Free CISA Exam Braindumps (page: 17)

Page 16 of 457

Which of the following is the BEST performance indicator for the effectiveness of an incident management program?

  1. Incident alert meantime
  2. Number of incidents reported
  3. Average time between incidents
  4. Incident resolution meantime

Answer(s): D



Backups will MOST effectively minimize a disruptive incident's impact on a business if they are:

  1. taken according to recovery point objectives (RPOs).
  2. scheduled according to the service delivery objectives.
  3. performed by automated backup software on a fixed schedule.
  4. stored on write-once read-many media.

Answer(s): A



An IS audit reveals that an organization is not proactively addressing known vulnerabilities. Which of the following should the IS auditor recommend the organization do FIRST?

  1. Ensure the intrusion prevention system (IPS) is effective.
  2. Verify the disaster recovery plan (DRP) has been tested.
  3. Assess the security risks to the business.
  4. Confirm the incident response team understands the issue.

Answer(s): C



An IS auditor has completed the fieldwork phase of a network security review and is preparing the initial draft of the audit report. Which of the following findings should be ranked as the HIGHEST risk?

  1. Network penetration tests are not performed.
  2. The network firewall policy has not been approved by the information security officer.
  3. Network firewall rules have not been documented.
  4. The network device inventory is incomplete.

Answer(s): D






Post your Comments and Discuss ISACA CISA exam with other Community members:

CISA Exam Discussions & Posts