ISACA CISA Exam Questions
Certified Information Systems Auditor (Page 49 )

Updated On: 28-Feb-2026

The performance, risks, and capabilities of an IT infrastructure are BEST measured using a:

  1. risk management review.
  2. control self-assessment (CSA).
  3. service level agreement (SLA).
  4. balanced scorecard.

Answer(s): D



To develop meaningful recommendations for findings, which of the following is MOST important for an IS auditor to determine and understand?

  1. Criteria
  2. Responsible party
  3. Impact
  4. Root cause

Answer(s): D



An organization allows employees to use personally owned mobile devices to access customers' personal information. Which of the following is MOST important for an IS auditor to verify?

  1. Employees have signed off on an acceptable use policy.
  2. Devices have adequate storage and backup capabilities.
  3. Mobile devices are compatible with company infrastructure.
  4. Mobile device security policies have been implemented.

Answer(s): D



When is the BEST time to commence continuity planning for a new application system?

  1. Immediately after implementation
  2. Following successful user testing
  3. During the design phase
  4. Just prior to the handover to the system maintenance group

Answer(s): C



Prior to the migration of acquired software into production, it is MOST important that the IS auditor review the:

  1. user acceptance test (UAT) report.
  2. vendor testing report.
  3. system documentation.
  4. source code escrow agreement.

Answer(s): A






Post your Comments and Discuss ISACA CISA exam dumps with other Community members:

Join the CISA Discussion