Free ISACA CISA Exam Braindumps (page: 80)

Due to a high volume of customer orders, an organization plans to implement a new application for customers to use for online ordering. Which type of testing is
MOST important to ensure the security of the application prior to go-live?

  1. Stress testing
  2. User acceptance testing (UAT)
  3. Vulnerability testing
  4. Regression testing

Answer(s): C



During an audit of identity and access management, an IS auditor finds that the engagement audit plan does not include the testing of controls that regulate access by third parties. Which of the following would be the auditor's BEST course of action?

  1. Add testing of third-party access controls to the scope of the audit.
  2. Plan to test these controls in another audit.
  3. Determine whether the risk has been identified in the planning documents.
  4. Escalate the deficiency to audit management.

Answer(s): C



What is the PRIMARY reason for conducting a risk assessment when developing an annual IS audit plan?

  1. Identify and prioritize audit areas
  2. Determine the existence of controls in audit areas
  3. Provide assurance material items will be covered
  4. Decide which audit procedures and techniques to use

Answer(s): A



An employee transfers from an organization's risk management department to become the lead IS auditor. While in the risk management department, the employee helped develop the key performance indicators (KPIs) now used by the organization. Which of the following would pose the GREATEST threat to the independence of this auditor?

  1. Evaluating the effectiveness of IT risk management processes
  2. Recommending controls to address the IT risks identified by KPIs
  3. Developing KPIs to measure the internal audit team
  4. Training the IT audit team on IT risk management processes

Answer(s): B



Viewing page 80 of 457
Viewing questions 317 - 320 out of 1823 questions



Post your Comments and Discuss ISACA CISA exam prep with other Community members:

CISA Exam Discussions & Posts