SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CISA: Certified Information Systems Auditor
Start Test
Study First
Subjects
:
certifications
,
cisa
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. An IS auditor has discovered a high-risk exception during control testing. The best course of action for the IS auditor to take - The IS auditor should immediately ________________ when any high-risk situation is discovered.
Compliance Testing
A Forensic Audit
Sampling Risk
Inform the auditee
2. (1.) Access Control (2.) Change Management (3.) Security Controls (4.) Incident Management (5.) SDLC (6.) Source code and versioning controls (7.) Monitoring and logging (8.) Event Management
Power system controls
Main types of Controls
Examples of IT General Controls
Business Continuity
3. Delivery of packets from one station to another - on the same network or on different networks.
Function Point Analysis
The Internet Layer in the TCP/IP model
Deming Cycle
Compliance Testing
4. A tightly coupled collection of computers that are used to solve a common task. One or more actively perform tasks - while zero or more may be in a standby state.
Sampling Risk
Blade Computer Architecture
A Server Cluster
Examples of IT General Controls
5. An active - instance of a server operating system running on a machine that is designed to house two or more such virtual servers.
A Problem
Hash
Project Management Strategies
A Virtual Server
6. An auditor has reviewed access privileges of some employees and has discovered that employees with longer terms of service have excessive privileges. This means User privileges are not being removed from their old position when they transfer to a new
The best approach for identifying high risk areas for an audit
Employees with excessive privileges
The Requirements
Network Layer Protocols
7. A large number of loosely coupled computers that are used to solve a common task may be in close proximity to each other or scattered over a large geographical area.
Options for Risk Treatment
Balanced Scorecard
Grid Computing
Formal waterfall
8. PERT: shows the ______________ critical path.
Attribute Sampling
A Financial Audit
Current and most up-to-date
Detection Risk
9. Contains programs that communicate directly with the end user.
TCP/IP Transport Layer packet delivery
OSI Layer 7: Application
Information security policy
An Administrative
10. The 5 types of risks that are related to audits include: (1.) Control Risk (2.) Detection Risk (3.) Inherent risk (4.) _____________ (5.) Sampling risk
A Service Provider audit
Precision means
The Requirements
Overall audit risk
11. A dynamically scalable and usually virtualized computing environment that is provided as a service. Clout computing services may be rented or leased so that an organization can have a scalable application without the need for supporting hardware.
Substantive Testing (test of transaction integrity)
OSI: Physical Layer
Cloud computing
Statement of Impact
12. To communication security policies - procedures - and other security-related information to an organization's employees.
Incident Management
The two Categories of Controls
Security Awareness program
The BCP process
13. A field in a record in one table that can reference a primary key in another table that can reference a primary key in another table.
Prblem Management
Split custody
Foreign Key
IT executives and the Board of Directors
14. Collections of Controls that work together to achieve an entire range of an organization's objectives.
A Sample Mean
Advantages of outsourcing
Background checks performed
Frameworks
15. IS auditors can _____________________ through the following means: (1.) training courses (2.) webinars (3.) ISACA chapter training events (4.) Industry conferences
Critical Path Methodology
Stay current with technology
Business Continuity
An Integrated Audit
16. A database administrator has been asked to configure a database management system so that it records all changes made by users - The DBA should implement ___________. This will cause the database to record every change that is made to it.
Audit logging
The Business Process Life Cycle
Release management
The first step in a business impact analysis
17. What type of testing is performed to verify the accuracy and integrity of transactions as they flow through a system?
Substantive Testing
ITIL definition of PROBLEM
Project Management Strategies
Geographic location
18. The process to ensure that standardized methods and procedures are used for efficient and prompt handling of all changes.
(1.) Polices (2.) Procedures (3.) Standards
Vulnerability in the organization's PBX
Precision means
ITIL definition of CHANGE MANAGEMENT
19. n audit strategy and plans that include: (1.) Scope (2.) Objectives (3.) Resources (4.) Procedures used to evaluation controls and processes
Statistical Sampling
The Eight Types of Audits
The audit program
TCP/IP Network Model
20. Guide program execution through organization of resources and development of clear project objectives.
Project Management Strategies
IT Services Financial Management
Rating Scale for Process Maturity
A Financial Audit
21. (1.) Reliable delivery (2.) Connection oriented (persistent connection) (3.) Order of Delivery (4.) Flow Control (transfer rate is throttled) (5.) Port Number
TCP/IP Transport Layer packet delivery
Stratified Sampling
Department Charters
IT standards are not being reviewed often enough
22. In Release Management - _________________ means that each step of the release process undergoes formal review and approval before the next step is allowed to begin.
A gate process
The 4-item focus of a Balanced Scorecard
Segregation of duties issue in a high value process
Personnel involved in the requirements phase of a software development project
23. (1.) Physical (2.) Technical (4.) Administrative
List of systems examined
Confidence coefficient
Audit Methodologies
Three Types of Controls
24. (1.) Access controls (2.) Encryption (3.) Audit logging
Change management
Detection Risk
Critical Path Methodology
Primary security features of relational databases
25. Gantt: used to display ______________.
Resource details
Cloud computing
Segregation of duties issue in a high value process
Audit Methodologies
26. During the development phase - Developers should only be performing Unit Testing - to verify that the individual sections of code they have written are performing properly.
Vulnerability in the organization's PBX
TCP/IP Internet Layer
Testing activities
The availability of IT systems
27. The IS auditor should act as a SME in the control self-assessment - but should not play a major role in the process.
The appropriate role of an IS auditor in a control self-assessment
An Operational Audit
Personnel involved in the requirements phase of a software development project
Sampling Risk
28. The risk that there are material weaknesses in existing business processes and no compensating controls to detect or prevent them
The Software Program Library
Insourcing
Inherent Risk
Audit logging
29. (1.) Objectives (2.) Components (3.) Business Units / Areas
Attribute Sampling
Dimensions of the COSO cube
More difficult to perform
Business Realization
30. A condition that is the result of multiple incidents that exhibit common symptoms e.g. A web application is displaying information incorrectly and many users have contacted the IT service desk.
An IS audit
A Problem
Deming Cycle
Capability Maturity Model Integration (CMMI)
31. To determine effectiveness of a disaster recovery program - an IT auditor should examine _____________.
Categories of risk treatment
Statistical Sampling
Detection Risk
Documentation and interview personnel
32. An organization has chosen to open a business office in another country where labor costs are lower and has hired workers to perform business functions there. - The organization is ___________ - while they may have opened the office in a foreign coun
Application Controls
Foreign Key
Insourcing
Lacks specific expertise or resources to conduct an internal audit
33. An organization is building a data center in an area frequented by power outages. The organization cannot tolerate power outages. The best _________________solution is an electric generator and an uninterruptible power supply. The UPS responds to the
Prblem Management
A Problem
Power system controls
ITIL - IT Infrastructure Library
34. Lowest layer. Delivers messages (frames) from one station to another vial local network.
Tolerable Error Rate
Six steps of the Release Management process
Control Unit
TCP/IP Link Layer
35. ITIL term used to describe the SDLC.
Release management
PERT Diagram?
Current and most up-to-date
Grid Computing
36. Use of a set of monitoring and review activities that confirm whether IS operations is providing service to its customers.
Overall audit risk
Prblem Management
To identify the tasks that are responsible for project delays
Service Level Management
37. Change Management includes a _____________ of six steps: (1.) Proposal or Request (2.) Review (3.) Approval (4.) Implementation (5.) Verification (6.) Post-change Review
Formal waterfall
The best approach for identifying high risk areas for an audit
Types of sampling an auditor can perform.
Advantages of outsourcing
38. Focuses on: maintaining service availability with the least disruption to standard operating parameters during an event
Application Controls
Business Continuity
Concentrate on samples known to represent high risk
A gate process
39. Defines internal controls and provides guidance for assessing and improving internal control systems.
Sample Standard Deviation
The two Categories of Controls
COSO (Committee of Sponsoring Organizations of the Treadway Commission)
TCP/IP Link Layer
40. A sampling technique used to study the characteristics of a population to determine how many samples possess a specific characteristic.
Structural fires and transportation accidents
Personnel involved in the requirements phase of a software development project
(1.) Polices (2.) Procedures (3.) Standards
Attribute Sampling
41. The set of activities that is concerned with the ability of the organization to continue to provide services - primarily in the event that a natural or man made disaster has occurred.
Service Continuity Management
Hash
An IS audit
List of systems examined
42. Aids in the coordinating of business processes using a sequence of three events -(1.) Business process creation (2.) Implementation (3.) Maintenance 3a. Benchmarking: Facilitates continuous improvement within the BPLC
SDLC Phases
Judgmental sampling
An IS audit
The Business Process Life Cycle
43. (1.) Avoidance (2.) Transfer (3.) Mitigation (4.) Acceptance
Annualized Loss Expectance (ALE)
Prblem Management
Service Continuity Management
Categories of risk treatment
44. The probability that a sample selected does not represent the entire population. This is usually expressed as a percentage - as the numeric inverse of the confidence coefficient.
OSI Layer 7: Application
Wet pipe fire sprinkler system
Expected Error Rate
Sampling Risk
45. One of a database table's fields - whose value is unique.
Assess the maturity of its business processes
Database primary key
A Sample Mean
Geographic location
46. An IS auditor is auditing the change management process for a financial application. The auditor has two primary pieces of evidence: change logs and a written analysis of the change logs performed by a business analyst. The change log is best because
Business impact analysis
The two Categories of Controls
objective and unbiased
Precision means
47. An auditor has discovered several errors in user account management: many terminated employees' computer accounts are still active. The best course of action - To improve the _________________ to reduce the number of exceptions. For a time - the proc
Employee termination process
A Sample Mean
A Server Cluster
TCP/IP Internet Layer
48. What three elements allow validation of business practices against acceptable measures of regulatory compliance - performance - and standard operational guidelines.
An IS audit
(1.) Polices (2.) Procedures (3.) Standards
Hash
The first step in a business impact analysis
49. The primary source for test plans in a software development project is: ________________ that are developed for a project should be the primary source for detailed tests.
ISO 20000 Standard:
The Requirements
General Controls
The best approach for identifying high risk areas for an audit
50. A maturity model that represents the aggregations of other maturity models.
Balanced Scorecard
Capability Maturity Model Integration (CMMI)
Buffers
PERT Diagram?