Courseiva

Certified Information Systems Auditor CISA (CISA) — Questions 76–150

934 questions total · 13pages · All types, answers revealed

Page 1

Page 2 of 13

Page 3
76
MCQeasy

Based on the exhibit, what is the security risk of this bucket policy?

A.The bucket is publicly readable
B.The bucket allows public write access
C.The bucket policy restricts access to a specific IAM role
D.The bucket policy is not encrypted
AnswerA

Principal: * allows anonymous access.

Why this answer

The bucket policy grants public read access by setting `"Principal": "*"` and `"Effect": "Allow"` with `"Action": "s3:GetObject"`. This means any unauthenticated user on the internet can list and retrieve objects in the bucket, making it publicly readable. The policy does not require any authentication or authorization checks, which is a common misconfiguration leading to data exposure.

Exam trap

ISACA often tests the distinction between read and write permissions in bucket policies, and the trap here is that candidates see `"Principal": "*"` and assume it means full public access (both read and write), but the specific `Action` determines the actual risk—only read access is granted in this case.

How to eliminate wrong answers

Option B is wrong because the policy only allows `s3:GetObject` (read) actions, not `s3:PutObject` or `s3:DeleteObject` (write) actions, so public write access is not granted. Option C is wrong because the policy sets `"Principal": "*"`, which applies to all principals, not restricting access to a specific IAM role; a restricted policy would specify an ARN like `"AWS": "arn:aws:iam::123456789012:role/MyRole"`. Option D is wrong because S3 bucket policies are not individually encrypted; they are stored as JSON documents within AWS IAM and are protected by AWS's infrastructure encryption at rest, and the question asks about a security risk, not a missing encryption feature that does not exist for policies.

77
MCQeasy

An IS auditor is evaluating the effectiveness of an organization's business continuity plan (BCP). Which of the following findings would be of GREATEST concern?

A.The backup tapes are stored in a locked cabinet in the server room
B.The BCP contact list has not been updated in six months
C.The BCP has not been tested in over two years
D.The BCP relies on manual workarounds for critical systems
AnswerC

An untested BCP leaves recovery capability unproven; plan validity, resource adequacy and RTO achievability remain assumptions. Over two years without exercising means environmental, personnel and system changes have invalidated assumptions, so the auditor cannot provide assurance that operations would resume within agreed timeframes during a real disruption.

Why this answer

The BCP has not been tested in over two years is the greatest concern because testing is the only way to validate that the plan works under real-world conditions. Without recent testing, the organization cannot be confident that recovery time objectives (RTOs) and recovery point objectives (RPOs) are achievable, and any gaps or assumptions in the plan remain undiscovered. ISACA standards recommend testing at least annually, and a two-year gap significantly increases the risk of plan failure during an actual disaster.

Exam trap

The trap here is that candidates often focus on obvious physical security or documentation issues (like tape storage or outdated contact lists) and underestimate that the absence of testing renders all other BCP components unvalidated, making it the most critical finding from an audit perspective.

How to eliminate wrong answers

Option A is wrong because storing backup tapes in a locked cabinet in the server room, while not ideal (they should be offsite for geographic redundancy), is a physical security control that does not directly invalidate the BCP's effectiveness; the greater risk is the lack of testing. Option B is wrong because a BCP contact list that has not been updated in six months is a maintenance issue, but it can be corrected quickly and does not indicate that the plan itself is unworkable; the lack of testing is a more fundamental flaw. Option D is wrong because relying on manual workarounds for critical systems is a design choice that may be acceptable if the manual procedures are documented, trained, and tested; the absence of testing is what makes this reliance dangerous.

78
MCQeasy

An organization wants to ensure that IT performance is measured against strategic goals. Which tool is BEST suited?

A.Balanced scorecard
B.Pareto chart
C.SWOT analysis
D.Gantt chart
AnswerA

The balanced scorecard translates strategic objectives into measurable perspectives — financial, customer, internal process, and learning and growth — and cascades them into IT metrics. This directly links IT performance measurement to strategic goals, which financial or operational metrics alone cannot achieve.

Why this answer

A balanced scorecard measures organizational performance across four perspectives — financial, customer, internal business processes, and learning and growth — and explicitly links operational metrics to strategic objectives. This makes it the best tool for ensuring IT performance is measured against strategic goals, since it translates strategy into measurable KPIs.

Exam trap

CISA often tests the difference between strategic alignment tools and general quality/planning tools — candidates pick SWOT because it sounds strategic, but SWOT assesses position, not performance against goals.

How to eliminate wrong answers

Option B is wrong because a Pareto chart is a quality tool that prioritizes problems by frequency (the 80/20 rule); it does not link performance to strategy. Option C is wrong because SWOT analysis is a strategic planning technique for assessing internal and external factors, not a performance measurement framework. Option D is wrong because a Gantt chart is a project scheduling tool showing tasks over time, not a strategic performance measurement system.

79
MCQmedium

An IT auditor is reviewing the change management process for a financial application. The auditor finds that emergency changes are frequently implemented without post-implementation review. What is the MOST significant risk?

A.The change may not be documented properly
B.The change may cause an outage during the next backup cycle
C.Security vulnerabilities may be introduced and remain undetected
D.Users may not be notified of the change
AnswerC

Without post-implementation review, emergency changes bypass verification, so malicious or accidental code and misconfigurations can enter production and persist unnoticed. This exposes the financial application to exploitable vulnerabilities that normal change controls would otherwise catch.

Why this answer

Emergency changes bypass the normal change management controls, including post-implementation review. Without a post-implementation review, any security vulnerabilities introduced by the change (e.g., misconfigurations, unpatched code, or weakened access controls) will not be identified and remediated. In a financial application, this can lead to data breaches, fraud, or regulatory non-compliance.

Thus, the most significant risk is that security vulnerabilities remain undetected.

Exam trap

CISA often tests the distinction between operational risks (e.g., outages, documentation) and security risks, expecting candidates to prioritize the risk with the most severe impact on confidentiality, integrity, and availability of financial data.

How to eliminate wrong answers

Option A is wrong because while documentation is important, it is a secondary control issue; the lack of documentation itself does not directly cause harm, whereas undetected vulnerabilities can lead to immediate security incidents. Option B is wrong because an outage during backup is a speculative operational risk and not the primary concern of change management; post-implementation review focuses on verifying the change's correctness and security, not backup timing. Option D is wrong because user notification is a procedural step, but failure to notify users does not inherently introduce security risks or system failures; it is a communication issue, not a control weakness with severe consequences.

80
MCQhard

An organization's IT governance committee is reviewing a proposal to use a public cloud provider that does not meet the organization's data encryption standards. The board has set a low risk appetite for data privacy. What is the BEST action?

A.Accept the proposal with additional monitoring
B.Delegate the decision to the security team
C.Accept the proposal but require the provider to sign a waiver
D.Reject the proposal until encryption requirements are met
AnswerD

Rejecting the proposal directly enforces the board's low risk appetite for data privacy, since the provider's encryption controls fall short of the organisation's mandated standards. Accepting residual privacy risk would exceed that appetite. Governance committees must align procurement decisions with stated risk tolerance rather than accept unmitigated control gaps.

Why this answer

The board has set a low risk appetite for data privacy, meaning the organization is willing to accept only minimal risk in this area. A cloud provider that does not meet the organization's data encryption standards introduces a risk that exceeds this appetite. Therefore, the proposal must be rejected until the provider can comply with the encryption requirements.

This aligns with governance principles where risk decisions must be made in accordance with the organization's risk appetite.

Exam trap

CISA often tests the misconception that additional monitoring or waivers can compensate for a control gap when the risk appetite is low, but the correct answer is to reject non-compliant proposals outright.

How to eliminate wrong answers

Option A is wrong because accepting the proposal with additional monitoring does not mitigate the risk to an acceptable level given the low risk appetite; monitoring is a detective control, not a preventive one, and the encryption gap remains. Option B is wrong because delegating the decision to the security team abdicates the governance committee's responsibility to align decisions with the board's risk appetite; the security team may not have the authority to accept risks on behalf of the board. Option C is wrong because a waiver signed by the provider does not reduce the risk; it merely acknowledges it, and the organization would still be accepting a risk that exceeds its stated appetite.

81
Multi-Selecthard

An IS auditor is reviewing an organization's implementation of a security information and event management (SIEM) system. The auditor wants to assess whether the SIEM is effectively supporting incident detection and response. Which TWO of the following are the MOST important factors for the auditor to evaluate? (Choose two.)

Select 2 answers
A.The completeness of log sources and the timeliness of log ingestion from critical systems.
B.The brand reputation of the SIEM vendor and the number of industry awards it has received.
C.The physical security of the SIEM server room and the biometric access controls at the data center.
D.The process for tuning correlation rules and the procedures for investigating and escalating alerts.
E.The total storage capacity of the SIEM and the compression ratio of archived logs.
AnswersA, D

A SIEM's detection capability depends on the breadth and timeliness of the data it ingests. If critical systems such as firewalls, domain controllers, and databases are not forwarding logs, or if ingestion is delayed, the SIEM cannot correlate events or alert on emerging threats in real time. Evaluating log source coverage and ingestion latency is therefore fundamental to assessing whether the SIEM can effectively support incident detection.

Why this answer

The effectiveness of a SIEM for incident detection and response hinges on two operational pillars: comprehensive, timely log ingestion from critical systems, and well-tuned correlation rules supported by defined investigation and escalation procedures. Without complete and timely data, detection is blind; without tuning and response processes, alerts are noise. Storage capacity, vendor reputation, and physical security are secondary considerations for this specific audit objective.

Exam trap

The trap here is focusing on technical specifications such as storage or vendor reputation instead of the operational factors that determine whether the SIEM actually detects and enables response to incidents.

82
MCQhard

An auditor finds that access reviews have not been completed for two quarters. What is the MOST significant risk?

A.Data integrity may be compromised
B.Unauthorized access may be granted and persist
C.System performance may degrade
D.Audit findings may be reported to management
AnswerB

Missed quarterly reviews mean accumulated entitlement drift goes undetected, so accounts retain access after role changes or termination. The stem's two-quarter gap directly enables unauthorised access to be granted and to persist unchallenged, which is the most significant consequence.

Why this answer

The most significant risk of missed access reviews is that unauthorized or excessive access rights remain in place undetected, allowing users to retain privileges they should no longer have (e.g., after role changes or terminations). This directly enables insider threats and privilege creep, which is the core control objective of periodic access reviews.

Exam trap

CISA often tests the difference between the risk itself (unauthorized access persisting) and the consequence (audit findings) — candidates pick the reporting outcome instead of the underlying security exposure.

How to eliminate wrong answers

Option A is wrong because data integrity is a broader concern affected by many controls; missed access reviews primarily affect authorization, not integrity directly. Option C is wrong because system performance is unrelated to access review cadence. Option D is wrong because audit findings being reported is a consequence of the gap, not the risk itself — the question asks for the most significant risk, which is the security exposure, not the reporting outcome.

83
Multi-Selectmedium

An IS auditor is selecting an appropriate audit sample. Which THREE of the following are factors that affect the sample size?

Select 3 answers
A.Tolerable error rate
B.Confidence level
C.Sampling interval
D.Expected error rate
E.Population standard deviation
AnswersA, B, D

Tolerable error rate directly drives sample size: the lower the rate the auditor will accept without extending testing, the larger the sample must be to detect deviations. It is one of the three inputs, alongside expected error rate and confidence level, that determine how many items are selected.

Why this answer

Tolerable error rate (A) is correct because it defines the maximum deviation from the control that the auditor is willing to accept while still relying on the control; a lower tolerable rate requires a larger sample to detect deviations. Confidence level (B) is correct because it reflects how certain the auditor wants to be that the sample result is representative of the population, and higher confidence directly increases the required sample size. Expected error rate (D) is correct because the auditor's estimate of the deviation rate in the population drives sample size upward as the expected rate approaches the tolerable rate.

Sampling interval (C) is not a determinant of sample size; it is derived from the sample size and population size when using systematic selection. Population standard deviation (E) applies to variables sampling for monetary amounts, not to attribute sampling for control deviations, so it is not a general factor here.

84
MCQmedium

A company is implementing a new procurement system. The project team is considering using a rapid application development (RAD) methodology. Which of the following is a potential risk of using RAD?

A.Inadequate documentation
B.Reduced stakeholder involvement
C.Longer development time
D.Difficulty in prototyping
AnswerA

RAD prioritises rapid prototyping and iterative user feedback over formal deliverables, so written specifications and design records are often minimal or skipped. That directly creates the risk of inadequate documentation, leaving insufficient records for future maintenance, audit or knowledge transfer once the project closes.

Why this answer

RAD prioritizes speed and iterative prototyping over formal documentation. Because the focus is on quickly delivering working software through user feedback and short development cycles, comprehensive documentation is often neglected or produced after the fact, leading to inadequate records for maintenance, auditing, and compliance.

Exam trap

The trap here is that candidates may assume RAD reduces stakeholder involvement due to its fast pace, but in reality RAD demands more frequent and active stakeholder participation to validate prototypes and provide feedback.

How to eliminate wrong answers

Option B is wrong because RAD actually increases stakeholder involvement through continuous user feedback and prototyping, not reduces it. Option C is wrong because RAD is specifically designed to shorten development time through iterative cycles and time-boxed delivery, not lengthen it. Option D is wrong because prototyping is a core strength of RAD, not a difficulty; RAD relies on rapid prototyping to refine requirements and validate functionality.

85
Multi-Selecthard

Which THREE of the following are components of the COBIT 2019 governance system?

Select 3 answers
A.Organizational structures
B.Information items
C.Processes
D.Service desk
E.Project management office
AnswersA, B, C

Organisational structures are one of COBIT 2019's governance system components, alongside processes, policies and procedures, information, culture and behaviour, people skills and competencies, services, infrastructure and applications. They define decision rights and accountability, satisfying the stem's requirement for governance system components.

Why this answer

COBIT 2019 defines a governance system as comprising several distinct types of components, and among the listed choices the three that belong are A (Organizational structures), B (Information items), and C (Processes). Organizational structures are correct because COBIT 2019 explicitly names them as a component type, covering the various decision-making bodies and roles (such as boards, committees, and executive management) that carry out governance and management activities. Information items are correct because COBIT 2019 lists them as a component, referring to the information produced and used by the governance system to enable informed decision-making and effective operation.

Processes are correct because COBIT 2019 identifies processes as a core component type, encompassing the organized sets of practices and activities (the governance and management objectives) used to achieve enterprise goals. The unmarked options do not belong: a service desk (D) is a specific IT service management function rather than a COBIT 2019 governance system component type, and a project management office (E) is a particular organizational entity or function, not one of the defined component categories in the COBIT 2019 governance system.

Exam trap

The trap here is confusing COBIT governance components with ITIL operational functions (service desk, PMO) — candidates who have ITIL fresh in mind often select service desk or PMO because they sound 'governance-adjacent' but are not COBIT 2019 components.

86
Multi-Selectmedium

An IT auditor is reviewing the asset management process for hardware lifecycle. Which two controls should the auditor verify to ensure secure disposition of decommissioned servers?

Select 2 answers
A.Hardware warranty tracking
B.Performance benchmarking
C.Secure sanitization of storage media
D.Formal disposal policy with authorization
E.Asset tagging during procurement
AnswersC, D

Sanitisation destroys residual data on decommissioned server drives, preventing recovery of sensitive information before the hardware leaves organisational control. Verifying this control confirms the confidentiality constraint in the disposition process is met, since disposal without media cleansing exposes data to unauthorised parties.

Why this answer

Option C (Secure sanitization of storage media) is correct because decommissioned servers often retain sensitive data on HDDs, SSDs, or NVMe drives, and the auditor must verify that media are wiped using approved methods such as NIST SP 800-88 purge/clear or cryptographic erase, or physically destroyed, before the hardware leaves organizational control. Option D (Formal disposal policy with authorization) is correct because secure disposition requires a documented, approved process that defines roles, disposal methods, chain-of-custody, and management sign-off, ensuring decommissioning is authorized and auditable rather than ad hoc. The unmarked options do not belong: A (Hardware warranty tracking) relates to maintenance and support entitlements, not data-bearing disposition; B (Performance benchmarking) measures system capability and has no bearing on secure disposal; and E (Asset tagging during procurement) is an intake/inventory control that supports tracking but does not itself ensure secure sanitization or authorized disposal at end of life.

Exam trap

The trap here is that candidates may confuse operational lifecycle tasks (warranty, tagging, benchmarking) with security-specific disposition controls, overlooking that only sanitization and authorized policy directly address data confidentiality and disposal governance.

87
MCQhard

An IS auditor is reviewing a network access control list and finds that a rule permits traffic from any source to a database server on port 1521. Management states the rule is required for a legacy application. Which of the following is the MOST appropriate audit response?

A.Remove the rule immediately to eliminate the exposure.
B.Accept the rule because management has provided a documented business justification.
C.Escalate the matter directly to the board of directors without further analysis.
D.Document the rule as a finding with a recommendation to restrict source addresses to the application servers.
AnswerD

The rule permits unrestricted access to a database listener, which is a significant exposure regardless of the legacy justification. The auditor should document the risk and recommend tightening the source range to only the application servers that require access. This preserves functionality while reducing the attack surface, and it is the response most aligned with the auditor's role of identifying and communicating risk.

Why this answer

The auditor should identify the exposure created by an unrestricted database access rule and communicate it with a practical recommendation. Restricting the source addresses maintains the legacy application's function while reducing risk. Auditors report and recommend; they do not implement changes or accept risks on management's behalf.

Escalation should follow the normal reporting process.

Exam trap

The trap here is treating a documented business justification as equivalent to an acceptable level of residual risk, when the auditor must still evaluate the exposure.

88
MCQeasy

An IS auditor is reviewing the audit committee's oversight of the IT audit function. Which of the following is the MOST important factor for the auditor to consider when assessing the committee's effectiveness?

A.The number of IT audit findings reported to the committee.
B.The committee's technical expertise in IT systems.
C.The frequency of audit committee meetings.
D.The committee's independence from management and its ability to challenge IT risk decisions.
AnswerD

The effectiveness of an audit committee in overseeing IT audit is fundamentally dependent on its independence from management and its willingness to challenge IT risk decisions. Independence ensures objective oversight, and the ability to challenge ensures that management's assertions are scrutinized. Without these, the committee cannot provide effective governance over IT risks and the audit function. This is a core principle in ISACA's governance guidance.

Why this answer

The most important factor in assessing the audit committee's effectiveness in overseeing IT audit is its independence from management and its ability to challenge IT risk decisions. Independence ensures that the committee can objectively evaluate management's actions and the auditor's findings. The ability to challenge ensures that management is held accountable and that risks are adequately addressed.

Other factors like meeting frequency, number of findings, or technical expertise are secondary to this core governance principle.

Exam trap

The trap here is equating effectiveness with activity metrics like meeting frequency or number of findings, rather than focusing on independence and the ability to challenge management.

89
MCQmedium

An IS auditor is assessing the controls in an agile development environment. What is the MOST effective way to verify that security testing is performed iteratively?

A.Observing a daily standup meeting
B.Interviewing the product owner about security priorities
C.Examining the final security test report after release
D.Reviewing the project's definition of done for each sprint
AnswerD

The definition of done is agreed per sprint and should explicitly include security testing criteria. Auditing each sprint's definition of done confirms whether security activities are embedded iteratively, providing direct evidence rather than relying on retrospective claims or final-phase testing.

Why this answer

In agile development, security testing must be integrated into each sprint to ensure continuous validation. The 'definition of done' (DoD) is the team's checklist for completing a user story; if it explicitly includes security testing tasks (e.g., static analysis, dynamic scans, or penetration tests), then verifying the DoD proves that security testing was performed iteratively. Option D directly examines this artifact, providing objective evidence of iterative security testing.

Exam trap

The trap here is that candidates confuse 'planning for security' (e.g., standups or product owner interviews) with 'evidence of security execution' (the DoD), or they mistakenly think a final report proves iterative testing when it only shows a single snapshot.

How to eliminate wrong answers

Option A is wrong because observing a daily standup meeting only reveals what the team plans to discuss, not whether security testing was actually completed; standups are status updates, not evidence of testing execution. Option B is wrong because interviewing the product owner about security priorities captures intent and backlog ordering, but does not confirm that security testing was performed in each iteration. Option C is wrong because examining the final security test report after release shows only a single point-in-time assessment, not iterative testing across sprints; it misses the continuous integration of security checks throughout development.

90
MCQmedium

An IS auditor is reviewing a project to implement a new loan origination system. The project manager has produced a detailed work breakdown structure (WBS), a critical path schedule, and a resource-loaded plan. Which of the following should the auditor verify FIRST to assess whether the project schedule is realistic?

A.That the project sponsor has signed the project charter and that the budget has been approved by the finance committee.
B.That the WBS has been decomposed to at least three levels and that each work package has a unique identifier.
C.That all project risks have been entered into the risk register and assigned an owner with a mitigation plan.
D.That the critical path includes all tasks with zero float and that resource constraints have been leveled against actual availability.
AnswerD

A credible schedule must reflect both logical dependencies and real resource availability. If the critical path is calculated without leveling against actual staff, the plan can show an impossibly short duration. The auditor should first confirm that zero-float tasks are correctly sequenced and that resourcing assumptions match the people actually assigned, because every later schedule claim depends on this foundation.

Why this answer

A realistic schedule requires correct logical dependencies and accurate resource assumptions. Zero-float tasks define the critical path, but if that path is built without leveling against actual staff availability, the projected end date is unreliable. Confirming that critical path tasks are sequenced properly and that resourcing reflects real capacity gives the auditor the strongest evidence about schedule feasibility before examining other project artifacts.

Exam trap

The trap here is assuming that an approved charter and budget validate the schedule, when schedule realism depends on dependency logic and resource leveling.

91
MCQhard

An IS auditor is evaluating the effectiveness of a control. The auditor observes the control being performed and then independently performs the same control to confirm the result. Which combination of evidence types is being used?

A.Inquiry and inspection
B.Inspection and observation
C.Analytical procedures and inquiry
D.Observation and re-performance
AnswerD

Observation supplies evidence that the control operates as described, while re-performance independently reproduces the same result, testing operating effectiveness rather than design alone. Together they satisfy the stem's requirement to confirm the control's effectiveness through direct auditor execution, not merely inquiry or inspection of documentation.

Why this answer

The auditor observed the control being performed (observation) and then independently performed the same control to confirm the result (re-performance). This combination of observation and re-performance provides strong evidence of control effectiveness because the auditor both witnesses and independently verifies the control. Inquiry and inspection are not the primary techniques used here.

Exam trap

CISA often tests whether candidates can distinguish observation from inspection and re-performance from inquiry, causing them to pick a combination that does not match the described auditor actions.

How to eliminate wrong answers

Option A is wrong because inquiry (asking questions) and inspection (examining records) were not the techniques described — the auditor watched and then re-executed the control. Option B is wrong because inspection involves examining documents or records, not independently re-performing the control. Option C is wrong because analytical procedures involve comparing data patterns and inquiry involves asking questions, neither of which matches the described activities.

92
MCQeasy

An organization is negotiating a contract with a cloud service provider. Which clause is most important for the IS auditor to ensure is included?

A.Data localization requirements.
B.Right-to-audit clause.
C.Automatic renewal terms.
D.Service level agreement (SLA) with penalties.
AnswerB

A right-to-audit clause contractually guarantees the IS auditor independent access to the provider's controls, records and evidence. Without it, the organisation cannot verify that the outsourced service meets its security and compliance obligations, leaving assurance dependent solely on the provider's own reporting.

Why this answer

The right-to-audit clause is the most critical contractual provision for an IS auditor because it grants the organization the legal right to inspect the cloud provider's controls, processes, and records — either directly or via third-party attestations (SOC 2, ISO 27001). Without it, the auditor cannot obtain sufficient evidence to opine on the effectiveness of controls over outsourced data and processing. It is the contractual foundation that makes all other assurance activities possible.

Exam trap

CISA often tests the misconception that an SLA with penalties or data localization clauses provide equivalent assurance to a right-to-audit — candidates must recognize that only the right-to-audit gives the auditor legal standing to obtain control evidence.

How to eliminate wrong answers

Option A is wrong because data localization requirements are jurisdiction-specific and may not be relevant to every organization; they address where data resides, not the auditor's ability to verify controls. Option C is wrong because automatic renewal terms are a commercial convenience and have no bearing on audit assurance or control verification. Option D is wrong because an SLA with penalties addresses service performance and remedies, not the auditor's right to examine the provider's control environment — penalties do not substitute for audit evidence.

93
MCQmedium

During a change advisory board (CAB) meeting, a proposed change to the database server is discussed. The change involves implementing a security patch that requires a reboot. The change is categorized as 'normal' and has been risk-assessed as low impact. What is the most likely role of the CAB in this scenario?

A.Review and approve the change
B.Implement the change directly
C.Reject the change as unnecessary
D.Defer the change to the next release cycle
AnswerA

Normal changes require CAB review and authorisation before implementation. Even though the patch is low impact, the reboot and database scope mean the CAB must review and approve it, satisfying the stem's normal-category constraint rather than auto-approving it as standard.

Why this answer

The CAB's primary role is to review and approve (or reject) proposed changes by assessing risk, impact, and readiness. In this scenario, the change is a normal change that has been risk-assessed as low impact, so the CAB's most likely action is to review and approve it for implementation during the maintenance window. The CAB does not implement changes, nor does it arbitrarily reject or defer changes that are properly justified and assessed.

Exam trap

The trap is confusing the CAB's governance role with operational execution; candidates may pick 'implement the change' because the scenario describes a technical task, but the CAB never implements — it reviews and approves.

How to eliminate wrong answers

Option B is wrong because the CAB is a governance and advisory body; implementation is performed by technical teams (e.g., database administrators, operations staff), not by the CAB itself. Option C is wrong because rejecting the change as unnecessary is not the CAB's default role when a change is properly justified and risk-assessed; rejection would only occur if the change lacked justification or introduced unacceptable risk. Option D is wrong because deferring to the next release cycle is a scheduling decision that may be made if the change is not urgent or if resources are constrained, but it is not the most likely role of the CAB in this scenario — the CAB's core function is review and approval.

94
MCQmedium

An IS auditor is evaluating the capacity management process. The auditor notices that CPU utilization has been consistently above 90% for the past three months. The IT manager states that no proactive capacity planning has been performed. What is the primary risk?

A.Potential service degradation or unplanned outages.
B.Increased licensing costs for software.
C.Inability to meet backup windows.
D.Increased energy costs for cooling.
AnswerA

Sustained CPU utilisation above 90% with no proactive capacity planning leaves no headroom for demand spikes, so response times degrade and components may fail. The primary risk is therefore service degradation or unplanned outages affecting dependent business processes.

Why this answer

Consistently high utilization without planning risks performance degradation and outages. The organization may not be able to handle peak loads.

95
MCQhard

An organization is deciding between building a custom application and purchasing a commercial off-the-shelf (COTS) product. The primary factor favoring the build option is:

A.Greater control over features
B.Faster time to market
C.Lower initial cost
D.Reduced vendor dependency
AnswerA

Building in-house gives the organization direct authority over the application's feature roadmap, letting it tailor functionality to unique business processes rather than adapting to a vendor's fixed release cycle. This satisfies the stem's decision factor: where differentiation or specialised requirements matter, custom development delivers feature control that COTS licensing cannot.

Why this answer

Building a custom application allows for tailored functionality that meets unique business requirements, which is a key advantage over COTS.

96
MCQmedium

A financial institution recently experienced a data breach where an attacker exfiltrated customer data through an SQL injection vulnerability in a web application. The IS auditor has been asked to review the application security controls. The web application is developed in-house and runs on an application server behind a web application firewall (WAF). The auditor reviews the WAF logs and finds that no SQL injection attacks were detected before the breach, but the logs show many blocked XSS attempts. The developer states that all input validation is performed on the client side using JavaScript. During the audit, the auditor also finds that the application uses a shared database account with DBA privileges for all connections. What is the MOST significant weakness that directly contributed to the breach?

A.Client-side input validation is insufficient and server-side validation is missing.
B.The use of a shared DBA database account violates the principle of least privilege.
C.The WAF is misconfigured to detect only XSS attacks but not SQL injection.
D.The application server is not patched against known SQL injection vulnerabilities.
AnswerA

JavaScript validation executes in the browser, so an attacker can bypass it entirely and submit crafted SQL directly to the server. With no server-side validation, the injection reached the database. This weakness directly enabled the breach, unlike the WAF, which logged blocked XSS attempts.

Why this answer

The breach occurred because input validation was performed only on the client side using JavaScript, which an attacker can trivially bypass by disabling JavaScript, intercepting requests with a proxy, or crafting raw HTTP requests. Without server-side validation, malicious SQL payloads reach the database directly. The WAF logs showing no SQL injection detections further confirm the attack bypassed client-side controls and the WAF's signature set, but the root cause is the absence of server-side validation.

Exam trap

CISA often tests the misconception that a WAF or client-side validation provides sufficient protection — candidates must recognize that only server-side validation and parameterized queries address the root cause of SQL injection.

How to eliminate wrong answers

Option B is wrong because while using a shared DBA account violates least privilege and worsens impact, it is not the weakness that directly enabled the SQL injection to succeed — the injection would have worked even with a low-privilege account. Option C is wrong because the WAF logs showing blocked XSS attempts do not prove the WAF was misconfigured for SQLi; WAFs can miss obfuscated SQLi, but the primary failure was the lack of server-side validation. Option D is wrong because SQL injection is an application coding flaw, not an unpatched server vulnerability — patching the application server would not fix insecure input handling in the web app.

97
MCQeasy

An IS auditor is reviewing the physical security controls at a data center. The auditor observes that entry to the data center requires a smart card and a PIN, and that the door is a single-leaf door with a standard lock. Which of the following is the MOST important physical security control that the auditor should recommend?

A.Require employees to sign a logbook upon entry and exit.
B.Implement a mantrap or double-door entry system to prevent tailgating.
C.Replace the standard lock with a biometric lock for all employees.
D.Install security cameras inside the data center to monitor activity.
AnswerB

A mantrap, or access control vestibule, uses two interlocking doors to ensure that only one person can enter at a time, effectively preventing tailgating. Tailgating is a common physical security breach where an unauthorized person follows an authorized person through a secure door. Given that the data center uses smart cards and PINs, the next logical enhancement is to control physical passage to prevent unauthorized entry via tailgating, which is a critical control for high-security areas.

Why this answer

The most important physical security control to recommend is a mantrap or double-door entry system to prevent tailgating. While the data center uses smart card and PIN for authentication, a single door allows multiple people to enter on one authentication. A mantrap ensures that each person is individually authenticated and prevents unauthorized individuals from following authorized personnel.

This is a fundamental control for high-security areas like data centers.

Exam trap

The trap here is focusing on strengthening authentication methods when the real vulnerability is the lack of anti-tailgating controls, which authentication alone cannot address.

98
MCQeasy

Which of the following audit types is performed by an independent third-party auditor and is typically required for regulatory compliance?

A.External audit
B.Operational audit
C.IS audit
D.Internal audit
AnswerA

External audits are conducted by auditors independent of the organisation, satisfying the regulatory-compliance constraint in the stem. This independence from management gives the resulting opinion the objectivity that internal or self-assessment reviews cannot provide, which regulators require when mandating assurance over controls and financial reporting.

Why this answer

External audits are conducted by third-party auditors to provide independent assurance, often required by regulations or standards.

99
MCQmedium

An organization outsources its data center operations to a third-party provider. Which of the following is the MOST important clause to include in the contract to ensure the organization can verify the provider's controls?

A.Exit strategy
B.Service level agreement (SLA)
C.Vendor concentration risk clause
D.Right-to-audit clause
AnswerD

A right-to-audit clause contractually grants the organisation the ability to inspect the provider's controls, evidence and processes. This directly satisfies the stem's verification constraint, since without it the outsourcer could refuse audits, leaving control effectiveness unconfirmed.

Why this answer

A right-to-audit clause allows the organization or its auditor to review the provider's controls.

100
MCQhard

An organization is selecting a disaster recovery (DR) site. The primary data center is located in a region prone to earthquakes. The DR site should be at a sufficient distance to avoid the same disaster. Which type of alternate site provides the best balance of cost and recovery time for a medium-sized organization?

A.Hot site
B.Warm site
C.Mobile site
D.Cold site
AnswerB

A warm site pre-installs hardware and connectivity but lacks live replicated data, so it restores from backups within hours or days. This sits between cold and hot sites on the cost-versus-recovery-time axis, meeting the medium-sized organisation's need to balance budget against acceptable downtime while sited away from the earthquake zone.

Why this answer

A warm site is partially configured with some hardware, software, and data synchronization, offering a balance between cost and recovery time. For a medium-sized organization, it provides faster recovery than a cold site while being significantly less expensive than a hot site, making it suitable for a region prone to earthquakes where the DR site must be geographically distant.

Exam trap

The trap here is that candidates often confuse 'warm site' with 'hot site' due to the similar terminology, but the key differentiator is the level of data synchronization and hardware readiness, not just the distance from the primary site.

How to eliminate wrong answers

Option A is wrong because a hot site is a fully redundant, real-time mirror of the primary data center, which is excessively costly for a medium-sized organization and typically used only for mission-critical systems requiring near-zero recovery time objectives (RTOs). Option C is wrong because a mobile site is a portable, self-contained unit that is not designed for permanent, geographically distant disaster recovery; it is more suited for temporary or tactical needs, not for avoiding region-wide disasters like earthquakes. Option D is wrong because a cold site has no pre-installed hardware or software, requiring weeks to procure and configure, resulting in a recovery time that is too long for most medium-sized organizations, especially when the primary site is in a high-risk area.

101
MCQeasy

Which of the following is a key control during the deployment phase of a system development life cycle?

A.Rollback plan
B.Code review
C.Threat modeling
D.User acceptance testing (UAT)
AnswerA

A rollback plan is the key deployment-phase control because it provides a tested mechanism to revert to the previous stable state if the release fails, directly satisfying the need to manage deployment risk and minimise disruption to production services. It addresses the stem's deployment-phase constraint, unlike design or post-implementation controls.

Why this answer

During the deployment phase, the system is moved into production, and a rollback plan is a critical control to revert to a previous stable state if the deployment fails or introduces defects. It ensures business continuity and minimizes downtime. Code review, threat modeling, and UAT occur earlier in the SDLC (development, design, and testing phases, respectively).

Exam trap

The trap is confusing deployment-phase controls with testing-phase controls — candidates often pick UAT because it sounds like a final check, but UAT occurs before deployment, while rollback planning is specifically executed during deployment.

How to eliminate wrong answers

Option B is wrong because code review is a development-phase control focused on identifying defects and security issues in source code before it is built or deployed. Option C is wrong because threat modeling is a design-phase activity that identifies potential threats and mitigations before code is written. Option D is wrong because user acceptance testing is a testing-phase activity that validates the system against business requirements before deployment, not during it.

102
MCQeasy

During the planning phase of an IS audit, which of the following is the PRIMARY purpose of conducting a risk assessment?

A.To determine the audit budget
B.To obtain management approval
C.To select the audit team members
D.To identify high-risk areas for audit focus
AnswerD

Risk assessment during planning directs audit resources toward areas of greatest exposure, ensuring effort concentrates where misstatement or control failure is most likely. It satisfies the stem by establishing which areas warrant audit focus, thereby shaping objectives, scope and subsequent testing priorities before fieldwork begins.

Why this answer

A risk assessment identifies high-risk areas to prioritize audit efforts and allocate resources effectively.

103
MCQhard

During an information systems audit, the IS auditor finds that data classification labels are not consistently applied across the organization. What is the most likely root cause of this issue?

A.The data classification policy is too complex and has too many levels.
B.Insufficient training and awareness programs on data classification.
C.The organization does not enforce consequences for misclassification.
D.Lack of automated classification tools integrated with the document management system.
AnswerB

Consistent labelling depends on staff knowing which classification applies and why. Without ongoing training and awareness, employees apply labels inconsistently or omit them, so the root cause is human rather than technical. Policy exists but is not operationalised through education, making insufficient training the underlying failure.

Why this answer

Inconsistent application of data classification labels is most commonly caused by insufficient training and awareness programs. Without proper education, users do not understand how to correctly classify data according to the policy, leading to inconsistent labeling across the organization.

Exam trap

The trap here is that candidates may focus on technical solutions (automated tools) or enforcement mechanisms, but the ISACA CISA exam emphasizes that the most common root cause of policy non-compliance is inadequate training and awareness, not technology or enforcement gaps.

How to eliminate wrong answers

Option A is wrong because while a complex policy with too many levels can contribute to confusion, the root cause is typically a lack of understanding of the existing policy, not the number of levels. Option C is wrong because lack of enforcement is a secondary issue; even with enforcement, users cannot comply if they do not know how to classify correctly. Option D is wrong because automated classification tools can help but are not the root cause; the primary issue is human error due to insufficient training, not the absence of technology.

104
Multi-Selectmedium

An IS auditor is assessing network security controls. Which TWO of the following are key elements of a firewall rule review?

Select 2 answers
A.Checking for default passwords on firewall
B.Verifying that each rule has a business justification
C.Comparing actual rules to documented rules
D.Testing firewall failover capabilities
E.Reviewing firewall performance metrics
AnswersB, C

Each firewall rule must map to a documented business need; rules lacking justification are candidates for removal, reducing attack surface. This satisfies the stem's rule-review element by confirming every permitted flow is authorised rather than merely technically functional.

Why this answer

A firewall rule review is fundamentally about validating the rulebase itself, so option B is correct: verifying that each rule has a business justification ensures no unnecessary, stale, or overly permissive rules remain, directly supporting least-privilege and reducing the attack surface. Option C is also correct because comparing the actual running rulebase against the documented/approved rules detects unauthorized changes, configuration drift, and shadowed or redundant rules, which is the core purpose of a rule review. Option A is not a rule-review element but a configuration/hardening check for default credentials, which is a separate control.

Option D concerns resilience and availability testing (failover), not rule correctness, and option E addresses capacity/performance monitoring rather than the appropriateness of the rules themselves.

Exam trap

CISA often tests the difference between rule review (policy and documentation validation) and firewall operational testing (failover, performance, password checks); candidates who pick operational tasks miss the 'rule review' scope.

105
MCQmedium

A large financial institution is evaluating the effectiveness of its IT governance framework. The board has requested a review to ensure alignment with business objectives and regulatory requirements. Which of the following is the MOST important factor for the board to consider when assessing the IT governance framework?

A.The framework is integrated with enterprise governance and supports strategic objectives.
B.The framework includes a detailed incident response plan.
C.The framework focuses on achieving high technical efficiency.
D.The framework minimizes overall IT costs.
AnswerA

Integration with enterprise governance directly satisfies the stem's alignment constraint: it ensures IT decisions cascade from and report into overall corporate strategy, so the board can trace IT investment to business objectives and regulatory obligations rather than assessing IT in isolation.

Why this answer

An effective IT governance framework must be integrated with enterprise governance to ensure alignment with business objectives and regulatory requirements. Option B is incorrect because incident response is an operational process, not a primary board-level governance consideration. Option C is incorrect because technical efficiency is a management concern, not a governance-level factor.

Option D is incorrect because minimizing IT costs is a tactical objective that may conflict with strategic priorities.

106
MCQeasy

Refer to the exhibit. An auditor finds that the file 'sensitive.txt' has world-writable permissions. Which of the following is the most appropriate remediation action?

A.Remove world-writable permissions using chmod 644.
B.Encrypt the file using GnuPG to protect its contents.
C.Apply an ACL to restrict access only to specific users.
D.Change the file owner to a different user using chown.
AnswerA

chmod 644 sets the file to rw-r--r--, removing world-writable and providing proper access.

Why this answer

The file 'sensitive.txt' has world-writable permissions, meaning any user on the system can modify or delete it. The most direct and appropriate remediation is to remove the world-writable permission using `chmod 644`, which sets the file to owner read-write, group read, and others read. This eliminates the security risk while preserving necessary access for the owner and group.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing encryption or ACLs, when the simplest and most direct fix is to adjust the file permissions using `chmod`.

How to eliminate wrong answers

Option B is wrong because encrypting the file with GnuPG protects its confidentiality but does not address the world-writable permission; the file remains modifiable by anyone, which could lead to data corruption or unauthorized changes. Option C is wrong because applying an ACL to restrict access to specific users is an alternative approach, but it is not the most appropriate remediation; the simplest and most direct fix is to remove the world-writable bit, and ACLs add complexity without necessity when a simple permission change suffices. Option D is wrong because changing the file owner using `chown` does not remove the world-writable permission; the new owner would still have the same permission issue unless the permissions are also modified.

107
MCQmedium

An IT steering committee is evaluating a proposal to migrate critical applications to the cloud. Which factor is MOST important to ensure alignment with business strategy?

A.The migration schedule and resource availability
B.How the cloud migration supports the organization's strategic objectives
C.The cloud provider's security certifications
D.Cost savings compared to on-premises solution
AnswerB

Strategic alignment is judged by whether the migration advances the organisation's stated objectives, not by technical merit alone. Framing the proposal around strategic support gives the steering committee the criterion needed to approve investment consistent with business direction.

Why this answer

The most important factor to ensure alignment with business strategy is how the cloud migration supports the organization's strategic objectives. This ensures that the migration is not just a technical exercise but drives business value, competitive advantage, and long-term goals.

Exam trap

CISA often tests the difference between tactical and strategic considerations; candidates may choose cost savings or security certifications as the most important, but strategic alignment with business objectives is the key governance principle.

How to eliminate wrong answers

Option A is wrong because schedule and resource availability are tactical considerations, not strategic alignment; they are important for execution but do not ensure alignment with business strategy. Option C is wrong because security certifications are a compliance requirement, not a strategic driver; they are necessary but not sufficient for strategic alignment. Option D is wrong because cost savings are a potential benefit but not the primary strategic factor; focusing solely on cost can lead to decisions that do not support broader business goals.

108
MCQeasy

In business continuity planning, a company identifies a critical business process with a maximum tolerable downtime (MTD) of 4 hours. What is the primary purpose of this metric?

A.To define the backup frequency
B.To calculate the mean time between failures (MTBF)
C.To establish service level agreements (SLAs)
D.To determine the recovery time objective (RTO)
AnswerD

MTD defines the maximum time a process can be unavailable, and the RTO must be set at or below it to keep downtime tolerable. Deriving the RTO from the 4-hour MTD ensures recovery capabilities align with business tolerance.

Why this answer

The maximum tolerable downtime (MTD) defines the maximum time a business process can be unavailable before unacceptable consequences occur. The recovery time objective (RTO) is derived from the MTD — it is the target time within which the process must be restored, and it must be less than the MTD to provide a safety margin. Therefore, the primary purpose of the MTD is to determine the RTO for the process.

Exam trap

The trap is confusing MTD with RTO or RPO; candidates must remember that MTD is the business tolerance limit, and RTO is the technical recovery target derived from it — MTD does not define backup frequency (that is RPO).

How to eliminate wrong answers

Option A is wrong because backup frequency is driven by the recovery point objective (RPO), which defines how much data loss is tolerable, not by MTD. Option B is wrong because mean time between failures (MTBF) is a reliability metric for hardware or components, unrelated to business continuity downtime tolerances. Option C is wrong because SLAs are contractual agreements that may reference RTO/RPO, but the MTD itself does not establish SLAs; SLAs are negotiated based on business requirements, of which MTD is one input.

109
MCQmedium

An organization is migrating data from a legacy system to a new ERP. What is the most critical data migration risk?

A.Data loss or corruption
B.Increased storage costs
C.Longer migration time
D.Incompatible hardware
AnswerA

Data loss or corruption directly threatens the migration's integrity, since legacy-to-ERP transfers involve format conversions, field mapping and bulk loads where truncation, encoding faults or failed batches can silently corrupt records. This satisfies the stem's "most critical" constraint because corrupted financial data undermines the ERP's ledger accuracy and auditability irreversibly.

Why this answer

Data loss or corruption is the most critical risk because it directly compromises the integrity and completeness of the migrated data, which is the core asset being transferred. Unlike cost or schedule overruns, corrupted data can lead to incorrect business decisions, regulatory non-compliance, and financial misstatements that may go undetected for long periods. The primary objective of any data migration is to preserve data accuracy and completeness, making this the highest-priority risk.

Exam trap

CISA often tests the distinction between project management risks (cost, schedule, hardware) and information asset risks (integrity, confidentiality, availability), expecting candidates to prioritize the risk that threatens the data itself.

How to eliminate wrong answers

Option B is wrong because increased storage costs are a financial concern that can be managed through capacity planning and does not threaten the integrity of the business data itself. Option C is wrong because longer migration time affects project schedule but can be mitigated with rollback plans and does not inherently damage the data. Option D is wrong because incompatible hardware is a technical infrastructure issue typically resolved during planning and testing, and it does not directly cause data integrity loss once the migration environment is validated.

110
MCQeasy

According to ISACA IT Audit Standards, which phase of the audit process includes the development of an audit programme?

A.Planning
B.Reporting
C.Fieldwork
D.Follow-up
AnswerA

Planning is the phase in which the audit programme is developed, setting scope, objectives, timing and the procedures to be performed. This satisfies the stem's requirement because ISACA standards place programme design before fieldwork begins, ensuring evidence gathering is structured and aligned to the engagement objectives.

Why this answer

According to ISACA IT Audit Standards, the audit programme — the detailed plan of audit procedures to be performed — is developed during the Planning phase. Planning encompasses scoping, risk assessment, resource allocation, and designing the procedures that will be executed during fieldwork. Reporting, fieldwork, and follow-up occur after the programme has been established.

Exam trap

CISA often tests whether candidates place audit programme development in Fieldwork rather than Planning, confusing the design of procedures with their execution.

How to eliminate wrong answers

Option B is wrong because Reporting is the phase where findings and conclusions are communicated, which occurs after the audit work is performed. Option C is wrong because Fieldwork is the execution phase where the audit programme is carried out, not where it is developed. Option D is wrong because Follow-up verifies that management remediated findings, which happens after reporting.

111
Multi-Selectmedium

An IS auditor is assessing the implementation of a new system that uses a relational database. The project team plans to migrate data from several legacy sources. Which TWO of the following controls are MOST important to include in the data conversion plan to help ensure the integrity of migrated data? (Choose two.)

Select 2 answers
A.Confirmation that the legacy system is decommissioned immediately after the conversion cutover.
B.Use of a parallel test environment that mirrors production hardware and software configurations for the conversion rehearsal.
C.Verification that referential integrity constraints are enabled and validated after the data load.
D.Approval of the data mapping document by the database administrator before the conversion begins.
E.Reconciliation of record counts and financial totals between legacy sources and the new database after conversion.
AnswersC, E

Referential integrity constraints prevent orphaned records and invalid relationships in the new database. If they are disabled during the load and not re-enabled and validated afterward, the database may contain inconsistent foreign key values that corrupt business logic and reporting. Confirming that constraints are active and that validation completed ensures the migrated data conforms to the target schema's relational rules.

Why this answer

Data migration integrity depends on detecting missing or corrupted records and ensuring that relationships between tables remain valid. Reconciliation of counts and totals provides independent verification that all expected data arrived, while validated referential integrity constraints ensure that foreign key relationships are sound. Together, these detective and preventive controls give the auditor the strongest evidence that the conversion preserved data accuracy and completeness.

Exam trap

The trap here is treating project logistics like legacy decommissioning or environment setup as data integrity controls, when the real assurance comes from reconciliation and referential integrity validation.

112
Multi-Selecthard

During a post-implementation review of a new accounting system, the IS auditor notes the following: the project was completed on time and within budget, but user satisfaction is low and there are several outstanding defect reports. Which THREE of the following are the MOST appropriate recommendations?

Select 3 answers
A.Compare actual benefits achieved against the business case
B.Establish a formal plan to resolve outstanding defects
C.Request additional budget to fix the defects
D.Immediately escalate the defect reports to the project sponsor
E.Conduct a lessons learned session to identify process improvements
AnswersA, B, E

On-time, on-budget delivery says nothing about value, so comparing realised benefits against the original business case tests whether the system actually delivered the expected outcomes — the gap the low satisfaction and defect backlog hint at.

Why this answer

Option A is correct because a post-implementation review must measure realized benefits against the original business case to determine whether the system delivered the expected value, especially when satisfaction is low. Option B is correct because outstanding defect reports represent unresolved risks to data integrity and operational reliability in an accounting system, so a formal remediation plan with ownership, priorities, and target dates is the appropriate control response. Option E is correct because a lessons learned session captures root causes of the schedule/budget-versus-quality gap and feeds process improvements into future projects.

Option C is not appropriate as a primary recommendation because additional budget is a funding request, not a control or governance action, and cost should follow an approved defect remediation plan. Option D is not appropriate because escalation to the sponsor may be a communication step, but it does not by itself resolve the defects or address the underlying process weaknesses.

Exam trap

CISA often tests whether candidates recommend process-based, governance-aligned actions rather than reactive or escalation-based responses, so options that skip formal remediation planning are typically distractors.

113
Multi-Selectmedium

Which TWO of the following are components of audit risk in IS auditing?

Select 2 answers
A.Detection risk
B.Financial risk
C.Business risk
D.Inherent risk
E.Operational risk
AnswersA, D

Detection risk is a component of audit risk, representing the risk that audit procedures fail to detect a material misstatement. It combines with inherent and control risk, satisfying the stem's requirement to identify audit risk components in IS auditing.

Why this answer

In IS auditing, audit risk is modeled as the risk that the auditor gives an inappropriate opinion on financial statements that are materially misstated, and its standard components are inherent risk, control risk, and detection risk. Detection risk (A) is correct because it is the risk that the auditor's procedures fail to detect a material misstatement that exists, and it is the component the auditor can directly manage by adjusting the nature, timing, and extent of audit procedures. Inherent risk (D) is correct because it is the susceptibility of an assertion to a material misstatement before considering any related internal controls, arising from factors such as complex IT environments, high transaction volumes, or estimation uncertainty.

The other options do not belong: financial risk (B), business risk (C), and operational risk (E) are broader enterprise or management risk categories, not the defined components of the audit risk model used in IS auditing.

114
Multi-Selecthard

Which THREE of the following are common techniques for ensuring business resilience?

Select 3 answers
A.Insurance policies
B.Regular data backups
C.Annual employee training
D.Redundant hardware
E.Single point of failure analysis
AnswersA, B, D

Insurance provides financial resilience to recover from losses.

Why this answer

Correct answers are A, B, and D: redundant hardware, regular data backups, and insurance policies. C and E are not resilience techniques; C is a risk analysis step, E is training which is supportive but not a core resilience technique.

115
MCQeasy

A compliance audit is primarily concerned with:

A.Evaluating the effectiveness of internal controls
B.Assessing the efficiency of IT operations
C.Ensuring the organization is meeting its strategic objectives
D.Determining whether the organization is following applicable laws and regulations
AnswerD

Compliance audits measure adherence to externally imposed criteria such as laws, regulations and contractual obligations, testing whether the organisation's controls and practises conform to those mandatory requirements rather than assessing efficiency or financial statement fairness.

Why this answer

A compliance audit is primarily concerned with determining whether the organization is adhering to applicable laws, regulations, standards, and contractual obligations. It tests conformity against defined criteria rather than evaluating control effectiveness, operational efficiency, or strategic alignment. The other options describe operational, performance, or strategic audits.

Exam trap

CISA often tests whether candidates confuse compliance audits (adherence to laws/regulations) with operational audits (control effectiveness) or performance audits (efficiency), leading them to select a control-focused answer.

How to eliminate wrong answers

Option A is wrong because evaluating the effectiveness of internal controls is the focus of an operational or internal control audit, not a compliance audit. Option B is wrong because assessing the efficiency of IT operations is a performance/operational audit objective. Option C is wrong because ensuring the organization meets strategic objectives is the domain of strategic or management audits, not compliance audits.

116
MCQmedium

An organization uses automated job scheduling for batch processing. A critical job fails due to a dependency on another job that has not completed. Which of the following controls would BEST prevent this issue?

A.Job failure alerts
B.Manual job scheduling
C.Rerun procedures
D.Dependency management
AnswerD

Dependency management ensures a job only starts once its prerequisite jobs complete successfully, preventing the failure caused by unmet dependencies. It directly addresses the scheduling constraint in the stem, unlike restart or notification controls that react after the job has already failed.

Why this answer

Dependency management is the correct control because it ensures that job scheduling logic explicitly defines and enforces the order of execution based on predecessor/successor relationships. By configuring dependencies (e.g., using job control language (JCL) with COND parameters or scheduling tools like CA Workload Automation ESP), the system will automatically hold a job until all prerequisite jobs have completed successfully, preventing the failure scenario described.

Exam trap

The trap here is that candidates often confuse detective controls (like alerts) with preventive controls, or assume that rerun procedures can prevent the initial failure, when in fact only dependency management addresses the root cause by enforcing execution order.

How to eliminate wrong answers

Option A is wrong because job failure alerts are a detective control that notifies administrators after the failure has already occurred, not a preventive control that stops the issue from happening. Option B is wrong because manual job scheduling introduces human error and inefficiency, and does not inherently enforce dependency sequencing; it would actually increase the risk of similar failures. Option C is wrong because rerun procedures are corrective controls that handle recovery after a failure, not preventive measures that avoid the dependency-related failure in the first place.

117
MCQeasy

A healthcare organization must comply with HIPAA regulations regarding patient data privacy. The IT department has implemented technical controls, but the compliance officer discovers that some employees are sharing passwords. What is the BEST governance response?

A.Implement multi-factor authentication to prevent password sharing.
B.Enforce the existing policy through disciplinary actions and additional training.
C.Report the incident to the regulatory authority as a data breach.
D.Revise the password policy to require more complex passwords.
AnswerB

Password sharing breaches the existing policy, so governance demands enforcing that policy through disciplinary action plus further training. Technical controls alone cannot compel behaviour; accountability and awareness address the human factor HIPAA privacy compliance requires.

Why this answer

Password sharing is a policy violation, not a technical control failure. The best governance response is to enforce the existing policy through disciplinary action and reinforce awareness via training, addressing the human/behavioral root cause while maintaining a documented compliance posture.

Exam trap

CISA often tests the distinction between technical controls and governance/administrative responses — candidates gravitate toward technical fixes (MFA, complexity) when the scenario calls for policy enforcement and training.

How to eliminate wrong answers

Option A is wrong because MFA is a technical control that reduces risk but does not directly address the governance issue of employees violating policy, and it does not remediate the existing violation. Option C is wrong because password sharing is an internal policy violation, not necessarily a reportable data breach under HIPAA unless actual unauthorized disclosure occurred. Option D is wrong because stronger password complexity does not prevent sharing and misdiagnoses the root cause as weak passwords rather than policy non-compliance.

118
MCQhard

An IS auditor is evaluating an organization's IT governance maturity using COBIT 2019. The auditor finds that IT processes are largely ad hoc, with no formal documentation or consistent monitoring. However, the organization has recently implemented a tool to automate some IT service management tasks. Management believes this tool elevates their maturity to a managed level. The auditor should:

A.Assess the actual process maturity against COBIT criteria, noting that tool implementation without process definition does not raise maturity.
B.Recommend immediate reclassification to the managed level to reflect management's commitment to improvement.
C.Conclude that the organization is at an initial level because the tool is not fully integrated with all IT processes.
D.Agree that the tool implementation demonstrates a managed level because automation implies repeatable processes.
AnswerA

COBIT 2019 maturity levels are based on the capability of processes, not on the tools used. Implementing a tool without defining, documenting, and consistently executing processes does not move the organization beyond the initial or ad hoc level. The auditor should evaluate the processes against the COBIT criteria for each maturity level, recognizing that automation can support but not substitute for process management.

Why this answer

COBIT 2019 maturity levels assess process capability, not the presence of tools. The organization's processes are ad hoc and undocumented, which aligns with the initial level. Implementing an automation tool does not automatically elevate maturity because the underlying processes are not defined, managed, or measured.

The IS auditor should evaluate the processes against COBIT criteria and conclude that the tool alone does not raise maturity to the managed level.

Exam trap

The trap here is equating the implementation of a tool with process maturity, overlooking that COBIT maturity is about process capability, not technology adoption.

119
Multi-Selecteasy

Which TWO of the following are examples of IT governance frameworks? (Select TWO.)

Select 2 answers
A.COBIT 2019
B.PMBOK
C.ITIL 4
D.ISO/IEC 38500
E.Six Sigma
AnswersA, D

COBIT 2019 is ISACA's governance framework for enterprise IT, defining governance and management objectives across a full domain structure. It is explicitly a governance framework, distinguishing it from audit standards, control sets or project delivery methods that operate at lower levels.

Why this answer

COBIT 2019 (A) is correct because it is ISACA's dedicated IT governance framework, providing governance and management objectives across the five domains (EDM, APO, BAI, DSS, MEA) to align IT with enterprise goals. ISO/IEC 38500 (D) is correct because it is the international standard for corporate governance of IT, defining principles (responsibility, strategy, acquisition, performance, conformance, human behaviour) and a governance model for directing and controlling IT. PMBOK (B) is a project management body of knowledge, ITIL 4 (C) is an IT service management framework, and Six Sigma (E) is a process-improvement methodology — none of these are IT governance frameworks.

Exam trap

CISA often tests the distinction between governance frameworks and management/process frameworks, causing candidates to confuse ITIL (service management) or PMBOK (project management) as governance frameworks.

120
MCQhard

During an audit of network security controls, the IS auditor reviews firewall rule sets and identifies a rule that allows any-to-any traffic from the internal network to the Internet. The rule has a business justification. What is the auditor's BEST recommendation?

A.Add an intrusion prevention system (IPS) to monitor the traffic
B.Require all traffic to go through a proxy server
C.Implement a more restrictive rule set based on specific IP addresses and ports
D.Accept the risk because there is a business justification
AnswerC

Any-to-any internal-to-Internet access grants unrestricted egress, enabling data exfiltration and command-and-control. Restricting to specific IP addresses and ports enforces least privilege while preserving the justified business need, satisfying the stem's requirement for a more granular, auditable rule set.

Why this answer

An any-to-any rule from internal to Internet is overly permissive and violates the principle of least privilege, even if a business justification exists. The auditor's best recommendation is to implement a more restrictive rule set based on specific IP addresses, ports, and protocols, which enforces least privilege while still meeting business needs. A business justification does not make an overly broad rule acceptable; the control should be tightened to the minimum necessary access.

Exam trap

The trap is accepting a business justification as sufficient for an overly broad rule; CISA tests that auditors must still recommend least-privilege restrictions even when a justification exists.

How to eliminate wrong answers

Option A is wrong because adding an IPS to monitor traffic is a compensating detective control, not a corrective measure; it does not reduce the attack surface created by the any-any rule and leaves the overly permissive rule in place. Option B is wrong because requiring all traffic to go through a proxy server is an architectural change that may not be feasible or necessary; it is not the auditor's first recommendation and does not directly address the rule specificity issue. Option D is wrong because accepting the risk solely due to a business justification ignores the principle of least privilege; a justification explains why access is needed, but the rule should still be as restrictive as possible.

121
MCQmedium

An IS auditor is assessing how an organization manages the risk of malicious code on employee workstations. The organization has deployed endpoint detection and response (EDR) agents on all workstations and maintains a centralized console. Which of the following is the MOST important factor in determining whether the EDR deployment effectively reduces malicious code risk?

A.Whether the EDR agents are installed on servers in addition to workstations.
B.Whether the EDR vendor has a large market share among similar organizations.
C.Whether the EDR agents are configured to update their detection signatures and behavioral models automatically.
D.Whether the EDR console is hosted in the same data center as the workstations it monitors.
AnswerC

EDR effectiveness depends heavily on current detection logic. If agents do not receive automatic updates to signatures and behavioral models, they will fail to recognize new malware variants and evolving attack techniques. Automatic updating ensures the endpoint can detect threats that emerge after deployment. Without it, the organization retains coverage only for known, older threats, which materially weakens the control's ability to reduce malicious code risk.

Why this answer

EDR reduces malicious code risk by detecting known and unknown threats through signatures and behavioral analysis. That capability degrades rapidly if the agent's detection logic is stale. Automatic updates keep both signature databases and behavioral models current, allowing the agent to recognize new variants and techniques.

Configuration and response integration matter, but without current detection logic the agent cannot identify the threats it is deployed to stop, so update configuration is the most important factor.

Exam trap

The trap here is treating vendor reputation or console placement as evidence of effectiveness, when detection currency through automatic updates is what determines whether the agent can actually identify malicious code.

122
MCQeasy

A medium-sized manufacturing company has recently deployed an ERP system to integrate its financial, supply chain, and HR processes. The IT department is small (5 staff) and reports to the CFO. The company has no formal IT governance committee; IT decisions are made by the CFO and CEO informally. During a recent audit, it was found that several critical security patches for the ERP system have not been applied, and there are no documented procedures for change management. The IT manager states that patches are applied when time permits, and changes are discussed via email. The CFO argues that the ERP is running fine and the audit findings are low risk. The IS auditor needs to recommend a course of action to improve IT governance. Which of the following is the MOST appropriate initial step?

A.Elevate the issue to the board of directors with a recommendation to outsource IT management
B.Recommend the formation of an IT steering committee comprising key business stakeholders to oversee IT strategy, risk, and resource allocation
C.Develop a comprehensive patch management policy and present it to the CFO for approval
D.Insist that the IT manager immediately apply all missing patches within one week
AnswerB

An IT steering committee gives the five-person IT function formal governance oversight, addressing the absent decision-making structure the audit flagged. It routes patch and change-management accountability through business stakeholders rather than the CFO's informal judgement, satisfying the need for documented, risk-based governance.

Why this answer

The root cause of the audit findings is the absence of IT governance, not the missing patches themselves. Forming an IT steering committee establishes a governance structure that aligns IT strategy with business objectives, assigns accountability for risk, and provides oversight for change and patch management. This addresses the underlying governance gap rather than a symptom, making it the most appropriate initial step for the IS auditor to recommend.

Exam trap

CISA often tests the distinction between addressing a symptom (missing patches) and addressing the root cause (lack of governance); candidates frequently choose the technical fix because it feels more actionable.

How to eliminate wrong answers

Option A is wrong because escalating to the board with an outsourcing recommendation is a disproportionate leap that skips the foundational governance step and presumes outsourcing is the solution before governance is even established. Option C is wrong because developing a patch management policy treats a symptom; without a governance body to approve, enforce, and fund it, the policy will likely be ignored, as evidenced by the CFO's dismissive attitude. Option D is wrong because insisting on immediate patching is an operational directive, not a governance recommendation, and it ignores the change management risk of applying untested patches to a production ERP without a formal process.

123
MCQmedium

An IS auditor is conducting an audit of a payroll application and selects a statistical sample of 200 payment transactions from a population of 20,000. Testing reveals 12 transactions where the gross pay was calculated incorrectly due to a flawed overtime rule. Which of the following is the MOST appropriate interpretation of this result?

A.The sample size should be increased until the number of exceptions falls within acceptable limits
B.The error rate in the sample should be projected to the population and evaluated against the tolerable deviation rate
C.The audit conclusion should be unqualified because 188 of 200 transactions were processed correctly
D.The 12 identified transactions should be corrected and the sample re-tested to confirm the control is now effective
AnswerB

For a compliance or attribute sample, the auditor projects the observed deviation rate to the population and compares it with the tolerable deviation rate set during planning. Twelve deviations in 200 items is a 6 percent rate, which must be evaluated against the tolerable rate before concluding whether the control or processing rule operated effectively across the population.

Why this answer

When testing attributes or compliance, the auditor projects the sample deviation rate to the population and compares it with the tolerable deviation rate established during planning. The finding of 12 deviations in 200 items yields a 6 percent rate that must be evaluated against that threshold, along with sampling risk, before determining whether the control can be relied upon.

Exam trap

The trap here is treating the raw percentage of correctly processed transactions as the audit conclusion instead of comparing the projected deviation rate with the pre-established tolerable deviation rate.

124
MCQhard

During an audit of a data center, an IS auditor discovers that a critical server's operating system has not been patched for eight months because the vendor's patch conflicted with a legacy application. Management accepts the risk and documents a compensating control of enhanced network monitoring. Which of the following should the IS auditor do NEXT?

A.Remove the finding from the report because management formally accepted the risk
B.Recommend replacing the legacy application to eliminate the patching conflict
C.Evaluate the design and operating effectiveness of the compensating control before concluding
D.Report the finding as a high-risk issue and demand immediate patching
AnswerC

When management accepts a risk and relies on a compensating control, the auditor must assess whether that control actually reduces the risk to an acceptable level. Enhanced network monitoring may or may not detect exploitation of the unpatched server. Testing the compensating control's design and operation allows the auditor to form a supportable conclusion about residual risk rather than accepting the documentation at face value.

Why this answer

Because management chose to accept the risk and rely on a compensating control, the auditor's next step is to test whether that control genuinely mitigates the risk. Only after evaluating its design and operating effectiveness can the auditor judge residual risk and decide how to report the matter. Simply accepting the documentation, dictating remediation, or jumping to application replacement all bypass the required evaluation.

Exam trap

The trap here is assuming that documented management risk acceptance ends the auditor's work, when the auditor must still assess whether the compensating control actually reduces risk to an acceptable level.

125
Multi-Selectmedium

An organization is developing a business continuity strategy. According to best practices, which THREE of the following should be included in the strategy?

Select 3 answers
A.Customer and partner communications plan.
B.Vendor contract renewal dates.
C.Procedures for staff to work remotely.
D.IT asset inventory list.
E.Details of alternate processing facilities.
AnswersA, C, E

A customer and partner communications plan ensures external stakeholders receive timely, accurate notifications during disruption, protecting reputation and contractual obligations. It satisfies the strategy's requirement to address interdependent parties, since continuity depends on coordinated messaging rather than internal recovery alone.

Why this answer

A customer and partner communications plan (A) is a required element of a business continuity strategy because during a disruption the organization must be able to notify external stakeholders about service status, expected recovery times, and alternate contact channels, which protects reputation and contractual relationships. Procedures for staff to work remotely (C) belong in the strategy because personnel are the most critical resource; documented remote-work procedures ensure that essential functions can continue when the primary site is unavailable. Details of alternate processing facilities (E) are essential because the strategy must identify where and how critical systems and operations will be resumed, including recovery site type (hot, warm, or cold), location, and activation criteria.

Vendor contract renewal dates (B) are administrative procurement data rather than continuity planning content, and an IT asset inventory list (D) is an operational input used during business impact analysis and recovery planning, not a strategic continuity element itself.

Exam trap

The trap is confusing BCP strategy elements with BCP inputs or administrative details; candidates may pick 'IT asset inventory' because it sounds important, but it is an input, not a strategic element.

126
MCQmedium

During an audit of a financial application, the IS auditor discovers that user access reviews are performed quarterly instead of monthly as required by policy. Which of the following is the BEST initial action for the auditor?

A.Recommend that the policy be changed to allow quarterly reviews
B.Report the noncompliance with the policy as a finding immediately
C.Escalate the issue to senior management for immediate resolution
D.Determine if compensating controls mitigate the risk of less frequent reviews
AnswerD

Before concluding on the control weakness, the auditor must assess whether other controls, such as automated provisioning or monitoring, reduce the exposure created by quarterly reviews. This determines the actual risk and whether the finding warrants escalation.

Why this answer

The IS auditor's primary role is to assess risk, not to enforce policy blindly. Quarterly reviews may still be acceptable if compensating controls (e.g., automated provisioning/deprovisioning, real-time monitoring, or role-based access controls) effectively reduce the risk of unauthorized access between reviews. Determining the presence and effectiveness of such controls is the best initial action before deciding whether to report noncompliance.

Exam trap

The trap here is that candidates assume policy noncompliance must always be reported immediately as a finding, but the CISA exam emphasizes risk-based auditing where the auditor first evaluates whether compensating controls mitigate the risk before concluding on the finding's significance.

How to eliminate wrong answers

Option A is wrong because recommending a policy change without first assessing the risk impact of the deviation could weaken security posture and is premature. Option B is wrong because immediately reporting noncompliance as a finding without evaluating compensating controls may result in an incomplete or misleading audit report, failing to consider the actual risk. Option C is wrong because escalating to senior management without first gathering evidence on compensating controls bypasses the auditor's responsibility to perform due diligence and risk assessment.

127
MCQhard

Which of the following is the BEST indicator that an organization's data security governance is effective?

A.Number of security incidents.
B.Percentage of employees trained.
C.Audit findings show compliance with data protection policies.
D.Number of encryption keys managed.
AnswerC

Compliance with data protection policies is the strongest evidence that governance controls actually operate as intended. Audit findings provide independent verification, confirming that policies are enforced rather than merely documented, which directly satisfies the stem's requirement for an effectiveness indicator.

Why this answer

Audit findings that show compliance with data protection policies provide independent, objective evidence that the governance program is working as intended. Unlike metrics such as incident counts or training percentages, audit results directly assess whether controls are implemented and effective. This makes them the best indicator of governance effectiveness.

Exam trap

CISA often tests the confusion between activity metrics (e.g., training percentage) and outcome-based evidence (e.g., audit findings), where the former measures effort and the latter measures effectiveness.

How to eliminate wrong answers

Option A is wrong because a low number of security incidents could be due to underreporting or lack of detection, not effective governance. Option B is wrong because training percentage measures awareness efforts, not whether policies are actually followed or controls are effective. Option D is wrong because the number of encryption keys managed is an operational metric, not an outcome-based indicator of governance effectiveness.

128
MCQhard

An IS auditor is reviewing an emergency change that was implemented to fix a critical security vulnerability. What is the most important post-implementation step?

A.Document the change and obtain retrospective approval
B.Update the configuration management database
C.Notify all users
D.Conduct a risk assessment
AnswerA

Emergency changes bypass the normal change advisory board, so retrospective approval restores governance while documentation preserves the audit trail. This satisfies the IS auditor's requirement that emergency fixes still receive formal authorisation and traceability after implementation.

Why this answer

Documenting the change and obtaining retrospective approval is the most important step because emergency changes bypass normal change control, and without proper documentation and after-the-fact authorization, the organization loses accountability and auditability. This step ensures the change is formally recorded in the change log and reviewed by the change advisory board (CAB) or equivalent authority, closing the governance gap created by the emergency. It also provides the audit trail needed for future reviews and compliance.

Exam trap

CISA often tests the principle that emergency changes still require retrospective approval and documentation, and candidates who prioritize technical follow-ups like CMDB updates or risk assessments over governance controls pick the wrong answer.

How to eliminate wrong answers

Option B is wrong because updating the configuration management database (CMDB) is important for asset accuracy but is a secondary administrative task that does not address the governance gap of an unauthorized change. Option C is wrong because notifying all users is a communication activity that does not satisfy change management control requirements and may not even be necessary for a security patch. Option D is wrong because conducting a risk assessment after the change is implemented is too late to inform the decision; the emergency change was already made, and the priority is to legitimize it through documentation and retrospective approval.

129
MCQmedium

Which of the following is a key component of an IT balanced scorecard from the 'internal process' perspective?

A.Customer satisfaction score
B.Employee satisfaction
C.System availability percentage
D.IT budget variance
AnswerC

The internal process perspective measures operational efficiency and service delivery. System availability percentage directly reflects how reliably IT processes deliver services, making it a valid internal process metric rather than a financial, customer or learning and growth measure.

Why this answer

The internal process perspective focuses on operational efficiency and effectiveness, such as system availability.

130
MCQmedium

An organization's IT governance framework includes a policy that all system access must be reviewed quarterly. The internal audit finds that reviews are incomplete. What is the BEST action?

A.Implement an automated access review tool
B.Reinforce accountability with managers
C.Disable all non-compliant accounts
D.Update the policy to require monthly reviews
AnswerB

Accountability sits with line managers who own the access reviews; reinforcing it makes them enforce the quarterly policy rather than audit merely re-testing. This addresses the root cause of incomplete reviews, restoring the control the framework requires.

Why this answer

When access reviews are incomplete, the root cause is often lack of accountability among managers who are responsible for conducting the reviews. Reinforcing accountability with managers—through clear expectations, consequences, and escalation—addresses the behavioral gap and ensures the control operates effectively. This is the best action because it directly targets the cause of non-compliance without weakening the control or introducing unnecessary risk.

Exam trap

CISA often tests the difference between treating the symptom (automation, disabling accounts) and addressing the root cause (accountability); candidates may pick a technical fix when the issue is a management/process failure.

How to eliminate wrong answers

Option A is wrong because implementing an automated tool may improve efficiency but does not address the underlying accountability issue; managers could still ignore the reviews. Option C is wrong because disabling all non-compliant accounts is a drastic, disruptive action that could lock out legitimate users and does not fix the process. Option D is wrong because updating the policy to require monthly reviews increases the burden without addressing why quarterly reviews are incomplete, likely worsening non-compliance.

131
MCQhard

An IS auditor is evaluating how an organization manages operating system patches on internet-facing web servers. The patch management procedure requires testing in a staging environment, approval by the change manager, and deployment within 30 days of release. The auditor finds that emergency patches for critical vulnerabilities are deployed directly to production within 24 hours without staging tests. Which of the following is the MOST appropriate conclusion?

A.The staging environment should be eliminated so all patches follow the same emergency path.
B.The emergency process is a control weakness because it bypasses testing entirely.
C.The emergency process is acceptable if it includes documented authorization, a rollback plan, and post-deployment verification.
D.The 30-day deployment window for routine patches is too long and should be shortened to 7 days.
AnswerC

Emergency patching of critical vulnerabilities on internet-facing systems is a legitimate risk response when the exposure window is short. What makes it acceptable is compensating control: a documented approval by an authorized person, a tested rollback plan in case the patch breaks the service, and verification after deployment that the patch applied and the service functions. This balances the security risk of delay against the operational risk of untested change.

Why this answer

Emergency patching is a necessary capability when critical vulnerabilities on internet-facing systems could be exploited before a normal change cycle completes. The control objective is not to prohibit the bypass but to ensure it is governed: authorized by an accountable person, accompanied by a rollback plan, and verified after deployment. If those compensating controls are documented and evidenced, the emergency path is an acceptable risk-based exception to the standard patch procedure.

Exam trap

The trap here is concluding that any deviation from the standard patch process is automatically a finding, rather than evaluating whether the emergency path has its own compensating controls.

132
MCQeasy

A project manager is selecting a development methodology for a project with well-defined requirements and low uncertainty. Which methodology is most appropriate?

A.Waterfall
B.Agile
C.Rapid Application Development (RAD)
D.Spiral
AnswerA

Waterfall suits projects with well-defined, stable requirements and low uncertainty because it progresses sequentially through fixed phases with upfront documentation. Its predictive, plan-driven structure matches the stem's constraint of clarity and minimal change, unlike iterative agile approaches.

Why this answer

Waterfall is the most appropriate methodology for projects with well-defined requirements and low uncertainty because it follows a linear, sequential approach where each phase (requirements, design, implementation, verification, maintenance) must be completed before the next begins. This structure minimizes risk when requirements are stable and unlikely to change, ensuring thorough documentation and predictable outcomes. In contrast, iterative or adaptive methods would introduce unnecessary complexity and overhead for such a deterministic project.

Exam trap

The trap here is that candidates often assume Agile is always the 'modern' or 'best' choice, but the CISA exam tests the principle that methodology selection must match project characteristics—specifically, Waterfall is optimal when requirements are fixed and uncertainty is low, not when adaptability is needed.

How to eliminate wrong answers

Option B (Agile) is wrong because Agile is designed for projects with high uncertainty and evolving requirements, emphasizing iterative development and customer collaboration, which would be inefficient and over-engineered for well-defined, low-uncertainty projects. Option C (Rapid Application Development) is wrong because RAD relies on prototyping and iterative user feedback, which is suited for projects with unclear requirements or high user involvement, not for those with already stable and clear specifications. Option D (Spiral) is wrong because Spiral is a risk-driven model that incorporates iterative prototyping and risk analysis, making it ideal for large, complex, or high-risk projects, but unnecessary and overly complex for low-uncertainty, well-defined projects.

133
MCQmedium

An IS auditor is reviewing how a data center schedules preventive maintenance on its uninterruptible power supply (UPS) systems and backup generators. The operations manager states that maintenance is performed monthly by an external vendor and that no formal maintenance window is documented because the work is done during low-usage hours. Which of the following is the MOST significant audit concern?

A.Maintenance is performed monthly instead of quarterly.
B.The vendor performing the maintenance is external rather than internal staff.
C.Maintenance is performed without a formally approved and documented maintenance window.
D.The operations manager, rather than the vendor, owns the maintenance schedule.
AnswerC

Without an approved maintenance window, maintenance activities can overlap with production processing, and any resulting outage cannot be traced to an authorized change. The auditor's primary concern is that maintenance on power infrastructure must be coordinated, approved, and recorded so that availability risk is controlled and accountability is maintained. Undocumented timing removes the audit trail and increases the chance of an unplanned service interruption.

Why this answer

Preventive maintenance on power infrastructure must be planned, authorized, and documented so that availability risks are controlled and any outage can be traced to an approved activity. Performing maintenance during low-usage hours without a formal window means the activity is not governed by change and scheduling controls, leaving the organization exposed to uncoordinated interruptions and no reliable record of what was done to critical equipment.

Exam trap

The trap here is assuming that maintenance performed during low-usage hours is inherently safe and therefore does not need a formal, approved window or documentation.

134
Multi-Selecthard

An IS auditor is reviewing the implementation of a new payroll system. The project team has decided to use a pilot conversion approach. Which TWO of the following are the MOST significant advantages of this approach? (Choose two.)

Select 2 answers
A.It allows for testing the system in a live environment with a subset of users before full rollout.
B.It allows for incremental learning and refinement of the implementation process before full deployment.
C.It minimizes the need for user training because only a few users are affected initially.
D.It provides a fallback option to revert to the old system if the pilot fails.
E.It eliminates the need for parallel testing with the old system.
AnswersA, B

Pilot conversion involves implementing the new system for a small group of users, such as one department or location. This allows the organization to test the system in a real production environment, identify issues, and make adjustments before rolling out to the entire organization. This reduces the risk of widespread failure.

Why this answer

Pilot conversion offers two key advantages: it enables live testing with a subset of users, allowing real-world validation and issue identification, and it facilitates incremental learning so that the implementation process can be refined before full deployment. These benefits reduce risk and improve the chances of a smooth organization-wide rollout.

Exam trap

The trap here is assuming that pilot conversion reduces training or eliminates parallel testing, when in fact it still requires training for all users and may still involve parallel runs for verification.

135
MCQmedium

An organization is implementing a custom ERP system. During user acceptance testing (UAT), critical bugs are found that affect core financial processing. The project sponsor suggests deploying the system on schedule and fixing bugs after go-live. What is the BEST course of action?

A.Delay go-live until all critical bugs are resolved and UAT is successfully completed
B.Go live as planned and fix bugs post-implementation
C.Accept the bugs with documented risk acceptance from management
D.Go live but include a rollback plan and deploy fixes immediately
AnswerA

Critical bugs affecting core financial processing mean the system cannot meet acceptance criteria; deploying anyway risks material financial misstatement. Delaying go-live until bugs are resolved and UAT passes satisfies the control objective that only validated systems enter production.

Why this answer

Deploying an ERP system with unresolved critical bugs in core financial processing violates the fundamental principle of system integrity and accuracy. UAT must be successfully completed to validate that the system meets business requirements and processes financial transactions correctly; going live with known critical defects introduces unacceptable risk of financial misstatement, regulatory non-compliance, and data corruption. Delaying go-live ensures that all critical bugs are resolved and retested, preserving the reliability of financial data and audit trails.

Exam trap

The trap here is that candidates may confuse 'risk acceptance' (Option C) as a valid management decision, but in the context of critical financial processing bugs, ISACA standards require resolution before go-live because accepted risks cannot ensure the integrity of financial data and auditability.

How to eliminate wrong answers

Option B is wrong because going live as planned with known critical bugs in core financial processing directly contradicts the ISACA requirement that UAT must be successfully completed before production deployment; post-implementation fixes cannot guarantee data integrity for transactions processed in the interim. Option C is wrong because risk acceptance from management does not override the technical necessity of resolving critical bugs that affect financial processing accuracy; accepted risks still expose the organization to potential financial loss, audit failures, and regulatory penalties. Option D is wrong because including a rollback plan and deploying fixes immediately does not address the fact that critical bugs will corrupt financial data from the moment of go-live; rollback only restores the previous state, it does not prevent the initial corruption, and immediate fixes cannot retroactively correct already-processed transactions.

136
MCQmedium

Which ITIL 4 guiding principle emphasizes understanding the current state and building on existing capabilities rather than starting from scratch?

A.Start where you are
B.Focus on value
C.Progress iteratively
D.Keep it simple
AnswerA

'Start where you are' directs teams to assess what already exists and reuse it, rather than discarding current capabilities. This directly satisfies the stem's requirement to build on existing capabilities instead of starting from scratch, avoiding unnecessary rework and cost.

Why this answer

Start where you are means assessing current services and processes to identify what can be reused or improved.

137
Multi-Selecteasy

Which TWO of the following are essential components of a disaster recovery plan (DRP)?

Select 2 answers
A.Steps for restoring IT systems
B.Detailed financial audit procedures
C.Employee performance reviews
D.List of critical contacts
E.Backup media rotation schedule
AnswersA, D

Restoring IT systems defines the recovery procedures and sequence needed to bring critical services back after disruption. Without documented restoration steps, the DRP cannot meet its recovery time and recovery point objectives, making it a core component.

Why this answer

Option A, steps for restoring IT systems, is correct because a DRP must define the documented procedures and sequence for recovering systems, applications, and data after a disruption, which is the plan's core operational purpose. Option D, a list of critical contacts, is correct because effective disaster recovery depends on reaching the right people—such as the DR team, vendors, and management—during an incident, so contact information is an essential DRP component. Option B, detailed financial audit procedures, is not part of a DRP; that belongs to financial auditing or accounting controls.

Option C, employee performance reviews, is an HR function unrelated to disaster recovery. Option E, a backup media rotation schedule, is a backup/recovery operational detail that supports data restoration but is not itself one of the essential DRP components being tested here.

Exam trap

The trap here is that candidates often confuse operational procedures like backup rotation schedules (Option E) with the essential recovery-focused components of a DRP, but the DRP itself does not include the rotation schedule—it only references the use of backups.

138
Multi-Selectmedium

An organization is developing a business continuity strategy for its key customer-facing application. The BIA determined an RTO of 2 hours and an RPO of 30 minutes. Which TWO strategies are most appropriate to meet these objectives?

Select 2 answers
A.Implement a hot standby site
B.Adopt a manual workaround process
C.Store backup tape at an offsite location
D.Use synchronous data replication to a secondary site
E.Perform daily full backups to tape
AnswersA, D

A hot standby site maintains continuously synchronised infrastructure with near-zero data loss, comfortably satisfying the 30-minute RPO and 2-hour RTO. Because systems run live and replicate in real time, failover completes within minutes, unlike warm or cold alternatives requiring rebuild time that would breach both objectives.

Why this answer

Option A (hot standby site) is correct because a hot standby keeps a fully operational, continuously synchronized environment ready to take over immediately, so the 2-hour RTO can be met with minimal failover time. Option D (synchronous data replication to a secondary site) is correct because synchronous replication commits writes to the secondary site before acknowledging them, giving an RPO of effectively zero, which is well within the required 30-minute RPO. Option B (manual workaround process) is not appropriate because manual procedures typically introduce delays and human error that cannot reliably satisfy a 2-hour RTO.

Option C (offsite tape storage) does not belong because retrieving and restoring tapes takes far longer than 2 hours and cannot meet a 30-minute RPO. Option E (daily full backups to tape) is unsuitable because a 24-hour backup interval yields an RPO of up to 24 hours, far exceeding the 30-minute requirement.

139
MCQmedium

An IT department is structured with a central group that manages infrastructure and security, while business units have their own IT staff for application support. This is an example of which IT organizational structure?

A.Matrix
B.Centralized
C.Decentralized
D.Hybrid
AnswerD

Hybrid structure combines centralised and decentralised functions, matching the stem's split between a central infrastructure and security group and business-unit IT staff handling application support. Central IT retains control over shared infrastructure and security, while business units keep local application expertise, satisfying both governance and responsiveness requirements.

Why this answer

A hybrid (or federated) structure combines centralized and decentralized elements, where some functions are centralized and others are distributed.

140
MCQeasy

Which type of disaster recovery test involves actually switching over to the alternate site and processing live transactions, but does not require the primary site to be shut down?

A.Simulation test
B.Full interruption test
C.Tabletop test
D.Parallel test
AnswerD

A parallel test processes live transactions at the alternate site while the primary site continues running, satisfying the stem's requirement that the primary is not shut down. Unlike full failover, both sites operate simultaneously, validating recovery capability without disrupting production.

Why this answer

Parallel testing is the correct answer because it involves processing live transactions at the alternate site while the primary site remains fully operational. This allows validation of the disaster recovery (DR) systems without risking a service outage, as both sites run concurrently and results are compared for consistency. Unlike a full interruption test, the primary site is not shut down, ensuring business continuity during the test.

Exam trap

The trap here is that candidates often confuse parallel testing with a full interruption test, mistakenly thinking that any test involving live transactions must require shutting down the primary site, but parallel testing explicitly avoids that by running both sites concurrently.

How to eliminate wrong answers

Option A is wrong because a simulation test involves a simulated disaster scenario where team members practice their roles, but it does not involve actual failover or processing of live transactions at the alternate site. Option B is wrong because a full interruption test requires the primary site to be shut down and all processing to be moved to the alternate site, which contradicts the condition that the primary site remains operational. Option C is wrong because a tabletop test is a discussion-based exercise where participants walk through disaster scenarios without any actual system failover or live transaction processing.

141
MCQhard

During an audit of patch management, the IS auditor notes that several critical patches have not been applied within the defined SLA. Which of the following is the BEST approach to evaluate the risk acceptance of these unpatched vulnerabilities?

A.Compute the aggregate risk score using a vulnerability management tool.
B.Review the risk acceptance documentation approved by the system owner and CISO.
C.Recommend immediate application of all missing patches.
D.Verify that the patches are not applicable to the environment.
AnswerB

Documented risk acceptance approved by the system owner and CISO evidences that the business knowingly accepted the unpatched vulnerabilities within its risk appetite. Reviewing that documentation lets the auditor evaluate whether acceptance was authorised, justified and consistent with policy.

Why this answer

The question asks how to evaluate the risk acceptance of unpatched vulnerabilities. Risk acceptance is a formal management decision that must be documented and approved by the appropriate authorities—typically the system owner and the CISO. Reviewing this documentation provides direct evidence that the organization has consciously accepted the risk, which is exactly what the auditor needs to evaluate.

Computing a risk score or recommending patching does not address whether the risk has been formally accepted.

Exam trap

CISA often tests the distinction between evaluating risk acceptance (reviewing documentation) and performing risk assessment or remediation (computing scores or patching), so candidates may incorrectly choose a technical action over a governance review.

How to eliminate wrong answers

Option A is wrong because computing an aggregate risk score quantifies the risk but does not evaluate whether that risk has been formally accepted by management. Option C is wrong because recommending immediate patching is a remediation action, not an evaluation of risk acceptance; it also ignores the possibility that the risk was deliberately accepted. Option D is wrong because verifying patch applicability is a technical validation step that determines if the patches are needed, but it does not assess whether the risk of not applying them has been accepted.

142
MCQmedium

An organization is implementing a data loss prevention (DLP) solution. Which of the following is the BEST approach to minimize false positives while ensuring sensitive data is protected?

A.Encrypt all outbound emails containing any attachment.
B.Deploy exact file matching against a database of known sensitive documents.
C.Use contextual analysis including user roles and data classification.
D.Apply keyword matching to all outbound emails.
AnswerC

Contextual analysis correlates user roles, data classification and destination, so DLP policies trigger only on genuinely risky transfers rather than every pattern match. This precision reduces false positives while preserving protection of sensitive data, satisfying both stem requirements simultaneously.

Why this answer

Contextual analysis (Option C) is the best approach because it reduces false positives by considering user roles, data classification, and behavioral patterns, ensuring that only genuinely risky data transfers are flagged. Unlike static methods, this dynamic analysis adapts to the organization's data governance policies, allowing legitimate business communications to proceed while still protecting sensitive information.

Exam trap

The trap here is that candidates often choose exact file matching (Option B) thinking it is the most precise, but they overlook its inability to handle data variations and its reliance on a static database, which leads to both false positives and false negatives in dynamic environments.

How to eliminate wrong answers

Option A is wrong because encrypting all outbound emails with attachments does not prevent data loss—it only protects data in transit, and it would generate massive false positives by treating all attachments as sensitive, including benign files. Option B is wrong because exact file matching against a database of known sensitive documents is too rigid; it cannot detect variations of sensitive data (e.g., modified versions or partial leaks) and would miss many real threats while still causing false positives if the database is incomplete. Option D is wrong because keyword matching to all outbound emails is prone to high false positives, as common words or phrases (e.g., 'confidential' in a non-sensitive context) trigger alerts, and it lacks the nuance to distinguish between legitimate and malicious use of sensitive terms.

143
MCQhard

An IS auditor is reviewing the IT governance of a financial services firm. The auditor discovers that the IT steering committee has approved a major core banking system upgrade, but the project lacks a formal business case and no post-implementation review is planned. Which of the following is the MOST significant risk arising from this situation?

A.The IT steering committee may not have the authority to approve such a project.
B.IT resources may be misallocated to projects that do not support business strategy.
C.The project may exceed its budget without proper justification.
D.The project may fail to meet technical specifications.
AnswerB

The absence of a formal business case means the project's strategic alignment and expected benefits are not evaluated. Without a post-implementation review, there is no verification that benefits were realized. This creates a significant risk that IT resources are invested in initiatives that do not deliver value or support business goals, leading to wasted resources and missed opportunities. This is the most critical governance risk.

Why this answer

The most significant risk is that without a formal business case, the project's alignment with business strategy and expected benefits are not established, and without a post-implementation review, there is no accountability for realizing those benefits. This can lead to misallocation of IT resources and failure to deliver value, which is a fundamental governance concern. Other risks, such as budget overruns or technical failures, are secondary to the strategic misalignment.

Exam trap

The trap here is focusing on tactical project risks like budget or technical issues, while overlooking the strategic governance risk of investing in initiatives without a business case or benefits realization review.

144
MCQmedium

A business continuity plan (BCP) includes a tabletop exercise once a year. An IS auditor finds that the exercise only involves IT staff. Which of the following is the BEST recommendation?

A.Perform a failover test of the production environment
B.Increase the frequency of IT-only exercises
C.Invite business process owners to participate in future exercises
D.Include a data restoration test in the exercise
AnswerC

Involving business process owners directly addresses the stem's constraint: the exercise excludes non-IT stakeholders. Business continuity depends on process recovery, not just infrastructure restoration, so owners validate recovery time objectives and interdependencies that IT staff cannot assess alone. Their participation tests cross-functional coordination, which is the exercise's core purpose.

Why this answer

The best recommendation is to invite business process owners to participate in future exercises because BCP is a business-wide initiative, not just IT. Their involvement ensures that business impact, recovery priorities, and cross-functional dependencies are properly tested. This addresses the auditor's finding that the exercise only involves IT staff.

Exam trap

CISA often tests the auditor's ability to recommend the most appropriate improvement, and candidates may choose technical fixes (like failover tests) instead of addressing the governance and business involvement gap.

How to eliminate wrong answers

Option A is wrong because a failover test of production is a technical recovery test, not a BCP tabletop exercise improvement, and it may be too disruptive. Option B is wrong because increasing frequency of IT-only exercises does not address the lack of business involvement, which is the core issue. Option D is wrong because including a data restoration test is a technical component and does not resolve the missing business representation.

145
MCQmedium

An organization is considering whether to build a custom application or purchase a commercial off-the-shelf (COTS) product. Which of the following factors would most strongly support a build decision?

A.Short time to market is critical.
B.The vendor offers a robust service-level agreement (SLA).
C.The required functionality is unique to the organization's competitive advantage.
D.The organization has limited in-house development resources.
AnswerC

Functionality delivering competitive advantage is organisation-specific and unlikely to exist in a COTS product, so purchasing would force costly customisation or forfeit differentiation. Building internally lets the organisation own and tailor that capability, satisfying the strategic requirement that drives the build decision.

Why this answer

When the required functionality is unique to the organization's competitive advantage, building a custom application is justified because COTS products cannot provide differentiated capabilities that create strategic value. Custom development allows the organization to tailor features, integrate proprietary processes, and maintain exclusive control over the intellectual property. This factor most strongly supports a build decision because it directly ties the software to business differentiation.

Exam trap

CISA often tests whether candidates can distinguish strategic differentiation (build) from operational efficiency (buy), so options emphasizing speed, SLAs, or resource constraints are distractors that actually favor buying.

How to eliminate wrong answers

Option A is wrong because a critical need for short time to market favors purchasing COTS, since custom development typically takes longer to deliver. Option B is wrong because a robust vendor SLA is a benefit of COTS procurement, not a reason to build; it reduces the risk of purchasing. Option D is wrong because limited in-house development resources is a constraint that argues against building and favors buying a COTS solution with vendor support.

146
MCQmedium

An IS auditor is reviewing the process for granting access to a critical financial system. The auditor finds that access requests are approved by the system owner but there is no segregation between the request and approval functions for emergency access. Which of the following is the BEST control to mitigate this risk?

A.Implement a break-glass procedure with post-event review
B.Require two-factor authentication for emergency access
C.Disable emergency access and require standard approval
D.Log all emergency access activities without review
AnswerA

A break-glass procedure grants emergency access under predefined conditions with logging, then mandates post-event review to validate and revoke it. This restores the missing segregation between request and approval by introducing independent retrospective scrutiny, mitigating the risk created when the system owner alone both requests and approves.

Why this answer

A break-glass procedure with post-event review directly addresses the lack of segregation between request and approval for emergency access by allowing immediate access while ensuring independent retrospective review. This compensates for the missing preventive segregation with a detective control that validates the emergency was legitimate. It preserves the ability to respond to incidents without waiting for standard approvals.

Exam trap

The trap here is choosing a preventive control (disable emergency access, add MFA) when the scenario already accepts that emergency access must exist; CISA expects a compensating detective control (break-glass with post-event review) that balances availability and accountability.

How to eliminate wrong answers

Option B is wrong because two-factor authentication strengthens authentication but does not compensate for the absence of segregation of duties between requesting and approving emergency access. Option C is wrong because disabling emergency access entirely could prevent timely response to critical incidents, creating an availability risk that outweighs the control benefit. Option D is wrong because logging without any review provides no assurance that emergency access was justified, so the risk remains unmitigated.

147
MCQmedium

An organization uses shared accounts for system administration. Which of the following is the BEST control to mitigate the risk of non-repudiation?

A.Changing the shared account password after each use.
B.Logging all commands executed by the shared account.
C.Requiring two-factor authentication for the shared account.
D.Implementing a privileged access management (PAM) solution with session recording.
AnswerD

Shared accounts destroy individual accountability, so non-repudiation requires attributing each privileged action to a named person. PAM with session recording achieves this by brokering access through unique credentials while capturing activity, letting administrators act without sharing passwords and enabling forensic attribution.

Why this answer

A PAM solution with session recording uniquely ties each privileged session to an authenticated individual, even when a shared account is used, because users check out credentials and their keystrokes/commands are captured under their own identity. This provides the attribution needed for non-repudiation, which is the ability to prove who performed a specific action. Password changes, logging, and MFA on the shared account do not identify which individual used it.

Exam trap

CISA often tests the distinction between authentication, logging, and accountability; candidates incorrectly assume that logging commands or adding MFA to a shared account provides non-repudiation, when only per-user attribution (e.g., PAM session recording) does.

How to eliminate wrong answers

Option A is wrong because rotating a shared password after each use only limits the window of exposure; it does not identify which individual used the account, so non-repudiation is not achieved. Option B is wrong because logging commands executed under a shared account records actions but cannot attribute them to a specific person, defeating non-repudiation. Option C is wrong because two-factor authentication on a shared account authenticates the account, not the individual, and the second factor may be shared or bypassed, so it still cannot prove who acted.

148
Multi-Selecthard

Which TWO of the following are indicators that an IS auditor may need to adjust the audit approach during fieldwork? (Select TWO.)

Select 2 answers
A.Inability to obtain sufficient appropriate audit evidence
B.Completion of the initial risk assessment
C.Audit team members are behind schedule
D.Management requests a change in audit scope
E.Higher than expected error rates in sample testing
AnswersA, E

Insufficient appropriate audit evidence prevents the auditor from reaching a conclusion against the audit objectives, so the planned procedures and scope must be revised. This indicator directly triggers a change in audit approach during fieldwork rather than being deferred to reporting.

Why this answer

Option A is correct because when an IS auditor cannot obtain sufficient appropriate audit evidence, the planned procedures are not yielding a reliable basis for conclusions, so the audit approach (for example, additional or alternative substantive testing, or revised reliance on controls) must be adjusted. Option E is correct because higher-than-expected error rates in sample testing indicate that the assessed level of control risk or the tolerable deviation/error rate may be wrong, requiring the auditor to expand testing, increase sample sizes, or reconsider the nature, timing, and extent of procedures. Option B is not correct because completing the initial risk assessment is a normal, planned phase of the audit that informs the approach rather than a fieldwork indicator that it must change.

Option C is not correct because being behind schedule is a project-management or resource issue, not audit evidence or risk information that by itself dictates a change in the audit approach. Option D is not correct because a management-requested scope change is a governance/engagement matter to be evaluated and approved, not an indicator arising from fieldwork evidence that the audit approach needs adjustment.

Exam trap

ISACA often tests the distinction between project management issues (like being behind schedule) and substantive audit evidence issues; candidates mistakenly select 'behind schedule' as a reason to adjust the audit approach, but it is a resource or timing problem, not a validity-of-evidence trigger.

149
MCQmedium

An IS auditor is performing a compliance audit of a company's data privacy practices. Which type of evidence would be most appropriate to verify that employees have completed mandatory privacy training?

A.Inspection of training completion records
B.Observation of a training session
C.Inquiry with the HR manager
D.Analytical procedures comparing training completion rates
AnswerA

Training completion records are documentary evidence generated by the learning system, directly showing whether each employee finished the mandatory privacy training. Inspection lets the auditor verify completion against the requirement, rather than relying on interviews or observation, which only confirm awareness or intent.

Why this answer

Inspection of training completion records provides documentary evidence that employees have actually completed the mandatory privacy training. This is a direct, tangible form of evidence that can be verified and tested. It is the most reliable and appropriate evidence for compliance verification because it shows a record of completion, not just intent or hearsay.

Exam trap

CISA often tests the reliability hierarchy of audit evidence; candidates may incorrectly choose inquiry or observation because they seem quicker, but inspection of records is the most reliable for compliance verification.

How to eliminate wrong answers

Option B is wrong because observing a training session only confirms that training is being delivered, not that all employees have completed it. Option C is wrong because inquiry with the HR manager yields verbal evidence, which is the least reliable and should be corroborated. Option D is wrong because analytical procedures compare rates but do not verify individual completion; they may highlight anomalies but are not direct evidence of completion.

150
MCQmedium

An organization is evaluating a vendor for a custom application development. The vendor states they are assessed at CMMI Level 2 (Managed). Which of the following best describes the implication of this rating?

A.The vendor's processes are defined and tailored from organization-wide standards.
B.The vendor's processes are continuously improved through quantitative feedback.
C.The vendor has a quantitatively managed process with statistical control.
D.The vendor's projects have a basic project management process that is planned and executed.
AnswerD

CMMI Level 2 (Managed) denotes that projects apply basic project management: requirements, planning, measurement and control are established per project, though organisation-wide standardisation is absent. This matches the stem's constraint of describing what a Level 2 rating implies for the vendor's development work.

Why this answer

CMMI Level 2 (Managed) indicates that the vendor has established basic project management processes to plan, execute, monitor, and control projects. This means projects are managed according to documented plans, with defined requirements, project planning, and configuration management, but processes are not yet standardized across the organization. Option D correctly captures this foundational level of process maturity.

Exam trap

The trap here is confusing CMMI Level 2 (Managed) with Level 3 (Defined) or Level 4 (Quantitatively Managed), leading candidates to select options that describe higher maturity levels where processes are standardized or statistically controlled.

How to eliminate wrong answers

Option A is wrong because it describes CMMI Level 3 (Defined), where processes are standardized and tailored from organization-wide standards, not Level 2. Option B is wrong because it describes CMMI Level 5 (Optimizing), where processes are continuously improved through quantitative feedback and innovation. Option C is wrong because it describes CMMI Level 4 (Quantitatively Managed), where processes are measured and controlled using statistical and quantitative techniques.

Page 1

Page 2 of 13

Page 3