SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CISA: Certified Information Systems Auditor
Start Test
Study First
Subjects
:
certifications
,
cisa
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Any event which is not part of the standard operation of service and which causes or may cause an interruption to or reduction in quality of that service. Includes THREE incident types: (1.) Service Outage (2.) Service Slowdown (3.) Software Bug
Incident Management
Release management
Three Types of Controls
COSO (Committee of Sponsoring Organizations of the Treadway Commission)
2. Disasters are generally grouped in terms of type: ______________.
OSI: Data Link Layer
(1.) Man-made (2.) Natural
Critical Path Methodology
Segregation of duties issue in a high value process
3. PERT: shows the ______________ critical path.
Deming Cycle
Advantages of outsourcing
Current and most up-to-date
Service Continuity Management
4. A sampling technique used to study the characteristics of a population to determine how many samples possess a specific characteristic.
Blade Computer Architecture
Attribute Sampling
TCP/IP Link Layer
A Sample Mean
5. (1.) Authentication (2.) Authorization (3.) Change Management (4.) Completeness checks (5.) Validation checks (6.) Input controls (7.) Output controls (8.) Problem management (9.) Identification/access controls
Statement of Impact
Geographic location
Attribute Sampling
Examples of Application Controls
6. The risk that an IS auditor will overlook errors or exceptions during an audit.
Detection Risk
A gate process
Volumes of COSO framework
OSI Layer 5: Session
7. n audit strategy and plans that include: (1.) Scope (2.) Objectives (3.) Resources (4.) Procedures used to evaluation controls and processes
The audit program
IT Strategy
Criticality analysis
Foreign Key
8. An audit of IS controls - security controls - or business controls to determine control existence and effectiveness.
Rating Scale for Process Maturity
Control Risk
CPU
An Operational Audit
9. The party that performs strategic planning - addresses near-term and long-term requirements aligning business objectives - and technology strategies.
The Steering Committee
A Financial Audit
Emergency Changes
Main types of Controls
10. IS auditors can _____________________ through the following means: (1.) training courses (2.) webinars (3.) ISACA chapter training events (4.) Industry conferences
Stay current with technology
An Integrated Audit
(1.) Man-made (2.) Natural
Wet pipe fire sprinkler system
11. What type of testing is performed to determine if control procedures have proper design and are operating properly?
Prblem Management
ITIL definition of PROBLEM
Compliance Testing
Critical Path Methodology
12. What three elements allow validation of business practices against acceptable measures of regulatory compliance - performance - and standard operational guidelines.
Main types of Controls
A Financial Audit
Examples of Application Controls
(1.) Polices (2.) Procedures (3.) Standards
13. Who is responsible for imposing an IT governance model encompassing IT strategy - information security - and formal enterprise architectural mandates?
Hash
IT executives and the Board of Directors
List of systems examined
Buffers
14. The probability that a sample selected actually represents the entire population. This is usually expressed as a percentage.
The audit program
Confidence coefficient
Background checks performed
Personnel involved in the requirements phase of a software development project
15. Consists of two main packet transport protocols: TCP and UDP.
Grid Computing
OSI: Data Link Layer
Sample Standard Deviation
TCP/IP Transport Layer
16. Used to estimate the effort required to develop a software program.
A Virtual Server
Categories of risk treatment
Function Point Analysis
Information systems access
17. The set of activities that is concerned with the ability of the organization to continue to provide services - primarily in the event that a natural or man made disaster has occurred.
(1.) Polices (2.) Procedures (3.) Standards
Service Continuity Management
Security Awareness program
The 5 types of Evidence that the auditor will collect during an audit.
18. An IS auditor needs to perform an audit of a financial system and needs to trace individual transactions through the system. What type of testing should the auditor perform?
ITIL definition of CHANGE MANAGEMENT
TCP/IP Transport Layer packet delivery
Substantive Testing (test of transaction integrity)
Testing activities
19. An organization is building a data center in an area frequented by power outages. The organization cannot tolerate power outages. The best _________________solution is an electric generator and an uninterruptible power supply. The UPS responds to the
COSO (Committee of Sponsoring Organizations of the Treadway Commission)
Power system controls
Split custody
Control Risk
20. One of a database table's fields - whose value is unique.
A Service Provider audit
Database primary key
Sampling Risk
Examples of IT General Controls
21. The IS auditor should conduct a risk assessment first to determine which areas have highest risk. She should devote more testing resources to those high-risk areas.
BCP Plans
The best approach for identifying high risk areas for an audit
Assess the maturity of its business processes
Volumes of COSO framework
22. (1.) Physical (2.) Technical (4.) Administrative
OSI Layer 6: Presentation
Rating Scale for Process Maturity
CPU
Three Types of Controls
23. (1.) Objectives (2.) Components (3.) Business Units / Areas
Dimensions of the COSO cube
Business Realization
Transport Layer Protocols
Elements of the COSO pyramid
24. Collections of Controls that work together to achieve an entire range of an organization's objectives.
Six steps of the Release Management process
OSI Layer 7: Application
Insourcing
Frameworks
25. Guide program execution through organization of resources and development of clear project objectives.
Project Management Strategies
Insourcing
The audit program
A Financial Audit
26. What activity involves the identification of potential risk and the appropriate response for each threat based on impact assessment using qualitative and/or quantitative measures for an enterprise-wide risk management strategy?
Risk Management
Balanced Scorecard
The 5 types of Evidence that the auditor will collect during an audit.
The 7 phases and their order in the SDLC
27. Used to translate or transform data from lower layers into formats that the application layer can work with.
OSI Layer 6: Presentation
Discovery Sampling
A Sample Mean
An Integrated Audit
28. An audit to determine the level and degree of compliance to a law - regulation - standard - contract provision - or internal control.
A Compliance audit
Inherent Risk
Insourcing
Main types of Controls
29. An IS auditor has discovered a high-risk exception during control testing. The best course of action for the IS auditor to take - The IS auditor should immediately ________________ when any high-risk situation is discovered.
Separate administrative accounts
Change management
Inform the auditee
Function Point Analysis
30. Used to measure the relative maturity of an organization and its processes.
Overall audit risk
Options for Risk Treatment
Capability Maturity Model
Testing activities
31. Critical Path Methodology helps a project manager determine which activities are on a project's critical list - ________________________.
ITIL - IT Infrastructure Library
Audit logging
An IS audit
To identify the tasks that are responsible for project delays
32. Should include 4 steps: (1.) Emergency Approval (2.) Implementation (3.) Verification (4.) Review
Segregation of duties issue in a high value process
Split custody
Emergency Changes
Six steps of the Release Management process
33. (1.) Developers (2.) Architects (3.) Analysts (4.) Users
Antivirus software on the email servers
Risk Management
More difficult to perform
Personnel involved in the requirements phase of a software development project
34. An IS auditor is examining the IT standards document for an organization that was last reviewed two years earlier. The best course of action for the IS auditor is: Report that the ____________________________. Two years is far too long between revie
The two Categories of Controls
The Requirements
List of systems examined
IT standards are not being reviewed often enough
35. Change Management includes a _____________ of six steps: (1.) Proposal or Request (2.) Review (3.) Approval (4.) Implementation (5.) Verification (6.) Post-change Review
Tolerable Error Rate
Formal waterfall
A Compliance audit
IT standards are not being reviewed often enough
36. A sampling technique where a population is divided into classes or strata - based upon the value of one of the attributes. Samples are then selected from each class.
IT Strategy
Main types of Controls
Stratified Sampling
Hash
37. An active - instance of a server operating system running on a machine that is designed to house two or more such virtual servers.
Data Link Layer Standards
IT Strategy
A Virtual Server
Volumes of COSO framework
38. A condition often identified as a result of multiple incidents that exhibit common symptoms. Problems can also be identified from a single significant incident for which the impact is significant.
ITIL definition of PROBLEM
Judgmental sampling
Buffers
The Software Program Library
39. Concerned with electrical and physical specifications for devices. No frames or packets involved.
Stay current with technology
A Problem
OSI: Physical Layer
Elements of the COBIT Framework
40. An organization has discovered that some of its employees have criminal records. The best course of action for the organization to take - The organization should have ___________________ on all of its existing employees and also begin instituting bac
Background checks performed
Options for Risk Treatment
Types of sampling an auditor can perform.
Configuration Management
41. (1.) MPLS (2.) SONET (3.) T-Carrier (4.) Frame Relay (5.) ISDN (6.) X.25
TCP/IP Transport Layer packet delivery
WAN Protocols
The audit program
objective and unbiased
42. The probability that a sample selected does not represent the entire population. This is usually expressed as a percentage - the numeric inverse of the confidence coefficient
Three Types of Controls
Capability Maturity Model Integration (CMMI)
Sampling Risk
Structural fires and transportation accidents
43. An audit of an IS department's operations and systems.
(1.) Man-made (2.) Natural
An IS audit
COSO (Committee of Sponsoring Organizations of the Treadway Commission)
To identify the tasks that are responsible for project delays
44. A field in a record in one table that can reference a primary key in another table that can reference a primary key in another table.
Foreign Key
Compliance Testing
Project change request
Geographic location
45. Used for several types of system changes: (1.) Incidents and problem resolution (bug fixes.) (2.) Enhancements (new functionality.) (3.) Subsystem patches and changes (require testing similar to when changes are made to the application itself.)
A Sample Mean
Inform the auditee
IT Service Management
The Release process
46. An audit that is performed in support of an anticipated or active legal proceeding.
Documentation and interview personnel
A Forensic Audit
Project Management Strategies
Balanced Scorecard
47. An audit of a third-party organization that provides services to other organizations.
Organizational culture and maturity
IT Services Financial Management
A Service Provider audit
A Server Cluster
48. Risk Mitigation Risk Avoidance Risk Transfer Risk Acceptance
Split custody
Discovery Sampling
Options for Risk Treatment
A gate process
49. Defines internal controls and provides guidance for assessing and improving internal control systems.
Inform the auditee
Testing activities
COSO (Committee of Sponsoring Organizations of the Treadway Commission)
Statistical Sampling
50. In Release Management - _________________ means that each step of the release process undergoes formal review and approval before the next step is allowed to begin.
Gantt Chart
A gate process
ISO 20000 Standard:
The 5 types of Evidence that the auditor will collect during an audit.