
Get 100% Real CISA Exam Questions, Accurate & Verified Answers As Seen in the Real Exam!
CISA Premium Files Updated Aug-2026 Practice Valid Exam Dumps Question
NEW QUESTION # 171
Which of the following is the MOST important privacy consideration for an organization that uses a cloud service provider to process customer data?
- A. Data privacy must be monitored in accordance with industry standards and best practices.
- B. Data privacy must be managed in accordance with the regulations applicable to the organization.
- C. Customer data transferred to the service provider must be reported to the regulatory authority.
- D. No personal information may be transferred to the service provider without notifying the customer.
Answer: B
NEW QUESTION # 172
Which of the following should occur EARLIEST in a business continuity management lifecycle?
- A. Identifying critical business processes
- B. Developing a training and awareness program
- C. Defining business continuity procedures
- D. Carrying out a threat and risk assessment
Answer: A
NEW QUESTION # 173
Stress testing should ideally be earned out under a:
- A. test environment with production workloads.
- B. production environment with production workloads.
- C. production environment with test data.
- D. test environment with test data.
Answer: A
Explanation:
Explanation
Stress testing is a type of performance testing that evaluates the behavior and reliability of a system under extreme conditions, such as high workload, limited resources, or concurrent users. Stress testing should ideally be carried out under a test environment with production workloads, as this would simulate the most realistic and demanding scenario for the system without affecting the actual production environment. A production environment with production workloads is not suitable for stress testing, as it could cause disruption or damage to the system and its users. A production environment with test data is not suitable for stress testing, as it could compromise the integrity and security of the production data. A test environment with test data is not suitable for stress testing, as it could underestimate the potential issues and risks that could occur in the production environment. References:
CISA Review Manual, 27th Edition, pages 471-4721
CISA Review Questions, Answers & Explanations Database, Question ID: 261
NEW QUESTION # 174
Which of the following should be the PRIMARY basis for prioritizing follow-up audits?
- A. Recommendation from executive management
- B. Complexity of management's action plans
- C. Audit cycle defined in the audit plan
- D. Residual risk from the findings of previous audits
Answer: D
Explanation:
Explanation
Residual risk from the findings of previous audits should be the primary basis for prioritizing follow-up audits, because it reflects the level of exposure and potential impact that remains after management has implemented corrective actions or accepted the risk. Follow-up audits should focus on verifying whether the residual risk is within acceptable levels and whether the corrective actions are effective and sustainable. Audit cycle defined in the audit plan, complexity of management's action plans, and recommendation from executive management are not valid criteria for prioritizing follow-up audits, because they do not consider the residual risk from previous audits. References: CISA Review Manual (Digital Version), Chapter 2, Section 2.4.3
NEW QUESTION # 175
The FIRST step in managing the risk of a cyber attack is to:
- A. identify critical information assets.
- B. assess the vulnerability impact.
- C. evaluate the likelihood of threats.
- D. estimate potential damage.
Answer: A
Explanation:
Explanation/Reference:
Explanation:
The first step in managing risk is the identification and classification of critical information resources (assets). Once the assets have been identified, the process moves onto the identification of threats, vulnerabilities and calculation of potential damages.
NEW QUESTION # 176
Which of the following BEST enables an organization to determine the effectiveness of its information security awareness program?
- A. Reviewing security staff performance evaluations
- B. Evaluating the results of a social engineering exercise
- C. Performing an analysis of the number of help desk calls
- D. Measuring user satisfaction with the quality of the training
Answer: B
NEW QUESTION # 177
Which of the following is the MOST important consideration to ensure the integrity of encrypted data?
- A. The accessibility of decryption keys
- B. The establishment of an encryption policy
- C. The frequency of encryption key updates
- D. The strength of the encryption algorithm
Answer: D
Explanation:
The integrity of encrypted data depends primarily on the strength of the encryption algorithm. A strong algorithm ensures that the data cannot be altered or deciphered without authorization, maintaining both confidentiality and integrity against cryptographic attacks.
NEW QUESTION # 178
Which of the following will BEST ensure that a proper cutoff has been established to reinstate transactions and records to their condition just prior to a computer system failure?
- A. Using a database management system (DBMS) to dynamically back-out partially processed transactions
- B. Ensuring bisynchronous capabilities on all transmission lines
- C. Maintaining system console logs in electronic format
- D. Rotating backup copies of transaction files offsite
Answer: A
Explanation:
Using a DBMS to dynamically back-out partially processed transactions allows for the rollback of transactions that were only partially completed before the system failure. It ensures that the data remains consistent and eliminates any incomplete or inconsistent data that may have been created during the system failure.
NEW QUESTION # 179
An organization is running servers with critical business application that are in an area subject to frequent but brief power outages. Knowledge of which of the following would allow the organization's management to monitor the ongoing adequacy of the uninterruptable power supply (UPS)?
- A. Duration and interval of the power outages
- B. Number of servers supported by the ups
- C. Mean time to recover servers after failure
- D. Business impact of server downtime
Answer: D
NEW QUESTION # 180
Which of the following is an estimation technique where the results can be measure by the functional size of an information system based on the number and complexity of input, output, interface and queries?
- A. Gantt Chart
- B. Critical path methodology
- C. Functional Point analysis
- D. Time box management
Answer: C
Explanation:
Explanation/Reference:
For CISA exam you should know below information about Functional Point Analysis:
Function Point Analysis (FPA) is an ISO recognized method to measure the functional size of an information system. The functional size reflects the amount of functionality that is relevant to and recognized by the user in the business. It is independent of the technology used to implement the system.
The unit of measurement is "function points". So, FPA expresses the functional size of an information system in a number of function points (for example: the size of a system is 314 fop's).
The functional size may be used:
To budget application development or enhancement costs
To budget the annual maintenance costs of the application portfolio
To determine project productivity after completion of the project
To determine the Software Size for cost estimating
All software applications will have numerous elementary processes or independent processes to move data. Transactions (or elementary processes) that bring data from outside the application domain (or application boundary) to inside that application boundary are referred to as external inputs. Transactions (or elementary processes) that take data from a resting position (normally on a file) to outside the application domain (or application boundary) are referred as either an external outputs or external inquiries. Data at rest that is maintained by the application in question is classified as internal logical files.
Data at rest that is maintained by another application in question is classified as external interface files.
Types of Function Point Counts:
Development Project Function Point Count
Function Points can be counted at all phases of a development project from requirements up to and including implementation. This type of count is associated with new development work. Scope creep can be tracked and monitored by understanding the functional size at all phase of a project. Frequently, this type of count is called a baseline function point count.
Enhancement Project Function Point Count
It is common to enhance software after it has been placed into production. This type of function point count tries to size enhancement projects. All production applications evolve over time. By tracking enhancement size and associated costs a historical database for your organization can be built. Additionally, it is important to understand how a Development project has changed over time.
Application Function Point Count
Application counts are done on existing production applications. This "baseline count" can be used with overall application metrics like total maintenance hours. This metric can be used to track maintenance hours per function point. This is an example of a normalized metric. It is not enough to examine only maintenance, but one must examine the ratio of maintenance hours to size of the application to get a true picture.
Productivity:
The definition of productivity is the output-input ratio within a time period with due consideration for quality.
Productivity = outputs/inputs (within a time period, quality considered) The formula indicates that productivity can be improved by (1) by increasing outputs with the same inputs, (2) by decreasing inputs but maintaining the same outputs, or (3) by increasing outputs and decreasing inputs change the ratio favorably.
Software Productivity = Function Points / Inputs
Effectiveness vs. Efficiency:
Productivity implies effectiveness and efficiency in individual and organizational performance.
Effectiveness is the achievement of objectives. Efficiency is the achievement of the ends with least amount of resources.
Software productivity is defined as hours/function points or function points/hours. This is the average cost to develop software or the unit cost of software. One thing to keep in mind is the unit cost of software is not fixed with size. What industry data shows is the unit cost of software goes up with size.
Average cost is the total cost of producing a particular quantity of output divided by that quantity. In this case to Total Cost/Function Points. Marginal cost is the change in total cost attributable to a one-unit change in output.
There are a variety of reasons why marginal costs for software increase as size increases. The following is a list of some of the reasons As size becomes larger complexity increases.
As size becomes larger a greater number of tasks need to be completed.
As size becomes larger there is a greater number of staff members and they become more difficult to manage.
Function Points are the output of the software development process. Function points are the unit of software. It is very important to understand that Function Points remain constant regardless who develops the software or what language the software is developed in. Unit costs need to be examined very closely.
To calculate average unit cost all items (units) are combined and divided by the total cost. On the other hand, to accurately estimate the cost of an application each component cost needs to be estimated.
Determine type of function point count
Determine the application boundary
Identify and rate transactional function types to determine their contribution to the unadjusted function point count.
Identify and rate data function types to determine their contribution to the unadjusted function point count.
Determine the value adjustment factor (VAF)
Calculate the adjusted function point count.
To complete a function point count knowledge of function point rules and application documentation is needed. Access to an application expert can improve the quality of the count. Once the application boundary has been established, FPA can be broken into three major parts FPA for transactional function types FPA for data function types
FPA for GSCs
Rating of transactions is dependent on both information contained in the transactions and the number of files referenced, it is recommended that transactions are counted first. At the same time a tally should be kept of all FTR's (file types referenced) that the transactions reference. Every FTR must have at least one or more transactions. Each transaction must be an elementary process. An elementary process is the smallest unit of activity that is meaningful to the end user in the business. It must be self-contained and leave the business in consistent state The following were incorrect answers:
Critical Path Methodology - The critical path method (CPM) is an algorithm for scheduling a set of project activities Gantt Chart - A Gantt chart is a type of bar chart, developed by Henry Gantt in the 1910s, that illustrates a project schedule. Gantt charts illustrate the start and finish dates of the terminal elements and summary elements of a project. Terminal elements and summary elements comprise the work breakdown structure of the project. Modern Gantt charts also show the dependency (i.e. precedence network) relationships between activities. Gantt charts can be used to show current schedule status using percent-complete shadings and a vertical "TODAY" line as shown here.
Time box Management - In time management, a time boxing allocates a fixed time period, called a time box, to each planned activity. Several project management approaches use time boxing. It is also used for individual use to address personal tasks in a smaller time frame. It often involves having deliverables and deadlines, which will improve the productivity of the user.
The following reference(s) were/was used to create this question:
CISA review manual 2014 Page number 154
NEW QUESTION # 181
Which of the following should be of GREATEST concern to an IS auditor when auditing an organization's IT strategy development process?
- A. A business impact analysis (BIA) was not performed to support the IT strategy
- B. The IT strategy was developed based on the current IT capability
- C. Information security was not included as a key objective m the IT strategic plan.
- D. The IT strategy was developed before the business plan
Answer: C
Explanation:
The greatest concern for an IS auditor when auditing an organization's IT strategy development process is that information security was not included as a key objective in the IT strategic plan. Information security is a vital component of IT strategy, as it ensures the confidentiality, integrity and availability of information assets, and supports the business objectives and regulatory compliance. The other options are not as significant as the lack of information security in the IT strategic plan. References: CISA Review Manual (Digital Version), Chapter 1, Section 1.31
NEW QUESTION # 182
During the review of a biometrics system operation, an IS auditor should FIRST review the stage of:
- A. enrollment.
- B. identification.
- C. storage.
- D. verification.
Answer: A
Explanation:
Section: Protection of Information Assets
Explanation:
The users of a biometrics device must first be enrolled in the device. The device captures a physical or
behavioral image of the human, identifies the unique features and uses an algorithm to convert them into a
string of numbers stored as a template to be used in the matching processes.
NEW QUESTION # 183
When performing a data classification project, an information security manager should:
- A. identify information custodians
- B. identify information owners
- C. assign information access privileges
- D. assign information critically and sensitivity
Answer: D
Explanation:
Section: Protection of Information Assets
NEW QUESTION # 184
Which of the following attack best describe "Computer is the target of a crime" and "Computer is the tool of a crime"?
- A. Traffic analysis and Eavesdropping
- B. Denial of Service (DoS) and Installing Key loggers
- C. War Driving and War Chalking
- D. Piggybacking and Race Condition
Answer: B
Explanation:
Explanation/Reference:
In computing, a denial-of-service (DoS) or distributed denial-of-service (DDoS) attack is an attempt to make a machine or network resource unavailable to its intended users. Although the means to carry out, motives for, and targets of a DoS attack may vary, it generally consists of efforts to temporarily or indefinitely interrupt or suspend services of a host connected to the Internet. As clarification, DDoS (Distributed Denial of Service) attacks are sent by two or more persons, or bots. (See botnet) DoS (Denial of Service) attacks are sent by one person or system.
Keystroke logging, often referred to as key logging or keyboard capturing, is the action of recording (or logging) the keys struck on a keyboard, typically in a covert manner so that the person using the keyboard is unaware that their actions are being monitored. It also has very legitimate uses in studies of human- computer interaction. There are numerous key logging methods, ranging from hardware and software- based approaches to acoustic analysis.
There are four types of a computer crimes:
1. Computer is the target of a crime - Perpetrator uses another computer to launch an attack. In this attack the target is a specific identified computer. Ex. Denial of Service (DoS), hacking
2. Computer is the Subject of a crime - In this attack perpetrator uses computer to commit crime and the target is another computer. In this attack, target may or may not be defined. Perpetrator launches attack with no specific target in mind. Ex. Distributed DoS, Malware
3. Computer is the tool of a crime - Perpetrator uses computer to commit crime but the target is not a computer. Target is the data or information stored on a computer. Ex. Fraud, unauthorized access, phishing, installing key logger
4. Computer Symbolizes Crime - Perpetrator lures the user of a computer to get confidential information.
Target is user of computer. Ex. Social engineering methods like Phishing, Fake website, Scam Mails, etc The following answers are incorrect:
Eavesdropping - is the act of secretly listening to the private conversation of others without their consent, as defined by Black's Law Dictionary. This is commonly thought to be unethical and there is an old adage that "eavesdroppers seldom hear anything good of themselves...eavesdroppers always try to listen to matters that concern them." Traffic analysis - is the process of intercepting and examining messages in order to deduce information from patterns in communication. It can be performed even when the messages are encrypted and cannot be decrypted. In general, the greater the number of messages observed, or even intercepted and stored, the more can be inferred from the traffic. Traffic analysis can be performed in the context of military intelligence, counter-intelligence, or pattern-of-life analysis, and is a concern in computer security.
Masquerading - A masquerade attack is an attack that uses a fake identity, such as a network identity, to gain unauthorized access to personal computer information through legitimate access identification. If an authorization process is not fully protected, it can become extremely vulnerable to a masquerade attack.
Masquerade attacks can be perpetrated using stolen passwords and logons, by locating gaps in programs, or by finding a way around the authentication process. The attack can be triggered either by someone within the organization or by an outsider if the organization is connected to a public network. The amount of access masquerade attackers get depends on the level of authorization they've managed to attain. As such, masquerade attackers can have a full smorgasbord of cybercrime opportunities if they've gained the highest access authority to a business organization. Personal attacks, although less common, can also be harmful.
The following reference(s) were/was used to create this question:
CISA review Manual 2014. Page number 321
http://en.wikipedia.org/wiki/Denial-of-service_attack
http://en.wikipedia.org/wiki/Eavesdropping
http://en.wikipedia.org/wiki/Traffic_analysis
http://www.techopedia.com/definition/4020/masquerade-attack
NEW QUESTION # 185
A post-implementation review was conducted by issuing a survey to users. Which of the following should be of GREATEST concern to an IS auditor?
- A. The survey form template did not allow additional feedback to be provided.
- B. The survey results were not presented in detail lo management.
- C. The survey questions did not address the scope of the business case.
- D. The survey was issued to employees a month after implementation.
Answer: C
NEW QUESTION # 186
Which of the following should an IS auditor recommend as MOST critical to an effective performance improvement process for IT services?
- A. Management accepts accountability for achieving performance goals.
- B. The performance goals are aligned with a commonly accepted framework.
- C. Progress on performance goals is regularly reported to the board.
- D. Root cause analysis of service issues is used to develop performance goals.
Answer: A
NEW QUESTION # 187
......
REAL CISA Exam Questions With 100% Refund Guarantee : https://www.dumpsvalid.com/CISA-still-valid-exam.html
Practice with CISA Dumps for Certified Information Systems Auditor Certified Exam Questions & Answer: https://drive.google.com/open?id=12AZ6lKfwiS3kgYCTcWXJxqhuPrzgh1NS