SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CISA: Certified Information Systems Auditor
Start Test
Study First
Subjects
:
certifications
,
cisa
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. (1.) Link (2.) Internet (3.) Transport (4.) Application
COSO (Committee of Sponsoring Organizations of the Treadway Commission)
Information security policy
IT executives and the Board of Directors
TCP/IP Network Model
2. (1.) Financial (2.) Customer (3.) Internal processes (4.) Innovation / Learning
A Sample Mean
The 4-item focus of a Balanced Scorecard
The availability of IT systems
Overall audit risk
3. A representation of how closely a sample represents an entire population.
Tolerable Error Rate
Stop-or-go Sampling
Service Continuity Management
Precision means
4. An audit of IS controls - security controls - or business controls to determine control existence and effectiveness.
IT Strategy
CPU
An Operational Audit
Information systems access
5. (1.) LAN protocols (2.) 80 (2.) 11 MAC/LLC (WiFi) (3.) Common Carrier packet networks (4.) ARP (5.) PPP and SLIP (6.) Tunneling - PPTP - L2TP
Wet pipe fire sprinkler system
Data Link Layer Standards
List of systems examined
less than 24 hours
6. PERT: shows the ______________ critical path.
A Sample Mean
Inherent Risk
Current and most up-to-date
Advantages of outsourcing
7. A computer uses RAM for several purposes: (1.) Operating System - to store info regarding running processes (2.) ____________ - that are used to temporarily store information retrieved from hard disks (3.) Storage of program code (4.) Storage of prog
Buffers
Service Level Management
An Integrated Audit
Risk Management
8. Contains programs that communicate directly with the end user.
Information systems access
Discovery Sampling
Attribute Sampling
OSI Layer 7: Application
9. Focuses on: post-event recovery and restoration of services
Options for Risk Treatment
Disaster Recovery
CPU
Risk Management
10. One of a database table's fields - whose value is unique.
The Requirements
A Sample Mean
TCP/IP Network Model
Database primary key
11. The 5 types of risks that are related to audits include: (1.) Control Risk (2.) Detection Risk (3.) Inherent risk (4.) _____________ (5.) Sampling risk
IT executives and the Board of Directors
Employee termination process
Overall audit risk
The audit program
12. An IS auditor is examining the IT standards document for an organization that was last reviewed two years earlier. The best course of action for the IS auditor is: Report that the ____________________________. Two years is far too long between revie
TCP/IP Internet Layer
IT standards are not being reviewed often enough
Current and most up-to-date
A Sample Mean
13. Change Management includes a _____________ of six steps: (1.) Proposal or Request (2.) Review (3.) Approval (4.) Implementation (5.) Verification (6.) Post-change Review
TCP/IP Network Model
The appropriate role of an IS auditor in a control self-assessment
Formal waterfall
Entire password for an encryption key
14. (1.) Access Control (2.) Change Management (3.) Security Controls (4.) Incident Management (5.) SDLC (6.) Source code and versioning controls (7.) Monitoring and logging (8.) Event Management
Examples of IT General Controls
Precision means
Antivirus software on the email servers
Examples of Application Controls
15. The sum of all samples divided by the number of samples.
Controls
Discovery Sampling
Types of sampling an auditor can perform.
A Sample Mean
16. Lowest layer. Delivers messages (frames) from one station to another vial local network.
TCP/IP Link Layer
Function Point Analysis
Incident Management
Precision means
17. A technique that is used to identify the most critical path in a project to understand which tasks are most likely to affect the project schedule.
The appropriate role of an IS auditor in a control self-assessment
OSI Layer 7: Application
Critical Path Methodology
Primary security features of relational databases
18. Disasters are generally grouped in terms of type: ______________.
Options for Risk Treatment
(1.) Man-made (2.) Natural
Department Charters
Sampling Risk
19. The process of recording the configuration of IT systems. Each configuration setting is known in ITSM parlance as a Configuration Item.
The Release process
A Problem
Advantages of outsourcing
Configuration Management
20. The probability that a sample selected does not represent the entire population. This is usually expressed as a percentage - as the numeric inverse of the confidence coefficient.
Server cluster
BCP Plans
Notify the Audit Committee
Sampling Risk
21. Use of a set of monitoring and review activities that confirm whether IS operations is providing service to its customers.
Service Level Management
Sample Standard Deviation
CPU
Server cluster
22. The risk that a material error exists that will not be prevented or detected by the organization's control framework - The possibility that a process or procedure will be unable to prevent or deter serious errors and wrongdoing.
Cloud computing
Control Risk
To identify the tasks that are responsible for project delays
Wet pipe fire sprinkler system
23. (1.) Develop a BC Policy (2.) Conduct BIA (3.) Perform critical analysis (4.) Establish recovery targets (5.) Develop recovery and continuity strategies and plans (6.) Test recovery and continuity plans and procedures Train personnel Maintain strateg
The BCP process
Attribute Sampling
OSI Layer 5: Session
A Cold Site
24. An audit of an IS department's operations and systems.
Expected Error Rate
The 5 types of Evidence that the auditor will collect during an audit.
An IS audit
TCP/IP Transport Layer packet delivery
25. An organization is building a data center in an area frequented by power outages. The organization cannot tolerate power outages. The best _________________solution is an electric generator and an uninterruptible power supply. The UPS responds to the
Power system controls
A Server Cluster
Buffers
Main types of Controls
26. An IS auditor has discovered a high-risk exception during control testing. The best course of action for the IS auditor to take - The IS auditor should immediately ________________ when any high-risk situation is discovered.
Service Level Management
Power system controls
Inform the auditee
Sampling Risk
27. Used to translate or transform data from lower layers into formats that the application layer can work with.
OSI Layer 6: Presentation
Blade Computer Architecture
OSI: Physical Layer
Examples of IT General Controls
28. The IS auditor should act as a SME in the control self-assessment - but should not play a major role in the process.
The appropriate role of an IS auditor in a control self-assessment
A Compliance audit
Buffers
Sampling Risk
29. An auditor is examining a key management process and has found that the IT department is not following its split-custody procedure. As a result - Someone may be in possession of the _________________.
Lacks specific expertise or resources to conduct an internal audit
Power system controls
IT executives and the Board of Directors
Entire password for an encryption key
30. A field in a record in one table that can reference a primary key in another table that can reference a primary key in another table.
The Eight Types of Audits
Foreign Key
Wet pipe fire sprinkler system
OSI: Network Layer
31. The party that performs strategic planning - addresses near-term and long-term requirements aligning business objectives - and technology strategies.
Discovery Sampling
Organizational culture and maturity
The Steering Committee
Deming Cycle
32. A CMM helps an organization to _______________ - which is an important first step to any large-scale process improvement effort.
Discovery Sampling
Assess the maturity of its business processes
SDLC Phases
Current and most up-to-date
33. To review and approve proposed changes to systems and infrastructure. This helps to reduce the risk of unintended events and unplanned downtime.
Testing activities
Change management
Registers
Overall audit risk
34. An auditor has discovered several errors in user account management: many terminated employees' computer accounts are still active. The best course of action - To improve the _________________ to reduce the number of exceptions. For a time - the proc
Dimensions of the COSO cube
Formal waterfall
Employee termination process
Reduced sign-on
35. IT Service Management is defined in ___________________ framework.
Six steps of the Release Management process
IT Service Management
ITIL definition of CHANGE MANAGEMENT
ITIL - IT Infrastructure Library
36. During an audit - the auditor should obtain 6 types of documents - (1.) Org charts (2.) ___________ (3.) third-party contracts (4.) policies and procedures (5.) standards (6.) system documentation
Foreign Key
ISO 20000 Standard:
Department Charters
Criticality analysis
37. Governed by: (1.) Effective Change Management (2.) Effective Application Testing (3.) Resilient Architecture (4.) Serviceable Components
Background checks performed
Examples of Application Controls
Disaster Recovery
The availability of IT systems
38. (1.) Hardware Complement (physical specifications) (2.) Hardware Configuration (firmware settings) (3.) Operating system version and configuration (4.) Software versions and configuration
Three Types of Controls
The typical Configuration Items in Configuration Management
Notify the Audit Committee
Data Link Layer Standards
39. A sampling technique where at least one exception is sought in a population
Discovery Sampling
Employee termination process
The typical Configuration Items in Configuration Management
OSI Layer 7: Application
40. A condition often identified as a result of multiple incidents that exhibit common symptoms. Problems can also be identified from a single significant incident for which the impact is significant.
The Software Program Library
Frameworks
TCP/IP Internet Layer
ITIL definition of PROBLEM
41. A sampling technique where items are chosen at random; each item has a statistically equal probability of being chosen.
Buffers
The 7 phases and their order in the SDLC
Emergency Changes
Statistical Sampling
42. Must be tested to validate effectiveness through: (1.) Document Review (2.) Walkthrough (3.) Simulation (4.) Parallel testing (5.) Cutover testing practices
Business Realization
An Operational Audit
Personnel involved in the requirements phase of a software development project
BCP Plans
43. A sampling technique used to permit sampling to stop at the earliest possible time. This technique is used when the auditor feels that there is a low risk or low rate of exceptions in the population.
IT Services Financial Management
less than 24 hours
Application Controls
Stop-or-go Sampling
44. An audit of a third-party organization that provides services to other organizations.
A Service Provider audit
Critical Path Methodology
List of systems examined
Elements of the COBIT Framework
45. The primary source for test plans in a software development project is: ________________ that are developed for a project should be the primary source for detailed tests.
Service Continuity Management
Criticality analysis
Audit logging
The Requirements
46. A large number of loosely coupled computers that are used to solve a common task may be in close proximity to each other or scattered over a large geographical area.
Transport Layer Protocols
Grid Computing
SDLC Phases
Risk Management
47. An audit that combines an operational audit and a financial audit.
Incident Management
More difficult to perform
objective and unbiased
An Integrated Audit
48. (1.) Avoidance (2.) Transfer (3.) Mitigation (4.) Acceptance
BCP Plans
Categories of risk treatment
Separate administrative accounts
TCP/IP Link Layer
49. Collections of Controls that work together to achieve an entire range of an organization's objectives.
Foreign Key
Project change request
Frameworks
Service Level Management
50. A condition that is the result of multiple incidents that exhibit common symptoms e.g. A web application is displaying information incorrectly and many users have contacted the IT service desk.
Sampling Risk
A gate process
Reduced sign-on
A Problem