Courseiva

Certified Information Systems Auditor CISA (CISA) — Questions 301–375

934 questions total · 13pages · All types, answers revealed

Page 4

Page 5 of 13

Page 6
301
MCQhard

A multinational corporation is implementing a global IT governance framework. Which of the following challenges is MOST likely to arise?

A.Conflicting regulatory requirements
B.Standardizing hardware across regions
C.Training users on new procedures
D.Software licensing costs
AnswerA

Differing data protection, privacy, and financial reporting rules across jurisdictions force the framework to reconcile incompatible mandates, which is the central governance obstacle. A single global policy cannot satisfy every regulator simultaneously, so conflicting requirements are the most likely challenge.

Why this answer

A global IT governance framework must reconcile laws, regulations, and industry standards across many jurisdictions. Multinationals face conflicting requirements — for example, GDPR data residency in the EU versus data localization laws in other countries, or differing breach-notification timelines. These conflicts directly shape governance policies, controls, and reporting, making them the most likely and most impactful challenge.

Exam trap

The trap is selecting an operational or financial issue (hardware, training, licensing) when the question asks about governance — CISA expects you to recognize that governance challenges are regulatory and strategic, not tactical.

How to eliminate wrong answers

Option B is wrong because hardware standardization is an operational/engineering task, not a governance challenge, and it is usually solvable with procurement standards. Option C is wrong because user training is a routine change-management activity, not a structural governance conflict. Option D is wrong because software licensing costs are a financial/procurement concern, not a governance framework challenge.

302
MCQhard

During a software asset management (SAM) audit, it is discovered that the organization is using software that has reached end-of-life. Which of the following is the MOST significant risk associated with this situation?

A.Incompatibility with new hardware
B.Lack of security patches
C.Increased maintenance costs
D.License compliance issues
AnswerB

End-of-life software no longer receives vendor security patches, so known vulnerabilities remain unmitigated and exploitable. This is the most significant risk because it directly exposes the organisation to compromise, outweighing the lesser concerns of reduced support or licence compliance.

Why this answer

End-of-life software no longer receives security patches from the vendor, meaning any newly discovered vulnerabilities will remain unaddressed. This creates a direct and exploitable attack surface, making lack of security patches the most significant risk because it can lead to data breaches, system compromise, and regulatory non-compliance.

Exam trap

The trap here is that candidates often focus on immediate operational or financial impacts like cost or compatibility, but the CISA exam prioritizes security risks, especially unpatched vulnerabilities, as the most critical consequence of end-of-life software.

How to eliminate wrong answers

Option A is wrong because incompatibility with new hardware, while operationally inconvenient, is typically manageable through virtualization, compatibility layers, or hardware refreshes and does not introduce active security threats. Option C is wrong because increased maintenance costs, though a financial concern, are a secondary business impact rather than a primary security or compliance risk; the organization could choose to absorb the cost without immediate harm. Option D is wrong because license compliance issues are a legal and contractual risk, but end-of-life software often has no active license requirement, and the greater danger is the absence of security updates that protect the organization from exploitation.

303
MCQmedium

An IS auditor finds that a project failed to meet its objectives because key stakeholders were not involved in the requirements definition phase. Which phase of the SDLC was most neglected?

A.Requirements analysis
B.Development
C.Design
D.Testing
AnswerA

Stakeholder involvement is a requirements analysis activity; excluding them there produces unvalidated, incomplete requirements that cascade into a project failing its objectives. The neglected phase is therefore requirements analysis, where elicitation and sign-off should have occurred.

Why this answer

The requirements analysis phase is where stakeholder needs are formally captured and documented. Without key stakeholder involvement, the project lacks a validated baseline of what must be built, leading to misaligned objectives and scope creep. The IS auditor’s finding directly points to a failure in this phase, as it is the only SDLC phase that defines the project’s success criteria from the user’s perspective.

Exam trap

The trap here is that candidates confuse the symptoms of failure (e.g., poor design or failed tests) with the root cause, which is always the phase where the input was missing—requirements analysis.

How to eliminate wrong answers

Option B is wrong because the development phase focuses on coding and building the system based on already-defined requirements; neglecting stakeholder input here would not cause the initial objective failure. Option C is wrong because the design phase translates requirements into technical specifications and architecture; if requirements were incomplete, design would be flawed, but the root cause remains the earlier phase. Option D is wrong because testing verifies that the system meets the documented requirements; it cannot compensate for missing or incorrect requirements that were never captured.

304
MCQeasy

Which of the following is the PRIMARY reason for implementing network segmentation?

A.To comply with licensing requirements.
B.To simplify IP address management.
C.To contain security breaches and limit lateral movement.
D.To improve network performance.
AnswerC

Segmentation places enforcement points between network zones, so a compromised host cannot freely reach other systems. This directly satisfies the containment constraint: it restricts lateral movement, limiting blast radius and buying incident responders time before the attacker pivots to critical assets.

Why this answer

The primary reason for network segmentation is to contain security breaches and limit lateral movement — by dividing the network into isolated zones, an attacker who compromises one segment cannot freely move to others. This is a foundational defense-in-depth control that reduces the blast radius of a breach and protects critical assets. While segmentation can have secondary benefits, security containment is its primary purpose in modern network design.

Exam trap

CISA often tests the distinction between primary and secondary benefits — candidates pick 'improve network performance' because segmentation can reduce broadcast traffic, but the PRIMARY reason is security containment and limiting lateral movement.

How to eliminate wrong answers

Option A is wrong because licensing compliance is unrelated to network segmentation — licensing is a legal/procurement matter, not a network architecture driver. Option B is wrong because simplifying IP address management is a potential administrative side effect of good network design, but it is not the primary reason organizations invest in segmentation. Option D is wrong because improving network performance can be a secondary benefit (by reducing broadcast domains and congestion), but it is not the primary reason — security containment is the driving rationale, especially given regulatory and threat-landscape pressures.

305
MCQhard

An organization is designing an IT balanced scorecard to align IT performance with business goals. Which perspective would include metrics related to IT employee skills and training?

A.Internal process
B.Customer
C.Financial
D.Learning and growth
AnswerD

The learning and growth perspective covers the intangible enablers of the other three perspectives, specifically staff competencies, training and skills development. It is the only balanced scorecard perspective addressing IT employee capabilities, so metrics on training and skills sit here rather than in business value, user orientation or operational excellence.

Why this answer

The Learning and Growth perspective of the IT balanced scorecard focuses on the intangible assets and capabilities that enable the other perspectives, including employee skills, training, knowledge management, and organizational culture. Metrics such as training hours per employee, certification rates, and employee satisfaction directly measure how well IT is developing its workforce to support business goals.

Exam trap

CISA often tests the four balanced scorecard perspectives, and candidates frequently confuse Learning and Growth with Internal Process because both involve internal IT activities; the key differentiator is that Learning and Growth is about people and capabilities, not operational workflows.

How to eliminate wrong answers

Option A is wrong because the Internal Process perspective measures operational efficiency, quality, and process improvement—not employee development. Option B is wrong because the Customer perspective focuses on user satisfaction, service delivery, and business partner feedback. Option C is wrong because the Financial perspective tracks costs, ROI, and budget performance, not human capital development.

306
MCQhard

An IS auditor is evaluating an organization's capacity management process for a critical database server. The auditor observes that CPU utilization averages 85% during peak hours, memory utilization is at 90%, and disk I/O wait times are consistently high. The organization has no formal capacity plan. Which of the following is the MOST significant risk the auditor should report?

A.The lack of a formal capacity plan may lead to unplanned outages and inability to meet service level agreements.
B.The high CPU and memory utilization may indicate a need for additional hardware, which should be procured immediately.
C.The disk I/O wait times suggest that the storage area network (SAN) is misconfigured and requires tuning.
D.The organization is not complying with industry best practices for capacity management, which could result in regulatory penalties.
AnswerA

This is the most significant risk because without a capacity plan, the organization cannot proactively address resource constraints. High utilization and I/O wait times indicate the server is near its limits, and any further growth or unexpected demand could cause performance degradation or outages, directly impacting SLAs.

Why this answer

The absence of a formal capacity plan is the most critical risk because it leaves the organization unable to predict and prevent performance issues. High utilization metrics indicate the server is already stressed, and without a plan, the organization cannot ensure it will meet current and future demands, leading to potential outages and SLA breaches. Other issues like hardware needs or SAN tuning are symptoms that should be addressed within a capacity management framework.

Exam trap

The trap here is focusing on the immediate technical symptoms (high utilization) rather than the underlying governance failure of not having a capacity plan, which is the root cause of the risk.

307
MCQmedium

An organization uses a cloud-based ERP system to manage financial transactions. The system is accessed by employees in finance, procurement, and sales departments. The IS auditor is reviewing the user access review process. The access review is performed quarterly by the IT manager using a report generated by the ERP system. The report lists all users and their roles. The IT manager manually checks off users who are still employed and approves the report. The auditor notes that the IT manager does not have detailed knowledge of job functions in each department. Additionally, the ERP system allows role combinations that may create segregation of duties conflicts, such as a user having both 'create purchase order' and 'approve purchase order' roles. The company's policy requires segregation of duties reviews to be performed by business process owners. Which of the following is the BEST recommendation?

A.Increase the frequency of access reviews to monthly
B.Implement an automated tool to identify segregation of duties conflicts
C.Assign the access review to business process owners from each department
D.Require the IT manager to obtain confirmation from each department head
AnswerC

Business process owners hold the job-function knowledge needed to judge whether assigned roles are appropriate, and policy already mandates their involvement in segregation of duties reviews. Delegating the quarterly review to them satisfies that requirement and enables detection of toxic role combinations the IT manager cannot assess.

Why this answer

The core issue is that the IT manager lacks the business process knowledge to assess whether role combinations create segregation of duties (SoD) conflicts. Company policy explicitly requires SoD reviews to be performed by business process owners. Assigning the access review to business process owners from each department (Option C) directly aligns with policy and ensures that those with functional knowledge evaluate whether role assignments violate SoD rules, such as a user having both 'create purchase order' and 'approve purchase order' roles.

Exam trap

The trap here is that candidates often choose an automated tool (Option B) as the 'best' technical solution, but the question emphasizes policy compliance and the need for business process owner involvement, not just technical detection.

How to eliminate wrong answers

Option A is wrong because increasing the frequency of reviews does not address the root cause—the reviewer lacks the business knowledge to identify SoD conflicts; monthly reviews by an unqualified reviewer would still miss conflicts. Option B is wrong because while an automated tool can flag potential SoD conflicts, the question asks for the BEST recommendation given the policy requirement that business process owners perform SoD reviews; automation is a supporting control, not a substitute for assigning the review to the correct personnel. Option D is wrong because requiring the IT manager to obtain confirmation from department heads still leaves the IT manager as the primary reviewer, which violates the policy that business process owners themselves should perform the review, and it introduces a reliance on indirect confirmation rather than direct ownership.

308
MCQeasy

An organization has defined an SLA that requires critical incidents to be resolved within 4 hours. A P1 incident is reported at 10:00 AM. At what time must the incident be resolved to meet the SLA?

A.2:00 PM
B.4:00 PM
C.6:00 PM
D.12:00 PM
AnswerA

Resolving by 2:00 PM satisfies the four-hour SLA window starting at 10:00 AM, giving the critical incident team the full mandated response period. Any later resolution breaches the defined service commitment, triggering escalation and SLA penalty provisions under the organisation's incident management process.

Why this answer

The SLA requires critical incidents to be resolved within 4 hours. A P1 incident reported at 10:00 AM must therefore be resolved by 2:00 PM, which is exactly 4 hours later. This is a straightforward time calculation based on the SLA definition.

Exam trap

CISA often tests basic SLA calculations, and the trap is misreading the start time or adding the wrong number of hours, or confusing the deadline with an earlier resolution time.

How to eliminate wrong answers

Option B is wrong because 4:00 PM would be 6 hours after 10:00 AM, exceeding the 4-hour SLA. Option C is wrong because 6:00 PM would be 8 hours later, far beyond the SLA. Option D is wrong because 12:00 PM is only 2 hours after 10:00 AM, which is earlier than the SLA deadline but not the required resolution time; the question asks when it must be resolved to meet the SLA, which is the deadline, not an earlier time.

309
Multi-Selectmedium

Which TWO of the following are typically included in the fieldwork phase of an IS audit? (Select two.)

Select 2 answers
A.Defining audit scope
B.Testing controls
C.Developing the audit program
D.Issuing the draft report
E.Performing walkthroughs
AnswersB, E

Testing controls occurs during fieldwork, where the auditor executes procedures such as inspection, inquiry, observation and re-performance to gather evidence supporting the preliminary control effectiveness conclusions formed during planning, directly satisfying the stem's fieldwork requirement.

Why this answer

Option B (Testing controls) is correct because the fieldwork phase is where the auditor executes the audit program by gathering evidence and evaluating whether controls are designed and operating effectively, which is the core of substantive and compliance testing. Option E (Performing walkthroughs) is correct because walkthroughs are an evidence-gathering technique performed during fieldwork to trace transactions or processes through the system and confirm the auditor's understanding of controls in operation. Option A (Defining audit scope) is incorrect because scope definition occurs during the planning phase, before fieldwork begins.

Option C (Developing the audit program) is incorrect because the audit program is designed in the planning phase to guide the subsequent fieldwork. Option D (Issuing the draft report) is incorrect because reporting occurs after fieldwork is completed, during the reporting phase.

310
MCQhard

An IS auditor is evaluating the encryption strategy for a healthcare organization subject to HIPAA. Which of the following is the MOST significant risk if the organization relies solely on encryption as a safe harbor?

A.Encryption keys are stored on the same server as the encrypted data.
B.The encryption algorithm used is not FIPS 140-2 validated.
C.Encryption is not applied to all ePHI in transit.
D.The encryption key rotation policy is not documented.
AnswerA

Storing keys alongside ciphertext collapses the two-party separation encryption depends on: anyone gaining server access obtains both data and keys, rendering encryption ineffective. This defeats HIPAA's safe harbour premise, which assumes keys remain protected and separate, so a single compromise exposes all protected health information.

Why this answer

HIPAA's encryption safe harbor only applies if ePHI is rendered unusable, unreadable, or indecipherable to unauthorized persons. If the encryption keys are stored on the same server as the encrypted data, an attacker who compromises that server obtains both the ciphertext and the keys, effectively defeating the encryption. This is the most significant risk because it nullifies the safe harbor protection entirely.

Exam trap

CISA often tests the misconception that any encryption satisfies the safe harbor, when the real trap is key management: storing keys with the data defeats encryption and is the most severe risk.

How to eliminate wrong answers

Option B is wrong because although FIPS 140-2 validation is a recognized standard, using a non-validated algorithm is a compliance weakness rather than an immediate defeat of the safe harbor; the data may still be encrypted with a strong algorithm. Option C is wrong because failing to encrypt all ePHI in transit is a gap in coverage, but it does not undermine the encryption that is applied; it is a scope issue, not a key-management failure. Option D is wrong because an undocumented key rotation policy is a documentation and governance weakness, not an immediate compromise of the encryption's effectiveness.

311
Multi-Selecteasy

An IS auditor is reviewing the backup process for a critical database. Which TWO of the following are essential controls to ensure data recoverability?

Select 2 answers
A.Automated job scheduling for backups.
B.Offsite storage of backup media.
C.Regular restore testing of backups.
D.Encryption of backup data.
E.Backup retention period of at least one year.
AnswersB, C

Offsite storage places backup media beyond the reach of site-specific events such as fire, flood or theft that could destroy both production systems and locally held copies. This satisfies the recoverability requirement by ensuring a surviving copy exists after a site-wide disaster.

Why this answer

Option B (offsite storage of backup media) is essential because it ensures that a viable copy of the data survives a site-level disaster such as fire, flood, or theft that destroys the primary data center, which is a core requirement for recoverability. Option C (regular restore testing of backups) is essential because backups are only proven recoverable when restores are actually performed and validated; untested backups may fail due to media errors, corrupted files, or incomplete jobs, so periodic restore drills confirm the recovery capability and RTO/RPO assumptions. Option A (automated job scheduling) improves reliability and consistency but is a convenience/efficiency control, not a guarantee of recoverability, since scheduled jobs can still fail silently.

Option D (encryption of backup data) is a confidentiality control that protects data at rest or in transit but does nothing to ensure the data can be restored. Option E (a one-year retention period) is an arbitrary retention choice driven by business, legal, and regulatory requirements rather than a universal essential control for recoverability.

Exam trap

The trap here is that candidates often confuse operational controls (like scheduling or encryption) with recoverability controls, forgetting that a backup is only as good as its ability to be restored from a separate location.

312
MCQeasy

In a waterfall SDLC, which phase requires formal sign-off from the business owner before proceeding to the next phase?

A.Development phase
B.Requirements phase
C.Design phase
D.Testing phase
AnswerB

Requirements are baselined and formally approved by the business owner before design begins, since later phases build directly on that frozen scope. Sign-off here authorises the project to proceed, whereas design and testing approvals occur within their own phases.

Why this answer

In a waterfall SDLC, the requirements phase concludes with formal business owner sign-off because it establishes the baseline for all subsequent design, development, and testing work. Once requirements are approved, changes become costly and require change control, so the business owner must formally accept the documented requirements before the project proceeds. This sign-off ensures mutual agreement on scope and reduces the risk of rework downstream.

Exam trap

CISA often tests whether candidates know which waterfall phase requires business owner sign-off, trapping those who pick design or testing because those phases also involve approvals but not the formal scope-baselining gate.

How to eliminate wrong answers

Option A (Development phase) is wrong because development sign-off is typically a technical milestone, not a business owner gate; the business owner's critical approval point is earlier, at requirements. Option C (Design phase) is wrong because design sign-off is usually a technical review (architecture, security) rather than the business owner's formal acceptance of scope. Option D (Testing phase) is wrong because testing sign-off (UAT) validates the built system against requirements, but the formal business owner gate that locks scope occurs at the end of requirements.

313
Multi-Selectmedium

An IS auditor is reviewing the design phase of a new procurement system. Which TWO of the following controls are MOST critical to include in the system design to prevent unauthorized purchases?

Select 2 answers
A.Mandatory approval workflows for purchase orders above a threshold.
B.Automated performance reports on purchase cycle times.
C.Segregation of duties between requisition and approval.
D.Real-time audit logging of all purchase transactions.
E.Encryption of purchase order data in transit.
AnswersA, C

Mandatory approval workflows enforce segregation of duties, ensuring purchase orders exceeding a defined threshold require authorised sign-off before commitment. This directly prevents unauthorised purchases by blocking orders that lack the required approval chain, satisfying the design-phase control objective.

Why this answer

Option A is correct because mandatory approval workflows for purchase orders above a defined threshold enforce an authorization control at the point of transaction, ensuring that high-value purchases cannot be committed without the required management sign-off, which directly prevents unauthorized purchases. Option C is correct because segregation of duties between requisition and approval ensures that the person initiating a purchase cannot also authorize it, removing the ability for a single individual to create and approve unauthorized purchases and providing a preventive, design-level control. Option B is not correct because automated performance reports on purchase cycle times are a detective/operational efficiency metric and do not prevent unauthorized purchases.

Option D is not correct because real-time audit logging is a detective control that records activity after the fact rather than preventing unauthorized purchases. Option E is not correct because encryption of purchase order data in transit protects confidentiality against interception but does not address the authorization of purchases.

Exam trap

The trap here is that candidates often confuse detective controls (like audit logging) or security controls (like encryption) with preventive controls that directly stop unauthorized actions, failing to recognize that only preventive controls like approval workflows and segregation of duties address the root cause of unauthorized purchases.

314
MCQmedium

An IS auditor is reviewing an organization's data classification policy. Which of the following findings is MOST critical?

A.Employees receive data classification training only once per year
B.Data classification is performed manually without automated tools
C.Sensitive data is not encrypted at rest
D.Data owners have not been identified for most data assets
AnswerD

Without identified data owners, no one is accountable for classifying, protecting or authorising access to data assets, undermining the entire classification policy. This governance gap is more critical than documentation or labelling weaknesses because ownership underpins every subsequent control.

Why this answer

Without identified data owners, no one is accountable for classifying, protecting, or granting access to data assets. This foundational gap undermines the entire data classification policy, making it impossible to enforce controls like encryption or access reviews. The CISA emphasizes that data owner assignment is the first step in any data governance framework.

Exam trap

The trap here is that candidates focus on visible technical controls like encryption (Option C) rather than the foundational governance requirement of data ownership, which the CISA considers more critical for policy effectiveness.

How to eliminate wrong answers

Option A is wrong because annual training, while not ideal, is a common baseline and does not directly break the classification policy; the critical failure is lack of ownership, not training frequency. Option B is wrong because manual classification can be acceptable in small environments or as a starting point; automated tools are a control enhancement, not a requirement. Option C is wrong because encryption at rest is a technical safeguard that should be applied based on classification, but without identified data owners, the classification itself is unenforceable.

315
Multi-Selecthard

An IS auditor is reviewing an organization's incident management process after a ransomware attack encrypted several file servers. Which TWO of the following should the auditor verify as part of assessing the effectiveness of the incident response? (Choose two.)

Select 2 answers
A.Whether the organization's antivirus signatures were updated on the same day as the attack
B.Whether the ransom demand was paid and whether the payment was properly authorized
C.Whether the organization's cyber insurance policy premium was paid before the incident occurred
D.Whether backups were isolated from the production network and restoration was successfully tested
E.Whether the incident was detected, contained, and communicated in accordance with the response plan
AnswersD, E

Ransomware commonly spreads to connected backup systems, so isolating backups from production and verifying that restoration actually works are essential controls. An untested or network-accessible backup may be encrypted along with production data. Confirming both isolation and successful restoration directly demonstrates whether the organization can recover without paying a ransom.

Why this answer

Assessing incident response effectiveness requires evidence that the organization could detect and contain the attack, communicate appropriately, and recover its data. Backup isolation and tested restoration, along with adherence to the response plan for detection, containment, and communication, directly demonstrate those capabilities. The other items address preventive metrics or financial matters that do not measure response performance.

Exam trap

The trap here is selecting financial or single-point preventive indicators, such as ransom payment or antivirus signature dates, instead of the operational capabilities that determine whether the incident was actually contained and recovered.

316
Drag & Dropmedium

Order the steps for conducting an audit engagement from start to finish.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Audit engagement follows: planning (scope, program), fieldwork, analysis, and reporting with management review.

317
Multi-Selectmedium

An IS auditor is reviewing the physical access controls at a data center. Which TWO of the following are the MOST effective controls to prevent unauthorized tailgating?

Select 2 answers
A.CCTV cameras at entry points.
B.Security guards checking badges.
C.Mantrap with interlocking doors.
D.Turnstiles that allow only one person per authentication.
E.Biometric authentication.
AnswersC, D

A mantrap with interlocking doors physically admits one person per cycle, so a second individual cannot follow through before the first door closes. This directly satisfies the stem's requirement to prevent unauthorised tailgating, unlike detective controls such as CCTV, which record the breach only after entry has occurred.

Why this answer

Option C, a mantrap with interlocking doors, is correct because it creates a controlled vestibule where the first door must close and the person must be authenticated before the second door opens, physically preventing a second individual from following through. Option D, turnstiles that allow only one person per authentication, is correct because the physical barrier permits exactly one authenticated entry at a time, so a tailgater cannot pass without their own valid credential. Option A, CCTV cameras, is only a detective control that records events after the fact and does not stop tailgating.

Option B, security guards checking badges, is a deterrent and detective measure but is subject to human error, distraction, and social-engineering bypass. Option E, biometric authentication, verifies the identity of the person authenticating but does not by itself prevent a second person from walking through the opened door behind them.

318
MCQhard

An IS auditor is reviewing the incident management process. Incidents are categorized as P1 (critical) through P4 (low). The SLA for P1 incidents requires initial response within 15 minutes and resolution within 4 hours. The auditor notes that the average time to respond to P1 incidents is 12 minutes, but the average resolution time is 6 hours. The root cause analysis shows that many P1 incidents are due to known errors documented in the known error database (KEDB). What is the most significant finding?

A.Problem management is not effectively utilizing the KEDB to prevent recurring incidents.
B.The average resolution time for P1 incidents exceeds SLA.
C.The average response time for P1 incidents is within SLA.
D.Incident management is not escalating P1 incidents properly.
AnswerA

Known errors in the KEDB should drive permanent fixes through problem management, eliminating recurrence. Resolution averaging six hours against a four-hour SLA, with recurring known errors, shows problem management is not converting KEDB entries into root-cause resolutions.

Why this answer

If known errors are causing P1 incidents, problem management should have identified workarounds or permanent fixes. The fact that these incidents recur indicates a weakness in the problem management process, which should reduce incidents from known errors.

319
MCQmedium

During an agile software development project, a sprint review meeting is conducted. What is the PRIMARY purpose of this meeting from an IS audit perspective?

A.To identify and document lessons learned for process improvement
B.To demonstrate the working product increment to stakeholders and gather feedback
C.To assign tasks to team members for the current sprint
D.To plan the tasks for the next sprint
AnswerB

The sprint review inspects the completed increment against acceptance criteria, giving stakeholders tangible evidence of progress and a forum to raise issues. This transparency lets auditors verify that delivered functionality matches requirements rather than relying solely on documentation.

Why this answer

The sprint review is a key control in agile to demonstrate completed work to stakeholders and obtain feedback. It serves as a form of user acceptance testing and helps ensure the product meets stakeholder needs.

320
MCQeasy

During a post-implementation review of a financial system, an IS auditor finds that several critical reports are not being generated correctly. Which of the following should the auditor recommend FIRST?

A.Conduct a new round of user acceptance testing.
B.Review the system configuration and compare with user requirements.
C.Disable the incorrect reports and create manual workarounds.
D.Immediately patch the system to fix the report generation.
AnswerB

Comparing system configuration against documented user requirements establishes whether the reporting defects stem from misconfiguration or from requirements never implemented. This diagnostic step precedes remediation, ensuring recommendations target the actual cause rather than merely retraining users or patching reports.

Why this answer

When reports are not generating correctly post-implementation, the auditor's first step should be to determine the root cause by reviewing the system configuration against documented user requirements. This diagnostic step identifies whether the issue is a configuration gap, a requirements misunderstanding, or a defect — informing any subsequent remediation. Jumping to fixes or workarounds without understanding the cause risks masking the real problem.

Exam trap

CISA often tests the principle that auditors should diagnose before remediating — candidates who pick 'patch immediately' or 'disable the reports' confuse the auditor's assurance role with an IT operations role.

How to eliminate wrong answers

Option A is wrong because conducting a new round of UAT is premature — UAT is a validation activity, not a diagnostic one, and should follow root-cause analysis, not precede it. Option C is wrong because disabling reports and creating manual workarounds is a compensating control that hides the problem rather than resolving it, and it introduces operational risk. Option D is wrong because immediately patching the system without understanding the cause may not fix the issue and could introduce new defects; remediation should follow diagnosis.

321
Multi-Selecteasy

An organization is implementing a data loss prevention (DLP) solution. Which TWO of the following are key considerations for effective DLP deployment?

Select 2 answers
A.Implementing DLP in monitoring mode initially to baseline traffic
B.Deploying DLP agents on all endpoints before defining policies
C.Encrypting all data at rest and in transit as a prerequisite
D.Classifying data based on sensitivity and criticality
E.Replacing user security awareness training with automated DLP
AnswersA, D

Deploying DLP in monitoring mode first establishes a behavioural baseline of sensitive-data flows without blocking legitimate business activity. This satisfies the stem's requirement for effective deployment by revealing false positives and policy gaps before enforcement, letting the organisation tune rules and classify data accurately prior to switching to active blocking.

Why this answer

Option A is correct because deploying DLP in monitoring (discovery/audit) mode first lets the organization baseline normal data flows, identify false positives, and tune policies before enforcing blocking actions, which minimizes business disruption. Option D is correct because effective DLP fundamentally depends on data classification—labeling data by sensitivity and criticality (e.g., PII, PHI, IP) so policies can accurately identify what to protect and how. Option B is wrong because policies and classification must be defined before agent rollout; deploying agents first without policies provides no meaningful protection and creates management overhead.

Option C is wrong because encryption at rest and in transit is a complementary data-protection control, not a prerequisite for DLP deployment. Option E is wrong because DLP augments, not replaces, user security awareness training, which remains essential for reducing human-driven data loss.

Exam trap

CISA often tests candidates who assume DLP should be deployed in blocking mode immediately or that encryption alone satisfies DLP, rather than recognizing the need for baselining and data classification first.

322
MCQmedium

An organization's security team proposes deploying a network-based intrusion prevention system (IPS) inline at the internet perimeter. Management asks the IS auditor to comment on the operational implications before approving the purchase. Which of the following should the auditor identify as the MOST significant operational risk of the inline placement?

A.The IPS will be unable to inspect encrypted traffic without additional decryption capability.
B.A false positive or device failure could block legitimate business traffic and cause an outage.
C.The IPS will not be able to correlate events with host-based logs from servers.
D.Signature updates will consume WAN bandwidth and degrade branch office performance.
AnswerB

Because inline prevention sits directly in the traffic path, a misclassified signature, a capacity limit, or a hardware fault can drop legitimate sessions for every user behind it. Availability of business services becomes dependent on the IPS tuning and resilience. This is the most significant operational risk and explains why fail-open design, bypass, and staged tuning are essential before enforcement mode is enabled.

Why this answer

Inline prevention changes the device from a passive observer into a component whose failure or misconfiguration directly affects service delivery. Every packet traverses it, so latency, throughput limits, and false positives translate into user-visible outages. The auditor should therefore focus on fail-open behavior, bypass paths, change control for signature updates, and a tuning period in detection mode before blocking is enabled.

Exam trap

The trap here is evaluating the IPS primarily as a detection tool and overlooking that inline enforcement makes the device a single point of failure for business traffic.

323
MCQeasy

An IS auditor is evaluating the effectiveness of an organization's change management process. Which of the following is the most important control to verify during the audit?

A.All changes are approved by the IT manager.
B.Emergency changes are documented after implementation.
C.A segregation of duties exists between development and production.
D.Change requests are prioritized by business impact.
AnswerC

Segregation of duties between development and production prevents developers from promoting their own code, which is the control that most directly mitigates unauthorised or untested changes. Verifying this separation confirms the change management process enforces independent review and approval before production deployment.

Why this answer

Segregation of duties between development and production environments ensures that code cannot be directly moved from development to production without independent review and testing. This control prevents unauthorized or untested code from affecting live systems, which is a fundamental principle of change management. Without this separation, a developer could introduce malicious or defective code directly into production, bypassing all quality and security checks.

Exam trap

The trap here is that candidates often focus on approval or prioritization controls (options A and D) as the most important, overlooking the foundational technical control of segregation of duties that directly prevents unauthorized code from reaching production.

How to eliminate wrong answers

Option A is wrong because requiring all changes to be approved by the IT manager is a basic authorization control, but it does not address the more critical risk of unauthorized code being introduced directly into production; approval alone cannot prevent a developer from bypassing the process. Option B is wrong because while documenting emergency changes after implementation is a compensating control, it is not the most important control; the highest priority is preventing unauthorized changes from reaching production, which segregation of duties achieves. Option D is wrong because prioritizing change requests by business impact is a project management activity that helps allocate resources, but it does not enforce any technical barrier against unauthorized code movement or ensure the integrity of the production environment.

324
MCQmedium

During an audit, the IS auditor discovers that the audit log for a critical server is overwritten every 24 hours. The auditor wants to ensure logs are preserved for a longer period. Which of the following recommendations is most appropriate?

A.Implement a manual backup of logs daily
B.Reduce the logging level to minimize data
C.Increase the log size to retain more data
D.Configure the server to archive logs to a centralized log management system
AnswerD

Forwarding logs to a centralised log management system preserves them beyond the server's 24-hour overwrite cycle, and typically enforces retention and access controls. Local archiving on the same server would still be vulnerable to the same overwrite and tampering risks.

Why this answer

The most appropriate recommendation is to configure the server to archive logs to a centralized log management system. This ensures logs are preserved beyond the 24-hour overwrite window by sending them to a separate, persistent storage location, which also supports security monitoring, forensics, and compliance requirements. Centralized logging (e.g., using syslog, SIEM, or a dedicated log collector) provides redundancy, integrity checks, and long-term retention without relying on the local server's limited storage.

Exam trap

The trap here is that candidates may choose Option C (increase log size) thinking it solves the retention issue, but they overlook that it only postpones the overwrite rather than providing a permanent, auditable archive, which is the core requirement for compliance and forensic readiness.

How to eliminate wrong answers

Option A is wrong because implementing a manual backup of logs daily is error-prone, relies on human intervention, and does not guarantee logs are captured before the 24-hour overwrite cycle completes; it also lacks automation and scalability. Option B is wrong because reducing the logging level to minimize data would discard potentially critical security events, defeating the purpose of preserving logs for audit and investigation. Option C is wrong because increasing the log size only delays the overwrite cycle but does not solve the fundamental retention problem; logs will still be overwritten once the increased capacity is exhausted, and it does not provide off-site or centralized storage.

325
MCQeasy

Which testing type is performed by end-users to verify that the system meets their needs?

A.Security testing
B.Integration testing
C.User acceptance testing
D.Unit testing
AnswerC

User acceptance testing is executed by end-users themselves, directly satisfying the stem's requirement that testing be performed by end-users. It validates the system against business needs and real-world workflows rather than technical specifications, confirming fitness for purpose before go-live. This distinguishes it from unit, integration and system testing, which developers or testers conduct.

Why this answer

User acceptance testing (UAT) is the final phase of the testing lifecycle where actual end-users validate that the system fulfills their business requirements and is ready for production deployment. Unlike technical testing types, UAT focuses on real-world workflows, data accuracy, and usability to confirm the system meets the agreed-upon acceptance criteria.

Exam trap

The trap here is that candidates often confuse user acceptance testing with system testing or integration testing, assuming any 'end-user' involvement means UAT, but UAT specifically requires users to validate business needs, not technical correctness.

How to eliminate wrong answers

Option A is wrong because security testing is a specialized technical test focused on identifying vulnerabilities, threats, and compliance gaps (e.g., OWASP Top 10, penetration testing), not on verifying that the system meets end-user needs. Option B is wrong because integration testing verifies that individual modules or services interact correctly (e.g., API contracts, data flow between subsystems), but it does not involve end-user validation of business requirements. Option D is wrong because unit testing is performed by developers on individual code components (e.g., functions, methods) to catch defects early, and it has no involvement from end-users.

326
MCQmedium

Which of the following is the BEST control to ensure that user acceptance testing (UAT) is effective?

A.UAT scripts are written by developers
B.UAT is performed after deployment
C.UAT testers are from the business and use realistic data
D.UAT is conducted by the quality assurance team
AnswerC

Effectiveness depends on testers representing real users exercising genuine business workflows against representative data. Business testers with realistic data validate that the system meets actual operational needs, whereas IT staff or synthetic data would miss usability and process gaps.

Why this answer

UAT should be performed by actual end users using real data to validate business requirements.

327
Multi-Selectmedium

An IS auditor is reviewing a change management process. Which TWO elements should be documented in a normal change request to ensure adequate governance? (Select TWO)

Select 2 answers
A.Test plan
B.Vendor contact information
C.Change requester's name
D.Rollback plan
E.Project budget remaining
AnswersA, D

A test plan evidences that the change was verified before release, confirming the requester identified how functionality and related controls would be validated. Without it, governance cannot demonstrate that the change works as intended or that regression risk was assessed prior to production deployment.

Why this answer

A test plan (A) is correct because a normal change request must document how the change will be verified before implementation, including test cases, expected results, and acceptance criteria, which provides evidence that the change was validated and supports governance over change risk. A rollback plan (D) is correct because it defines the documented steps, triggers, and responsible parties for reverting the change if it fails or causes an incident, ensuring business continuity and recoverability are addressed before approval. Vendor contact information (B) is not a required element of a standard change request; it is only relevant for vendor-supported changes and is not part of the governance documentation for every change.

The change requester's name (C) is typically captured as basic identification metadata, but it does not by itself ensure adequate governance of the change's risk and validation. Project budget remaining (E) relates to financial tracking and is not a required component of a change request's governance documentation.

Exam trap

CISA often tests the misconception that administrative details (requester name, vendor contact, budget) are governance elements — the exam expects candidates to identify the two elements that directly support change validation and risk mitigation: test plan and rollback plan.

328
Multi-Selectmedium

An IS auditor is reviewing an organization's IT governance framework and notes that the board of directors has established an IT strategy committee. Which TWO of the following are the MOST appropriate responsibilities for this committee? (Choose two.)

Select 2 answers
A.Designing and implementing IT internal controls over financial reporting.
B.Managing day-to-day IT operations and resolving technical issues.
C.Monitoring the performance of IT investments and ensuring benefits realization.
D.Approving the IT strategic plan and ensuring alignment with business objectives.
E.Conducting technical vulnerability assessments and penetration testing.
AnswersC, D

Monitoring IT investment performance and benefits realization is a key governance responsibility of the IT strategy committee. By overseeing whether IT projects deliver expected value, the committee ensures accountability and supports continuous improvement. This oversight helps prevent wasteful spending and ensures that IT contributes to business success.

Why this answer

The IT strategy committee, as a board-level body, should focus on strategic oversight: approving the IT strategic plan and ensuring alignment with business objectives, and monitoring IT investment performance and benefits realization. These responsibilities ensure that IT supports the organization's goals and delivers value. Operational tasks such as managing daily operations, designing controls, or conducting technical tests are management responsibilities and fall outside the committee's governance mandate.

Exam trap

The trap here is confusing governance with management, leading to the selection of operational tasks that are not appropriate for a board-level committee.

329
MCQmedium

An IS auditor is reviewing an organization's IT governance structure. The board of directors has delegated all IT oversight to the CIO, who reports to the CFO. The auditor finds that the board receives only annual summaries of IT performance and never reviews IT risks. Which of the following is the MOST significant governance concern?

A.The board has not retained ultimate responsibility for IT oversight.
B.The CFO should not have IT reporting to them because it creates a conflict of interest.
C.IT performance is not measured using balanced scorecard metrics.
D.The CIO lacks the authority to implement IT strategies.
AnswerA

The board is ultimately responsible for IT governance, including risk oversight. By delegating all oversight to the CIO and only receiving annual summaries, the board has effectively abdicated its responsibility. This creates a governance gap where IT risks may not be adequately addressed at the highest level. The auditor should flag this as a significant deficiency because it undermines the principles of effective IT governance.

Why this answer

The board of directors holds ultimate accountability for IT governance, including oversight of IT risks and alignment with business strategy. Delegating all oversight to the CIO without active board involvement and only receiving annual summaries means the board is not fulfilling its fiduciary duty. This creates a significant governance risk because IT decisions may not be aligned with stakeholder interests and risks may go unaddressed.

The auditor should highlight this as a critical concern.

Exam trap

The trap here is assuming that delegating IT oversight to a capable CIO absolves the board of its governance responsibilities, when in fact the board must retain ultimate accountability.

330
MCQhard

An IS auditor uses statistical sampling to test a population of 10,000 transactions. The auditor discovers 5 errors in the sample of 200. Which of the following conclusions is most appropriate?

A.The population error rate is exactly 2.5%
B.The population has a material weakness
C.The population error rate is 5%
D.The population error rate is likely between 1% and 4% at a given confidence level
AnswerD

Five errors in 200 gives a 2.5% sample rate, and statistical projection applies a confidence interval around it. The range 1% to 4% reflects that sampling uncertainty, whereas a single point estimate would overstate precision.

Why this answer

Statistical sampling produces an estimate with a confidence interval, not a point value, so the correct conclusion is that the true population error rate likely falls within a range around the observed 2.5% (5/200). The option stating a range of 1% to 4% at a given confidence level correctly reflects that sampling results are probabilistic. The other options assert exact rates or draw conclusions about materiality that the sample alone cannot support.

Exam trap

CISA often tests the misconception that a sample error rate equals the population error rate, tempting candidates to pick the exact 2.5% figure instead of a confidence interval.

How to eliminate wrong answers

Option A is wrong because it treats the sample rate of 2.5% as the exact population rate, ignoring sampling risk and the confidence interval. Option B is wrong because materiality is a judgment based on the auditor's threshold and the nature of the errors, not something a sample of 200 can declare on its own. Option C is wrong because 5% is not the observed rate — 5 errors in 200 is 2.5%, so this option misstates the arithmetic and the concept.

331
MCQmedium

An IS auditor is evaluating the change management process. Which of the following is the BEST indicator that emergency changes are being properly controlled?

A.Emergency changes are documented with a justification and promptly reviewed after implementation
B.Emergency changes are approved by the change manager within 24 hours
C.Emergency changes are tested in a production-like environment before implementation
D.Emergency changes require approval from the CAB before implementation
AnswerA

Documenting each emergency change with justification and reviewing it promptly afterwards confirms the control operated: the change was authorised retrospectively and assessed, rather than bypassing governance entirely, which is the strongest evidence of proper control.

Why this answer

The best indicator that emergency changes are properly controlled is that they are documented with a justification and promptly reviewed after implementation. Emergency changes, by definition, bypass the normal pre-approval and testing cycle, so the compensating control is retrospective review and documentation to ensure accountability and to catch any issues. This aligns with ITIL and COBIT guidance that emergency changes must be logged, justified, and reviewed post-implementation.

Exam trap

CISA often tests the misconception that emergency changes should still go through full pre-approval or testing — the correct control is post-implementation review and documentation, not pre-approval.

How to eliminate wrong answers

Option B is wrong because approval within 24 hours still implies pre-approval, which defeats the purpose of an emergency change and may delay critical fixes; it also does not address post-implementation review. Option C is wrong because testing in a production-like environment before implementation is a normal change control, not an emergency change control — emergencies often cannot wait for testing. Option D is wrong because requiring CAB approval before implementation contradicts the definition of an emergency change, which is invoked precisely when the CAB cannot convene in time.

332
MCQhard

An IS auditor is reviewing an organization's security monitoring architecture. The organization uses a SIEM to collect logs from servers, firewalls, and applications. Management reports that the SIEM is functioning as designed and alerts are generated. Which of the following findings would be of MOST concern to the auditor?

A.Log retention is set to 30 days, and the organization's incident response procedure requires investigating events up to 90 days old.
B.Log sources use different time zone settings and the SIEM normalizes timestamps at ingestion.
C.The SIEM is deployed on-premises rather than as a cloud-hosted service.
D.The SIEM generates more alerts than the security team can review in a shift.
AnswerA

If the retention period is shorter than the investigation window defined by policy, evidence required to investigate incidents will be unavailable. Detection may occur, but without 90 days of logs the team cannot reconstruct the scope, timeline, or root cause of events that surface late. This is a direct conflict between a configured control and a documented requirement, making it the most concerning finding because it undermines incident response and forensic capability.

Why this answer

A monitoring system is only as useful as the evidence it retains. When the configured retention period is shorter than the period the incident response process requires for investigation, the organization cannot reconstruct events that are discovered late. This misalignment between a technical setting and a documented requirement directly impairs detection follow-up and forensic analysis, making it the finding that most threatens the effectiveness of security monitoring.

Exam trap

The trap here is focusing on alert volume or architecture, when the decisive issue is whether retained evidence matches the investigation timeline defined by policy.

333
Multi-Selectmedium

An IS auditor is assessing the effectiveness of access controls. Which TWO procedures provide the strongest evidence? (Select two.)

Select 2 answers
A.Re-performance of access provisioning using a test account
B.Inspection of access violation audit logs
C.Inquiry of the security administrator
D.Inspection of user access review documentation
E.Observation of access request processing
AnswersA, B

Re-performance of access provisioning using a test account lets the auditor independently execute the control and observe actual system behaviour, producing direct evidence. This satisfies the stem's requirement for the strongest evidence of access control effectiveness.

Why this answer

Re-performance of access provisioning using a test account (A) is correct because the auditor independently executes the provisioning process and directly verifies whether the system enforces the intended access rules, yielding first-hand evidence that is stronger than documentation or interviews. Inspection of access violation audit logs (B) is correct because these logs are system-generated records that reveal actual attempts to exceed authorized access and whether the controls detected and responded to them, providing objective evidence of control operation. Inquiry of the security administrator (C) is not sufficient because it relies on management's assertions rather than independent verification.

Inspection of user access review documentation (D) shows that reviews were documented but does not confirm the underlying access rights are actually correct or enforced. Observation of access request processing (E) only reflects the process at the moment observed and may not represent normal or complete control operation.

Exam trap

CISA often tests the evidence reliability hierarchy, tempting candidates to select inquiry or observation because they are easy to perform, when the exam expects the strongest (re-performance and system-generated logs).

334
Multi-Selecthard

Which THREE of the following are essential components of a data classification program?

Select 3 answers
A.Data retention and disposal schedules
B.Regular vulnerability scanning
C.Assignment of data owners
D.Standardized labeling guidelines
E.Implementation of database encryption
AnswersA, C, D

Retention and disposal schedules operationalise classification by defining how long each category is kept and how it is destroyed. Without them, labels carry no lifecycle consequence, so the programme cannot satisfy legal, regulatory or contractual retention constraints identified during classification.

Why this answer

Data classification programs require defined lifecycle handling, so option A (data retention and disposal schedules) is correct because classification only has value if each class carries rules for how long data is kept and how it is securely destroyed. Option C (assignment of data owners) is correct because owners are accountable for classifying their data, approving access, and reviewing classifications, which is the governance backbone of any classification program. Option D (standardized labeling guidelines) is correct because consistent labels (for example, Public, Internal, Confidential, Restricted) are what let users and systems apply handling rules uniformly across the organization.

The unmarked options do not belong: regular vulnerability scanning (B) is a technical security control for finding weaknesses, not a classification component, and database encryption (E) is a protective safeguard applied after classification rather than an essential element of the classification process itself.

Exam trap

The trap here is that candidates confuse operational security controls (like vulnerability scanning or encryption) with the administrative and procedural components of a data classification program, which are specifically about defining ownership, labeling, and lifecycle management.

335
MCQeasy

A medium-sized e-commerce company recently suffered a ransomware attack that encrypted critical databases. The IT team restored systems from backups, but the incident exposed a lack of clear roles and responsibilities for incident response. The board has asked the IT governance committee to review and improve the incident response governance. The committee notes that while there is an incident response policy, it is not regularly tested, and staff are unsure of their roles. The company also lacks a formal communication protocol for notifying stakeholders. What should the committee prioritize to strengthen governance over incident response?

A.Invest in advanced endpoint detection and response tools.
B.Outsource incident response to a managed security service provider.
C.Define and communicate clear roles and responsibilities for incident response, and establish accountability.
D.Conduct a tabletop exercise to test the current plan.
AnswerC

Assigning and communicating explicit incident response roles, with named accountability, removes the confusion staff reported and gives the untested policy operational substance. This directly satisfies the governance gap the board identified, enabling escalation and stakeholder notification to function during future incidents.

Why this answer

The committee should prioritize defining and communicating clear roles and responsibilities for incident response and establishing accountability. The incident exposed a lack of clarity in roles, which is a governance issue. Without clear roles, even the best tools or outsourced services may not be effective.

This directly addresses the governance gap identified.

Exam trap

CISA often tests the distinction between governance (roles, accountability) and technical controls or testing, tempting candidates to choose a tactical solution like tabletop exercises or tools when the root cause is unclear roles.

How to eliminate wrong answers

Option A is wrong because investing in advanced endpoint detection and response tools is a technical control, not a governance improvement; it does not address the lack of clear roles and responsibilities. Option B is wrong because outsourcing incident response may provide expertise but does not fix the internal governance issue of unclear roles and accountability; it could even exacerbate the problem if not managed properly. Option D is wrong because conducting a tabletop exercise is a testing activity that can help validate roles, but it is not the first priority when roles are not defined; you cannot test what does not exist.

The priority should be to define roles first.

336
MCQeasy

An IS auditor is reviewing the IT organizational structure of a mid-sized manufacturing company. The auditor finds that the IT department reports to the CFO, and there is no separate IT strategy committee. The CEO believes that IT is a support function and does not need board-level representation. Which of the following is the MOST appropriate recommendation for the auditor?

A.The CFO should be given additional training on IT governance.
B.The organization should establish an IT governance framework with board involvement.
C.The IT department should report to the CEO to ensure strategic alignment.
D.The IT department should be outsourced to reduce costs and improve efficiency.
AnswerB

Establishing a formal IT governance framework ensures that IT is aligned with business strategy and that the board provides oversight. This addresses the root cause: the CEO's view that IT is merely support and does not need board representation. A governance framework defines roles, responsibilities, and processes for IT decision-making, ensuring IT is managed as a strategic asset.

Why this answer

The CEO's perception of IT as a support function and the absence of board-level oversight indicate a governance gap. Establishing an IT governance framework with board involvement ensures IT is strategically managed and aligned with business goals. This is the most comprehensive and appropriate recommendation, addressing the root cause rather than symptoms.

Exam trap

The trap here is recommending structural changes like reporting line adjustments or outsourcing, which do not address the fundamental need for board-level IT governance and strategic alignment.

337
MCQeasy

A small business wants to protect customer data stored on a local file server. Which of the following is the MOST cost-effective control to prevent unauthorized access?

A.Enable detailed audit logs
B.Configure file-level permissions
C.Implement full-disk encryption
D.Deploy biometric authentication
AnswerB

File-level permissions restrict access through the operating system's existing access control, requiring no new hardware or software spend. This directly satisfies the stem's cost-effectiveness constraint while preventing unauthorised access to the customer data on the local file server.

Why this answer

Configuring file-level permissions (e.g., NTFS permissions on Windows or POSIX ACLs on Linux) is the most cost-effective control because it directly restricts which users or groups can read, write, or modify specific files and folders on the server. This granular access control prevents unauthorized access without requiring additional hardware or complex management, making it ideal for a small business with limited budget.

Exam trap

The trap here is that candidates often confuse detective controls (audit logs) or encryption (which protects data at rest) with preventive access controls, leading them to choose a more expensive or less effective option instead of the simple, direct file permission configuration.

How to eliminate wrong answers

Option A is wrong because audit logs only record access events after they occur; they do not prevent unauthorized access in real time. Option C is wrong because full-disk encryption protects data at rest if the physical disk is stolen, but it does not control access while the server is running and the OS is booted. Option D is wrong because biometric authentication is expensive to deploy and maintain, and it addresses authentication at the system level rather than directly controlling access to specific files on the server.

338
MCQmedium

An organization is implementing a data loss prevention (DLP) solution. Which of the following is the BEST approach to reduce false positives during initial deployment?

A.Use default policies without modification
B.Limit scope to one department to minimize noise
C.Deploy in monitor-only mode and analyze alerts for a period
D.Block all sensitive data transmissions immediately
AnswerC

Monitor-only mode logs what the DLP policy would have blocked without enforcing it, letting analysts review alerts and tune rules against real traffic. This reduces false positives before enforcement, satisfying the requirement for the best initial deployment approach.

Why this answer

Deploying a DLP solution in monitor-only mode allows the organization to observe what data is being transmitted and generate alerts without blocking any traffic. This enables security teams to analyze the alerts against actual business workflows, fine-tune policies, and eliminate false positives before moving to an active enforcement mode. It is a best practice for initial deployment to avoid disrupting legitimate business operations.

Exam trap

The trap here is that candidates may think limiting scope (Option B) is the best way to reduce noise, but the question asks for the best approach to reduce false positives, and monitor-only mode provides the necessary feedback loop to tune policies before enforcement, whereas limiting scope only reduces volume, not the false positive rate.

How to eliminate wrong answers

Option A is wrong because default policies are generic and not tailored to the organization's specific data types, workflows, or user behavior, which typically results in a high volume of false positives and potential missed detections. Option B is wrong because limiting scope to one department reduces the overall visibility and may miss data loss events in other departments, while still generating false positives within that department due to untuned policies. Option D is wrong because immediately blocking all sensitive data transmissions without first understanding normal traffic patterns will almost certainly disrupt legitimate business processes and cause significant operational impact.

339
MCQhard

An IS auditor is reviewing a system development project that uses a commercial software package customized with vendor-supplied extension points. The project team has documented customizations in a separate repository but has not maintained a traceability matrix linking business requirements to configuration items. Which of the following is the GREATEST risk arising from this situation?

A.The project may exceed its budget because customization effort cannot be accurately estimated for future phases.
B.Future upgrades may fail or require extensive rework because the impact of vendor changes on customizations cannot be reliably assessed.
C.Developers may introduce unauthorized changes because the separate customization repository is not integrated with the change management system.
D.User acceptance testing may be incomplete because test cases cannot be traced back to the original business requirements.
AnswerB

Without traceability from requirements to configuration items, the team cannot quickly determine which customizations support which business needs or which vendor patches will affect them. During an upgrade, this gap forces costly discovery work and increases the chance of breaking critical functionality. The greatest risk is therefore an inability to assess upgrade impact, which can delay patching and introduce production outages.

Why this answer

A traceability matrix connects business requirements to the configuration items and customizations that satisfy them. Without it, the organization cannot determine which customizations are affected by a vendor upgrade or patch. That uncertainty forces expensive manual analysis, delays security updates, and raises the likelihood of production failures.

While testing gaps and budget overruns matter, the enduring operational risk of unmanageable upgrades is the most severe consequence for a customized commercial package.

Exam trap

The trap here is focusing on testing or budgeting gaps, when the missing traceability matrix most severely undermines the ability to manage vendor upgrades and patches.

340
MCQmedium

An IS auditor is reviewing the user access recertification process. Which of the following findings would MOST concern the auditor regarding the effectiveness of access reviews?

A.The recertification report includes all users with active accounts
B.Reviews are performed quarterly instead of annually
C.Some users did not respond to the recertification request within the deadline
D.Managers approve all access requests without verifying job requirements
AnswerD

Managers rubber-stamping approvals defeats the review's purpose: recertification exists to confirm each user's access still matches current job requirements. Without that verification, excessive or stale entitlements persist, violating least privilege and undermining the control's effectiveness. This directly addresses the stem's concern about review effectiveness, unlike process timing or documentation issues.

Why this answer

Managers approving all access requests without verifying job requirements is the most concerning finding because it defeats the purpose of recertification: access is rubber-stamped rather than validated against least privilege. This creates a systemic risk of privilege creep and unauthorized access that no amount of process formality can offset. The other findings are either positive or minor operational issues.

Exam trap

CISA often tests the difference between a control's existence and its effectiveness; candidates pick operational issues (missed deadlines) over the substantive failure (blind approval) because the former sounds more concrete.

How to eliminate wrong answers

Option A is wrong because including all active users in the report is a completeness control, not a deficiency. Option B is wrong because quarterly reviews are more frequent (and thus stronger) than annual reviews. Option C is wrong because non-response within a deadline is an operational lapse that can be remediated, not a fundamental control failure.

341
MCQmedium

An organization's backup strategy includes full backups every Sunday and incremental backups on other days. On Wednesday, a failure occurs. Which backups are needed to restore the data?

A.Sunday's full backup only
B.Sunday's full backup and Wednesday's incremental backup
C.Wednesday's incremental backup only
D.Sunday's full backup and Monday through Wednesday incremental backups
AnswerD

Incremental backups capture only changes since the previous backup, so restoration requires the last full backup plus every incremental in sequence. Sunday's full plus Monday, Tuesday and Wednesday incrementals satisfies the stem's Wednesday failure scenario.

Why this answer

To restore from incremental backups, you need the last full backup (Sunday) and all incremental backups from Monday through Wednesday.

342
MCQhard

A multinational corporation is evaluating its IT governance structure. The board wants to ensure that IT investments are prioritized based on risk and value. Which framework component is MOST critical?

A.Service level agreements
B.Balanced scorecard
C.IT steering committee
D.Portfolio management process
AnswerD

Portfolio management processes let the board prioritise and monitor IT investments against risk and value criteria, directly satisfying the stem's requirement. It provides the governance mechanism for balancing investment mix, whereas other components address resource, performance or compliance concerns.

Why this answer

A portfolio management process systematically evaluates and prioritizes investments based on risk and value, aligning with board objectives. Steering committee provides oversight, but portfolio management is the mechanism for prioritization.

343
MCQeasy

A mid-sized company is implementing a new IT service management (ITSM) tool to improve incident management. The IT manager wants to ensure that the tool aligns with ITIL best practices. The company has a dedicated service desk team that handles about 200 incidents per week. The IT manager is considering whether to implement a self-service portal for users to submit incidents and check status, or to continue using email-based incident reporting. The service desk team is concerned that a self-service portal might reduce their direct interaction with users and potentially lead to less personalized support. However, the IT manager believes that a portal could improve efficiency and tracking. The company's IT governance framework requires that any major IT investment be approved by the steering committee and that there be a clear business case. The IT manager has prepared a business case but the steering committee wants to ensure that the solution is aligned with ITIL and that it addresses key incident management processes. Which of the following is the most appropriate next step for the IT manager?

A.Implement the self-service portal immediately to improve efficiency, then present the business case later.
B.Conduct a process review with stakeholders to define requirements based on ITIL guidelines before selecting a tool.
C.Proceed with the self-service portal without further review because it is clearly beneficial.
D.Abandon the self-service portal idea and continue with email-based reporting.
AnswerB

ITIL-aligned requirements must be defined before tool selection, ensuring the ITSM solution supports incident management processes rather than forcing process change. A stakeholder process review establishes the business case the steering committee requires, addressing governance and alignment constraints.

Why this answer

ITIL best practices emphasize that process design should precede tool selection. Conducting a process review with stakeholders ensures the self-service portal aligns with defined incident management workflows, such as categorization, prioritization, and escalation, before committing to a specific tool. This step also satisfies the IT governance requirement for a clear business case by validating requirements against ITIL guidelines.

Exam trap

The trap here is that candidates may assume any self-service portal automatically improves efficiency and aligns with ITIL, but CISA tests the principle that process definition must precede tool selection to ensure governance and best practice alignment.

How to eliminate wrong answers

Option A is wrong because implementing the portal immediately without presenting the business case violates the IT governance framework requiring steering committee approval for major IT investments, and it risks deploying a tool that does not align with ITIL-defined incident management processes. Option C is wrong because proceeding without further review ignores the service desk team's concerns about reduced personalization and fails to ensure the portal supports ITIL processes like incident categorization and SLA tracking, which could lead to inefficiencies. Option D is wrong because abandoning the portal idea outright dismisses the potential efficiency gains and tracking improvements that a properly designed self-service portal can provide, and it does not address the need to align with ITIL best practices.

344
MCQmedium

During an operational audit of an IT department, the auditor finds that system uptime is 99.9% but the department missed two critical project deadlines. Which conclusion is most appropriate?

A.The department has a material weakness in controls
B.The department is efficient but may not be effective
C.The department is operating effectively based on uptime
D.The department should be outsourced
AnswerB

Uptime measures how well resources were used to keep systems running, indicating efficiency, while missed deadlines show the department failed to achieve its objectives, indicating ineffectiveness. Efficiency and effectiveness are distinct axes, so the department can be efficient yet ineffective.

Why this answer

Efficiency is about doing things right (resource utilization, uptime, throughput), while effectiveness is about doing the right things (achieving objectives such as project deadlines). The department kept systems running (efficient) but missed critical deadlines (not effective), so the correct conclusion is that it is efficient but may not be effective. This distinction is central to ISACA's performance management concepts.

Exam trap

CISA often tests the efficiency-versus-effectiveness distinction, tempting candidates to equate high uptime with overall effectiveness when the question deliberately includes missed objectives.

How to eliminate wrong answers

Option A is wrong because missing deadlines does not by itself establish a material weakness in controls — it is a performance outcome, not a control deficiency finding. Option C is wrong because uptime alone is an efficiency metric and does not demonstrate effectiveness against the department's objectives. Option D is wrong because outsourcing is a remediation decision that cannot be justified by the facts presented and is not an audit conclusion.

345
MCQmedium

An IS auditor is reviewing a waterfall SDLC project that has completed the requirements phase. Which of the following is the greatest risk to the project?

A.The project manager left the company.
B.A key business stakeholder did not sign off on the requirements.
C.The development team is unfamiliar with the technology.
D.The design phase is behind schedule.
AnswerB

Unsigned requirements leave scope unbaselined, so later changes cascade through design, build and test with no approved reference point. In waterfall, defects introduced at requirements cost most to correct, and the missing sign-off removes the control that would otherwise catch stakeholder misalignment before construction begins.

Why this answer

In waterfall, requirements are defined upfront and changes are difficult. If a key stakeholder did not sign off, there is a risk that later phases will be based on incomplete or incorrect requirements.

346
MCQhard

An IS auditor is reviewing the change management process for a critical financial application. Which of the following findings would be of GREATEST concern?

A.Standard changes are documented but not tracked individually
B.Change requests are logged in a spreadsheet instead of a dedicated system
C.Emergency changes are implemented without subsequent CAB approval
D.The CAB meets only once per month
AnswerC

Emergency changes bypassing subsequent CAB review leave the most critical control gap: changes reach production without retrospective scrutiny, risking undocumented, untested modifications to a financial application. Other findings are less severe because normal changes still receive approval before deployment.

Why this answer

Emergency changes implemented without subsequent CAB approval represent a critical control failure because emergency changes bypass the normal review and approval process, and if they are not retroactively reviewed, unauthorized or risky changes may remain in production. This creates a significant risk of undetected errors, fraud, or security vulnerabilities in a critical financial application. The lack of post-implementation approval means no oversight exists for changes that could directly affect financial reporting or data integrity.

Exam trap

CISA often tests the misconception that emergency changes are acceptable without any approval, but the real issue is the lack of subsequent CAB approval, which is a critical control gap.

How to eliminate wrong answers

Option A is wrong because standard changes are pre-approved, low-risk, and documented; not tracking them individually is acceptable and not a major concern. Option B is wrong because using a spreadsheet instead of a dedicated system is a tooling inefficiency, not a control weakness that directly compromises change integrity. Option D is wrong because a monthly CAB meeting may slow down changes but does not bypass approval controls; it is a scheduling issue, not a critical control failure.

347
Multi-Selecteasy

An IS auditor is reviewing the logical access controls for a cloud-based HR system. The system contains sensitive employee data. The auditor notes that user provisioning is performed by the HR department without IT involvement, and there is no formal access request or approval process. Which THREE of the following are the MOST significant risks?

Select 3 answers
A.There is no audit trail of who granted access and why
B.Segregation of duties between HR and IT is not maintained
C.Password policies may not be enforced
D.Users may be granted excessive privileges beyond their job requirements
E.User accounts may not be locked after multiple failed login attempts
AnswersA, B, D

Absent formal requests or approvals, no record exists linking an account to an authoriser or business justification. This defeats accountability and non-repudiation, leaving the auditor unable to reconstruct who granted access, when, or why — undermining investigation, disciplinary action and regulatory evidence.

Why this answer

Option A is correct because provisioning without a formal access request or approval process means there is no documented record of who authorized or granted each user's access, eliminating the audit trail needed to trace accountability for access decisions. Option B is correct because HR performing user provisioning without IT involvement removes the segregation of duties between the department that owns the employee data and the function that administers system access, allowing a single group to both request and grant privileges. Option D is correct because without a formal request and approval workflow, there is no validation against job roles, so users can be provisioned with rights exceeding their job requirements (excessive privileges).

Options C and E are not among the most significant risks here because password policy enforcement and account lockout after failed logins are authentication controls configured within the system itself, and nothing in the scenario indicates these controls are absent or affected by the HR provisioning process.

Exam trap

CISA often tests whether candidates can distinguish risks directly caused by the described control gap (no approval, no SoD) from generic security risks (password policy, lockout) that are not implicated by the scenario.

348
Multi-Selectmedium

Which TWO of the following are key elements of a change request document?

Select 2 answers
A.Vendor contract
B.Justification
C.Project budget
D.Rollback plan
E.User manual
AnswersB, D

Justification records the business or technical reason the change is needed, letting the Change Advisory Board weigh benefit against risk and cost. Without it, approvers cannot judge whether the change is warranted, so the document fails its decision-support purpose.

Why this answer

Option B (Justification) is correct because a change request must state the business or technical reason the change is needed, so the change advisory board (CAB) can assess its value and priority before approval. Option D (Rollback plan) is correct because every change request must document how to revert the change if it fails or causes an outage, which is essential for risk mitigation and restoring the configuration item to its prior baseline. A vendor contract (A) is a procurement/legal artifact, not a standard component of a change request.

A project budget (C) relates to financial planning and cost control, not to the change management process itself. A user manual (E) is end-user documentation and has no role in defining or approving a change.

Exam trap

CISA often tests whether candidates confuse supporting documents (contracts, budgets, manuals) with the intrinsic elements of a change request—candidates pick budget because cost impact feels relevant, but the budget itself is not an RFC component.

349
Multi-Selectmedium

Which TWO of the following are key controls that an IS auditor should expect to find in a well-managed system development life cycle (SDLC)?

Select 2 answers
A.Segregation of duties between development and testing.
B.Vendor due diligence reports.
C.Formal change control process for code changes.
D.Automated unit testing scripts.
E.Gantt chart for project scheduling.
AnswersA, C

Separating development from testing prevents developers from validating their own code, reducing the risk that defects or unauthorised changes pass undetected. This segregation of duties is a fundamental SDLC control auditors expect within a well-managed development process.

Why this answer

Option A is correct because segregation of duties between development and testing is a fundamental SDLC control that prevents developers from testing their own code, thereby reducing the risk of undetected errors and unauthorized changes reaching production. Option C is correct because a formal change control process for code changes ensures that all modifications are authorized, documented, tested, and approved before implementation, which is a core governance control within any well-managed SDLC. Options B, D, and E are not key SDLC controls: vendor due diligence reports relate to third-party risk management rather than the SDLC itself, automated unit testing scripts are a technical testing technique rather than a control expectation, and a Gantt chart is merely a project scheduling tool that does not provide control assurance over the development process.

Exam trap

The trap here is that candidates confuse project management artifacts (like Gantt charts) or development tools (like unit test scripts) with actual controls, but the CISA exam focuses on controls that enforce separation of duties and formal change management, not on the tools or schedules used to manage the project.

350
MCQmedium

An organization is developing a policy on acceptable use of company IT resources. Which of the following should be included to support effective governance?

A.Detailed technical configuration standards
B.Consequences of non-compliance
C.Service level targets for IT support
D.Procedures for incident response
AnswerB

Consequences of non-compliance give the acceptable use policy enforceable weight, satisfying governance's need for accountability. Without stated disciplinary or access-revocation outcomes, the policy remains advisory and staff face no deterrent. This directly supports the stem's governance objective by linking defined behaviour to measurable sanctions, ensuring violations are addressed consistently rather than left to managerial discretion.

Why this answer

An acceptable use policy (AUP) is a governance document that defines what employees may and may not do with company IT resources, and its enforceability depends on clearly stated consequences for non-compliance. Including consequences supports governance by establishing accountability and giving management a basis for disciplinary or legal action. This makes B the most appropriate inclusion for effective governance.

Exam trap

CISA often tests the distinction between policy-level content (purpose, scope, roles, consequences) and operational content (procedures, SLAs, technical standards), so candidates must not pick operational artifacts for a governance policy question.

How to eliminate wrong answers

Option A is wrong because detailed technical configuration standards belong in hardening baselines or standards documents, not in a policy-level AUP; mixing them dilutes the policy's governance purpose. Option C is wrong because service level targets for IT support are operational metrics documented in SLAs, not part of an acceptable use policy. Option D is wrong because incident response procedures are operational runbooks, not policy content; the AUP may reference them but should not contain them.

351
MCQmedium

An IS auditor is assessing the capacity management process for a cloud-based enterprise resource planning (ERP) system. The organization has experienced performance degradation during peak periods, and the cloud provider's auto-scaling features are not fully utilized. Which of the following should the auditor recommend FIRST?

A.Configure auto-scaling policies based on historical peak usage patterns.
B.Conduct a performance test to simulate peak loads and identify bottlenecks.
C.Implement monitoring tools to track resource utilization and performance metrics.
D.Increase the baseline capacity of the cloud infrastructure to handle peak loads.
AnswerC

Before optimizing auto-scaling or adjusting capacity, the organization needs accurate data on resource usage and performance. Monitoring tools provide visibility into when and why degradation occurs, enabling informed decisions. Without this baseline, any capacity changes are guesswork. The auditor should recommend establishing monitoring first as it is foundational to effective capacity management and will inform subsequent actions.

Why this answer

Effective capacity management begins with understanding current resource utilization and performance. The organization has auto-scaling capabilities but is not using them fully, and performance issues exist. Before making changes, the auditor should recommend implementing monitoring to collect data on resource usage, peak times, and bottlenecks.

This data will inform whether to adjust auto-scaling policies, increase baseline capacity, or optimize the application. Monitoring is the essential first step to ensure that subsequent actions are targeted and effective.

Exam trap

The trap here is jumping to a technical fix like increasing capacity or configuring auto-scaling without first establishing monitoring, which is necessary to make informed decisions and avoid unnecessary costs.

352
MCQhard

A multinational corporation is implementing a global HR system. The project team decides to use a pilot implementation in one region before rolling out to others. What is the PRIMARY risk if the pilot region is not representative of the entire organization?

A.The pilot team may become overly confident.
B.The pilot may run over budget due to unexpected challenges.
C.Issues relevant to other regions may remain undetected.
D.The implementation schedule will be delayed.
AnswerC

A non-representative pilot exercises only one region's data volumes, tax rules and integrations, so defects unique to other regions stay hidden until full rollout. The primary risk is therefore undetected issues elsewhere, defeating the pilot's purpose of validating the design organisation-wide.

Why this answer

The primary risk of a non-representative pilot is that region-specific variations in regulatory, cultural, or technical infrastructure (e.g., data privacy laws like GDPR, local labor regulations, or network latency) will not be exercised. This means defects or integration failures that are unique to other regions remain hidden until full rollout, undermining the pilot's purpose as a risk-reduction mechanism. Option C directly captures this core risk of undetected issues.

Exam trap

The trap here is that candidates confuse a secondary consequence (like budget overruns or delays) with the primary risk, which is the failure to detect region-specific issues that could cause catastrophic failures during full rollout.

How to eliminate wrong answers

Option A is wrong because pilot team overconfidence is a secondary human-factor risk, not the primary technical risk of a non-representative sample; the pilot could still surface issues even if the team is overconfident. Option B is wrong because unexpected challenges in a non-representative pilot are less likely to cause budget overruns (the pilot may actually be too easy), and the primary risk is about undetected issues, not cost. Option D is wrong because schedule delays are a possible consequence of undetected issues, but the primary risk is the failure to detect those issues in the first place, not the delay itself.

353
MCQmedium

During a post-implementation review of a new financial system, the IS auditor finds that user acceptance testing (UAT) was completed with only 60% of test cases passed. Which of the following is the MOST significant risk?

A.The system deployment was delayed
B.The system performance is below expectations
C.The project was not completed within the planned budget
D.The system may not fully meet business requirements, leading to user workarounds
AnswerD

Passing only 60% of UAT cases means 40% of tested business scenarios failed, so the system may not satisfy requirements and users will adopt manual workarounds that undermine controls and reporting integrity. This is the most significant risk.

Why this answer

Low UAT pass rate indicates unresolved defects or unmet user requirements, leading to user dissatisfaction and potential workarounds that compromise controls.

354
MCQeasy

An IS auditor is reviewing the access control list (ACL) on a router that connects the corporate network to the internet. The auditor notices that the ACL permits inbound traffic on port 3389 (RDP) from any source IP address to a specific internal server. Which of the following is the MOST appropriate recommendation?

A.Implement account lockout policies to prevent brute-force attacks.
B.Change the default RDP port to a non-standard port to obscure the service.
C.Enable Network Level Authentication (NLA) on the RDP server.
D.Restrict inbound RDP access to specific trusted IP addresses or require VPN access.
AnswerD

Allowing RDP from any source IP exposes the server to brute-force attacks, credential stuffing, and exploitation of RDP vulnerabilities. The most appropriate recommendation is to restrict access to known trusted IPs or require users to connect via VPN, which adds an authentication layer. This reduces the attack surface and aligns with the principle of least privilege. It directly addresses the risk of unauthorized access.

Why this answer

The most appropriate recommendation is to restrict inbound RDP access to specific trusted IP addresses or require VPN access. This directly reduces the exposure of the RDP service to potential attackers. While other measures like NLA or account lockout can add defense in depth, they do not address the fundamental issue of allowing RDP from any source.

Restricting access is a preventive control that aligns with least privilege and reduces the attack surface.

Exam trap

The trap here is choosing a hardening measure like changing the port or enabling NLA, which does not address the core problem of unrestricted inbound access.

355
MCQeasy

Which of the following is the PRIMARY purpose of a data classification scheme?

A.To enable encryption of all sensitive data
B.To meet regulatory compliance requirements
C.To define data retention periods
D.To ensure appropriate security controls are applied based on data sensitivity
AnswerD

Classification assigns sensitivity labels that determine which security controls apply, ensuring protection is proportionate to data value and regulatory requirements. It is the foundational input to control selection, not an end in itself; encryption, access rules and retention all derive from the assigned classification tier.

Why this answer

A data classification scheme assigns sensitivity labels (e.g., public, internal, confidential, restricted) to information assets. Its primary purpose is to ensure that appropriate security controls—such as access control lists, encryption strength, and monitoring—are applied proportionally to the data's sensitivity. Without classification, controls would be either insufficient for high-risk data or overly restrictive for low-risk data, undermining both security and operational efficiency.

Exam trap

The trap here is that candidates mistake a downstream benefit (like enabling encryption or meeting compliance) for the primary purpose, when the core goal is to drive risk-based security control selection based on data sensitivity.

How to eliminate wrong answers

Option A is wrong because enabling encryption of all sensitive data is a specific control outcome, not the primary purpose of classification; classification informs which data requires encryption, but the scheme itself does not enforce encryption. Option B is wrong because meeting regulatory compliance requirements is a benefit or driver for classification, but not its primary purpose; compliance mandates often require classification, but the scheme's core goal is to guide control selection, not merely to check a compliance box. Option C is wrong because defining data retention periods is a separate data lifecycle management function typically governed by a retention policy or schedule, not by the classification scheme; classification labels may influence retention, but the primary purpose is not to set retention durations.

356
MCQmedium

A system has a Mean Time Between Failures (MTBF) of 200 hours and a Mean Time To Repair (MTTR) of 20 hours. What is the availability of the system?

A.95.0%
B.91.0%
C.90.0%
D.90.9%
AnswerD

Availability equals MTBF divided by the sum of MTBF and MTTR: 200 / (200 + 20) = 200/220 = 0.909, giving 90.9%. The 20-hour repair window is the only downtime component, so the system is available for 200 of every 220 hours.

Why this answer

Availability is calculated as MTBF / (MTBF + MTTR). With MTBF = 200 hours and MTTR = 20 hours, availability = 200 / (200 + 20) = 200/220 = 0.90909..., which rounds to 90.9%. This formula reflects the proportion of total time the system is operational versus the total time including repair.

Exam trap

CISA often tests the availability formula, and candidates frequently confuse MTBF and MTTR or incorrectly use MTTR/MTBF instead of MTBF/(MTBF+MTTR).

How to eliminate wrong answers

Option A (95.0%) is wrong because it would require MTTR of approximately 10.5 hours (200/210 ≈ 95.2%), not 20 hours. Option B (91.0%) is wrong because it does not match the precise calculation; 200/220 = 90.909%, which rounds to 90.9%, not 91.0%. Option C (90.0%) is wrong because it incorrectly uses a simple subtraction or misapplies the formula; 200/220 is not 90.0%.

357
MCQeasy

During which phase of the SDLC should security requirements be formally documented and approved by the business owner?

A.Design phase
B.Requirements phase
C.Testing phase
D.Development phase
AnswerB

Security requirements must be captured alongside functional requirements so they are baselined and approved before design begins. Documenting them in the requirements phase lets the business owner formally accept them, preventing costly retrofitting of controls during coding or testing.

Why this answer

Security requirements must be identified and approved early to ensure proper controls are built into the system. The requirements phase is the appropriate stage for this.

358
MCQhard

A multinational corporation has defined its risk appetite as 'moderate' for IT investments. The IT steering committee is evaluating a new project with potential high returns but also significant cybersecurity risks. The project's risk profile is assessed as 'high' by the risk management team. What should the committee do FIRST?

A.Request the project team to identify risk mitigation measures.
B.Approve the project but increase monitoring.
C.Escalate the decision to the board of directors.
D.Reject the project immediately as it exceeds risk appetite.
AnswerA

Requesting mitigation measures first addresses the high-risk profile before any acceptance decision, aligning residual risk with the moderate appetite. Identifying controls and their effectiveness gives the committee the information needed to approve, modify or reject the project.

Why this answer

When a project's risk profile exceeds the organization's defined risk appetite, the FIRST step is to understand whether the risk can be brought within tolerance through mitigation. The committee cannot make an informed accept/reject/escalate decision until the risk management team and project team have identified possible controls and residual risk. Requesting mitigation measures preserves the opportunity for high returns while aligning the project with the 'moderate' appetite.

Exam trap

CISA often tests the misconception that any project exceeding risk appetite must be immediately rejected or escalated, when the correct first step is always to evaluate mitigation and residual risk before making a governance decision.

How to eliminate wrong answers

Option B is wrong because approving a high-risk project that exceeds the stated risk appetite without first evaluating mitigation bypasses governance and effectively ignores the risk appetite framework. Option C is wrong because escalation to the board is premature—the board should only be involved if risk cannot be reduced to an acceptable level or if the decision exceeds the committee's delegated authority. Option D is wrong because immediate rejection is a knee-jerk response that discards potential high returns without first determining whether controls can reduce risk to an acceptable level.

359
Multi-Selecthard

A global retail company is implementing an IT governance framework. The board of directors has asked the IS auditor to identify the KEY components that should be included in the framework to ensure effective governance. Which TWO of the following are essential components of an IT governance framework? (Choose two.)

Select 2 answers
A.Outsourcing of all IT functions to a third party
B.Detailed technical training for all IT staff
C.Performance measurement and monitoring
D.Use of a specific software development methodology
E.IT strategic alignment with business objectives
AnswersC, E

Performance measurement and monitoring are essential to IT governance because they provide the means to assess whether IT is delivering value, managing risks, and using resources efficiently. Without metrics and monitoring, the board and management cannot make informed decisions or hold IT accountable. This component enables continuous improvement and ensures that governance objectives are being met. It is a recognized pillar of effective governance frameworks.

Why this answer

IT strategic alignment and performance measurement are core components of an IT governance framework. Alignment ensures IT supports business goals, while performance measurement provides the feedback loop to assess effectiveness and drive accountability. Other options, such as training, development methodologies, and outsourcing, are operational or strategic choices that may be governed but are not fundamental building blocks of the framework itself.

Exam trap

The trap here is confusing operational activities like technical training or specific development methodologies with the strategic components of IT governance, which focus on direction, alignment, and oversight.

360
MCQmedium

An IS auditor is reviewing the backup strategy for a financial institution's core transaction processing system. The system processes high volumes of transactions continuously and requires a recovery point objective (RPO) of 5 minutes. The current strategy includes nightly full backups and hourly incremental backups. Which of the following should the auditor recommend as the MOST appropriate improvement?

A.Perform full backups twice daily instead of nightly.
B.Increase the frequency of incremental backups to every 15 minutes.
C.Implement snapshot-based backups every 30 minutes.
D.Implement continuous data protection (CDP) with journaling to capture every transaction.
AnswerD

CDP captures changes continuously or near-continuously, enabling recovery to any point in time with minimal data loss. With an RPO of 5 minutes, hourly incrementals are insufficient. CDP can achieve an RPO of seconds or minutes, meeting the requirement. This is the most appropriate recommendation because it directly addresses the gap between the current backup frequency and the required RPO.

Why this answer

The core transaction system requires an RPO of 5 minutes, meaning no more than 5 minutes of data can be lost. Nightly full and hourly incremental backups leave up to 60 minutes of data at risk. Continuous data protection captures every change, enabling recovery to within seconds or minutes, thus meeting the RPO.

Increasing incremental frequency to 15 minutes still exceeds the RPO, and other options are even less frequent. CDP is the only viable solution among the choices.

Exam trap

The trap here is assuming that more frequent traditional backups (e.g., every 15 minutes) can meet a very low RPO, when in fact only continuous or near-continuous replication technologies can achieve RPOs of 5 minutes or less.

361
MCQeasy

An organization wants to ensure that its backup tapes are protected from unauthorized access. Which of the following is the MOST effective control?

A.Physical locks on the tape library
B.Encryption of the backup data
C.Access control lists on the backup server
D.Offsite storage of tapes
AnswerB

Encryption renders tape contents unreadable without the decryption key, protecting data even if physical media is lost, stolen or accessed by unauthorised staff. This directly satisfies the requirement to prevent unauthorised access to backup tapes.

Why this answer

Encryption of the backup data is the most effective control because it protects the data itself, regardless of where the tapes are stored or who physically possesses them. Even if tapes are stolen, lost, or accessed without authorization, the data remains unreadable without the encryption keys. This directly addresses the confidentiality of backup data at rest, which is the core requirement.

Physical and logical controls can be bypassed, but strong encryption provides a last line of defense.

Exam trap

CISA often tests the distinction between physical, logical, and data-level controls; candidates may choose physical locks or offsite storage because they seem tangible, but the most effective control for protecting data confidentiality is encryption, as it renders the data useless even if other controls fail.

How to eliminate wrong answers

Option A is wrong because physical locks on the tape library only protect against physical access at that specific location; they do not protect tapes in transit, offsite, or if the lock is compromised. Option C is wrong because access control lists on the backup server only control logical access to the server, not the tapes themselves; if tapes are removed, the ACLs are irrelevant. Option D is wrong because offsite storage only provides geographic separation for disaster recovery; it does not prevent unauthorized access if the offsite facility has weak controls or if tapes are stolen during transport.

362
MCQmedium

An organization has implemented a business continuity plan (BCP) and disaster recovery plan (DRP). During a recent full interruption test, the IT team discovered that the recovery time objective (RTO) for a critical application was not met. What is the MOST likely reason for this failure?

A.The recovery point objective (RPO) was set too low, causing data loss.
B.The backup data was not encrypted, leading to corruption during restoration.
C.The tabletop exercise was not conducted before the full interruption test.
D.The alternate site did not have adequate processing capacity to handle the workload.
AnswerD

Insufficient processing capacity at the alternate site means the workload cannot be recovered within the required window, directly explaining the missed RTO. This satisfies the stem's constraint by identifying a resource shortfall in the recovery environment rather than a procedural or documentation failure.

Why this answer

The most likely reason the RTO was not met is that the alternate site lacked sufficient processing capacity to handle the workload. RTO measures the time to restore service availability; if the failover site cannot support the required compute, memory, or I/O throughput, restoration will be delayed or fail outright. This is a common capacity planning failure in DR testing, where the alternate site is sized for minimal operations but not for the full production load.

Exam trap

The trap here is that candidates confuse RTO with RPO or assume procedural gaps (like missing a tabletop exercise) are the root cause, when the actual failure is a technical capacity limitation at the alternate site.

How to eliminate wrong answers

Option A is wrong because RPO being set too low (i.e., very frequent backups) reduces potential data loss, not causes RTO failure; RPO and RTO are independent metrics. Option B is wrong because backup encryption does not cause corruption; encryption protects data at rest, and corruption typically results from media errors or improper backup/restore processes, not the encryption itself. Option C is wrong because while tabletop exercises validate plans, skipping one does not directly cause a capacity shortfall at the alternate site; the RTO failure here is a technical infrastructure issue, not a procedural gap.

363
MCQmedium

An IS auditor is reviewing the access recertification process for a financial application. The process requires users' managers to confirm access rights quarterly. Which of the following findings should MOST concern the auditor?

A.Access rights are recertified annually instead of quarterly.
B.There is no process to act on access changes identified during recertification.
C.Recertification forms are completed by users themselves rather than managers.
D.Recertification results are not documented or retained.
AnswerB

Recertification only reduces excessive access if identified changes are actually revoked or modified. Without an execution process, managers' quarterly confirmations produce no remediation, leaving inappropriate rights intact indefinitely — defeating the control's purpose and exposing the financial application to unauthorised transactions.

Why this answer

The most concerning finding is that there is no process to act on access changes identified during recertification. Even if recertification is performed, without follow-up to revoke or modify access, the process is ineffective and leaves inappropriate access in place, increasing the risk of unauthorized access. This directly undermines the control's purpose.

Exam trap

CISA often tests the difference between a control activity and its effectiveness; candidates may focus on the frequency or who performs recertification, but the lack of follow-up is the critical failure.

How to eliminate wrong answers

Option A is wrong because while quarterly recertification is required, annual recertification still provides some level of review; the lack of action on findings is a more severe control failure. Option C is wrong because although recertification by users themselves is a segregation of duties issue, it is less severe than having no remediation process; user self-certification can still be reviewed by managers. Option D is wrong because lack of documentation is a compliance and audit trail issue, but the absence of action on identified changes means the control does not mitigate risk at all.

364
MCQeasy

According to ISO/IEC 38500, which principle requires that IT investments are made for valid business reasons and with clear business outcomes?

A.Performance
B.Strategy
C.Acquisition
D.Responsibility
AnswerB

The Strategy principle of ISO/IEC 38500 requires evaluating IT investments against business rationale and expected outcomes, ensuring proposals have valid business reasons. It differs from Acquire, which governs obtaining IT assets, and Conformance, which addresses compliance with rules.

Why this answer

The 'Strategy' principle of ISO/IEC 38500 states that IT should be aligned with the business strategy and investments should be made for valid business reasons.

365
MCQmedium

An organization is acquiring a new financial system. The contract includes a clause that allows the organization to audit the vendor's controls. Which type of report would most efficiently provide assurance over the vendor's internal controls?

A.Financial audit report
B.SOC 2 report
C.Penetration test report
D.ISO 27001 certificate
AnswerB

A SOC 2 report covers the vendor's controls against trust services criteria, giving the organisation independent assurance over security and processing integrity. It is obtained once and shared with many customers, avoiding the cost of exercising the contractual audit right.

Why this answer

A SOC 2 report is specifically designed to provide assurance over a service organization's controls related to security, availability, processing integrity, confidentiality, and privacy, which directly addresses the need to audit the vendor's internal controls for a financial system. It is more efficient than other options because it is a standardized, independent assessment that covers the control environment relevant to financial data processing.

Exam trap

The trap here is that candidates may confuse a SOC 2 report with a financial audit report (Option A) because both involve auditors, but SOC 2 is specifically for service organization controls, not financial statement accuracy.

How to eliminate wrong answers

Option A is wrong because a financial audit report focuses on the accuracy of financial statements, not on the operational or security controls of the vendor's systems. Option C is wrong because a penetration test report only provides a point-in-time assessment of security vulnerabilities, not a comprehensive evaluation of ongoing internal controls. Option D is wrong because an ISO 27001 certificate confirms that a vendor has an information security management system (ISMS) in place, but it does not provide a detailed, auditable report of control effectiveness or specific control activities like a SOC 2 report does.

366
MCQeasy

An IS auditor is reviewing the IT operations of a small company. The auditor finds that scheduled batch jobs are monitored manually by an operator who checks job logs each morning. Which of the following is the MOST significant risk associated with this practice?

A.Job failures may not be detected until the next morning, delaying critical business processes.
B.Batch jobs may run longer than expected, causing resource contention during peak hours.
C.The operator may lack the technical skills to restart failed jobs, leading to prolonged outages.
D.Manual monitoring increases the risk of unauthorized access to job logs containing sensitive data.
AnswerA

With only a daily manual check, a failed batch job could go unnoticed for up to 24 hours. This delay can disrupt dependent business processes, such as financial reporting or payroll, causing operational and financial impact. Automated monitoring with alerts would enable immediate detection and response. This is the most significant risk because it directly affects timeliness and availability of critical processing.

Why this answer

Manual monitoring once per day means that any failure occurring after the check will not be detected until the next day, potentially delaying critical business processes. Automated monitoring with real-time alerts is essential for timely detection and response. Resource contention, operator skill, and log access are relevant but are not the primary risk introduced by this practice.

Exam trap

The trap here is focusing on secondary operational issues like performance or security instead of the core weakness: delayed detection of job failures due to infrequent manual monitoring.

367
MCQmedium

An IS auditor is reviewing the job scheduling environment for an organization's overnight batch processing on a mainframe. The auditor finds that operators have the authority to modify job control statements, restart failed jobs, and manually release jobs held for review, all using the same production operator ID. Which finding should the auditor report as the GREATEST concern?

A.Operators can restart failed jobs without notifying the application owner.
B.Operators can manually release jobs held for review using the same production operator ID.
C.Execution, modification, and review of batch jobs are performed under a single shared operator ID.
D.Operators can modify job control statements without a second approver.
AnswerC

The greatest concern is the collapse of segregation of duties: one shared production operator ID performs execution, modification of job control statements, restart, and release of held jobs. Because the same credential spans all these functions, no independent review or approval can be enforced, and actions cannot be attributed to an individual. This defeats the detective and preventive controls that a batch environment depends on.

Why this answer

Batch integrity depends on separating who prepares and modifies jobs from who executes, restarts, and releases them, and on unique IDs so every action is attributable. When one shared operator ID carries modification, restart, and release rights, a single operator can alter processing logic and then release the altered job without any independent check. That combination of powers, not any single right, is the reportable control failure.

Exam trap

The trap here is focusing on one sensitive permission, such as job control statement modification, instead of recognizing that the combination of modification, restart, and release rights under a single shared ID is what eliminates independent review.

368
MCQmedium

A university is implementing a new student information system. The project team uses an iterative development approach. During user acceptance testing, students report that the online course registration portal crashes when more than 100 users register simultaneously. The development team identifies a database connection pooling issue and estimates a fix will take three weeks. The project deadline is in two weeks. The project manager suggests deploying the system as is and fixing the issue after go-live, as the crash is rare. The IS auditor is consulted. What should the auditor recommend?

A.Delay the go-live until the defect is fixed and user acceptance testing is passed.
B.Document the risk and proceed with the go-live, planning to fix later.
C.Deploy on time but restrict registration to fewer than 100 students per session.
D.Implement a temporary increase in server capacity to handle the load.
AnswerA

Deploying a system that crashes under concurrent load breaches availability, a core IS control objective. User acceptance testing has not passed, so the defect represents an unmitigated risk to a critical student service. The auditor should recommend delaying go-live until the connection pooling fix is implemented and acceptance testing succeeds.

Why this answer

Deploying a system with a known critical defect that fails under expected load conditions violates the principle of delivering a reliable and secure system. The database connection pooling issue causes the portal to crash under concurrent user load, which is a functional failure that directly impacts business operations. Delaying go-live ensures the defect is fixed and user acceptance testing (UAT) is fully passed, aligning with the IS auditor's responsibility to recommend risk mitigation over acceptance of a preventable failure.

Exam trap

The trap here is that candidates may assume a 'rare' crash can be accepted as a post-go-live fix, but the IS auditor must recognize that the crash occurs under a specific, predictable load threshold that is likely to be exceeded during normal operations, making it a high-risk defect that requires pre-deployment resolution.

How to eliminate wrong answers

Option B is wrong because documenting the risk and proceeding without fixing the defect ignores the fact that the crash is not 'rare'—it occurs under a predictable load of 100 concurrent users, which is a realistic scenario for a university registration portal. Option C is wrong because restricting registration to fewer than 100 students per session is a manual workaround that does not address the underlying database connection pooling issue; it introduces operational complexity and still risks failure if the limit is accidentally exceeded. Option D is wrong because a temporary increase in server capacity (e.g., adding more CPU or memory) does not fix a database connection pooling defect—the crash is caused by connection exhaustion or misconfiguration in the connection pool library, not by insufficient hardware resources.

369
MCQmedium

A security auditor discovers that a server has been compromised due to an unpatched vulnerability. Which of the following would have most effectively prevented this incident?

A.Enabling firewall rules to limit access.
B.Implementing a vulnerability management program with regular patching.
C.Installing a host-based intrusion detection system (HIDS).
D.Using strong passwords on the server.
AnswerB

A vulnerability management programme with regular patching directly addresses the root cause: the unpatched software flaw. Continuous scanning identifies missing updates, and scheduled remediation closes the exposure window before attackers exploit it, which no detective or compensating control could achieve as effectively.

Why this answer

A vulnerability management program with regular patching directly addresses the root cause of the compromise: the unpatched vulnerability. By systematically identifying, prioritizing, and applying security patches, the organization eliminates the known weakness that the attacker exploited. This proactive measure prevents the initial compromise, whereas other controls only detect or limit the attack after the vulnerability is exploited.

Exam trap

The trap here is that candidates often choose a detective or preventive control (like a firewall or HIDS) that mitigates the attack surface or detects the breach, rather than recognizing that patching is the only option that eliminates the root cause of the vulnerability itself.

How to eliminate wrong answers

Option A is wrong because firewall rules limit network access but do not fix the underlying unpatched vulnerability; an attacker who gains access through an allowed port or via an internal vector can still exploit the unpatched flaw. Option C is wrong because a host-based intrusion detection system (HIDS) only detects suspicious activity after the exploitation begins or has occurred, it does not prevent the initial compromise from an unpatched vulnerability. Option D is wrong because strong passwords protect against credential-based attacks, but they are irrelevant when the attacker bypasses authentication entirely by exploiting a software vulnerability that does not require valid credentials.

370
Multi-Selectmedium

During an audit of the incident response process, the IS auditor finds that the organization relies on shared accounts for system administration. Which TWO of the following are the MOST significant risks associated with shared accounts?

Select 2 answers
A.Increased complexity in password management
B.Lack of individual accountability for actions performed
C.Increased overhead for account provisioning
D.Audit trails may not be reliable for forensic investigations
E.Higher likelihood of password sharing outside the authorized group
AnswersB, D

Shared credentials remove the unique user identifier that links an action to a person, so no one can be held answerable for privileged changes. This directly undermines the accountability principle the audit is testing, since attribution becomes impossible when several administrators use one login.

Why this answer

Option B is correct because shared accounts eliminate the one-to-one mapping between a user identity and an account, so when multiple administrators use the same credentials there is no way to attribute a specific action to a specific individual, destroying individual accountability. Option D is correct because the audit logs generated under a shared account record only the account name, not the actual person, so the resulting audit trail cannot reliably support forensic investigations or non-repudiation. Options A and C are operational inconveniences rather than the most significant risks, and option E describes a possible consequence of poor password hygiene rather than the core accountability and forensic integrity risks that an IS auditor would emphasize.

Exam trap

CISA often tests the distinction between operational inconveniences (password complexity, provisioning overhead) and fundamental control failures (lack of accountability, unreliable audit trails); candidates may pick the more visible but less severe operational risks.

371
MCQmedium

An organization is conducting a Business Impact Analysis (BIA). Which of the following metrics defines the maximum acceptable outage time for a critical business process?

A.Recovery Point Objective (RPO)
B.Maximum Tolerable Downtime (MTD)
C.Recovery Time Objective (RTO)
D.Work Recovery Time (WRT)
AnswerB

Maximum Tolerable Downtime directly expresses the longest period a critical process may remain unavailable before unacceptable business impact occurs, which is precisely the outage limit a BIA must document. Recovery Time Objectives for individual systems are then derived to sit within this business-defined threshold, satisfying the stem's requirement for the maximum acceptable outage.

Why this answer

Maximum Tolerable Downtime (MTD) defines the maximum acceptable outage time for a critical business process. It represents the total time a business can tolerate the unavailability of a process before unacceptable consequences occur. MTD is a key output of the BIA and sets the upper limit for recovery objectives.

Exam trap

CISA often tests the distinction between MTD, RTO, RPO, and WRT; candidates may incorrectly select RTO as the maximum acceptable outage, but RTO is the target recovery time, not the maximum tolerable downtime.

How to eliminate wrong answers

Option A (RPO) is wrong because RPO defines the maximum acceptable data loss measured in time, not outage duration. Option C (RTO) is wrong because RTO is the target time to restore a system or process after a disruption, which must be less than MTD. Option D (WRT) is wrong because Work Recovery Time is the time needed to verify data integrity and resume normal operations after systems are restored, which is part of the overall recovery but not the maximum acceptable outage.

372
MCQeasy

Which of the following is the PRIMARY benefit of using a hardware security module (HSM) for key management?

A.It reduces the cost of key management.
B.It improves encryption speed.
C.It provides tamper-resistant storage for encryption keys.
D.It simplifies key distribution.
AnswerC

An HSM stores cryptographic keys inside hardened hardware that detects and responds to physical tampering, preventing key extraction. This tamper-resistant storage is the primary benefit, protecting keys from compromise even if the host system is breached.

Why this answer

The primary benefit of a hardware security module (HSM) is that it provides tamper-resistant, physically secured storage for encryption keys. HSMs are designed to protect keys from extraction or modification, even if an attacker gains physical access to the device, which is critical for maintaining the confidentiality and integrity of cryptographic operations. This aligns with the core purpose of an HSM: to safeguard the root of trust in a key management infrastructure.

Exam trap

The trap here is that candidates may confuse the security-focused purpose of an HSM with operational benefits like cost reduction or performance improvement, leading them to select options that describe side effects or unrelated advantages rather than the primary benefit.

How to eliminate wrong answers

Option A is wrong because HSMs typically increase the cost of key management due to the specialized hardware, certification, and maintenance required, not reduce it. Option B is wrong because HSMs are not primarily designed to improve encryption speed; in fact, they can introduce latency compared to software-based encryption, and their value lies in security, not performance. Option D is wrong because HSMs do not simplify key distribution; they are often used in conjunction with complex key distribution protocols (e.g., PKCS#11, KMIP) and may add operational overhead for secure key exchange.

373
MCQmedium

An IS auditor is reviewing the endpoint security controls of a hospital that permits clinicians to use personal laptops and tablets to access the electronic health record (EHR) system. The auditor finds that the organization issued written acceptable-use agreements, but devices are not inspected, and no enrollment process exists. Which of the following is the MOST significant risk arising from this situation?

A.Unmanaged devices may retain unencrypted copies of protected health information after a clinician leaves the organization.
B.Personal devices may introduce malware that spreads to the EHR application servers.
C.Clinicians may install unauthorized software that consumes excessive bandwidth on the hospital network.
D.The acceptable-use agreement may be unenforceable because it was not signed by a witness.
AnswerA

Without enrollment or inspection, the hospital cannot enforce encryption, remote wipe, or data-retention controls on personally owned devices. Clinical data cached locally on an unmanaged laptop or tablet survives the end of employment, and the organization has no technical means to erase it. This loss of control over protected health information is the most significant exposure because it creates both regulatory breach liability and direct patient-privacy harm.

Why this answer

The defining weakness is that personally owned devices are used for clinical work without enrollment, inspection, or technical controls. That means the organization cannot enforce encryption, remote wipe, or retention limits, so protected health information can persist on hardware it does not own or manage. Data remanence on unmanaged endpoints is the most consequential risk because it directly threatens confidentiality and creates reportable breach exposure.

Exam trap

The trap here is focusing on malware or network performance, which are secondary operational concerns, instead of the organization's inability to control or erase sensitive data on devices it does not manage.

374
MCQmedium

An IS auditor is reviewing a systems acquisition project that involves purchasing an ERP system. Which of the following is the MOST significant risk related to data migration during implementation?

A.Inadequate security controls in the new system
B.Insufficient training of end users on the new system
C.Incomplete or inaccurate data conversion from legacy systems
D.Lack of integration testing between modules
AnswerC

Incomplete or inaccurate conversion transfers corrupt, missing or duplicated records into the ERP, directly undermining financial reporting, payroll accuracy and subsequent processing. This is the most significant migration risk because defects introduced silently during conversion are difficult to detect and costly to remediate once live.

Why this answer

Incomplete or inaccurate data conversion from legacy systems is the most significant data migration risk because it directly corrupts the new ERP's foundational data, leading to erroneous transactions, reporting failures, and compliance issues. Data integrity is the core objective of migration, and failures here cascade across all modules.

Exam trap

CISA often tests whether candidates prioritize data integrity over training or security in migration contexts—candidates may pick training because it feels user-centric, but the question asks about the most significant data migration risk.

How to eliminate wrong answers

Option A is wrong because inadequate security controls, while serious, are a system-wide risk addressed by security architecture and controls—not specific to data migration. Option B is wrong because insufficient training affects user adoption and productivity but does not corrupt the data itself. Option D is wrong because lack of integration testing affects module interoperability, which is a testing-phase risk, not a data migration risk per se.

375
Drag & Dropmedium

Order the steps for performing a data backup in the correct sequence.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Backup process: identify data, choose method, schedule, execute/verify, and store offsite.

Page 4

Page 5 of 13

Page 6