Skip to Content

ISACA CISA Certified Information Systems Auditor Exam Questions and Answers – 24

The latest ISACA CISA (Certified Information Systems Auditor) certification actual real practice exam question and answer (Q&A) dumps are available free, which are helpful for you to pass the ISACA CISA exam and earn ISACA CISA certification.

ISACA Certified Information Systems Auditor (CISA) Exam Questions and Answers

CISA Question 2571

Question

Which of the following is the BEST way to control the concurrent use of licensed software?

A. User self-discipline.
B. Monitor by system administrator.
C. Surprise audit conducted by vendors.
D. Metering software

Answer

B. Monitor by system administrator.

CISA Question 2572

Question

Which of the following is a prerequisite to help ensure that IS hardware and software support the delivery of mission-critical functions?

A. Control over IS infrastructure expenditure
B. An independent audit of the process
C. A comprehensive IS applications architecture
D. Documented emergency change procedures

Answer

C. A comprehensive IS applications architecture

CISA Question 2573

Question

Code changes are compiled and placed in a change folder by the developer. An implementation team migrates changes to production from the change folder.
Which of the following BEST indicates separation of duties is in place during the migration process?

A. A second individual performs code review before the change is released to production.
B. The developer approves changes prior to moving them to the change folder.
C. The implementation team does not have experience writing code.
D. The implementation team does not have access to change the source code.

Answer

A. A second individual performs code review before the change is released to production.

CISA Question 2574

Question

Which of the following are the PRIMARY considerations when determining the timing of remediation testing?

A. The level of management and business commitment to implementing agreed action plans
B. The difficulty of scheduling resources and availability of management for a follow-up engagement
C. The availability and competencies of control owners for implementing the agreed action
D. The significance of the reported findings and the impact if corrective actions are not taken

Answer

D. The significance of the reported findings and the impact if corrective actions are not taken

CISA Question 2575

Question

The success of an IT projects is measured PRIMARILY by the:

A. translation of business vision to function vision
B. implementation of current technology
C. benefit that the business derives from the outcome
D. efficient use of resources

Answer

C. benefit that the business derives from the outcome

CISA Question 2576

Question

What would be an IS auditor’s BEST recommendation upon finding that a third-party IT service provider hosts the organization’s human resources (HR) system in a foreign country?

A. Conduct a privacy impact analysis.
B. Implement change management review.
C. Review third-party audit reports.
D. Perform background verification checks.

Answer

A. Conduct a privacy impact analysis.

CISA Question 2577

Question

When determining whether a project in the design phase will meet organizational objectives, what is BEST to compare against the business case?

A. Project plan
B. Requirements analysis
C. Implementation plan
D. Project budget provisions

Answer

B. Requirements analysis

CISA Question 2578

Question

An online retailer is receiving customer about receiving different items from what they ordered on the organization’s website. The root cause has been traced to poor data quality. Despite efforts to clean erroneous data from the system, multiple data quality issues continue to occur. Which of the following recommendations would be the BEST way to reduce the likelihood of future occurrences?

A. Implement business rules to validate employee data entry.
B. Invest in additional employee training for data entry.
C. Assign responsibility for improving data quality.
D. Outsource data cleansing activities to reliable third parties

Answer

A. Implement business rules to validate employee data entry.

CISA Question 2579

Question

A multinational organization is integrating its existing payroll system with a human resource information system. Which of the following should be of GREATEST concern to the IS auditor?

A. System documentation
B. Currency conversion
C. Application interfaces
D. Scope creep

Answer

C. Application interfaces

CISA Question 2580

Question

When implementing an upgraded enterprise resource planning (ERP) system, which of the following is the MOST important consideration for a golive decision?

A. Test cases
B. Rollback strategy
C. Business case
D. Post-implementation review objectives

Answer

C. Business case