each requirement and then allotting score to the software that meets that requirement is called as
a)
Point scoring Analysis
b)
Agenda based presentations
c)
Public evaluation reports
d)
Benchmarking solutions
8.
Which of the following are primarily focus of risk management process
a)
Market Risk
b)
Credit Risk
c)
Operational Risk
d)
All of above
9.
Who ensures that system controls and supporting processes provide an effective level of protection, based on the data classification set in accordance with corporate security policies and procedures
a)
Security Officer
b)
Programmers/Developers
c)
Technology Specialist
d)
Systems Analyst
10.
Which of the following risks are not part and parcel of business activities
a)
Market Risk
b)
Credit Risk
c)
Operational Risk
d)
All of above
11.
Offsite Data Protection types include
a)
Data Vaults
b)
Hybrid Onsite and Offsite Vaulting
c)
Both of the above
d)
None of the above
12.
Which of the following are not a element of Risk Management
a)
Proactive approach
b)
No Ambuiguity
c)
Cultural change
d)
none of above
13.
,---------- is ability of organisation to sustain losses due to materialization of risk
a)
Risk Tolerance
b)
Risk Appetite
c)
Risk Mitigation
d)
Risk Transfer
14.
Which one of the following cloud concepts is<br />related to sharing and pooling the resources?
a)
Polymorphism
b)
Virtualisation
c)
Abstraction
d)
Encapsulation
15.
Which aspect related to Project Planning does process of handing over deliverables come under?<br />
a)
Project execution
b)
Project execution
c)
Project monitoring and controlling
d)
Project closing
16.
Graphical representation of risk profile is termed as
a)
Risk Profile
b)
Risk aggregation
c)
Heat Risk
d)
Risk Scenario
17.
Block the Socket (Socket is entry point i.e. Ip address + porttcp) component of incident is a process related to which phase of incident response?
a)
Identification
b)
Containment
c)
Eradication
d)
Isolation
18.
Blocks hold batches of valid transactions that<br />are hashed and encoded into a?
a)
Merkle Tree
b)
Cryptographic Hash
c)
Genesis Block
d)
Temporary Fork
19.
Overall scope and objectives of audit will normally change when we change from manual auditing to computerised environment
a)
true
b)
false
c)
Partly true
20.
Fine for failure to conduct data audit higher of
a)
5 crore or 2% of turnover
b)
5 crore or 4 % of turnover
c)
15 crore of 2% of turnover
d)
15 crore or 4% of turnover
21.
Which of the following states objectives of the project,the stakeholders in the system to be produced and project manager& project sponser
a)
Business case
b)
Project charter
c)
Both A and B
22.
Which of the following is popularly used for<br />storing bitcoins?
a)
Pocket
b)
Wallet
c)
Box
d)
Stack
23.
Scope of work of SOC team would defined in
a)
Operation
b)
Security
c)
Compliance
d)
All of the above
24.
Ensure that employees do not talk to the media '- is the responsibility of which Disaster Management Team?
a)
Administrative Responsibilities
b)
Network Responsibilities
c)
Public Relations Responsibilities
d)
Operations Responsibilities
25.
Risk assessement procedure includes which of the steps
a)
Inquires of the management and of others in entity
b)
Analytical procedure
c)
Observation and inspection
d)
All of the above
26.
The most important requirement of IT governance function to be effective is<br />
a)
Monitoring
b)
Evaluation
c)
Directing
d)
Managing
27.
SET of SIEM is used to perform correlation,indepth analysis,storing the analysis and reporting
a)
true
b)
false
28.
The use of a GANTT chart can:
a)
aid in scheduling project task
b)
determine project checkpoints.
c)
ensure documentation standard
d)
direct the post-implementation review
29.
Which of the following functions, if combined, would provide the<br />GREATEST risk to an organisation
a)
Systems analyst and Database administrator
b)
Quality assurance and computer operator
c)
Computer Operator and Tape Librarian
d)
Application Programmer and Data entry clerk
30.
In Bitcoin case, blockchain is used in a …… way
a)
Decentralized
b)
Centralized
c)
Both A and B
d)
None of the above
31.
Which of the following is the role of an IS Auditor in the detailed design phase of SDLC?
a)
Analyse the justification for going in for a development or acquisition
b)
Review input, processing and output controls
c)
Ensure that the documentation is complete
d)
Review QA report on adopting coding standards by developers
32.
…...... Is the layer which converts data into bits and puts it to copper wire or fiber wire for further transmission
a)
Application Layer
b)
Application Programming Interface
c)
Link Layer
d)
Internet Layer
33.
Type of computing technology i.e. services & apps that run on a distributed network through virtualized resources?
a)
Distributed Computing
b)
Cloud Computing
c)
Soft Computing
d)
Parallel Computing
34.
Which of the following is major risk factor
a)
Existence of inflaionary trends
b)
Vendor launches new software
c)
BOD elects new chairman
d)
Change in government post elections
35.
Decomposing object or executable code into source code and using it to analyse the program is known as
a)
Reverse engineering
b)
reenginnering
c)
blackbox testing
d)
both a and b
e)
none of above
36.
What is the purpose of Principles, policies and framework in an organization ?
a)
To control the employees
b)
To arrive at the business strategy of the organization
c)
To convey the management’s direction & instruction
d)
To comply with statutory regulations
37.
When the back-ups are taken of the system and data together, they are called total system’s back-up.
a)
True
b)
false
38.
Apart from being effective and efficient, what other characteristic should a good policy possess ?
a)
To control the employees
b)
Making sense & appearing logical to those who have to comply with them
c)
To arrive at the business strategy of the organization
d)
To comply with statutory regulations
39.
The scope of ---------------- encompasses all events and incidents (including security related) that could have an impact on ICT infrastructure and systems.
a)
ISO/IEC 27031:2011
b)
ISO 22301:2019
c)
Both of the above
d)
None of the above
40.
Processes are one of the 7 enablers of Governance of Enterprise IT under COBIT 2019. What are the types of processes distinguished under COBIT 2019 ?
a)
Strategy processes and action processes
b)
Group processes versus individual processes
c)
Governance processes and management processes
d)
Macro versus micro processes
41.
Which two of the following models will not be able to give the desired outcome if user participation is not involved
a)
Waterfall & spiral
b)
RAD & Spiral
c)
RAD & Waterfall
d)
RAD & prototyping
42.
How does the RACI (Responsible, Accountable, Consulted, Informed) model help in an organization ?
a)
Helps clarify roles and responsibilities
b)
Facilitates documentation of processes
c)
Basis for development of organization chart
d)
Accelerates decision-making process
43.
In Governance of Enterprise IT, the IT Strategy Committee should include
a)
Board members alone, considering the strategic content
b)
Non-Board members alone, considering the need for implementation support
c)
Both Board as well as non-Board members
d)
Board members and IT managers alone
44.
Which of the following is a program evaluation review technique that considers different scenarios for planning and control projects?
a)
Function Point Analysis (FPA)
b)
GANTT
c)
Rapid Application Development (RAD)
d)
PERT
45.
The MAJOR consideration for an IS auditor reviewing an organization's IT project portfolio is the
a)
IT budget
b)
existing IT environment
c)
business plan
d)
investment plan
46.
Which of the following has primary responsibility for implementation of Governance of Enterprise IT
a)
The Managing Director or CEO of the Organization
b)
The CIO of the organization
c)
The IT Strategy Committee
d)
The IT Steering Committee
47.
Which of the 7 enablers of COBIT 2019 is considered the most important ?
a)
Organization structure
b)
Principles, policies & framework
c)
Processes
d)
Information
48.
What are the security steps involved in the development phase of SDLC?
a)
To identify possible attacks and design controls
b)
To train developers on security coding practices
c)
To ensure security requirements are tested during testing
d)
To perform security scan of application after implementation
49.
Of the following, the MAIN purpose for periodically testing offsite facilities is to
a)
ensure the integrity of the data in the database
b)
eliminate the need to develop detailed contingency plans
c)
ensure the continued compatibility of the contingency facilities
d)
ensure that program and system documentation remains current.
50.
A blockchain, originally block chain, is a growing list of records, called blocks, that are linked using?
a)
Timestamp
b)
hash
c)
Merkle tree
d)
Cryptography
51.
Which of the following is the role of a programmer?
a)
Approve, supervise and direct IT projects
b)
Convert design into programs by coding
c)
Checking compliance with SDLC standards
d)
Testing programs and sub programs
52.
who is responsible for cyber security efforts and and initiatives?
a)
CEO
b)
CFO
c)
CTO
d)
CISO
53.
Who is ultimately responsible for providing requirement specifications to the software-development team?
a)
The project sponsor
b)
The project members
c)
The project leader
d)
The project steering committee
54.
Which of the following is considered to be most complex
a)
Waterfall
b)
Prototype
c)
Incremental
d)
Spiral
55.
The technical feasibility study for automating a business process using information technology includes which of the following?
a)
Is the cost of hardware and software for the class of applications being considered
b)
Are the benefits derived from new application such as improved efficiency, reduced costs, business growth, and customer and user satisfaction
c)
Is the cost of conducting a full systems development/acquisition, implementation and operation
d)
Is system scalable and can it handle the expected business and data growth?
56.
………….. is an SEIM TOOL,used to collect logs from devices
a)
Agents
b)
Collectors
c)
SIEM CORE
d)
All of the above
57.
Which of the following is a type of Cloud<br />Computing Service Models?
a)
Public-as-a-Service
b)
Platform-as-a-Service
c)
Community-as-a-Service
d)
Private-as-a-Service
58.
One of the primary reasons for implementing Governance of Enterprise IT (GEIT) is to alleviate pain points in the organization. Another major reason is
a)
Ensure up-to-date technology
b)
Trigger events like merger/acquisition, new regulations, etc
c)
Achieve stake holder satisfaction
d)
Higher vulnerability of IT compared to other functions
59.
The Crisis Phase is under the overall responsibility of the
a)
Incident Control Team (ICT).
b)
Business Continuity Team (BCT)
c)
Both of the above
d)
None of the above
60.
Which software category of maintenance is a reactive approach?
a)
Corrective
b)
Adaptive
c)
Preventive
d)
All of the above
61.
Which one of the following could be a Critical Success factor in GEIT implementation ?
a)
Trigger events like merger/acquisition, new regulations, etc.
b)
The project is handled exclusively & in isolation to day-to-day business
c)
Focus on quick wins to demonstrate benefit & build confidence
d)
Focus on quick wins to demonstrate benefit & build confidence
62.
In this model, a series of mini-waterfalls are performed, where all phases of the waterfall development model are completed for a small part of the system, before proceeding to the next increment. What SDLC model is this?<br />
a)
Waterfall model
b)
Prototype model
c)
Spiral model
d)
Incremental model
63.
How is alignment of strategic IT Plans with business done?
a)
Holding regular meetings with IT department participation
b)
Having an IT department nominee in non-IT meetings
c)
Clearly communicating the objectives & accountabilities
d)
Taking a bottom-up perspective
64.
Which of the following is the weakness of the Agile Software development methodology?
a)
Fast speed and lower cost may affect adversely the system quality
b)
The project may end up with more requirements than needed (gold-plating)
c)
Potential for feature creep where more and more features are added to the system during development
d)
There is lack of emphasis on necessary designing and documentation due to time management and generally is left out or incomplete.
65.
Which one of the following is a KEY management practice for aligning IT strategy with enterprise strategy ?
a)
Identify gaps between current & target environment
b)
Taking a bottom-up perspective
c)
Holding regular meetings with IT department participation
d)
Having an IT department nominee in non-IT meetings
66.
Which of the following metrics could be used for evaluation of value optimization ?
a)
Number of low cost IT equipment procured during a financial year
b)
Replacing full time IT employees with outsourced personnel
c)
Percentage of IT enabled investments where claimed benefits were met or exceeded
d)
Wage cost reduction through non-filling of some vacant IT positions
67.
With reference to Capex & Opex, how can valuation of any business be improved ?
a)
Increasing Capex & proportionately reducing Opex
b)
Reduction in Opex irrespective of impact on day-to-day operations
c)
With Capex constant, reduction in Opex without hurting day-to-day operations
d)
Increasing both Capex & Opex with the objective of increased profits
68.
The success of capacity management would depend most upon which one of the following factors ?
a)
Historical trend of capacity expansions
b)
Historical trend of capacity expansions
c)
Cost comparison through industry benchmarking
d)
Availability of adequate funds for procurement
69.
In OOSD the templates contains the characteristics of the Class --------
a)
Without containing specific data
b)
Containing specific data
c)
where data and procedure can be grouped
d)
None of above
70.
Which one of the following is an important tool used for managing & monitoring service providers ?
a)
Regular meetings
b)
Third party inspection arrangements
c)
Service Level Agreements
d)
Cost comparison through industry benchmarking
71.
During which phase of software maintenance process a downtime is announced
a)
During Scope of Maintenance
b)
During Plan of Maintenance
c)
During Software Maintenance
d)
During Go-Live
72.
To support an organization's goals, the IS department should have
a)
a low-cost philosophy
b)
long- and short-range plans.
c)
leading-edge technology
d)
planned to acquire new hardware and software
73.
User account information have the following information which is either
a)
clear text
b)
Hashed
c)
Both
d)
None of these
74.
The level at which the previously described established process operates within defined limits to achieve its process outcomes
a)
Level 5
b)
Level 3
c)
Level 2
d)
Level 4
75.
Objective of resource optimization process is to ensure
a)
Resource needs for the enterprise are minimised
b)
Return on IT investments is ensured.
c)
Increased monitoring of benefit realization
d)
Making IT infrastructure resilient
76.
Management of IS operation involves the operation of Information system for
a)
IT infrastructure
b)
server
c)
user operation
d)
All of these
77.
What often results in project scope creep when functional requirements are not defined as well as they could be
a)
Inadequate software baselining
b)
Insufficient strategic planning
c)
Inaccurate resource allocation
d)
Project delay
78.
System Software installed on mother board is called as ?
a)
CPU
b)
Dataware
c)
Firmware
d)
None of them
79.
In …......... Schema, the logical design of database is mapped to physical schema
a)
External Schema
b)
Conceptual Schema
c)
Physical Schema
d)
None of the Option
80.
--------------- is a parallel processing of transactions to an alternate site, as opposed to batch dump process like electronic vaulting.
a)
Remote journaling
b)
Database shadowing
c)
RAID level 5
d)
Electronic vaulting
81.
In line with ISO/IEC 38500, Governance processes under COBIT 2019 are based upon the principles of
a)
Evaluate, Direct, Monitor
b)
Align, Plan & Organize
c)
Monitor, Evaluate & Assess
d)
Build, Acquire and Implement
82.
How is Value Optimization of IT achieved ?
a)
Going in for low cost IT equipment
b)
Replacing full time IT employees with outsourced personnel
c)
Taking a bottom-up perspective
d)
Value Optimization of business processes, IT services & assets
83.
A good performance management system assesses performance against goals through Key Goal Indicators. Simultaneously, it monitors performance of process through _
a)
Work flow indicators
b)
Moving average indicators
c)
Moving average indicators
d)
Industry benchmarks
84.
Mr Johnson has just taken charge as Head of a fledgling educational institution which has not had a good track record. He feels that he has his task cut out for him he needs to focus more on the lead parameters rather than lag indicators so that he can create sustainable results. Which of the following would be an example of lead indicators
a)
Number of passes by students in the Matriculation examination
b)
Number of all-India rank holders from the school in the Matriculation examination
c)
Number of failures in the Matriculation examination
d)
Number of hours of refresher courses attended by teachers
85.
Test to be carried out when individual software modules are combined as group
a)
Unit testing
b)
Integration testing
c)
System testing
d)
White box testing
86.
_____________ is responsible for all digital initiatives in an organisation
a)
CIO
b)
CTO
c)
CISO
d)
CEO
87.
Which of the following life cycle model can't be chosen if the development team has less experience on similar projects
a)
spiral model
b)
Waterfall
c)
RAD
d)
Iterative model
88.
Which approach is usally adopted to devolop and improve the audit process on continuous basis so that focus is on high risk areas and maxi.value addition from resources deployed
a)
Internal Auditing
b)
IS audit
c)
Risk based Audit
d)
Internal and external control framework
89.
Basic Operation of SIEM tools, on the logs collected from the devices is
a)
Live correlating the logs
b)
correlating the log
c)
Collecting the log
d)
Analysing the log
90.
Identify the disadvantages of spiral model
a)
Doesn't work well for smaller project
b)
High amount of risk analysis
c)
Strong approval and documentation control
d)
Additional functionaltiy can be added at a later date
91.
What does User Acceptance Testing focus on?
a)
Ensuring that the system is production-ready and satisfies all accepted (baselined) requirements
b)
Conforming to the quality standards of the organisation accepted before development
c)
Documenting specifications, technology employed, use of coding standards
d)
Controlling the execution of tests and the comparing of actual outcomes with predicted outcomes
92.
The Balanced Score Card is an invaluable management tool that helps translate strategy into action and also for
a)
Balancing share holders needs with employee needs
b)
Bringing non-financial indicators into better focus
c)
Balancing needs of multiple functions within an organization
d)
Balancing lead and lag indicators
93.
.............. Is not at type of application software
a)
Package Software
b)
Engineering Software
c)
Communication software
d)
Knowledge Software
e)
None of the Option
94.
SIM is used to perform
a)
Correlation
b)
in depth analysis
c)
Storing and analysing files
d)
reporting
95.
All of the following are security and control concerns associated with disaster recovery procedures EXCEPT:
a)
Loss of audit trail.
b)
Insufficient documentation of procedures.
c)
Inability to restart under control.
d)
Inability to resolve system deadlock.
96.
The Balanced Score Card
a)
Is meant for the use of only the senior level executives
b)
Cannot be linked to the IT goals & objectives
c)
Cannot be the basis for performance incentives
d)
Can be cascaded down to all levels of the organization
97.
What is the primary purpose of an incident management program?
a)
Identify and assess incidents
b)
Conduct lessons learned sessions
c)
Alert key individuals
d)
Alert key individuals
98.
Logs generated by IS infrastructure in SOC are correlated to
a)
SIEM TOOLS
b)
CERT-IN
c)
Incident Resopnse Team
d)
All of the above
99.
A legacy payroll application is migrated to a new application. Which of the following stakeholders should be PRIMARILY responsible for reviewing and signing-off on the accuracy and completeness of the data before going live?
a)
IS auditor
b)
Database administrator
c)
Project manager
d)
Data Owner
100.
A mirror backup is identical to a full backup, with the exception that
a)
the files are not compressed in zip files
b)
they cannot be protected with a password
c)
Both of the above
d)
None of the above
101.
What is the most important aspect of the CIMA Strategic Score Card approach
a)
Focuses exclusively on strategy matters
b)
Focuses exclusively on IT governance & strategy aspects
c)
Addresses conformance as well as performance, focussing on strategic issues
d)
Unlike the Balanced Score card, it focuses on lead indicators alone
102.
Strategic position, Strategic options and Strategic implementation are three of the four basic elements of the CIMA Strategic Score card. What is the fourth element
a)
Strategic Risks
b)
Strategic Conformance
c)
Strategic Performance
d)
Strategic IT
103.
WHICH OF FOLLOWING IS A SYSTEM OF INTER-CONNECTED AND INTER-RELATED DEVICES ABILITY TO TRANSFER THE DATA OVER NETWORK
a)
ROBOTIC PROCESS AUTOMATION
b)
ARTIFICIAL INTELLIGENCE
c)
INTERNET OF THINGS
d)
BLOCKCHAIN
104.
Who have defined Balanced Scorecard?
a)
Robert S Kaplan
b)
David P Norton
c)
Both 1 and 2
d)
None of these
105.
The use of a GANTT chart can:
a)
aid in scheduling project task
b)
determine project checkpoints.
c)
ensure documentation standard
d)
direct the post-implementation review
106.
What is a reliable technique for estimating the scope and cost of a software-development project
a)
Function point analysis (FPA
b)
Feature point analysis (FPA)
c)
GANTT
d)
PERT
107.
Which of the following is not a necessary criteria for change management for IT department
a)
Minimum Cost
b)
Good quality
c)
Minimum Time
d)
Minimum business disruption
108.
Characteristics of BSC (Balanced Scorecard) is to provide a balance between relatively opposing forces like:-
a)
Internal and external influences
b)
Leading and lagging indicators and forces
c)
Financial and non financial goals
d)
Finance priorities and operations
e)
All of the above
109.
…............ Is a component of SQL which can Insert, Update, Select and Delete records in a Table
a)
Data Manipulation Language (DML)
b)
Data Control Language (DCL)
c)
Data Definition Language (DDL)
d)
None of the Option
110.
Under SQC 1 of ICAI the firm has an obligation to establish and maintain a system of quality control to provide it with reasonable assurance that
a)
The firm and its personnel comply with professional standards and regulatory and legal requirements
b)
The reports issued by the firm or engagement partners are appropriate in the circumstances
c)
Both of the above
d)
None of the above
111.
A professionally managed SOC may not provide real time alerts and data for investigation
a)
true
b)
false
c)
Can't say
112.
In which software testing approach, tester has knowledge of the internal working of the software
a)
Black box testing
b)
White box testing
c)
Grey box testing
d)
All of the above
113.
Which among the following is not an approch to conduct the interface / integration testing
a)
Sandwich
b)
Top-down
c)
Bottom-up
d)
Mid Level
114.
State the correct order
a)
Preparation, Identification,Containment,Recovery, Follow up,Documentation
b)
Preparation Identification,Containment,Follow up, Recovery,Documentation
c)
Identification,Preparation,Containment,Recovery, Follow up,Documentation
d)
Identification,Preparation,Containment,Recovery,Documentation, Follow up
115.
As per the IT asset management methodolgy, policy for network infrastructure
a)
10 yrs
b)
5 yrs
c)
3 yrs
d)
2 yrs
116.
Which are the common metrics in financial perspective of BSC
a)
Economic value added
b)
Market share
c)
Inventory turnover
d)
Turnover rate
117.
Diagnostic analysis examine
a)
insight based on past information
b)
cause of past result
c)
and recognize patterns and proactive action
d)
best option to choose
118.
Which are the common metrics in customer perspective of BSC
a)
Revenue growth
b)
Share of wallet
c)
On-time deliveries
d)
Profitability
119.
Which are the common metrics in internal process perspective of BSC
a)
Patents pending
b)
Inventory turnover
c)
Both 1 and 2
d)
None of these
120.
Which are the common metrics in learning and growth perspective of BSC
a)
Employee satisfaction
b)
Turnover rate
c)
Absenteeism
d)
Training hours
e)
All of the above
121.
Which are the performance measures in learning and growth perspective of BSC
a)
Brand awareness Score
b)
Increase shareholders value
c)
Market share
d)
Productivity index
122.
Which are the performance measures in customer perspective of BSC
a)
Market share
b)
Brand awareness Score
c)
Both 1 and 2
d)
None of these
123.
OOSD can be done using
a)
Waterfall model
b)
incremental model
c)
Both a and b but iterative approch is required
d)
Analysis and design are often considered at same time
e)
Both C and D
124.
In CMMI,In which level implemented process acheives its process purpose
a)
Established
b)
Optimized
c)
Performed
d)
Managed
125.
Configuration control refers to the----
a)
description of change
b)
Approver Authority
c)
Quality Assurance
d)
All of the above
126.
In service level agreement which of the followinbg challenges that need to be looked into by both the parties
a)
clear scope of services
b)
metric measurement
c)
responibilities
d)
All of these
127.
During which stage,project manager devolop&execute communication plan
a)
Project planning stage
b)
Project initiation stage
c)
project execution stage
d)
Monitioring stage
128.
ISO/IEC 27002:2013 is a code of practice - a generic, advisory document, not a formal specification such as ISO/IEC 27001:2013
a)
true
b)
false
c)
Partly True
129.
Gas leak outside or during working hours, repaired after some hours will call for which Phases of Disaster?
a)
All the phases, however, no staff and public evacuation
b)
Crisis Phase only, staff and public evacuation
c)
All phases in full
d)
Only emergency response phase is appropriate
130.
After implementation of a disaster recovery plan (DRP), predisaster and postdisaster operational cost for an organization will:
a)
decrease
b)
not change (remain the same)
c)
increase
d)
increase or decrease depending upon the nature of the business.
131.
IOT DEVICE HARDWARE LIFESPAN
a)
5 YEAR
b)
20 YEAR
c)
1 YEAR
d)
THEIR OWN LIFE CYCLE
132.
Which are the basic elements of strategic scorecard
a)
Strategic position
b)
Strategic options
c)
Strategic implementation
d)
Strategic risks
e)
All of the above
133.
------- backup captures files that were created or changed since the last backup, regardless of backup type.
a)
Incremental
b)
Differential
c)
Full
d)
Mirror
134.
The GREATEST challenge in outsourcing data<br />processing is
a)
Data confidentiality
b)
Distance
c)
Data integrity
d)
Cost
135.
Approval/ signoffs by the user and IT management at designated milestones is a feature of
a)
Incremental model
b)
Waterfall model
c)
Prototype model
d)
all of above
e)
both b and c
136.
What are benefits of effective performance mgt system
a)
Provides early warning indicator (EWI) for warning
b)
EWI of effectiveness of corrective action
c)
Provides feedback to stakeholders
d)
Builds common results language among all decision makers
e)
All of the above
137.
User connects through a client software to email server and downloads incoming mails. Mails are retained on the server even after they are downloaded. This is which type of Incoming mail Protocol
a)
POP 3
b)
IMAP
c)
SMTP
d)
None of the Option
138.
What is the role of IS auditor in requirement phase except
a)
Review the alternate solutions for reasonableness
b)
Review detailed requirement defination documents and verify its accuracy
c)
review existing data flow diagram and other related specification like forms data, output
d)
Identify the affected usess
139.
Performance measurement is used for the following:-
a)
Measure and manage products and services
b)
Assure accountability
c)
Make budgeting decisions
d)
Optimise performance
e)
All of the above
140.
What are the examples of performance measurement outcome:-
a)
Improved staff productivity
b)
Better salary hike
c)
More work life harmony
d)
More holidays for employees
141.
Which of the following tools and techniques primarily help in improving productivity of SDLC project team members?
a)
Use of Standard Methodology
b)
Software Sizing using FPA
c)
Developers’ Workbench
d)
Appropriate HR Policies
142.
The focus of ------------- is to ensure continuity of business delivery of products and services after occurrence of disruptive events (e.g., natural disasters, man-made disasters, etc.)
a)
ISO/IEC 27031:2011
b)
ISO 22301:2019
c)
Both of the above
d)
None of the above
143.
Which of the following activities is not involved in Log management
a)
Log Aggregation
b)
Log Collection
c)
Analysis
d)
All of them involve
144.
Who sets the goals and directions in the enterprise for monitoring performance mgt?
a)
CIO (Chief Information Officer)
b)
CTO (Chief Technical officer)
c)
Board of directors
d)
Service line managers
145.
What are the goals of performance measurement system?
a)
Input and feedback
b)
Outcome and performance
c)
Customer requirement and customer feedback
d)
Employee productivity and customer feedback
146.
An organization's IS audit charter should specify the:
a)
short- and long-term plans for IS audit engagements
b)
objectives and scope of IS audit engagement
c)
detailed training plan for the IS audit staff
d)
role of the IS audit function
147.
Organization considering deploying application using cloud computing services provided by third party service provider. The MAIN advantage of this arrangement is that it will:
a)
minimize risks associated with IT
b)
help in optimizing resource utilization
c)
ensure availability of skilled resources
d)
reduce investment in IT infrastructure
148.
Which of the following procedures would an IS auditor NOT perform during pre-audit planning to gain an understanding of the overall environment under review?
a)
Tour key organization activities
b)
Interview key members of management to understand business risks
c)
Perform compliance tests to determine if regulatory requirements are met
d)
Review prior audit reports
149.
During which phase of software maintenance process a downtime is announced
a)
During Scope of Maintenance
b)
During Plan of Maintenance
c)
During Software Maintenance
d)
During Go-Live
150.
While preparing the request for proposal, what should an organisation do to ensure vendor viability and financial stability?<br />
a)
Compare product functionalities against requirements
b)
Validate vendor claims about their product performance
c)
Get feedback from existing customers of the vendor on supporting documents of the vendor
d)
Evaluate what king of support the vendor provides
151.
……is the process of identifying threats and vulnerabilities to the Info.assets and deciding counter measures to reduce risk to acceptable low level
a)
Risk Based Audit
b)
Risk Management
c)
Risk Universe
d)
All the above
152.
Activities on critical path have --------- slack time.
a)
Zero
b)
Maximum
c)
Minimum
d)
Average
153.
Which of the following term is not correct
a)
IT department themselves only identify Configuration items
b)
Configuration control is the term used throughout the lifecycle of any hardware or software configuration change mgt.
c)
Configuration Status Accounting is more about documentation and communication of information
d)
None of the above
154.
IT resource optimization plan should primarily focus on
a)
Reducing cost of resources
b)
Ensuring availability
c)
Conducting training programs
d)
Information security issues
155.
Which of the following are NON_PROCEDURAL LANGUAGES?
a)
Query and Report Generators
b)
Embedded Database Languages
c)
Relational Database Languages
d)
All of the above
156.
As per ITAF issued by ISACA on materiality, at which stage the IS audit and assurance professionals shall consider potential weaknesses or absences of controls.
a)
Planning an engagement
b)
Executing an engagement
c)
Documenting
d)
Collecting evidence
157.
Which of the following is considered as an example of a lead indicator
a)
Comparative market position of organization
b)
Number of gaps with respect to industry standard
c)
Percentage of growth achieved over three years
d)
Improvement in customer satisfaction survey
Reset
