Free ISACA CISA Exam Braindumps (page: 72)

Following the sale of a business division, employees will be transferred to a new organization, but they will retain access to IT equipment from the previous employer. An IS auditor has recommended that both organizations agree to and document an acceptable use policy for the equipment. What type of control has been recommended?

  1. Corrective control
  2. Preventive control
  3. Detective control
  4. Directive control

Answer(s): D



What is the BEST way for an IS auditor to assess the adequacy of an expert consultant who was selected to be involved in an audit engagement?

  1. Obtain an understanding of the expert's relevant experience.
  2. Verify that the engagement letter outlines the expert's responsibilities.
  3. Review the independence and objectivity of the expert.
  4. Review the industry reputation of the expert consultant's firm.

Answer(s): C



In a small IT web development company where developers must have write access to production, the BEST recommendation of an IS auditor would be to:

  1. perform a user access review for the development team.
  2. hire another person to perform migration to production.
  3. implement continuous monitoring controls.
  4. remove production access from the developers.

Answer(s): C



Of the following, who are the MOST appropriate staff for ensuring the alignment of user authorization tables with approved authorization forms?

  1. Security administrators
  2. System owners
  3. Database administrators (DBAs)
  4. IT managers

Answer(s): B



Viewing page 72 of 457
Viewing questions 285 - 288 out of 1823 questions



Post your Comments and Discuss ISACA CISA exam prep with other Community members:

CISA Exam Discussions & Posts