ISACA CISA Exam Questions
Certified Information Systems Auditor (Page 67 )

Updated On: 28-Feb-2026

While reviewing an organization's business continuity plan (BCP), an IS auditor observes that a recently developed application is not included. The IS auditor should:

  1. ensure that the criticality of the application is determined.
  2. include in the audit findings that the BCP is incomplete.
  3. recommend that the application be incorporated in the BCP.
  4. ignore the observation as the application is not mission critical.

Answer(s): A



Data anonymization helps to prevent which types of attacks in a big data environment?

  1. Man-in-the-middle
  2. Denial of service (DoS)
  3. Correlation
  4. Spoofing

Answer(s): C



During a review of a production schedule, an IS auditor observes that a staff member is not complying with mandatory operational procedures. The auditor's NEXT step should be to:

  1. note the noncompliance in the audit working papers.
  2. determine why the procedures were not followed.
  3. issue an audit memorandum identifying the noncompliance.
  4. include the noncompliance in the audit report.

Answer(s): B



The PRIMARY objective of IT service level management is to:

  1. improve IT cost control.
  2. manage computer operations activities.
  3. satisfy customer requirements.
  4. increase awareness of IT services.

Answer(s): C



The use of which of the following would BEST enhance a process improvement program?

  1. Balanced scorecard
  2. Project management methodologies
  3. Capability maturity models
  4. Model-based design notations

Answer(s): C



Viewing page 67 of 366
Viewing questions 331 - 335 out of 1823 questions



Post your Comments and Discuss ISACA CISA exam dumps with other Community members:

CISA Exam Discussions & Posts

AI Tutor