ISACA CISA Exam Questions
Certified Information Systems Auditor (Page 8 )

Updated On: 21-Feb-2026

An IS auditor is reviewing processes for importing market price data from external data providers. Which of the following findings should the auditor consider
MOST critical?

  1. The quality of the data is not monitored.
  2. The transfer protocol does not require authentication.
  3. Imported data is not disposed frequently.
  4. The transfer protocol is not encrypted.

Answer(s): A



In a controlled application development environment, the MOST important segregation of duties should be between the person who implements changes into the production environment and the:

  1. application programmer.
  2. quality assurance (QA) personnel.
  3. computer operator.
  4. systems programmer.

Answer(s): A



A small startup organization does not have the resources to implement segregation of duties. Which of the following is the MOST effective compensating control?

  1. Rotation of log monitoring and analysis responsibilities
  2. Additional management reviews and reconciliations
  3. Mandatory vacations
  4. Third-party assessments

Answer(s): B



When planning an audit to assess application controls of a cloud-based system, it is MOST important for the IS auditor to understand the:

  1. availability reports associated with the cloud-based system.
  2. architecture and cloud environment of the system.
  3. policies and procedures of the business area being audited.
  4. business process supported by the system.

Answer(s): B



Which of the following data would be used when performing a business impact analysis (BIA)?

  1. Projected impact of current business on future business
  2. Expected costs for recovering the business
  3. Cost of regulatory compliance
  4. Cost-benefit analysis of running the current business

Answer(s): B






Post your Comments and Discuss ISACA CISA exam dumps with other Community members:

Join the CISA Discussion