Free ISACA CISA Exam Braindumps (page: 53)

An organization recently decided to send the backup of its customer relationship management (CRM) system to its cloud provider for recovery. Which of the following should be of GREATEST concern to an IS auditor reviewing this process?

  1. Testing of restore data has not been performed.
  2. Validation of backup data has not been performed.
  3. Backups are sent and stored in unencrypted format.
  4. The cloud provider is located in a different country.

Answer(s): C



A checksum is classified as which type of control?

  1. Preventive control
  2. Detective control
  3. Administrative control
  4. Corrective control

Answer(s): B



During a follow-up audit, an IS auditor finds that some critical recommendations have not been addressed as management has decided to accept the risk. Which of the following is the IS auditor's BEST course of action?

  1. Adjust the annual risk assessment accordingly.
  2. Require the auditee to address the recommendations in full.
  3. Evaluate senior management's acceptance of the risk.
  4. Update the audit program based on management's acceptance of risk.

Answer(s): C



Management has asked internal audit to prioritize and perform a specialized cybersecurity audit, but the IS audit team has no experience in this area. Which of the following is the BEST course of action?

  1. Delay the audit until the IS auditors are sufficiently trained.
  2. Delay the audit until an experienced IS auditor has been hired.
  3. Perform the audit as requested using third-party support.
  4. Perform the audit with the most experienced IS auditors.

Answer(s): C



Viewing page 53 of 457
Viewing questions 209 - 212 out of 1823 questions



Post your Comments and Discuss ISACA CISA exam prep with other Community members:

CISA Exam Discussions & Posts