ISACA CISA Exam Questions
Certified Information Systems Auditor (Page 19 )

Updated On: 24-Feb-2026

During an audit of a reciprocal disaster recovery agreement between two companies, the IS auditor would be MOST concerned with the:

  1. allocation of resources during an emergency.
  2. maintenance of hardware and software compatibility.
  3. differences in IS policies and procedures.
  4. frequency of system testing.

Answer(s): B



Which of the following BEST indicates the effectiveness of an organization's risk management program?

  1. Residual risk is minimized.
  2. Inherent risk is eliminated.
  3. Control risk is minimized.
  4. Overall risk is quantified.

Answer(s): A



Providing security certification for a new system should include which of the following prior to the system's implementation?

  1. End-user authorization to use the system in production
  2. Testing of the system within the production environment
  3. An evaluation of the configuration management practices
  4. External audit sign-off on financial controls

Answer(s): C



Which of the following should be the FIRST step when developing a data loss prevention (DLP) solution for a large organization?

  1. Create the DLP policies and templates.
  2. Conduct a threat analysis against sensitive data usage.
  3. Conduct a data inventory and classification exercise.
  4. Identify approved data workflows across the enterprise.

Answer(s): C



Which of the following activities would allow an IS auditor to maintain independence while facilitating a control self-assessment (CSA)?

  1. Implementing the remediation plan
  2. Developing the remediation plan
  3. Developing the CSA questionnaire
  4. Partially completing the CSA

Answer(s): C






Post your Comments and Discuss ISACA CISA exam dumps with other Community members:

Join the CISA Discussion