Courseiva

Certified Information Systems Auditor CISA (CISA) — Questions 901–934

934 questions total · 13pages · All types, answers revealed

Page 12

Page 13 of 13

901
MCQhard

A financial services company is developing a new customer-facing web application for account management. The project is using a waterfall methodology. The initial requirements were gathered six months ago, and the coding phase is nearly complete. The business sponsor now requests a new feature that allows customers to view transaction receipts online. The project manager is concerned that this change will delay the project by two months and exceed the budget. The sponsor insists that the feature is critical for customer satisfaction and that the project must adapt. The development team estimates it will take 200 hours to implement. The steering committee is divided. As an IS auditor, what would be the BEST recommendation to resolve this?

A.Formally submit a change request, assess the impact on cost and schedule, and obtain approval from the change control board before proceeding.
B.Terminate the current project and launch a new project incorporating the new feature.
C.Advise the sponsor to postpone the feature until the next release and continue as planned.
D.Instruct the development team to implement the feature immediately to satisfy the sponsor.
AnswerA

Waterfall baselines are controlled through formal change management. Submitting a change request lets the change control board assess the 200-hour impact on cost and schedule, then approve or reject it, preserving scope discipline while giving the sponsor a legitimate route to adapt.

Why this answer

In a waterfall methodology, changes after the coding phase require a formal change control process to assess impact on cost, schedule, and scope. The correct answer is A because submitting a change request to the change control board (CCB) ensures that the 200-hour effort, two-month delay, and budget overrun are evaluated against business priorities, maintaining project governance and auditability. This aligns with ISACA’s guidance on managing scope creep in systems development.

Exam trap

The trap here is that candidates may choose Option C (postpone) thinking it avoids delay, but the question explicitly states the sponsor insists the feature is critical, so ignoring it fails to address the business need and can lead to project failure despite staying on schedule.

How to eliminate wrong answers

Option B is wrong because terminating the current project and launching a new one is an extreme, inefficient response that wastes completed coding work and introduces unnecessary risk, failing to leverage the existing investment. Option C is wrong because it unilaterally overrides the sponsor’s business-critical requirement without formal evaluation, which can lead to stakeholder dissatisfaction and missed market needs, violating the principle of balanced governance. Option D is wrong because instructing the team to implement immediately bypasses change control, budget approval, and impact analysis, creating uncontrolled scope creep and potential audit findings for unauthorized changes.

902
MCQhard

An IS auditor is reviewing the release management process for a critical application. The release strategy includes a phased rollout to 10% of users initially, then 50%, then 100%. The first phase revealed a data integrity issue that affected a subset of transactions. The release manager decided to continue with the next phase while a patch was being developed. What should the auditor most recommend?

A.Document the issue as a known error and proceed.
B.Accelerate the rollout to quickly identify all issues.
C.Increase testing in the next phase to catch issues earlier.
D.Halt the rollout until the data integrity issue is resolved.
AnswerD

Continuing a phased rollout while a known data integrity defect remains unresolved propagates corruption to 50% and then 100% of users. Halting until the patch is validated prevents wider impact, satisfying the stem's need to contain an identified integrity issue.

Why this answer

Continuing the rollout while a data integrity issue exists could affect more users. Best practice is to halt the rollout until the issue is resolved and patched, to prevent further impact and ensure the fix is effective.

903
MCQmedium

An IS auditor is reviewing a post-implementation review (PIR) of a new CRM system. The auditor finds that the project was completed on time and within budget, but the business case benefits have not been realized. Which of the following is the MOST likely cause?

A.The PIR was conducted too early to measure benefits.
B.The project team focused on technical delivery rather than business outcomes.
C.The system was delivered with more features than required, leading to complexity.
D.The budget was insufficient to cover change management activities.
AnswerB

A common reason for unrealized benefits is that the project team prioritizes technical milestones (e.g., on-time, on-budget) over achieving the business objectives. Without clear alignment to business goals and benefit realization planning, the system may be delivered but not used effectively to generate the intended value.

Why this answer

When a project is delivered on time and within budget but benefits are not realized, the root cause is often that the project was managed as a technical exercise rather than a business change initiative. Without explicit focus on benefit realization, user adoption, and process alignment, the system may not deliver the expected value.

Exam trap

The trap here is assuming that on-time and on-budget delivery equates to project success, whereas benefit realization is the ultimate measure of success.

904
Multi-Selectmedium

An IS auditor is evaluating an organization's SDLC controls for a new system. Which TWO of the following are key controls that should be in place during the design phase? (Select TWO.)

Select 2 answers
A.Architecture review by a senior architect
B.Static application security testing (SAST)
C.User acceptance testing (UAT)
D.Regression testing
E.Threat modeling to identify security threats
AnswersA, E

Architecture review by a senior architect validates design decisions against security, scalability and compliance requirements before coding begins, satisfying the design-phase control objective. It provides independent scrutiny of proposed structures, catching flaws when remediation is cheapest. This directly addresses the stem's requirement for key design-phase SDLC controls.

Why this answer

Option A (Architecture review by a senior architect) is correct because the design phase is exactly when the proposed system architecture, integration points, and technology choices must be validated against enterprise standards, scalability, and security requirements before costly build work begins. Option E (Threat modeling to identify security threats) is correct because threat modeling is a design-phase activity that systematically identifies threats, attack surfaces, and required mitigations (e.g., using STRIDE or DREAD) so that security controls are built into the design rather than retrofitted. Option B (SAST) is not a design-phase control; static application security testing analyzes source code or binaries during coding/build, so it belongs to development and testing phases.

Option C (UAT) is a testing-phase control performed by end users to confirm the system meets business requirements before go-live. Option D (Regression testing) is also a testing-phase control executed after changes to verify that existing functionality has not been broken.

Exam trap

The trap here is that candidates confuse security testing techniques like SAST with design-phase controls, or they mistakenly think UAT or regression testing occur early in the SDLC, when in fact they belong to later phases.

905
Drag & Dropmedium

Arrange the steps to perform a risk assessment in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Risk assessment begins with asset identification, then threat/vulnerability identification, followed by risk analysis, prioritization, and documentation of treatment.

906
MCQmedium

An organization is selecting a vendor for a new procurement system. Which of the following is the MOST important factor to include in the contract?

A.A clause limiting vendor liability
B.Fixed price for the entire contract term
C.Detailed service level agreements (SLAs)
D.Right to audit the vendor's security controls
AnswerD

A contractual right to audit lets the organisation independently verify the vendor's security controls, rather than relying on self-attestation. This directly addresses the stem's constraint: the vendor will process organisational data, so the contract must preserve ongoing assurance over those controls.

Why this answer

The right to audit the vendor's security controls is the most important factor because it provides the organization with the ability to verify that the vendor is complying with security requirements and contractual obligations. Without this right, the organization has no assurance that its data is protected, especially when the vendor handles sensitive information. This is a critical governance and risk management control.

Exam trap

The trap is selecting options that seem important for contract management (e.g., SLAs, liability limits) but do not provide the organization with the ability to verify security controls; the exam expects you to prioritize the right to audit as a fundamental assurance mechanism.

How to eliminate wrong answers

Option A is wrong because a clause limiting vendor liability may protect the vendor financially but does not ensure security; it could even reduce the vendor's incentive to maintain strong controls. Option B is wrong because a fixed price for the entire contract term is a financial consideration, not a security or compliance control; it does not address the protection of organizational assets. Option C is wrong because detailed SLAs are important for defining performance expectations, but they do not provide the organization with the ability to independently verify security controls; SLAs typically focus on availability, response times, and other service metrics, not security assurance.

907
MCQeasy

During an audit of the information security program, the IS auditor reviews the organization's information security policy. Which of the following is the PRIMARY purpose of an information security policy?

A.To provide detailed step-by-step instructions for implementing security controls
B.To specify the technical configurations for security devices
C.To define the roles and responsibilities for information security
D.To communicate management's commitment and direction for information security
AnswerD

The policy exists to articulate management's commitment and strategic direction for information security, authorising the programme and setting expectations. This satisfies the stem's constraint by establishing the mandate from which standards, procedures and controls derive their authority.

Why this answer

The primary purpose of an information security policy is to communicate management's commitment, intent, and direction for information security across the organization. It is a high-level governance document that establishes the mandate from which standards, procedures, and guidelines flow. It is not intended to be technically prescriptive or operational.

Exam trap

CISA often tests the policy vs. procedure vs. standard distinction; candidates pick 'define roles and responsibilities' because it sounds governance-oriented, but that is a supporting artifact, not the policy's primary purpose.

How to eliminate wrong answers

Option A is wrong because step-by-step implementation instructions belong in procedures, not the policy, which is deliberately high-level. Option B is wrong because technical configurations for security devices belong in standards, baselines, or hardening guides (e.g., CIS Benchmarks), not the policy. Option C is wrong because while roles and responsibilities may be referenced in a policy, defining them in detail is typically the role of supporting documents; the policy's primary purpose is to express management's direction and commitment, not to be an RACI chart.

908
MCQmedium

Which of the following is the MOST effective control to prevent unauthorized USB devices from connecting to corporate workstations?

A.Device control software that blocks non-approved USB devices.
B.User awareness training.
C.Physical security guards.
D.Encrypting all USB devices.
AnswerA

Device control software enforces an allow-list at the endpoint, blocking non-approved USB devices by class or serial before they mount. This directly satisfies the stem's prevention requirement, unlike policy or awareness measures that cannot technically stop a device connecting.

Why this answer

Device control software (e.g., endpoint DLP or USB whitelisting tools) operates at the OS kernel or driver level to enforce a hardware ID or vendor ID allowlist, blocking any USB device not explicitly approved. This is the only option that provides a preventive, automated, and continuous control against unauthorized USB connections, regardless of user behavior or physical access.

Exam trap

The trap here is that candidates often confuse encryption (which protects data confidentiality) with access control (which prevents connection), or overestimate the effectiveness of training and physical security against a technical bypass like USB autorun or BadUSB.

How to eliminate wrong answers

Option B is wrong because user awareness training is a detective/deterrent control that relies on human compliance and does not technically prevent a USB device from being recognized by the operating system. Option C is wrong because physical security guards control physical access to the facility but cannot prevent an insider from plugging an unauthorized USB device into a workstation already inside the perimeter. Option D is wrong because encrypting USB devices protects data at rest on the device but does nothing to prevent the device from being connected to a corporate workstation in the first place.

909
Multi-Selectmedium

An IS auditor is reviewing a business continuity plan (BCP). Which TWO of the following are key components of the business continuity strategy? (Select two.)

Select 2 answers
A.Incident management procedures
B.Data backup and recovery
C.Alternate facilities
D.Service desk procedures
E.Change management process
AnswersB, C

Data backup and recovery is a core continuity strategy component because it restores lost or corrupted data within the recovery point and recovery time objectives. Without verified backups, critical processes cannot resume after disruption, regardless of other arrangements.

Why this answer

Data backup and recovery (B) is a key component of the business continuity strategy because it defines how critical data and systems are restored to meet the recovery point objective (RPO) and recovery time objective (RTO) after a disruption. Alternate facilities (C) is also a key component because the strategy must specify the recovery site options—such as hot, warm, or cold sites, or reciprocal agreements—to resume operations when the primary facility is unavailable. Incident management procedures (A) are part of the incident response and operational response process, not the strategic BCP components themselves.

Service desk procedures (D) are operational support activities and do not constitute a continuity strategy element. Change management process (E) governs controlled modifications to the IT environment and is not a BCP strategy component.

Exam trap

CISA often tests the distinction between BCP components and IT operational processes—candidates may select incident management or change management because they are ITIL processes, but the exam requires identifying the strategic continuity elements like backup/recovery and alternate facilities.

910
Multi-Selectmedium

Which THREE of the following are acceptable methods for gathering audit evidence? (Select THREE.)

Select 3 answers
A.Accepting management's assertions without corroboration
B.Observation of processes being performed
C.Reperformance of control procedures
D.Inquiry of personnel
E.Obtaining hearsay from third parties
AnswersB, C, D

Observation involves watching personnel perform a process or control in real time, providing direct evidence that the procedure exists and is executed as described. It is an accepted evidence-gathering technique, though it only reflects performance at the moment of observation rather than the whole period.

Why this answer

Observation of processes being performed (B) is a valid evidence-gathering method because the auditor directly witnesses controls or procedures in operation, providing first-hand evidence of how activities are actually carried out. Reperformance of control procedures (C) is acceptable because the auditor independently executes the control or procedure and compares the result to the original, yielding highly reliable evidence of operating effectiveness. Inquiry of personnel (D) is an accepted method, as auditors routinely obtain written or oral information from knowledgeable staff, though it is typically corroborated with other evidence due to its lower reliability.

Accepting management's assertions without corroboration (A) is not acceptable because assertions alone are not sufficient, appropriate audit evidence and must be verified. Obtaining hearsay from third parties (E) is not acceptable because unverified second-hand information lacks the reliability and directness required for audit evidence.

Exam trap

The trap here is that candidates may mistakenly believe that inquiry alone (Option D) is insufficient, but inquiry is a valid evidence-gathering method when combined with other procedures, while accepting unsupported assertions (Option A) and hearsay (Option E) are never acceptable as primary evidence.

911
Multi-Selectmedium

An IS auditor is assessing the effectiveness of an organization's IT governance framework. Which TWO of the following are essential components that the auditor should verify are in place? (Choose two.)

Select 2 answers
A.A formal IT risk management process integrated with enterprise risk management
B.IT strategic planning aligned with business objectives
C.A centralized help desk with 24/7 support for all IT issues
D.Detailed technical training for all IT staff on emerging technologies
E.A policy requiring all software purchases to be approved by the CIO
AnswersA, B

IT risk management is critical for identifying, assessing, and mitigating risks that could impact business objectives. Integration with enterprise risk management ensures that IT risks are considered in the broader organizational context. The auditor should verify that risk assessments are performed regularly, risk appetite is defined, and mitigation strategies are implemented. This process helps the organization avoid surprises and ensures that IT governance is proactive rather than reactive, aligning with frameworks like COBIT and ISO 27001.

Why this answer

Effective IT governance requires alignment of IT strategy with business objectives and integration of IT risk management with enterprise risk management. These components ensure that IT delivers value, risks are managed, and resources are optimized. The auditor should verify that these elements are formally established, documented, and actively used.

Without them, governance is incomplete and may fail to meet organizational needs. Operational elements like training, help desks, and approval policies are not core governance components.

Exam trap

The trap here is equating operational IT practices, such as help desk support or software approval, with essential governance components, which focus on strategic alignment and risk oversight.

912
MCQmedium

An IS auditor is using analytical procedures during the planning phase. Which of the following is an example of an analytical procedure?

A.Comparing current-year expenses to prior-year expenses
B.Observing the inventory count
C.Inspecting authorization forms for signatures
D.Confirming account balances with third parties
AnswerA

Analytical procedures evaluate financial information through plausible relationships among data. Comparing current-year expenses against prior-year figures is a substantive analytical comparison that highlights unexpected fluctuations or trends, unlike inquiry, observation or inspection, which are tests of controls or detail.

Why this answer

Analytical procedures involve evaluating financial information by analyzing plausible relationships among data — comparing current-year expenses to prior-year expenses is a textbook example of such a comparison. It helps the auditor identify unusual fluctuations or trends that warrant further investigation during planning. This is distinct from tests of details and substantive procedures that involve direct evidence gathering.

Exam trap

CISA often tests whether candidates can distinguish analytical procedures (analysis of relationships/trends) from other evidence-gathering techniques like observation, inspection, and confirmation — the trap is picking a procedure that gathers direct evidence instead of one that analyzes financial relationships.

How to eliminate wrong answers

Option B is wrong because observing the inventory count is a physical observation procedure (a test of controls/substantive test), not an analytical procedure — it involves watching a process, not analyzing financial relationships. Option C is wrong because inspecting authorization forms for signatures is inspection of documentation, a test of details that verifies existence and approval, not an analytical comparison. Option D is wrong because confirming account balances with third parties is a confirmation procedure (external evidence gathering), which is a substantive test of details rather than an analytical procedure.

913
MCQhard

An IS auditor is assessing an organization's IT governance framework and finds that the IT balanced scorecard includes metrics such as system uptime, number of help desk tickets resolved, and average response time. The auditor notes that these are all internal IT operational metrics. The MOST significant concern is that:

A.The scorecard does not include financial metrics such as IT cost per employee or return on IT investment.
B.The metrics are too technical for the board to understand and may lead to misinterpretation.
C.The scorecard lacks metrics that measure the contribution of IT to business strategy and customer value.
D.The metrics are not benchmarked against industry standards, making them less useful for comparison.
AnswerC

A balanced scorecard should include metrics from multiple perspectives, including business contribution and customer orientation. Focusing solely on internal operational metrics like uptime and ticket resolution provides an incomplete view of IT performance. The most significant concern is that the scorecard does not measure how IT contributes to business strategy or delivers value to customers, which is essential for effective IT governance and alignment.

Why this answer

An IT balanced scorecard should provide a balanced view of IT performance across multiple perspectives, including business contribution, customer orientation, operational excellence, and future orientation. The scenario describes only internal operational metrics, which means the scorecard does not measure IT's contribution to business strategy or customer value. This imbalance is the most significant concern because it prevents the board and management from assessing whether IT is delivering strategic value.

Exam trap

The trap here is focusing on the technical nature or lack of benchmarking of the metrics rather than the fundamental imbalance in the scorecard's perspectives.

914
MCQeasy

An IS auditor is assessing physical security at a data center that houses the organization's core transaction processing systems. The auditor observes that the main entrance uses a badge reader, but the door to the server hall is propped open with a box while staff move equipment. Which of the following is the auditor's GREATEST concern?

A.The data center lacks a mantrap or interlocking double-door entry at the main entrance.
B.The server hall door being propped open allows unauthorized physical access to critical systems.
C.Equipment is being moved without a documented change management ticket.
D.The badge reader at the main entrance does not record access attempts for later review.
AnswerB

A propped door defeats the entire physical access control for the server hall, letting anyone in the vicinity reach the core transaction systems. Physical access often leads to direct compromise, theft, or destruction that logical controls cannot stop. This is the greatest concern because the exposure is immediate, affects the most critical assets, and nullifies the badge-based control design.

Why this answer

Physical access to core transaction systems is a foundational control, and a door propped open removes that barrier entirely, allowing anyone nearby to reach the servers. Because physical proximity enables direct compromise, theft, or sabotage that logical controls cannot prevent, this observation carries the greatest risk. Missing logs, undocumented moves, and the absence of a mantrap are lesser issues by comparison.

Exam trap

The trap here is ranking a missing enhancement or a logging gap above an active control failure, when the propped door represents an immediate, realized exposure of the most critical assets.

915
MCQmedium

An IS auditor is reviewing the logical access controls of a financial application. Which of the following is the BEST way to verify that user access rights are appropriate?

A.Interview the IT security manager about the access control process.
B.Review the access control list for each user.
C.Re-perform a sample of transactions to detect unauthorized access.
D.Compare the user access rights with the job descriptions and responsibilities.
AnswerD

Job descriptions define what access each role legitimately requires, so comparing granted rights against them tests whether access aligns with actual duties. This detects excessive or stale privileges, directly verifying appropriateness rather than merely confirming that controls exist.

Why this answer

Comparing user access rights directly against job descriptions and responsibilities is the most effective method to verify that access is appropriate based on the principle of least privilege. This approach ensures that each user's permissions align with their actual job functions, which is the core objective of a logical access control review. Interviewing or reviewing lists alone does not validate the appropriateness of access against business roles.

Exam trap

The trap here is that candidates often choose Option C (re-performing transactions) because it sounds like a direct test of control effectiveness, but it only detects unauthorized access after the fact and does not verify the appropriateness of the access rights themselves.

How to eliminate wrong answers

Option A is wrong because interviewing the IT security manager only provides a subjective, second-hand description of the process, not objective evidence that actual user access rights are appropriate. Option B is wrong because reviewing the access control list for each user shows what rights exist but does not compare them against any baseline (e.g., job roles) to determine if those rights are appropriate. Option C is wrong because re-performing a sample of transactions detects unauthorized access attempts but does not verify that the current access rights assigned to users are appropriate; it tests operational effectiveness, not the design of access provisioning.

916
MCQeasy

An organization is developing its IT strategy to align with the overall business strategy. The business strategy emphasizes rapid market expansion through digital products. Which of the following IT strategies would BEST support this business goal?

A.Standardize all IT systems to reduce complexity.
B.Adopt agile development methods and scalable cloud infrastructure.
C.Outsource all IT operations to a low-cost provider.
D.Minimize IT investment to preserve capital for business growth.
AnswerB

Agile methods enable rapid iterative delivery of digital products, while scalable cloud infrastructure absorbs unpredictable demand during market expansion. Together they satisfy the strategy's requirement for speed and elasticity, which traditional waterfall development and fixed on-premises capacity cannot match.

Why this answer

A business strategy focused on rapid market expansion through digital products requires IT to deliver quickly and scale elastically. Agile development methods enable fast iteration and responsiveness to market feedback, while scalable cloud infrastructure provides the elasticity to handle growth without heavy upfront capital investment. Together they directly enable speed and scale, which are the core requirements of the stated strategy.

Exam trap

CISA often tests whether candidates equate cost reduction with strategic alignment, so the trap is picking the low-cost outsourcing or standardization option when the business goal is speed and growth.

How to eliminate wrong answers

Option A is wrong because standardizing all IT systems reduces complexity but can slow innovation and does not directly enable rapid digital product expansion. Option C is wrong because outsourcing to a low-cost provider may reduce cost but does not inherently provide the agility or scalability needed for rapid market expansion. Option D is wrong because minimizing IT investment starves the digital product initiatives that the business strategy depends on.

917
MCQeasy

An IS auditor is preparing the audit report. According to ISACA standards, which of the following should be included in the final audit report?

A.Only the audit findings
B.Only the recommendations
C.Findings, recommendations, and management action plans
D.The audit program and procedures
AnswerC

ISACA standards require the final report to document findings, their risk implications, recommendations, and management's agreed action plans with target dates. Including all three elements ensures the report is complete, actionable, and supports follow-up of remediation.

Why this answer

According to ISACA's IT Audit Framework and the ISACA Code of Professional Ethics, the final audit report must include the audit findings, recommendations, and management's action plans. Findings describe the condition, criteria, cause, and effect; recommendations provide guidance for remediation; and management action plans document the agreed-upon corrective steps and timelines. This triad ensures the report is complete, actionable, and supports follow-up.

Exam trap

CISA often tests the misconception that the audit report should only include findings or recommendations, or that the audit program is part of the report, when in fact ISACA standards require the triad of findings, recommendations, and management action plans.

How to eliminate wrong answers

Option A is wrong because findings alone lack the necessary recommendations and management commitments for remediation. Option B is wrong because recommendations without findings lack context and evidence, and without management action plans there is no accountability. Option D is wrong because the audit program and procedures are internal working documents that detail the audit methodology; they are not part of the final report to management and the board.

918
MCQmedium

A company is considering restructuring its IT department from a centralized to a decentralized model to give business units more autonomy. What is a PRIMARY governance risk associated with this move?

A.Difficulty in managing vendor contracts due to decentralization.
B.Reduced innovation due to lack of central coordination.
C.Increased risk of project cost overruns.
D.Inconsistent IT policies and security controls across business units.
AnswerD

Decentralisation pushes policy and control decisions to individual business units, which then apply differing standards. The stem's autonomy constraint means no single authority enforces uniform configuration, so inconsistent IT policies and security controls across business units become the primary governance risk.

Why this answer

Decentralizing IT gives business units autonomy, but the primary governance risk is that each unit may adopt its own policies, standards, and security controls. This fragmentation leads to inconsistent security postures, compliance gaps, and difficulty enforcing enterprise-wide governance. The core risk is loss of centralized control over policy and security consistency.

Exam trap

CISA often tests whether candidates confuse operational risks (cost overruns, vendor management) with governance risks (policy and control consistency), so the trap is picking a cost-related option.

How to eliminate wrong answers

Option A is wrong because vendor contract management can be centralized even in a decentralized IT model, and it is not the primary governance risk. Option B is wrong because decentralization typically increases innovation at the business unit level, not reduces it. Option C is wrong because project cost overruns can occur in any model and are a project management risk, not the primary governance risk of decentralization.

919
MCQmedium

An organization has experienced several security incidents due to unauthorized changes to production systems. Which governance mechanism should be strengthened?

A.IT asset management
B.Configuration management database
C.Incident response plan
D.Change management process
AnswerD

Unauthorised changes to production systems indicate that changes are not being requested, assessed, approved and tracked before implementation. Strengthening change management enforces authorisation, testing and rollback controls, directly preventing the uncontrolled modifications that caused the incidents.

Why this answer

Unauthorized changes to production systems indicate a failure in the change management process, which is designed to control and authorize modifications. Strengthening change management ensures that all changes are reviewed, approved, and documented, reducing the risk of unauthorized alterations. The other mechanisms address asset inventory, configuration data, or incident response, but do not directly prevent unauthorized changes.

Exam trap

CISA often tests the confusion between change management and configuration management; candidates must remember that change management controls modifications, while configuration management tracks the state of assets.

How to eliminate wrong answers

Option A is wrong because IT asset management focuses on tracking hardware and software assets, not on controlling changes to them. Option B is wrong because a configuration management database (CMDB) records configuration items and relationships but does not enforce change approval. Option C is wrong because an incident response plan deals with reacting to incidents, not preventing unauthorized changes.

920
MCQeasy

An IT steering committee is reviewing a proposal for a new customer relationship management (CRM) system. Which of the following BEST demonstrates that the proposal aligns with the organization's strategic goals?

A.The business case includes a clear link to the organization's five-year strategic plan.
B.The project manager has extensive experience with CRM implementations.
C.The proposed system includes advanced analytics capabilities.
D.The vendor offers discounted licensing for the first year.
AnswerA

A business case explicitly linking the CRM proposal to the five-year strategic plan demonstrates traceable alignment with stated organisational objectives. This direct mapping gives the steering committee the clearest evidence that the investment supports long-term goals rather than isolated departmental needs.

Why this answer

The business case including a clear link to the organization's five-year strategic plan directly demonstrates alignment with strategic goals. This shows that the CRM proposal is not just a tactical IT purchase but is explicitly tied to the long-term objectives of the organization, which is the best evidence of strategic alignment.

Exam trap

CISA often tests the difference between tactical benefits (features, cost savings) and strategic alignment, where candidates may be distracted by attractive features or cost reductions.

How to eliminate wrong answers

Option B is wrong because the project manager's experience, while valuable, does not demonstrate that the CRM system aligns with strategic goals; it only speaks to execution capability. Option C is wrong because advanced analytics capabilities are a feature, not evidence of strategic alignment; the system could have advanced analytics but still not support the organization's strategy. Option D is wrong because discounted licensing is a financial incentive, not a strategic alignment factor; it may reduce cost but does not show how the system supports strategic objectives.

921
Multi-Selectmedium

An IS auditor is evaluating the network segmentation of a manufacturing company that separates its corporate network from the industrial control system (ICS) environment. The auditor finds that a firewall exists between the zones, but engineering workstations on the corporate network can reach programmable logic controllers directly over several open ports. Which TWO of the following findings should the auditor report as the MOST significant weaknesses? (Choose two.)

Select 2 answers
A.Multiple ports are open through the firewall between the corporate and ICS zones, expanding the attack surface.
B.Engineering workstations are not running the same endpoint protection version as corporate desktops.
C.The firewall between the corporate and ICS zones does not perform deep packet inspection of industrial protocols.
D.The ICS network uses the same directory services as the corporate network for authentication.
E.Direct connectivity from corporate workstations to programmable logic controllers bypasses the intended zone separation.
AnswersA, E

Each permitted port represents an allowed path into the control environment, and unnecessary open ports give an attacker additional footholds and lateral-movement options. A firewall that passes many services to programmable logic controllers is effectively a porous boundary rather than a controlled one. The auditor should report the excessive rule set and recommend restricting traffic to only the specific protocols and hosts genuinely required for operations.

Why this answer

Effective segmentation depends on preventing corporate systems from initiating sessions with control devices and on keeping the boundary rule set as narrow as operations allow. Direct reachability from engineering workstations to programmable logic controllers defeats the zone design, and a broad set of open ports gives attackers multiple paths into the ICS environment. Together these findings show that the firewall exists in name only and does not enforce the intended separation.

Exam trap

The trap here is chasing secondary hardening items such as protocol inspection or antivirus versions while missing that the boundary itself is functionally bypassed by direct connectivity and permissive rules.

922
MCQhard

An IT auditor is reviewing the business continuity plan (BCP) for a financial services firm. The plan includes a hot site that is shared with another organization under a reciprocal agreement. Which of the following findings should be of MOST concern to the auditor?

A.The hot site uses a different internet service provider than the primary site
B.The hot site has not been tested in the past 12 months
C.The reciprocal agreement does not guarantee exclusive use of the hot site during a disaster
D.The hot site is located in the same seismic zone as the primary site
AnswerC

Reciprocal agreements offer no contractual guarantee of priority access; both parties may invoke the site simultaneously, leaving the firm without recovery capacity. This unenforceable exclusivity is the most serious finding, since the hot site may be unavailable when needed.

Why this answer

A reciprocal agreement for a shared hot site does not guarantee exclusive access during a disaster. If both organizations declare a disaster simultaneously, the site may become oversubscribed, leading to resource contention and potential failure of the BCP. This directly undermines the recovery capability, making it the most critical finding.

Exam trap

The trap here is that candidates may focus on technical details like ISP diversity or testing frequency, but the core BCP principle is that a shared resource without guaranteed exclusive access is a fundamental design flaw that can render the entire plan ineffective during a concurrent disaster.

How to eliminate wrong answers

Option A is wrong because using a different ISP for the hot site is actually a best practice to avoid single points of failure and is not a concern. Option B is wrong because while annual testing is recommended, the lack of a test in 12 months is a finding but not as critical as the lack of guaranteed exclusive access; the plan could still be viable with more frequent testing scheduled. Option D is wrong because being in the same seismic zone is a risk, but it is less immediate than the operational risk of resource contention; many organizations accept this risk with geographic separation within the same region.

923
MCQhard

An organization is implementing a COTS application. The project team plans to heavily customize the application to meet unique business processes. Which of the following is the most significant risk?

A.Vendor lock-in
B.Incompatibility with future releases
C.Difficulties in applying future vendor upgrades
D.High implementation cost
AnswerC

Heavy customisation modifies vendor-supplied code and data structures, so future vendor upgrades and patches may conflict with or overwrite those changes. This creates significant rework and regression risk each time the vendor releases a new version, making upgrade difficulties the primary risk of the COTS implementation.

Why this answer

Heavy customization of a COTS application modifies its core code or configuration in ways that diverge from the vendor's standard product. When the vendor releases updates or patches, these customizations often conflict with the new code, making upgrades complex, risky, or even impossible without rework. This directly threatens the organization's ability to stay current with security fixes and new features, which is a critical operational and compliance risk.

Thus, difficulties in applying future vendor upgrades is the most significant risk.

Exam trap

CISA often tests the distinction between customization risks and general implementation risks; candidates may choose vendor lock-in or high cost because they sound plausible, but the most significant risk from heavy customization is the difficulty of applying future vendor upgrades, which directly impacts maintainability and security.

How to eliminate wrong answers

Option A is wrong because vendor lock-in is a risk when an organization becomes dependent on a vendor's proprietary technology, but it is not the most immediate or significant risk when heavy customization is involved; lock-in can occur even with minimal customization. Option B is wrong because incompatibility with future releases is a subset of the upgrade difficulty risk; it is not as comprehensive as the challenge of applying upgrades, which includes compatibility, testing, and rework. Option D is wrong because high implementation cost is a financial concern that may be planned for and is typically a one-time expense, whereas upgrade difficulties can lead to ongoing increased costs, security vulnerabilities, and business disruption.

924
MCQhard

An IS auditor is evaluating the patch management process. The auditor notes that critical security patches are applied within 30 days, but the policy requires 7 days. The IT manager states that the delay is due to testing requirements. What should the auditor recommend?

A.Implement a risk-based patching process that allows faster deployment for critical patches
B.Require automated patching without testing
C.Accept the current practice as a compensating control
D.Modify the policy to align with the actual patching timeline
AnswerA

A risk-based process lets critical patches be deployed faster than the current 30-day cycle while retaining testing for lower-risk updates, closing the gap against the 7-day policy requirement. It directly resolves the conflict between the IT manager's testing constraint and the mandated remediation timeline.

Why this answer

A risk-based patching process prioritizes critical patches for immediate deployment while allowing less critical patches to undergo standard testing. This balances security needs with operational stability, addressing the policy violation without sacrificing testing entirely. The auditor should recommend this approach because it aligns with industry best practices (e.g., NIST, ISO 27001) and enables faster remediation of high-risk vulnerabilities.

Exam trap

CISA often tests the confusion between policy compliance and risk management; candidates may choose to modify the policy or accept the delay, but the correct answer is to recommend a risk-based approach that satisfies both security and operational needs.

How to eliminate wrong answers

Option B is wrong because automated patching without testing can introduce instability and outages, especially in complex environments. Option C is wrong because accepting the current practice as a compensating control does not address the policy violation; a compensating control must provide equivalent risk mitigation, which a 30-day delay does not. Option D is wrong because modifying the policy to match the actual timeline weakens security governance and does not address the root cause of the delay.

925
Multi-Selectmedium

Which TWO of the following are considered essential components of an information security policy framework? (Choose two.)

Select 2 answers
A.Data classification policy
B.Business continuity plan
C.Incident response plan
D.Network architecture diagram
E.Acceptable use policy
AnswersA, E

A data classification policy is essential because it defines how information is categorised by sensitivity, driving the protective controls, handling rules and access decisions applied throughout the framework. Without it, controls cannot be consistently proportionate to data value, leaving the framework without a foundation for risk-based safeguarding.

Why this answer

A data classification policy (A) is an essential component of an information security policy framework because it defines how data is categorized by sensitivity and criticality, which drives the selection of appropriate security controls, handling procedures, and access restrictions. An acceptable use policy (E) is likewise essential, as it establishes the rules for how employees may use organizational IT assets, networks, and data, setting clear expectations and accountability. Together, these two policies form foundational governance documents that shape user behavior and data protection requirements.

The business continuity plan (B) and incident response plan (C) are important operational documents, but they are typically treated as supporting plans that implement or respond to policy rather than as core policy framework components. A network architecture diagram (D) is a technical artifact that documents infrastructure, not a policy statement, so it does not belong in the policy framework.

Exam trap

ISACA often tests the distinction between policies (high-level rules) and operational plans or technical artifacts, so candidates mistakenly select BCP or incident response plans as policy components because they are security-related, but they are not part of the policy framework itself.

926
MCQmedium

An organization is adopting a decentralized IT structure to better meet the needs of its business units. Which of the following is a potential risk of this approach?

A.Increased duplication of IT resources and inconsistent standards
B.Slower response to business unit needs
C.Higher initial setup costs for central services
D.Reduced alignment with corporate strategy
AnswerA

Decentralised IT lets each business unit procure and configure independently, so overlapping systems and divergent configurations emerge across units. This directly satisfies the stem's risk: duplicated IT resources alongside inconsistent standards, raising cost and complicating governance, integration and security enforcement.

Why this answer

Decentralized IT structures push decision-making authority and resources down to individual business units, which naturally leads to each unit acquiring its own hardware, software, and support staff. This fragmentation creates redundant systems and divergent technical standards across the organization, increasing cost and complexity. The correct answer captures this classic trade-off: while decentralization improves responsiveness, it sacrifices economies of scale and standardization.

Exam trap

CISA often tests the trade-off between centralization and decentralization, and candidates frequently confuse the risks of one with the benefits of the other—picking 'slower response' as a risk of decentralization when it is actually a risk of centralization.

How to eliminate wrong answers

Option B is wrong because slower response to business unit needs is a risk of centralized IT, not decentralized IT—decentralization is specifically adopted to speed up responsiveness. Option C is wrong because higher initial setup costs for central services is a risk of centralization (building shared infrastructure), whereas decentralization typically shifts costs to business units and may reduce central setup costs. Option D is wrong because reduced alignment with corporate strategy is a broader governance risk that can occur in both models, but it is not the primary, direct operational risk of decentralization; the most immediate and well-documented risk is duplication and inconsistent standards.

927
MCQmedium

An IT auditor is reviewing the change management process for a financial institution. The auditor finds that emergency changes are frequently approved by the change manager without CAB review. Which risk is most associated with this practice?

A.Increase in unauthorized changes
B.Excessive documentation overhead
C.Delayed incident resolution
D.Inadequate backup procedures
AnswerA

Bypassing CAB review removes independent oversight, so the change manager alone authorises emergency changes. That concentrates approval authority in one person, enabling changes to be implemented without detection or challenge — directly increasing the risk of unauthorised changes, the specific risk the stem's missing segregation of duties creates.

Why this answer

Emergency changes approved without CAB review bypass the normal oversight and segregation of duties, increasing the risk that unauthorized or malicious changes are introduced. The change manager alone may not have the authority or expertise to assess all risks, leading to potential fraud, errors, or security breaches. This is a classic control weakness in change management.

Exam trap

CISA often tests the difference between a risk and an inefficiency; candidates may choose 'delayed incident resolution' because they think bypassing CAB speeds things up, but the question asks for the risk of bypassing, which is unauthorized changes.

How to eliminate wrong answers

Option B is wrong because excessive documentation overhead is not a risk but a potential inefficiency; the question asks for the risk associated with bypassing CAB. Option C is wrong because delayed incident resolution is not directly caused by bypassing CAB; in fact, bypassing CAB may speed up resolution. Option D is wrong because inadequate backup procedures are unrelated to the change approval process.

928
MCQhard

A company plans to implement a commercial off-the-shelf (COTS) application and requires significant customization to match its unique business processes. The vendor advises against extensive customization because it may complicate future upgrades. What is the BEST course of action?

A.Use the vendor's customization module to minimize upgrade risks
B.Customize but maintain detailed documentation for upgrade impact analysis
C.Proceed with extensive customization to meet business needs
D.Avoid customization and re-engineer business processes to match the COTS application
AnswerD

Re-engineering business processes to align with the COTS application preserves the vendor's upgrade path, since unsupported modifications typically break patching and future releases. This satisfies the stem's constraint that extensive customization complicates upgrades, accepting process change as the trade-off for maintainability and vendor support.

Why this answer

The best course of action is to avoid customization and re-engineer business processes to match the COTS application. This approach preserves the integrity of the vendor's standard codebase, ensuring that future upgrades and patches can be applied with minimal friction. Extensive customization creates a fork from the vendor's baseline, leading to costly regression testing, potential security gaps, and upgrade incompatibilities that undermine the long-term value of the COTS investment.

Exam trap

The trap here is that candidates often choose 'customize but document' (Option B) because it sounds like a balanced, pragmatic approach, but the CISA exam emphasizes that any customization that deviates from the vendor's standard configuration introduces unacceptable upgrade and maintenance risks, making process re-engineering the only truly sustainable choice.

How to eliminate wrong answers

Option A is wrong because using a vendor's customization module does not eliminate upgrade risks; it only provides a structured way to apply customizations, but those customizations still create dependencies on specific API versions or hooks that can break during major version upgrades. Option B is wrong because maintaining detailed documentation for upgrade impact analysis is a mitigation tactic, not a solution—it does not prevent the underlying technical debt, code conflicts, or the need for extensive rework when the vendor releases a new version. Option C is wrong because proceeding with extensive customization directly contradicts the vendor's guidance and industry best practices, leading to a 'customized fork' that makes future upgrades prohibitively expensive or impossible without re-implementing all custom logic.

929
MCQeasy

A financial institution is deploying a data loss prevention (DLP) solution. Which of the following is the MOST important prerequisite to ensure the DLP can effectively detect sensitive data?

A.Configuring incident response procedures
B.Installing endpoint agents on all devices
C.Implementing network segmentation
D.Performing a data classification exercise
AnswerD

Data classification assigns sensitivity labels that DLP engines match against, defining what counts as sensitive before inspection rules can act. Without it, pattern matching alone produces false positives and misses regulated data. This satisfies the stem's prerequisite constraint: detection depends on knowing which data requires protection, not merely deploying tooling.

Why this answer

A DLP solution detects sensitive data by matching content against predefined patterns or rules. Without a data classification exercise, the organization cannot define what constitutes 'sensitive data' (e.g., PII, PCI, IP), making the DLP blind to what it should monitor. Classification provides the taxonomy and metadata (e.g., labels, tags) that the DLP engine uses to trigger alerts or blocks, ensuring detection is both accurate and aligned with policy.

Exam trap

ISACA often tests the misconception that deploying agents or configuring network controls is the first step, but the trap here is that technical controls are useless without first defining what data is sensitive through classification.

How to eliminate wrong answers

Option A is wrong because incident response procedures are reactive steps taken after a DLP alert is generated, not a prerequisite for detection itself; configuring them before classification would leave the DLP without a detection baseline. Option B is wrong because endpoint agents are a deployment method for DLP, but without knowing what data is sensitive, agents cannot be configured to scan for the correct content or patterns. Option C is wrong because network segmentation controls data flow between zones but does not define what data is sensitive; a DLP can still fail to detect sensitive data crossing segments if it lacks classification rules.

930
MCQhard

An IT auditor is evaluating the capacity management process. Which of the following findings would be of MOST concern?

A.Alert thresholds are set at 80% utilization
B.Resource utilization trends are not monitored
C.Capacity thresholds are reviewed annually
D.Capacity reports are generated monthly
AnswerB

Without utilisation trend monitoring, capacity planning becomes reactive, so degradation and exhaustion are detected only after service impact. This directly violates the capacity management process's core requirement to anticipate future resource needs, making it the most concerning finding because it removes the early-warning mechanism on which every other capacity control depends.

Why this answer

The core purpose of capacity management is to ensure that IT resources are sized and timed to meet current and future demand in a cost-effective manner. This is impossible without monitoring resource utilization trends, because trends are the predictive input that drives forecasting, threshold tuning, and procurement decisions. If trends are not monitored, the organization is reactive rather than proactive and will suffer either performance degradation or wasteful over-provisioning.

Therefore, the absence of trend monitoring is the most significant control gap among the findings.

Exam trap

CISA often tests the difference between a genuine control gap and a merely suboptimal configuration, so candidates wrongly flag reasonable settings like 80% thresholds or annual reviews instead of the fundamental absence of trend monitoring.

How to eliminate wrong answers

Option A is wrong because an 80% utilization alert threshold is a reasonable, commonly recommended early-warning level that leaves headroom before saturation, so it is not a deficiency. Option C is wrong because reviewing capacity thresholds annually is a normal governance cadence and, while more frequent review may be desirable in fast-changing environments, it is not inherently a serious control failure. Option D is wrong because generating capacity reports monthly is a standard and adequate reporting frequency for most organizations, so it does not represent a material weakness.

931
Multi-Selecthard

An organization is implementing a change management process based on ITIL. Which THREE change types should be included in the policy?

Select 3 answers
A.Planned change – scheduled during maintenance windows with no approval needed.
B.Emergency change – requires immediate implementation to resolve a major incident.
C.Standard change – pre-approved, low risk, follows a defined procedure.
D.Major change – requires executive approval and a separate risk assessment.
E.Normal change – requires approval from the Change Advisory Board (CAB).
AnswersB, C, E

Emergency changes address major incidents requiring immediate implementation, bypassing the normal CAB cycle to restore service quickly. Including this type satisfies the stem's constraint by defining a controlled fast-track path with retrospective review, so urgent fixes are not made outside the process.

Why this answer

Option B is correct because ITIL defines an emergency change as one that must be implemented immediately, typically to resolve a major incident or restore a critical service, and it follows an expedited approval path (e.g., Emergency CAB). Option C is correct because a standard change is a pre-authorized, low-risk, routine change with a documented procedure, so it does not require individual CAB review each time. Option E is correct because a normal change is the standard ITIL category that must be assessed and approved by the Change Advisory Board (CAB) before implementation.

Option A is incorrect because planned changes are not a distinct ITIL change type and, more importantly, scheduled changes still require appropriate authorization rather than 'no approval needed.' Option D is incorrect because 'major change' is not one of the three ITIL change types; major changes are handled as normal or emergency changes with escalated approval and risk assessment.

Exam trap

The trap here is that candidates confuse 'Planned change' (a scheduling concept) with a formal ITIL change type, leading them to select Option A, but ITIL only recognizes Standard, Emergency, and Normal changes.

932
MCQhard

A company's availability monitoring shows that a critical application has an average MTBF of 720 hours and an average MTTR of 4 hours. What is the availability percentage?

A.99.72%
B.99.17%
C.99.95%
D.99.45%
AnswerD

Availability equals MTBF divided by the sum of MTBF and MTTR: 720 ÷ (720 + 4) = 720 ÷ 724 = 0.99447, which rounds to 99.45%. This satisfies the stem's requirement to convert the given reliability and repair figures into an availability percentage.

Why this answer

Availability = MTBF / (MTBF + MTTR) = 720 / (720 + 4) = 720 / 724 ≈ 0.994475, or 99.45%.

933
Multi-Selectmedium

Which TWO of the following are key benefits of using a system development life cycle (SDLC) methodology? (Select exactly two.)

Select 2 answers
A.It provides a structured approach to system development
B.It ensures user requirements are captured and validated
C.It prevents any scope changes during development
D.It eliminates the need for security testing
E.It reduces the overall cost of development
AnswersA, B

A structured approach directly satisfies the need for control and repeatability across development phases. By defining discrete stages — requirements, design, build, test, deploy — SDLC enforces consistent governance, review gates and documentation, reducing ad hoc decisions and unmanaged scope creep that undermine auditability and security assurance.

Why this answer

Option A is correct because an SDLC methodology provides a structured, phased approach (such as requirements, design, development, testing, and deployment) that organizes and governs how a system is built, giving repeatability and control over the process. Option B is correct because SDLC methodologies explicitly include requirements-gathering and validation phases, ensuring user and stakeholder requirements are captured, documented, and confirmed before and during development. Option C is incorrect because SDLC methodologies do not prevent scope changes; they provide change-control mechanisms to manage scope changes, which can and do still occur.

Option D is incorrect because security testing remains necessary and is typically integrated into SDLC phases (e.g., during testing or via secure development practices), not eliminated. Option E is incorrect because while an SDLC can improve efficiency and reduce rework costs, it does not guarantee a reduction in overall development cost, so this is not a key guaranteed benefit.

934
MCQmedium

An IS auditor is reviewing the deployment pipeline for an organization's e-commerce platform. The pipeline automatically deploys every code commit that passes automated unit tests to production without manual approval. The organization argues this accelerates feature delivery. Which of the following is the auditor's GREATEST concern with this approach?

A.Automated unit tests may not cover all business logic and integration scenarios, allowing defective changes to reach production.
B.Automated deployments increase the cost of infrastructure because they require additional testing environments.
C.Developers may not have the authority to approve their own changes, creating a segregation-of-duties conflict.
D.The pipeline may not maintain an audit trail of who approved each deployment, violating regulatory requirements.
AnswerA

Unit tests typically validate isolated code components and often miss integration, configuration, and business-process exceptions. In a fully automated deployment without a manual gate, a defect that passes unit tests could reach production and disrupt revenue-generating transactions. This is the greatest risk because it directly affects availability and integrity of the e-commerce platform.

Why this answer

The correct answer is the one highlighting that automated unit tests may not cover all business logic and integration scenarios, allowing defective changes to reach production. In a continuous deployment model, the absence of a manual approval gate shifts the burden of quality assurance entirely to automated tests. If those tests are insufficient, the organization faces significant operational and financial risk.

Exam trap

The trap here is assuming that automated testing is always sufficient and that the only risk is segregation of duties, when in fact the primary concern is the completeness of test coverage.

Page 12

Page 13 of 13