Courseiva

Certified Information Systems Auditor CISA (CISA) — Questions 1–75

934 questions total · 13pages · All types, answers revealed

Page 1 of 13

Page 2
1
MCQmedium

During a build vs. buy analysis, the IS auditor observes that the organization decided to build a custom application because no vendor solution met all requirements. Which of the following risks should the auditor emphasize?

A.Lack of customization
B.Dependence on external support
C.Vendor lock-in
D.Increased time-to-market and development costs
AnswerD

Building custom software demands staffing, tooling and iterative testing that vendor licensing avoids, so delivery slips and budgets overrun — directly satisfying the stem's build-versus-buy constraint. The auditor should emphasise that no vendor solution met all requirements, meaning bespoke development absorbs the full cost and schedule risk internally.

Why this answer

When an organization chooses to build a custom application instead of buying a vendor solution, the primary risks shift from external dependencies to internal development challenges. Building custom software typically requires significant upfront investment in time, skilled personnel, and financial resources, and it often takes longer to deliver than implementing an existing product. Therefore, the auditor should emphasize increased time-to-market and development costs as the key risk in this scenario.

Exam trap

CISA often tests the ability to distinguish between risks associated with building versus buying software; candidates may incorrectly associate vendor-related risks like lock-in or external support dependence with custom development, when in fact the primary risks of building are internal, such as increased time-to-market and development costs.

How to eliminate wrong answers

Option A is wrong because lack of customization is actually a risk of buying a vendor solution, not building one; custom-built applications are inherently customizable. Option B is wrong because dependence on external support is a risk associated with purchasing vendor software, where the organization relies on the vendor for updates and fixes, whereas building in-house reduces external support dependence. Option C is wrong because vendor lock-in occurs when an organization is tied to a specific vendor's proprietary technology, which is a risk of buying, not building; building custom avoids vendor lock-in but introduces other risks.

2
Multi-Selecthard

An organization is implementing a privacy program to comply with GDPR. Which THREE of the following are essential elements for managing cross-border data transfers?

Select 3 answers
A.Standard Contractual Clauses (SCCs)
B.Data Protection Impact Assessment (DPIA)
C.Adequacy decision by the European Commission
D.Binding Corporate Rules (BCRs)
E.Data encryption at rest
AnswersA, C, D

SCCs are the European Commission's approved contractual template that imposes GDPR-equivalent safeguards on a data importer in a third country lacking an adequacy decision. They provide the lawful transfer mechanism the privacy program requires for such restricted jurisdictions.

Why this answer

Standard Contractual Clauses (SCCs) (A) are a core GDPR transfer mechanism under Article 46, providing pre-approved contractual terms that legally safeguard personal data when it moves to a third country lacking an adequacy finding. An adequacy decision by the European Commission (C) is essential because under Article 45 it declares a third country's data protection regime essentially equivalent to the EU's, allowing transfers without additional safeguards. Binding Corporate Rules (BCRs) (D) are another Article 47 mechanism, essential for multinational groups to legitimize intra-group cross-border transfers through internally binding data protection policies approved by supervisory authorities.

The unmarked options do not belong: a DPIA (B) is a risk assessment tool for high-risk processing, not a transfer mechanism, and encryption at rest (E) is a security control that may supplement but does not by itself legalize a cross-border transfer.

Exam trap

The trap is selecting security measures like encryption or risk assessments as legal transfer mechanisms. Candidates might think encryption alone suffices, but GDPR requires a legal basis for transfer. The exam tests knowledge of the specific legal instruments (SCCs, adequacy, BCRs) that are explicitly recognized.

3
MCQhard

An online retail company runs its e-commerce platform on a virtualized infrastructure with 50 virtual servers. The platform experiences intermittent slowdowns during peak hours, and recent monitoring reports show that disk I/O latency on the storage area network (SAN) frequently exceeds 50 ms during these periods. The SAN has two fabric switches and a single storage array with 12 TB of usable capacity, currently at 80% utilization. The company’s disaster recovery plan requires recovery point objective (RPO) of 1 hour and recovery time objective (RTO) of 4 hours for the e-commerce platform. During a recent test failover to the disaster recovery site, the IT team discovered that the replication link between primary and DR sites is saturated, causing replication lag of up to 3 hours. The team also noted that the DR site storage has only 6 TB of usable capacity, now at 60% utilization. The IT manager is concerned about meeting the RPO and RTO. Which course of action should the IT team take first?

A.Upgrade the SAN fabric switches to support higher throughput and reduce disk I/O latency
B.Add additional storage capacity to the DR site to reduce storage utilization
C.Implement more frequent incremental backups and reduce retention period to free up storage
D.Upgrade the replication link between primary and DR sites to a higher bandwidth connection
AnswerD

Upgrading the replication link directly addresses the saturated inter-site connection causing three-hour replication lag, which breaches the one-hour RPO. Higher bandwidth restores replication throughput so changes reach the DR site within the RPO window, and it also supports completing failover within the four-hour RTO. Storage I/O latency is a separate performance issue.

Why this answer

The immediate issue preventing the organization from meeting its RPO of 1 hour is the saturated replication link, which causes replication lag of up to 3 hours. Upgrading the link to a higher bandwidth connection directly addresses the bottleneck, reducing replication time and enabling the RPO to be met. Other options, while potentially beneficial, do not resolve the primary cause of the RPO failure.

Exam trap

The trap here is that candidates focus on the disk I/O latency or storage utilization issues, which are performance concerns, rather than recognizing that the saturated replication link is the direct cause of the RPO failure and must be addressed first.

How to eliminate wrong answers

Option A is wrong because upgrading the SAN fabric switches addresses disk I/O latency, which is a performance issue, not the replication lag that causes the RPO violation. Option B is wrong because adding storage capacity to the DR site does not reduce replication lag; it may even increase the amount of data that needs to be replicated. Option C is wrong because implementing more frequent incremental backups does not solve the replication link saturation; it could increase the load on the link and worsen the lag, and backups are not the same as synchronous or asynchronous replication used for RPO.

4
MCQmedium

A company is using an agile development methodology for a critical business application. The IS auditor is concerned about the lack of formal documentation. What is the BEST approach to mitigate this risk?

A.Require the project to switch to a waterfall methodology.
B.Accept the lack of documentation because agile emphasizes working software.
C.Perform a detailed code review to compensate for missing documentation.
D.Ask the team to maintain a lightweight document of important decisions and changes.
AnswerD

Lightweight documentation of key decisions and changes preserves an audit trail of design rationale and approvals while respecting agile's preference for working software over comprehensive documentation. This satisfies the auditor's need for traceability without imposing heavyweight artefacts that would disrupt iterative delivery.

Why this answer

The best approach because it balances agile principles with the need for auditability. In agile, lightweight documentation (e.g., architecture decision records, user story acceptance criteria) captures key decisions and changes without the overhead of full waterfall documentation. This mitigates the risk of knowledge loss while preserving the team's velocity.

Exam trap

The trap here is that candidates may confuse agile's 'working software over comprehensive documentation' with 'no documentation at all,' leading them to choose Option B, while the correct answer recognizes that lightweight documentation is both agile-compliant and risk-mitigating.

How to eliminate wrong answers

Option A is wrong because forcing a switch to waterfall would disrupt the existing agile workflow, likely causing delays and team resistance, and is not a proportionate response to a documentation gap. Option B is wrong because accepting the lack of documentation ignores the auditor's responsibility to ensure that critical business applications have sufficient records for maintenance, compliance, and knowledge transfer; agile emphasizes working software but does not prohibit necessary documentation. Option C is wrong because code review, while valuable for quality, does not capture design decisions, rationale, or change history that documentation provides; it is a complementary practice, not a substitute for documentation.

5
MCQmedium

An IS auditor is reviewing the audit follow-up process. The auditor notes that management has implemented corrective actions for 80% of previous audit findings. What should the auditor conclude?

A.The audit scope was too narrow
B.Further investigation of outstanding findings is needed
C.The audit process is effective
D.Management is compliant with all recommendations
AnswerB

Eighty per cent completion leaves 20% of findings unresolved, so the auditor cannot conclude remediation is effective. Outstanding findings require follow-up to determine whether management has accepted the risk, delayed action, or lacks the capability to implement corrective measures.

Why this answer

An 80% closure rate indicates that 20% of findings remain unresolved. ISACA standards require auditors to verify that all high-risk findings are remediated before concluding on control effectiveness. Without evidence that the outstanding 20% are low-risk or have an accepted risk, the auditor must investigate further to ensure residual risk is within the organization's appetite.

Exam trap

The trap here is that candidates assume a high percentage (80%) implies overall effectiveness, but CISA requires verification that all findings, especially high-risk ones, are resolved or formally accepted, not just a majority.

How to eliminate wrong answers

Option A is wrong because a narrow scope would typically result in missing findings, not in a specific closure percentage; the 80% figure does not indicate scope deficiency. Option C is wrong because an effective audit process requires not only corrective actions but also timely closure of all findings; 80% closure alone does not prove the overall process is effective, as the remaining 20% may represent critical gaps. Option D is wrong because management implementing 80% of recommendations explicitly means they are not compliant with all recommendations; the remaining 20% are outstanding.

6
MCQeasy

A company is developing a mobile banking application. Which test phase is MOST critical to ensure that the application functions correctly from the end user's perspective?

A.System testing.
B.User acceptance testing (UAT).
C.Unit testing.
D.Integration testing.
AnswerB

UAT is performed by actual end users in a production-like environment, validating that workflows, usability and business rules meet their needs. Unlike unit, integration or system testing, which verify technical correctness against specifications, UAT directly satisfies the stem's constraint of functioning correctly from the end user's perspective.

Why this answer

User acceptance testing (UAT) is the most critical phase for verifying that the mobile banking application meets end-user requirements and functions correctly from their perspective. Unlike other testing phases that focus on technical correctness, UAT involves real users performing actual banking transactions (e.g., fund transfers, balance inquiries) in a production-like environment to validate usability, workflow accuracy, and compliance with business rules. This ensures the application is ready for deployment and will be accepted by its intended audience.

Exam trap

The trap here is that candidates often confuse system testing with user acceptance testing, mistakenly thinking that verifying all system functions technically is equivalent to ensuring the application works correctly from the end user's perspective.

How to eliminate wrong answers

Option A is wrong because system testing validates the complete integrated system against functional and non-functional requirements but does not involve end users; it focuses on technical correctness rather than user perspective. Option C is wrong because unit testing verifies individual components or modules in isolation, typically by developers, and cannot assess end-to-end user workflows or usability. Option D is wrong because integration testing checks the interactions between integrated modules or external systems (e.g., APIs, databases) but does not evaluate the application from an end user's viewpoint or validate business processes.

7
MCQeasy

An organization uses automated job scheduling for nightly batch processing. One job fails due to a missing dependency file. What is the most effective control to prevent recurrence?

A.Use a different scheduling tool
B.Define dependencies within the job scheduler
C.Increase the frequency of job reruns
D.Assign manual operators to monitor jobs
AnswerB

Defining dependencies within the job scheduler ensures the failing job only starts once its prerequisite files exist, directly addressing the missing dependency file constraint. The scheduler evaluates these conditions before execution, blocking the run rather than allowing failure. This prevents recurrence through automated precondition checking, unlike manual verification or post-failure alerting.

Why this answer

Defining dependencies within the job scheduler is the most effective control to prevent recurrence of a job failure due to a missing dependency file. By explicitly defining dependencies, the scheduler ensures that prerequisite jobs or files are available before the dependent job runs, preventing failures caused by missing inputs.

Exam trap

CISA often tests the difference between preventive controls (defining dependencies) and detective/corrective controls (monitoring, reruns), so candidates must choose the most effective preventive measure.

How to eliminate wrong answers

Option A is wrong because using a different scheduling tool does not address the root cause; the issue is lack of dependency management, not the tool itself. Option C is wrong because increasing the frequency of job reruns is a reactive measure that may waste resources and does not prevent the failure; it only retries after failure. Option D is wrong because assigning manual operators to monitor jobs is not as effective or reliable as automated dependency management; it is prone to human error and does not scale.

8
MCQeasy

An IS auditor is conducting a preliminary review of a newly acquired subsidiary and needs to understand the organizational structure, key business processes, and the technology environment before drafting the engagement plan. Which of the following techniques is MOST appropriate for gathering this broad understanding?

A.Testing the operating effectiveness of general IT controls
B.Conducting interviews with key personnel
C.Reviewing prior audit working papers
D.Performing a walk-through of selected transactions
AnswerB

Interviews with management and process owners efficiently capture organizational structure, business objectives, key processes, and the technology environment. ISACA guidance identifies interviews and discussions with auditees as a primary information-gathering technique during the preliminary phase, allowing the auditor to scope the engagement before committing to detailed testing.

Why this answer

During preliminary review the auditor's objective is broad understanding, not verification. Interviewing management and process owners quickly reveals structure, processes, and technology, and lets the auditor follow up with documentation review or observation where answers are unclear. Detailed techniques such as walk-throughs, control testing, or reliance on prior papers presuppose knowledge the auditor does not yet possess for a newly acquired subsidiary.

Exam trap

The trap here is assuming that reviewing prior audit working papers is always the most efficient planning technique, when for a new subsidiary no relevant history exists and interviews are the practical way to build initial understanding.

9
MCQmedium

During a review of firewall rule sets, an IS auditor finds a rule that allows any source IP to access any destination IP on TCP port 443. Which of the following should the auditor do FIRST?

A.Test whether the rule is actually being used.
B.Escalate the finding to senior management.
C.Determine if the rule has a documented business justification.
D.Recommend immediate removal of the rule.
AnswerC

Before judging the any-any port 443 rule as a finding, the auditor must establish whether a documented business justification exists. Determining intent and approval first distinguishes an authorised exception from an undocumented, unjustified exposure, directing subsequent audit action appropriately.

Why this answer

When an IS auditor identifies a potentially risky firewall rule, the first step is to determine whether the rule has a documented business justification before taking any action. Auditors must gather evidence and understand the context — a rule allowing TCP 443 from any source may be legitimate for a public-facing web server. Only after establishing whether the rule is justified can the auditor decide on escalation or remediation.

Exam trap

The trap is jumping to remediation or escalation — CISA questions frequently test whether candidates understand that auditors must first gather evidence and assess justification before recommending action, reflecting the 'audit, don't fix' principle.

How to eliminate wrong answers

Option A is wrong because testing whether the rule is used is a technical validation step, but it does not establish whether the rule is authorized or justified — usage alone does not imply approval. Option B is wrong because escalating to senior management is premature before the auditor has gathered facts and assessed the rule's justification. Option D is wrong because recommending immediate removal without understanding the business context could disrupt legitimate services and violates the auditor's role of assessing rather than unilaterally acting.

10
MCQhard

An IS auditor is planning the use of computer-assisted audit techniques (CAATs) to test a large transaction population for duplicate payments. Which of the following is the MOST important consideration before relying on the CAAT results?

A.Ensuring the CAAT scripts are documented in the permanent audit file
B.Verifying the completeness and accuracy of the data extracted from the source system
C.Obtaining management's written approval to run queries against production data
D.Confirming that the CAAT software is licensed to the audit organization
AnswerB

CAAT results are only as reliable as the data analysed. The auditor must establish that the extract is complete and accurate, for example by reconciling record counts and control totals to the source system. Without this validation, duplicates or omissions in the extract could produce false conclusions about the transaction population.

Why this answer

Before relying on CAAT output, the auditor must be satisfied that the data analysed is complete and accurate, typically by reconciling extract record counts and control totals to the source system. Only then can duplicate-payment exceptions be attributed to the population rather than to extraction errors. Licensing, approvals, and documentation support the work but do not validate the data itself.

Exam trap

The trap here is focusing on the tool and its permissions while overlooking that the reliability of the analysis depends first on the integrity of the extracted data.

11
MCQmedium

An IS auditor is evaluating the security of the architecture. Which of the following is the MOST critical finding?

A.The web server has a public IP address
B.SQL traffic from the web server to the database server is allowed
C.No encryption for SQL traffic between web and database servers
D.The database server is not placed in the DMZ
AnswerC

Unencrypted SQL traffic between web and database servers exposes credentials and data to interception or man-in-the-middle attacks across the network. Encryption such as TLS protects this channel, making its absence the most critical architectural weakness among the findings.

Why this answer

The most critical finding because unencrypted SQL traffic between the web and database servers exposes sensitive data to interception via man-in-the-middle attacks. Even if the traffic is confined to an internal network, an attacker who compromises the web server can sniff credentials or query results in plaintext. Encrypting SQL traffic with TLS or IPSec is a fundamental security control to protect data in transit.

Exam trap

The trap here is that candidates often focus on network placement (DMZ vs. internal) or the mere existence of SQL traffic, rather than recognizing that unencrypted data in transit is a far more critical vulnerability than architectural placement issues.

How to eliminate wrong answers

Option A is wrong because a web server typically requires a public IP address to serve external clients; this is a design choice, not a security finding. Option B is wrong because SQL traffic from the web server to the database server is expected and necessary for application functionality; the issue is not the existence of the traffic but its lack of encryption. Option D is wrong because placing the database server in the DMZ would expose it directly to external threats; best practice is to place the database server on a separate internal network segment behind the DMZ, not inside it.

12
MCQhard

An IT auditor is reviewing the policy hierarchy of an organization. Which of the following correctly describes the relationship between a policy and a procedure?

A.A policy is reviewed annually, while a procedure is reviewed every five years.
B.A policy is a detailed step-by-step instruction, while a procedure is a high-level statement.
C.A policy is a mandatory requirement, while a procedure is optional.
D.A policy defines the 'what' and 'why', while a procedure defines the 'how'.
AnswerD

Policies sit at the top of the hierarchy, stating mandatory intent and rationale without prescribing steps. Procedures sit beneath, translating that intent into sequential, actionable instructions. This layered relationship satisfies the auditor's need to distinguish governance intent from operational implementation.

Why this answer

A policy is a high-level statement of management intent that defines what must be done and why, establishing mandatory requirements and direction. A procedure is the detailed, step-by-step operational instruction that defines how to accomplish the policy's requirements. This 'what/why vs. how' distinction is the foundational relationship in any IT governance documentation hierarchy.

Exam trap

CISA often tests the confusion between policy and procedure definitions, tempting candidates to pick the option that swaps their meanings or introduces review-frequency or optionality as the differentiator.

How to eliminate wrong answers

Option A is wrong because review frequency is not the defining relationship between policies and procedures; both are typically reviewed at least annually or upon significant change, and the question asks about their conceptual relationship, not cadence. Option B is wrong because it reverses the definitions — a policy is high-level, and a procedure is the detailed step-by-step instruction. Option C is wrong because both policies and procedures are mandatory within the scope of the ISMS; procedures are not optional, they are the prescribed method for complying with policy.

13
MCQhard

An IS auditor is performing a compliance audit of data privacy regulations. The auditor finds that the organization's privacy policy is not fully aligned with regulatory requirements. Which of the following is the auditor's BEST course of action?

A.Ignore the issue because the policy is only a minor deviation.
B.Report the finding as a non-compliance issue and recommend updates to the policy.
C.Draft a new privacy policy for the organization.
D.Conclude that the organization is compliant because the policy exists.
AnswerB

Because the policy fails to meet regulatory requirements, the auditor must document this as a non-compliance finding and recommend remediation. Reporting and recommending updates satisfies the compliance audit objective, giving management a basis to align the policy with the applicable privacy regulations.

Why this answer

The auditor should report the non-compliance finding and recommend corrective actions, as the primary goal of a compliance audit is to identify gaps.

14
MCQeasy

An IS auditor is conducting an audit of a small manufacturing company's IT operations. The company has 50 employees and uses a single server running Windows Server 2019 for file sharing and print services. There is no formal change management process. The IT manager, who also doubles as the system administrator, has full administrative rights and is the only person who can make changes to the server. During the audit, the auditor notices that the server's local security policy is configured to allow unlimited password attempts and no account lockout. The IT manager states that this is to avoid locking out users who forget their passwords. The auditor also finds that the guest account is enabled on the server. What should the auditor recommend as the HIGHEST priority action?

A.Train employees on password security.
B.Implement a formal change management process.
C.Disable the guest account and enforce account lockout policy.
D.Separate the roles of IT manager and system administrator.
AnswerC

Disabling the guest account and enforcing lockout directly closes the anonymous access and unlimited brute-force vectors the auditor observed. These are the highest-priority exposures because they permit unauthorised access and password guessing, outweighing the absence of formal change management.

Why this answer

The guest account being enabled on a Windows Server 2019 file/print server is an immediate, exploitable security hole — anyone on the network can authenticate anonymously and potentially access shared resources. Combined with unlimited password attempts and no account lockout, the server is also wide open to brute-force attacks against legitimate accounts. Disabling the guest account and enforcing an account lockout policy addresses both the most severe exposure and the weakest authentication control, making it the highest-priority remediation.

Exam trap

CISA often tests whether candidates prioritize immediate, exploitable technical vulnerabilities over longer-term governance or process improvements — the trap is choosing 'change management' or 'segregation of duties' because they sound like mature audit recommendations, when the question asks for the HIGHEST priority action.

How to eliminate wrong answers

Option A is wrong because user awareness training does not remediate a technical misconfiguration — the guest account and lack of lockout would remain exploitable regardless of how well users are trained. Option B is wrong because while the absence of change management is a governance weakness, it is a longer-term process improvement and does not address the immediate, active vulnerabilities on the server. Option D is wrong because separating the IT manager and sysadmin roles is a segregation-of-duties improvement that is impractical for a 50-person company and does not close the guest account or lockout gaps.

15
MCQmedium

An organization uses a hot site for disaster recovery. During a recent test, the hot site did not have the latest version of the application software. What is the MOST likely cause?

A.Inadequate change management procedures
B.Failure to synchronize data
C.Lack of backup media
D.Insufficient bandwidth
AnswerA

Inadequate change management procedures let production application updates bypass the disaster recovery hot site, so its software falls behind. Because the hot site must mirror production, any change not propagated there during testing reveals a failure to synchronise configuration items across environments — the exact gap the stem describes.

Why this answer

A hot site is a fully equipped alternate facility with hardware, connectivity, and software ready to run production, so the missing latest application version points to a process failure in propagating changes to the DR environment. Inadequate change management means updates applied to production were not replicated to the hot site, leaving it out of sync. This is the most likely cause because the hot site's infrastructure itself is functional — only the software baseline is stale.

Exam trap

CISA often tests the confusion between data synchronization failures and change management failures — candidates must recognize that a stale application version is a change-control issue, not a data replication issue.

How to eliminate wrong answers

Option B is wrong because failure to synchronize data would affect the currency of database contents, not the version of the application binaries installed at the hot site. Option C is wrong because lack of backup media would prevent restoration of data or code entirely, not merely leave an older version running. Option D is wrong because insufficient bandwidth would slow replication or failover performance, but would not by itself cause the hot site to run an outdated application version.

16
MCQmedium

An organization's IT security policy requires that all employees complete annual security awareness training. An auditor notes that completion rate is only 60%. What is the MOST effective way to monitor compliance?

A.Review training records manually each quarter
B.Implement a learning management system that tracks completions and generates reports
C.Require managers to confirm their staff's completion
D.Conduct surprise audits of employee knowledge
AnswerB

A learning management system records each employee's completion status centrally and produces auditable reports, giving continuous, verifiable evidence of the 60% shortfall. This directly satisfies the policy's need to monitor annual training compliance across the workforce.

Why this answer

A Learning Management System (LMS) automates tracking of training completion, provides real-time dashboards, and generates compliance reports, which is the most effective and scalable way to monitor adherence to the annual training policy. It reduces manual effort and provides auditable evidence. This directly addresses the low completion rate by enabling continuous monitoring and follow-up.

Exam trap

The trap here is confusing knowledge testing (surprise audits) with compliance monitoring; CISA exams often test whether candidates choose automated, evidence-based monitoring over manual or subjective methods.

How to eliminate wrong answers

Option A is wrong because manual quarterly reviews are labor-intensive, error-prone, and not timely enough to enforce annual compliance. Option C is wrong because manager confirmation is subjective and lacks verifiable evidence; it does not provide an automated audit trail. Option D is wrong because surprise audits test knowledge, not completion of the required training, and they are reactive rather than monitoring compliance.

17
MCQmedium

A hospital is implementing a new electronic health record (EHR) system to replace a legacy system. During the implementation phase, the project manager proposes using a parallel changeover strategy. Which of the following is the MOST significant risk associated with this approach?

A.The high cost of training users on both systems simultaneously.
B.The need to maintain and reconcile data in both systems, increasing the risk of data inconsistencies.
C.The inability to roll back to the legacy system if the new system fails.
D.The prolonged project timeline due to extended testing phases.
AnswerB

Parallel changeover runs old and new systems simultaneously, requiring dual data entry and reconciliation. In a hospital, this can lead to discrepancies between the legacy EHR and the new system, potentially affecting patient care. The main risk is the complexity and cost of maintaining data integrity across both systems during the overlap period.

Why this answer

Parallel changeover involves running both old and new systems concurrently, which introduces significant data reconciliation challenges. In a hospital, where accurate patient data is critical, the risk of inconsistencies between the two systems is the most significant concern. This approach is often chosen for high-risk systems to provide a fallback, but it requires robust controls to ensure data integrity.

Exam trap

The trap here is assuming that parallel changeover eliminates risk because it provides a fallback, but it actually introduces new risks related to data consistency and operational complexity.

18
MCQmedium

What is the primary purpose of a chargeback model for IT services?

A.To increase the IT budget
B.To simplify IT financial management
C.To centralize IT decision-making
D.To provide transparency and encourage efficient use of IT resources
AnswerD

A chargeback model bills business units for their actual IT consumption, creating cost visibility and accountability. This directly satisfies the stem's requirement for transparency, while usage-based billing discourages wasteful consumption, encouraging efficient use of IT resources across the organisation.

Why this answer

Chargeback models allocate IT costs to business units based on usage, promoting accountability and cost awareness.

19
MCQeasy

An IS auditor is planning an audit of an organization's IT infrastructure. Which of the following is the PRIMARY benefit of using a risk-based approach?

A.It ensures that all controls are tested equally.
B.It reduces the overall cost of the audit.
C.It focuses audit efforts on areas with the highest risk.
D.It guarantees the detection of material misstatements.
AnswerC

Risk-based auditing directs scarce audit resources toward the areas of greatest exposure, so coverage and testing concentrate where the likelihood and impact of failure are highest. This satisfies the stem's demand for the primary benefit by aligning audit effort with the organisation's most significant risks rather than treating all infrastructure equally.

Why this answer

A risk-based approach allows the auditor to focus on areas with higher risk, thereby optimizing the use of audit resources and ensuring that significant risks are addressed.

20
MCQmedium

An IS auditor is reviewing the process for granting privileged access in a large organization. Which of the following findings should be of MOST concern?

A.Privileged access is granted without approval from the system owner
B.Privileged accounts are not monitored in real-time
C.Privileged access is reviewed quarterly
D.There is no segregation of duties for privileged users
AnswerA

Without system owner approval, privileged access bypasses the authorisation control that ensures rights are granted only when a legitimate business need exists. This is the most serious finding because unapproved rights enable unauthorised changes and cannot be traced to an accountable approver.

Why this answer

Granting privileged access without approval from the system owner is the most serious finding because it removes the fundamental authorization control that ensures only legitimate, accountable requests receive elevated rights. Without owner approval, there is no business justification, no accountability trail, and no way to verify that the access is appropriate for the user's role. This directly undermines the principle of least privilege and creates an uncontrolled pathway to critical systems.

Exam trap

CISA often tests the distinction between preventive and detective controls — candidates may pick 'no real-time monitoring' because it sounds alarming, but the absence of an approval control is the more fundamental governance failure.

How to eliminate wrong answers

Option B is wrong because lack of real-time monitoring is a detective-control weakness, but it is less severe than an absent preventive control — monitoring gaps can be remediated with tooling, whereas unapproved access grants are already a governance failure. Option C is wrong because quarterly review of privileged access is actually a reasonable periodic control; while more frequent reviews may be desirable, quarterly is not inherently a finding of concern. Option D is wrong because lack of segregation of duties is a concern, but it is a design issue that can be mitigated with compensating controls; the absence of any approval process is a more fundamental breakdown of the access governance framework.

21
MCQhard

During a business impact analysis (BIA), a department manager states that their process can be disrupted for up to 8 hours, but data loss cannot exceed 15 minutes. Which two metrics are defined by these statements?

A.Mean time to repair (MTTR) and mean time between failures (MTBF)
B.Recovery time objective (RTO) and recovery point objective (RPO)
C.Service level objective (SLO) and service level agreement (SLA)
D.Maximum tolerable downtime (MTD) and working recovery time (WRT)
AnswerB

The 8-hour disruption tolerance defines the recovery time objective, the maximum acceptable downtime before the process must be restored. The 15-minute data loss limit defines the recovery point objective, the maximum tolerable data loss measured backwards from the incident.

Why this answer

The maximum downtime is the recovery time objective (RTO), and the maximum data loss is the recovery point objective (RPO).

22
MCQmedium

An information systems auditor is evaluating user accounts in an organization's Linux environment. The accounts have the following properties: - The 'root' account has its password field set to '!!' (disabled). - The 'admin' account has its password field set to '!' (locked) and UID 0. - The 'test' account is a regular user with UID 1000. Based on this information, which user account poses the HIGHEST security risk?

A.root
B.admin
C.test
D.None of the accounts are risky
AnswerB

The admin account has UID 0, granting full root-equivalent privileges, yet its password field is locked with '!'. This combination creates a privileged account that may be activated or exploited, posing a higher risk than the disabled root or the unprivileged test account.

Why this answer

The 'admin' account poses the highest security risk because, despite its password being locked (indicated by '!' in the shadow file), it has UID 0 (root privileges). A locked password prevents password-based login, but the account may still be accessible via SSH keys or other authentication methods, and its privileged status makes it a valuable target for privilege escalation attacks. In contrast, the 'root' account may be fully disabled, and the 'test' account is a standard user without elevated privileges.

Exam trap

Candidates often assume that a locked account is inherently safe, but the trap is that an account with UID 0 (root privileges) remains a high risk even if its password is locked, as alternative authentication methods or local privilege escalation could still be exploited. The question tests understanding that account risk must consider both privilege level and authentication controls together.

How to eliminate wrong answers

Option A is wrong because 'root' is often locked for direct login (e.g., PermitRootLogin no in sshd_config) or has a strong password enforced by policy, reducing its immediate risk compared to an active admin account. Option C is wrong because 'test' accounts are typically non-privileged, have limited access, and are often disabled or have expired passwords, making them lower risk. Option D is wrong because the 'admin' account clearly presents a higher risk due to its privileged nature and common weak configurations, so it is incorrect to say none are risky.

23
Multi-Selectmedium

An organization is implementing ITIL 4. Which TWO of the following are part of the four dimensions of service management? (Select TWO.)

Select 2 answers
A.Governance
B.Organizations and People
C.Financial Management
D.Service Level Management
E.Information and Technology
AnswersB, E

Organizations and People is one of the four ITIL 4 dimensions of service management, covering roles, responsibilities, culture and staffing. It satisfies the stem's requirement by naming a dimension alongside Information and Technology, Partners and Suppliers, and Value Streams and Processes, which together ensure a holistic approach to service design and delivery.

Why this answer

The ITIL 4 four dimensions of service management are Organizations and People, Information and Technology, Partners and Suppliers, and Value Streams and Processes. Option B (Organizations and People) is correct because it is one of these four dimensions, covering roles, responsibilities, culture, and competencies needed to deliver services. Option E (Information and Technology) is also correct because it addresses the information, knowledge, and technologies required for service management.

Option A (Governance) is not one of the four dimensions; governance is a component of the ITIL 4 service management framework but not a dimension. Option C (Financial Management) is a service management practice, not a dimension. Option D (Service Level Management) is likewise a practice within ITIL 4, not one of the four dimensions.

Exam trap

CISA often tests the confusion between ITIL 4 dimensions and practices or Service Value System components; candidates may incorrectly select Governance or Financial Management as dimensions.

24
Multi-Selectmedium

Which TWO of the following are primary objectives of capacity management? (Select exactly 2.)

Select 2 answers
A.To ensure adequate IT resources to meet current and future business demands
B.To monitor and report on system performance against SLAs
C.To minimize the total cost of ownership of IT resources
D.To procure hardware and software at the lowest possible cost
E.To optimize the use of existing resources to support business growth
AnswersA, E

Capacity management balances current resource provisioning against forecast demand, ensuring performance and availability as business needs grow. This satisfies the objective of aligning IT capacity with both present workloads and anticipated future requirements, preventing both over-provisioning and shortfalls.

Why this answer

Option A is correct because capacity management's core purpose is to plan and provision IT resources (CPU, memory, storage, network bandwidth) so that they are sufficient for both present workloads and forecast future business demand. Option E is correct because capacity management also seeks to right-size and tune existing resources—through techniques like workload balancing, virtualization, and utilization monitoring—so that current infrastructure can efficiently absorb business growth without unnecessary over-provisioning. Options B, C, and D are not primary objectives: monitoring and reporting performance against SLAs belongs to service level management and performance monitoring, while minimizing total cost of ownership and procuring hardware/software at the lowest cost are financial and procurement goals rather than the capacity management objectives of matching supply to demand and optimizing resource use.

Exam trap

CISA often tests the distinction between capacity management objectives (adequate and optimized resources) and related but separate objectives like cost minimization or SLA monitoring, so candidates must not select answers that describe financial or service-level goals.

25
MCQeasy

Which of the following is the PRIMARY purpose of conducting a penetration test?

A.To test incident response capabilities
B.To exploit vulnerabilities to assess real-world impact
C.To meet compliance requirements
D.To identify vulnerabilities in a system
AnswerB

Exploiting vulnerabilities demonstrates actual business impact, satisfying the stem's demand for the primary purpose. Unlike vulnerability scanning, which merely enumerates weaknesses, penetration testing actively validates exploitability and quantifies consequence, giving management evidence of real-world risk exposure rather than theoretical findings.

Why this answer

The primary purpose of a penetration test is to exploit vulnerabilities in a controlled manner to assess the real-world impact and business risk, not merely to list them. While vulnerability scanning identifies weaknesses, penetration testing goes further by simulating an attacker's actions to determine if and how a vulnerability can be leveraged to compromise systems, data, or operations. This aligns with the CISA focus on evaluating the effectiveness of security controls under realistic attack conditions.

Exam trap

The trap here is confusing a vulnerability assessment (option D) with a penetration test, as many candidates think the primary goal is simply finding flaws, but CISA emphasizes that the real purpose is to exploit them to measure impact.

How to eliminate wrong answers

Option A is wrong because testing incident response capabilities is a secondary benefit, not the primary purpose; a penetration test may trigger IR processes, but its core objective is to validate security controls through exploitation. Option C is wrong because meeting compliance requirements (e.g., PCI DSS 11.4) is a driver for conducting a test, but the primary purpose remains the technical assessment of real-world exploitability and impact. Option D is wrong because identifying vulnerabilities is the goal of a vulnerability assessment, not a penetration test; a penetration test assumes vulnerabilities exist and focuses on exploiting them to measure actual risk.

26
Multi-Selecthard

An IS auditor is designing test procedures for an audit of an organization's network perimeter. The auditor plans to use computer-assisted audit techniques (CAATs) to analyze firewall log data covering six months. Which TWO of the following are the MOST important considerations when using CAATs in this engagement? (Choose two.)

Select 2 answers
A.The brand and model of the firewall appliance generating the logs
B.Security and confidentiality controls over the extracted log data and the CAAT environment
C.Whether the audit team has prior experience auditing firewall rules
D.Completeness and integrity of the firewall log data extracted for analysis
E.The cost of the CAAT software license compared to manual testing
AnswersB, D

Extracted firewall logs can reveal network topology, internal addressing, and traffic patterns, so the data and the environment where CAATs run must be protected. If analysis occurs on an unsecured workstation or copies of logs are left on shared drives, the audit itself creates a confidentiality and security exposure. Safeguarding the data throughout analysis and retention is therefore a key consideration.

Why this answer

When CAATs are used, the auditor must first establish that the data being analyzed is complete and accurate, because flawed input guarantees flawed conclusions about firewall activity over six months. Equally important, extracted logs and the analysis environment must be secured so the audit does not introduce confidentiality or integrity risks. Appliance brand, team experience, and license cost affect logistics but not the fundamental reliability or safety of the CAAT results.

Exam trap

The trap here is focusing on tool-related logistics such as appliance brand or license cost, while overlooking that CAAT results are only valid when the extracted data is complete, unaltered, and protected throughout the analysis.

27
MCQmedium

An organization's business continuity plan (BCP) includes alternate facilities that can be operational within 24 hours. The maximum tolerable downtime (MTD) for a critical process is 12 hours. What is the most significant gap?

A.The BCP does not include customer communication procedures.
B.The alternate facility cannot be activated within the required MTD.
C.The BCP does not address data backup procedures.
D.The recovery time objective (RTO) for the process is not defined.
AnswerB

The alternate facility needs 24 hours to become operational, but the critical process tolerates only 12 hours of downtime, so recovery exceeds the MTD by 12 hours. The gap is the mismatch between facility activation time and the required recovery timeframe.

Why this answer

The alternate facility recovery time (24 hours) exceeds the MTD (12 hours), meaning the process would fail its recovery requirement.

28
MCQhard

A multinational manufacturing company with operations in 20 countries has historically allowed each regional division to manage its own IT systems independently. Recently, the company experienced a significant data breach originating from a region with weaker security controls, leading to financial losses and reputational damage. The board has mandated stronger IT governance to prevent future incidents. The CIO proposes implementing a global IT governance framework with centralized policy enforcement. However, regional directors argue that local regulations and business needs require autonomy. The governance committee must decide on a course of action that balances risk and business flexibility. Which of the following approaches is the MOST appropriate?

A.Adopt a federated governance model with global policies and local flexibility within defined tolerances.
B.Allow each region to continue independently but require quarterly reporting to the committee.
C.Implement a fully centralized IT governance model with no regional deviations.
D.Maintain the status quo but enforce minimum security standards across all regions.
AnswerA

A federated model sets mandatory global policies, such as security baselines, while permitting regional deviations within defined tolerances. This directly addresses the breach caused by weak local controls without stripping the autonomy regional directors require for local regulations.

Why this answer

A federated governance model with global policies and local flexibility within defined tolerances is the most appropriate because it balances the board's mandate for stronger, centralized governance with the regional directors' need for autonomy to meet local regulations and business requirements. It establishes global minimum standards while allowing regions to adapt within approved boundaries, directly addressing the risk of weak regional controls without eliminating necessary flexibility.

Exam trap

The trap is choosing extreme options (full centralization or full autonomy) when the scenario explicitly demands a balance between global risk control and local flexibility.

How to eliminate wrong answers

Option B is wrong because allowing each region to continue independently with only quarterly reporting does not provide the centralized enforcement needed to prevent a repeat of the breach; reporting is reactive and does not ensure consistent controls. Option C is wrong because a fully centralized model with no regional deviations ignores local regulatory and business needs, which can cause compliance violations and operational friction, making it impractical for a multinational. Option D is wrong because maintaining the status quo while enforcing minimum standards is essentially what already failed; without a governance framework to enforce and monitor those standards, the same weaknesses persist.

29
MCQmedium

An IS auditor is reviewing a post-implementation review report for a new financial system. Which finding would most indicate that the project did not meet its objectives?

A.Three minor change requests were submitted in the first month
B.Users required additional training after go-live
C.The project budget was exceeded by 5%
D.The system processed transactions 20% slower than projected
AnswerD

Throughput below the projected baseline means the system fails its defined performance objective, so the project did not deliver the agreed benefits. Budget compliance and delivery date are irrelevant to this finding; processing speed is a measurable acceptance criterion.

Why this answer

A system processing transactions 20% slower than projected directly indicates that the system failed to meet a key performance objective, which is a core project objective. Post-implementation reviews assess whether the system delivers expected performance, functionality, and benefits; a significant performance shortfall is a clear sign objectives were not met. This finding most strongly indicates a failure to meet objectives.

Exam trap

CISA often tests the difference between normal post-go-live issues (training, minor changes, small budget variance) and substantive failures to meet objectives — the trap is over-weighting minor issues as objective failures.

How to eliminate wrong answers

Option A is wrong because three minor change requests in the first month are normal and expected as users adapt to the system, not an indication of failure to meet objectives. Option B is wrong because additional training after go-live is common and does not necessarily mean objectives were unmet — it may reflect normal user onboarding. Option C is wrong because a 5% budget overrun, while not ideal, is relatively minor and does not by itself indicate that the project failed to meet its objectives, especially if benefits are realized.

30
MCQmedium

Which of the following is the BEST example of an analytical procedure used during an IS audit?

A.Observing the data center's physical security controls.
B.Reviewing a sample of change requests for proper authorization.
C.Comparing current period IT expenses to prior periods and investigating significant variances.
D.Interviewing the IT manager about change management procedures.
AnswerC

Comparing current IT expenses against prior periods and investigating variances is a substantive analytical procedure: it identifies anomalous fluctuations requiring explanation, providing audit evidence about account balances without detailed transaction testing. This satisfies the stem's requirement for an analytical procedure, unlike compliance testing or control walkthroughs, which examine process design rather than financial reasonableness.

Why this answer

Analytical procedures involve evaluating financial information by studying plausible relationships among data. Comparing current period expenses to prior periods is a typical example.

31
MCQmedium

Given this configuration, which is the PRIMARY concern?

A.Data change rate exceeds bandwidth
B.RTO may not be achievable
C.Synchronous replication may impact application performance
D.Bandwidth may be insufficient to meet RPO
AnswerD

The required replication bandwidth exceeds available bandwidth, risking RPO violations.

Why this answer

The primary concern is that bandwidth may be insufficient to meet the Recovery Point Objective (RPO). In synchronous replication, every write must be acknowledged by the remote site before the local write completes, so the link bandwidth must be at least equal to the peak data change rate. If bandwidth is lower, replication cannot keep up, causing the RPO (maximum acceptable data loss) to be violated as the backlog grows.

This directly threatens the organization's ability to recover data within the defined time window.

Exam trap

The trap here is that candidates often focus on the immediate performance impact (Option C) or the obvious bandwidth mismatch (Option A), but fail to recognize that the ultimate business requirement is the RPO, and insufficient bandwidth directly makes that requirement unachievable.

How to eliminate wrong answers

Option A is wrong because 'data change rate exceeds bandwidth' is a symptom of insufficient bandwidth, not the primary concern; the core issue is that the RPO cannot be met, not just that the rate exceeds capacity. Option B is wrong because RTO (Recovery Time Objective) relates to how quickly systems can be restored after a failure, not to the replication link's ability to keep data synchronized; synchronous replication does not directly affect RTO unless the link failure delays failover. Option C is wrong because while synchronous replication can impact application performance due to write latency, this is a secondary operational concern; the primary risk is that the RPO becomes unachievable if bandwidth is inadequate, which is a more critical business continuity issue.

32
MCQhard

An organization is evaluating a cloud-based identity as a service (IDaaS) for single sign-on (SSO). Which of the following security concerns is MOST critical to address?

A.Lack of encryption for SAML assertions
B.Incompatibility with legacy applications
C.Downtime of the IDaaS provider
D.Compromise of the identity provider's credentials
AnswerD

In SSO, the identity provider becomes the single authentication authority, so its credential compromise grants attackers access to every connected application. This concentration of trust makes IdP credential compromise the most critical concern, outweighing other IDaaS risks in the stem.

Why this answer

The compromise of the identity provider's (IdP) credentials is the most critical security concern because the IdP acts as the central trust anchor for all SSO transactions. If an attacker gains control of the IdP's signing key or administrative credentials, they can forge SAML assertions for any user, bypassing all downstream authentication and gaining unauthorized access to every connected service provider (SP). This represents a single point of failure that undermines the entire SSO trust model.

Exam trap

The trap here is that candidates often focus on technical protocol details like encryption (Option A) or operational risks like downtime (Option C), but the CISA exam emphasizes that the most critical security concern in any federated identity system is the protection of the identity provider's root of trust—its credentials—because a compromise there negates all other controls.

How to eliminate wrong answers

Option A is wrong because SAML assertions are inherently signed and often encrypted end-to-end using XML Signature and XML Encryption standards; the lack of encryption for the assertion body does not expose the authentication token if the transport layer (TLS) is used, and the critical security control is the digital signature, not encryption. Option B is wrong because incompatibility with legacy applications is an integration or migration concern, not a security concern; it can be addressed through federation gateways or protocol translation without compromising the security posture of the SSO system. Option C is wrong because downtime of the IDaaS provider is an availability and business continuity issue, not a security concern; while it impacts access, it does not directly lead to unauthorized data disclosure or system compromise.

33
MCQhard

An organization's backup strategy includes taking full backups weekly and transactional log backups every 15 minutes. The auditor wants to verify that backup encryption is implemented for offsite storage. Which control is most relevant?

A.Backup compression
B.Offsite transport log
C.Backup encryption at rest
D.Backup verification logs
AnswerC

Backup encryption at rest protects the transactional log and full backup files stored offsite, directly satisfying the auditor's verification objective. Because log backups occur every 15 minutes, each resulting file must be encrypted before leaving the environment, ensuring confidentiality of data at the offsite storage location.

Why this answer

Backup encryption at rest ensures that data stored offsite is protected from unauthorized access, which is a key control for offsite backups.

34
MCQeasy

Which type of change in ITIL requires approval from the Change Advisory Board (CAB) before implementation?

A.Emergency change
B.Normal change
C.Standard change
D.All changes
AnswerB

Normal changes follow the full assessment and authorisation path, so they require CAB approval before implementation. Standard changes are pre-authorised by a defined procedure, and emergency changes use a separate expedited route, typically with retrospective CAB review.

Why this answer

Normal changes are those that are not pre-approved or emergency. They require assessment and approval by the CAB to evaluate risks and impacts.

35
MCQmedium

A company has multiple business units with conflicting IT priorities. Which governance body should resolve this?

A.IT steering committee
B.Board of directors
C.IT management
D.Audit committee
AnswerA

An IT steering committee provides cross-functional executive oversight, arbitrating competing priorities between business units and aligning IT investment with enterprise strategy. It holds the authority to allocate resources and settle conflicts that individual unit managers cannot resolve, directly satisfying the stem's requirement for a governance body to mediate conflicting IT priorities.

Why this answer

An IT steering committee is the governance body composed of senior business and IT leaders that prioritizes IT investments and resolves conflicts between business units' competing IT priorities. It exists precisely to arbitrate cross-functional prioritization and align IT initiatives with business strategy, making it the correct forum for resolving conflicting priorities among business units.

Exam trap

CISA often tests the distinction between governance and management — candidates must remember that the IT steering committee is the governance body that resolves cross-business-unit IT priority conflicts, not IT management or the board.

How to eliminate wrong answers

Option B is wrong because the board of directors focuses on overall corporate strategy, fiduciary oversight, and shareholder interests — it does not typically get involved in operational IT prioritization conflicts between business units. Option C is wrong because IT management executes and delivers IT services but does not have the cross-business authority to arbitrate conflicting priorities between business units. Option D is wrong because the audit committee oversees financial reporting, internal controls, and compliance — not IT project prioritization.

36
MCQhard

Based on the exhibit, what should the IS auditor MOST likely recommend?

A.Investigate whether any changes are missing from the log
B.Immediately block all direct production access for developers
C.Require all changes to go through the standard approval process
D.Review the criteria for emergency changes and enforce proper classification
AnswerD

Emergency changes bypass normal approval, so auditors should verify that classification criteria are defined and consistently applied. Reviewing those criteria and enforcing proper classification prevents unjustified use of the expedited path, directly addressing the control weakness the exhibit reveals.

Why this answer

The exhibit shows changes classified as 'emergency' bypassing the standard approval process. The IS auditor's primary concern is that emergency changes may be misclassified to avoid proper review, increasing risk. Option D is correct because it addresses the root cause: reviewing the criteria for emergency changes and enforcing proper classification ensures that only truly urgent changes bypass standard controls, while all others follow the required approval path.

Exam trap

ISACA often tests the misconception that the IS auditor should immediately block all direct production access or require all changes to go through standard approval, when the real issue is ensuring proper classification and enforcement of the emergency change process.

How to eliminate wrong answers

Option A is wrong because the log may be complete; the issue is not missing entries but the classification and approval process for changes that are logged. Option B is wrong because blocking all direct production access for developers is an overly restrictive measure that may hinder legitimate emergency fixes; the focus should be on proper change classification and approval, not blanket access denial. Option C is wrong because requiring all changes to go through the standard approval process would eliminate the emergency change process entirely, which is not practical for urgent fixes; the correct approach is to ensure emergency changes are properly classified and justified, not to eliminate the process.

37
Multi-Selecteasy

Which TWO of the following are primary objectives of an information system audit?

Select 2 answers
A.Ensure optimal performance of IT systems
B.Implement security patches and updates
C.Identify areas for improvement in IT processes
D.Evaluate the effectiveness of internal controls
E.Prepare financial statements for external reporting
AnswersC, D

Identifying areas for improvement in IT processes is a core assurance objective: the auditor evaluates controls against criteria and reports weaknesses, feeding remediation and continuous improvement. This satisfies the stem's requirement for a primary objective, since information system audits exist to assess effectiveness and recommend enhancements, not merely to detect fraud or verify accounts.

Why this answer

An information system audit is fundamentally an assurance engagement, so its primary objectives are to evaluate the effectiveness of internal controls (D) — determining whether controls are designed and operating to provide reasonable assurance over confidentiality, integrity, and availability of information and IT services — and to identify areas for improvement in IT processes (C), since audit findings and recommendations drive corrective action and process maturity. Both C and D align with the auditor's independent, objective assessment role rather than with operational execution. Option A is not a primary audit objective because optimizing performance is an IT management/operations responsibility; the auditor may assess performance-related controls but does not ensure optimal performance.

Option B is also an operational task performed by IT staff (e.g., patch management), not an audit objective, and option E belongs to financial accounting/reporting, not to the IS audit function.

Exam trap

The trap here is confusing operational or management responsibilities (like performance tuning or patch implementation) with the auditor's role of evaluating controls and identifying process improvements, leading candidates to select options that describe IT tasks rather than audit objectives.

38
MCQeasy

Which of the following is the PRIMARY purpose of conducting a privacy impact assessment (PIA)?

A.To document the data processing activities
B.To obtain consent from data subjects
C.To ensure compliance with data protection laws
D.To identify privacy risks and recommend mitigations
AnswerD

A privacy impact assessment systematically examines a processing activity to identify privacy risks and recommend mitigations before harm occurs. This proactive risk identification and treatment is its primary purpose, distinguishing it from breach response, consent collection or regulatory notification.

Why this answer

The PRIMARY purpose of a Privacy Impact Assessment (PIA) is to systematically identify and assess privacy risks associated with a project, system, or process, and to recommend mitigation measures. It is a proactive risk management tool that helps organizations understand how personal information is collected, used, shared, and retained, and to address potential privacy harms before they occur. While compliance with laws and documenting processing activities are outcomes or components, the core objective is risk identification and mitigation.

Exam trap

CISA often tests the distinction between the primary purpose of a PIA (risk identification and mitigation) and secondary outcomes like compliance or documentation, causing candidates to select a broader or more familiar concept such as legal compliance.

How to eliminate wrong answers

Option A is wrong because documenting data processing activities is a component of a PIA (e.g., data mapping) but not its primary purpose; documentation supports the risk assessment. Option B is wrong because obtaining consent from data subjects is a separate legal basis for processing and is not the purpose of a PIA; consent may be one mitigation if required, but it is not the primary goal. Option C is wrong because ensuring compliance with data protection laws is a benefit or driver of conducting a PIA, but the primary purpose is to identify and mitigate privacy risks; compliance is an outcome, not the core objective.

39
MCQmedium

An IS auditor is reviewing the physical security controls at a data center that hosts the organization's primary transaction processing systems. The auditor observes that the data center uses a single-factor proximity card reader at the main entrance, the server room door is propped open during a vendor maintenance visit, and CCTV cameras record continuously but recordings are retained for only seven days. Which of the following should the auditor identify as the MOST significant control weakness?

A.The main entrance uses a single-factor proximity card reader instead of multifactor authentication.
B.CCTV recordings are retained for only seven days rather than the organization's 90-day standard.
C.The data center lacks biometric authentication at the server room entrance.
D.The server room door was propped open during the vendor visit, defeating the access control boundary.
AnswerD

A propped door during a vendor visit directly compromises the physical access control boundary and allows unescorted or unauthorized entry into the area housing critical transaction systems. Unlike the other observations, this is an active control failure occurring in real time that exposes the most sensitive assets. Vendor visits are a known risk period, and the door being held open means the access control system is not actually enforcing who enters the server room, making this the most significant weakness observed.

Why this answer

The propped server room door during a vendor visit is an active failure of the physical access control boundary protecting the transaction processing systems. While single-factor entry, short CCTV retention, and lack of biometrics are all valid observations, none of them currently allows uncontrolled access to the most sensitive area. The auditor should prioritize the real-time breach and require escorted vendor procedures and door alarms.

Exam trap

The trap here is gravitating toward technology gaps such as missing biometrics while overlooking an active physical control failure happening during the audit.

40
MCQeasy

A medium-sized retail company relies on an ERP system for order processing and inventory management. The system is hosted on-premises with daily backups stored on tape. The company's business continuity plan specifies an RTO of 4 hours and an RPO of 1 hour for the ERP system. During a recent fire drill, it was discovered that restoring the ERP system from tape took over 6 hours, and the most recent backup was from the previous day. Which of the following is the BEST course of action to meet the RTO and RPO goals?

A.Increase the frequency of tape backups to every 30 minutes.
B.Conduct quarterly fire drills instead of annually.
C.Implement a hot standby site with real-time replication.
D.Replace tape backups with weekly cloud backups.
AnswerC

Real-time replication to a hot standby site satisfies both constraints simultaneously: continuous data mirroring delivers an RPO near zero, well inside the one-hour limit, while the standby's pre-installed ERP instance allows failover within minutes, meeting the four-hour RTO that tape restoration cannot.

Why this answer

The drill revealed two failures: restore time exceeded the 4-hour RTO, and the backup was a day old, missing the 1-hour RPO. A hot standby site with real-time replication addresses both — failover can occur within minutes (meeting RTO) and replication keeps data current to seconds (meeting RPO). This is the only option that closes both gaps simultaneously.

Exam trap

CISA often tests the distinction between RTO and RPO — candidates frequently pick a backup-frequency fix (improves RPO only) when the scenario's real failure is restore speed (RTO).

How to eliminate wrong answers

Option A is wrong because increasing tape backup frequency to every 30 minutes improves RPO but does nothing for RTO — restoring from tape still takes hours, and tape-based restore speed is the bottleneck. Option B is wrong because more frequent drills test the plan but do not change the underlying recovery capability; the RTO/RPO gaps remain. Option D is wrong because weekly cloud backups are less frequent than the current daily tape backups, worsening RPO, and cloud restore over WAN may still exceed the 4-hour RTO.

41
MCQmedium

An organization uses role-based access control (RBAC) for its enterprise resource planning (ERP) system. What is the greatest risk if user role assignments are not reviewed regularly?

A.Inconsistent application of password policies across roles.
B.Privilege creep, where users retain permissions no longer needed.
C.Increased authentication failures due to expired passwords.
D.Inability to track audit logs for user activity.
AnswerB

Without periodic review, permissions accumulate as users change roles, so RBAC assignments no longer reflect least privilege. This privilege creep grants excessive access rights, increasing the risk that a user can perform unauthorised transactions or misuse segregation-of-duties conflicts within the ERP system.

Why this answer

In RBAC, permissions are assigned to roles, and users inherit those permissions through role membership. Without regular reviews, users may retain roles (and thus permissions) long after their job functions change, leading to privilege creep. This violates the principle of least privilege and increases the risk of unauthorized access or data breaches within the ERP system.

Exam trap

The trap here is that candidates confuse the operational impact of role reviews (privilege creep) with other access control issues like password policies or logging, which are separate concerns in the Protection of Information Assets domain.

How to eliminate wrong answers

Option A is wrong because password policies are typically set at the system or domain level, not tied to individual RBAC roles; inconsistent application would stem from policy configuration issues, not role review frequency. Option C is wrong because authentication failures due to expired passwords are managed by password expiration policies and account lockout mechanisms, not by the review of role assignments. Option D is wrong because audit log tracking is a function of the logging and monitoring infrastructure (e.g., SIEM, audit trails), not directly dependent on whether role assignments are reviewed; even with stale roles, logs can still be captured and tracked.

42
MCQmedium

An IS auditor is reviewing an organization's network segmentation design. The organization states that its cardholder data environment is isolated from the corporate network. During testing, the auditor discovers that a management VLAN can reach both environments and that the firewall permits administrative protocols from the management VLAN to any host. Which of the following is the auditor's BEST conclusion?

A.Segmentation is effective because administrative traffic is trusted and exempt from segmentation controls.
B.The finding is not significant because the management VLAN is internal to the organization.
C.Segmentation is ineffective because the management VLAN provides a path that bypasses the intended isolation.
D.The finding is acceptable if management traffic is encrypted with strong ciphers.
AnswerC

A management VLAN that can reach both the cardholder data environment and the corporate network, with administrative protocols permitted to any host, creates a bridge that defeats the purpose of segmentation. The intended isolation no longer holds because an attacker compromising a management workstation could pivot between environments, so the auditor should conclude the control objective is not met.

Why this answer

Segmentation depends on preventing any path between environments that should not communicate. A management VLAN with administrative protocol access to any host in both the cardholder data environment and the corporate network creates exactly such a path, so the isolation claim fails. Encryption, internal origin, and presumed trust of administrative traffic do not remove the reachability that allows lateral movement, and the auditor should report the design as ineffective.

Exam trap

The trap here is treating management traffic as inherently trusted, when a management VLAN that spans both environments is itself the bypass that breaks segmentation.

43
Multi-Selecthard

An organization is planning a full interruption test of its disaster recovery plan. Which THREE of the following should the IS auditor recommend as best practices for this type of test? (Select three.)

Select 3 answers
A.Notify all relevant stakeholders in advance
B.Conduct the test during peak business hours to simulate real conditions
C.Define clear test objectives and success criteria
D.Have a rollback plan in case of failure
E.Ensure the test is scheduled after a major system upgrade to validate changes
AnswersA, C, D

Advance notification lets stakeholders prepare for service disruption and staff the test, preventing the interruption from being mistaken for a genuine disaster. This satisfies the stem's full interruption scenario, where unannounced downtime could trigger unnecessary escalation.

Why this answer

Option A is correct because notifying all relevant stakeholders in advance is a best practice for a full interruption test, ensuring that business units, IT staff, and management are aware of the planned outage and can prepare for the disruption, thereby preventing unintended operational impact. Option C is correct because defining clear test objectives and success criteria provides measurable benchmarks for evaluating whether the disaster recovery plan achieves its recovery time objective (RTO) and recovery point objective (RPO), making the test meaningful and auditable. Option D is correct because having a rollback plan in case of failure is essential, as a full interruption test actually shuts down production systems, and if recovery fails, the organization must be able to restore normal operations quickly to avoid extended downtime.

Option B is not recommended because conducting the test during peak business hours unnecessarily magnifies risk to critical operations; such tests are typically scheduled during off-peak or maintenance windows. Option E is not recommended because scheduling the test immediately after a major system upgrade introduces unvalidated changes and instability, which could confound test results and increase the risk of failure unrelated to the DR plan itself.

Exam trap

The trap here is that candidates may confuse a full interruption test with a tabletop or simulated test, incorrectly assuming that notifying stakeholders (Option A) reduces realism, when in fact it is a critical safety control for a live failover exercise.

44
Multi-Selectmedium

An IS auditor is reviewing the physical security controls at a data center that hosts the organization's core banking platform. During the walkthrough, the auditor notes that the mantrap entrance functions correctly, but the loading dock door is propped open for ventilation and the CCTV system records only the main corridor. Which TWO of the following findings should the auditor report as control weaknesses? (Choose two.)

Select 2 answers
A.The organization has not implemented a formal visitor escort policy for the data center.
B.The data center does not use biometric authentication at the mantrap entrance.
C.CCTV coverage does not include the loading dock or other areas outside the main corridor.
D.The loading dock door is propped open, bypassing the physical perimeter control.
E.The mantrap entrance allows only one person to enter at a time and slows authorized staff.
AnswersC, D

Video surveillance that covers only the main corridor leaves the loading dock and other sensitive areas unmonitored, creating blind spots where unauthorized activity could occur undetected. Because the loading dock is already identified as an uncontrolled entry point, the absence of camera coverage there compounds the risk. The auditor should report the incomplete CCTV coverage as a control weakness that limits detection and investigation capability.

Why this answer

The walkthrough produced two concrete observations that weaken physical security: the loading dock door is propped open, bypassing the perimeter, and CCTV covers only the main corridor, leaving other areas unmonitored. Both conditions create opportunities for unauthorized entry and undetected activity. The functioning mantrap is not a weakness, and the scenario provides no evidence about biometric authentication or visitor escort policies, so those cannot be reported as findings.

Exam trap

The trap here is reporting assumptions about controls that were not observed, such as missing biometrics or escort policies, instead of the two weaknesses actually seen during the walkthrough.

45
Multi-Selecteasy

Which TWO of the following are common objectives of an IT balanced scorecard? (Choose two.)

Select 2 answers
A.Deploying a new ERP system
B.Reducing the number of help desk tickets
C.Enhancing IT staff skills and knowledge
D.Implementing a new firewall
E.Improving customer satisfaction with IT services
AnswersC, E

The IT balanced scorecard includes a learning and growth perspective, which covers developing IT staff competencies. Enhancing staff skills and knowledge therefore aligns with that objective, supporting the stem's requirement for common balanced scorecard goals.

Why this answer

The IT balanced scorecard adapts the four-perspective Kaplan-Norton framework to IT, so its objectives are outcome-oriented goals rather than one-off projects. Option C, enhancing IT staff skills and knowledge, is correct because it maps to the learning and growth (innovation) perspective, which drives the internal process and customer perspectives through continuous capability development. Option E, improving customer satisfaction with IT services, is correct because it maps to the customer perspective, measuring how well IT delivers value and meets service expectations.

Options A (deploying a new ERP system) and D (implementing a new firewall) are specific tactical projects or deliverables, not strategic scorecard objectives, and option B (reducing the number of help desk tickets) is a narrow operational metric that may even conflict with service quality rather than a balanced scorecard objective.

Exam trap

CISA often tests the difference between strategic objectives (like improving satisfaction or skills) and tactical initiatives (like deploying a system or reducing tickets).

46
MCQmedium

During the requirements gathering phase for a new financial system, stakeholders disagree on the priority of security controls versus user convenience. Which of the following is the BEST approach?

A.Postpone security decisions to later phases
B.Let the project team decide based on development ease
C.Conduct a risk assessment to balance security and usability
D.Implement all security controls regardless of convenience
AnswerC

A risk assessment quantifies the likelihood and impact of threats against the cost of controls, producing an evidence-based balance rather than letting the loudest stakeholder win. It satisfies the need to resolve the security-versus-convenience disagreement objectively during requirements gathering.

Why this answer

A risk assessment provides a structured, evidence-based framework for balancing security controls against user convenience during requirements gathering. By evaluating the likelihood and impact of threats specific to financial systems (e.g., transaction fraud, data breaches) against usability needs, the organization can prioritize controls that mitigate high-risk exposures without unnecessarily impeding legitimate business processes. This aligns with the COBIT 5 principle of balancing benefits, risk, and resource optimization.

Exam trap

The trap here is that candidates may choose Option A, mistakenly believing that security can be 'bolted on' later, but CISA emphasizes that security must be integrated from the requirements phase to avoid costly redesigns and compliance violations.

How to eliminate wrong answers

Option A is wrong because postponing security decisions to later phases introduces significant rework costs and integration challenges, as security requirements must be baked into system architecture from the start (e.g., secure coding practices, access control design). Option B is wrong because letting the project team decide based on development ease ignores stakeholder priorities and regulatory compliance (e.g., PCI DSS, SOX), leading to potential audit failures and security gaps. Option D is wrong because implementing all security controls regardless of convenience can cripple user productivity and lead to shadow IT, where users bypass controls (e.g., using unapproved cloud storage), increasing overall risk.

47
MCQeasy

An organization has implemented role-based access control (RBAC). Which of the following is the PRIMARY benefit of RBAC?

A.Simplified user permission management
B.Encryption of sensitive data at rest
C.Elimination of compliance requirements
D.Improved protection against malware
AnswerA

RBAC assigns permissions to roles rather than individual accounts, so administrators grant access by role membership. This simplifies user permission management, particularly at scale, because changes are applied once per role instead of being replicated across every user.

Why this answer

RBAC simplifies user permission management by assigning permissions to roles rather than individuals, allowing administrators to grant or revoke access by modifying role memberships. This reduces administrative overhead and the risk of permission errors, as changes propagate automatically to all users in a role. The primary benefit is operational efficiency in access control, not direct security features like encryption or malware protection.

Exam trap

The trap here is that candidates may confuse RBAC's administrative benefit with other security controls, assuming it directly provides encryption or malware defense, when in fact RBAC is purely an access management model.

How to eliminate wrong answers

Option B is wrong because encryption of sensitive data at rest is a data protection mechanism, not a benefit of RBAC; RBAC controls access to data but does not encrypt it. Option C is wrong because RBAC does not eliminate compliance requirements; it can help meet compliance (e.g., least privilege) but regulations still mandate audits, logging, and other controls. Option D is wrong because RBAC does not directly protect against malware; malware protection relies on endpoint security, antivirus, and network controls, not role-based access.

48
MCQmedium

A hospital is implementing a new electronic health records (EHR) system. The system will be used by doctors, nurses, and administrative staff. During the user acceptance testing (UAT) phase, the nursing staff reports that the interface for entering patient vitals is too slow and requires many clicks, which slows down their workflow. The project team has already completed system testing and is preparing for go-live in two weeks. The development team can make a quick fix to streamline the vital signs entry by adding a shortcut, but this change has not been tested. The IT director is concerned about patient safety and wants to ensure the system is usable. What is the BEST course of action?

A.Implement the quick fix immediately and go live as scheduled
B.Proceed with go-live as planned and address usability issues in a future release
C.Assess the risk, develop the fix, fast-track testing, and if successful, include it in the go-live
D.Delay go-live by one month to fully test the fix
AnswerC

Assessing the risk, building the fix, fast-tracking testing, then including it only if successful balances usability against patient safety. It addresses the nurses' workflow complaint without bypassing verification, unlike deploying untested changes or ignoring the issue before go-live.

Why this answer

It balances patient safety with project timelines by formally assessing the risk of the untested fix, developing it, and then fast-tracking a targeted regression test. This approach ensures the usability issue is resolved without bypassing necessary quality controls, which is critical for a clinical system where data entry errors could directly impact patient care. The IT director's concern about patient safety is addressed by the risk assessment and focused testing, while the go-live date is preserved if the fix passes.

Exam trap

The trap here is that candidates may choose Option B (defer usability) thinking it is safer, but they fail to recognize that a usability issue in a clinical workflow directly threatens patient safety by increasing the likelihood of data entry errors, making risk assessment and targeted remediation the correct approach.

How to eliminate wrong answers

Option A is wrong because implementing an untested change immediately before go-live violates change management best practices and could introduce critical defects that compromise patient safety, such as data corruption or loss of vital signs. Option B is wrong because proceeding with a known usability flaw that slows down vital signs entry increases the risk of data entry errors or omissions, which in a clinical setting can lead to incorrect treatment decisions and patient harm. Option D is wrong because delaying go-live by a full month is unnecessarily conservative for a targeted fix that can be validated through fast-tracked regression testing, and it introduces project delays and costs without proportional risk reduction.

49
MCQmedium

When an organization uses an external provider to manage its IT help desk, this is an example of which sourcing model?

A.Cloud services
B.Outsourcing
C.Insourcing
D.Co-sourcing
AnswerB

Outsourcing transfers the help desk function to an external provider under contract, with the vendor owning delivery and staffing. This differs from insourcing, which retains the function internally, and from managed services models that typically cover broader infrastructure operations.

Why this answer

Outsourcing is the sourcing model where an external provider manages a specific IT function, such as the help desk, under a contract. This transfers operational responsibility to the third party while the organization retains oversight. It is distinct from cloud services, insourcing, and co-sourcing.

Exam trap

CISA often tests the distinction between outsourcing and co-sourcing; candidates may incorrectly choose co-sourcing when the scenario describes full external management.

How to eliminate wrong answers

Option A is wrong because cloud services refer to on-demand delivery of computing resources (IaaS, PaaS, SaaS) over the internet, not the management of a help desk function. Option C is wrong because insourcing means using internal resources to provide the service, which is the opposite of using an external provider. Option D is wrong because co-sourcing involves a mix of internal staff and external providers sharing responsibility, whereas the scenario describes full external management.

50
Multi-Selectmedium

An organization is implementing a new customer relationship management (CRM) system using an agile methodology. Which THREE areas should the IS auditor focus on to assess the effectiveness of controls during the development process?

Select 3 answers
A.Use of formal change request documentation for each change
B.Inclusion of security requirements in user stories
C.Conduct of sprint retrospectives to identify improvements
D.Performance of code reviews and static analysis
E.Adherence to the original detailed project plan
AnswersB, C, D

Embedding security requirements in user stories makes them estimable, testable and traceable within sprints. The auditor examines whether stories carry explicit security acceptance criteria, since this determines whether controls are actually built rather than deferred to post-release remediation.

Why this answer

Option B is correct because in agile development, security requirements must be embedded into user stories and the product backlog so that controls are designed and tested iteratively rather than bolted on at the end; an IS auditor should verify that security acceptance criteria exist for each story. Option C is correct because sprint retrospectives are the agile mechanism for inspecting the process and identifying control and quality improvements, so their consistent conduct demonstrates an effective feedback loop for the development process. Option D is correct because code reviews and static analysis (e.g., SAST tools) provide technical verification of secure coding and defect detection at each increment, which is a key control compensating for the reduced reliance on phase-gate documentation in agile.

Option A is not the best focus because formal change request documentation for every change reflects a traditional waterfall change-control model, whereas agile relies on backlog refinement and continuous integration rather than per-change formal requests. Option E is not appropriate because adherence to an original detailed project plan contradicts agile's adaptive, iterative planning, where scope and plans evolve across sprints.

Exam trap

CISA often tests the misconception that agile projects should still follow waterfall-style documentation and plan adherence — candidates who pick A or E apply traditional audit thinking to an agile context.

51
MCQmedium

An organization is considering outsourcing its IT help desk. Which of the following is a key risk that should be addressed in the outsourcing contract?

A.Reduced flexibility in service hours
B.Lack of technical expertise in the outsourcing provider
C.Higher cost compared to in-house operations
D.Inadequate data privacy and security measures
AnswerD

Outsourcing transfers customer and employee data to a third party, so the contract must impose confidentiality, access controls, breach notification and regulatory compliance obligations. Without these, the provider could expose or misuse data, creating legal and reputational risk for the organisation.

Why this answer

Data privacy and security are critical when outsourcing services that handle sensitive information.

52
Multi-Selectmedium

Which TWO of the following are essential components of an effective incident response plan? (Select exactly 2.)

Select 2 answers
A.Root cause analysis procedures
B.Detailed vulnerability scanning schedules
C.Clearly defined roles and responsibilities
D.List of all hardware vendors and support contacts
E.Communication and escalation procedures
AnswersC, E

Defined roles and responsibilities assign specific ownership for detection, containment, eradication and recovery, eliminating ambiguity during high-pressure incidents. Without named accountable parties, response actions stall or duplicate, directly undermining the plan's coordination requirement in the stem.

Why this answer

Option C (Clearly defined roles and responsibilities) is correct because an incident response plan must assign specific duties—such as incident commander, triage lead, and communications officer—so that during a live incident each responder knows exactly who owns containment, eradication, and recovery tasks, preventing duplicated effort or gaps. Option E (Communication and escalation procedures) is correct because the plan must specify internal and external notification paths, escalation thresholds and timeframes, and contact trees (including legal, executive, and regulatory/PR channels) so that incidents are reported and elevated promptly and consistently. The unmarked options do not belong: root cause analysis (A) is a post-incident activity that improves future response but is not an essential structural component of the plan itself, vulnerability scanning schedules (B) belong to vulnerability management rather than incident response, and a hardware vendor contact list (D) is at best a supporting asset inventory detail, not a core component of an effective incident response plan.

Exam trap

ISACA often tests the distinction between proactive security activities (like vulnerability scanning or vendor lists) and the reactive, operational components of an incident response plan, leading candidates to mistakenly include non-essential items that are important for general IT management but not for immediate incident handling.

53
MCQeasy

Which of the following is a key control in the deployment phase of the SDLC?

A.Rollback plan
B.Threat modeling
C.User acceptance testing
D.Code review
AnswerA

A rollback plan provides a tested mechanism to revert to the prior stable state if deployment fails or introduces critical defects. This directly addresses the deployment phase's key risk — production disruption — by enabling rapid restoration of service, satisfying the stem's requirement for a key deployment control.

Why this answer

A rollback plan ensures that if deployment fails, the system can be restored to a known good state.

54
MCQhard

A multinational corporation is deploying a data loss prevention (DLP) solution across its network. The DLP system must be configured to prevent the exfiltration of personally identifiable information (PII) while minimizing false positives. Which approach is most effective?

A.Block all outbound email containing keywords such as 'SSN' or 'credit card'
B.Require all users to complete annual data handling training and rely on self-reporting
C.Implement full disk encryption on all endpoints and encrypt all outbound traffic
D.Use regex patterns for PII combined with context-aware policies (e.g., user role, destination domain)
AnswerD

Regex alone matches any 16-digit string, generating false positives on order numbers and test data. Layering context-aware policies — user role and destination domain — narrows matches to genuine exfiltration attempts, satisfying the stem's dual requirement to block PII while minimising false positives.

Why this answer

The most effective DLP approach combines regex-based detection of PII patterns with context-aware policies that consider user role, destination domain, and other metadata. This reduces false positives by only blocking or alerting when sensitive data is leaving in a risky context (e.g., a finance user sending to an external domain), while allowing legitimate business flows. Pure pattern matching without context generates excessive false positives, and encryption or training alone do not prevent exfiltration.

Exam trap

CISA often tests the misconception that encryption or training alone satisfies DLP requirements, or that simple keyword blocking is sufficient; the exam expects context-aware, layered detection to balance security and false positives.

How to eliminate wrong answers

Option A is wrong because blocking all outbound email containing keywords like 'SSN' or 'credit card' is overly broad and will generate massive false positives (e.g., legitimate business discussions, test data), disrupting operations without effectively preventing exfiltration via other channels. Option B is wrong because relying on annual training and self-reporting is a policy/awareness control, not a technical DLP enforcement mechanism, and it cannot prevent or detect actual data exfiltration. Option C is wrong because full disk encryption and encrypting outbound traffic protect data at rest and in transit from interception, but they do not prevent an authorized user from sending PII outbound; encryption does not address the exfiltration use case.

55
MCQmedium

A large enterprise recently experienced a data breach due to an insider threat. The IT governance committee is reviewing the incident and considering measures to prevent recurrence. Which of the following is the BEST course of action to address the root cause?

A.Implement a privileged access management (PAM) solution to control and monitor elevated access.
B.Increase logging and auditing of all user activities.
C.Deploy a security information and event management (SIEM) tool.
D.Terminate the employment of the insider who caused the breach.
AnswerA

Privileged access management directly addresses insider misuse by vaulting, brokering and session-recording elevated accounts, enforcing least privilege and just-in-time elevation. This targets the root cause — uncontrolled privileged credentials — rather than merely detecting activity after the breach has already occurred.

Why this answer

A privileged access management (PAM) solution directly addresses the root cause of an insider threat by controlling, monitoring, and auditing elevated access rights. Since the breach was caused by an insider, limiting and tracking privileged accounts prevents unauthorized or excessive use of administrative credentials, which is the most effective preventive measure against recurrence.

Exam trap

The trap here is that candidates often confuse detective controls (logging, SIEM) with preventive controls (PAM), or they mistakenly view termination as a root-cause fix rather than a reactive measure, failing to recognize that the root cause is the lack of access governance.

How to eliminate wrong answers

Option B is wrong because increasing logging and auditing of all user activities is a detective control, not a preventive one; it helps identify breaches after they occur but does not stop an insider from abusing elevated access. Option C is wrong because deploying a SIEM tool aggregates and correlates logs for detection and analysis, but it does not prevent an insider from using privileged access to cause a breach. Option D is wrong because terminating the insider is a reactive disciplinary action that addresses the specific individual but does not fix the underlying lack of access controls, leaving the enterprise vulnerable to future insider threats.

56
MCQmedium

An organization uses a standard change model for low-risk, pre-approved changes. Which of the following is an example of a standard change?

A.Upgrading the core router to a new model
B.Changing the backup schedule from daily to weekly
C.Applying a routine security patch to the firewall
D.Migrating the entire email system to the cloud
AnswerC

Routine firewall security patching fits the standard change model because it is pre-approved, low-risk, and repeatable, following a documented procedure with no CAB review required. This satisfies the stem's constraint that standard changes are pre-authorised, low-risk, and executed without individual assessment.

Why this answer

Standard changes are pre-approved, low-risk, and follow a defined procedure. Applying a routine security patch that has been tested and approved falls under this category.

57
MCQeasy

In a spiral SDLC model, what is the primary purpose of risk analysis in each iteration?

A.To identify and resolve potential project risks early
B.To assess user satisfaction with the prototype
C.To plan the next iteration's tasks
D.To define detailed functional requirements
AnswerA

Each spiral cycle begins by analysing risks so that high-exposure items are addressed through prototyping and mitigation before major investment continues. This early resolution reduces the likelihood of costly rework or failure in later, more expensive iterations.

Why this answer

In the spiral model, each iteration begins with risk analysis to identify and resolve potential project risks early, which is the core differentiator of this model. This allows the team to address high-risk areas before investing heavily in development, reducing the chance of costly failures later. The risk analysis directly informs whether to proceed, modify, or abandon the iteration.

Exam trap

The trap here is confusing the spiral model's risk analysis with general project risk management or with other phases like planning or requirements gathering; candidates may pick an answer that sounds plausible but is not the specific purpose of risk analysis in each iteration.

How to eliminate wrong answers

Option B is wrong because assessing user satisfaction with the prototype is part of the evaluation phase, not the primary purpose of risk analysis. Option C is wrong because planning the next iteration's tasks is a separate activity that follows risk analysis, not its purpose. Option D is wrong because defining detailed functional requirements is typically done during requirements elicitation, not during risk analysis in the spiral model.

58
Multi-Selectmedium

An organization is migrating from a legacy system to a new ERP. Which TWO of the following are the HIGHEST risks during data migration?

Select 2 answers
A.Incorrect data mapping between old and new systems
B.Insufficient network bandwidth during cutover
C.Lack of user training on the new system
D.Lack of segregation of duties in the new system
E.Incomplete or inaccurate source data
AnswersA, E

Incorrect mapping transfers values into wrong fields, corrupting balances, inventory and master data that downstream processes depend on. Because errors propagate silently and are costly to unwind post-cutover, mapping validation is a highest-risk migration concern.

Why this answer

Option A is correct because incorrect data mapping between the legacy and new ERP schemas directly causes fields to be transformed, truncated, or populated into the wrong target columns, producing corrupt or unusable records in the new system — a core data migration risk. Option E is correct because incomplete or inaccurate source data (missing values, duplicates, inconsistent formats) propagates defects into the ERP and undermines the integrity of the migrated dataset, regardless of how well the mapping is designed. These two are the highest risks because they directly threaten the accuracy and completeness of the migrated data itself, which is the primary objective of the migration.

Option B is not a top migration risk since bandwidth affects cutover performance/throughput rather than data correctness and is typically mitigated by scheduling and sizing. Option C concerns post-migration adoption and user competence, not the integrity of the migrated data. Option D is an access-control/governance risk in the new system's design, not a data migration risk.

Exam trap

The trap is that candidates may focus on technical or training risks that are more visible, but the exam expects recognition that data integrity risks (mapping and source data quality) are the highest during data migration.

59
MCQeasy

A systems analyst is gathering requirements for a new customer relationship management (CRM) system. Which of the following is the MOST important activity to ensure that the final system meets user needs?

A.Creating a prototype and asking for feedback after development.
B.Conducting a joint requirements validation session with stakeholders.
C.Developing a detailed technical specification before user sign-off.
D.Documenting all requirements in a formal specification.
AnswerB

A joint requirements validation session brings stakeholders together to review and confirm documented requirements, exposing gaps, conflicts and misunderstandings before design begins. This shared verification directly reduces the risk of building a CRM that fails to meet user needs.

Why this answer

Conducting a joint requirements validation session with stakeholders (Option B) is the most important activity because it ensures that the requirements are accurate, complete, and agreed upon before development begins. This collaborative review process directly involves end users and business owners, allowing for immediate clarification and correction of misunderstandings, which is critical for aligning the CRM system with actual business processes. Without this validation, even a perfectly built system may fail to meet user needs, leading to costly rework.

Exam trap

The trap here is that candidates often confuse 'documenting requirements' (Option D) with 'validating requirements,' assuming that formal documentation alone is sufficient to ensure user needs are met, whereas the CISA exam emphasizes that validation through stakeholder interaction is the critical step to prevent costly rework.

How to eliminate wrong answers

Option A is wrong because creating a prototype and asking for feedback after development violates the iterative validation principle; feedback should be gathered during development, not after, to avoid rework and misalignment with user expectations. Option C is wrong because developing a detailed technical specification before user sign-off assumes that technical details can be finalized without user validation, which often leads to a system that meets technical specs but fails to satisfy business requirements. Option D is wrong because documenting all requirements in a formal specification alone does not ensure that the requirements are correct or understood by stakeholders; it is a passive activity that lacks the interactive validation needed to confirm user needs.

60
MCQeasy

According to ISACA IT Audit Standards, which of the following is the primary purpose of audit documentation (working papers)?

A.To facilitate the planning of the next audit
B.To serve as a legal record for potential litigation
C.To provide a basis for the audit report and support the auditor's conclusions
D.To demonstrate compliance with audit standards
AnswerC

Working papers record the procedures performed, evidence obtained and conclusions reached, giving reviewers and regulators a basis to support the audit report. This evidentiary foundation is the primary purpose, not administrative convenience or staff appraisal.

Why this answer

Audit documentation supports the auditor's conclusions and provides evidence of the work performed. It is not primarily for future audit planning or legal protection.

61
Drag & Dropmedium

Arrange the steps to implement a password policy in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Password policy implementation: define requirements, set expiration, lockout, communicate, and enforce.

62
MCQhard

During a third-party software vendor audit, the IS auditor discovers that the vendor uses a common shared database for multiple clients and relies on application-level access controls. Which of the following is the GREATEST concern?

A.Data from different clients may be commingled and accessible.
B.The database does not encrypt data at rest.
C.The vendor does not perform regular penetration testing.
D.The vendor lacks segregation of duties among administrators.
AnswerA

Application-level controls alone cannot prevent cross-client exposure if the shared database or application is compromised or misconfigured. Commingled client data in one repository removes the isolation boundary, so a single flaw could expose every tenant's records, making this the greatest concern.

Why this answer

The greatest concern is that data from different clients may be commingled and accessible because the vendor uses a common shared database with only application-level access controls. If application controls fail or are bypassed, clients could access each other's data, leading to a confidentiality breach and compliance violations. This represents a multi-tenancy risk that is more severe than the other issues listed.

Exam trap

CISA often tests the severity of risks in multi-tenant environments; candidates may focus on encryption or penetration testing as the greatest concern, but the exam expects recognition that commingling of client data with only application-level controls poses the most direct and severe confidentiality risk.

How to eliminate wrong answers

Option B is wrong because lack of encryption at rest is a concern, but it is less severe than the risk of cross-client data exposure; encryption protects data if the storage media is compromised, but commingling directly exposes data to other tenants. Option C is wrong because lack of regular penetration testing is a process weakness, but it does not directly cause data leakage between clients; it is a secondary control gap. Option D is wrong because lack of segregation of duties among administrators is an internal control issue, but it does not inherently expose client data to other clients; the shared database with application-level controls is a more direct and immediate threat to data confidentiality.

63
MCQmedium

An organization uses shared accounts for system administration. Which of the following is the MOST significant audit concern?

A.Increased complexity of password management
B.Lack of individual accountability and audit trail
C.Violation of segregation of duties
D.Higher risk of password sharing outside the team
AnswerB

Shared administrative accounts mean activity cannot be attributed to a named individual, so the audit trail cannot support investigation, least-privilege enforcement or disciplinary action. This loss of individual accountability is the most significant concern because it undermines every other administrative control.

Why this answer

Shared administrative accounts break the fundamental audit principle of individual accountability because multiple administrators operate under one identity, making it impossible to attribute a specific action to a specific person. Without unique user IDs, the audit trail (logs, change records, access reviews) cannot reliably identify who performed which action, undermining non-repudiation and forensic investigation. This is the most significant concern because it defeats the purpose of logging and monitoring controls that auditors rely on.

Exam trap

CISA often tests the distinction between operational inconvenience (password complexity) and control failure (loss of accountability), so candidates who focus on the 'sharing' risk rather than the audit trail principle pick the wrong answer.

How to eliminate wrong answers

Option A is wrong because password management complexity is an operational inconvenience, not a control failure — it can be mitigated with a privileged access management (PAM) vault and does not by itself destroy auditability. Option C is wrong because segregation of duties is a related but distinct concern; shared accounts do not automatically violate SoD if duties are otherwise separated, and SoD can still be enforced through other controls. Option D is wrong because password sharing outside the team is a symptom of the same root problem (no individual accountability) and is a risk rather than the core audit concern; the fundamental issue is the loss of attributable audit trails.

64
Multi-Selecthard

An IS auditor is reviewing the organization's incident management process. Which THREE of the following are essential components of an effective incident response plan?

Select 3 answers
A.Defined roles and responsibilities for the incident response team
B.Procedures for evidence collection and chain of custody
C.Communication procedures for internal and external stakeholders
D.A list of all employees and their contact information
E.A detailed technical guide for each software application
AnswersA, B, C

Clearly defined roles and responsibilities assign each team member specific duties during an incident, preventing duplicated effort, gaps and confusion under pressure. This structure is essential for the plan to execute coordinated containment, eradication and recovery actions.

Why this answer

Option A is correct because an effective incident response plan must clearly define roles and responsibilities for the incident response team, ensuring each member knows their specific duties and authority during an incident. Option B is correct because procedures for evidence collection and chain of custody are essential to preserve forensic integrity, support potential legal or disciplinary actions, and ensure evidence is admissible. Option C is correct because communication procedures for internal and external stakeholders are critical for timely notification, coordination, regulatory compliance, and managing public relations during and after an incident.

Option D is not correct because a list of all employees and their contact information, while useful for general administration, is not an essential component of an incident response plan and may be maintained separately in a business continuity or crisis communication plan. Option E is not correct because a detailed technical guide for each software application is an operational or application-specific document, not a core component of an incident response plan, which should focus on processes, roles, and communication rather than exhaustive technical manuals.

65
MCQeasy

An IT auditor is reviewing the business continuity plan (BCP) testing schedule. The organization conducts a test where participants discuss their roles and responses to a scenario without any actual system activation. Which type of test is this?

A.Parallel test
B.Walkthrough
C.Simulation
D.Tabletop exercise
AnswerD

A tabletop exercise gathers participants to walk through roles, decisions and communications against a hypothetical scenario, with no systems activated and no relocation. This discussion-based format contrasts with functional, simulation and full-interruption tests, which involve actual system or site activation.

Why this answer

A tabletop exercise is a discussion-based BCP test where participants verbally walk through their roles and responses to a hypothetical scenario without activating systems or relocating staff. It is the least disruptive and least expensive test type, used to validate plans, clarify roles, and identify gaps before conducting more resource-intensive tests. Because the question specifies 'discuss their roles and responses... without any actual system activation,' this maps directly to a tabletop exercise.

Exam trap

The trap here is confusing discussion-based tests (tabletop, walkthrough) with execution-based tests (simulation, parallel, full interruption); candidates who see 'scenario' and jump to 'simulation' miss the phrase 'without any actual system activation.'

How to eliminate wrong answers

Option A is wrong because a parallel test involves running the recovery site in parallel with the primary site, processing live transactions simultaneously — it requires actual system activation. Option B is wrong because a walkthrough is a structured review of the plan document step by step, often with a checklist, and does not involve scenario-based role discussion; it is more of a documentation review than a response rehearsal. Option C is wrong because a simulation is a more advanced test where participants actually perform recovery activities (e.g., restoring data, activating alternate sites) in a simulated environment, which goes beyond discussion.

66
MCQhard

An organization is implementing a change management process. A change that requires approval from the Change Advisory Board (CAB) but is scheduled to be implemented during the next maintenance window is classified as which type of change?

A.Emergency change
B.Standard change
C.Minor change
D.Normal change
AnswerD

A normal change is defined by its adherence to the full change management process, requiring formal assessment and authorisation. The scenario's explicit mention that the change requires approval from the Change Advisory Board (CAB) directly aligns with this classification. Additionally, scheduling the implementation during a future maintenance window signifies a planned, non-urgent deployment, confirming it follows the structured workflow typical of a normal change, rather than an emergency or pre-approved standard change.

Why this answer

A normal change is any change that is not a standard (pre-approved, low-risk, routine) change and not an emergency change; it must go through the full change management process including CAB review and approval, and is typically scheduled for a maintenance window. Because the change requires CAB approval and is scheduled for the next maintenance window, it fits the definition of a normal change. Standard changes are pre-authorized and do not require CAB review, while emergency changes bypass the normal schedule.

Exam trap

The trap is assuming that any scheduled, low-risk change is a 'standard change'; candidates must remember that standard changes are pre-authorized and do not require CAB approval, whereas normal changes do.

How to eliminate wrong answers

Option A is wrong because an emergency change is one that must be implemented immediately to resolve an incident or restore service, bypassing the normal CAB schedule (often with retroactive approval); this change is scheduled, not urgent. Option B is wrong because a standard change is a pre-approved, low-risk, repeatable change (e.g., password reset, adding a user) that does not require CAB approval at all. Option C is wrong because 'minor change' is not a standard ITIL change category — ITIL 4 defines standard, normal, and emergency changes; minor changes are a colloquial term and not the formal classification tested here.

67
MCQhard

In a RACI matrix for the change management process, who is typically Accountable for the overall change process?

A.The change requester
B.The system owner
C.The change manager
D.The IT director
AnswerC

The change manager owns the end-to-end change process, answering for its design, compliance and outcomes, while others are consulted or informed. This satisfies the stem's accountability requirement, since RACI accountability rests with the single role answerable for the process.

Why this answer

In a RACI matrix, the Accountable party is the single individual who ultimately owns the outcome and answers for the process end-to-end. For change management, that role is the change manager, who owns the change process, chairs the change advisory board (CAB), and is answerable for whether changes are properly assessed, approved, and implemented. The change requester and system owner are typically Responsible or Consulted, not Accountable for the overall process.

Exam trap

CISA often tests the distinction between Accountable (single owner who answers for the outcome) and Responsible (the doer), so candidates who equate 'who does the work' with 'who is accountable' pick the requester or system owner.

How to eliminate wrong answers

Option A is wrong because the change requester is Responsible for submitting and supporting the change request, not Accountable for the entire change management process. Option B is wrong because the system owner is Consulted or Responsible for changes affecting their system, but does not own the enterprise change process. Option D is wrong because the IT director is typically Informed or holds executive oversight, but the operational accountability for the change process sits with the change manager.

68
MCQmedium

An IT steering committee is reviewing a proposed project to migrate critical applications to the cloud. Which of the following is the PRIMARY role of the IT steering committee in this decision?

A.To perform the technical feasibility study
B.To select the cloud service provider
C.To ensure the project aligns with business strategy
D.To manage the project budget and schedule
AnswerC

The steering committee's primary function is governance: confirming that proposed investments align with and advance the organisation's business strategy. Cloud migration decisions are prioritised on strategic fit, not technical detail, so alignment with business strategy is its core responsibility.

Why this answer

The IT steering committee ensures that IT investments align with business strategy. They are responsible for strategic alignment and approving major projects based on business value.

69
Multi-Selecteasy

Which TWO of the following are key components of an IT governance framework? (Choose two.)

Select 2 answers
A.Network topology diagram
B.Help desk procedures
C.Hardware inventory
D.IT strategy
E.IT steering committee
AnswersD, E

IT strategy aligns technology investment and delivery with enterprise objectives, giving the governance framework its direction-setting component. It ensures decisions about resources, risk and priorities trace back to business goals rather than isolated technical preferences.

Why this answer

Option D (IT strategy) is correct because an IT governance framework must define how IT is aligned with and supports the organization's business objectives, and the IT strategy is the core document that establishes this direction, priorities, and value delivery. Option E (IT steering committee) is correct because governance requires a decision-making body with assigned authority and accountability; the IT steering committee provides oversight, prioritization, and resource-allocation decisions across IT initiatives. The remaining options do not belong: a network topology diagram (A) and a hardware inventory (C) are operational/technical artifacts describing infrastructure, not governance mechanisms, and help desk procedures (B) are tactical service-management documentation rather than a governance component.

Exam trap

CISA often tests the distinction between governance artifacts (strategy, steering committees, policies, oversight bodies) and operational/technical artifacts (topology diagrams, help desk procedures, inventories) — candidates frequently pick the technical-sounding option because it feels concrete.

70
Multi-Selectmedium

An organization is implementing COBIT 2019. Which TWO of the following are governance enablers? (Choose two.)

Select 2 answers
A.Hardware configuration
B.Project schedule
C.Organizational structures
D.Network performance
E.Culture, ethics and behavior
AnswersC, E

Organizational structures are a COBIT 2019 governance enabler, defining decision rights, roles and reporting lines that determine how governance is implemented. They satisfy the enabler category covering the formal entities and relationships through which IT governance decisions are made and executed.

Why this answer

In COBIT 2019, governance enablers are the components that make governance and management of enterprise IT possible, and the framework defines seven enabler categories: principles/policies/frameworks, processes, organizational structures, culture/ethics/behavior, information, services/infrastructure/applications, and people/skills/competencies. Option C (Organizational structures) is correct because it is one of these seven enabler categories, covering the decision-making roles, boards, and committees that define accountability for I&T governance. Option E (Culture, ethics and behavior) is also correct because it is explicitly listed as an enabler category, capturing the values and behaviors of individuals and the enterprise that influence governance outcomes.

Options A (Hardware configuration), B (Project schedule), and D (Network performance) are not governance enablers; they are specific technical or project-level artifacts that fall under other domains (e.g., services/infrastructure or management processes) rather than being one of COBIT's defined enabler categories.

Exam trap

CISA often tests whether candidates confuse operational artifacts (schedules, hardware, performance metrics) with the seven formal COBIT governance enabler categories.

71
MCQmedium

An IS auditor is reviewing change management procedures. Which of the following situations would be of GREATEST concern?

A.A standard change was implemented without CAB approval
B.An emergency change was implemented and not reviewed after resolution
C.The change request did not include an impact analysis
D.A normal change had a rollback plan that was not tested
AnswerB

Emergency changes bypass normal review, so the absence of post-implementation review leaves the change permanently unverified, with no confirmation it was authorised, tested, or documented. This defeats the control's compensating mechanism and represents the greatest change management concern.

Why this answer

An emergency change bypasses the normal CAB review and testing gates, so the only compensating control is a mandatory post-implementation review (PIR) to confirm the change worked, assess side effects, and retroactively authorize it. If that review never happens, the change remains unauthorized and unverified, leaving a permanent gap in the change management audit trail. This is the greatest concern because it defeats the entire purpose of the emergency-change exception.

Exam trap

CISA often tests the distinction between process-documentation weaknesses (missing impact analysis, untested rollback) and control-bypass weaknesses (unreviewed emergency change) — candidates pick the more 'visible' documentation gap instead of the actual loss of control.

How to eliminate wrong answers

Option A is wrong because standard (pre-approved, low-risk) changes are by definition pre-authorized through a standing CAB-approved model, so implementing one without a per-change CAB vote is normal and not a control failure. Option C is wrong because a missing impact analysis is a documentation/process weakness that is typically caught and remediated during normal change review, not a bypass of the control framework. Option D is wrong because an untested rollback plan on a normal change is a risk-mitigation weakness, but the change still went through CAB approval, testing, and post-implementation verification — a lesser concern than an unreviewed emergency change.

72
MCQeasy

In a RACI matrix for an IT change management process, who is responsible for performing the change?

A.The business process owner
B.The system administrator
C.The IT director
D.The change manager
AnswerB

In a RACI matrix, the Responsible party performs the actual work of implementing the change. A system administrator executes the technical change tasks, distinguishing this from the Accountable owner who authorises it and the Consulted or Informed stakeholders.

Why this answer

In a RACI matrix, the 'Responsible' party is the one who actually performs the work — for an IT change, that is typically the system administrator who implements the change. The business process owner is usually Accountable or Consulted, the IT director may be Accountable or Informed, and the change manager coordinates the process but does not perform the technical change.

Exam trap

CISA often tests whether candidates confuse 'Responsible' (does the work) with 'Accountable' (owns the outcome), leading them to select a manager or owner instead of the hands-on administrator.

How to eliminate wrong answers

Option A is wrong because the business process owner is typically Accountable (owns the outcome) or Consulted, not the one executing the technical change. Option C is wrong because the IT director usually serves as Accountable or Informed at a governance level, not as the hands-on implementer. Option D is wrong because the change manager coordinates, approves, and tracks changes (often Accountable or Responsible for the process), but does not perform the actual technical implementation.

73
MCQeasy

An IS auditor is reviewing the post-implementation review (PIR) of a newly deployed human resources (HR) system. Which of the following should be the PRIMARY focus of the PIR?

A.Verifying that the system meets business requirements and delivers expected benefits.
B.Ensuring that all project documentation is archived.
C.Comparing actual project costs to the approved budget.
D.Confirming that the project team has been released from their assignments.
AnswerA

The primary purpose of a post-implementation review is to determine if the system achieved its intended business objectives and benefits. This involves assessing user satisfaction, system performance, and alignment with business needs. Cost and schedule are inputs, but the core focus is on benefits realization and whether the system is fit for purpose.

Why this answer

A post-implementation review should primarily evaluate whether the system meets business requirements and delivers the expected benefits. This assessment helps organizations learn from the project and ensure the system is providing value. While cost, documentation, and resource release are relevant, they are secondary to the core goal of benefits realization.

Exam trap

The trap here is equating the post-implementation review with a financial audit or administrative closeout, rather than a benefits realization assessment.

74
MCQmedium

A financial institution is evaluating its IT governance structure. Which of the following roles is BEST suited to ensure independent oversight of IT investments?

A.Chief Information Officer (CIO)
B.Project Management Office (PMO) director
C.IT Audit Committee
D.Chief Information Security Officer (CISO)
AnswerC

An independent audit committee provides objective oversight.

Why this answer

The IT Audit Committee is the correct answer because it provides independent oversight of IT investments by operating outside of management's direct reporting structure. Unlike the CIO, PMO director, or CISO, who are all part of management and may have vested interests in project approvals or resource allocation, the IT Audit Committee reports to the board of directors and ensures that IT investments align with enterprise strategy, risk appetite, and regulatory requirements without bias.

Exam trap

The trap here is that candidates often confuse operational management roles (CIO, PMO director, CISO) with governance roles, mistakenly believing that a senior IT manager can provide independent oversight when they are actually part of the management chain being overseen.

How to eliminate wrong answers

Option A is wrong because the Chief Information Officer (CIO) is a senior management role responsible for the day-to-day operation and strategic planning of IT, which inherently lacks the independence required for oversight of IT investments. Option B is wrong because the Project Management Office (PMO) director is focused on project execution, resource management, and delivery metrics, not on independent governance or strategic alignment of IT investments. Option D is wrong because the Chief Information Security Officer (CISO) is primarily concerned with information security risk management and compliance, not with the broader financial and strategic oversight of IT investments.

75
MCQeasy

An IS auditor is reviewing the physical security controls at a data center. The auditor observes that the data center has a single entrance with a biometric scanner, but the door is propped open by a cleaning cart while the cleaning staff works inside. Which of the following is the MOST appropriate action for the auditor to take?

A.Ignore the observation because the cleaning staff are authorized personnel who have undergone background checks.
B.Recommend replacing the biometric scanner with a more robust access control system.
C.Report the issue to the cleaning supervisor and consider the matter resolved.
D.Document the observation as a finding because the propped door defeats the access control and allows unauthorized entry.
AnswerD

A propped door bypasses the biometric access control, allowing anyone to enter without authentication. This is a clear physical security weakness that undermines the entire access control objective. The auditor should document it as a finding because it represents a real risk of unauthorized access. Observing and reporting the issue is the appropriate audit action, not ignoring or downplaying it.

Why this answer

A propped door completely bypasses the biometric access control, creating a path for unauthorized entry. The auditor should document this as a finding because it represents a failure of the physical access control objective. The appropriate recommendation would be to implement compensating controls such as door alarms, mantrap entrances, or strict policy enforcement to prevent doors from being held open.

Exam trap

The trap here is assuming that because the individuals present are authorized, the propped door is acceptable, when in fact the open door allows anyone to enter without authentication.

Page 1 of 13

Page 2