Pass ISACA CISA exam Dumps 100 Pass Guarantee With Latest Demo [Q297-Q315]

Share

Pass ISACA CISA exam Dumps 100 Pass Guarantee With Latest Demo

The  CISA PDF Dumps Greatest for the ISACA Exam Study Guide!

NEW QUESTION # 297
Which type of device sits on the perimeter of a corporate of home network, where it obtains a public IP address and then generates private IP addresses internally?

  • A. Switch
  • B. Gateway
  • C. Intrusion prevention system (IPS)
  • D. Router

Answer: D

Explanation:
Explanation
A router is a type of device that sits on the perimeter of a corporate or home network, where it obtains a public IP address and then generates private IP addresses internally. A router connects two or more networks and forwards packets between them based on routing rules. A router can also provide network address translation (NAT) functionality, which allows multiple devices to share a single public IP address and access the internet.
A switch is a type of device that connects multiple devices within a network and forwards packets based on MAC addresses. An intrusion prevention system (IPS) is a type of device that monitors network traffic and blocks or modifies malicious packets based on predefined rules. A gateway is a type of device that acts as an interface between different networks or protocols, such as a modem or a firewall. References: CISA Review Manual (Digital Version), [ISACA Glossary of Terms]


NEW QUESTION # 298
When reviewing a database supported by a third-party service provider, an IS auditor found minor control deficiencies. The auditor should FIRST discuss recommendations with the:

  • A. organization's chief information officer (CIO)
  • B. organization's service level manager
  • C. service provider support team manager
  • D. service provider contract liaison

Answer: C

Explanation:
Section: The process of Auditing Information System


NEW QUESTION # 299
Which of the following provides the BEST evidence of an organization's disaster recovery readiness?

  • A. A disaster recovery plan
  • B. Processes for maintaining the disaster recovery plan
  • C. Customer references for the alternate site provider
  • D. Results of tests and drills

Answer: D

Explanation:
Explanation/Reference:
Explanation:
Plans are important, but mere plans do not provide reasonable assurance unless tested. References for the alternate site provider and the existence and maintenance of a disaster recovery plan are important, but only tests and drills demonstrate the adequacy of the plans and provide reasonable assurance of an organization's disaster recovery readiness.


NEW QUESTION # 300
When evaluating information security governance within an organization, which of the following findings should be of MOST concern to an IS auditor?

  • A. The information security department has difficulty filling vacancies
  • B. An information security governance audit was not conducted within the past year
  • C. Information security policies are updated annually
  • D. The data center manager has final sign-off on security projects

Answer: B

Explanation:
The most concerning finding for an IS auditor when evaluating information security governance within an organization is B. An information security governance audit was not conducted within the past year. According to the ISACA Certified Information System Auditor (CISA) Study Guide, information security governance audits should be conducted annually to ensure that the organization's information security policies and procedures are effective and up to date. Additionally, information security governance audits should assess the organization's risk management processes, control environment, and compliance with relevant laws and regulations. If an information security governance audit has not been conducted in the past year, then the organization may be at higher risk of data breaches and other security incidents.


NEW QUESTION # 301
Which of the following BEST helps to ensure data integrity across system interfaces?

  • A. Environment segregation
  • B. Reconciliations
  • C. Access controls
  • D. System backups

Answer: C


NEW QUESTION # 302
During which phase of the software development life cycle is it BEST to initiate the discussion of application controls?

  • A. Business case development phase when stakeholders are identified
  • B. Application coding phase when algorithms are developed to solve business problems
  • C. Application design phase process functionalities are finalized
  • D. User acceptance testing (UAT) phase when test scenarios are designed

Answer: C

Explanation:
The best time to initiate the discussion of application controls is during the Application Design phase, when the process functionalities are finalized. This is according to the ISACA CISA Study Manual, which states, "Application controls should be discussed during the design phase and implemented in the development of the system." (ISACA CISA Study Manual, 26th Edition, Section 4.2.2, Page 4.27)


NEW QUESTION # 303
An effective implementation of security roles and responsibilities is BEST evidenced across an enterprise when:

  • A. policies are rolled out and disseminated
  • B. reviews and updates of policies are regularly performed
  • C. pokies are signed off by users.
  • D. operational activities are aligned with policies.

Answer: D


NEW QUESTION # 304
How do modems (modulation/demodulation) function to facilitate analog transmissions to enter a digital
network?

  • A. Modems convert analog transmissions to digital, and digital transmission to analog.
  • B. Modems encapsulate digital transmissions within analog, and analog transmissions within digital.
  • C. Modems encapsulate analog transmissions within digital, and digital transmissions within analog.
  • D. Modems convert digital transmissions to analog, and analog transmissions to digital.

Answer: A

Explanation:
Section: Protection of Information Assets
Explanation
Explanation:
Modems (modulation/demodulation) convert analog transmissions to digital, and digital transmissions to
analog, and are required for analog transmissions to enter a digital network.


NEW QUESTION # 305
Which of the following observations should be of GREATEST concern to an IS auditor reviewing a large organization's virtualization environment?

  • A. An unused printer has been left connected to the host system.
  • B. Guest tools have been installed without sufficient access control,
  • C. A rootkit was found on the host operating system
  • D. Host inspection capabilities have been disabled

Answer: B


NEW QUESTION # 306
Which of the following should be the FIRST consideration when deciding whether data should be moved to a cloud provider for storage?

  • A. Data classification
  • B. Data storage costs
  • C. Service level agreements (SLAs)
  • D. Vendor cloud certification

Answer: A

Explanation:
Explanation
Data classification is the first consideration when deciding whether data should be moved to a cloud provider for storage because it determines the level of protection and security required for the data. Data classification also helps to identify the legal and regulatory requirements that apply to the data, such as privacy, retention and disposal policies. Data storage costs, vendor cloud certification and service level agreements (SLAs) are important factors to consider, but they are secondary to data classification. References: CISA Review Manual (Digital Version) 1, Chapter 5, Section 5.3.2


NEW QUESTION # 307
While conducting an audit, an IS auditor detects the presence of a virus. What should be the IS auditor's next step?

  • A. Ensure deletion of the virus.
  • B. Inform appropriate personnel immediately.
  • C. Observe the response mechanism.
  • D. Clear the virus from the network.

Answer: B

Explanation:
The first thing an IS auditor should do after detecting the virus is to alert the organization to its presence, then wait for their response. Choice A should be taken after choice C.
This will enable an IS auditor to examine the actual workability and effectiveness of the response system. An IS auditor should not make changes to the system being audited, and ensuring the deletion of the virus is a management responsibility.


NEW QUESTION # 308
Which of the following is the PRIMARY objective of a business impact analysis (BIA)?

  • A. Define the recovery point objective (RPO).
  • B. Confirm control effectiveness.
  • C. Determine recovery priorities.
  • D. Analyze vulnerabilities.

Answer: C

Explanation:
Section: Protection of Information Assets


NEW QUESTION # 309
Which of the following type of a computer network is a WAN that are limited to a city?

  • A. MAN
  • B. SAN
  • C. LAN
  • D. PAN

Answer: A

Explanation:
Explanation/Reference:
MAN - A metropolitan area network (MAN) is a computer network in which two or more computers or communicating devices or networks which are geographically separated but in same metropolitan city and are connected to each other are said to be connected on MAN. Metropolitan limits are determined by local municipal corporations; the larger the city, the bigger the MAN, the smaller a metro city, smaller the MAN.
For your exam you should know below information about computer networks:
Local Area Network (LAN)
A local area network (LAN) is a computer network that interconnects computers within a limited area such as a home, school, computer laboratory, or office building using network media.
Local Area Network

Wide Area Network
A wide area network (WAN) is a network that covers a broad area (i.e., any telecommunications network that links across metropolitan, regional, national or international boundaries) using leased telecommunication lines.
Wide Area Network

Source of image: http://www.netprivateer.com/images/lanwan.gif
Metropolitan Area Network
A metropolitan area network (MAN) is a computer network in which two or more computers or communicating devices or networks which are geographically separated but in same metropolitan city and are connected to each other are said to be connected on MAN. Metropolitan limits are determined by local municipal corporations; the larger the city, the bigger the MAN, the smaller a metro city, smaller the MAN Metropolitan Area Network

Source of image: http://cis.msjc.edu/courses/images/MAN.jpg
Personal Area Network
A personal area network (PAN) is a computer network used for data transmission among devices such as computers, telephones and personal digital assistants. PANs can be used for communication among the personal devices themselves (intrapersonal communication), or for connecting to a higher level network and the Internet (an uplink).
Personal Area Network

Click HERE for original image
Storage Area Network
A storage area network (SAN) is a dedicated network that provides access to consolidated, block level data storage. SANs are primarily used to enhance storage devices, such as disk arrays, tape libraries, and optical jukeboxes, accessible to servers so that the devices appear like locally attached devices to the operating system. A SAN typically has its own network of storage devices that are generally not accessible through the local area network (LAN) by other devices.
Storage Area Network

Source of image: http://www.imexresearch.com/images/sasnassan-3.gif
The following were incorrect answers:
PAN - A personal area network (PAN) is a computer network used for data transmission among devices such as computers, telephones and personal digital assistants. PANs can be used for communication among the personal devices themselves (intrapersonal communication), or for connecting to a higher level network and the Internet (an uplink).
LAN - A local area network (LAN) is a computer network that interconnects computers within a limited area such as a home, school, computer laboratory, or office building using network media.
SAN - A storage area network (SAN) is a dedicated network that provides access to consolidated, block level data storage. SANs are primarily used to enhance storage devices, such as disk arrays, tape libraries, and optical jukeboxes, accessible to servers so that the devices appear like locally attached devices to the operating system. A SAN typically has its own network of storage devices that are generally not accessible through the local area network (LAN) by other devices.
The following reference(s) were/was used to create this question:
CISA review manual 2014 Page number 258


NEW QUESTION # 310
An IS auditor is performing a follow-up audit for findings identified in an organization's user provisioning process Which of the following is the MOST appropriate population to sample from when testing for remediation?

  • A. All users provisioned after the final audit report was issued
  • B. All users provisioned after the finding was originally identified
  • C. All users who have followed user provisioning processes provided by management
  • D. All users provisioned after management resolved the audit issue

Answer: A


NEW QUESTION # 311
An organization was severely impacted alter an advanced persistent threat (APT) attack Afterwards it was found that the initial breach happened a month prior to the attack. Management's GREATEST concern should be

  • A. the installation of critical security patches
  • B. the effectiveness of monitoring processes
  • C. external firewall policies.
  • D. results of the past internal penetration test

Answer: B


NEW QUESTION # 312
Function Point Analysis (FPA) provides an estimate of the size of an information system based only on the number and complexity of a system's inputs and outputs. True or false?

  • A. False
  • B. True

Answer: A

Explanation:
Section: Protection of Information Assets
Explanation:
Function point analysis (FPA) provides an estimate of the size of an information system based on the number and complexity of a system's inputs, outputs, and files.


NEW QUESTION # 313
Which of the following BEST minimizes performance degradation of serve's used to authenticate users of an e-commerce website?

  • A. Configure each authentication server as belonging to a cluster of authentication servers
  • B. Configure each authentication server and ensure that each disk of its RAID is attached to the primary controller.
  • C. Configure a single server as a primary authentication server and a second server as a secondary authentication server
  • D. Configure each authentication server and ensure that the disks of each server form part of a duplex

Answer: A


NEW QUESTION # 314
An IS auditor wants to determine who has oversight of staff performing a specific task and is referencing the organization's RACI chart. Which of the following roles within the chart would provide this information?

  • A. Responsible
  • B. informed
  • C. Consulted
  • D. Accountable

Answer: D

Explanation:
Section: The process of Auditing Information System


NEW QUESTION # 315
......


Information Systems Acquisition, Development, & Implementation: This subject will measure the candidates’ skills in the following subtopics:

  • Information systems implementation – testing methodologies; system migration, data conversion, and infrastructure deployment; post-implementation review.
  • Information system acquisition and development – project management and governance; control identification & design; system development methodologies; business case & feasibility analysis;

ISACA CISA (Certified Information Systems Auditor) exam is an internationally recognized certification that is designed for IT professionals who want to specialize in information systems auditing, control, and security. Certified Information Systems Auditor certification is awarded by the Information Systems Audit and Control Association (ISACA), which is a globally recognized professional association for IT governance, security, and auditing.


The CISA certification exam is a comprehensive, four-hour test consisting of 150 multiple-choice questions that test candidates' knowledge in five domains of information systems auditing: 1) The process of auditing information systems, 2) Governance and management of IT, 3) Information systems acquisition, development and implementation, 4) Information systems operations, maintenance and support, and 5) Protection of information assets. Candidates must score at least 450 out of a possible 800 points to pass the exam and earn the CISA certification.

 

Read Online CISA Test Practice Test Questions Exam Dumps: https://www.getvalidtest.com/CISA-exam.html

Easily To Pass New CISA Premium Exam: https://drive.google.com/open?id=1YnjeFkZIHCv2uj_y0wMaDQ2D6TkgwcqC