WorksheetsCISA Practice Exam
Total questions: 75
Worksheet time: 38mins
Which of the following processes will be MOST effective in reducing the risk that unauthorized software on a backup server is distributed to a production server?
Manually copy files to accomplish replication
Review changes in the software version control system.
Ensure that developers do not have access to the backup server
Review the access control log of the backup server
While performing an audit of an accounting application’s internal data integrity controls, an information systems (IS) auditor identifies a major control deficiency in the change management software supporting the accounting application. The MOST appropriate action for the IS auditor to take is to:
continue to test the accounting application controls and inform the IT manager about the control deficiency and recommend possible solutions.
complete the audit and not report the control deficiency because it is not part of the audit scope.
continue to test the accounting application controls and include the deficiency in the final report.
cease all audit activity until the control deficiency is resolved
When reviewing a hardware maintenance program, an information systems (IS) auditor should assess whether:
the schedule of all unplanned maintenance is maintained
it is in line with historical trends
it has been approved by the IS steering committee
the program is validated against vendor specifications
When reviewing the desktop software compliance of an organization, the information systems (IS) auditor should be MOST concerned if the installed software:
is installed, but not documented in the IT department records
is being used by users not properly trained in its use
is not listed in the approved software standards document
has a license that will expire in the next 15 days
When an employee is terminated from service, the MOST important action is to:
hand over all of the employee’s files to another designated employee
complete a backup of the employee’s work
notify other employees of the termination
disable the employee’s logical access
While evaluating software development practices in an organization, an information systems (IS) auditor notes that the quality assurance (QA) function reports to project management. The MOST important concern for an IS auditor is the:
effectiveness of the QA function because it should interact between project management and user management.
efficiency of the QA function because it should interact with the project implementation team.
effectiveness of the project manager because the project manager should interact with the QA function
efficiency of the project manager because the QA function needs to communicate with the project implementation team.
Change control for business application systems being developed using prototyping can be complicated by the:
iterative nature of prototyping
rapid pace of modifications in requirements and design
emphasis on reports and screens
lack of integrated tools
During an information systems (IS) audit of the disaster recovery plan of a global enterprise, the auditor observes that some remote offices have very limited local IT resources. Which of the following observations is the MOST critical for the IS auditor?
A test has not been made to ensure that local resources can maintain security and service standards when recovering from a disaster or incident.
The corporate business continuity plan (BCP) plan does not accurately document the systems that exist at remote offices.
Corporate security measures have not been incorporated into the test plan
A test has not been made to ensure that backups from the remote offices are usable
During an information systems (IS) risk assessment of a health care organization regarding protected health information (PHI), an IS auditor interviews IS management. Which of the following findings from the interviews would be of MOST concern to the IS auditor?
The organization does not encrypt all of its outgoing email messages
Staff have to type [PHI] in the subject field of email messages to be encrypted
An individual’s computer screen saver function is disabled.
Server configuration requires the user to change the password annually.
An information systems (IS) auditor reviewing wireless network security determines that the Dynamic Host Configuration Protocol is disabled at all wireless access points. This practice:
reduces the risk of unauthorized access to the network
is not suitable for small networks
automatically provides an Internet Protocol (IP) address to anyone
increases the risk associated with Wireless Encryption Protocol
Which of the following is MOST indicative of the effectiveness of an information security awareness program?
Employees report more information regarding security incidents
All employees have signed the information security policy
Most employees have attended an awareness session
Information security responsibilities have been included in job descriptions
An information systems (IS) auditor performing a review of application controls evaluates the:
efficiency of the application in meeting the business processes
impact of any exposures discovered
business processes served by the application
application optimization
Which of the following processes should an information systems (IS) auditor recommend to assist in the recording of baselines for software releases?
User acceptance testing (UAT)
Backup and recovery
Incident management
Configuration management
Which of the following does a lack of adequate controls represent?
An impact
A vulnerability
An asset
A threat
Which of the following sampling methods is MOST useful when testing for compliance?
Attribute sampling
Variable sampling
Stratified mean-per-unit sampling
Difference estimation sampling
The PRIMARY goal of a website certificate is:
authentication of the website that will be surfed.
authentication of the user who surfs through that site.
preventing surfing of the website by hackers.
the same purpose as that of a digital certificate.
An information systems (IS) auditor discovers several IT-based projects were implemented and not approved by the steering committee. What is the GREATEST concern for the IS auditor?
The IT department’s projects will not be adequately funded.
IT projects are not following the system development life cycle (SDLC) process.
IT projects are not consistently formally approved.
The IT department may not be working toward a common goal.
Which of the following is an advantage of prototyping?
The finished system normally has strong internal controls.
Prototype systems can provide significant time and cost savings.
Change control is often less complicated with prototype systems.
Prototyping ensures that functions or extras are not added to the intended system.
Which of the following provides the GREATEST assurance for database password encryption?
Secure hash algorithm-256
Advanced encryption standard (AES)
Secure Shell (SSH)
Triple DES (3DES)
An information systems (IS) auditor reviewing the authentication controls of an enterprise should be MOST concerned if:
user accounts are not locked out after five failed attempts
passwords can be reused by employees within a defined time frame
system administrators use shared login credentials
password expiration is not automated
What is the PRIMARY reason for an information systems (IS) auditor to exercise due professional care?
To get reasonable assurance that IS controls are well-designed and effective
To eliminate inherent, control and detection risk associated with IS audit
To detect errors, misstatements or fraudulent transactions in IS and report them
To make sure that evidence collected during the IS audit is appropriate and sufficient
When developing a security architecture, which of the following steps should be executed FIRST?
Developing security procedures
Defining a security policy
Specifying an access control methodology
Defining roles and responsibilities
Which of the following preventive controls BEST helps secure a web application?
Password masking
Developer training
Use of encryption
Vulnerability testing
An organization is implementing an enterprise resource planning (ERP) application. Of the following, who is PRIMARILY responsible for overseeing the project to ensure that it is progressing in accordance with the project plan and that it will deliver the expected results?
Project sponsor
System development project team
Project steering committee
User project team
The BEST method for assessing the effectiveness of a business continuity plan (BCP) is to review the:
plans and compare them to appropriate standards
results from previous tests
emergency procedures and employee training
offsite storage and environmental controls
Which of the following does an information systems (IS) auditor consider to be MOST important when evaluating an organization’s IT strategy? That it:
was approved by line management
does not vary from the IT department’s preliminary budget
complies with procurement procedures
supports the business objectives of the organization
Which of the following should an information systems (IS) auditor recommend to BEST enforce alignment of an IT project portfolio with strategic organizational priorities?
Define a balanced scorecard (BSC) for measuring performance
Consider user satisfaction in the key performance indicators (KPIs)
Select projects according to business benefits and risk
Modify the yearly process of defining the project portfolio
An offsite information processing facility (IPF) with electrical wiring, air conditioning and flooring, but no computer or communications equipment, is a:
cold site
warm site
dial-up site
duplicate processing facility
Which of the following reports should an information systems (IS) auditor use to check compliance with a service level agreement’s requirement for uptime?
Utilization reports
Hardware error reports
System logs
Availability reports
From an IT governance perspective, what is the PRIMARY responsibility of the board of directors? To ensure that the IT strategy:
is cost-effective.
is forward thinking and innovative.
is aligned with the business strategy.
has the appropriate priority level assigned.
Which of the following distinguishes a business impact analysis (BIA) from a risk assessment?
Inventory of critical assets
Identification of vulnerabilities
Listing of threats
Determination of acceptable downtime
Which of the following is an implementation risk within the process of decision support systems (DSSs)?
Management control
Semi-structured dimensions
Inability to specify purpose and usage patterns
Changes in decision processes
Which of the following types of testing determines whether a new or modified system can operate in its target environment without adversely impacting other existing systems?
Parallel testing
Pilot testing
Interface/integration testing
Sociability testing
Which of the following is the BEST audit procedure to determine if a firewall is configured in compliance with the enterprise security policy?
Review the parameter settings.
Interview the firewall administrator.
Review the actual procedures.
Review the device’s log file for recent attacks.
A legacy payroll application was migrated to a new application. Which of the following stakeholders should be PRIMARILY responsible for reviewing and signing off on the accuracy and completeness of the data before going live?
Information systems (IS) auditor
Database administrator (DBA)
Project manager
Data owner
During an assessment of software development practices, an information systems (IS) auditor finds that open-source software components were used in an application designed for a client. What is the GREATEST concern that the auditor has about the use of open-source software?
The client did not pay for the open-source software components
The organization and client must comply with open-source software license terms
Open-source software has security vulnerabilities
Open-source software is unreliable for commercial use
Which of the following types of transmission media provide the BEST security against unauthorized access?
Copper wire
Shielded twisted pair
Fiber-optic cables
Coaxial cables
Corrective action has been taken by an auditee immediately after the identification of a reportable finding. The information systems (IS) auditor should:
include the finding in the final report because the IS auditor is responsible for an accurate report of all findings.
not include the finding in the final report because management resolved the item.
not include the finding in the final report because corrective action can be verified by the IS auditor during the audit.
include the finding in the closing meeting for discussion purposes only.
An information systems (IS) auditor is developing an audit plan for an environment that includes new systems. Enterprise management wants the IS auditor to focus on recently implemented systems. How should the IS auditor respond?
Audit the new systems as requested by management
Audit systems not included in last year’s scope
Determine the highest-risk systems and plan accordingly
Audit systems not in last year’s scope and the new systems
The Transport Layer Security (TLS) protocol ensures the confidentiality of data and message by using:
symmetric encryption
message authentication codes
hash function
digital signature certificates
What is the MAJOR benefit of conducting a control self-assessment (CSA) over a traditional audit?
It detects risk sooner.
It replaces the internal audit function.
It reduces the audit workload.
It reduces audit resource requirements.
Which of the following tasks should be performed FIRST when preparing a disaster recovery plan (DRP)?
Develop a recovery strategy
Perform a business impact analysis (BIA)
Map software systems, hardware and network components
Appoint recovery teams with defined personnel, roles and hierarchy
Which of the following would be a MAJOR concern for an information systems (IS) auditor reviewing a business continuity plan (BCP)?
The plan is approved by the chief information officer.
The plan contact lists have not been updated.
Test results are not adequately documented.
The training schedule for recovery personnel is not included.
An information systems (IS) auditor wants to analyze audit trails on critical servers to discover potential anomalies in user or system behavior. Which of the following is the MOST suitable for performing that task?
Computer-aided software engineering tools
Embedded data collection tools
Trend/variance detection tools
Heuristic scanning tools
When testing program change requests for a remote system, an information systems (IS) auditor finds that the number of changes available for sampling does not provide a reasonable level of assurance. What is the MOST appropriate action for the IS auditor to take?
Develop an alternate testing procedure
Report the finding to management
Perform a walkthrough of the change management process
Create additional sample data to test additional changes
The final decision to include a material finding in an audit report should be made by the:
audit committee
auditee’s manager
information systems (IS) auditor
chief executive officer
Which of the following BEST provides assurance of the integrity of new staff?
Background screening
References
Bonding
Qualifications listed on a resume
An information systems (IS) auditor of a health care organization is reviewing contractual terms and conditions of a third-party cloud provider being considered to host patient health information. Which of the following contractual terms is the GREATEST risk to the customer organization?
Data ownership is retained by the customer organization.
The third-party provider reserves the right to access data to perform certain operations.
Bulk data withdrawal mechanisms are undefined.
The customer organization is responsible for backup, archiving and restoration.
An information systems (IS) auditor is assigned to review an organization’s information security policy. Which of the following issues represents the HIGHEST potential risk?
The policy has not been updated in more than one year.
The policy includes no revision history.
The policy is approved by the security administrator.
The organization does not have an information security policy committee.
The information systems (IS) auditor is reviewing the implementation of a storage area network (SAN). The SAN administrator indicates that logging and monitoring is active, hard zoning is used to isolate data belonging to different business units and all unused SAN ports are disabled. The administrator implemented the system, performed and documented security testing during implementation and is the only user with administrative rights to the system. What should the IS auditor’s initial determination be?
There is no significant potential risk.
Soft zoning presents a potential risk.
Disabling unused ports presents a potential risk.
The SAN administrator presents a potential risk.
Which of the following is MOST critical for the successful implementation and maintenance of a security policy?
Assimilation of the framework and intent of a written security policy by all appropriate parties
Management support and approval for the implementation and maintenance of a security policy
Enforcement of security rules by providing punitive actions for any violation of security rules
Stringent implementation, monitoring and enforcing of rules by the security officer through access control software
Enterprise governance of IT frameworks has been developed MAINLY to help an organization’s leaders:
use resources responsibly and manage information systems risk.
realize benefits and manage the performance of practices and processes.
deliver value to stakeholders and preserve the value created.
establish accountability and manage information security risk.
Which of the following is the MOST important skill that an information systems (IS) auditor should develop to understand the constraints of conducting an audit?
Managing audit staff
Allocating resources
Project management
Attention to detail
If inadequate, which of the following is the MOST likely contributor to a denial-of-service (DoS) attack?
Router configuration and rules
Design of the internal network
Updates to the router system software
Audit testing and review techniques
The cost of ongoing operations when a disaster recovery plan (DRP) is in place, compared to not having a DRP, will MOST likely:
increase
decrease
remain the same
be unpredictable
Which one of the following can be used to provide automated assurance that proper data files are being used during processing?
File header record
Version usage
Parity checking
File security controls
A database administrator (DBA) who needs to make emergency changes to a database after normal working hours should log in:
with their named account to make the changes.
with the shared DBA account to make the changes.
to the server administrative account to make the changes.
to the user’s account to make the changes.
An enterprise has established a guest network for visitor access. Which of the following should be of GREATEST concern to an information systems (IS) auditor?
A login screen is not displayed for guest users
The guest network is not segregated from the production network
Guest users who are logged in are not isolated from each other
A single-factor authentication technique is used to grant access
The BEST overall quantitative measure of the performance of biometric control devices is:
false-rejection rate (FRR)
false-acceptance rate (FAR)
equal error rate (EER)
estimated-error rate
Which of the following must exist to ensure the viability of a duplicate information processing facility (IPF)?
The site is near the primary site to ensure quick and efficient recovery
The site contains the most advanced hardware available
The workload of the primary site is monitored to ensure adequate backup is available
The hardware is tested when it is installed to ensure it is working properly
Which of the following groups would create the MOST concern to an information systems (IS) auditor if the group has full access to the production database?
Application developers
System administrators
Business users
Information security team
Which of the following is the MOST important consideration when defining recovery point objectives (RPOs)?
Minimum operating requirements
Acceptable data loss
Mean time between failures
Acceptable time for recovery
To address an organization’s disaster recovery requirements, backup intervals should not exceed the:
service level objective
recovery time objective (RTO)
recovery point objective (RPO)
maximum acceptable outage (MAO)
An organization sells books and music online on its secure website. Transactions are transferred to the accounting and delivery systems every hour to be processed. Which of the following controls BEST ensures that sales processed on the secure website are transferred to both systems?
Transaction totals are recorded daily in the sales systems. Daily sales system totals are aggregated and totaled.
Transactions are automatically numerically sequenced. Sequences are checked and gaps in continuity are accounted for.
Processing systems check for duplicated transaction numbers. If a transaction number is duplicated (already present), it is rejected.
System time is synchronized hourly using a centralized time server. All transactions have a date/time stamp.
Which of the following is of GREATEST concern to an information systems (IS) auditor when performing an audit of a client relationship management system migration project?
The technical migration is planned for a Friday preceding a long weekend, and the time window is too short for completing all tasks.
Employees pilot testing the system are concerned that the data representation in the new system is completely different from the old system.
A single implementation is planned, immediately decommissioning the legacy system.
Five weeks prior to the target date, there are still numerous defects in the printing functionality of the new system’s software.
An information systems (IS) auditor reviewing a cloud computing environment that is managed by a third party should be MOST concerned when:
The enterprise is not permitted to assess the controls in the participating vendor’s site.
The service level agreement (SLA) does not address the responsibility of the vendor in the case of a security breach.
Laws and regulations are different in the countries of the enterprise and the vendor.
The enterprise is using an older version of a browser and is vulnerable to certain types of security risk.
When reviewing system parameters, an information systems (IS) auditor’s PRIMARY concern should be that:
they are set to meet both security and performance requirements
changes are recorded in an audit trail and periodically reviewed
changes are authorized and supported by appropriate documents
access to parameters in the system is restricted
What BEST describes the risk that information collected may contain a material error that may go undetected during information systems (IS) auditing?
Inherent risk
Audit risk
Control risk
Detection risk
The PRIMARY objective of performing a postincident review is that it presents an opportunity to:
improve the internal control process.
harden the network to industry good practices.
highlight the importance of incident response management to management.
improve employee awareness of the incident response process.
Which of the following would be the BEST overall control for an Internet business looking for confidentiality, reliability and integrity of data?
Transport Layer Security (TLS)
Intrusion detection system (IDS)
Public key infrastructure
Virtual private network (VPN)
An organization has contracted with a vendor for a turnkey solution for its electronic toll collection system (ETCS). The vendor has provided its proprietary application software as part of the solution. The contract should require that:
a backup server is available to run ETCS operations with up-to-date data
a backup server is loaded with all relevant software and data
the systems staff of the organization is trained to handle any event
source code of the ETCS application is placed in escrow
When reviewing an enterprise’s logical access security to its remote systems, which of the following would be of GREATEST concern to an information systems (IS) auditor?
Passwords are shared.
Unencrypted passwords are used.
Redundant logon IDs exist.
Third-party users possess administrator access.
On which of the following factors should an information systems (IS) auditor PRIMARILY focus when determining the appropriate level of protection for an information asset?
Results of a risk assessment
Relative value to the business
Results of a vulnerability assessment
Cost of security controls
An information systems (IS) auditor performing a review of a major software development project finds that it is on schedule and under budget even though the software developers have worked considerable amounts of unplanned overtime. The IS auditor should:
conclude that the project is progressing as planned because dates are being met.
question the project manager further to identify whether overtime costs are being tracked accurately.
conclude that the programmers are intentionally working slowly to earn extra overtime pay.
investigate further to determine whether the project plan may not be accurate.
Value delivery from IT to the business is MOST effectively achieved by:
aligning the IT strategy with the enterprise strategy
embedding accountability in the enterprise
providing a positive return on investment
establishing an enterprisewide risk management process
