
Latest CISA Exam Real Tests Free Updated Today
CISA Real Exam Question Answers Updated [May 03, 2026]
NEW QUESTION # 359
A financial services organization is developing and documenting business continuity measures. In which of
the following cases would an IS auditor MOST likely raise an issue?
- A. The business continuity capabilities are planned around a carefully selected set of scenarios which
describe events that might happen with a reasonable probability. - B. The recovery time objectives (RTOs) do not take IT disaster recovery constraints into account, such as
personnel or system dependencies during the recovery phase. - C. The organization plans to rent a shared alternate site with emergency workplaces which has only
enough room for half of the normal staff. - D. The organization uses good practice guidelines instead of industry standards and relies on external
advisors to ensure the adequacy of the methodology.
Answer: A
Explanation:
Section: Protection of Information Assets
Explanation:
It is a common mistake to use scenario planning for business continuity. The problem is that it is
impossible to plan and document actions for every possible scenario. Planning for just selected scenarios
denies the fact that even improbable events can cause an organization to break down. Best practice
planning addresses the four possible areas of impact in a disaster: premises, people, systems, and
suppliers and other dependencies. All scenarios can be reduced to these four categories and can be
handled simultaneously. There are very few special scenarios which justify an additional separate analysis,
it is a good idea to use best practices and external advice for such an important topic, especially since
knowledge of the right level of preparedness and the judgment about adequacy of the measures taken is
not available in every organization. The recovery time objectives (RTOs) are based on the essential
business processes required to ensure the organization's survival, therefore it would be inappropriate for
them to be based on IT capabilities. Best practice guidelines recommend having 20%-40% of normal
capacity available at an emergency site; therefore, a value of 50% would not be a problem if there are no
additional factors.
NEW QUESTION # 360
In which of the following situations is it MOST appropriate to implement data mirroring as the recovery strategy?
- A. Disaster tolerance is high.
- B. Recovery point objective is high.
- C. Recovery point objective is low.
- D. Recovery time objective is high.
Answer: C
Explanation:
A recovery point objective (RPO) indicates the latest point in time at which it is acceptable to recover the datA . If the RPO is low, data mirroring should be implemented as the data recovery strategy. The recovery time objective (RTO) is an indicator of the disaster tolerance. The lower the RTO, the lower the disaster tolerance. Therefore, choice C is the correct answer.
NEW QUESTION # 361
.What type of risk is associated with authorized program exits (trap doors)? Choose the BEST answer.
- A. Inherent risk
- B. Detective risk
- C. Audit risk
- D. Business risk
Answer: A
Explanation:
Inherent risk is associated with authorized program exits (trap doors).
NEW QUESTION # 362
Backup procedures for an organization's critical data are considered to be which type of control?
- A. Detective
- B. Corrective
- C. Compensating
- D. Directive
Answer: B
NEW QUESTION # 363
To determine if unauthorized changes have been made to production code the BEST audit procedure is to:
- A. examine the change control system records and trace them forward to object code files.
- B. review change approved designations established within the change control system.
- C. examine object code to find instances of changes and trace them back to change control records.
- D. review access control permissions operating within the production program libraries.
Answer: C
Explanation:
The procedure of examining object code files to establish instances of code changes and tracing these back to change control system records is a substantive test that directly addresses the risk of unauthorized code changes. The other choices are valid procedures to apply in a change control audit but they do not directly address the risk of unauthorized code changes.
NEW QUESTION # 364
Capacity management enables organizations to:
- A. forecast technology trends.
- B. establish the capacity of network communication links.
- C. identify the extent to which components need to be upgraded.
- D. determine business transaction volumes.
Answer: D
NEW QUESTION # 365
Which of the following information security requirements BE ST enables the tracking of organizational data in a bring your own device (BYOD) environment?
- A. Employees must sign acknowledgment of the organization's mobile device acceptable use policy
- B. Employees must immediately report lost or stolen mobile devices containing organizational data
- C. Employees must enroll their personal devices in the organization's mobile device management program
Answer: C
Explanation:
The best way to track organizational data in a BYOD environment is to enroll the personal devices in the organization's mobile device management (MDM) program. This will allow the organization to monitor, control, and secure the data on the devices remotely. Employees must also report lost or stolen devices and sign the acceptable use policy, but these are not sufficient to enable tracking of data. References: Info Technology & Systems Resources | COBIT, Risk, Governance ... - ISACA, section "Book IT Control Objectives for Sarbanes-Oxley, 4th Edition | Digital | English"
NEW QUESTION # 366
Which of the following is the BEST source for describing the objectives of an organization s information systems?
- A. Business process owners
- B. Information security management
- C. IT management
- D. End users
Answer: A
NEW QUESTION # 367
An IS auditor examining the configuration of an operating system to verify the controls should review the:
- A. parameter settings.
- B. authorization tables.
- C. routing tables.
- D. transaction logs.
Answer: A
Explanation:
Section: Protection of Information Assets
Explanation:
Parameters allow a standard piece of software to be customized for diverse environments and are important in determining how a system runs. The parameter settings should be appropriate to an organization's workload and control environment, improper implementation and/or monitoring of operating systems can result in undetected errors and corruption of the data being processed, as well as lead to unauthorized access and inaccurate logging of system usage. Transaction logs are used to analyze transactions in master and/or transaction files. Authorization tables are used to verify implementation of logical access controls and will not be of much help when reviewing control features of an operating system. Routing tables do not contain information about the operating system and, therefore, provide no information to aid in the evaluation of controls.
NEW QUESTION # 368
Which of the following software tools is often used for stealing money from infected PC owner through taking control of the modem?
- A. War dialer
- B. System patcher
- C. T1 dialer
- D. None of the choices.
- E. T3 dialer
- F. Porn dialer
Answer: F
Explanation:
Explanation/Reference:
Explanation:
One way of stealing money from infected PC owner is to take control of the modem and dial an expensive toll call. Dialer such as porn dialer software dials up a premium-rate telephone number and leave the line open, charging the toll to the infected user.
NEW QUESTION # 369
Which of the following is the PRIMARY concern if a business continuity plan (BCP) is not based on a business impact analysis (BIA)?
- A. The strategy of the BCP does not reflect estimated potential losses.
- B. The knowledge of key people within the organization was not considered in the BCP.
- C. The critical systems were not identified, but all systems are covered in the BCP.
- D. Management was not involved in the early stages of the BCP.
Answer: D
Explanation:
Section: Protection of Information Assets
NEW QUESTION # 370
What would be an IS auditor's BEST course of action when an auditee is unable to close all audit recommendations by the time of the follow-up audit?
- A. Evaluate the residual risk due to open issues.
- B. Ensure the open issues are retained in the audit results.
- C. Recommend compensating controls for open issues.
- D. Terminate the follow-up because open issues are not resolved
Answer: A
Explanation:
Explanation
The best course of action for an IS auditor when an auditee is unable to close all audit recommendations by the time of the follow-up audit is to evaluate the residual risk due to open issues. Residual risk is the risk that remains after the implementation of controls or mitigating actions. Evaluating the residual risk due to open issues can help the IS auditor assess the impact and likelihood of the potential threats and vulnerabilities that have not been addressed by the auditee, as well as the adequacy and effectiveness of the existing controls or mitigating actions. Evaluating the residual risk due to open issues can also help the IS auditor prioritize and communicate the open issues to the auditee and other stakeholders, such as senior management or audit committee, and recommend appropriate actions or escalation procedures.
Ensuring the open issues are retained in the audit results is a course of action for an IS auditor when an auditee is unable to close all audit recommendations by the time of the follow-up audit, but it is not the best one.
Ensuring the open issues are retained in the audit results can help the IS auditor document and report the status and progress of the audit recommendations, as well as provide a basis for future follow-up audits. However, ensuring the open issues are retained in the audit results does not provide an analysis or evaluation of the residual risk due to open issues, which is more important for informing decision-making and action-taking.
Terminating the follow-up because open issues are not resolved is not a course of action for an IS auditor when an auditee is unable to close all audit recommendations by the time of the follow-up audit, but rather a consequence or outcome of it. Terminating the follow-up because open issues are not resolved may indicate that the auditee has failed to comply with the agreed-upon actions or deadlines, or that the IS auditor has encountered significant obstacles or resistance from the auditee. Terminating the follow-up because open issues are not resolved may also trigger further actions or sanctions from the IS auditor or other authorities, such as issuing a qualified or adverse opinion, withholding certification, or imposing penalties.
Recommending compensating controls for open issues is not a course of action for an IS auditor when an auditee is unable to close all audit recommendations by the time of the follow-up audit, but rather a possible outcome or result of it. Compensating controls are alternative or additional controls that are implemented to reduce or eliminate the risk associated with a weakness or deficiency in another control. Recommending compensating controls for open issues may be appropriate when the auditee is unable to implement the original audit recommendations due to technical, operational, financial, or other constraints, and when the compensating controls can provide a similar or equivalent level of assurance. However, recommending compensating controls for open issues requires a prior evaluation of the residual risk due to open issues, which is more important for determining whether compensating controls are necessary and feasible.
References:
Follow-up Audits - Canadian Audit and Accountability Foundation 1
Conducting The Audit Follow-Up: When To Verify - The Auditor 2
Internal Audit Follow Ups: Are They Really Worth The Effort
NEW QUESTION # 371
An IS auditor reviewing an accounts payable system discovers that audit logs are not being reviewed. When this issue is raised with management the response is that additional controls are not necessary because effective system access controls are inplace. The BEST response the auditor can make is to:
- A. review the background checks of the accounts payable staff.
- B. accept management's statement that effective access controls are in place.
- C. review the integrity of system access controls.
- D. stress the importance of having a system control framework in place.
Answer: D
Explanation:
Experience has demonstrated that reliance purely on preventative controls is dangerous. Preventative controls may not prove to be as strong as anticipated or their effectiveness can deteriorate over time. Evaluating the cost of controls versus the quantum of risk is a valid management concern. However, in a high-risk system a comprehensive control framework is needed, intelligent design should permit additional detective and corrective controls to be established that don't have high ongoing costs, e.g., automated interrogation of logs to highlight suspicious individual transactions or data patterns. Effective access controls are, in themselves, a positive but, for reasons outlined above, may not sufficiently compensate for other control weaknesses. In this situation the IS auditor needs to be proactive. The IS auditor has a fundamental obligation to point out control weaknesses that give rise to unacceptable risks to the organization and work with management to have these corrected. Reviewing background checks on accounts payable staff does not provide evidence that fraud will not occur.
NEW QUESTION # 372
Which of the following should be done FIRST to minimize the risk of unstructured data?
- A. Identify repositories of unstructured data.
- B. Implement strong encryption for unstructured data.
- C. Implement user access controls to unstructured data.
- D. Purchase tools to analyze unstructured data.
Answer: A
Explanation:
Based on the information provided, the first step to minimize the risk of unstructured data should be to A: Identify repositories of unstructured data. Unstructured data can present a significant security risk if not managed properly, so it is important to identify where it is stored and who has access to it. Once the repositories of unstructured data have been identified, additional steps can be taken to protect it, such as implementing strong encryption and user access controls, and purchasing tools to analyze it.
NEW QUESTION # 373
Which of the following should an IS auditor review to understand project progress in terms of time, budget and deliverables for early detection of possible overruns and for projecting estimates at completion (EACs)?
- A. Cost budget
- B. Function point analysis
- C. Program Evaluation and Review Technique
- D. Earned value analysis
Answer: D
Explanation:
Earned value analysis (EVA) is an industry standard method for measuring a project's progress at any given point in time, forecasting its completion date and final cost, and analyzing variances in the schedule and budget as the project proceeds. It compares the planned amount of work with what has actually been completed, to determine if the cost, schedule and work accomplished are progressing in accordance with the plan. EVA works most effectively if a well-formed work breakdown structure exists. Function point analysis (FPA) is an indirect measure of software size and complexity and, therefore, does not address the elements of time and budget. Cost budgets do not address time. PERT aids in time and deliverables management, but lacks projections for estimates at completion (EACs) and overall financial management.
NEW QUESTION # 374
Which of the following represents the GREATEST risk created by a reciprocal agreement for disaster
recovery made between two companies?
- A. The security infrastructures in each company may be different.
- B. The recovery plan cannot be tested.
- C. Developments may result in hardware and software incompatibility.
- D. Resources may not be available when needed.
Answer: C
Explanation:
Section: Protection of Information Assets
Explanation:
If one organization updates its hardware and software configuration, it may mean that it is no longer
compatible with the systems of the other party in the agreement. This may mean that each company is
unable to use the facilities at the other company to recover their processing following a disaster. Resources
being unavailable when needed are an intrinsic risk in any reciprocal agreement, but this is a contractual
matter and is not the greatest risk. The plan can be tested by paper-based walkthroughs, and possibly by
agreement between the companies. The difference in security infrastructures, while a risk, is not
insurmountable.
NEW QUESTION # 375
......
Latest CISA Study Guides 2026 - With Test Engine PDF: https://www.testkingit.com/ISACA/latest-CISA-exam-dumps.html
Easily To Pass New ISACA CISA Dumps with 650 Questions: https://drive.google.com/open?id=13HW-gLKTVbvF2jlUApPIPF6sA9Wm4YgK