Skip to Content

ISACA CISA Certified Information Systems Auditor Exam Questions and Answers – 25

The latest ISACA CISA (Certified Information Systems Auditor) certification actual real practice exam question and answer (Q&A) dumps are available free, which are helpful for you to pass the ISACA CISA exam and earn ISACA CISA certification.

ISACA Certified Information Systems Auditor (CISA) Exam Questions and Answers

CISA Question 2621

Question

Which of the following is the MOST important consideration when developing an online business architecture and recovery strategy?

A. Vendors’ network security
B. Immediate problem resolution
C. Vendors’ financial stability
D. Single points of failure

Answer

D. Single points of failure

CISA Question 2622

Question

Which of the following is the BEST indication of control maturity in an organization’s systems development and implementation processes?

A. Code changes are tested and deployed manually.
B. Code changes are deployed to a test server and then to production.
C. Code changes are documented and approved.
D. Code changes are tested and deployed through automation.

Answer

D. Code changes are tested and deployed through automation.

CISA Question 2623

Question

An organization is developing a web portal using some external components. Which of the following should be of MOST concern to an IS auditor?

A. Open-source components were integrated during development.
B. Some of the developers are located in another country.
C. The organization has not reviewed the components for known exploits.
D. Staff require additional training in order to perform code review.

Answer

C. The organization has not reviewed the components for known exploits.

CISA Question 2624

Question

Which of the following would be an IS auditor’s GREATEST concern when reviewing the early stages of a software development project?

A. The lack of acceptance criteria behind user requirements
B. The lack of completion of all requirements at the end of each sprint
C. The lack of technical documentation to support the program code
D. The lack of a detailed unit and system test plan

Answer

D. The lack of a detailed unit and system test plan

CISA Question 2625

Question

An IS auditor finds that the cost of developing an application is now projected to significantly exceed the budget. Which of the following is the
GREATEST risk to communicate to senior management?

A. Increased staff turnover
B. Project abandonment
C. Noncompliance with project methodology
D. Inability to achieve expected benefits

Answer

B. Project abandonment

CISA Question 2626

Question

Which of the following is the BEST indication that a newly developed information system is ready for migration into production?

A. Items in the work breakdown structure are completed.
B. Audit has signed off.
C. User acceptance testing is successfully completed.
D. Technical requirements are met.

Answer

C. User acceptance testing is successfully completed.

CISA Question 2627

Question

An advantage of object-oriented system development is that it:

A. partitions systems into a client/server architecture.
B. decreases the need for system documentation.
C. is easier to code than procedural languages.
D. is suited to data with complex relationships.

Answer

D. is suited to data with complex relationships.

CISA Question 2628

Question

An IS auditor is reviewing the release management process for an in-house software development solution. In which environment is the software version MOST likely to be the same as production?

A. Testing
B. Development
C. Integration
D. Staging

Answer

D. Staging

CISA Question 2629

Question

A new application will require multiple interfaces. Which of the following testing methods can be used to detect interface errors early in the development life cycle?

A. Acceptance
B. Top down
C. Sociability
D. Bottom up

Answer

D. Bottom up

CISA Question 2630

Question

An IS auditor would be concerned if the quality assurance (QA) function were found to be performing which of the following roles?

A. Reviewing the code to ensure proper documentation and development practices were followed
B. Submitting corrected code for issues identified through the testing process
C. Evaluating whether the testing assumptions and developed code are aligned to the design criteria
D. Ensuring the development methods and standards are adhered to throughout the process

Answer

A. Reviewing the code to ensure proper documentation and development practices were followed