wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

ISA 3.0 Module 2

Total questions: 56

Worksheet time: 28mins

Name
Class
Date
1.

An IT steering committee should review information system primarily to assess:

a)

Whether IT processes support business requirements

b)

If proposed system functionality is adequate.

c)

The stability of existing software.

d)

The complexity of install technology.

2.

The most likely effect of lack of senior management commitment to IT strategic planning is:

a)

A lack of investment in technology.

b)

A lack of methodology for system development.

c)

The technology not aligning with the organisations objective.

d)

And absence of control over technology contracts.

3.

which of the following is a function of an IS steering committee?

a)

Monitoring vendor-controlled change control and testing

b)

Ensuring a separation of duties within the information processing environment

c)

Approving and monitoring major projects, the status of IS plans and budgets

d)

Between the highest departments and the end users

4.

An IS Steering committee should:

a)

Include a mix of members from different departments and staff levels.

b)

Ensure that IS security policies and procedures have been executed properly.

c)

Have formal terms of reference and maintain minutes of its meetings.

d)

Be briefed about new trends and products at each meeting by the vendor.

5.

involvement of senior management is most important in the development of:

a)

Strategic plans

b)

IS policies

c)

IS procedures

d)

Standards and guidelines

6.

effective IT governance will ensure that the IT plan is consistent with the organisations:

a)

Business plan

b)

Audit plan

c)

Security plan

d)

Investment plan

7.

establishing the level of acceptable risk is the responsibility of:

a)

Quality assurance management

b)

Senior business management

c)

The chief information officer

d)

The chief security officer

8.

IT Governance is primary, the responsibility of the:

a)

Chief executive officer

b)

Board of directors

c)

IT steering committee

d)

Audit committee

9.

From a control perspective, the key element in job description is that they:

a)

Provide instructions on how to do the job and define authority.

b)

Our current, documented and readily available to the employee.

c)

Communicate management specific job performance expectations.

d)

Established responsibility and accountability for the employees action.

10.

which of the following would best provide assurance of the integrity of new staff?

a)

Background screening

b)

References

c)

Bonding

d)

Qualifications listed on the resume

11.

It is becoming increasingly important for businesses to have a business contingency plan for their information systems. The criticality of the contingency plan will depend mainly upon – – – – – –.

a)

The extent of investment in the organisation on IT

b)

Likely level of impact due to failure or non-availability of IT.

c)

The severity of the incident.

d)

The extent of risk aversion of the organisation.

12.

In terms of ascending order of severity/ intensity, how would the terms incident, crisis, emergency and disaster be ordered?

a)

Incident, crisis, emergency, disaster

b)

Incident, emergency, crisis, disaster

c)

Emergency, incident, crisis, disaster

d)

Emergency, crisis, incident, disaster

13.

An organisation with intensive internet based business has its computer servers located in an area known for power outages at times for several hours a day. How is the organisation exposure to this situation expressed in business continuity management terms?

a)

Risk

b)

Vulnerability

c)

contingency

d)

Emergency

14.

what is minimum business continuity objective?

a)

Organisation objective to continue doing business despite disruptions

b)

Organisation objective to continue minimum level of business even during financial crisis.

c)

Organisation approach to reduce business operations to a minimum level during crisis

d)

Minimum level of services/ products acceptable during a disruption.

15.

what is maximum acceptable outage?

a)

Maximum loss and organisation can afford to observe on account of a disruption

b)

Maximum loss of output and organisation can afford an account of a description

c)

Maximum number of person and organisation can afford to shift out during an emergency

d)

Maximum period of time and organisation can tolerate disruption of a critical business function.

16.

what is contingency plan?

a)

An overall process of repairing for unexpected events

b)

A list of contingency that can strike an organisations operations.

c)

Plan of deployment of a contingent of officials involved with security

d)

Maximum number of person and organisation can afford to shift out during an emergency

17.

preventive measures and corrective measures are two of the three basic strategies that encompass a disaster recovery plan. What is the third basic strategy?

a)

Restoration phase

b)

Planning phase

c)

Stabilisation phase

d)

Multiplication phase

18.

crisis phase, emergency response phase and recovery phase at three of the four phases that are typical of any disaster scenario. What is the fourth phase?

a)

Restoration phase

b)

Planning phase

c)

Multiplication phase

d)

Stabilisation Phase

19.

What are the pre- requisites in developing a business continuity plan, BCP?

a)

Planning for all phases and making it part of business process.

b)

Testing of the BCP.

c)

Waiting for one incident to learn from, before drawing up BCP.

d)

Having the organisation strategic long-term plan ready.

20.

What are the key phases prior to the development of a business continuity plan, BCP?

a)

Maintenance of the BCP.

b)

Business impact analysis and risk assessment.

c)

Testing of the BCP

d)

Training and awareness of employees

21.

Which of the following is the best approach for monitoring the performance of IT resources?

a)

Compare indicators against expected thresholds

b)

Monitor lead indicators with industry best practices.

c)

Define threshold lag indicators based on long-term plan.

d)

Lead indicator on corresponding indicator.

22.

Which of the following is configured as an example of lead indicator?

a)

Number of gaps with respect to industry standard.

b)

Comparative market position of organisation

c)

Percentage of growth achieved over three years

d)

Improvement in customer satisfaction survey

23.

IT resource optimisation plan should primarily focus on

a)

Reducing cost of resources

b)

Ensuring availability

c)

Conducting training program

d)

Information security issues

24.

Which of the following is the primary purpose of optimising the use of IT resources within an enterprise?

a)

To increase likelihood of benefit realisation

b)

To ensure readiness for future change

c)

To reduce cost of IT investments

d)

To address dependency on IT capabilities

25.

An advantage of the use of hot sites as a backup alternative is:

a)

The cost related with hot sites are low.

b)

That hot sites can be used for a long amount of time

c)

That hot sites do not require that equipment and system software be compatible with the primary installation being backed up.

d)

That hot site can be made ready for operation within a short span of time.

26.

An IS auditor reviewing an organisation’s information system disaster recovery plan should verify that it is

a)

Tested every 1 month

b)

Regularly reviewed and updated.

c)

Approved by the chief executive officer

d)

Approved by the top management

27.

Which of the following methods of results analysis, during the testing of the business continuity plan (BCP), provides the best assurance that the plan is workable?

a)

Quantitatively measuring the results of the test

b)

Measurement of accuracy.

c)

Elapsed time for completion of prescribe tasks.

d)

Evaluation of the observed test results

28.

The primary objective of corporate governance is:

a)

Reduce IT cost in line with enterprise objectives and performance.

b)

Optimise implementation of IT controls in line with business needs

c)

Implement security policies and procedures using best practices

d)

Increase shareholder value by enhancing economic performance

29.

How many objectives are there in COBIT - 2019?

a)

5

b)

40

c)

35

d)

114

30.

ISO 27001 consists of how many controls?

a)

10

b)

114

c)

35

d)

40

31.

_____ is an international standard for corporate government for information technology?

a)

ISO 27000

b)

ISO 27001

c)

ISO 38500

d)

ISO 31000

32.

The level to which an enterprise can accept financial loss from a new initiative is:

a)

Risk tolerance

b)

Risk management

c)

Risk appetite

d)

Risk acceptance

33.

which of the following is the most important characteristic of policies?

a)

Must be limited in number

b)

Requires framework to implement

c)

Reviewed periodically

d)

Non-intrusive and logical

34.

Prioritisation of IT initiatives within organisation is primarily based on:

a)

Results of risk assessments

b)

Expected benefit realisation

c)

Recommendations of CIO

d)

Rate of obsolescence of IT

35.

Which of the following is best control for building requisite skills and competencies within an organisation?

a)

Hiring only highly qualified people

b)

Outsourcing the critical operations

c)

Conducting skill enhancement training

d)

Defining skill requirements in job description

36.

What is the most important in developing a performance management system?

a)

Deciding on incentive schemes

b)

Identifying enterprise goals and their linkage to operating environment

c)

Developing clear organisation structure

d)

Benchmarking with industry

37.

A good performance measurement system, assesses performance against goals through key goal indicators. Simultaneously, it monitors performance of process through – – – –.

a)

Work flow indicators.

b)

Moving average indicators.

c)

Key process indicators.

d)

Industry benchmarks.

38.

The approach of using lead indicators for performance measurement is called – – –

a)

Reactive approach

b)

Retroactive approach

c)

Proactive approach

d)

Retrospective approach

39.

The approach of using lag indicators for performance measurement is called – – –

a)

Proactive approach

b)

Reactive approach

c)

Retroactive approach

d)

Retrospective approach

40.

where is the capability maturity framework of performance management system generally used?

a)

Hardware development company

b)

Research and development institution

c)

Software development company

d)

Educational institutions

41.

Mr. Johnson has taken charge as head of an educational institution, which has not had a good track record. He feels that he has his task cut out for him. He needs to focus more on the lead parameters rather than the lag indicators so that he can create sustainable results. Which of the following would be an example of lead indicators?

a)

Number of passes by students in the matriculation examination.

b)

Number of all India rank holders from school in the matriculation examination

c)

Number of failures in the matriculation examination

d)

Number hours of refresher course attended by the teachers

42.

In governance, value creation happens through benefit, realisation, risk optimisation and resource optimisation decisions taking into account – –

a)

All stakeholders needs

b)

All shareholders needs

c)

Organisational goals

d)

Organisational vision, mission

43.

The balance scorecard is an invaluable management tool that helps translate strategy into action and also for – – –

a)

Balancing shareholder needs with employee needs

b)

Bringing non-financial indicators into better focus.

c)

Balancing needs of multiple functions within an organisation

d)

Balancing lead and log indicators

44.

The balance scorecard is designed to ensure that performance metrics and strategic themes are balanced with financial and non-financial, operational and financial, lead and lag indicators. Financial, Customer and internal business process, prospective are three of the four prospective of BSE. The fourth prospective is – –

a)

Learning and growth

b)

Shareholders versus employees

c)

Short-term versus long-term

d)

Lead and lag indicators

45.

The balance scorecard — — — — —

a)

is meant for the use of only the senior level executives

b)

Cannot be linked to the IT goals and objectives

c)

Cannot be the basis for performance incentives

d)

Can be cascaded down to all the levels of the organisation

46.

Strategic position, strategic options and strategy implementation are three of the four basic elements of the CIMA strategic scorecard. What is the fourth element?

a)

Strategic risks

b)

Strategic conformance

c)

Strategic performance

d)

Strategic IT

47.

During 2009, the Satyam computers candle broke out. The companies chairman admitted to falsification of accounts to the tune of US dollar 1.47 billion. The auditors for this company were mainly exposed to what type of risk?

a)

Audit risk

b)

Financial risk

c)

Procedural risk

d)

IT risk

48.

COBIT define six control objectives for application controls. Under which of the following objectives does validating input data classify?

a)

Data collection and entry

b)

Complete and authenticity checks

c)

Processing integrity and validity

d)

Transaction authentication and integrity

49.

Which of the following would an IS auditor consider the most relevant to short-term planning for the IS department?

a)

Allocating resources

b)

Keeping current with Technology advances

c)

Conducting control self assessment

d)

Evaluating hardware needs

50.

Which of the following goals would you expect to find in an organisation strategic plan?

a)

Test a new accounting package

b)

Perform an evaluation of information technology needs

c)

Implement a new project planning system within the next 12 months

d)

Become the supplier of choice for the product offered

51.

which of the following would an IS auditor considered to be the most important when evaluating an organisation IS strategy? That is.:

a)

Has been approved by the line management

b)

Does not vary from the IS departments, preliminary budget

c)

Complies with procurement procedures

d)

Supports the business objectives of the organisation

52.

An IS auditor reviewing and organisation’s IT strategic plan should first REVIEW:

a)

The existing IT environment

b)

The business plan

c)

The present IT budget

d)

Current technology trends

53.

When reviewing IS strategies, the IS auditor can best assess whether IS strategy supports the organisations business objectives by determining if IS

a)

Has all the personal and equipment that needs

b)

Plans are consistent with management strategy

c)

Uses its equipment and personal effectively and efficiently

d)

Has sufficient excess capacity to respond to changing directions

54.

The advantage of a bottom of approach to the development of organisational policies is that the policies:

a)

Are developed for the organisation as a whole

b)

Are more likely to be derived as a result of risk assessment

c)

Will not conflict with overall corporate policy

d)

Ensure consistency across the organisation

55.

which of the following is the greatest risk of an inadequate policy definition for ownership of data and systems?

a)

User management coordination does not exist

b)

Specific user accountability cannot be established

c)

Unauthorised users may have access to originate, modify or delete data

d)

Audit recommendations may not be implemented

56.

The primary objective of an audit of IT security policies is to ensure that:

a)

They are distributed and available to all staff

b)

Security and control policies, support business and IT objectives

c)

There is a published organisational chart with functional descriptions

d)

Duties are appropriately segregated