Summer Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

Isaca Certification CISA Full Course Free

Page: 29 / 106
Total 1407 questions

Certified Information Systems Auditor Questions and Answers

Question 113

Which of the following would be of GREATEST concern to an IS auditor reviewing an IT strategy document?

Options:

A.

The previous year’s IT strategic goals were not achieved.

B.

Target architecture is defined at a technical level.

C.

Financial estimates of new initiatives are disclosed within the document.

D.

Strategic IT goals are derived solely from the latest market trends.

Question 114

What is the MAIN purpose of an organization's internal IS audit function?

Options:

A.

Identify and initiate necessary changes in the control environment to help ensure sustainable improvement.

B.

Independently attest the organization’s compliance with applicable legal and regulatory requirements.

C.

Review the organization's policies and procedures against industry best practices and standards.

D.

Provide assurance to management about the effectiveness of the organization's risk management and internal controls.

Question 115

An IS auditor has been asked to review an event log aggregation system to ensure risk management practices have been applied. Which of the following should be of MOST concern to the auditor?

Options:

A.

Log feeds are uploaded via batch process.

B.

Completeness testing has not been performed on the log data.

C.

The log data is not normalized.

D.

Data encryption standards have not been considered.

Question 116

An IS auditor determines elevated administrator accounts for servers that are not properly checked out and then back in after each use. Which of the following is the MOST appropriate sampling technique to determine the scope of the problem?

Options:

A.

Haphazard sampling

B.

Random sampling

C.

Statistical sampling

D.

Stratified sampling

Page: 29 / 106
Total 1407 questions