Courseiva

Certified Information Systems Auditor CISA (CISA) — Questions 376–450

934 questions total · 13pages · All types, answers revealed

Page 5

Page 6 of 13

Page 7
376
Multi-Selectmedium

Which of the following are key considerations when implementing a data classification policy? (Choose THREE.)

Select 3 answers
A.Encryption key management
B.Definition of classification categories
C.Backup frequency requirements
D.Handling and labeling procedures
E.Assignment of data owners
AnswersB, D, E

Defining classification categories establishes the taxonomy itself—the labels such as public, internal, confidential and restricted—that every subsequent rule references. Without agreed categories, no consistent assignment, labelling or handling can occur, making this a foundational consideration for the policy.

Why this answer

Option B is correct because a data classification policy must first define the classification categories (e.g., Public, Internal, Confidential, Restricted) so that data can be consistently evaluated and tagged against a common taxonomy. Option D is correct because handling and labeling procedures specify how each class of data must be marked, stored, transmitted, and destroyed, translating the classification scheme into enforceable day-to-day controls. Option E is correct because assigning data owners establishes accountability for classifying data correctly, approving access, and reviewing classifications over time, which is essential for the policy to function.

Option A does not belong because encryption key management is a cryptographic control that supports protection of classified data but is not itself a defining consideration of the classification policy. Option C does not belong because backup frequency is a availability/recovery decision typically governed by backup and retention policies, not by the data classification scheme itself.

Exam trap

ISACA often tests the distinction between policy-level definitions (classification categories, data owners, handling procedures) and operational controls (encryption, backup frequency), leading candidates to mistakenly select technical safeguards as key policy considerations.

377
MCQhard

An IS auditor is assessing the risk of material misstatement in a highly automated transaction processing environment. The auditor notes that the system automatically calculates interest and posts it to customer accounts. Which of the following audit approaches would BEST address the risk of incorrect interest calculations?

A.Increase the sample size for substantive testing to achieve a higher confidence level.
B.Rely on the IT department's quality assurance testing of the interest calculation module.
C.Review and test the application's interest calculation logic and related change controls.
D.Perform substantive testing of a sample of interest calculations using an independent tool.
AnswerC

In a highly automated environment, the primary risk is that the programmed logic is incorrect or has been improperly changed. Testing the calculation logic and the change management controls provides assurance that the automated calculations are correct and remain so. This approach addresses the root cause and is more efficient than substantive testing of individual transactions, as it evaluates the system's inherent processing controls.

Why this answer

In a highly automated transaction processing environment, the most effective audit approach to address the risk of incorrect interest calculations is to review and test the application's calculation logic and the related change controls. This provides assurance that the automated calculations are correct and that any changes are properly authorized, tested, and implemented. Substantive testing alone may not detect systematic errors and is less efficient.

Relying on IT's QA lacks independence. Increasing sample size does not address root cause.

Exam trap

The trap here is defaulting to substantive testing of transactions when the risk is embedded in automated logic, where testing the program logic and change controls is more effective.

378
MCQhard

In a spiral model SDLC, risk analysis is performed at the beginning of each iteration. What is the PRIMARY benefit of this approach?

A.It reduces the number of deliverables
B.It eliminates the need for user acceptance testing
C.It ensures all requirements are gathered upfront
D.It allows for early detection and mitigation of project risks
AnswerD

Analysing risk at the start of every spiral iteration surfaces threats and uncertainties before significant design and coding effort is committed, so mitigation can be planned into the next loop. This early detection reduces the cost of rework compared with deferring risk assessment to later lifecycle phases.

Why this answer

In the spiral model, risk analysis at the start of each iteration allows the team to identify, assess, and mitigate risks early before they escalate. This iterative risk-driven approach is the defining characteristic of the spiral model and its primary benefit over waterfall or pure prototyping.

Exam trap

CISA often tests whether candidates confuse the spiral model's iterative risk focus with waterfall's upfront requirements gathering—candidates may pick 'ensures all requirements are gathered upfront' because it sounds thorough, but that contradicts the spiral model's iterative nature.

How to eliminate wrong answers

Option A is wrong because the spiral model does not reduce deliverables—it typically produces incremental releases per spiral, potentially increasing deliverable count. Option B is wrong because user acceptance testing is still required in the spiral model; risk analysis does not replace validation. Option C is wrong because gathering all requirements upfront is a waterfall characteristic—the spiral model explicitly embraces evolving requirements through iterations.

379
MCQeasy

An IS auditor is reviewing the IT governance framework of a small organization. The auditor finds that the IT manager reports directly to the CFO, and there is no separate IT steering committee. Which of the following is the MOST appropriate conclusion?

A.The IT manager should report to the COO to ensure operational alignment.
B.The governance structure is inadequate because IT should report to the CEO.
C.The lack of an IT steering committee is a critical deficiency that must be remediated immediately.
D.The governance structure may be appropriate for the organization's size, provided IT decisions are aligned with business strategy.
AnswerD

In smaller organizations, formal IT steering committees may not be necessary if there is effective communication and alignment between IT and business leadership. The key is whether IT decisions support business objectives. The reporting line to the CFO can be effective if it ensures IT is integrated with financial and strategic planning. This conclusion is balanced and recognizes that governance structures should fit the organization's context.

Why this answer

The most appropriate conclusion is that the governance structure may be appropriate for the organization's size, provided IT decisions are aligned with business strategy. Smaller organizations often rely on informal governance mechanisms rather than formal committees. The reporting line to the CFO can be effective if it facilitates strategic alignment and oversight.

The auditor should focus on whether the structure achieves governance objectives, not on prescriptive best practices that may not fit the context.

Exam trap

The trap here is assuming that a formal IT steering committee and a specific reporting line are mandatory for all organizations, regardless of size or context.

380
MCQmedium

During the planning phase of an IS audit, the auditor identifies that the organization has recently implemented a new ERP system. Which of the following actions should the auditor prioritize?

A.Exclude the ERP system from the audit scope because it is new and not yet stable
B.Include a review of the ERP system in the audit scope due to the high inherent risk
C.Delay the audit until the ERP system has been fully stabilized for six months
D.Focus only on financial reporting controls related to the ERP system
AnswerB

A newly implemented ERP system carries high inherent risk because of untested configuration, data migration and access provisioning. Including it in the audit scope ensures the auditor evaluates these risks during planning, directing resources toward the area most likely to contain material weaknesses.

Why this answer

A newly implemented ERP system represents high inherent risk due to its complexity, cost, and impact on financial reporting and operations, so the auditor should include it in the audit scope. Prioritizing the ERP review ensures that risks introduced by the new system — such as data migration errors, access control gaps, and process changes — are assessed early. Excluding or delaying the audit would leave significant risk unaddressed.

Exam trap

CISA often tests the misconception that new systems should be excluded or delayed from audit until 'stable' — candidates forget that high inherent risk demands earlier, not later, audit attention.

How to eliminate wrong answers

Option A is wrong because excluding a new ERP system from the audit scope ignores the elevated risk it introduces; new systems are precisely when controls are most likely to be misconfigured. Option C is wrong because delaying the audit for six months allows risks to persist unchecked and may violate audit timelines or regulatory requirements; audits should be timely. Option D is wrong because focusing only on financial reporting controls is too narrow — a new ERP affects operational, compliance, and IT general controls, all of which warrant review.

381
Multi-Selectmedium

Which TWO of the following are key objectives of a post-implementation review of a new system?

Select 2 answers
A.Update the disaster recovery plan
B.Assess the project budget variance
C.Identify lessons learned for future projects
D.Evaluate vendor performance
E.Verify that the system meets user requirements
AnswersC, E

A post-implementation review compares actual outcomes against expectations and documents what worked and what did not, feeding that knowledge into subsequent projects. Capturing lessons learned is therefore a core objective, reducing repeated mistakes and improving future delivery.

Why this answer

Option C is correct because a post-implementation review (PIR) is fundamentally a lessons-learned exercise: it captures what went well and what did not during the project so that future projects can avoid repeating mistakes and replicate successes. Option E is correct because the PIR's primary purpose is to confirm that the delivered system actually satisfies the business and user requirements defined in the original scope, often through user feedback and acceptance criteria verification. Options A, B, and D, while potentially useful activities, are not key objectives of a PIR: updating the disaster recovery plan is a separate operational/BCP task, budget variance assessment is typically part of project closure or earned value management, and vendor performance evaluation is usually handled through contract management or procurement reviews.

Exam trap

The trap here is that candidates often confuse the PIR with project closure activities, mistakenly selecting budget variance or vendor evaluation as key objectives, when the PIR is specifically focused on verifying system effectiveness and capturing lessons learned for future projects.

382
MCQeasy

An IS auditor is planning an audit of a data center and must decide whether to test controls or rely on the work of the organization's internal audit function. Which of the following is the MOST important activity before the auditor can rely on that work?

A.Obtaining a representation letter from the internal audit director confirming all findings were reported
B.Evaluating the competence, objectivity, and quality of the internal auditors' work
C.Confirming that the internal audit function uses the same audit software tools as the IS auditor
D.Verifying that the internal audit function reports administratively to the audit committee of the board
AnswerB

ISACA standards require the external auditor to assess the internal audit function's competence and objectivity and to evaluate the quality of its work before relying on it. A favorable assessment allows the auditor to reduce direct testing, but the reliance decision must be documented and supported by evidence gathered about the internal function itself.

Why this answer

Before relying on the work of internal audit, the IS auditor must determine that the function is competent and objective and that its work is of adequate quality. This evaluation supports a decision to reduce, but not eliminate, the auditor's own procedures. The other listed activities do not establish the professional reliability of the internal audit work being considered.

Exam trap

The trap here is assuming that a favorable structural fact, such as a direct reporting line or a shared audit tool, is by itself sufficient to justify reliance on internal audit work.

383
MCQhard

An IS auditor is evaluating how an organization disposes of decommissioned hard drives that previously stored customer financial records. Management states that drives are physically destroyed by a third-party vendor, but no certificates of destruction are retained and the vendor's personnel perform the destruction at the organization's loading dock without supervision. Which of the following is the MOST important control weakness?

A.Physical destruction is less secure than software-based overwriting of the drives.
B.The third-party vendor has not been assessed for financial stability.
C.Destruction is performed without supervision and no certificates of destruction are retained to evidence the disposal.
D.Drives should be degaussed before being released to the vendor.
AnswerC

Without supervision, drives could be diverted, swapped, or only partially destroyed, and without certificates there is no evidence that destruction occurred. This combination eliminates accountability and leaves the organization unable to demonstrate compliance with data disposal requirements. For media containing customer financial records, the auditor should report the lack of oversight and documentation as the most important weakness because it directly threatens data confidentiality.

Why this answer

When a third party destroys media containing customer financial records, the organization remains accountable for the confidentiality of that data. Unsupervised destruction at the loading dock allows drives to be diverted or inadequately destroyed, and the absence of certificates means the organization cannot prove disposal occurred. The auditor should report the lack of supervision and destruction evidence as the most important weakness because it removes both physical control and auditability.

Exam trap

The trap here is treating physical destruction as inherently sufficient and overlooking that without supervision and certificates the organization cannot prove the drives were actually destroyed.

384
MCQmedium

Scenario: A healthcare organization is implementing a new electronic health records (EHR) system. The project has been delayed due to scope creep and resource constraints. The project sponsor is pressuring the project manager to accelerate the timeline by skipping user acceptance testing (UAT) and going live immediately. The organization has a governance policy that requires all IT projects to complete UAT before deployment. The project manager is concerned about quality and patient safety. Which of the following is the BEST course of action?

A.Compromise by conducting a limited UAT on only critical functionalities.
B.Resign from the project due to ethical concerns.
C.Accept the sponsor's request and skip UAT to meet the deadline.
D.Adhere to the governance policy and escalate the risk to the steering committee for a decision.
AnswerD

Escalation preserves the mandatory UAT control while transferring the timeline risk decision to the steering committee, which owns governance exceptions. Skipping UAT would breach policy and expose patient safety, so the project manager must not accept that risk unilaterally.

Why this answer

The governance policy mandates UAT before deployment, and skipping it could compromise patient safety and data integrity in the EHR system. By escalating the risk to the steering committee, the project manager ensures that the decision is made at the appropriate governance level, balancing project pressures with compliance and quality. This approach aligns with the CISA domain of Governance and Management of IT, where adherence to policies and risk escalation are key controls.

Exam trap

The trap here is that candidates may choose a compromise (Option A) thinking it balances speed and quality, but it still violates the governance policy and fails to address the root cause of scope creep and resource constraints through proper escalation.

How to eliminate wrong answers

Option A is wrong because conducting a limited UAT on only critical functionalities still violates the governance policy and may miss integration or workflow defects that affect patient safety across non-critical modules. Option B is wrong because resigning is an extreme measure that abdicates professional responsibility; the project manager should first use escalation channels and governance processes to address the conflict. Option C is wrong because skipping UAT entirely disregards the governance policy and introduces unacceptable risks to patient safety and regulatory compliance, which could lead to severe consequences for the organization.

385
MCQhard

An IT department uses a balanced scorecard (BSC) to measure performance. The financial perspective shows that IT costs are within budget, but customer satisfaction scores are declining. The learning and growth perspective indicates low employee engagement. Which action should the IT governance committee prioritize?

A.Reduce IT costs further to reallocate savings to customer service.
B.Invest in training and development programs for IT staff.
C.Increase the IT budget to hire more staff.
D.Outsource customer-facing IT support to a third party.
AnswerB

Low employee engagement drives the customer satisfaction decline, so training and development addresses the learning and growth weakness that ultimately feeds the customer perspective. Fixing the root cause is preferable to treating the lagging satisfaction symptom.

Why this answer

The BSC's learning and growth perspective is the foundational driver of the other three perspectives — low employee engagement directly undermines process quality, customer satisfaction, and ultimately financial outcomes. Since customer satisfaction is already declining and the root cause traces to employee engagement, the governance committee should prioritize investing in training and development to fix the upstream cause. This aligns with the BSC's cause-and-effect logic where learning and growth improvements cascade into customer and financial results.

Exam trap

CISA often tests whether candidates chase the symptom (customer satisfaction) with a direct fix rather than addressing the upstream BSC perspective (learning and growth) that the data identifies as the root cause — the trap is picking the option that 'sounds responsive' instead of the one the scorecard logic dictates.

How to eliminate wrong answers

Option A is wrong because cutting costs further ignores the identified root cause (low engagement) and risks worsening customer satisfaction by starving the IT function of resources. Option C is wrong because simply increasing budget to hire more staff does not address the engagement problem — more disengaged staff does not improve customer outcomes and may increase costs without benefit. Option D is wrong because outsourcing customer-facing support is a tactical workaround that does not fix the internal learning and growth deficiency and often degrades customer satisfaction further due to loss of institutional knowledge.

386
MCQhard

An IT auditor is reviewing the organization's policy hierarchy. Which of the following correctly represents the typical order from highest to lowest level?

A.Policy, Guideline, Standard, Procedure, Work instruction
B.Policy, Standard, Guideline, Procedure, Work instruction
C.Procedure, Policy, Standard, Guideline, Work instruction
D.Standard, Policy, Guideline, Procedure, Work instruction
AnswerB

Policy sits at the top, stating management intent, followed by standards that mandate specific controls, then guidelines, procedures and work instructions. Each lower layer becomes progressively more detailed and operational, satisfying the hierarchy the auditor must verify.

Why this answer

The hierarchy is: Policy (high-level principles), Standard (mandatory requirements), Guideline (recommended practices), Procedure (step-by-step instructions), Work instruction (detailed task-level instructions).

387
MCQhard

An IS auditor is assessing the security controls in a newly developed mobile banking application. The development team used the OWASP Mobile Application Security Verification Standard (MASVS) as a guide. Which of the following would be the MOST effective evidence that the application meets the standard's requirements for secure data storage?

A.A penetration test report showing no critical vulnerabilities in the application's data storage mechanisms.
B.A static application security testing (SAST) report that identifies all hardcoded secrets and insecure storage APIs.
C.A combination of static and dynamic analysis reports, plus a manual review of data storage locations, mapped to MASVS controls.
D.A code review checklist signed off by the lead developer confirming that sensitive data is encrypted.
AnswerC

MASVS verification requires a mix of automated and manual testing to cover all storage locations and data types. Static and dynamic analyses identify code-level and runtime issues, while manual review ensures that all sensitive data is stored securely. This comprehensive approach provides strong evidence of compliance with the standard's requirements.

Why this answer

The most effective evidence is a combination of static and dynamic analysis with manual review, as it covers code and runtime aspects and ensures all storage locations are examined. This aligns with MASVS's requirement for thorough verification. Other options are partial or self-attested and do not provide the depth needed to confirm secure data storage fully.

Exam trap

The trap here is assuming that a single penetration test or a developer's checklist is sufficient to prove compliance with a comprehensive standard like MASVS.

388
Multi-Selectmedium

An IS auditor is reviewing the business impact analysis (BIA) for a financial services company. Which THREE metrics are typically defined in a BIA?

Select 3 answers
A.Mean time to repair (MTTR).
B.Mean time between failures (MTBF).
C.Recovery point objective (RPO).
D.Maximum tolerable downtime (MTD).
E.Recovery time objective (RTO).
AnswersC, D, E

RPO defines the maximum tolerable data loss, expressed as time, and directly drives backup frequency. A BIA must record it so recovery strategies align with the financial services company's tolerance for lost transactions, making it one of the three core metrics alongside RTO and MTD.

Why this answer

The BIA defines the recovery objectives that drive continuity and DR planning: C (Recovery point objective, RPO) specifies the maximum acceptable data loss measured in time before the disruption, determining backup frequency; D (Maximum tolerable downtime, MTD) is the total time a business process can be unavailable before unacceptable impact occurs, and it bounds the recovery strategy; and E (Recovery time objective, RTO) is the target time to restore the process or system after disruption, which must be less than the MTD. These three are business-driven metrics derived from process criticality and impact over time. By contrast, A (MTTR) and B (MTBF) are operational reliability and maintainability metrics of components or systems, not business impact metrics defined in a BIA.

Exam trap

The trap here is that candidates confuse operational metrics like MTBF and MTTR (which are used in IT service management and availability calculations) with the business-focused recovery metrics (RTO, RPO, MTD) that are defined in a BIA, leading them to select options A or B instead of the correct trio.

389
MCQhard

An organization's IT strategy is developed by the IT department without input from business stakeholders. Which of the following is the MOST significant risk?

A.Technology may become obsolete quickly.
B.IT projects may exceed budget.
C.IT staff may lack required skills.
D.IT strategy may not support business objectives.
AnswerD

Without business stakeholder input, the IT strategy is shaped by technical priorities alone, so it can diverge from what the organisation actually needs to achieve. The stem's constraint — strategy developed in isolation — directly produces misalignment with business objectives, the most significant enterprise-wide risk.

Why this answer

An IT strategy developed in isolation from business stakeholders risks being misaligned with organizational goals, meaning IT investments may not deliver business value or support strategic objectives. This is the most significant risk because it undermines the entire purpose of IT governance—ensuring IT enables and extends business strategy. Other risks like obsolescence, budget overruns, or skill gaps are secondary symptoms that may result from misalignment.

Exam trap

CISA often tests the distinction between strategic risks (misalignment with business objectives) and operational risks (budget, skills, obsolescence); candidates frequently pick a tangible operational issue when the question asks for the MOST significant strategic risk.

How to eliminate wrong answers

Option A is wrong because technology obsolescence is a tactical/technical risk that can be managed through lifecycle planning and is not the primary consequence of excluding business stakeholders. Option B is wrong because budget overruns are a project management concern that can occur even with perfect business alignment and is not the most significant strategic risk. Option C is wrong because skill gaps are an operational HR/training issue that does not directly stem from the lack of business input in strategy development.

390
MCQmedium

An organization is implementing a software asset management (SAM) program. Which of the following is the PRIMARY benefit of SAM?

A.Ensuring compliance with software licensing agreements
B.Reducing hardware costs
C.Automating patch management
D.Improving network performance
AnswerA

SAM maintains an accurate inventory of installed software against entitlements, so licensing compliance is the primary benefit. It directly satisfies the stem's constraint by reconciling deployed licences with purchased rights, preventing legal exposure and unbudgeted true-up costs.

Why this answer

The primary benefit of a software asset management (SAM) program is ensuring compliance with software licensing agreements, which mitigates legal, financial, and reputational risk from unlicensed or over-deployed software. SAM provides visibility into what software is installed, where, and under what license terms, enabling accurate reconciliation of entitlements versus deployments. While SAM can yield cost savings, compliance is the primary driver because non-compliance carries legal penalties and audit exposure.

Exam trap

CISA often tests the distinction between primary and secondary benefits — candidates pick cost reduction (a common outcome) instead of compliance, which is the stated primary purpose of SAM.

How to eliminate wrong answers

Option B is wrong because reducing hardware costs is a potential secondary outcome of better asset visibility, not the primary benefit of SAM, which focuses on software. Option C is wrong because patch management is a separate IT operations discipline; SAM may inform patch decisions by identifying installed software, but automating patching is not its purpose. Option D is wrong because network performance is unrelated to software asset management — SAM does not monitor or optimize network traffic.

391
MCQmedium

An IS auditor is evaluating the incident response (IR) plan. Which of the following is the BEST indicator that the plan is effective?

A.The plan is approved by senior management
B.The plan is updated annually
C.Lessons learned from tabletop exercises are incorporated into the plan
D.The plan includes contact information for key stakeholders
AnswerC

Incorporating lessons learned from tabletop exercises demonstrates a functioning feedback loop: identified gaps are remediated and the plan evolves. This evidences continuous improvement and validates that the IR plan adapts to discovered weaknesses, the strongest indicator of effectiveness.

Why this answer

The best indicator of an IR plan's effectiveness is that lessons learned from tabletop exercises are incorporated into the plan. Tabletop exercises simulate real-world incidents, revealing gaps in procedures, communication, and decision-making. When findings from these exercises are fed back into the plan, it demonstrates a continuous improvement cycle—meaning the plan is not just a static document but a living, tested capability.

This directly evidences that the plan works in practice and evolves to address weaknesses, which is the essence of effectiveness.

Exam trap

CISA often tests the difference between compliance-oriented attributes (approval, annual review, contact lists) and effectiveness-oriented evidence (testing and continuous improvement), tempting candidates to choose the most formal or frequently updated option rather than the one that proves the plan works in practice.

How to eliminate wrong answers

Option A is wrong because senior management approval indicates governance and support, but not operational effectiveness—a plan can be approved yet untested and flawed. Option B is wrong because annual updates may be a compliance requirement, but updating without testing does not guarantee the plan addresses real incident scenarios or that changes are based on actual performance. Option D is wrong because including contact information is a basic completeness check, not an indicator of effectiveness; contacts may be outdated or the plan may still fail during an incident.

392
MCQeasy

A medium-sized manufacturing company has a decentralized IT structure where each business unit manages its own IT budget and projects. The CEO is concerned that IT investments are not aligned with corporate strategy and that there is duplication of effort. The IT department lacks a formal project portfolio management process. The company has experienced several project failures due to poor prioritization. The CEO has asked the newly hired IT auditor to recommend an initial step to improve IT governance. The auditor should recommend:

A.Establishing an IT steering committee with representatives from business units and IT
B.Implementing a project portfolio management software tool immediately to track all projects
C.Conducting a security risk assessment of all IT systems
D.Outsourcing IT management to a third-party provider
AnswerA

A steering committee directly addresses the stem's constraint: no formal portfolio process across decentralised units. It creates a cross-functional forum that prioritises and aligns IT investments with corporate strategy, resolving duplication and poor prioritisation before any tooling or policy is introduced.

Why this answer

An IT steering committee provides governance oversight, ensures alignment with corporate strategy, and helps prioritize projects to avoid duplication. This foundational step addresses the root cause of poor alignment and project failures before implementing tools or processes. Option B is premature because a tool without governance oversight may not improve prioritization.

Option C focuses on security, not overall strategic alignment. Option D is drastic and does not address internal governance issues.

393
MCQeasy

A company is migrating from a legacy system to a cloud-based ERP. Which of the following is the MOST important control to ensure data integrity during data conversion?

A.Automated backup
B.User acceptance testing
C.Parallel running
D.Reconciliation of control totals
AnswerD

Reconciliation of control totals compares record counts and financial aggregates between legacy and cloud ERP after conversion, detecting missing, duplicated or altered records. This directly verifies data integrity during migration, unlike access controls or encryption, which protect data rather than confirm its completeness and accuracy.

Why this answer

Reconciliation of control totals is the most important control because it directly verifies that the sum of key fields (e.g., total account balances, record counts) in the source system matches the target cloud-based ERP after conversion. This ensures no data is lost, duplicated, or corrupted during the extraction, transformation, and loading (ETL) process, which is critical for maintaining data integrity in a migration from a legacy system.

Exam trap

The trap here is that candidates often confuse 'parallel running' (a system validation technique) with a data integrity control, but parallel running validates operational consistency over time, not the precise completeness and accuracy of the converted data set itself.

How to eliminate wrong answers

Option A is wrong because automated backup protects against data loss due to failures but does not validate the accuracy or completeness of converted data during migration. Option B is wrong because user acceptance testing (UAT) focuses on verifying that the new system meets functional requirements and business processes, not on detecting data integrity issues like missing or misaligned records in the converted dataset. Option C is wrong because parallel running compares outputs of the old and new systems over time to validate operational consistency, but it does not provide a precise, field-level check of data conversion completeness and accuracy like control totals do.

394
MCQeasy

In an Agile software development project, who is primarily responsible for prioritizing the product backlog?

A.Scrum Master
B.Development Team
C.Project Manager
D.Product Owner
AnswerD

The Product Owner owns backlog prioritisation, sequencing items by business value to satisfy the Agile constraint that a single accountable voice orders work. This role bridges stakeholders and the development team, ensuring each iteration delivers maximum value. Scrum assigns this explicitly to the Product Owner, not the Scrum Master or team.

Why this answer

In Scrum, the Product Owner is the single person accountable for maximizing product value and is solely responsible for ordering the Product Backlog. The Product Owner prioritizes items based on business value, stakeholder input, and strategic goals, and is the only role authorized to change backlog order.

Exam trap

CISA often tests the confusion between the Product Owner (backlog prioritization) and the Scrum Master (process facilitation), so candidates who associate 'leadership' with 'prioritization' pick the Scrum Master.

How to eliminate wrong answers

Option A is wrong because the Scrum Master is a servant-leader who facilitates Scrum events and removes impediments, but does not own or prioritize the backlog. Option B is wrong because the Development Team self-organizes to deliver the work but does not decide what gets built next — that is the Product Owner's call. Option C is wrong because 'Project Manager' is not a Scrum role; Scrum defines only three accountabilities (Product Owner, Scrum Master, Developers), and traditional project management duties are distributed among them.

395
Multi-Selectmedium

An IS auditor is reviewing an organization's IT operations incident management process. The auditor finds that incidents are categorized and prioritized, but there is no formal escalation procedure. Which TWO of the following are the MOST significant risks of not having an escalation procedure? (Choose two.)

Select 2 answers
A.Critical incidents may not be escalated to senior management in a timely manner, delaying decision-making.
B.Support staff may not have clear guidance on when to involve higher-tier support, causing delays in resolution.
C.The organization may incur unnecessary costs by over-escalating minor incidents to senior management.
D.Incidents may be resolved without proper documentation, leading to incomplete records.
E.Incidents may be incorrectly prioritized, leading to a focus on low-impact issues.
AnswersA, B

This is a significant risk because without a defined escalation path, critical incidents may remain at lower support tiers, preventing senior management from being informed and making timely decisions. This can prolong outages and increase business impact. Escalation procedures ensure that the right people are engaged at the right time, especially for high-severity incidents that require executive attention or cross-functional coordination.

Why this answer

A formal escalation procedure defines when and how incidents should be escalated to higher tiers of support or management. Without it, critical incidents may not receive timely attention from senior management, and support staff may lack clear criteria for involving higher-level resources. These two risks can lead to extended outages, poor decision-making, and increased business impact.

The other options describe issues related to documentation, prioritization, or over-escalation, which are less directly caused by the absence of an escalation procedure.

Exam trap

The trap here is selecting documentation or prioritization issues as primary risks, when the core risks are delayed escalation of critical incidents and unclear guidance for support staff on when to escalate.

396
Multi-Selectmedium

An IS auditor is reviewing the privileged access management (PAM) process. Which TWO of the following are the MOST effective controls to prevent misuse of privileged accounts?

Select 2 answers
A.Session recording and monitoring of privileged activities
B.Implementation of just-in-time (JIT) privileged access
C.Quarterly review of privileged account access
D.Assignment of generic administrative accounts to multiple users
E.Use of shared passwords for emergency access
AnswersA, B

Session recording and monitoring create attributable, tamper-evident evidence of every privileged action, deterring misuse and enabling detection after the fact. This satisfies the stem's prevention-of-misuse constraint by removing the anonymity that privileged accounts otherwise grant, since administrators know their sessions are captured and reviewed.

Why this answer

Option A is correct because session recording and monitoring of privileged activities creates a tamper-evident audit trail and real-time oversight, which deters misuse and enables detection and accountability for every privileged action. Option B is correct because just-in-time (JIT) privileged access grants elevated rights only for a limited, approved window and revokes them automatically, drastically shrinking the standing attack surface and the opportunity for misuse. Option C is not the most effective preventive control because a quarterly review is a detective, after-the-fact activity that can leave misuse undetected for up to three months.

Option D is wrong because generic administrative accounts shared by multiple users destroy individual accountability and make attribution of actions impossible. Option E is wrong because shared passwords for emergency access eliminate non-repudiation and cannot be traced to a specific individual, increasing the risk of undetected misuse.

Exam trap

CISA often tests the difference between preventive and detective controls, and candidates may select periodic reviews or shared accounts as effective controls when they actually weaken accountability and do not prevent real-time misuse.

397
MCQeasy

Which of the following is the BEST indicator of IT performance from the customer perspective in an IT balanced scorecard?

A.Number of security incidents
B.System availability percentage
C.Help desk resolution time
D.IT budget as a percentage of revenue
AnswerC

Help desk resolution time directly measures service responsiveness as experienced by end users, satisfying the balanced scorecard's customer perspective. Unlike internal metrics such as server uptime or patch compliance, it captures the user's actual experience of IT support delivery.

Why this answer

The customer perspective in an IT balanced scorecard focuses on how users perceive IT services. Help desk resolution time directly measures service quality from the customer's viewpoint.

398
MCQhard

During an audit, the IS auditor finds that the business continuity plan (BCP) was last updated two years ago and does not include new cloud-based applications. The organization has not conducted a BCP test in 18 months. What should the auditor recommend FIRST?

A.Obtain management approval for BCP updates
B.Perform a risk assessment to prioritize changes
C.Immediately schedule a full-scale test
D.Update the BCP to include cloud applications
AnswerB

A risk assessment identifies which cloud applications and business functions carry the greatest exposure from the outdated BCP, letting remediation be sequenced by impact rather than by document age alone. It must precede rewriting or testing, since those activities depend on prioritised findings.

Why this answer

Before updating the BCP or scheduling tests, the IS auditor must ensure that a current risk assessment is performed to identify and prioritize the impact of changes—such as the introduction of cloud-based applications—on business continuity. Without a risk assessment, updates or tests may address the wrong threats or miss critical dependencies, violating the principle that BCP updates should be risk-driven. This aligns with ISACA's guidance that risk assessment is the foundation for BCP maintenance and testing frequency.

Exam trap

The trap here is that candidates often jump to 'update the BCP' or 'test immediately' as the first action, but the CISA exam emphasizes that risk assessment must precede any changes to ensure resources are allocated to the highest-priority gaps.

How to eliminate wrong answers

Option A is wrong because obtaining management approval for BCP updates is premature without first understanding the risks introduced by the new cloud applications; approval should follow a risk-based prioritization. Option C is wrong because immediately scheduling a full-scale test without updating the BCP to reflect current cloud environments could lead to inaccurate test results and wasted resources, and may even cause service disruption if cloud dependencies are not documented. Option D is wrong because updating the BCP to include cloud applications without a prior risk assessment may result in misaligned recovery strategies, such as incorrect RTO/RPO assumptions for cloud workloads, and could miss other critical changes.

399
MCQhard

An organization has implemented a new IT service management (ITSM) tool. The IT manager wants to measure the effectiveness of incident management. Which metric is MOST appropriate?

A.Mean time to resolve (MTTR) incidents
B.Percentage of incidents resolved on first call
C.Number of incidents reported per month
D.Percentage of system uptime
AnswerA

MTTR directly quantifies how quickly incidents are resolved, which is the core effectiveness measure for incident management. It satisfies the stem's requirement to gauge the ITSM process's performance by tracking elapsed time from incident logging to restoration of normal service.

Why this answer

Mean time to resolve (MTTR) is the most appropriate metric for measuring the effectiveness of incident management because it directly reflects how quickly the IT team can restore normal service operation after an incident. In ITIL-based ITSM tools, MTTR tracks the elapsed time from incident logging to resolution, providing a clear indicator of process efficiency and team responsiveness.

Exam trap

The trap here is that candidates often confuse incident management metrics with service desk or availability metrics, picking 'percentage of incidents resolved on first call' because it sounds like a measure of effectiveness, but it actually measures first-contact resolution efficiency, not the end-to-end incident management process.

How to eliminate wrong answers

Option B is wrong because the percentage of incidents resolved on first call measures first-level support efficiency, not the overall effectiveness of the incident management process, which includes escalation and resolution workflows. Option C is wrong because the number of incidents reported per month is a volume metric that indicates incident frequency, not the quality or speed of resolution. Option D is wrong because system uptime is a metric for availability management, not incident management; it measures service reliability rather than how incidents are handled.

400
MCQmedium

An organization is adopting ITIL 4 for service management. Which guiding principle emphasizes starting from existing processes rather than building from scratch?

A.Start where you are
B.Progress iteratively
C.Focus on value
D.Optimize and automate
AnswerA

'Start where you are' advises assessing and leveraging existing processes, services and tools rather than discarding them for a greenfield build. It directly satisfies the stem's constraint of beginning from current capabilities when adopting ITIL 4.

Why this answer

The ITIL 4 guiding principle 'Start where you are' advises organizations not to discard existing processes, tools, and knowledge when adopting new practices. Instead, they should assess what already works, leverage it, and improve incrementally rather than building everything from scratch. This directly matches the question's emphasis on starting from existing processes.

Exam trap

CISA often tests ITIL 4 guiding principles with scenarios that sound like multiple principles; the trap is choosing 'Progress iteratively' or 'Optimize and automate' when the scenario specifically describes reusing existing processes.

How to eliminate wrong answers

Option B is wrong because 'Progress iteratively with feedback' is about breaking work into smaller, manageable iterations and using feedback to improve, not about reusing existing processes. Option C is wrong because 'Focus on value' is about aligning everything to customer value, not about leveraging current state. Option D is wrong because 'Optimize and automate' is about making processes efficient and using technology to automate them, which comes after understanding the current state.

401
MCQmedium

A financial services firm has a mature IT governance framework. The IS auditor is reviewing the IT governance structure and notices that the IT steering committee meets quarterly and focuses primarily on project approvals. Which of the following is the MOST significant concern regarding this committee's effectiveness?

A.The committee's scope is too narrow to provide comprehensive IT governance oversight.
B.Project approvals should be delegated to the project management office.
C.Quarterly meetings are too infrequent to approve projects in a timely manner.
D.The committee lacks representation from business unit leaders.
AnswerA

An IT steering committee should oversee a broad range of IT governance matters, including strategic alignment, risk management, resource allocation, and performance monitoring. Focusing primarily on project approvals limits its ability to address other critical governance areas. This narrow scope can lead to unmanaged risks, misalignment with business strategy, and missed opportunities for value creation. The committee's effectiveness is significantly compromised if it does not cover the full spectrum of IT governance responsibilities.

Why this answer

The most significant concern is that the IT steering committee's scope is too narrow, focusing only on project approvals. Effective IT governance requires oversight of strategic alignment, risk management, resource allocation, and performance. A committee that limits itself to project approvals fails to address these critical areas, leaving the organization exposed to unmanaged risks and misaligned IT investments.

Broadening the committee's mandate is essential for effective governance.

Exam trap

The trap here is focusing on meeting frequency or representation as the primary issue, when the real problem is the committee's limited scope of responsibilities.

402
Multi-Selecthard

An IS auditor is reviewing the backup and restoration controls for a hospital's electronic health record (EHR) system, which runs on a relational database with a recovery point objective (RPO) of 15 minutes. The database administrator performs a full backup every Sunday at 01:00, differential backups nightly at 01:00, and transaction log backups every 15 minutes. During testing, the auditor observes that a restore of the database to a point in time at 14:07 on Wednesday completed successfully but took 9 hours, exceeding the stated maximum tolerable downtime (MTD) of 4 hours. Which TWO conclusions should the auditor draw from this observation? (Choose two.)

Select 2 answers
A.The recovery process should be re-engineered or supplemented so that restoration can be completed within the MTD.
B.The transaction log backups should be replaced with hourly full backups to reduce the total restore time.
C.The differential backup strategy is the root cause of the lengthy restore because differential backups must be applied in sequence.
D.The restore should be considered a failure of the backup integrity controls because the elapsed time exceeded the MTD.
E.The backup schedule satisfies the RPO but the restoration time indicates the MTD cannot be met with the current recovery strategy.
AnswersA, E

Because the restore succeeded but exceeded the 4-hour MTD, the recovery capability does not support the business requirement. The auditor should conclude that the recovery process needs redesign, such as using snapshot or replication technologies, faster storage, or parallel recovery, to bring restoration time within the MTD. This is the actionable control conclusion from the test.

Why this answer

The backup frequency meets the RPO, but the restore duration violates the MTD, revealing a gap between backup adequacy and actual recoverability. The auditor must recognize that a successful restore is not sufficient if it cannot be completed within the business tolerance. The appropriate conclusions are that the RPO is satisfied and that the recovery process must be improved to meet the MTD.

Exam trap

The trap here is assuming that a successful restore proves the recovery strategy is adequate, when recovery time objectives and maximum tolerable downtime are separate requirements that a slow restore can violate.

403
MCQmedium

An IT steering committee is evaluating a major system upgrade. Which of the following is the PRIMARY benefit of using an IT balanced scorecard in this evaluation?

A.It replaces the need for a detailed business case.
B.It provides a framework to align IT investments with business strategy across financial, customer, internal process, and learning/growth perspectives.
C.It ensures the project is completed within budget and on time.
D.It focuses solely on the financial returns of IT investments.
AnswerB

The balanced scorecard translates IT activity into financial, customer, internal process, and learning/growth measures, letting the steering committee judge the upgrade against business objectives rather than technical criteria alone. This alignment is its primary benefit.

Why this answer

The IT balanced scorecard provides a framework to align IT investments with business strategy by evaluating performance across four perspectives: financial, customer, internal process, and learning/growth. This holistic view ensures that IT initiatives are not just financially driven but also consider customer value, operational efficiency, and future readiness. It is a strategic management tool, not a replacement for a business case or a project management schedule.

Exam trap

CISA often tests the misconception that the balanced scorecard is solely financial or replaces other governance tools, so candidates must remember its multi-perspective nature and its role in strategic alignment.

How to eliminate wrong answers

Option A is wrong because the balanced scorecard complements, rather than replaces, a detailed business case; it provides a broader evaluation framework but does not eliminate the need for financial and risk analysis. Option C is wrong because ensuring project completion within budget and on time is a project management concern, not the primary benefit of the balanced scorecard, which focuses on strategic alignment. Option D is wrong because the balanced scorecard explicitly includes non-financial perspectives, so it does not focus solely on financial returns.

404
MCQeasy

An organization is implementing a new IT governance framework. Which of the following is the PRIMARY benefit of using a framework like COBIT?

A.Reducing IT operational costs.
B.Aligning IT strategy with business goals.
C.Eliminating all IT-related risks.
D.Ensuring compliance with all regulatory requirements.
AnswerB

COBIT provides a structured governance model linking IT activities, resources and performance measurement directly to enterprise objectives. This alignment ensures IT investments and controls demonstrably support business strategy, which is the framework's primary governance benefit rather than mere compliance or cost reduction.

Why this answer

COBIT is designed to bridge the gap between business objectives and IT operations by providing a framework that maps IT processes to business goals. The primary benefit is ensuring that IT strategy directly supports and enables business strategy, rather than focusing on cost reduction or risk elimination.

Exam trap

The trap here is that candidates often confuse the primary benefit of a governance framework (strategic alignment) with secondary benefits like cost reduction or compliance, leading them to pick a plausible but incorrect answer that addresses a tactical outcome rather than the core strategic purpose.

How to eliminate wrong answers

Option A is wrong because reducing IT operational costs is a possible outcome of good governance but not the primary purpose of COBIT; cost reduction is more directly addressed by frameworks like ITIL or specific cost-optimization practices. Option C is wrong because no framework can eliminate all IT-related risks; risk management aims to reduce risk to an acceptable level, not achieve zero risk. Option D is wrong because ensuring compliance with all regulatory requirements is an objective of governance but not the primary benefit of COBIT; compliance is one component of a broader alignment goal, and no framework can guarantee compliance with every regulation.

405
Multi-Selectmedium

Which TWO of the following are components of the ITIL 4 four dimensions of service management? (Select TWO.)

Select 2 answers
A.Finance and accounting
B.Risk and compliance
C.Organizations and people
D.Information and technology
E.Marketing and sales
AnswersC, D

Organisations and people is a named ITIL 4 dimension, addressing roles, responsibilities, culture and staffing needed for service management. It satisfies the stem because ITIL 4 explicitly lists this dimension, distinguishing the human and structural aspects from information, technology and partners.

Why this answer

Option C, Organizations and people, is correct because it is one of the four dimensions of ITIL 4 service management, covering roles, responsibilities, culture, and organizational structure. Option D, Information and technology, is also correct as it addresses the information, knowledge, and technologies required to deliver and manage services. The other three options do not belong: Finance and accounting (A), Risk and compliance (B), and Marketing and sales (E) are business functions or governance concerns, not the ITIL 4 dimensions, which are Organizations and people, Information and technology, Partners and suppliers, and Value streams and processes.

Exam trap

CISA often tests the specific components of the ITIL 4 four dimensions, so candidates must memorize them accurately and not confuse them with general business functions like finance or marketing.

406
MCQmedium

An IS auditor is reviewing an agile project that uses Scrum. Which event provides the best opportunity for the auditor to assess whether completed user stories meet the defined acceptance criteria?

A.Sprint review
B.Daily standup
C.Retrospective
D.Sprint planning
AnswerA

The sprint review is where the team demonstrates completed user stories against their acceptance criteria with stakeholders present. This gives the auditor direct evidence of whether each story actually satisfies the defined criteria before it is accepted.

Why this answer

The sprint review is the Scrum event where the team demonstrates completed work to stakeholders and gathers feedback, making it the best opportunity for an IS auditor to assess whether completed user stories meet the defined acceptance criteria. During the sprint review, the product owner and stakeholders review the increment and verify that it meets the acceptance criteria, providing a clear checkpoint for audit evidence. This event directly addresses the completion and acceptance of user stories.

Exam trap

CISA often tests the confusion between Scrum events, leading candidates to select the retrospective or daily standup instead of the sprint review for assessing completed work.

How to eliminate wrong answers

Option B is wrong because the daily standup is a brief coordination meeting for the development team to synchronize activities, not to review acceptance criteria. Option C is wrong because the retrospective focuses on process improvement, not on verifying completed work against criteria. Option D is wrong because sprint planning is for selecting backlog items for the upcoming sprint, not for assessing completed stories.

407
MCQhard

During a post-implementation review of a new HR system, the auditor finds that the system's disaster recovery plan (DRP) was not tested before go-live. Which of the following is the BEST recommendation?

A.Accept the risk because the system is new
B.Implement a backup procedure for the system
C.Conduct a DRP test immediately and document results
D.Schedule a DRP test within the next six months
AnswerC

Testing the untested DRP immediately validates recovery capability and produces documented evidence, closing the gap identified at go-live. This is the best recommendation because it directly addresses the missing test and provides assurance that recovery objectives are achievable.

Why this answer

The best recommendation is to conduct a DRP test immediately and document the results. A DRP that has not been tested poses a significant risk because it may not work as intended. Testing validates the plan, identifies gaps, and ensures that recovery objectives can be met.

Accepting the risk is not appropriate, implementing a backup procedure is only part of DRP, and scheduling a test within six months delays mitigation of a critical gap.

Exam trap

CISA often tests the auditor's role in recommending timely action; candidates may choose to delay testing or focus on backups instead of addressing the untested DRP directly.

How to eliminate wrong answers

Option A is wrong because accepting the risk is not acceptable for a new system that likely supports critical HR functions; the auditor should recommend immediate action. Option B is wrong because implementing a backup procedure is only one component of a DRP; the DRP encompasses broader recovery strategies, and the issue is that the DRP was not tested, not that backups are missing. Option D is wrong because scheduling a test within six months is too long to wait; the system is already live, and the risk of an untested DRP is immediate and should be addressed promptly.

408
MCQmedium

During a review of the patch management process, the IS auditor finds that critical security patches are applied within 30 days, but the policy requires application within 7 days. The IT manager argues that the delay is due to testing requirements. What should the auditor recommend?

A.Escalate to senior management immediately
B.Update the policy to allow 30 days for critical patches
C.Require risk acceptance documentation for each patch that misses the SLA
D.Accept the delay as necessary for stability
AnswerC

Where testing causes patches to breach the seven-day SLA, documented risk acceptance transfers accountability to business owners for the residual exposure during the delay. This satisfies the stem's compliance gap by ensuring deviations are formally acknowledged rather than silently tolerated, without abandoning the testing control.

Why this answer

The policy requires 7-day patching but actual practice is 30 days, creating a documented control gap. Rather than silently accepting the deviation or weakening the standard, the auditor should recommend that each missed SLA be formally documented as a risk acceptance so management owns the residual risk. This preserves the control baseline while providing an auditable trail of conscious risk decisions.

Exam trap

CISA often tests the distinction between the auditor's role and management's role, so the trap is choosing escalation or policy relaxation when the correct answer is to require formal risk acceptance by the business owner, preserving auditor independence and the control baseline.

How to eliminate wrong answers

Option A is wrong because immediate escalation to senior management is premature; the auditor's first duty is to recommend a governance-based remedy (documented risk acceptance) before escalating, and escalation without a documented risk decision skips the proper remediation path. Option B is wrong because changing the policy to match the deficient practice lowers the security baseline to fit the weakness rather than fixing the process, which violates the principle that policy should drive practice, not the reverse. Option D is wrong because simply accepting the delay as necessary for stability provides no formal accountability, no documented risk decision, and no audit trail, which is exactly what an IS auditor must not endorse.

409
MCQhard

An IS auditor is examining how an organization classifies and handles its data. The auditor finds that the data classification policy defines four tiers but does not specify retention periods, handling procedures, or labeling requirements for each tier. Management states that employees use their judgment when handling sensitive information. Which of the following is the MOST appropriate recommendation?

A.Implement automated data loss prevention (DLP) tools to enforce handling rules across all endpoints.
B.Reduce the number of classification tiers to two to simplify employee decision-making.
C.Require management to define retention periods, handling procedures, and labeling requirements for each classification tier.
D.Conduct mandatory security awareness training so employees can better judge how to handle sensitive data.
AnswerC

The policy establishes tiers but omits the operational requirements that make classification meaningful. Without defined retention, handling, and labeling rules, employees cannot apply consistent protection, and reliance on individual judgment creates unacceptable variability. The auditor should recommend that management complete the policy by specifying these requirements for each tier, which provides a basis for later technical enforcement and monitoring.

Why this answer

A data classification policy is only effective when each tier carries explicit retention, handling, and labeling requirements. The organization's policy defines tiers but leaves their treatment to employee judgment, which produces inconsistent protection and no auditable standard. The auditor should recommend that management complete the policy by specifying these requirements per tier, creating the foundation for consistent handling and subsequent enforcement through technical controls.

Exam trap

The trap here is recommending a technical enforcement tool such as DLP before the underlying policy defines what must be enforced.

410
Multi-Selecthard

A company is updating its business continuity plan (BCP). Which THREE of the following should be included as key components?

Select 3 answers
A.List of critical staff and contact information
B.Detailed network topology diagrams
C.Vendor contracts for equipment replacement
D.Procedures for activating the plan
E.Results of the latest risk assessment
AnswersA, D, E

Correct: Essential for communication and activation.

Why this answer

A BCP must include a current list of critical staff and their contact information to enable rapid activation of the plan and coordination during a disruption. Without this, key personnel cannot be reached, delaying response and recovery efforts.

Exam trap

The trap here is that candidates confuse supporting operational documents (like network diagrams) with essential BCP components, or mistake vendor contracts for the actual resource allocation procedures required in a continuity plan.

411
MCQmedium

A bank is converting data from its legacy core banking system to a new platform. Which control is MOST critical to ensure the completeness and accuracy of data conversion?

A.Parallel running of both systems
B.Reconciliation of converted data totals to source system totals
C.Data validation rules programmed in the conversion tool
D.User acceptance testing of the new system
AnswerB

Reconciliation compares converted totals against source system totals, directly detecting omitted, duplicated or altered records. This control verifies completeness and accuracy at the data level, which is the conversion risk the bank faces, rather than relying on procedural or access controls that cannot confirm every record migrated correctly.

Why this answer

Reconciliation of converted data totals to source system totals is the most critical control because it directly verifies that every record from the legacy system has been accurately migrated without loss or duplication. This control compares aggregate values (e.g., account balances, transaction counts) between the source and target databases, providing a definitive check for completeness and accuracy that other controls cannot guarantee.

Exam trap

The trap here is that candidates confuse 'data validation rules' (which ensure individual field correctness) with 'reconciliation' (which ensures aggregate completeness and accuracy), leading them to choose Option C even though validation cannot detect missing records or totals.

How to eliminate wrong answers

Option A is wrong because parallel running tests business processes and system functionality, but it does not provide a systematic, record-level verification of data completeness and accuracy; discrepancies in data may be masked by compensating process flows. Option C is wrong because data validation rules in the conversion tool only check format and business rule compliance during transformation, but they cannot detect missing records or totals that were never extracted from the source. Option D is wrong because user acceptance testing focuses on whether the new system meets functional requirements, not on verifying that every data element from the legacy system has been accurately transferred.

412
MCQeasy

Which of the following audit types is MOST likely to be performed by an organization's own employees?

A.External audit
B.IS audit
C.Internal audit
D.Compliance audit
AnswerC

Internal audit is performed by the organisation's own employees, who report to management or the audit committee. This contrasts with external audit, delivered by independent third parties, directly satisfying the stem's requirement for work conducted by staff within the organisation.

Why this answer

An internal audit is performed by an organization's own employees, typically as part of an internal audit department, to evaluate the effectiveness of internal controls, risk management, and governance processes. This is distinct from external audits, which are conducted by independent third parties.

Exam trap

CISA often tests the distinction between internal and external audits; candidates may confuse 'IS audit' with 'internal audit' because IS audits are frequently performed internally, but the key is who performs the audit, not the subject matter.

How to eliminate wrong answers

Option A is wrong because an external audit is performed by an independent external auditor, not by the organization's own employees. Option B is wrong because an IS audit (information systems audit) can be internal or external; the term itself does not specify who performs it, and it is not necessarily limited to employees. Option D is wrong because a compliance audit can be internal or external, and it focuses on adherence to regulations or standards, not on the performer.

413
MCQmedium

An IS auditor is reviewing a system development project to assess whether it is on schedule. Which of the following would provide the BEST evidence of project progress against the planned timeline?

A.Minutes from status review meetings
B.Approved requirements document
C.Successful unit test results
D.Updated project schedule with actual completion dates for milestones
AnswerD

A schedule showing planned milestones alongside actual completion dates lets the auditor compare baseline against reality and compute slippage directly. It is objective, verifiable evidence of timeline performance, unlike verbal updates or forecasts that merely restate intentions.

Why this answer

The updated project schedule with actual completion dates for milestones (Option D) provides direct, objective evidence of progress against the planned timeline. It shows the baseline plan, the actual dates work was completed, and the variance, allowing the IS auditor to quantitatively assess schedule adherence. This is the primary artifact for schedule tracking in system development projects.

Exam trap

The trap here is that candidates often confuse evidence of technical progress (like passing unit tests) with evidence of schedule progress, failing to recognize that technical success does not equate to on-time delivery.

How to eliminate wrong answers

Option A is wrong because minutes from status review meetings are subjective summaries of discussions and opinions, not objective evidence of actual completion dates or schedule variance. Option B is wrong because an approved requirements document defines what the system should do, not when tasks were completed or how the project is tracking against the timeline. Option C is wrong because successful unit test results verify that individual code modules function correctly, but they do not provide any information about whether those tests were completed on schedule or how the project is performing against the planned timeline.

414
MCQhard

Refer to the exhibit. During a security audit, an IS analyst identifies that a critical business application hosted on 192.168.1.100:443 is unreachable from the 10.0.1.0/24 subnet. Which of the following is the MOST likely cause?

A.The first rule blocks all traffic from 10.0.1.0/24
B.The second rule blocks HTTPS traffic from any source to the host
C.The third rule permits all traffic from the 10.0.0.0/16 subnet
D.The firewall is misconfigured for TCP traffic
AnswerA

Correct: The deny rule for the subnet overrides any permit.

Why this answer

The first rule in the exhibit explicitly denies all traffic from the 10.0.1.0/24 subnet, which is the source subnet in the scenario. Since firewall rules are processed sequentially from top to bottom, this deny rule matches the traffic before any subsequent permit rules can be evaluated, making the host at 192.168.1.100:443 unreachable from that subnet.

Exam trap

The trap here is that candidates often assume a broader permit rule (like the third rule) will override a more specific deny rule, but they forget that firewall rules are evaluated top-down and the first match wins, so the deny rule takes precedence.

How to eliminate wrong answers

Option B is wrong because the second rule blocks HTTPS traffic from any source to the host, but it would only apply if the first rule did not already deny the traffic; however, the first rule is more specific to the source subnet and is processed first, so the second rule is never reached. Option C is wrong because the third rule permits all traffic from the 10.0.0.0/16 subnet, which includes 10.0.1.0/24, but it is placed after the deny rule and is never evaluated due to the sequential nature of firewall rule processing. Option D is wrong because the firewall is not misconfigured for TCP traffic in general; the specific deny rule for the source subnet is the direct cause, and TCP traffic from other subnets would be handled by subsequent rules.

415
MCQeasy

During a change management board (CAB) meeting, a proposed change to the network firewall configuration is discussed. The change is considered low risk and pre-approved. Which type of change does this represent?

A.Emergency change
B.Major change
C.Standard change
D.Normal change
AnswerC

A standard change is a pre-authorised, low-risk change with a documented procedure, requiring no further CAB approval before implementation. This directly satisfies the stem's constraints: the firewall change is low risk and pre-approved, so it follows an established path rather than requiring individual authorisation.

Why this answer

A standard change is a pre-approved, low-risk change that follows a documented procedure and does not require additional review or approval from the change management board (CAB). Since the firewall change is described as low risk and pre-approved, it fits the definition of a standard change. Standard changes are routine and repeatable, allowing them to bypass the full CAB review process, which is reserved for normal or major changes.

Exam trap

CISA often tests the distinction between standard and normal changes, where candidates may incorrectly assume that any low-risk change is a normal change requiring CAB approval, forgetting that standard changes are pre-approved and do not need CAB review.

How to eliminate wrong answers

Option A is wrong because an emergency change is an unplanned change that must be implemented immediately to resolve a critical incident or restore service, and it typically requires expedited approval, not pre-approval. Option B is wrong because a major change is a high-risk change that significantly impacts the organization and requires extensive review, testing, and approval by the CAB, not a low-risk pre-approved change. Option D is wrong because a normal change is a change that is not an emergency or standard change; it requires review and approval by the CAB, even if it is low risk, whereas standard changes are pre-approved and do not require such review.

416
MCQmedium

An organization is implementing a new system using a rapid application development (RAD) approach. The IS auditor is concerned about the lack of formal documentation. Which of the following is the MOST appropriate audit response?

A.Report a finding that the lack of documentation is a material weakness.
B.Recommend that the organization switch to a waterfall methodology to ensure documentation.
C.Assess whether critical design and control documentation is being maintained to support future changes and audits.
D.Suspend the project until full documentation is produced.
AnswerC

In RAD, documentation may be lighter, but critical design decisions and control specifications should still be documented to enable maintenance, audits, and compliance. The auditor should verify that essential documentation exists, even if it is not as extensive as in waterfall. This ensures the system remains auditable and maintainable without stifling the RAD approach.

Why this answer

In a RAD environment, documentation may be less formal, but critical design and control documentation must still be maintained to support future changes, audits, and compliance. The auditor should assess whether such documentation exists and is adequate, rather than recommending a methodology change or taking extreme actions. This balances the need for agility with the need for auditability.

Exam trap

The trap here is assuming that RAD inherently lacks documentation and therefore must be replaced or penalized, rather than evaluating whether essential documentation is present.

417
MCQhard

You are the IT governance lead at a multinational corporation with a complex IT environment spanning multiple business units. The company has recently experienced a series of minor security incidents where unauthorized access was gained through unused user accounts that were not disabled after employees left the organization. Additionally, there have been delays in provisioning access for new hires, leading to productivity losses. The IT department currently uses a manual process for access management, with each business unit maintaining its own user lists. The company has a policy that requires access reviews every quarter, but these are often missed or performed superficially. The CIO has asked you to recommend a solution that addresses these issues while ensuring compliance with regulations such as GDPR and SOX. Which of the following is the BEST course of action?

A.Require each business unit to submit monthly reports of active users to IT, which will then manually disable accounts not on the list.
B.Develop a new policy that mandates quarterly access reviews and disciplinary action for non-compliance.
C.Increase the frequency of access reviews to monthly and assign a dedicated team to perform them.
D.Implement an identity governance and administration (IGA) tool that automates user provisioning and de-provisioning, integrates with HR systems, and enforces access reviews.
AnswerD

Automated provisioning and de-provisioning tied to HR system feeds directly eliminates the orphaned accounts and provisioning delays described, while scheduled access reviews enforce the quarterly policy and produce the audit evidence GDPR and SOX demand.

Why this answer

Implementing an Identity Governance and Administration (IGA) tool directly addresses the root causes: manual, decentralized access management and lack of automated de-provisioning. IGA integrates with HR systems (e.g., Workday, SAP SuccessFactors) to trigger automatic account creation for new hires and immediate deactivation upon termination, eliminating orphaned accounts. It also enforces scheduled, auditable access reviews with certification workflows, ensuring compliance with GDPR (right to erasure, data minimization) and SOX (segregation of duties, access controls).

This automated approach resolves both the security incidents from unused accounts and the productivity losses from delayed provisioning.

Exam trap

The trap here is that candidates often choose options that increase manual oversight (like monthly reports or dedicated teams) because they seem practical, but the CISA exam emphasizes automated, integrated solutions (IGA) as the only sustainable way to achieve compliance and security at scale in complex, multi-unit environments.

How to eliminate wrong answers

Option A is wrong because it perpetuates the manual, error-prone process by relying on business units to submit reports and IT to manually disable accounts, which does not scale, introduces latency, and fails to prevent orphaned accounts between reporting cycles. Option B is wrong because developing a new policy without automated enforcement tools does not address the root cause of missed or superficial reviews; it merely adds another layer of documentation that is likely to be ignored without technical controls. Option C is wrong because increasing review frequency and assigning a dedicated team still relies on manual processes, which are costly, prone to human error, and cannot guarantee timely de-provisioning or integration with HR lifecycle events.

418
MCQmedium

During system development, which testing phase is performed by developers to verify that individual program units function correctly?

A.Integration testing
B.User acceptance testing
C.Unit testing
D.System testing
AnswerC

Unit testing targets individual program units or components in isolation, confirming each functions correctly before integration. Developers perform it during construction, making it the phase that verifies discrete code modules rather than assembled or system-level behaviour.

Why this answer

Unit testing is the phase where developers test individual program units or modules in isolation to verify they function correctly according to their design specifications. This is the lowest level of testing and is typically performed using stubs and drivers to simulate interfaces with other components.

Exam trap

The trap here is confusing the scope of testing phases: candidates often mistake integration testing (which tests module interactions) for unit testing (which tests individual modules in isolation), especially when the question emphasizes 'by developers' and 'individual program units'.

How to eliminate wrong answers

Option A is wrong because integration testing focuses on verifying the interactions and data flow between integrated modules, not individual units. Option B is wrong because user acceptance testing is performed by end users to validate that the system meets business requirements, not by developers to test code units. Option D is wrong because system testing validates the complete, integrated system against functional and non-functional requirements, not individual program units.

419
Multi-Selecthard

Which TWO of the following are indicators that a project is at risk of failure according to ISACA's project governance framework?

Select 2 answers
A.Regular status meetings with stakeholders.
B.Lack of clear communication channels among team members.
C.Adoption of iterative development.
D.Frequent changes to project scope without formal approval.
E.Use of a project management office (PMO).
AnswersB, D

Weak or absent communication channels prevent risks, dependencies and issues from surfacing to governance bodies, so decisions are made on incomplete information. ISACA's project governance framework treats this breakdown in information flow as a leading indicator of project failure risk.

Why this answer

Option B is correct because ISACA's project governance framework identifies poor or unclear communication among team members as a key warning sign of project failure, since it leads to misalignment, unresolved issues, and unmanaged dependencies. Option D is correct because frequent scope changes without formal approval indicate weak change control and governance, which ISACA cites as a major risk factor for cost overruns, schedule slippage, and loss of stakeholder confidence. The remaining options do not indicate risk: regular status meetings with stakeholders (A) and use of a PMO (E) are actually governance-strengthening practices that improve oversight and communication, while adoption of iterative development (C) is a legitimate delivery approach that, when properly governed, supports incremental value delivery rather than signaling failure.

Exam trap

The trap here is that candidates may confuse a lack of communication channels with other common risk factors like scope creep, but ISACA specifically lists communication breakdowns as a distinct risk indicator separate from scope change management.

420
MCQmedium

Refer to the exhibit. An auditor notices this log entry during a review. The user john.doe does not have a legitimate business need to access executive salaries. Which of the following is the MOST likely control failure?

A.Database firewall misconfiguration
B.Audit logging is not enabled
C.Inadequate access controls or role-based permissions
D.Lack of encryption at rest
AnswerC

Role-based permissions should restrict salary records to HR and payroll roles. john.doe accessing executive salaries indicates entitlements were granted too broadly or not reviewed, so least privilege and segregation were not enforced. The log shows authorisation succeeded when it should have been denied, confirming an access control failure.

Why this answer

The log entry shows user john.doe successfully accessed executive salary data via a SELECT query. Since the user has no legitimate business need for this data, the most likely control failure is inadequate access controls or role-based permissions (RBAC). Proper RBAC would restrict access to sensitive columns or tables based on job function, preventing unauthorized queries regardless of other controls.

Exam trap

The trap here is that candidates may focus on the log entry's existence and incorrectly assume audit logging is the issue (Option B), when in fact the log proves logging works, and the real failure is the lack of preventive access controls that should have blocked the query before it executed.

How to eliminate wrong answers

Option A is wrong because a database firewall misconfiguration might allow or deny traffic at the network layer, but it does not typically enforce granular row- or column-level access based on user identity within a query; the log shows the query succeeded, indicating the firewall (if present) allowed it, but the core issue is that the user should not have been permitted to see the data at all. Option B is wrong because audit logging is clearly enabled—the log entry itself is evidence of logging; the failure is not the absence of logs but the absence of preventive controls. Option D is wrong because lack of encryption at rest protects data from physical theft or unauthorized file access, but it does not prevent an authenticated user from querying data through the application or database interface; encryption at rest would not have blocked this SELECT statement.

421
MCQmedium

An IT steering committee is reviewing a proposal for a new customer relationship management (CRM) system. What is the committee's MOST important role?

A.Approving technical specifications
B.Selecting the vendor
C.Ensuring alignment with business objectives
D.Managing the project budget
AnswerC

The steering committee's primary function is to ensure proposed IT investments align with and support business objectives, prioritising them accordingly. Confirming that the CRM system delivers strategic business value, rather than assessing technical detail, is its most important role.

Why this answer

An IT steering committee is a governance body whose primary function is to ensure that IT investments and projects align with the organization's strategic business objectives. It prioritizes, funds, and monitors initiatives at a portfolio level, so its most important role is strategic alignment rather than tactical execution. Technical specifications, vendor selection, and day-to-day budget management are delegated to project teams and IT management.

Exam trap

CISA often tests the confusion between governance and management roles — candidates pick a hands-on activity like vendor selection or budget management when the question asks about the steering committee's strategic purpose.

How to eliminate wrong answers

Option A is wrong because approving technical specifications is an architecture or engineering responsibility, not a governance committee's role — the committee sets direction, not design. Option B is wrong because vendor selection is typically delegated to procurement and the project team against criteria the committee approves, not performed by the committee itself. Option D is wrong because managing the project budget is the project manager's operational responsibility; the committee approves funding and monitors outcomes, but does not manage the budget line by line.

422
MCQhard

An IS auditor is examining how a financial services firm enforces data loss prevention (DLP) for outbound email. The firm uses a network DLP appliance that inspects SMTP traffic and blocks messages containing unencrypted account numbers. The auditor discovers that employees can bypass the appliance by using a personal webmail account over HTTPS. Which of the following should the auditor recommend FIRST?

A.Require employees to sign an acceptable use policy acknowledging that personal webmail use is prohibited.
B.Increase the sensitivity of the DLP appliance's pattern matching so it detects account numbers in more formats.
C.Block access to personal webmail and other unauthorized exfiltration channels at the web gateway, then extend DLP coverage to those channels.
D.Deploy TLS inspection at the perimeter so the DLP appliance can examine HTTPS sessions to webmail providers.
AnswerC

The first step is to close the channel that bypasses the existing control. If personal webmail is blocked at the web gateway and DLP coverage is extended to web and other egress paths, employees can no longer trivially circumvent the appliance. This addresses the root cause by eliminating the unmonitored path, after which additional inspection technologies can be layered in as needed. It also aligns with a defense-in-depth approach that does not rely on a single inspection point.

Why this answer

The DLP appliance only inspects SMTP, so employees who use personal webmail over HTTPS bypass it entirely. The most effective first step is to block unauthorized exfiltration channels at the web gateway and extend DLP coverage so the control cannot be trivially circumvented. Closing the unmonitored path addresses the root cause, whereas tuning detection patterns or relying on policy alone leaves the bypass intact.

Exam trap

The trap here is focusing on improving detection accuracy inside a channel that is already monitored instead of closing the unmonitored channel that defeats the control.

423
MCQeasy

Which of the following is the PRIMARY purpose of a business impact analysis (BIA)?

A.To establish service level agreements (SLAs)
B.To identify critical business processes and their recovery requirements
C.To test the effectiveness of backup procedures
D.To develop the disaster recovery plan
AnswerB

The BIA determines which business processes are critical and quantifies their recovery time objectives and recovery point objectives. These outputs drive the continuity strategy, so identifying critical processes and their recovery requirements is its primary purpose rather than risk ranking alone.

Why this answer

A business impact analysis (BIA) is the foundational step in business continuity planning that identifies which business processes are critical and quantifies the impact of their disruption over time. It determines recovery time objectives (RTOs) and recovery point objectives (RPOs) for each process, which then drive the recovery strategies and resource requirements documented in the BCP and DRP. Without a BIA, recovery priorities cannot be rationally established.

Exam trap

The trap here is confusing the BIA with the BCP or DRP — candidates often pick 'develop the disaster recovery plan' because they conflate the analysis phase with the planning phase that follows it.

How to eliminate wrong answers

Option A is wrong because SLAs are contractual agreements between a service provider and customer defining expected service levels; they are informed by, but not the purpose of, a BIA. Option C is wrong because testing backup procedures is a validation activity within the BCP maintenance lifecycle, not the purpose of the BIA itself — the BIA identifies what needs to be recovered, not whether backups work. Option D is wrong because developing the disaster recovery plan is a downstream activity that uses BIA output; the BIA is an input to the DRP, not the DRP itself, and conflating the two reverses the dependency.

424
MCQhard

An auditor discovers that a financial institution's IT department uses a decentralized model, with each business unit managing its own applications. What is a PRIMARY risk of this structure?

A.Inconsistent security controls across units
B.Reduced agility in responding to business needs
C.Difficulty in scaling IT infrastructure
D.Higher IT costs due to duplication
AnswerA

Decentralised application management lets each business unit define its own access rules, patching cycles and configuration baselines, so controls diverge across the institution. That inconsistency directly satisfies the stem's primary-risk framing: no central authority enforces uniform standards, leaving weaker units as exploitable entry points for attackers.

Why this answer

Decentralized IT often leads to inconsistent security controls and increased risk of data breaches.

425
MCQmedium

An auditor is selecting a sample of purchase orders for testing. The auditor decides to select every 50th purchase order from a list. This is an example of:

A.Judgmental sampling
B.Random sampling
C.Systematic sampling
D.Stratified sampling
AnswerC

Systematic sampling selects items at fixed intervals from a population list, here every 50th purchase order. This satisfies the auditor's need for an efficient, unbiased selection method that spreads the sample evenly across the entire sequence, provided the list has no cyclical pattern aligning with the interval.

Why this answer

Systematic sampling involves selecting every nth item from a sequentially ordered population, such as every 50th purchase order. This method is a statistical sampling technique that provides a random-like selection if the starting point is random and the population is not patterned. The scenario explicitly describes selecting every 50th item, which is the definition of systematic sampling.

Exam trap

CISA often tests the distinction between systematic and random sampling — candidates see 'every 50th' and think it's random, but the fixed interval is the defining characteristic of systematic sampling.

How to eliminate wrong answers

Option A is wrong because judgmental sampling relies on the auditor's discretion to pick items, not a fixed interval. Option B is wrong because random sampling uses random number generators or tables to select items, with no fixed interval. Option D is wrong because stratified sampling divides the population into subgroups (strata) and samples from each, which is not described here.

426
MCQmedium

An IS auditor is evaluating how an organization detects unauthorized changes to the configuration of its internet-facing web servers. The organization runs a file integrity monitoring tool that hashes critical configuration files hourly and alerts on any hash mismatch. Which of the following is the MOST important factor in determining whether this control provides effective detection?

A.The tool uses a well-known cryptographic hash algorithm such as SHA-256.
B.The baseline of approved file hashes is stored on the same server being monitored.
C.The tool hashes files every hour rather than in real time.
D.Alerts generated by the tool are routed to a monitored queue that is reviewed and acted upon.
AnswerD

A detection control is only effective if its output leads to timely investigation and response. Routing alerts to a queue that is actively monitored and acted upon closes the loop between detection and response, ensuring that a hash mismatch actually triggers investigation. Without this, even a technically perfect integrity check produces no security value because no one responds.

Why this answer

Detection controls create value only when their alerts are reviewed and acted upon. A file integrity monitoring tool can hash files perfectly and still provide no protection if mismatches are logged to an unmonitored queue. Routing alerts to a staffed queue with defined response procedures connects detection to action, making it the most important factor.

Algorithm strength, polling frequency, and baseline placement matter, but each is secondary to whether someone responds to the alert.

Exam trap

The trap here is focusing on the technical strength of the hashing implementation when the decisive factor is whether anyone reviews and acts on the alerts it produces.

427
MCQmedium

An IS auditor is examining how a data center protects its backup tapes while they are transported to an offsite vault. Management states that tapes are encrypted at rest using AES-256. Which of the following is the MOST important control the auditor should verify to protect the tapes during transit?

A.The offsite vault maintains a temperature and humidity-controlled environment.
B.The encryption keys are stored in a hardware security module (HSM) at the primary data center.
C.Backup jobs are scheduled outside business hours to reduce contention with production systems.
D.A chain-of-custody log with tamper-evident seals and dual custody is maintained for each shipment.
AnswerD

During transit, tapes are outside the physically protected data center, so the primary risk is loss, theft, or substitution. A chain-of-custody log with tamper-evident seals and dual custody provides detective and preventive assurance that media were not accessed or swapped. This directly addresses the in-transit exposure and complements encryption by ensuring the physical media remain accounted for.

Why this answer

Because transport places media outside the controlled data center, the auditor should focus on physical custody controls. A documented chain of custody with tamper-evident seals and dual custody provides accountability and detects unauthorized access or substitution. Encryption protects confidentiality of data on the tape, but it does not prevent loss of the media or a denial of recovery capability, so custody controls are the most important complement.

Exam trap

The trap here is assuming encryption at rest fully protects backup tapes, when physical custody and tamper evidence are the controls that address the in-transit risk window.

428
Multi-Selectmedium

Which TWO of the following are types of analytical procedures used in an IS audit? (Select two.)

Select 2 answers
A.Ratio analysis
B.Observation
C.Re-performance
D.Trend analysis
E.Inquiry
AnswersA, D

Ratio analysis is an analytical procedure that compares financial or operational relationships, such as current assets to current liabilities, to identify unusual variances or trends. It is one of the recognised techniques IS auditors apply when performing substantive and preliminary analytical review.

Why this answer

Ratio analysis (A) is a correct type of analytical procedure because it compares financial or operational relationships—such as the current ratio or inventory turnover—to identify unusual variances or anomalies that may signal control weaknesses or misstatements during an IS audit. Trend analysis (D) is also correct because it examines data across multiple periods to detect patterns, directional changes, or outliers, such as a rising rate of failed login attempts or increasing transaction error rates, which helps auditors assess risk and system performance. Observation (B), re-performance (C), and inquiry (E) are not analytical procedures; they are substantive audit techniques or evidence-gathering methods—observation involves watching processes, re-performance involves independently executing controls or calculations, and inquiry involves asking personnel questions—none of which rely on the analytical comparison of financial or operational data relationships.

Exam trap

CISA often tests whether candidates can distinguish evidence-gathering techniques (inquiry, observation, re-performance) from analytical procedures (ratio, trend, regression, reasonableness).

429
Multi-Selecthard

Which THREE of the following are common challenges when integrating a software package with existing legacy systems? (Select exactly three.)

Select 3 answers
A.Availability of modern integration middleware
B.Lack of documented application programming interfaces (APIs)
C.Performance constraints of the legacy environment
D.Data format and schema mismatches
E.Need for custom development to bridge the gap
AnswersB, C, D

Legacy systems frequently expose no documented APIs, so integration must rely on undocumented interfaces, direct database access or screen scraping. That absence of stable, supported programmatic interfaces is a core integration challenge for the package.

Why this answer

Option B is correct because legacy systems frequently lack documented APIs, forcing integrators to reverse-engineer interfaces or rely on undocumented entry points, which makes integration fragile and time-consuming. Option C is correct because legacy environments often run on constrained hardware, outdated runtimes, or monolithic architectures whose throughput and latency cannot meet the demands of a new software package. Option D is correct because legacy systems typically use proprietary, flat-file, EBCDIC, or otherwise non-standard data formats and schemas that must be mapped and transformed to interoperate with modern packages.

Option A is not a challenge but rather a potential enabler, since modern integration middleware (ESBs, API gateways, iPaaS) is generally available to help bridge systems. Option E is not one of the three selected challenges; while custom development is often a consequence of gaps such as missing APIs or format mismatches, it is a remediation approach rather than a distinct integration challenge in this scenario.

Exam trap

The trap here is confusing a solution (custom development or middleware) with the underlying challenge, leading candidates to select 'Need for custom development' as a challenge when it is actually a response to the real challenges of missing APIs, data mismatches, and performance constraints.

430
Multi-Selecthard

An organization is implementing a large ERP system. The project manager is concerned about segregation of duties conflicts. Which THREE controls should the IS auditor recommend to mitigate segregation of duties risks during implementation? (Select THREE)

Select 3 answers
A.Use automated segregation of duties monitoring tools
B.Delay deployment until all segregation conflicts are resolved
C.Implement role-based access controls (RBAC) aligned with job functions
D.Conduct a single user acceptance test (UAT) at the end of the project
E.Require dual approval for sensitive transactions
AnswersA, C, E

Continuous automated monitoring detects toxic access combinations across the ERP as roles and users change, flagging conflicts that manual reviews miss. It provides detective coverage throughout implementation, when role design is still fluid and SoD conflicts are introduced.

Why this answer

Option A is correct because automated segregation of duties (SoD) monitoring tools continuously analyze user role assignments and transaction authorizations against a ruleset of conflicting access combinations, enabling early detection and remediation of toxic combinations during ERP implementation. Option C is correct because role-based access controls (RBAC) map permissions to defined job functions rather than to individuals, which prevents the accumulation of conflicting duties and provides a maintainable, auditable authorization structure in the ERP. Option E is correct because requiring dual approval (two-person integrity) for sensitive transactions such as vendor master changes or payment runs compensates for residual SoD conflicts by ensuring no single user can complete a high-risk action alone.

Option B is not appropriate because halting deployment until every conflict is resolved is impractical and ignores the use of compensating controls and risk acceptance. Option D is not appropriate because a single end-of-project UAT would not provide the continuous, iterative control testing needed to detect SoD conflicts throughout implementation.

Exam trap

The trap is the absolutist option — candidates are drawn to 'delay deployment until all conflicts are resolved' because it sounds rigorous, but CISA expects recognition that compensating controls, not elimination, are the practical mitigation for inherent SoD conflicts.

431
MCQmedium

An IS auditor is reviewing an agile software development project. Which of the following would be the BEST evidence that adequate controls are in place for user acceptance?

A.The product backlog is managed by the product owner
B.Daily standup meetings are held to track progress
C.Retrospectives are conducted after each sprint
D.Each sprint concludes with a sprint review attended by stakeholders
AnswerD

Sprint reviews provide evidence that stakeholders inspect the increment each sprint, satisfying the need for continuous user acceptance in agile delivery. Unlike a single end-of-project sign-off, this recurring stakeholder validation demonstrates acceptance controls operate throughout development, directly addressing the stem's requirement for adequate user acceptance evidence.

Why this answer

In agile development, the sprint review is the ceremony where the team demonstrates the completed increment to stakeholders, who provide feedback and formally accept or reject the work. This stakeholder participation at the end of each sprint is the strongest evidence that user acceptance controls are functioning, because acceptance is continuous rather than deferred to a single end-of-project event. It directly addresses the risk that delivered functionality diverges from business needs.

Exam trap

CISA often tests the confusion between the sprint review (product acceptance with stakeholders) and the sprint retrospective (internal process improvement), causing candidates to select the retrospective as evidence of user acceptance.

How to eliminate wrong answers

Option A is wrong because the product owner managing the backlog is a prioritization and requirements-grooming control, not a user acceptance control — it ensures the right work is queued, not that delivered work is accepted. Option B is wrong because daily standups are an internal team coordination mechanism for tracking progress and removing impediments; they involve the development team, not business stakeholders, and produce no acceptance decision. Option C is wrong because retrospectives focus on process improvement — inspecting how the team worked and identifying changes for the next sprint — not on validating or accepting the product increment with users.

432
MCQeasy

An IT manager needs to ensure that the organization's IT resources are used efficiently. Which of the following is the BEST metric to measure IT resource utilization?

A.System uptime percentage
B.Average server CPU utilization
C.Number of help desk tickets resolved per day
D.Percentage of projects completed on time
AnswerB

Average server CPU utilisation directly quantifies how much processing capacity is consumed versus available, giving a concrete efficiency measure of IT resource usage. It satisfies the manager's need to measure utilisation, unlike metrics such as incident counts or uptime that reflect availability rather than efficiency.

Why this answer

Average server CPU utilization directly measures how much of the computing capacity is being consumed over time, making it the most relevant metric for assessing whether IT resources are being used efficiently. High or low CPU utilization can indicate over-provisioning, under-utilization, or potential performance bottlenecks, enabling the IT manager to optimize resource allocation.

Exam trap

The trap here is that candidates often confuse availability metrics (uptime) with utilization metrics, or they mistakenly equate operational outputs (tickets resolved, project completion) with resource efficiency, leading them to pick a superficially plausible but incorrect answer.

How to eliminate wrong answers

Option A is wrong because system uptime percentage measures availability, not utilization; a server can be up 99.999% of the time but idle, wasting resources. Option C is wrong because the number of help desk tickets resolved per day measures service desk productivity and incident handling efficiency, not the utilization of IT resources like servers or storage. Option D is wrong because the percentage of projects completed on time measures project management performance and schedule adherence, not the operational efficiency of IT resource usage.

433
Multi-Selecthard

Which TWO of the following are BEST indicators that a system development project is at risk of failure?

Select 2 answers
A.Frequent scope changes
B.Clear communication
C.Robust testing
D.Unrealistic schedule
E.High team morale
AnswersA, D

Frequent scope changes signal unstable requirements and weak change control, eroding baseline estimates and rework capacity. This is a recognised early warning that the project is drifting from its approved objectives, making failure more likely as effort compounds.

Why this answer

Frequent scope changes (A) are a classic early warning sign of project failure because uncontrolled scope creep invalidates baselines, disrupts design and testing, and causes cost and schedule overruns. An unrealistic schedule (D) is also a strong risk indicator, since compressing effort below what the work actually requires forces shortcuts in analysis, coding, and testing, leading to defects and missed milestones. In contrast, clear communication (B), robust testing (C), and high team morale (E) are all positive project health indicators that reduce risk rather than signal failure.

Exam trap

The trap here is that candidates confuse project risk indicators with project success factors, mistakenly selecting positive attributes like clear communication or high morale as signs of risk, when the question asks for indicators of failure.

434
MCQhard

During a spiral SDLC project, the IS auditor should focus on which aspect as the primary risk?

A.Scope creep
B.Lack of documentation
C.Inadequate user involvement
D.Incomplete risk assessment
AnswerD

Spiral development iterates through repeated risk analysis cycles, so an incomplete or superficial risk assessment undermines the model's core control. The auditor's primary focus is therefore whether each spiral iteration properly identifies, evaluates and mitigates risk before proceeding.

Why this answer

The spiral model is explicitly risk-driven — each spiral iteration begins with identifying and evaluating risks before determining whether to proceed, and the model was designed by Barry Boehm precisely to manage risk in large, complex projects. Therefore, the IS auditor's primary focus should be on whether risk assessment is performed completely and rigorously at each cycle, since an incomplete risk assessment undermines the model's core control mechanism.

Exam trap

The trap is selecting a generic SDLC risk such as scope creep or user involvement instead of recognizing that the spiral model's defining characteristic — and therefore its primary audit focus — is its risk-driven nature.

How to eliminate wrong answers

Option A is wrong because scope creep, while a common project risk, is not unique to the spiral model and is not its defining risk characteristic — the spiral model's iterative nature actually provides more opportunities to reassess and control scope than waterfall. Option B is wrong because lack of documentation is a general criticism of agile and rapid-development approaches, not the primary risk of the spiral model, which produces substantial documentation at each phase. Option C is wrong because inadequate user involvement is a generic SDLC risk applicable to all methodologies; it does not reflect the spiral model's distinctive risk-driven design, which mandates stakeholder evaluation at each spiral.

435
Multi-Selecthard

During a firewall rule review, an IS auditor identifies several rules that allow any-to-any traffic. Which THREE of the following should the auditor recommend as the MOST appropriate actions?

Select 3 answers
A.Obtain business justification for each any-to-any rule
B.Replace any-to-any rules with specific source/destination rules
C.Immediately delete all any-to-any rules without review
D.Increase logging for any-to-any rules to detect misuse
E.Remove any-to-any rules that lack business justification
AnswersA, B, E

Any-to-any rules bypass least privilege, so the auditor must first establish why each exists. Obtaining business justification determines whether the rule is genuinely required, enabling informed decisions to tighten, replace or remove it rather than blindly deleting needed connectivity.

Why this answer

Option A is correct because an IS auditor must first obtain business justification for each any-to-any rule, since a rule may be required for a legitimate business or technical purpose and cannot be judged in isolation. Option B is correct because the fundamental remediation for overly permissive rules is to replace any-to-any rules with specific source, destination, port, and protocol rules that enforce least privilege and reduce the attack surface. Option E is correct because any any-to-any rule that lacks a valid business justification should be removed, as it represents unnecessary exposure with no documented need.

Option C is not appropriate because immediately deleting all any-to-any rules without review could disrupt legitimate business traffic and cause outages, violating change management and availability requirements. Option D is not the most appropriate action because increasing logging only detects misuse after the fact; it does not remediate the excessive permissiveness that the auditor should recommend eliminating.

Exam trap

CISA often tests the temptation to recommend immediate deletion of risky rules, when the correct audit approach is justification, replacement, and controlled removal.

436
MCQmedium

An organization experiences a critical system failure during non-business hours. The IT team discovers that the last full backup was 48 hours ago, and the incremental backups for the past 24 hours are corrupted. The recovery time objective (RTO) for this system is 4 hours, and the recovery point objective (RPO) is 1 hour. Which of the following is the MOST immediate concern?

A.The backup schedule should be changed to daily full backups
B.The data loss may exceed the recovery point objective (RPO)
C.The root cause of the failure must be determined before recovery
D.The recovery time objective (RTO) of 4 hours will be exceeded
AnswerB

Corrupted incremental backups mean recovery can only restore data as of the last full backup, 48 hours ago, breaching the one-hour RPO by a wide margin. The four-hour RTO remains achievable; the immediate concern is the volume of unrecoverable transactions, making data loss the priority over restoration speed.

Why this answer

The RPO of 1 hour means the organization can tolerate losing at most 1 hour of data. With the last full backup 48 hours old and incremental backups for the past 24 hours corrupted, the usable recovery point is at least 24 hours old, resulting in data loss far exceeding the 1-hour RPO. This gap between actual and acceptable data loss is the most immediate concern because it directly violates the business continuity requirement.

Exam trap

The trap here is that candidates focus on the RTO (4 hours) as the most urgent metric, overlooking that the RPO violation (data loss of 24+ hours vs. 1-hour tolerance) is a more fundamental and immediate business continuity failure, since lost data cannot be recovered by simply restoring faster.

How to eliminate wrong answers

Option A is wrong because changing the backup schedule to daily full backups does not address the immediate data loss crisis; it is a long-term preventive measure, not an urgent response to the current RPO violation. Option C is wrong because determining the root cause of the failure should occur after recovery, not before; delaying recovery to investigate the cause would worsen the RTO breach and data loss. Option D is wrong because the RTO of 4 hours is a recovery speed target, and while it may be challenged, the primary and most immediate concern is the massive data loss (RPO violation), not the recovery time itself.

437
MCQeasy

Which of the following is a key advantage of using an iterative SDLC model over a waterfall model?

A.Reduces the need for user involvement
B.Better suited for projects with stable requirements
C.Easier to manage project costs
D.Provides more flexibility to adapt to changing requirements
AnswerD

Iterative models deliver working increments in short cycles, allowing requirements to be revisited between iterations. Waterfall freezes requirements after the analysis phase, so late changes are costly; iteration directly satisfies the need to accommodate evolving requirements.

Why this answer

Iterative SDLC models develop software in repeated cycles, delivering working increments and incorporating feedback between iterations, which allows requirements to evolve as understanding deepens. This built-in adaptability is the key advantage over waterfall, where requirements are frozen after the requirements phase and changes become expensive and disruptive. The iterative approach directly addresses the reality that requirements often change during long projects.

Exam trap

The trap is the option that sounds plausible but reverses the model's characteristic — candidates may pick 'reduces the need for user involvement' when iterative models actually demand more frequent user engagement than waterfall.

How to eliminate wrong answers

Option A is wrong because iterative models actually increase user involvement — each iteration typically requires user feedback and validation — rather than reducing it; claiming they reduce user involvement inverts the model's core strength. Option B is wrong because waterfall, not iterative, is better suited to stable requirements; iterative models shine precisely when requirements are uncertain or volatile, so this option describes a waterfall advantage. Option C is wrong because iterative projects can be harder to manage cost-wise, not easier — the scope may shift between iterations, making fixed-price contracting and budget forecasting more challenging than in waterfall's linear structure.

438
MCQmedium

An organization has a clean desk policy. Which of the following is the BEST audit procedure to test compliance with this policy?

A.Interview employees about their understanding of the policy.
B.Review security awareness training records.
C.Review incident reports related to lost documents.
D.Conduct unannounced walkthroughs of work areas.
AnswerD

Unannounced walkthroughs provide direct, contemporaneous evidence of actual workspace conditions, since staff cannot tidy desks in advance. This tests real compliance with the clean desk policy, unlike interviews or policy reviews that only confirm awareness or documentation.

Why this answer

Direct observation provides the most reliable evidence of compliance.

439
MCQeasy

A mid-sized company is upgrading its legacy financial system to a new cloud-based ERP. The project manager has decided to use a big-bang cutover approach to minimize costs and time. During the first week post-go-live, users report that several critical reports are generating incorrect totals. An initial investigation reveals that the data mapping from the old system to the new system was not fully validated. Which of the following should the IS auditor recommend as the most appropriate corrective action?

A.Perform a data mapping review and remediation, then run parallel operations until accuracy is confirmed
B.Implement additional manual controls and have users double-check all reports
C.Increase the project budget and hire more consultants to fix the issues
D.Immediately revert to the legacy system and restart the project with a phased approach
AnswerA

Big-bang cutover removed the reconciliation window, so the unvalidated mapping corrupted report totals. Reviewing and remediating the mapping, then running parallel operations, restores accuracy evidence before trusting the new ERP as the sole system of record.

Why this answer

A big-bang cutover with unvalidated data mapping introduces a high risk of data integrity issues, as seen with the incorrect report totals. Running parallel operations after a data mapping review and remediation allows the IS auditor to validate that the new ERP processes data correctly by comparing outputs with the legacy system, ensuring accuracy before full reliance. This aligns with ISACA's guidance on post-implementation verification and control testing for data conversion in cloud-based ERP migrations.

Exam trap

The trap here is that candidates may choose Option D (revert to legacy) because it seems safest, but the CISA exam emphasizes cost-effective, risk-based corrective actions that validate data integrity without abandoning the project, making parallel operations the preferred approach.

How to eliminate wrong answers

Option B is wrong because adding manual controls and user double-checks is a detective, not corrective, control that does not address the root cause of incorrect data mapping; it increases operational burden and error risk without fixing the underlying data transformation logic. Option C is wrong because increasing the budget and hiring more consultants is a reactive, non-technical solution that does not guarantee the data mapping errors are identified and corrected; it may accelerate work but does not provide a validation mechanism. Option D is wrong because immediately reverting to the legacy system and restarting with a phased approach is overly disruptive, costly, and time-consuming; it ignores the possibility of a targeted fix and parallel testing, which is more efficient and preserves project momentum.

440
MCQeasy

Which of the following is the PRIMARY benefit of using a prototype during system development?

A.Clarifying user requirements
B.Accelerating coding
C.Minimizing documentation
D.Reducing development cost
AnswerA

A prototype gives users something concrete to interact with, exposing gaps and ambiguities in stated needs before full build. This early feedback loop reduces rework, making requirements clarification the primary benefit rather than cost, documentation, or code reuse.

Why this answer

A prototype is a working model built early to elicit and validate user requirements before full-scale development. Its primary benefit is clarifying and confirming what users actually need, reducing the risk of building the wrong system.

Exam trap

CISA often tests the primary purpose of a technique — candidates pick cost or speed benefits, but the exam expects the requirements-clarification rationale.

How to eliminate wrong answers

Option B is wrong because prototypes are often throwaway and do not directly accelerate production coding — they may even add work if discarded. Option C is wrong because prototyping typically increases, not minimizes, documentation and iteration artifacts. Option D is wrong because reducing cost is a possible downstream benefit, but it is not the primary purpose; prototypes can increase short-term cost and their main value is requirements clarification.

441
Multi-Selectmedium

An IS auditor is assessing the effectiveness of the change management process for a critical financial application. The auditor wants to determine whether changes are adequately tested before being deployed to production. Which TWO of the following procedures would provide the MOST relevant evidence? (Choose two.)

Select 2 answers
A.Review the change management policy to verify that it requires user acceptance testing prior to production deployment.
B.Observe a developer performing unit testing in the development environment.
C.Re-perform the testing for a sample of changes by executing the test scripts in a test environment and comparing results.
D.Select a sample of recent production changes and inspect the associated test plans, test results, and approvals.
E.Interview the change manager to understand the testing process and any recent challenges.
AnswersC, D

Re-performing testing for a sample of changes allows the auditor to independently verify whether the tests produce the expected results and whether the changes function as intended. This provides strong, direct evidence of the effectiveness of testing. It is especially useful when documentation alone is insufficient or when the auditor needs to confirm the accuracy of reported test results.

Why this answer

To determine whether changes are adequately tested before production deployment, the auditor needs evidence of actual testing activities. Inspecting test documentation for a sample of changes confirms that testing occurred and was approved. Re-performing tests independently verifies the reliability of those tests.

Together, these procedures provide direct evidence of operating effectiveness, whereas policy review, interviews, and observation of development testing are less conclusive.

Exam trap

The trap here is selecting policy review or interviews, which test the design of the process rather than its operating effectiveness for specific changes.

442
Multi-Selectmedium

An IS auditor is reviewing an organization's problem management process. The auditor finds that problem records are created only after multiple incidents with the same root cause have occurred, and there is no proactive trend analysis. Which TWO of the following are the MOST important improvements the auditor should recommend? (Choose two.)

Select 2 answers
A.Require all incidents to be escalated to the problem manager immediately.
B.Establish a formal problem prioritization scheme based on business impact and urgency.
C.Outsource the problem management function to a third-party service provider.
D.Automate the closure of incidents when a problem record is created.
E.Implement trend analysis of incident data to identify recurring issues and raise problem records proactively.
AnswersB, E

A formal prioritization scheme ensures that problem records are addressed according to business impact and urgency, optimizing resource allocation. Without it, problems may be handled in an ad hoc manner, delaying resolution of critical issues. This improvement complements proactive identification by ensuring that the most significant problems receive appropriate attention and escalation.

Why this answer

The problem management process is reactive because problems are only created after multiple incidents. The two most important improvements are proactive trend analysis to identify recurring issues and a formal prioritization scheme to ensure business-relevant problems are addressed appropriately. These changes shift the process from reactive to proactive and risk-based, reducing repeat incidents and aligning problem resolution with business impact.

Exam trap

The trap here is recommending operational changes like escalating all incidents or automating closures, which do not address the core weakness of missing proactive analysis and prioritization.

443
MCQmedium

An organization's IT department is considering a shift from insourcing to co-sourcing for application development. What is a PRIMARY advantage of co-sourcing?

A.Eliminates the cost of employee benefits
B.Simplifies performance management
C.Reduces the need for IT governance
D.Provides access to specialized expertise while maintaining internal control
AnswerD

Co-sourcing blends external specialists with retained internal staff, so the organisation gains scarce development skills it cannot recruit while keeping architectural direction, data governance and oversight in-house. That balance satisfies the stem's need for capability uplift without surrendering control of the application estate.

Why this answer

Co-sourcing combines internal and external resources, allowing access to specialized skills while retaining control.

444
MCQmedium

An IS auditor is reviewing how an organization manages its backup media. The auditor learns that full backups are written to tape each night, the tapes are stored in a cabinet in the data center, and the same cabinet is used to store cleaning supplies and spare hardware. Which of the following is the MOST significant risk the auditor should highlight?

A.Backup media are stored without environmental protection and alongside materials that could damage or contaminate the tapes.
B.Nightly full backups consume excessive storage capacity and should be replaced with incremental backups.
C.The backup process may not be documented, creating a risk of inconsistent restores.
D.Backup tapes stored on-site cannot be used to restore data after a disaster that destroys the data center.
AnswerA

Cleaning supplies and spare hardware in the same cabinet introduce chemical vapors, dust, physical impact, and possible liquid spills that can corrupt magnetic tape media. This is a direct threat to the recoverability of the organization's backup data. The auditor should report that media lack proper environmental controls and are exposed to contaminants and physical hazards, which jeopardizes restoration when it is needed most.

Why this answer

Backup tapes stored in a cabinet shared with cleaning supplies and spare hardware are exposed to chemical vapors, dust, impact, and spills that can render the media unreadable. Because these tapes are the organization's recovery capability, their physical protection is critical. The auditor should report the lack of environmental controls and the co-location with potentially damaging materials as the most significant risk in this finding.

Exam trap

The trap here is jumping to the on-site storage issue while overlooking that the media are physically exposed to contaminants in the same cabinet.

445
MCQmedium

An organization is implementing a data masking solution for a non-production database. Which of the following is the MOST important requirement?

A.Masked data should maintain referential integrity.
B.Masked data should be encrypted.
C.Masked data should be irreversible.
D.Masked data should be randomized across all columns.
AnswerA

Masked values must preserve the relationships between primary and foreign keys across tables; otherwise joins in the non-production database break and testing becomes invalid. Maintaining referential integrity ensures the masked dataset remains structurally consistent and usable.

Why this answer

In a non-production database, data masking must preserve referential integrity to ensure that relationships between tables (e.g., foreign keys) remain valid after masking. Without referential integrity, application logic that relies on these relationships would break, making the non-production environment unusable for testing or development. This is the most critical requirement because masked data must still function correctly within the database schema.

Exam trap

The trap here is that candidates often confuse data masking with encryption or hashing, assuming irreversibility or encryption are the top priorities, but the CISA exam emphasizes that the primary goal in a non-production environment is usability and data integrity, not cryptographic security.

How to eliminate wrong answers

Option B is wrong because encryption is a security control for data at rest or in transit, not a masking requirement; masked data is already obfuscated and does not need encryption to fulfill its purpose. Option C is wrong because irreversibility is a property of hashing or tokenization, not a mandatory requirement for data masking; masking can be reversible (e.g., using deterministic substitution) as long as the original data is not exposed. Option D is wrong because randomizing data across all columns would destroy referential integrity and consistency; masking often uses deterministic algorithms to maintain relationships and data distribution patterns.

446
MCQeasy

An organization has a policy requiring annual information security awareness training for all employees. During a recent audit, it was found that 20% of employees had not completed the training. What is the BEST course of action for the IT governance committee?

A.Reduce the training frequency to biennial.
B.Require managers to ensure their teams complete training and escalate non-compliance to HR.
C.Extend the training deadline by three months.
D.Make the training optional for employees with high performance ratings.
AnswerB

Line managers own their teams' compliance, so requiring them to enforce completion and escalating persistent non-compliance to HR applies accountability and consequence. This addresses the 20% gap through existing governance structures rather than ad hoc reminders or policy rewrites.

Why this answer

The governance committee's role is to ensure policy compliance through accountability mechanisms. Requiring managers to enforce completion and escalating non-compliance to HR reinforces the policy's mandatory nature and creates consequences for non-compliance, which is the most effective way to achieve sustained compliance. This addresses the root cause—lack of enforcement—rather than weakening the policy.

Exam trap

CISA often tests the difference between treating the symptom (extending deadlines, reducing frequency) and addressing the root cause (lack of accountability); candidates may pick a lenient option that weakens the control instead of enforcing it.

How to eliminate wrong answers

Option A is wrong because reducing training frequency weakens the security posture and does not address the non-compliance; it simply lowers the bar to make numbers look better. Option C is wrong because extending the deadline is a temporary fix that does not create accountability and may result in continued non-compliance. Option D is wrong because making training optional for high performers creates a double standard, undermines the policy, and leaves the organization exposed to insider threats regardless of performance ratings.

447
MCQmedium

An IT auditor is reviewing the problem management process. The IT team maintains a repository of known errors with documented workarounds. Which component of problem management is this?

A.Service request
B.Root cause analysis
C.Known error database
D.Problem record
AnswerC

The known error database records previously diagnosed problems and their documented workarounds, letting service desk staff resolve recurring incidents quickly without re-diagnosing root cause. It is a core problem management artefact, distinct from the incident record itself.

Why this answer

A known error database (KED) is the ITIL problem management repository that stores known errors and their documented workarounds. When the IT team maintains a repository of known errors with workarounds, that is by definition the KED.

Exam trap

CISA often tests the confusion between the problem record (single problem lifecycle) and the known error database (aggregated repository of known errors and workarounds).

How to eliminate wrong answers

Option A is wrong because a service request is a user request for something (e.g., password reset), handled by request fulfillment, not problem management. Option B is wrong because root cause analysis is the investigative activity that identifies the underlying cause of a problem, not the repository itself. Option D is wrong because a problem record documents a single problem's lifecycle; the KED is the aggregated repository of known errors and workarounds.

448
Multi-Selecthard

Which THREE of the following are common challenges when implementing a bring-your-own-device (BYOD) policy that affect information systems operations? (Select exactly 3.)

Select 3 answers
A.Difficulty in enforcing data encryption and remote wipe capabilities
B.Reduced hardware procurement costs for the organization
C.Increased employee productivity due to device familiarity
D.Incompatibility between corporate applications and various device platforms
E.Increased risk of malware infections due to unmanaged devices
AnswersA, D, E

On personally owned hardware, the organisation lacks administrative control, so enforcing encryption and triggering remote wipes is legally and technically constrained. This satisfies the stem's operations challenge by creating gaps in data protection and breach containment.

Why this answer

Options A, D, and E are correct. BYOD introduces security risks such as difficulty enforcing data encryption and remote wipe (A), incompatibility between corporate apps and various platforms (D), and increased risk of malware from unmanaged devices (E). Option B is an advantage, not a challenge.

Option C is a potential benefit, not a common challenge.

449
Multi-Selectmedium

Which TWO of the following are essential controls to ensure data integrity during a cloud migration project?

Select 2 answers
A.Granting all migration team members full database access
B.Implementing encryption at rest and in transit
C.Using a phased migration approach without rollback capability
D.Running reconciliation checks comparing source and target data counts
E.Performing a single full data validation after migration
AnswersB, D

Encryption at rest and in transit protects data confidentiality and integrity throughout the migration, satisfying the stem's data-integrity requirement. It prevents tampering or interception while data moves between source and cloud environments, ensuring transferred records remain unaltered and trustworthy.

Why this answer

Option B is correct because implementing encryption at rest and in transit protects data from unauthorized modification or interception during transfer and storage, directly preserving integrity throughout the migration. Option D is correct because reconciliation checks that compare source and target data counts (and ideally checksums or hashes) detect any data loss, duplication, or corruption introduced during migration, verifying that the transferred data matches the original. Option A is wrong because granting all team members full database access violates least privilege and increases the risk of accidental or malicious data alteration.

Option C is wrong because a phased migration without rollback capability removes the ability to revert corrupted or incomplete transfers, undermining integrity safeguards. Option E is wrong because a single full validation only after migration is too late and too coarse; integrity must be verified continuously or at multiple checkpoints, not once at the end.

Exam trap

The trap here is that candidates often confuse encryption with confidentiality and overlook its role in integrity, or they assume that a single post-migration validation (Option E) is sufficient, ignoring the need for ongoing reconciliation checks (Option D) to detect incremental data loss or corruption during the transfer process.

450
MCQmedium

A company outsources its data center operations to a third-party provider. Which of the following is the MOST important control to include in the outsourcing contract?

A.Detailed escalation procedures for incidents
B.Service level agreements with financial penalties
C.Requirements for encryption of data at rest
D.Right to audit the provider's facilities and processes
AnswerD

The right to audit gives the company contractual authority to inspect the provider's facilities and processes, verifying that outsourced controls operate effectively. Without it, the organisation cannot independently confirm compliance or security, so this clause is the most critical control to embed in the outsourcing contract.

Why this answer

The right to audit the provider's facilities and processes is the most important control because it ensures the outsourcing company can verify that the provider is complying with security, regulatory, and contractual requirements. Without audit rights, the company has no independent means to confirm that controls are effective, leaving it exposed to undetected risks.

Exam trap

CISA often tests the difference between assurance and operational controls. Candidates might choose SLAs or encryption because they sound important, but the right to audit is the governance mechanism that provides ongoing assurance.

How to eliminate wrong answers

Option A is wrong because escalation procedures are operational and do not provide assurance over the provider's controls. Option B is wrong because SLAs with penalties address performance but not compliance or security verification. Option C is wrong because encryption is a specific technical control, but it is only one aspect and does not guarantee overall compliance; audit rights are broader and more fundamental.

Page 5

Page 6 of 13

Page 7