Courseiva

Certified Information Systems Auditor CISA (CISA) — Questions 226–300

934 questions total · 13pages · All types, answers revealed

Page 3

Page 4 of 13

Page 5
226
MCQmedium

An IS auditor is evaluating the backup strategy for a system with a recovery point objective (RPO) of 15 minutes and a recovery time objective (RTO) of 2 hours. The current strategy is a full backup nightly to tape with tapes transported offsite weekly. Which finding is MOST significant?

A.Weekly offsite transport is unnecessary because the data centre already has fire suppression and redundant power.
B.The backup window may overlap with online transaction processing, degrading system performance for users.
C.The nightly full backup exceeds the 15-minute RPO, and weekly offsite transport increases the potential data loss window.
D.Tape media is less durable than disk, so the backup may be unreadable when restoration is attempted.
AnswerC

A nightly full backup means up to 24 hours of data could be lost, far exceeding the 15-minute RPO, and weekly offsite shipment means recovery after a site loss could depend on tapes that are days old. This is the most significant finding because the strategy cannot meet the defined recovery objectives at all, leaving the business exposed to substantial data loss and extended outage.

Why this answer

The strategy must be evaluated against the stated RPO and RTO. A nightly full backup permits up to a day of data loss against a fifteen-minute RPO, and weekly offsite shipment means a site loss could force recovery from tapes several days old, also jeopardizing the two-hour RTO. The dominant finding is therefore the fundamental inability of the current approach to meet the defined recovery objectives, which requires a redesign such as more frequent incremental or continuous replication.

Exam trap

The trap here is focusing on tape durability or backup window performance instead of measuring the backup frequency and offsite cadence against the stated RPO and RTO.

227
MCQeasy

Which of the following is the PRIMARY purpose of a service desk?

A.To monitor network performance
B.To manage IT assets
C.To perform root cause analysis
D.To provide a single point of contact for incidents and service requests
AnswerD

A service desk exists to give users one consistent entry point for logging incidents and service requests, ensuring nothing is lost across multiple channels. This single-point-of-contact function is its defining purpose, distinct from resolution, which second-level and specialist teams perform.

Why this answer

The service desk acts as a single point of contact for IT support.

228
Multi-Selecthard

An IS auditor is reviewing an organization's IT service continuity plan (ITSCP) that supports its business continuity plan (BCP). The auditor finds that the ITSCP includes recovery strategies for critical systems but lacks details on roles and responsibilities during a disaster. Which TWO of the following should the auditor recommend to address this gap? (Choose two.)

Select 2 answers
A.Align the ITSCP with the BCP by mapping IT recovery times to business process RTOs.
B.Conduct regular testing of the ITSCP through tabletop exercises.
C.Document detailed recovery procedures for each critical system.
D.Define a crisis management team with clear roles and decision-making authority.
E.Establish an emergency operations center (EOC) with assigned staff and contact information.
AnswersD, E

A crisis management team with defined roles ensures that during a disaster, there is clear leadership and decision-making. This addresses the gap in roles and responsibilities. The team should include representatives from IT, business units, and communications. Clear authority helps avoid confusion and delays. This is a key recommendation to improve the ITSCP's effectiveness and alignment with the BCP.

Why this answer

The ITSCP lacks details on roles and responsibilities during a disaster. To address this, the auditor should recommend defining a crisis management team with clear roles and establishing an emergency operations center with assigned staff and contact information. These actions directly provide the missing structure for decision-making and coordination.

Documenting recovery procedures, testing, and aligning with BCP are important but do not specifically fill the gap of roles and responsibilities.

Exam trap

The trap here is selecting testing or procedure documentation as the primary fix, when the specific deficiency is the absence of defined roles and responsibilities, which are best addressed by establishing a crisis management team and an emergency operations center.

229
Multi-Selecthard

An IS auditor is evaluating the reliability of audit evidence obtained from an IT system. Which TWO of the following factors most directly affect the reliability of the evidence? (Choose two.)

Select 2 answers
A.The format in which the evidence is presented (e.g., paper vs. electronic).
B.The cost of obtaining the evidence.
C.The effectiveness of the controls over the evidence's completeness and accuracy.
D.The qualifications of the IS auditor performing the review.
E.The independence of the provider of the evidence.
AnswersC, E

The effectiveness of controls over the completeness and accuracy of the evidence directly impacts its reliability. If the system that generates the evidence lacks proper controls, the evidence may be incomplete or inaccurate. The auditor must assess whether the controls ensure the data is reliable. This is a core consideration in IS auditing, as evidence from systems with strong controls is more trustworthy.

Why this answer

The reliability of audit evidence is directly influenced by the independence of the evidence provider and the effectiveness of controls over its completeness and accuracy. Independent sources are less likely to be biased, and strong controls ensure the evidence is accurate and complete. Auditor qualifications, cost, and format do not directly affect the inherent reliability of the evidence, although they may influence the auditor's evaluation or selection of evidence.

Exam trap

The trap here is confusing factors that affect the audit process (like auditor qualifications or cost) with factors that directly affect the reliability of the evidence itself.

230
MCQmedium

Which of the following is a permanent file item in an IS audit working paper?

A.Confirmation letters from vendors
B.Current year's audit program
C.Organizational chart of the IT department
D.List of audit findings for the current year
AnswerC

Permanent files hold enduring reference material relevant across multiple audits, such as organisational charts, policies and system inventories. An IT department organisational chart retains ongoing relevance to governance and segregation-of-duties assessments, unlike current-year working papers that are superseded each engagement.

Why this answer

The organizational chart of the IT department is a permanent file item because it documents the entity's structure and is retained across multiple audit engagements. Permanent files contain information of continuing relevance, such as organizational charts, accounting manuals, and long-term contracts. Current year's audit program and findings are current file items, and confirmation letters are also current file evidence.

Exam trap

CISA often tests the distinction between permanent and current audit files, and candidates frequently misclassify engagement-specific evidence like audit programs or findings as permanent.

How to eliminate wrong answers

Option A is wrong because vendor confirmation letters are audit evidence gathered for the current engagement and belong in the current file. Option B is wrong because the current year's audit program is specific to the engagement and is a current file item. Option D is wrong because the list of audit findings for the current year is engagement-specific and belongs in the current file.

231
MCQmedium

An IS auditor is reviewing the network segmentation of a retail company's cardholder data environment (CDE). The auditor finds that the CDE and the corporate user VLAN are separated by a firewall, but the same flat Layer 2 domain spans both segments, and no internal segmentation firewall exists between the CDE web tier and the CDE database tier. Which of the following findings should the auditor report as the GREATEST risk?

A.The CDE and corporate VLAN share a flat Layer 2 domain, allowing lateral movement without passing through the firewall.
B.The corporate VLAN should be moved into the CDE so that all traffic is inspected by the same firewall policy.
C.The firewall separating the CDE and corporate VLAN is a single point of failure and should be deployed in a high-availability pair.
D.The absence of an internal segmentation firewall between the web tier and the database tier is the greatest risk.
AnswerA

A shared Layer 2 domain means hosts in the corporate VLAN and the CDE can communicate at the data-link layer, bypassing the firewall that was intended to be the sole control point. An attacker on a compromised workstation could reach CDE hosts directly via ARP and MAC-level traffic, defeating the segmentation the organization believes is in place. This is the most severe issue because the compensating control does not actually enforce the separation it claims to provide.

Why this answer

The critical issue is that the CDE and corporate network share a flat Layer 2 domain, so hosts can communicate via ARP and MAC-level traffic without traversing the firewall. This silently defeats the intended segmentation and enables lateral movement from a compromised corporate workstation into the cardholder data environment. Eliminating the shared broadcast domain and forcing all inter-segment traffic through the firewall restores the control the organization believes is operating.

Exam trap

The trap here is assuming that a firewall between VLANs guarantees isolation, when a shared Layer 2 domain allows traffic to bypass the firewall entirely.

232
MCQeasy

Which of the following is the BEST indicator that an organization's incident management process is effective?

A.The average time to resolve incidents is under 1 hour
B.The number of incidents reported per month is increasing
C.All incidents are logged within 10 minutes of detection
D.The percentage of recurring incidents is decreasing over time
AnswerD

A falling recurrence rate evidences root cause elimination rather than repeated firefighting, showing problems are fixed permanently. This directly satisfies the effectiveness indicator, since volume alone or speed of closure does not prove the process prevents incidents from returning.

Why this answer

The best indicator of an effective incident management process is a decreasing percentage of recurring incidents over time, because it demonstrates that root cause analysis is being performed and corrective actions are preventing repeat occurrences. This is a lagging indicator of process maturity — it shows the organization is learning from incidents, not just resolving them quickly. Metrics like MTTR or logging speed measure efficiency, not effectiveness.

Exam trap

CISA often tests the distinction between efficiency metrics (MTTR, logging speed) and effectiveness metrics (recurrence rate, root cause elimination), tricking candidates into picking the fastest-sounding operational metric.

How to eliminate wrong answers

Option A is wrong because a low average resolution time (under 1 hour) measures efficiency, not effectiveness — an organization could be closing tickets quickly without fixing root causes, leading to repeat incidents. Option B is wrong because an increasing number of reported incidents could indicate either improved detection (good) or worsening security posture (bad); it is ambiguous and not a reliable effectiveness indicator. Option C is wrong because logging incidents within 10 minutes of detection measures process compliance and timeliness, not whether the process actually reduces risk or prevents recurrence.

233
MCQmedium

A company is outsourcing software development. What is the IS auditor's PRIMARY concern?

A.The vendor's development methodology
B.Protection of intellectual property and data
C.The vendor's financial stability
D.Compliance with service level agreements
AnswerB

Outsourcing transfers code and data to a third party, so the auditor's primary concern is safeguarding intellectual property and confidential data through contractual controls, access restrictions and monitoring, since loss or misuse directly threatens the organisation's assets and compliance obligations.

Why this answer

Protection of intellectual property and data is the primary concern for an IS auditor when outsourcing software development because it represents the highest risk to the organization. While vendor methodology, financial stability, and SLA compliance are important, they are secondary to ensuring that sensitive data and proprietary information are safeguarded against unauthorized access or disclosure.

234
Multi-Selecthard

Which THREE are core components of a comprehensive identity and access management (IAM) system? (Choose three.)

Select 3 answers
A.Virtual private network (VPN) for remote network access.
B.Data loss prevention (DLP) to prevent data exfiltration.
C.Single sign-on (SSO) for simplified authentication.
D.Privileged access management (PAM) for managing administrative accounts.
E.Role-based access control (RBAC) for assigning permissions based on job roles.
AnswersC, D, E

SSO lets users authenticate once and access multiple systems through a trusted identity provider, centralising credential verification. It is a core IAM component because it reduces password sprawl while preserving authentication assurance across federated applications.

Why this answer

Single sign-on (SSO) is a core IAM component because it centralizes authentication so users log in once and gain access to multiple applications via federated protocols such as SAML 2.0 or OIDC, directly addressing authentication and access convenience. Privileged access management (PAM) is core IAM because it secures, vaults, and audits administrative and high-risk accounts (e.g., root, domain admin) with session recording, credential rotation, and just-in-time elevation. Role-based access control (RBAC) is core IAM because it is the authorization model that assigns permissions based on job roles, enforcing least privilege through role-to-permission mappings.

A VPN is a network access/transport control, not an identity or access management function, and DLP is a data-centric security control for preventing exfiltration, so neither belongs to the core IAM component set.

Exam trap

ISACA often tests the distinction between infrastructure security tools (VPN, DLP) and core IAM functions (authentication, authorization, administration). The trap is confusing network-level or data-level controls with identity-centric components that directly manage user access rights and authentication workflows.

235
MCQmedium

An organization is considering outsourcing its IT infrastructure management. Which of the following is the MOST important factor to include in the service level agreement (SLA)?

A.Definition of key performance indicators (KPIs) and reporting frequency.
B.List of hardware and software to be managed.
C.Staffing levels and qualifications of vendor personnel.
D.Price reduction clauses for non-compliance.
AnswerA

Defined KPIs with reporting frequency make the provider's performance measurable and enforceable, directly satisfying the SLA's need for objective, auditable service commitments. Without quantified metrics and a stated reporting cadence, the organisation cannot verify delivery, trigger remedies, or evidence due diligence to auditors assessing third-party management.

Why this answer

The most important element of an SLA for outsourced IT infrastructure is a clear definition of KPIs and the frequency of reporting against them, because KPIs are the measurable criteria that determine whether the vendor is meeting the agreed service levels. Without well-defined KPIs and reporting, the SLA cannot be enforced, performance cannot be objectively assessed, and remedies (including penalties) have no basis. This is the foundation on which all other SLA provisions rest.

Exam trap

CISA often tests the distinction between foundational SLA elements (KPIs and reporting) and secondary provisions (penalties, staffing, inventory) — candidates are tempted to pick penalty clauses, but without defined KPIs and reporting, penalties cannot be applied.

How to eliminate wrong answers

Option B is wrong because a list of hardware and software is a scope/inventory artifact, not the most critical SLA element — scope matters, but without measurable KPIs the SLA cannot verify service delivery. Option C is wrong because staffing levels and qualifications are vendor-internal operational details; while relevant to capability, they are not the primary SLA metric and can be addressed in the contract's resource clauses. Option D is wrong because price reduction clauses for non-compliance are remedies that only function once KPIs and reporting are defined — penalties without measurable KPIs are unenforceable, making this a secondary, dependent provision.

236
MCQeasy

An organization's mobile device management (MDM) policy requires that all corporate data on employee-owned smartphones be protected. Which control best ensures that corporate data can be remotely wiped without affecting personal data?

A.Disabling the ability to copy/paste between corporate and personal apps
B.Implementing a containerization solution that separates work and personal profiles
C.Requiring a strong password and biometric authentication
D.Enforcing a full device encryption policy
AnswerB

Containerisation creates a managed, encrypted work partition on the employee-owned device, isolating corporate applications and data from the personal profile. A selective wipe then removes only the container's contents, leaving personal photos, messages and apps untouched, satisfying the policy's requirement to protect corporate data without affecting personal data.

Why this answer

Containerization (also known as dual-persona or sandboxing) creates a separate, encrypted container on the device for corporate apps and data. This allows the MDM to issue a selective wipe command that destroys only the container and its contents, leaving the user's personal apps, photos, and settings untouched. Without containerization, a remote wipe would typically erase the entire device, including all personal data.

Exam trap

The trap here is that candidates often confuse 'full device encryption' (Option D) with selective wipe capability, assuming encryption alone allows granular data removal, when in fact encryption without containerization still requires wiping the entire encrypted volume.

How to eliminate wrong answers

Option A is wrong because disabling copy/paste between corporate and personal apps prevents data leakage but does not enable selective remote wipe; it is a data loss prevention (DLP) control, not a wipe mechanism. Option C is wrong because requiring a strong password and biometric authentication controls device access but has no effect on the scope of a remote wipe; it is an authentication control, not a data separation or wipe control. Option D is wrong because enforcing full device encryption protects data at rest but does not differentiate between corporate and personal data; a remote wipe under full encryption would still erase the entire device, including personal data.

237
MCQmedium

An IS auditor is reviewing the physical security controls for a data center. The auditor observes that the data center has a raised floor, a fire suppression system, and biometric access controls. The auditor also notes that the data center is located in a region prone to flooding. Which of the following controls is MOST important to mitigate the risk of flooding?

A.Elevating the data center floor above the expected flood level.
B.A sump pump system in the basement.
C.Water detection sensors under the raised floor.
D.A fire suppression system that also removes water.
AnswerA

Elevating the data center floor above the expected flood level is a preventive physical control that directly reduces the risk of floodwater reaching the equipment. By placing the data center on a higher floor or raising the entire facility, water from a flood would need to rise significantly before affecting operations. This is the most effective way to mitigate flood risk, as it addresses the threat at its source by keeping water out.

Why this answer

Elevating the data center floor above the expected flood level is the most important control because it prevents floodwater from reaching critical equipment. It is a preventive measure that directly addresses the flood risk, whereas other options like sensors or pumps are detective or mitigating. In flood-prone areas, physical elevation is a fundamental design consideration for data center resilience.

Exam trap

The trap here is confusing detective controls like water sensors with preventive controls, when the question asks for the best mitigation of flood risk.

238
Multi-Selecteasy

An IT governance framework should include which TWO key components? (Select exactly two.)

Select 2 answers
A.User training
B.Vendor lock-in
C.Strategic alignment
D.Network firewall rules
E.Performance measurement
AnswersC, E

Strategic alignment ensures IT investments and initiatives directly support organisational objectives, satisfying the governance requirement to link technology decisions with business strategy. COBIT and ISO/IEC 38500 both identify this linkage as a core governance component, distinct from operational execution, because governance must direct where IT resources are deployed rather than merely manage their day-to-day running.

Why this answer

Strategic alignment (C) is a core component of any IT governance framework because governance must ensure that IT investments, priorities, and initiatives directly support the organization's business goals and objectives. Performance measurement (E) is equally essential, as governance requires metrics, KPIs, and monitoring mechanisms (such as balanced scorecards or COBIT goals) to verify that IT delivers value, manages risk, and meets agreed service levels. Together, these two components reflect the dual governance mandate of directing IT toward business strategy while measuring whether it actually delivers.

The other options do not belong: user training (A) is an operational capability rather than a governance component, vendor lock-in (B) is a risk to be avoided, not a framework element, and network firewall rules (D) are technical security controls, not governance-level components.

Exam trap

The trap here is confusing operational IT controls (training, firewalls) with governance framework components — CISA candidates often pick 'user training' because it sounds foundational, but governance is about direction and oversight, not execution.

239
MCQmedium

An IS auditor is leading an audit engagement and discovers that a key member of the audit team lacks the technical expertise to evaluate a newly implemented cloud encryption control. The audit manager insists the team member proceed anyway to save time. According to ISACA IT Audit Standards, what is the MOST appropriate action for the IS auditor to take?

A.Proceed with the audit as planned and note the limitation in the audit report.
B.Delegate the entire engagement to the audit manager who has more experience.
C.Expand the audit scope to include additional systems to compensate for the knowledge gap.
D.Obtain the necessary expertise through additional training or by engaging a qualified specialist.
AnswerD

ISACA IT Audit Standards require that auditors possess or obtain the competencies necessary to perform the engagement. When a team member lacks the technical skill to evaluate a control, the auditor should either ensure appropriate training or bring in a qualified specialist. This preserves the integrity of the audit opinion and complies with the standards' competence requirement, rather than accepting an inherent limitation.

Why this answer

ISACA IT Audit Standards require that the audit team collectively possess the competencies needed for the engagement. When a specific technical skill is missing, the auditor should acquire it through training or engage a qualified specialist. This preserves the validity of the audit opinion and satisfies professional standards.

Proceeding with known incompetence, reassigning the entire engagement, or expanding scope does not remedy the underlying proficiency deficiency.

Exam trap

The trap here is assuming that documenting a competence limitation in the report excuses the auditor from the standard's requirement to obtain the necessary expertise.

240
MCQmedium

An organization experiences a ransomware attack that encrypts critical files. Which of the following is the BEST recovery strategy to minimize data loss?

A.Disconnect the network and rebuild systems from scratch
B.Pay the ransom to decrypt files
C.Restore from offline backups taken before the attack
D.Use system restore points on the same network
AnswerC

Offline backups taken before the attack remain unencrypted and unreachable by ransomware, satisfying the requirement to minimise data loss. Unlike replicas or online backups, which may also be encrypted or corrupted, offline media preserves a clean recovery point, enabling restoration of critical files without paying the ransom.

Why this answer

Restoring from offline backups taken before the attack ensures that the recovered data is clean and free from encryption, as the ransomware cannot modify backups that are not connected to the network. This strategy minimizes data loss by reverting to the most recent known-good state without relying on potentially compromised or incomplete system restore points.

Exam trap

The trap here is that candidates may choose Option D (system restore points) because they seem convenient and built-in, but they fail to realize that ransomware specifically targets and deletes these snapshots, making them unreliable for recovery.

How to eliminate wrong answers

Option A is wrong because rebuilding systems from scratch without backups results in complete data loss, as no user or application data is preserved. Option B is wrong because paying the ransom does not guarantee decryption, encourages further attacks, and may leave backdoors or incomplete file recovery. Option D is wrong because system restore points on the same network are often encrypted by the ransomware, as they reside on accessible storage, and they typically only restore system files, not user data.

241
MCQeasy

Which of the following evidence types involves the auditor independently performing a control procedure to verify its effectiveness?

A.Inspection
B.Observation
C.Inquiry
D.Re-performance
AnswerD

Re-performance involves the auditor independently executing the control procedure or calculation and comparing the result with the organisation's own performance. This directly satisfies the stem's constraint of independently verifying effectiveness, unlike inspection or observation, which only confirm that a control exists or was performed.

Why this answer

Re-performance involves the auditor independently executing a control procedure or recalculation to verify its effectiveness. This provides direct evidence of the control's operation. Inspection, observation, and inquiry are less direct forms of evidence.

Exam trap

CISA often tests the reliability of different evidence-gathering techniques, and candidates may confuse re-performance with observation or inspection, overlooking that re-performance provides the strongest evidence of control operation.

How to eliminate wrong answers

Option A is wrong because inspection involves examining records or documents, which provides indirect evidence of control effectiveness. Option B is wrong because observation involves watching a process being performed, but it only provides evidence at the time of observation and may be affected by the observer effect. Option C is wrong because inquiry involves asking questions, which yields verbal evidence that is generally less reliable and must be corroborated.

242
MCQeasy

An organization wants to ensure that data is not retained longer than necessary. Which of the following is the BEST control to implement?

A.Encrypt all data at rest
B.Implement a backup retention policy
C.Use role-based access controls
D.Define and enforce data retention schedules
AnswerD

Retention schedules ensure data is deleted when no longer needed.

Why this answer

Defining and enforcing data retention schedules directly addresses the requirement to not retain data longer than necessary by specifying precise timeframes for data deletion or archival. This control ensures compliance with legal, regulatory, and business needs by automating the lifecycle management of data, such as through expiration policies in object storage (e.g., S3 Lifecycle rules) or database TTL (time-to-live) settings. Without such schedules, data may persist indefinitely, increasing storage costs and regulatory risk.

Exam trap

The trap here is that candidates confuse data retention (how long data is kept) with data protection mechanisms like encryption or access control, or they mistakenly think backup retention policies are sufficient for primary data lifecycle management.

How to eliminate wrong answers

Option A is wrong because encrypting data at rest protects confidentiality but does not control how long data is stored; it can even hinder deletion if encryption keys are not properly managed. Option B is wrong because a backup retention policy governs copies of data for recovery purposes, not the primary data itself; it may inadvertently retain data longer than necessary if not aligned with the primary retention schedule. Option C is wrong because role-based access controls (RBAC) restrict who can access or modify data but do not enforce time-based deletion or retention limits.

243
MCQmedium

An IS auditor is planning an audit of a cloud-hosted application and needs to determine whether the cloud provider's controls are adequate. The provider offers a SOC 2 Type II report. Which of the following should the auditor do FIRST?

A.Request a bridge letter to cover the gap between the report period and the current date.
B.Accept the SOC 2 Type II report as sufficient evidence without further review.
C.Review the report's scope, period, and the service auditor's opinion to determine its relevance to the audit objectives.
D.Perform independent penetration testing of the cloud provider's environment.
AnswerC

Before relying on a SOC 2 report, the auditor must confirm that its scope covers the relevant trust services criteria and systems, that the period aligns with the audit period, and that the opinion is unqualified or appropriately qualified. Only then can the auditor assess whether the report provides sufficient evidence. Using the report without this evaluation could lead to inappropriate reliance.

Why this answer

The auditor should first evaluate whether the SOC 2 Type II report is relevant and reliable by examining its scope, period, and opinion. This determines whether the report can be used as evidence or whether additional procedures are needed. Bridge letters and independent testing are secondary considerations.

Uncritical acceptance is not acceptable under audit standards.

Exam trap

The trap here is treating the mere existence of a SOC 2 report as sufficient evidence without evaluating its scope, period, and opinion.

244
MCQeasy

An organization has a policy requiring all employees to complete annual information security awareness training. Which of the following is the BEST way to verify compliance with this policy?

A.Conduct phishing simulation tests
B.Survey employees about their satisfaction with training
C.Interview HR about training content
D.Review training completion records from the learning management system
AnswerD

Reviewing learning management system completion records provides direct, timestamped evidence that each employee finished the annual training, satisfying the policy's compliance verification requirement. Unlike interviews or observation, which sample behaviour, the LMS record is authoritative and auditable per employee, enabling exception reporting for those overdue.

Why this answer

The policy specifically requires employees to complete annual information security awareness training. The most direct and objective way to verify compliance is to examine the training completion records maintained by the learning management system (LMS). These records provide evidence of who has completed the training and when, directly confirming adherence to the policy.

Other methods may assess effectiveness or satisfaction but do not verify completion.

Exam trap

CISA often tests the distinction between verifying compliance (checking if requirements are met) and assessing effectiveness (evaluating impact or quality), so candidates may incorrectly choose phishing simulations or surveys, which measure effectiveness rather than compliance.

How to eliminate wrong answers

Option A is wrong because phishing simulation tests measure employee behavior and susceptibility to phishing, not whether they have completed the required training. Option B is wrong because surveying employee satisfaction with training assesses quality and perception, not compliance with the completion requirement. Option C is wrong because interviewing HR about training content provides information about the training material itself, not evidence that employees have completed it.

245
MCQmedium

An auditor is reviewing IT asset management processes. The auditor finds that several servers running an older operating system are still in production, even though the vendor has ended support. What is the primary risk associated with this finding?

A.Lack of vendor support and security patches
B.Non-compliance with software licensing
C.Incompatibility with new hardware
D.Increased licensing costs
AnswerA

Once a vendor ends support, no further security patches or vulnerability fixes are released, leaving known exploits permanently unpatched on production servers. This exposes the organisation to compromise and non-compliance, since compensating controls cannot fully substitute for vendor-supplied remediation.

Why this answer

Unsupported software no longer receives security patches, making the systems vulnerable to exploitation.

246
MCQmedium

An organization has implemented a clean desk policy. Which of the following is the BEST audit procedure to verify compliance?

A.Reviewing security camera footage of office areas
B.Reviewing the policy document and employee acknowledgments
C.Interviewing employees about the policy
D.Conducting unannounced inspections of workstations
AnswerD

Unannounced inspections provide direct, first-hand evidence of whether sensitive documents and media are actually secured when staff leave workstations, satisfying the need to verify real compliance rather than assumed adherence. Announced checks or policy reviews only confirm intent, not operational practice.

Why this answer

Surprise walkthroughs provide a realistic view of daily compliance, unlike scheduled inspections.

247
MCQhard

During a review of firewall rule sets, an IS auditor identifies a rule that allows 'any-any' traffic from an internal subnet to the DMZ. The rule was implemented six months ago based on a business request that has since been completed. The firewall administrator explains that the rule was kept for convenience. Which of the following is the BEST audit recommendation?

A.Conduct a penetration test to assess the risk
B.Remove the rule immediately and verify no impact
C.Document the rule with a risk acceptance signed by management
D.Modify the rule to allow only specific ports and protocols
AnswerB

The any-any rule grants broad internal-to-DMZ access with no business justification, violating least privilege and expanding the attack surface. Removing it and verifying no impact eliminates the exposure while confirming that no legitimate dependency remains.

Why this answer

The rule is overly permissive, no longer justified by business need, and poses an unnecessary risk. The best recommendation is to remove the rule immediately and verify no impact, as it aligns with the principle of least privilege and reduces the attack surface.

Exam trap

The trap is choosing 'modify the rule' because it seems less disruptive, but the rule is no longer needed, so removal is the best practice; also, 'any-any' is too broad to simply modify without understanding requirements.

How to eliminate wrong answers

Option A is wrong because a penetration test is a point-in-time assessment and does not address the immediate risk; it also does not remove the rule. Option C is wrong because documenting the rule with risk acceptance is inappropriate when the rule is no longer needed; risk acceptance should be a last resort after risk mitigation. Option D is wrong because modifying the rule to allow specific ports is a mitigation, but the rule is no longer required, so removal is better; also, 'any-any' includes all ports, so modifying might still leave unnecessary access.

248
MCQhard

A large financial institution is implementing a new core banking system to replace a legacy system. The project has been underway for 18 months and is behind schedule. User acceptance testing (UAT) has revealed significant data integrity issues, including missing customer records and incorrect interest calculations. The project manager, under pressure from senior management to meet a regulatory deadline, proposes going live with a promise to fix the issues in a post-implementation phase. The development team has been making ad hoc code changes directly in the test environment without version control or proper testing. Additionally, the IS auditor discovers that the business requirements were never formally signed off by the user community; only verbal approvals were obtained. The project has consumed 90% of the budget but only 60% of the functionality is tested. Which of the following is the BEST course of action for the IS auditor to recommend?

A.Allow the go-live with a formal post-implementation support plan and a dedicated team to address defects.
B.Recommend halting the go-live until the business requirements are formally signed off and UAT is completed successfully with all critical defects resolved.
C.Suggest a phased go-live, releasing the tested modules to production while continuing development on the remaining modules.
D.Escalate the issues to the board of directors and recommend immediate termination of the project.
AnswerB

Halting go-live addresses the root governance failures: unsigned business requirements and incomplete UAT with unresolved critical defects. Proceeding would expose the institution to regulatory breach and data corruption, so the auditor must recommend remediation before implementation rather than accepting post-implementation fixes.

Why this answer

The project lacks formal sign-off on business requirements, has unresolved critical data integrity issues, and has been making uncontrolled code changes without version control. Going live under these conditions would violate ISACA's IS acquisition and implementation standards, which require that all critical defects be resolved and UAT be successfully completed before production deployment. The regulatory deadline does not justify bypassing these fundamental controls, as post-implementation fixes cannot guarantee data integrity and could lead to regulatory penalties.

Exam trap

The trap here is that candidates may choose Option A because they think a post-implementation support plan is a pragmatic compromise, but the CISA exam emphasizes that going live with unresolved critical defects and uncontrolled code changes violates fundamental SDLC controls and ISACA's IS acquisition and implementation standards.

How to eliminate wrong answers

Option A is wrong because allowing go-live with a post-implementation support plan ignores the fact that the project has already consumed 90% of the budget with only 60% functionality tested, and the ad hoc code changes without version control indicate a lack of configuration management that would likely cause more defects in production. Option C is wrong because a phased go-live assumes that some modules are fully tested and stable, but the UAT has revealed systemic data integrity issues (missing records, incorrect interest calculations) that affect the entire system, not just untested modules, and the lack of formal requirements sign-off means even tested modules may not meet user needs. Option D is wrong because immediate termination is too drastic given that the project is 60% tested and the regulatory deadline is a real constraint; the auditor should first recommend corrective actions (formal sign-off, controlled testing, defect resolution) before considering termination.

249
MCQeasy

Which of the following is the BEST indicator of the effectiveness of a security awareness program?

A.Reduction in the number of successful phishing attacks.
B.Positive feedback from employees about the training.
C.Number of employees who completed the training.
D.Average test scores on post-training assessments.
AnswerA

Successful phishing attacks measure actual user behaviour under real adversarial conditions, directly evidencing whether awareness training changed outcomes. Completion rates and quiz scores reflect attendance, not resistance, so a sustained reduction in successful phishing satisfies the stem's effectiveness indicator by demonstrating transferred vigilance rather than passive knowledge.

Why this answer

A decrease in successful phishing attacks demonstrates behavioral change.

250
Multi-Selecthard

Which TWO of the following are indicators of poor project governance that an IS auditor should identify?

Select 2 answers
A.Scope changes are frequently requested and approved verbally.
B.Project progress reports are inconsistent and lack key metrics.
C.Project team uses an agile methodology.
D.Project status meetings are held weekly.
E.The project budget is reallocated across phases.
AnswersA, B

Verbal approval of frequent scope changes bypasses formal change control, the mechanism that preserves baselined scope, cost and schedule. This directly evidences weak governance, since the stem asks for indicators of poor project governance: undocumented, unauthorised scope creep escapes audit trail and steering committee oversight.

Why this answer

Option A is correct because approving scope changes verbally indicates a lack of formal change control procedures, which is a hallmark of poor project governance; without documented approval, scope creep and accountability issues arise. Option B is correct because inconsistent progress reports lacking key metrics (e.g., earned value, schedule variance, milestone completion) mean the project lacks reliable monitoring and oversight, preventing stakeholders from making informed decisions. Option C is not an indicator of poor governance because agile methodology is a legitimate, structured project management approach when properly governed.

Option D is not an indicator of poor governance because weekly status meetings are a normal and often beneficial communication practice. Option E is not an indicator of poor governance because reallocating budget across phases can be a legitimate, approved response to changing project needs when done through proper change control.

Exam trap

The trap here is that candidates may confuse agile methodology with poor governance, but agile includes its own governance mechanisms (e.g., sprint reviews, backlog grooming, definition of done) that, when followed, do not indicate weak oversight.

251
Multi-Selecteasy

Which TWO of the following are benefits of implementing an IT governance framework?

Select 2 answers
A.Improved risk management and mitigation
B.Reduction in IT staff headcount
C.Enhanced regulatory compliance
D.Reduced IT operational costs
E.Elimination of all IT project failures
AnswersA, C

Frameworks like COBIT emphasize risk management.

Why this answer

Implementing an IT governance framework, such as COBIT or ISO/IEC 38500, establishes structured policies, procedures, and controls that directly improve risk management and mitigation. By defining clear roles, accountability, and risk appetite, the framework ensures that risks are systematically identified, assessed, and treated, rather than being managed ad hoc. This aligns IT strategy with business objectives and embeds risk management into daily operations.

Exam trap

The trap here is that candidates often confuse the benefits of an IT governance framework with operational cost-cutting or headcount reduction, when in fact the framework's core value is in aligning IT with business goals, improving risk management, and ensuring compliance, not in directly reducing expenses or eliminating failures.

252
MCQmedium

An IS auditor is reviewing the firewall rule base. Which of the following findings would be of MOST concern?

A.A rule that has not been reviewed for 18 months
B.A rule that permits traffic from a specific IP to a database server on port 1433
C.A rule that allows any source IP to access a critical server on port 443
D.A rule that allows any service from the Internet to the internal network
AnswerD

A rule permitting any service from the Internet to the internal network exposes every internal host and port to unrestricted external access, effectively bypassing perimeter segmentation. This is the most severe finding because it enables broad exploitation, far exceeding risks from individual permissive rules.

Why this answer

A rule that allows any service from the Internet to the internal network is the most concerning because it effectively bypasses the firewall's purpose, permitting unrestricted inbound access to internal systems. This exposes the entire internal network to external threats, including malware, unauthorized access, and exploitation of any vulnerable service. Such a rule violates the principle of least privilege and is a critical misconfiguration that auditors flag as a severe control weakness.

Exam trap

The trap is equating 'any source IP' with 'any service'; candidates see 'any source' in option C and pick it, missing that the protocol and destination are restricted, whereas option D allows any service to the entire internal network.

How to eliminate wrong answers

Option A is wrong because a rule not reviewed for 18 months is a hygiene issue and a policy violation, but it is less severe than an any-service rule that actively exposes the internal network. Option B is wrong because permitting a specific IP to a database server on port 1433 (SQL Server) is a narrow, targeted rule that may be legitimate for application access, though it should be reviewed for necessity. Option C is wrong because allowing any source IP to access a critical server on port 443 (HTTPS) is common for public-facing web servers and is not inherently dangerous if the service is hardened and intended to be public.

253
MCQhard

A company's endpoint protection solution alerts on a file that is digitally signed by a trusted software vendor but exhibits malicious behavior on execution. What type of threat does this scenario most likely depict?

A.A Trojan horse disguised as legitimate software.
B.Signed malware, indicating the certificate may have been compromised.
C.A zero-day exploit targeting an unpatched vulnerability.
D.A fileless attack that never writes to disk.
AnswerB

A valid vendor certificate means the binary passes signature checks, so detection relies on behaviour rather than reputation; malicious code signed with a compromised or misused certificate is signed malware. This matches the stem's trusted-signature-but-malicious-execution scenario.

Why this answer

The scenario describes a file that is digitally signed by a trusted vendor yet exhibits malicious behavior. This is the classic definition of signed malware, where the digital certificate used to sign the file has likely been stolen, misused, or issued fraudulently. The trusted signature bypasses reputation-based and allowlist controls, making the threat particularly dangerous because the file appears legitimate to security tools that trust the vendor's certificate.

Exam trap

The trap here is that candidates confuse 'signed malware' with a 'Trojan horse,' but the critical differentiator is the presence of a valid digital signature from a trusted vendor, which is not inherent to Trojans and is the specific mechanism that makes this threat unique.

How to eliminate wrong answers

Option A is wrong because a Trojan horse is malware that disguises itself as a legitimate program, but it does not necessarily carry a valid digital signature from a trusted vendor; the key detail here is the presence of a trusted digital signature, which is not a requirement for a Trojan. Option C is wrong because a zero-day exploit targets an unpatched vulnerability in software or the OS, not a signed file; the threat is not about exploiting a vulnerability but about abusing a trusted certificate to bypass security controls. Option D is wrong because a fileless attack operates in memory without writing files to disk, whereas this scenario explicitly involves a file that is alerted on by endpoint protection, meaning it exists on disk and is signed.

254
MCQmedium

Refer to the exhibit. An application log shows an error. What is the MOST likely cause of this error?

A.The database server is offline
B.The user does not have insert privileges
C.The data type of the username field is incorrect
D.A duplicate username was inserted into the USERS table
AnswerD

A duplicate username violates the UNIQUE constraint on the USERS table, causing the insert to fail and the application to log the resulting database error. This directly satisfies the stem's constraint: the logged error stems from a rejected insert, not from authentication, connectivity or permission issues elsewhere.

Why this answer

The error message 'Duplicate entry 'admin' for key 'PRIMARY'' indicates a violation of the PRIMARY KEY constraint on the USERS table. Since the username field is the primary key, inserting a second row with the same username (e.g., 'admin') causes MySQL to reject the INSERT operation with error code 1062. This is a unique constraint violation, not a connectivity or privilege issue.

Exam trap

The trap here is that candidates may confuse a duplicate key error with a privilege or connectivity issue, but the specific error code 1062 and the phrase 'Duplicate entry' directly point to a unique constraint violation, not a server or permission problem.

How to eliminate wrong answers

Option A is wrong because a database server being offline would produce a connection timeout or 'Can't connect to MySQL server' error (e.g., error 2003), not a duplicate key error. Option B is wrong because insufficient INSERT privileges would generate an 'Access denied for user' error (e.g., error 1142), not a duplicate entry error. Option C is wrong because an incorrect data type for the username field would cause a type mismatch or truncation error (e.g., error 1366 or 1406), not a duplicate key violation.

255
MCQmedium

An IS auditor is assessing an ERP implementation. Which of the following control concerns is MOST likely to arise from segregation of duties conflicts?

A.Data migration errors
B.Inadequate system performance
C.Integration complexity
D.Unauthorized transactions or fraud
AnswerD

When one person can initiate, approve and record a transaction, no independent check exists, enabling fictitious vendors, duplicate payments or unauthorised adjustments to pass undetected. This is the classic fraud exposure that segregation of duties controls are designed to prevent.

Why this answer

ERP systems often combine roles that were separate in legacy systems, increasing risk of fraud.

256
MCQmedium

An organization uses role-based access control (RBAC). An employee is transferred to a new department. According to best practices, what should be done regarding the employee's access rights?

A.Remove access to the previous department's resources after a grace period.
B.Keep all access but log usage.
C.Immediately revoke all previous access and assign new role permissions.
D.Keep previous access and grant new role permissions.
AnswerC

RBAC grants permissions through roles, so a transfer creates risk of accumulated privileges. Revoking all prior access and assigning only the new department's role permissions enforces least privilege and prevents the employee retaining unnecessary rights from the previous position.

Why this answer

RBAC mandates that access rights are strictly tied to job functions. When an employee changes departments, their previous role permissions are no longer applicable and must be immediately revoked to prevent unauthorized access, while new role permissions are granted to align with their new responsibilities. This follows the principle of least privilege and ensures that access rights are always current with the employee's role.

Exam trap

The trap here is that candidates may think a grace period or logging is acceptable, but CISA emphasizes immediate revocation to maintain least privilege and prevent unauthorized access during role transitions.

How to eliminate wrong answers

Option A is wrong because a grace period introduces a window of unauthorized access, violating the principle of least privilege and RBAC's requirement for immediate role alignment. Option B is wrong because keeping all access with logging does not prevent the employee from accessing resources they no longer need, which is a security risk and non-compliant with RBAC's role-based assignment. Option D is wrong because retaining previous access while granting new permissions results in excessive privileges, violating the segregation of duties and least privilege principles.

257
MCQmedium

A company is developing a mobile application that processes credit card payments. During the testing phase, which of the following types of testing is MOST critical to ensure security?

A.Interface testing.
B.Usability testing.
C.Penetration testing.
D.Regression testing.
AnswerC

Penetration testing actively simulates real attacks against the payment application, exposing exploitable vulnerabilities in authentication, input handling and cardholder data flows. This directly validates security controls, which functional or unit testing cannot, making it most critical before release.

Why this answer

Penetration testing is the most critical testing type for a mobile application processing credit card payments because it simulates real-world attacks to identify exploitable vulnerabilities in the payment data flow, authentication mechanisms, and API endpoints. This directly addresses PCI DSS requirements for security testing of cardholder data environments, unlike other testing types that focus on functionality or user experience.

Exam trap

The trap here is that candidates confuse 'regression testing' or 'interface testing' with security validation, overlooking that only penetration testing actively attempts to exploit vulnerabilities in the payment processing logic and data handling.

How to eliminate wrong answers

Option A is wrong because interface testing verifies correct data exchange between system components (e.g., API request/response formats) but does not actively probe for security weaknesses like SQL injection or insecure direct object references. Option B is wrong because usability testing evaluates user experience and workflow efficiency, not the security of payment data transmission or storage. Option D is wrong because regression testing ensures new code changes do not break existing functionality, but it does not include adversarial testing to uncover new vulnerabilities introduced in the payment processing logic.

258
Multi-Selecthard

Which THREE of the following are key components of an effective information security awareness program? (Choose three.)

Select 3 answers
A.Phishing simulation exercises
B.Reward program for reporting incidents
C.Annual one-time training for all employees
D.Support from top management
E.Regularly scheduled training sessions on security policies
AnswersA, D, E

Simulations test and improve behavior.

Why this answer

Phishing simulation exercises are a key component of an effective information security awareness program because they provide hands-on, practical experience in identifying and responding to real-world phishing attempts. By simulating attacks, organizations can measure employee susceptibility, reinforce training, and reduce the risk of successful social engineering attacks. This proactive approach helps build a security-conscious culture and directly addresses the human factor in cybersecurity.

Exam trap

The trap here is that candidates may confuse a reward program for reporting incidents as a core component of awareness, when in fact it is a supplementary measure, not a foundational element like management support or regular training.

259
MCQeasy

An IS auditor is reviewing the audit committee's oversight of the IT audit function. The auditor notes that the audit committee approves the annual IT audit plan but does not receive regular updates on the status of management's remediation of audit findings. Which of the following is the MOST significant risk arising from this situation?

A.Management may fail to address significant control weaknesses in a timely manner.
B.The auditor may not be able to perform follow-up activities on previous audit findings.
C.The IT audit function may not have sufficient resources to complete the audit plan.
D.The IT audit plan may not align with the organization's strategic objectives.
AnswerA

Without regular updates on remediation status, the audit committee cannot hold management accountable for resolving audit findings. This increases the likelihood that significant control weaknesses remain unaddressed, exposing the organization to unresolved risks. The audit committee's oversight role is critical to ensuring that management takes corrective action, so this is the most direct and significant risk.

Why this answer

The audit committee's oversight role includes monitoring management's progress in addressing audit findings. Without regular remediation updates, the committee cannot ensure that significant control weaknesses are corrected promptly. This creates a governance gap where unresolved risks persist, making the failure to remediate timely the most significant consequence of the described situation.

Exam trap

The trap here is assuming that the audit committee's approval of the audit plan is sufficient oversight, overlooking the need for ongoing monitoring of remediation activities.

260
MCQeasy

A company is implementing a new IT governance framework. Which of the following is the PRIMARY benefit of aligning IT strategy with business strategy?

A.Simplifies IT architecture
B.Improves IT staff morale
C.Ensures IT investments support business objectives
D.Reduces IT costs
AnswerC

Alignment directs funding and resources toward initiatives that deliver measurable business value, so IT spend directly supports strategic goals. This satisfies the stem's requirement for the primary benefit of linking IT strategy to business strategy.

Why this answer

Aligning IT strategy with business strategy ensures that technology investments, projects, and resources are directed toward achieving the organization's business goals, which is the fundamental purpose of IT governance frameworks like COBIT. This alignment translates business objectives into IT priorities so that every dollar and hour spent on IT delivers measurable business value.

Exam trap

CISA often tests the difference between primary governance benefits and secondary operational outcomes, tempting candidates to pick cost reduction or architecture simplification instead of business objective support.

How to eliminate wrong answers

Option A is wrong because simplifying IT architecture is a possible byproduct, not the primary benefit of strategic alignment. Option B is wrong because IT staff morale is an internal HR outcome and not the governance objective. Option D is wrong because cost reduction may or may not result from alignment; the primary benefit is value delivery and objective support, not cost cutting.

261
MCQhard

During a post-implementation review, an IS auditor identifies that the system's actual transaction processing time is significantly higher than the benchmark specified in the service level agreement (SLA). The vendor claims it is due to inadequate network bandwidth provided by the client. What should the auditor do first?

A.Review the SLA to determine responsibility for network performance
B.Recommend increasing network bandwidth
C.Escalate the issue to senior management
D.Perform independent performance testing
AnswerA

The SLA defines which party owns network bandwidth and performance thresholds. Before evaluating the vendor's claim, the auditor must establish contractual responsibility, since that determines whether the shortfall is a vendor breach or a client-side infrastructure issue.

Why this answer

The SLA should define responsibilities for network performance. The auditor should first review the SLA to determine who is responsible. Option B is incorrect because recommending bandwidth increase without verifying responsibility is premature.

Option C is incorrect because escalation to senior management is not the first step; review of SLA should occur first. Option D is incorrect because independent performance testing may be unnecessary if the SLA clarifies responsibility.

262
MCQhard

An IS auditor is assessing the security of an organization's virtualization environment. The auditor finds that the hypervisor management interface is accessible from the general corporate network and uses default credentials. Which of the following is the MOST critical risk associated with this finding?

A.An attacker could cause a denial of service by overwhelming the hypervisor with management requests.
B.An attacker could exploit a vulnerability in the hypervisor to escape to the host operating system.
C.An attacker could gain control of the hypervisor and compromise all hosted virtual machines.
D.An attacker could intercept network traffic between virtual machines on the same host.
AnswerC

The hypervisor management interface is a high-value target because it controls the entire virtual infrastructure. If an attacker accesses it with default credentials, they can potentially shut down, modify, or create virtual machines, and even move laterally to other systems. This could lead to a complete compromise of all hosted workloads, data breaches, and service outages. This is the most critical risk because it affects the entire virtual environment, not just a single VM.

Why this answer

The most critical risk is that an attacker could gain control of the hypervisor and compromise all hosted virtual machines. The hypervisor management interface is a privileged access point; if exposed and using default credentials, it can be easily exploited. An attacker with administrative control can manipulate all VMs, access sensitive data, and disrupt services across the entire virtual infrastructure.

This represents a single point of failure with catastrophic potential.

Exam trap

The trap here is focusing on specific technical attacks like VM escape or traffic sniffing while underestimating the immediate and severe impact of unauthorized administrative access to the hypervisor.

263
Multi-Selectmedium

Which TWO of the following are recommended practices for aligning IT strategy with business goals, according to COBIT 2019?

Select 2 answers
A.Implementing a continuous monitoring system for IT operational metrics
B.Conducting monthly IT steering committee meetings to review project status
C.Adopting a governance framework that covers all IT-related activities and stakeholder needs
D.Defining IT investment portfolios based on business value contribution
E.Using agile development methodologies for all IT projects
AnswersC, D

Adopting a governance framework spanning all IT-related activities and stakeholder needs directly satisfies COBIT 2019's alignment principle, since the framework cascades enterprise goals into IT objectives and defines decision rights, accountability and performance measurement across every domain, ensuring IT strategy remains traceable to business intent rather than isolated departmental priorities.

Why this answer

Option C is correct because COBIT 2019's governance system is explicitly built on a governance framework that spans the whole enterprise—covering all IT-related activities through the governance and management objectives and addressing the needs of internal and external stakeholders, which is exactly what aligning IT strategy with business goals requires. Option D is correct because COBIT 2019's BA (Build, Acquire and Implement) and APO (Align, Plan and Organise) domains, particularly APO05 Managed Portfolio, call for managing IT investments as a portfolio prioritised by business value and strategic contribution, directly tying IT spending to business goals. Option A is not marked correct because continuous monitoring of operational metrics is a performance/operations practice rather than a strategic alignment practice in COBIT 2019.

Option B is not marked correct because, while steering committees are useful, COBIT 2019 does not prescribe monthly IT steering committee meetings as a recommended alignment practice. Option E is not marked correct because COBIT 2019 is methodology-agnostic and does not mandate agile for all IT projects as a means of strategic alignment.

Exam trap

The trap here is that candidates confuse operational or tactical activities (like monitoring metrics or project reviews) with strategic governance practices, which COBIT 2019 defines as framework-level alignment, not day-to-day management tasks.

264
MCQhard

A multinational corporation is implementing a new enterprise resource planning (ERP) system across multiple regions. The project uses a phased roll-out. After the first phase in Asia, the system experiences intermittent synchronization errors between the central database and regional servers. The IT team suspects network latency but cannot reproduce the issue consistently. The project sponsor wants to proceed with the next phase in Europe to avoid further delays. The IS auditor is performing a post-implementation review. What is the MOST appropriate recommendation?

A.Proceed with the European roll-out and monitor for similar issues.
B.Switch to a different ERP vendor that offers better cloud capabilities.
C.Conduct a thorough root cause analysis of the synchronization issue before any further roll-out.
D.Document the synchronization error as a known issue and accept the operational risk.
AnswerC

Proceeding to Europe while the Asia synchronisation fault remains undiagnosed risks replicating the defect across regions and compounding data integrity issues. Root cause analysis first satisfies the audit objective of confirming the phased roll-out is controlled before further deployment, rather than masking an unresolved defect.

Why this answer

The intermittent synchronization errors indicate a potential data integrity or consistency issue that must be fully understood before expanding the system's footprint. Proceeding without root cause analysis risks propagating the defect to the European phase, which could lead to widespread data corruption, increased remediation costs, and regulatory non-compliance. A thorough root cause analysis (e.g., examining network latency, transaction log replication, or database conflict resolution) is essential to ensure the ERP's distributed architecture is reliable.

Exam trap

The trap here is that candidates may choose Option A (proceed and monitor) because it seems pragmatic and avoids project delays, but the CISA exam emphasizes that unresolved control weaknesses in a post-implementation review must be addressed before expanding the system to prevent cascading failures.

How to eliminate wrong answers

Option A is wrong because proceeding with the European roll-out while only monitoring for similar issues ignores the fundamental need to resolve the existing synchronization defect; it assumes the problem is isolated to Asia, but the same network latency or configuration flaw could affect Europe. Option B is wrong because switching to a different ERP vendor is a drastic, costly, and premature response that does not address the specific technical root cause (e.g., network latency, replication protocol misconfiguration, or timeout settings) and introduces new integration risks. Option D is wrong because documenting the error as a known issue and accepting operational risk violates the principle of preventing data integrity failures; synchronization errors can cause inconsistent data across regions, leading to financial reporting errors or transaction failures, which are unacceptable in a post-implementation review.

265
MCQmedium

Midway through a multi-year ERP implementation, the CIO asks the IS auditor to review how the organization is realizing the intended business benefits. The project is on schedule and within budget, but business unit managers report that key process changes have not been adopted. Which of the following is the MOST appropriate action for the IS auditor to recommend?

A.Implement a formal benefits realization plan with defined ownership and periodic measurement of outcome metrics.
B.Escalate the schedule and budget variances to the audit committee for immediate action.
C.Perform a post-implementation review immediately to determine whether the project should be cancelled.
D.Recommend that the project steering committee increase the frequency of status reporting to weekly.
AnswerA

Because the project is on time and on budget yet benefits are not materializing, the gap is in benefits management, not delivery. A formal benefits realization plan assigns accountability for outcome metrics and establishes periodic measurement so deviations trigger corrective action. This directly addresses the governance objective of ensuring IT investments deliver value, which is exactly what the CIO asked the auditor to assess.

Why this answer

The scenario deliberately separates delivery success from benefit realization: the project is on time and within budget, yet process changes are not adopted, meaning the investment's intended value is at risk. The governance response is to establish benefits ownership and outcome measurement through a benefits realization plan. Escalating false variances, increasing reporting cadence, or prematurely conducting a post-implementation review all fail to create accountability for outcomes.

Exam trap

The trap here is assuming that on-time, on-budget delivery equates to successful benefits realization, when the two are governed by separate mechanisms.

266
MCQeasy

A small business wants to protect customer data collected through its e-commerce website. Which control is most appropriate for protecting the data at rest and in transit?

A.Implement a network firewall to block unauthorized access.
B.Perform regular backups of the database to ensure data availability.
C.Deploy an intrusion detection system (IDS) to monitor for threats.
D.Use encryption for data at rest and in transit.
AnswerD

Encryption applies cryptographic protection to customer data both at rest and in transit, directly meeting the stem's dual requirement. At rest, it renders stored records unreadable; in transit, TLS or similar protects data moving between the browser and web server.

Why this answer

Encryption is the only control that directly protects the confidentiality and integrity of data both at rest (e.g., AES-256 for database files) and in transit (e.g., TLS 1.3 for HTTPS). It renders data unreadable without the proper decryption key, ensuring that even if storage media or network traffic is intercepted, the customer data remains secure.

Exam trap

The trap here is that candidates often confuse preventive controls like firewalls or IDS with data protection mechanisms, failing to recognize that encryption is the only direct safeguard for data confidentiality both at rest and in transit.

How to eliminate wrong answers

Option A is wrong because a network firewall controls access at the network layer but does not protect data at rest (e.g., stored database files) or data in transit from eavesdropping or decryption after interception. Option B is wrong because regular backups ensure data availability and recovery, not confidentiality or integrity; backups themselves must be encrypted to protect data at rest. Option C is wrong because an IDS monitors and alerts on suspicious activity but does not prevent data exposure; it cannot encrypt data or protect it from being read if intercepted.

267
Multi-Selecteasy

During an audit of physical security, the IS auditor observes that employees frequently leave confidential documents on their desks overnight. Which TWO controls should the auditor recommend?

Select 2 answers
A.Deploy additional CCTV cameras
B.Conduct security awareness training
C.Implement a clean desk policy
D.Implement a visitor management system
E.Install motion detectors
AnswersB, C

Security awareness training addresses the human behaviour behind documents left on desks, teaching staff classification handling and the clean desk requirement. It complements procedural controls by changing the culture that causes the exposure the auditor observed.

Why this answer

Option B (Conduct security awareness training) is correct because the root cause of documents being left out overnight is employee behavior, and awareness training directly educates staff on their security responsibilities, the risks of leaving confidential information exposed, and proper handling and storage procedures. Option C (Implement a clean desk policy) is correct because it establishes a formal, enforceable requirement that all sensitive documents be secured or locked away at the end of the workday, directly addressing the observed weakness and providing a basis for audits and disciplinary action. Option A (Deploy additional CCTV cameras) is not appropriate because cameras only provide detective/monitoring capability and do not prevent employees from leaving documents on desks.

Option D (Implement a visitor management system) does not belong because the issue involves employees, not visitors, and visitor control does not address internal document handling. Option E (Install motion detectors) is not relevant because motion detection is an intrusion-detection control for after-hours physical access, not a control over how employees handle confidential documents.

Exam trap

The trap is choosing physical detection controls (CCTV, motion detectors) because they sound security-related, when the question asks for controls that directly address the observed behavior of leaving documents on desks.

268
MCQhard

During the user acceptance testing (UAT) phase of a new financial application, the business users report that the system calculates interest incorrectly for certain loan types. The project manager wants to fix this quickly. Which of the following is the BEST course of action?

A.Instruct the business to work around the issue until the next release
B.Authorize the development team to fix the bug immediately and re-deploy
C.Roll back to the previous version of the application
D.Log the defect and perform impact analysis before approving a fix
AnswerD

Logging the defect and performing impact analysis before approving a fix ensures the incorrect interest calculation is properly assessed against scope, dependencies, and financial risk. This satisfies the UAT control requirement, preventing hasty changes that could introduce further errors into a financial application.

Why this answer

In the UAT phase, any defect must be formally logged and subjected to impact analysis before a fix is approved. This ensures that the proposed change does not introduce new risks, break other functionality, or violate regulatory compliance—critical for a financial application handling interest calculations. Skipping this process could lead to cascading failures or audit findings.

Exam trap

The trap here is that candidates often choose Option B (immediate fix) because it seems efficient, but CISA emphasizes that any change during UAT must follow a controlled process to avoid introducing new risks, especially in financial systems where accuracy and auditability are paramount.

How to eliminate wrong answers

Option A is wrong because instructing business users to work around a calculation error in a financial application is unacceptable; it risks financial misstatements and violates internal control requirements. Option B is wrong because authorizing an immediate fix without impact analysis bypasses change management controls, potentially destabilizing the application and introducing new defects. Option C is wrong because rolling back to a previous version may not resolve the interest calculation issue (it could have existed before) and would discard any other validated changes, causing regression without proper analysis.

269
MCQmedium

Which of the following is the PRIMARY purpose of a change advisory board (CAB) in the change management process?

A.To approve all standard changes without review
B.To assess, prioritize, and authorize changes
C.To authorize emergency changes immediately
D.To develop technical solutions for change requests
AnswerB

The change advisory board's primary function is to assess each change's risk and impact, prioritise it against other changes, and authorise or reject it, satisfying the stem's focus on the change management process. Implementation and post-implementation review sit with other roles, not the CAB.

Why this answer

The CAB is responsible for reviewing and approving changes, assessing risks, and ensuring proper planning and testing.

270
MCQhard

An IS auditor is planning an audit of a decentralized organization with multiple business units. The auditor wants to use a risk-based approach. Which of the following is the MOST appropriate factor to prioritize audit coverage?

A.The geographical location of each business unit.
B.The results of a risk assessment evaluating inherent risk and control effectiveness.
C.The budget allocated to each business unit for IT.
D.The number of employees in each business unit.
AnswerB

In a decentralised organisation, coverage should be prioritised by a risk assessment weighing inherent risk against control effectiveness across business units. This directs limited audit resources to the units with the greatest residual exposure, satisfying the stem's requirement for the most appropriate prioritisation factor.

Why this answer

A risk-based audit approach prioritizes coverage based on the likelihood and impact of risk, which is precisely what a risk assessment evaluating inherent risk and control effectiveness produces. Inherent risk reflects the susceptibility of a process or unit to error or fraud before controls, while control effectiveness indicates how much of that risk is mitigated. Combining these two factors lets the auditor direct limited audit resources to the areas of greatest residual risk, which is the defining principle of risk-based auditing.

Exam trap

CISA often tests the distinction between risk-based prioritization and convenience-based prioritization (location, budget, headcount), tempting candidates to pick a tangible, easily measured factor over the correct risk assessment output.

How to eliminate wrong answers

Option A is wrong because geographical location is at best a secondary scoping consideration and does not by itself indicate the level of risk to the organization. Option C is wrong because IT budget size reflects spending, not risk exposure — a well-funded unit can still carry high inherent risk. Option D is wrong because headcount is a size metric, not a risk metric, and larger units are not automatically riskier than smaller ones.

271
Multi-Selectmedium

Which TWO of the following are key considerations when managing software licenses in an organization? (Select TWO).

Select 2 answers
A.Implementing automated license optimization tools
B.Conducting regular license compliance audits
C.Storing all software installation media in a secure location
D.Maintaining a hardware inventory for asset tracking
E.Ensuring all software is patched to the latest version
AnswersA, B

Automated licence optimisation tools continuously reconcile installed software against entitlements, reclaiming unused seats and flagging over-deployment before true-up audits. This directly satisfies the stem's consideration of ongoing licence management, since manual tracking cannot scale across large estates and typically causes compliance breaches or unnecessary spend.

Why this answer

Option A is correct because automated license optimization tools (e.g., Software Asset Management/SAM platforms that reconcile entitlements against discovered installations) continuously track usage, identify unused or over-deployed licenses, and help reclaim or reassign seats, which directly reduces cost and compliance risk. Option B is correct because regular license compliance audits compare purchased entitlements against actual deployments and usage, producing the evidence needed to true-up agreements, avoid vendor penalties, and satisfy software audits. Option C is not a key license-management consideration; storing installation media securely is a media-handling/backup practice, not license entitlement management.

Option D is not correct because a hardware inventory supports asset tracking and configuration management, but it does not by itself address license entitlements, usage rights, or compliance. Option E is not correct because patching to the latest version is vulnerability and configuration management, unrelated to tracking or optimizing software licenses.

272
Multi-Selectmedium

Which TWO of the following are the MOST effective controls to prevent unauthorized changes to production data?

Select 2 answers
A.Requiring change management approval for all production changes
B.Enforcing segregation of duties between development and production
C.Implementing audit logging of all data changes
D.Encrypting production data at rest
E.Using automated testing for all code changes
AnswersA, B

Ensures changes are authorized before implementation.

Why this answer

Requiring change management approval for all production changes is a preventive control that ensures every modification to production data is formally authorized, reviewed, and documented before implementation. This directly prevents unauthorized changes by enforcing a gatekeeping process where only approved changes proceed, reducing the risk of data integrity breaches. Without this control, even with other safeguards, an attacker or insider could bypass technical controls by simply requesting a change through official channels.

Exam trap

ISACA often tests the distinction between preventive and detective controls, and the trap here is that candidates mistakenly choose audit logging (a detective control) as a preventive measure because it provides evidence of changes, but it does not stop unauthorized changes from occurring.

273
MCQeasy

During which phase of the SDLC should security requirements be formally documented and approved?

A.Design phase
B.Requirements phase
C.Development phase
D.Testing phase
AnswerB

Documenting and approving security requirements during the requirements phase ensures controls are baselined before design and coding begin. This satisfies the stem's constraint that security requirements be formally documented and approved at the earliest phase, preventing costly retrofitting later.

Why this answer

Security requirements must be formally documented and approved during the Requirements phase of the SDLC because this is when functional and non-functional needs, including security controls, are defined before any design or coding begins. Integrating security at this stage ensures that confidentiality, integrity, and availability requirements are captured in the system specification, preventing costly rework later. The Requirements phase is the earliest point where stakeholders can review and approve security constraints, such as encryption standards or access control policies, aligning them with business objectives.

Exam trap

The trap here is that candidates often confuse the Requirements phase with the Design phase, mistakenly thinking security requirements are documented during design because that is when security controls are technically specified, but formal approval must occur earlier in the requirements stage to drive the entire development lifecycle.

How to eliminate wrong answers

Option A is wrong because the Design phase translates approved requirements into technical architecture and detailed specifications, but security requirements must already be documented and approved before design begins to guide secure design decisions. Option C is wrong because the Development phase focuses on coding and unit testing based on the design, and introducing security requirements at this stage would lead to retrofitting controls, increasing risk and cost. Option D is wrong because the Testing phase validates that the system meets documented requirements, including security ones, but it is too late to formally document and approve security requirements; they must be established earlier to define test cases.

274
Multi-Selectmedium

Which THREE of the following are typical controls in the design phase of the SDLC?

Select 3 answers
A.Designing security controls
B.Architecture review
C.Code review
D.Threat modeling
E.User acceptance testing
AnswersA, B, D

The design phase translates requirements into technical specifications, so designing security controls here embeds confidentiality, integrity and availability measures into the solution before coding begins. Addressing security at design prevents costly retrofitting and satisfies the SDLC control objective of proactive risk mitigation.

Why this answer

Option A (Designing security controls) is correct because the design phase is exactly where security requirements are translated into concrete controls such as encryption schemes, authentication mechanisms, and access control models before any code is written. Option B (Architecture review) is correct because reviewing the proposed system architecture during design ensures that structural weaknesses, trust boundaries, and integration points are evaluated and corrected early, when changes are cheapest. Option D (Threat modeling) is correct because threat modeling is a design-phase activity that systematically identifies threats, attack vectors, and mitigations against the planned architecture and data flows.

Option C (Code review) does not belong because it occurs during the implementation or development phase, after code exists to inspect. Option E (User acceptance testing) does not belong because UAT is a testing/validation activity performed late in the SDLC, after the system is built, to confirm it meets business requirements.

Exam trap

CISA often tests whether candidates can correctly place security activities into the right SDLC phase, luring them into selecting code review or UAT because those sound security-adjacent when they actually belong to later phases.

275
MCQeasy

An organization is implementing a new IT governance framework. Which of the following is the PRIMARY benefit of aligning IT strategy with business strategy?

A.Increased technical efficiency
B.Improved resource allocation
C.Reduced IT costs
D.Enhanced security posture
AnswerB

Aligning IT strategy with business strategy ensures IT investments, staffing and budgets target the organisation's actual priorities. This directly produces improved resource allocation, since resources flow to initiatives that demonstrably support business objectives rather than isolated technical goals.

Why this answer

Aligning IT strategy with business strategy ensures that IT investments and initiatives directly support business objectives, leading to more effective prioritization and allocation of resources (budget, personnel, technology) to areas that deliver the most value. This alignment is a core goal of IT governance frameworks like COBIT, which emphasize value delivery and resource optimization.

Exam trap

The trap is choosing a tangible, operational benefit like reduced costs or increased efficiency, which are outcomes of good IT management but not the primary benefit of strategic alignment; the exam expects you to recognize that alignment drives resource allocation toward business value.

How to eliminate wrong answers

Option A is wrong because increased technical efficiency is an operational outcome, not the primary benefit of strategic alignment; efficiency can be achieved without alignment. Option C is wrong because reduced IT costs may result from alignment but is not the primary benefit—alignment is about value creation, not just cost cutting. Option D is wrong because enhanced security posture is a component of IT governance but not the primary benefit of aligning IT with business strategy; security is one of many domains.

276
MCQhard

An organization processes personal data of EU residents and has implemented pseudonymisation as a privacy control. The IS auditor is reviewing the effectiveness of this control in meeting GDPR requirements. Which of the following is the MOST important limitation of pseudonymisation?

A.Pseudonymisation eliminates the need for data subject rights
B.Pseudonymisation is not recognized by GDPR
C.Pseudonymisation cannot be applied to structured data
D.Pseudonymised data is still considered personal data under GDPR
AnswerD

Pseudonymisation replaces direct identifiers but retains a key enabling re-identification, so the data remains personal data under GDPR and its protections still apply. This limits the control: it reduces risk but does not remove the organisation's compliance obligations.

Why this answer

Under GDPR Article 4(5), pseudonymisation is a technique where personal data can no longer be attributed to a specific data subject without additional information kept separately. However, because re-identification remains possible with that additional information, pseudonymised data is still legally considered personal data under GDPR, meaning data subject rights, breach notification, and other obligations continue to apply. This is the most important limitation an IS auditor must recognize when assessing the control's effectiveness.

Exam trap

CISA often tests the misconception that pseudonymisation equals anonymisation — candidates incorrectly assume pseudonymised data falls outside GDPR scope, when in fact it remains personal data subject to full regulatory obligations.

How to eliminate wrong answers

Option A is wrong because pseudonymisation does not eliminate data subject rights — GDPR Articles 15-22 rights (access, erasure, portability, etc.) still apply to pseudonymised data since it remains personal data. Option B is wrong because GDPR explicitly recognizes pseudonymisation in Article 4(5) and encourages it as a safeguard under Article 32 and Recital 28. Option C is wrong because pseudonymisation can absolutely be applied to structured data — it is commonly implemented via tokenization, hashing, or key-value substitution in relational databases and data warehouses.

277
Multi-Selecthard

An IS auditor is performing a risk assessment for an audit of a cloud service provider. Which THREE factors should be considered when assessing inherent risk? (Select THREE.)

Select 3 answers
A.Complexity of the cloud architecture
B.Effectiveness of monitoring controls
C.Strength of access controls
D.Sensitivity of data stored in the cloud
E.Recent changes to the cloud environment
AnswersA, D, E

Complexity of the cloud architecture directly elevates inherent risk, since intricate multi-tenant, hybrid or interconnected designs enlarge the attack surface and obscure control gaps before any mitigation exists. It satisfies the stem's inherent-risk constraint by capturing design-driven uncertainty the auditor must weigh independently of implemented controls.

Why this answer

Inherent risk is assessed before considering controls, so the auditor should focus on factors that increase risk exposure independent of mitigation. Option A (Complexity of the cloud architecture) is correct because multi-tenant, virtualized, and distributed architectures increase the likelihood of misconfigurations, service dependencies, and attack surface, raising inherent risk. Option D (Sensitivity of data stored in the cloud) is correct because the classification and regulatory obligations of the data (e.g., PII, PCI DSS, PHI) directly determine the impact if confidentiality, integrity, or availability is compromised.

Option E (Recent changes to the cloud environment) is correct because changes such as new deployments, migrations, or configuration updates introduce instability and unverified states that elevate inherent risk. Options B (Effectiveness of monitoring controls) and C (Strength of access controls) are not inherent risk factors; they are control effectiveness considerations evaluated during the control risk assessment, after inherent risk has been determined.

Exam trap

CISA often tests the inherent-versus-control risk boundary, tempting candidates to select control-related options (monitoring, access controls) as inherent-risk factors because they sound risk-relevant.

278
MCQhard

An IS auditor is assessing the capacity management process for a virtualized data center. The auditor finds that CPU and memory utilization on a cluster of hosts regularly exceeds 85 percent during month-end processing, causing performance degradation. Management states that they monitor utilization but have no formal forecasting or trend analysis. Which of the following is the MOST significant risk arising from this situation?

A.Inaccurate chargeback to business units for IT resource consumption.
B.Noncompliance with software licensing agreements due to overutilization.
C.Inability to recover from a disaster within the recovery time objective.
D.Unplanned outages and service degradation during peak business periods.
AnswerD

Without forecasting or trend analysis, capacity shortfalls during predictable peaks such as month-end can lead to resource exhaustion, causing outages or severe performance degradation. This directly threatens service availability and business operations. The risk is significant because the organization already experiences high utilization and has no forward-looking process to anticipate and remediate capacity constraints before they impact users.

Why this answer

The absence of forecasting and trend analysis in a capacity management process means the organization cannot anticipate resource demands. With utilization already exceeding 85 percent during month-end, the most significant risk is that peak loads will exhaust resources, causing outages or severe performance issues. This directly impacts business operations and service availability.

Other concerns like chargeback or licensing are less immediate and not indicated by the scenario.

Exam trap

The trap here is focusing on secondary IT management concerns like chargeback or licensing when the scenario's core issue is the lack of predictive capacity planning leading to operational disruption.

279
MCQmedium

An organization is implementing a new ERP system and is concerned about segregation of duties (SoD) conflicts. What is the BEST approach to address this during the implementation?

A.Assign all administrative rights to a single user for efficiency
B.Configure role-based access controls with SoD rules in the system
C.Rely on manual compensating controls after go-live
D.Document SoD conflicts for future resolution
AnswerB

Embedding SoD rules into role-based access controls means the ERP enforces conflicting-duty separation at design time, preventing toxic combinations such as creating a vendor and approving its payment. Configuring this during implementation satisfies the stem's concern before go-live.

Why this answer

Configuring SoD rules within the ERP system helps enforce segregation and prevent conflicts during operations.

280
MCQhard

A multinational corporation is implementing a bring your own device (BYOD) policy. Which of the following is the most important security control to ensure corporate data is protected on employee devices?

A.Require employees to install antivirus software.
B.Prohibit the use of personal devices for work.
C.Mandate full-device encryption.
D.Implement mobile device management (MDM) with containerization.
AnswerD

MDM with containerization separates corporate data into an encrypted, policy-controlled workspace on the personal device, leaving personal apps outside its scope. This directly satisfies BYOD's core constraint: protecting corporate information on hardware the organisation does not own, while enforcing selective wipe and access controls without erasing employees' personal content.

Why this answer

Mobile Device Management (MDM) with containerization creates a separate, encrypted workspace on the employee's device that isolates corporate data from personal data. This ensures that the organization can enforce security policies (e.g., remote wipe, access controls) on the corporate container without affecting the user's personal information, which is critical for BYOD environments where full-device control is not feasible.

Exam trap

The trap here is that candidates often confuse full-device encryption (Option C) as sufficient for BYOD, failing to recognize that encryption alone does not provide data segregation or selective wipe capabilities, which are essential for protecting corporate data on a device the organization does not fully own.

How to eliminate wrong answers

Option A is wrong because antivirus software alone cannot prevent data leakage or enforce access controls on corporate data; it only protects against malware and does not address the core requirement of data segregation on a shared device. Option B is wrong because prohibiting personal devices for work directly contradicts the BYOD policy being implemented, making it a policy rejection rather than a security control. Option C is wrong because full-device encryption protects data at rest but does not separate corporate data from personal data; in a BYOD scenario, the organization would have no control over the user's personal apps or data, and a remote wipe would erase everything, including personal content.

281
MCQhard

A financial services organization recently experienced a data breach where customer financial records were exfiltrated. The investigation reveals that an attacker gained access through a compromised privileged account belonging to a database administrator. The attacker used valid credentials to log into the database server and then exported a large volume of data using native database tools. The security team notes that the organization has multi-factor authentication (MFA) enabled for all remote access, but the database server was accessed from an internal IP address. The organization also has a data loss prevention (DLP) system, but it did not alert on the export because the traffic was encrypted. The database activity monitoring (DAM) system did log the export, but alerts were not reviewed due to high volume and many false positives. Which of the following would have been most effective in preventing this breach?

A.Deploying a DLP solution that can inspect encrypted traffic via SSL interception
B.Implementing a privileged access management (PAM) solution that requires approval for elevated actions and records sessions
C.Segmenting the database server onto a separate network with strict firewall rules
D.Improving the database activity monitoring (DAM) alerting to reduce false positives
AnswerB

PAM with approval workflows and session recording would have blocked or flagged the database administrator's credential use for bulk export, since it enforces just-in-time elevation and logs privileged sessions. MFA and DLP failed because the access was internal and encrypted.

Why this answer

The breach occurred because a privileged database administrator account was compromised, and the attacker used native database tools to export data from an internal IP address, bypassing MFA. A privileged access management (PAM) solution would have required approval for elevated actions (e.g., exporting large volumes of data) and recorded the session, providing both preventive control (approval workflow) and detective control (session recording) to stop or immediately detect the abuse of valid credentials. This directly addresses the root cause—compromised privileged credentials—rather than relying on network or alerting controls that were circumvented.

Exam trap

The trap here is that candidates often focus on detection or network controls (DLP, segmentation, DAM) instead of recognizing that the root cause is the abuse of valid privileged credentials, which requires a preventive control like PAM that manages and monitors privileged access at the point of action.

How to eliminate wrong answers

Option A is wrong because SSL interception of encrypted traffic would not have prevented the breach; the attacker used native database tools over an encrypted connection from an internal IP, and DLP inspection of encrypted traffic would still need to decrypt and analyze the content, which is complex and may not block the export if the attacker uses legitimate database protocols. Option C is wrong because network segmentation with firewall rules would not prevent an attacker who already has valid credentials from an internal IP; the attacker was already on the internal network and could access the database server through permitted firewall rules. Option D is wrong because improving DAM alerting to reduce false positives would only improve detection, not prevention; the breach had already occurred by the time the alert was generated, and the attacker had already exfiltrated the data.

282
MCQeasy

What is the PRIMARY purpose of a post-implementation review?

A.To close the project budget and finalize costs
B.To evaluate the performance of the project team
C.To document lessons learned for future projects
D.To assess whether expected benefits were achieved
AnswerD

A post-implementation review compares actual outcomes against the business case after a system goes live, determining whether the projected benefits, costs and objectives were realised. This assessment informs corrective action and improves future project justification.

Why this answer

The primary purpose of a post-implementation review (PIR) is to determine whether the system or project has delivered the expected business benefits, such as improved efficiency, cost savings, or enhanced functionality. This aligns with the IS auditor's focus on value realization and governance, ensuring that the investment achieved its intended objectives before the project is formally closed.

Exam trap

The trap here is that candidates confuse the PIR's primary purpose with the project closure process (Option A) or the team's performance evaluation (Option B), but CISA emphasizes that the review's core objective is to confirm that the system delivers the expected business value, not just to complete administrative tasks.

How to eliminate wrong answers

Option A is wrong because closing the project budget and finalizing costs is a financial closure activity that occurs during project closeout, not the primary goal of a PIR, which focuses on benefits realization. Option B is wrong because evaluating the performance of the project team is a human resource or project management task, often done during or immediately after project execution, whereas the PIR assesses the system's outcomes against business case criteria. Option C is wrong because documenting lessons learned is a secondary output of a PIR, but the primary purpose is to verify that expected benefits were achieved; lessons learned support future projects but do not validate the current investment's success.

283
MCQmedium

An organization is implementing a privileged access management (PAM) solution. Which of the following is the PRIMARY benefit of using a PAM tool?

A.Elimination of shared accounts by providing individual credentials
B.Enforcement of segregation of duties between IT and security teams
C.Automated password resets for user accounts
D.Centralized management and monitoring of privileged account usage
AnswerD

Centralised management and monitoring consolidates privileged accounts into a controlled vault, enabling credential checkout, session recording and anomaly detection. This directly addresses the core PAM objective of curbing unmonitored, standing administrative access across the estate.

Why this answer

The primary benefit of a PAM solution is centralized management and monitoring of privileged account usage — it vaults credentials, controls who can check out which privileged accounts, records sessions, and provides audit trails. This addresses the core risk that privileged accounts (root, admin, service accounts) are the most sought-after targets for attackers and the hardest to oversee when scattered across systems. While PAM can support the other options to varying degrees, centralized management and monitoring is the defining, primary purpose.

Exam trap

CISA often tests the distinction between PAM's primary purpose (centralized privileged account management and monitoring) and secondary benefits (reducing shared accounts, enabling password resets), causing candidates to select a true-but-not-primary answer.

How to eliminate wrong answers

Option A is wrong because while PAM can reduce shared accounts by issuing individual credentials, that is a secondary benefit, not the primary purpose — PAM's core value is centralized control and visibility over privileged access, not merely credential individualization. Option B is wrong because segregation of duties between IT and security teams is an organizational governance decision, not something a PAM tool enforces by itself; PAM can support SoD but does not establish it. Option C is wrong because automated password resets for regular user accounts is a helpdesk/identity management function (often handled by IAM or self-service password reset tools), not the primary benefit of PAM, which focuses on privileged accounts.

284
MCQmedium

An organization is implementing a new IT policy. What is the MOST important step to ensure compliance?

A.Publishing the policy on the intranet
B.Conducting training and awareness sessions
C.Establishing penalties for non-compliance
D.Assigning a policy owner
AnswerB

Training and awareness sessions translate the new policy into employee understanding, directly satisfying the compliance constraint that staff must know what the policy requires before they can follow it. Without this, controls and monitoring address ignorance rather than intent, so awareness is the foundational step for achieving consistent adherence.

Why this answer

Conducting training and awareness sessions is the most important step to ensure compliance because employees must understand the policy and their responsibilities before they can comply. Training translates policy into actionable behavior, addresses questions, and builds the knowledge needed for consistent adherence. Without awareness, even a well-written policy is unlikely to be followed.

Exam trap

CISA often tests the misconception that publishing a policy or assigning an owner equals compliance — candidates pick passive steps when the active step of training and awareness is what actually drives adherence.

How to eliminate wrong answers

Option A is wrong because publishing on the intranet only makes the policy available; it does not ensure employees read, understand, or follow it. Option C is wrong because penalties may deter non-compliance but do not teach correct behavior and are reactive rather than proactive. Option D is wrong because assigning a policy owner is an accountability step, not a compliance-enabling step; the owner still needs to drive awareness and training.

285
MCQmedium

An IS auditor is reviewing an organization's endpoint protection controls after several employees reported slow performance on their laptops. The auditor observes that the anti-malware solution performs a full disk scan every night, and the audit log shows that the last successful signature update was 47 days ago. Which of the following is the MOST significant concern the auditor should report?

A.The nightly full disk scan consumes excessive endpoint resources and degrades user productivity.
B.The organization has not implemented application whitelisting to complement the anti-malware solution.
C.The full disk scan schedule conflicts with the organization's backup window and may cause backup failures.
D.The anti-malware signature database has not been updated for 47 days, leaving endpoints exposed to recent threats.
AnswerD

Signature files that are 47 days stale mean newly discovered malware families and variants cannot be detected by the endpoint control. This directly defeats the preventive purpose of the anti-malware solution and represents a material gap in the protection of information assets. The auditor should report this as the primary concern because it exposes the organization to known, circulating threats.

Why this answer

The most significant concern is that endpoint protection is running with signatures that are 47 days old, which means the control cannot detect recently identified malware. A deployed but outdated anti-malware solution provides a false sense of security because it appears active yet fails against current threats. Performance and scheduling issues are secondary operational matters, while the stale signature database is a direct, measurable weakness in the protection of information assets.

Exam trap

The trap here is focusing on the visible performance complaints from users instead of recognizing that stale signatures silently neutralize the anti-malware control.

286
MCQmedium

An IS auditor is planning an engagement and needs to obtain an understanding of the organization's IT environment to develop the audit programme. Which of the following techniques is MOST appropriate for this purpose?

A.Interviews with key IT personnel and review of system documentation.
B.Penetration testing of the organization's external network perimeter.
C.Substantive testing of transaction details in the general ledger.
D.Statistical sampling of user access records to project error rates.
AnswerA

Interviews and documentation review are core planning techniques used to understand the IT environment, including infrastructure, applications, and control processes. They help the auditor identify risks and design an appropriate audit programme. ISACA standards emphasize obtaining sufficient knowledge of the area under review during planning, and these techniques efficiently provide that understanding before fieldwork begins.

Why this answer

During planning, the auditor must obtain sufficient knowledge of the area under review to identify risks and design the audit programme. Interviews with IT personnel and review of system documentation are efficient, appropriate techniques for building that understanding. Substantive testing, statistical sampling, and penetration testing are fieldwork or specialized procedures that occur after planning has established the scope and objectives.

Exam trap

The trap here is selecting a technical testing technique such as penetration testing or sampling when the planning phase requires broad understanding rather than detailed testing.

287
MCQeasy

Which testing phase is MOST effective for validating that the system meets business needs?

A.User acceptance testing
B.Regression testing
C.Unit testing
D.Integration testing
AnswerA

User acceptance testing is performed by business users against real workflows, confirming the system satisfies stated business needs rather than merely matching technical specifications. Unit, integration and system testing verify code and interfaces; only UAT directly satisfies the stem's constraint of validating fitness for business purpose before go-live.

Why this answer

User acceptance testing (UAT) is the final phase of testing where actual end-users validate the system against real-world business requirements and workflows. It confirms that the system meets the agreed-upon business needs, functional specifications, and operational criteria before production deployment. Unlike technical testing phases, UAT focuses on business process alignment and user satisfaction.

Exam trap

ISACA often tests the misconception that integration testing or system testing validates business needs, but only UAT directly involves end-users and business stakeholders to confirm the system meets their operational requirements.

How to eliminate wrong answers

Option B (Regression testing) is wrong because it focuses on verifying that recent code changes have not broken existing functionality, not on validating business needs. Option C (Unit testing) is wrong because it tests individual components or modules in isolation at the developer level, ensuring code correctness but not business requirement alignment. Option D (Integration testing) is wrong because it validates that combined modules or systems work together correctly, but it does not assess whether the overall system satisfies business objectives or user expectations.

288
MCQmedium

A company plans to outsource its data center operations to a cloud service provider. What is the MOST important governance consideration for the board before finalizing the contract?

A.Select a provider with the lowest cost per transaction.
B.Negotiate the transfer of existing IT staff to the provider.
C.Ensure the contract includes clauses for regulatory compliance and audit rights.
D.Define a detailed exit strategy for transitioning to another provider.
AnswerC

Outsourcing data centre operations transfers processing to a third party, so the board must secure contractual regulatory compliance and audit rights. These clauses preserve oversight and evidence-gathering ability, satisfying the governance obligation for accountability over outsourced services.

Why this answer

The board's primary governance responsibility is to ensure the organization remains compliant with all applicable laws and regulations, even when operations are outsourced. Without explicit contractual clauses for regulatory compliance and audit rights, the company loses visibility and control over how its data is handled, creating legal and reputational risk. This is the most critical governance consideration because it directly addresses accountability and oversight.

Exam trap

CISA often tests the distinction between governance and management. Candidates may choose an operational or tactical answer (like exit strategy or cost) instead of the governance-level answer that focuses on compliance and audit rights.

How to eliminate wrong answers

Option A is wrong because selecting a provider based solely on lowest cost ignores risk, compliance, and service quality, which are core governance concerns. Option B is wrong because transferring IT staff is an operational HR matter, not a governance imperative. Option D is wrong because while an exit strategy is important for business continuity, it is secondary to ensuring compliance and auditability during the contract term.

289
Multi-Selectmedium

An IS auditor is planning a risk-based audit of a financial system. Which TWO of the following factors should the auditor consider when assessing inherent risk? (Select two.)

Select 2 answers
A.Complexity of transactions
B.Volume of transactions
C.Auditor's experience with similar systems
D.Results of prior audits
E.Effectiveness of internal controls
AnswersA, B

Complexity of transactions is a direct indicator of inherent risk because intricate processes and calculations are inherently more susceptible to errors or misstatements, even before considering internal controls. For a financial system, highly complex transactions, such as those involving derivatives or multi-currency conversions, present a greater predisposition to material misstatement. An IS auditor must recognise this increased susceptibility when assessing the risk profile of the system.

Why this answer

Inherent risk is the risk that exists before considering internal controls, so the auditor should focus on factors intrinsic to the system and its transactions. Option A, complexity of transactions, is correct because highly complex transactions increase the likelihood of errors, misstatements, or fraud going undetected, raising inherent risk. Option B, volume of transactions, is correct because a high volume of transactions increases the chance of errors and makes manual verification harder, which elevates inherent risk.

Option C, auditor's experience with similar systems, is not an inherent risk factor; it affects the auditor's competence and detection risk, not the risk inherent in the system. Option D, results of prior audits, is not an inherent risk factor; it is evidence used to assess control risk and plan the audit, but it does not define inherent risk. Option E, effectiveness of internal controls, is not an inherent risk factor because inherent risk is assessed before considering controls; control effectiveness relates to control risk.

Exam trap

CISA often tests the inherent-versus-control risk distinction, tempting candidates to select control effectiveness or prior audit results as inherent-risk factors because they are commonly used in audit planning.

290
MCQeasy

An organization is implementing a new financial system. Which of the following is the MOST important control to ensure data integrity during the data migration phase?

A.Conducting a post-implementation review
B.Implementing reconciliation controls between source and target
C.Encrypting data in transit
D.Performing user acceptance testing
AnswerB

Reconciliation controls compare source and target records, detecting omissions, duplications and value mismatches introduced during migration. This directly satisfies the stem's data integrity constraint, since completeness and accuracy of migrated financial data are verified before the new system goes live.

Why this answer

Reconciliation controls between source and target systems are the most critical control for ensuring data integrity during migration because they provide a systematic method to verify that every record has been accurately transferred without loss, duplication, or corruption. This typically involves comparing record counts, hash totals, or checksums (e.g., using MD5 or SHA-256) between the legacy and new databases, and flagging any discrepancies for correction before the system goes live.

Exam trap

The trap here is that candidates often confuse data integrity controls with security controls (like encryption) or validation activities (like UAT), failing to recognize that reconciliation is the only option that directly verifies the accuracy and completeness of the migrated data itself.

How to eliminate wrong answers

Option A is wrong because a post-implementation review occurs after the migration is complete and cannot prevent or detect data integrity issues during the migration process itself; it is a retrospective evaluation, not a real-time control. Option C is wrong because encrypting data in transit (e.g., using TLS 1.3 or IPsec) protects confidentiality and prevents unauthorized interception, but it does not ensure that the data being transferred is accurate, complete, or uncorrupted. Option D is wrong because user acceptance testing (UAT) focuses on validating that the system meets functional requirements and user expectations, not on verifying the completeness and accuracy of migrated data at the record level.

291
MCQmedium

Refer to the exhibit. An auditor finds that users are able to reuse previous passwords easily. Which setting should be modified to address this weakness?

A.Increase the password history to 10
B.Increase the minimum password age to 7 days
C.Enable password expiration notifications
D.Increase the maximum password age to 30 days
AnswerA

Password history records previously used hashes, so raising it to 10 prevents users from cycling back to any of their last ten passwords. This directly blocks the reuse weakness the auditor identified, forcing genuinely new credentials at each change.

Why this answer

Increasing the password history setting (e.g., to 10) prevents users from reusing their most recent passwords by storing a specified number of previous password hashes. When a user attempts to change their password, the system compares the new password against the stored history and rejects it if it matches any of the remembered passwords. This directly addresses the weakness of easy password reuse.

Exam trap

The trap here is that candidates often confuse password history with password age settings, thinking that increasing the maximum password age or minimum password age will prevent reuse, when in fact only password history directly blocks the use of previously used passwords.

How to eliminate wrong answers

Option B is wrong because increasing the minimum password age to 7 days prevents users from changing passwords frequently to cycle back to an old password, but it does not prevent reuse of previous passwords after that period expires. Option C is wrong because enabling password expiration notifications only alerts users that their password will expire; it does not enforce any restriction on reusing old passwords. Option D is wrong because increasing the maximum password age to 30 days extends how long a password can be used before it must be changed, but it does not prevent the user from reusing a previous password when the change occurs.

292
MCQhard

A company uses a RAID 5 array for its file server. One disk fails, and the system continues to operate. However, during the rebuild process, a second disk fails. What is the likely consequence?

A.Performance degrades but data remains intact
B.Data is still available from parity
C.The system automatically switches to a hot spare
D.Data loss occurs
AnswerD

RAID 5 tolerates only one simultaneous disk failure, storing parity across all member disks. With one disk already failed, the array runs in degraded mode with no redundancy; a second failure during rebuild leaves insufficient parity to reconstruct missing data, so the volume is lost. This satisfies the stem's double-failure constraint.

Why this answer

RAID 5 tolerates exactly one disk failure by storing distributed parity across all member disks. When one disk fails, the array enters degraded mode and can still serve data by reconstructing missing blocks from parity. However, if a second disk fails before the first is rebuilt, the parity information is insufficient to reconstruct two missing data sets, resulting in complete data loss for the array.

Exam trap

The trap is assuming RAID 5 can survive any single failure plus a rebuild — candidates forget that the rebuild window is a period of zero redundancy, so a second failure during rebuild is catastrophic.

How to eliminate wrong answers

Option A is wrong because performance degradation without data loss describes a single-disk failure scenario, not a double failure — with two failed disks, RAID 5 cannot maintain data integrity. Option B is wrong because parity can only reconstruct one missing disk's worth of data; with two disks down, the parity equations are underdetermined and data cannot be recovered. Option C is wrong because hot spare activation is a configuration feature that may or may not exist, and even if a hot spare is present, it only helps if it kicks in before the second failure — the question states the second failure occurs during rebuild, so the spare (if any) is already being rebuilt and cannot save the array.

293
Multi-Selecthard

Which THREE of the following are characteristics of a SMART recommendation? (Select three.)

Select 3 answers
A.Measurable
B.General
C.Time-bound
D.Specific
E.Subjective
AnswersA, C, D

Measurable makes the recommendation verifiable: it specifies a quantifiable metric or threshold so the auditee and auditor can objectively confirm whether the action was implemented and effective, satisfying the SMART criterion that otherwise leaves recommendations unverifiable.

Why this answer

A SMART recommendation must be Measurable (A), meaning it includes quantifiable criteria or metrics (e.g., a percentage, count, or threshold) so progress and success can be objectively verified. It must also be Time-bound (C), specifying a deadline or timeframe (e.g., "within 90 days") so the recommendation has a defined completion point. Finally, it must be Specific (D), clearly stating the exact action, system, or process to be changed rather than a vague aspiration.

The unmarked options do not belong: General (B) contradicts the specificity requirement of SMART, and Subjective (E) is wrong because SMART criteria rely on objective, verifiable evidence rather than personal opinion.

294
MCQeasy

An organization's IT department has a policy that all new hires must sign an acceptable use policy (AUP) before gaining access to systems. During an audit, the IS auditor finds that several contractors were granted access without signing the AUP. Which of the following is the auditor's BEST recommendation?

A.Require the IT manager to manually verify AUP signatures before granting access.
B.Update the AUP to include contractors and re-communicate the policy.
C.Conduct additional security awareness training for all contractors.
D.Implement automated enforcement to block access until the AUP is signed.
AnswerD

Automated enforcement ensures compliance by preventing access until the AUP is acknowledged. This is the best recommendation because it addresses the root cause—human error or process bypass—and provides a preventive control. Manual reminders or training alone are less effective. Automated enforcement is a standard practice for ensuring policy compliance at scale.

Why this answer

The most effective recommendation is to implement automated enforcement that blocks system access until the AUP is signed. This preventive control ensures consistent compliance and eliminates the risk of human error. Other options are either detective or corrective and do not prevent unauthorized access in the first place.

Exam trap

The trap here is assuming that training or manual checks are sufficient when the issue is a lack of enforcement, not awareness.

295
MCQeasy

An IS auditor is reviewing the physical access controls at a data center. Which of the following is the MOST effective control to prevent tailgating?

A.Security guards at the entrance
B.CCTV cameras at the entrance
C.Mantrap
D.Biometric readers at all entrances
AnswerC

A mantrap permits only one person through an interlocking door sequence at a time, physically preventing an unauthorised individual from following an authenticated person. This directly satisfies the stem's constraint by eliminating the single-entry tailgating vector that badge readers alone cannot address.

Why this answer

A mantrap is a physical security control consisting of a small vestibule with two interlocking doors, where the first door must close and the person must be authenticated before the second door opens. This design physically prevents tailgating because only one person can occupy the space at a time, and unauthorized individuals cannot slip through behind an authorized person. It is the most effective preventive control specifically engineered to defeat tailgating.

Exam trap

CISA often tests the difference between preventive and detective physical controls — candidates pick CCTV or guards (detective/deterrent) when the question asks for the MOST effective control to PREVENT tailgating, which requires a physical interlock like a mantrap.

How to eliminate wrong answers

Option A is wrong because security guards are a deterrent and detective control — they can observe and challenge tailgaters, but human attention lapses and a determined tailgater can still slip past, especially during high-traffic periods. Option B is wrong because CCTV cameras are purely detective and after-the-fact — they record tailgating but do nothing to prevent it in real time. Option D is wrong because biometric readers authenticate the person presenting credentials but do not prevent a second person from following closely behind through the same door — biometrics alone do not stop tailgating without a physical interlock.

296
Multi-Selecteasy

An IS auditor is reviewing the ITIL incident management process. Which THREE are the correct priority levels and their typical definitions?

Select 3 answers
A.P1: Critical impact, immediate response required.
B.P4: Critical impact, requires escalation to senior management.
C.P2: Low impact, can be resolved within normal service hours.
D.P2: High impact, requires urgent response.
E.P3: Moderate impact, standard response time.
AnswersA, D, E

P1 denotes the highest priority, reserved for incidents causing critical business impact or major service outage, demanding immediate response and continuous effort until resolution. This matches the ITIL priority matrix, where priority derives from impact and urgency, so P1 definitions must reflect severe disruption requiring escalation.

Why this answer

Option A is correct because P1 is the highest priority level in ITIL incident management, reserved for critical impact incidents (e.g., major outages affecting the whole organization) that demand immediate response and often major incident procedures. Option D is correct because P2 represents high-impact incidents requiring an urgent response, typically affecting a significant user group or critical business function but not as catastrophically as P1. Option E is correct because P3 denotes moderate impact incidents handled with a standard response time under normal service desk workflows.

Option B is incorrect because P4 is the lowest priority (low impact, minor issue), not a critical-impact level requiring senior management escalation. Option C is incorrect because P2 is not defined as low impact resolved within normal service hours; that description better fits P4 or P3, whereas P2 requires urgent attention.

Exam trap

The trap here is that candidates often confuse P2 with low impact or normal service hours, but ITIL defines P2 as high impact requiring urgent response, not low impact, and P4 is never critical impact.

297
Multi-Selectmedium

An IS auditor is reviewing capacity management practices. Which TWO indicators suggest that proactive capacity management is being performed effectively?

Select 2 answers
A.Conducting business impact analysis (BIA) annually.
B.Reviewing backup logs for errors.
C.Monitoring resource utilization trends over time.
D.Setting threshold alerts for CPU, memory, and disk usage.
E.Analyzing historical cost data for IT infrastructure.
AnswersC, D

Tracking utilisation trends over time reveals gradual growth before thresholds are breached, enabling forecasting and timely scaling. This satisfies the stem's requirement for proactive capacity management, since trend analysis anticipates future demand rather than reacting to incidents. Point-in-time monitoring alone would be reactive, whereas historical baselines support informed planning decisions.

Why this answer

Option C is correct because proactive capacity management depends on continuously collecting and analyzing resource utilization metrics (CPU, memory, disk, network, I/O) over time to identify growth trends and forecast future demand before performance degrades. Option D is correct because configuring threshold alerts for CPU, memory, and disk usage enables early detection of approaching capacity limits, allowing remediation actions to be taken before service levels are impacted. Together, trend monitoring and threshold alerting are the hallmarks of a proactive, forecast-driven capacity management process.

Option A is not correct because a BIA is a business continuity/disaster recovery activity that identifies critical processes and recovery requirements, not a capacity management indicator. Option B is not correct because reviewing backup logs addresses backup integrity and recoverability, which is unrelated to capacity planning. Option E is not correct because analyzing historical cost data supports IT financial management and budgeting, not the technical forecasting of resource capacity needs.

Exam trap

CISA often tests the distinction between proactive and reactive activities, and candidates may confuse business continuity or cost analysis tasks with capacity management indicators.

298
MCQmedium

An IS auditor is performing a compliance audit of a data privacy regulation. Which of the following is the PRIMARY source of audit criteria?

A.Prior audit findings
B.Industry best practices
C.The specific requirements of the regulation
D.The organization's internal policies
AnswerC

The regulation's own text supplies the authoritative criteria against which compliance is measured, since the audit tests conformity with those mandated requirements rather than internal policy or generic frameworks. It directly satisfies the stem's demand for the primary source of audit criteria in a regulatory compliance audit.

Why this answer

In a compliance audit, the audit criteria are the standards, laws, regulations, or contractual requirements against which the auditor measures the organization's controls and practices. When auditing against a data privacy regulation, the specific requirements of that regulation are the authoritative source of criteria — they define what compliance actually means. Internal policies and best practices may be relevant context, but they cannot override or substitute for the regulatory requirements themselves.

Exam trap

CISA often tests the distinction between audit criteria and audit evidence — candidates incorrectly select internal policies or best practices because they sound authoritative, but the regulation itself is always the primary criteria for a regulatory compliance audit.

How to eliminate wrong answers

Option A is wrong because prior audit findings are historical observations about past gaps; they inform follow-up but do not establish the criteria for the current compliance audit. Option B is wrong because industry best practices are advisory and not legally binding — they may exceed or fall short of regulatory requirements and cannot serve as the primary benchmark for regulatory compliance. Option D is wrong because the organization's internal policies are what is being audited, not the criteria — if internal policies are weaker than the regulation, the regulation still governs.

299
MCQeasy

An IS auditor is reviewing the incident response (IR) process. Which of the following is the BEST way to test the effectiveness of the IR plan?

A.Checking the availability of forensic tools
B.Interviewing the IR team
C.Conducting a tabletop exercise
D.Reviewing IR policies and procedures
AnswerC

A tabletop exercise walks participants through a simulated incident, testing decision-making, roles, communication and plan completeness without production disruption. This validates the IR plan's effectiveness against the stem's requirement, unlike reviewing documentation, which only confirms the plan exists.

Why this answer

A tabletop exercise is the best way to test the effectiveness of an incident response plan because it simulates a realistic incident scenario and requires the IR team to walk through their roles, decisions, and communications in a facilitated discussion. This reveals gaps in the plan, unclear responsibilities, and coordination breakdowns without the risk or cost of a live simulation. It directly tests whether the plan works in practice, not just whether it exists on paper.

Exam trap

CISA often tests the difference between reviewing documentation (policies, procedures) and actually testing a plan — candidates pick 'reviewing IR policies' because it sounds thorough, but the question asks for the BEST way to TEST effectiveness, which requires an exercise like a tabletop.

How to eliminate wrong answers

Option A is wrong because checking the availability of forensic tools only verifies that tools exist and are accessible — it does not test whether the IR team can use them effectively during an actual incident or whether the plan's procedures are sound. Option B is wrong because interviewing the IR team gathers opinions and stated knowledge but does not validate that the plan functions under pressure or that team members can execute their roles in a coordinated way. Option D is wrong because reviewing IR policies and procedures is a documentation review that confirms the plan exists and is written correctly, but it provides no evidence that the plan works when executed.

300
MCQeasy

An IS auditor is reviewing how a data center protects its backup tapes while they are in transit to an offsite storage facility. Management states that tapes are encrypted before shipment and that a courier transports them in sealed containers. Which of the following is the MOST appropriate evidence to confirm that the tapes are protected in transit?

A.Review the encryption algorithm and key length used for the backup tapes.
B.Interview the backup administrator about the tape pickup schedule.
C.Examine the offsite storage vendor's SOC 2 report.
D.Inspect the courier's chain-of-custody logs and verify the sealed-container handoff signatures.
AnswerD

Chain-of-custody logs with signed handoffs demonstrate that the sealed containers were tracked from pickup to delivery, providing direct evidence that physical protection was maintained during transit. This is the strongest audit evidence available for the transit leg of the media lifecycle, since the auditor can trace each tape shipment and confirm no unaccounted gaps or broken seals occurred.

Why this answer

The scenario tests physical media protection during transit, so the auditor needs evidence covering the movement of tapes between sites. Signed chain-of-custody documentation with sealed-container handoffs directly evidences that custody was maintained and containers stayed intact from pickup to delivery, which is the specific control objective. Encryption, interviews, and vendor-side reports each address different phases of the media lifecycle and cannot substitute for transit custody records.

Exam trap

The trap here is assuming that encrypting backup tapes removes the need for physical transit controls, when custody documentation is still required to prove the media was protected and accounted for in transit.

Page 3

Page 4 of 13

Page 5