[Apr 09, 2023] Get New CISA Certification Practice Test Questions Exam Dumps [Q121-Q146]

Share

[Apr 09, 2023] Get New CISA Certification Practice Test Questions Exam Dumps

Real CISA Exam Dumps Questions Valid CISA Dumps PDF


What are the strengths of the candidate who wants to take the ISACA CISA Exam

There are qualified and knowledgeable instructors. They specialize in the subject matter and can teach it well. The facilities that the school has for learning purposes are extremely sophisticated and modern. The library is large and full of resources for students to enjoy and boost their learning abilities. The school has a good reputation in the community, which means students can find jobs easily with a degree from this university. An online program makes it possible for more people to enroll in the university even if they have family or work commitments. This is an excellent option for someone who is looking to get ahead in their career but doesn't have the time or money to go away from home anymore.


Conclusion

The CISA exam is definitely an instrumental tool for IT generalists wanting to jump aboard the audit field or IT auditors who want to climb the career ladder. With a successful feat in this superior Isaca certification, you become an in-demand specialist with a validated skillset and proven IT/IS audit expertise. So, better get started with your preparation by utilizing the helpful resources mentioned above and earn this top-notch endorsement in no time.

 

NEW QUESTION 121
Which of the following controls will MOST effectively detect inconsistent records resulting from the lack of referential integrity in a database management system?

  • A. Periodic table link checks
  • B. Performance monitoring tools
  • C. Incremental data backups
  • D. Concurrent access controls

Answer: A

 

NEW QUESTION 122
Which of the following is the MOST effective way for an organization to help ensure agreed-upon action plans from an IS audit will be implemented?

  • A. Ensure sufficient audit resources are allocated,
  • B. Communicate audit results organization-wide.
  • C. Ensure ownership is assigned.
  • D. Test corrective actions upon completion.

Answer: C

 

NEW QUESTION 123
Which of the following would an IS auditor PRIMARILY review to understand key drivers of a project?

  • A. IT strategy and objectives
  • B. Project risk matrix
  • C. Earned value analysis (EVA)
  • D. Business case

Answer: D

 

NEW QUESTION 124
The MOST efficient way to confirm that an ERP system being implemented satisfies business expectations is to utilize which of the following types of testing?

  • A. Alpha
  • B. Parallel
  • C. Pilot
  • D. Sociability

Answer: B

 

NEW QUESTION 125
An IS auditor has imported data from the client's database. The next step-confirming whether the imported data are complete-is performed by:

  • A. reviewing the printout of the first 100 records of original data with the first 100 records of imported data.
  • B. filtering data for different categories and matching them to the original data.
  • C. matching control totals of the imported data to control totals of the original data.
  • D. sorting the data to confirm whether the data are in the same order as the original data.

Answer: C

Explanation:
Matching control totals of the imported data with control totals of the original data is the next logical step, as this confirms the completeness of the imported datA . It is not possible to confirm completeness by sorting the imported data, because the original data may not be in sorted order. Further, sorting does not provide control totals for verifying completeness. Reviewing a printout of 100 records of original data with 100 records of imported data is a process of physical verification andconfirms the accuracy of only these records. Filtering data for different categories and matching them to original data would still require that control totals be developed to confirm the completeness of the data.

 

NEW QUESTION 126
Which of the following should an IS auditor ensure is classified at the HIGHEST level of sensitivity?

  • A. Server room access history
  • B. Emergency change records
  • C. Penetration test results
  • D. it security incidents

Answer: C

 

NEW QUESTION 127
An IS auditor doing penetration testing during an audit of internet connections would:

  • A. examine security settings.
  • B. evaluate configurations.
  • C. ensure virus-scanning software is in use.
  • D. use tools and techniques available to a hacker.

Answer: D

Explanation:
Explanation/Reference:
Explanation:
Penetration testing is a technique used to mimic an experienced hacker attacking a live site by using tools and techniques available to a hacker. The other choices are procedures that an IS auditor would consider undertaking during an audit of Internet connections, but are not aspects of penetration testing techniques.

 

NEW QUESTION 128
For a discretionary access control to be effective, it must:

  • A. operate independently of mandatory access controls.
  • B. operate within the context of mandatory access controls.
  • C. enable users to override mandatory access controls when necessary.
  • D. be specifically permitted by the security policy.

Answer: B

Explanation:
Section: Protection of Information Assets
Explanation:
Mandatory access controls are prohibitive; anything that is not expressly permitted is forbidden. Only within this context do discretionary controls operate, prohibiting still more access with the same exclusionary principle. When systems enforce mandatory access control policies, they must distinguish between these and the mandatory access policies that offer more flexibility.
Discretionary controls do not override access controls and they do not have to be permitted in the security policy to be effective.

 

NEW QUESTION 129
During a follow-up audit, an IS auditor learns the organization implemented an automated process instead
of the originally agreed upon enhancement of the manual process. The auditor should:

  • A. report the recommendation as implemented
  • B. verify that the new process satisfies control objectives
  • C. perform a cost-benefit analysis on the new process
  • D. report the finding that recommendations were not acted upon

Answer: B

Explanation:
Section: The process of Auditing Information System

 

NEW QUESTION 130
Which of the following INCORRECTLY describes the layer functions of the LAN or WAN Layer of the TCP/ IP model?

  • A. Combines packets into bytes and bytes into frame
  • B. Provide address to media using MAC address
  • C. Providers logical addressing which routers use for path determination
  • D. Performs only error detection

Answer: C

Explanation:
Explanation/Reference:
The word INCORRECTLY is the keyword used in the question. You need to find out the functionality that is not performed by LAN or WAN layer in TCP/IP model.
The Network layer of a TCP/IP model provides logical addressing which routers use for path determination.
For your exam you should know below information about TCP/IP model:
Network Models

Layer 4. Application Layer
Application layer is the top most layer of four layer TCP/IP model. Application layer is present on the top of the Transport layer. Application layer defines TCP/IP application protocols and how host programs interface with Transport layer services to use the network.
Application layer includes all the higher-level protocols like DNS (Domain Naming System), HTTP (Hypertext Transfer Protocol), Telnet, SSH, FTP (File Transfer Protocol), TFTP (Trivial File Transfer Protocol), SNMP (Simple Network Management Protocol), SMTP (Simple Mail Transfer Protocol) , DHCP (Dynamic Host Configuration Protocol), X Windows, RDP (Remote Desktop Protocol) etc.
Layer 3. Transport Layer
Transport Layer is the third layer of the four layer TCP/IP model. The position of the Transport layer is between Application layer and Internet layer. The purpose of Transport layer is to permit devices on the source and destination hosts to carry on a conversation. Transport layer defines the level of service and status of the connection used when transporting data.
The main protocols included at Transport layer are TCP (Transmission Control Protocol) and UDP (User Datagram Protocol).
Layer 2. Internet Layer
Internet Layer is the second layer of the four layer TCP/IP model. The position of Internet layer is between Network Access Layer and Transport layer. Internet layer pack data into data packets known as IP datagram's, which contain source and destination address (logical address or IP address) information that is used to forward the datagram's between hosts and across networks. The Internet layer is also responsible for routing of IP datagram's.
Packet switching network depends upon a connectionless internetwork layer. This layer is known as Internet layer. Its job is to allow hosts to insert packets into any network and have them to deliver independently to the destination. At the destination side data packets may appear in a different order than they were sent. It is the job of the higher layers to rearrange them in order to deliver them to proper network applications operating at the Application layer.
The main protocols included at Internet layer are IP (Internet Protocol), ICMP (Internet Control Message Protocol), ARP (Address Resolution Protocol), RARP (Reverse Address Resolution Protocol) and IGMP (Internet Group Management Protocol).
Layer 1. Network Access Layer
Network Access Layer is the first layer of the four layer TCP/IP model. Network Access Layer defines details of how data is physically sent through the network, including how bits are electrically or optically signaled by hardware devices that interface directly with a network medium, such as coaxial cable, optical fiber, or twisted pair copper wire.
The protocols included in Network Access Layer are Ethernet, Token Ring, FDDI, X.25, Frame Relay etc.
The most popular LAN architecture among those listed above is Ethernet. Ethernet uses an Access Method called CSMA/CD (Carrier Sense Multiple Access/Collision Detection) to access the media, when Ethernet operates in a shared media. An Access Method determines how a host will place data on the medium.
IN CSMA/CD Access Method, every host has equal access to the medium and can place data on the wire when the wire is free from network traffic. When a host wants to place data on the wire, it will check the wire to find whether another host is already using the medium. If there is traffic already in the medium, the host will wait and if there is no traffic, it will place the data in the medium. But, if two systems place data on the medium at the same instance, they will collide with each other, destroying the data. If the data is destroyed during transmission, the data will need to be retransmitted. After collision, each host will wait for a small interval of time and again the data will be retransmitted.
Protocol Data Unit (PDU) :
Protocol Data Unit - PDU

The following answers are incorrect:
The other options correctly describe functionalities of application layer in TCP/IP model.
The following reference(s) were/was used to create this question:
CISA review manual 2014 page number 272

 

NEW QUESTION 131
Which of the following BEST describes the role of a directory server in a public key infrastructure (PKI)?

  • A. Stores certificate revocation lists (CRLs)
  • B. Makes other users' certificates available to applications
  • C. Encrypts the information transmitted over the network
  • D. Facilitates the implementation of a password policy

Answer: B

Explanation:
Section: Protection of Information Assets
Explanation:
A directory server makes other users' certificates available to applications. Encrypting the information
transmitted over the network and storing certificate revocation lists (CRLs) are roles performed by a
security server. Facilitating the implementation of a password policy is not relevant to public key
infrastructure (PKl).

 

NEW QUESTION 132
The BEST overall quantitative measure of the performance of biometric control devices is:

  • A. false-acceptance rate.
  • B. equal-error rate.
  • C. false-rejection rate.
  • D. estimated-error rate.

Answer: B

Explanation:
Explanation/Reference:
Explanation:
A low equal-error rate (EER) is a combination of a low false-rejection rate and a low false- acceptance rate. EER, expressed as a percentage, is a measure of the number of times that the false-rejection and false-acceptance rates are equal. A low EER is the measure of the more effective biometrics control device. Low false-rejection rates or low false- acceptance rates alone do not measure the efficiency of the device. Estimated-error rate is nonexistent and therefore irrelevant.

 

NEW QUESTION 133
Phishing attack works primarily through:

  • A. email attachment
  • B. chat
  • C. news
  • D. SMS
  • E. file download
  • F. None of the choices.
  • G. email and hyperlinks

Answer: G

Explanation:
Section: Protection of Information Assets
Explanation:
"Phishing applies to email appearing to come from a legitimate business, requesting "verification"" of
information and warning of some dire consequence if it is not done. The letter usually contains a link to a
fradulent web page that looks legitimate and has a form requesting everything from a home address to an
ATM card's PIN."

 

NEW QUESTION 134
What is an effective countermeasure for the vulnerability of data entry operators potentially leaving their computers without logging off?

  • A. Screensaver passwords
  • B. Administrator alerts
  • C. Close supervision
  • D. Employee security awareness training

Answer: A

Explanation:
Section: Protection of Information Assets
Explanation:
Screensaver passwords are an effective control to implement as a countermeasure for the vulnerability of data entry operators potentially leaving their computers without logging off.

 

NEW QUESTION 135
Which of the following provide(s) near-immediate recoverability for time-sensitive systems and transaction
processing?

  • A. Parallel processing
  • B. Automated electronic journaling and parallel processing
  • C. Data mirroring
  • D. Data mirroring and parallel processing

Answer: D

Explanation:
Section: Protection of Information Assets
Explanation:
Data mirroring and parallel processing are both used to provide near- immediate recoverability for time-
sensitive systems and transaction processing.

 

NEW QUESTION 136
In which of the following transmission media it is MOST difficult to modify the information traveling across the network?

  • A. Copper cable
  • B. Satellite Radio Link
  • C. Coaxial cable
  • D. Fiber Optics

Answer: D

Explanation:
Explanation/Reference:
Fiber optics cables are used for long distance, hard to splice, not vulnerable to cross talk and difficult to tap. It supports voice data, image and video.
For your exam you should know below information about transmission media:
Copper Cable
Copper cable is very simple to install and easy to tap. It is used mostly for short distance and supports voice and data.
Copper has been used in electric wiring since the invention of the electromagnet and the telegraph in the
1820s.The invention of the telephone in 1876 created further demand for copper wire as an electrical conductor.
Copper is the electrical conductor in many categories of electrical wiring. Copper wire is used in power generation, power transmission, power distribution, telecommunications, electronics circuitry, and countless types of electrical equipment. Copper and its alloys are also used to make electrical contacts.
Electrical wiring in buildings is the most important market for the copper industry. Roughly half of all copper mined is used to manufacture electrical wire and cable conductors.
Copper Cable

Coaxial cable
Coaxial cable, or coax (pronounced 'ko.aks), is a type of cable that has an inner conductor surrounded by a tubular insulating layer, surrounded by a tubular conducting shield. Many coaxial cables also have an insulating outer sheath or jacket. The term coaxial comes from the inner conductor and the outer shield sharing a geometric axis. Coaxial cable was invented by English engineer and mathematician Oliver Heaviside, who patented the design in 1880.Coaxial cable differs from other shielded cable used for carrying lower-frequency signals, such as audio signals, in that the dimensions of the cable are controlled to give a precise, constant conductor spacing, which is needed for it to function efficiently as a radio frequency transmission line.
Coaxial cable is expensive and does not support many LAN's. It supports data and video.
Coaxial Cable

Fiber optics
An optical fiber cable is a cable containing one or more optical fibers that are used to carry light. The optical fiber elements are typically individually coated with plastic layers and contained in a protective tube suitable for the environment where the cable will be deployed. Different types of cable are used for different applications, for example long distance telecommunication, or providing a high-speed data connection between different parts of a building.
Fiber optics used for long distance, hard to splice, not vulnerable to cross talk and difficult to tap. It supports voice data, image and video.
Radio System
Radio systems are used for short distance, cheap and easy to tap.
Radio is the radiation (wireless transmission) of electromagnetic signals through the atmosphere or free space.
Information, such as sound, is carried by systematically changing (modulating) some property of the radiated waves, such as their amplitude, frequency, phase, or pulse width. When radio waves strike an electrical conductor, the oscillating fields induce an alternating current in the conductor. The information in the waves can be extracted and transformed back into its original form.
Fiber Optics

Microwave radio system
Microwave transmission refers to the technology of transmitting information or energy by the use of radio waves whose wavelengths are conveniently measured in small numbers of centimeter; these are called microwaves.
Microwaves are widely used for point-to-point communications because their small wavelength allows conveniently-sized antennas to direct them in narrow beams, which can be pointed directly at the receiving antenna. This allows nearby microwave equipment to use the same frequencies without interfering with each other, as lower frequency radio waves do. Another advantage is that the high frequency of microwaves gives the microwave band a very large information-carrying capacity; the microwave band has a bandwidth 30 times that of all the rest of the radio spectrum below it. A disadvantage is that microwaves are limited to line of sight propagation; they cannot pass around hills or mountains as lower frequency radio waves can.
Microwave radio transmission is commonly used in point-to-point communication systems on the surface of the Earth, in satellite communications, and in deep space radio communications. Other parts of the microwave radio band are used for radars, radio navigation systems, sensor systems, and radio astronomy.
Microwave radio systems are carriers for voice data signal, cheap and easy to tap.
Microwave Radio System

Satellite Radio Link
Satellite radio is a radio service broadcast from satellites primarily to cars, with the signal broadcast nationwide, across a much wider geographical area than terrestrial radio stations. It is available by subscription, mostly commercial free, and offers subscribers more stations and a wider variety of programming options than terrestrial radio.
Satellite radio link uses transponder to send information and easy to tap.
The following answers are incorrect:
Copper Cable- Copper cable is very simple to install and easy to tap. It is used mostly for short distance and supports voice and data.
Satellite Radio Link - Satellite radio link uses transponder to send information and easy to tap.
Coaxial cable - Coaxial cable are expensive and does not support many LAN's. It supports data and video The following reference(s) were/was used to create this question:
CISA review manual 2014 page number 265

 

NEW QUESTION 137
The PRIMARY purpose of a configuration management system is to:

  • A. define baselines for software.
  • B. standardize change approval.
  • C. track software updates.
  • D. support the release procedure.

Answer: A

 

NEW QUESTION 138
Which of the following is the MOST effective way to prevent unauthorized changes from being moved into production?

  • A. Enforce segregation of duties between developers and migrators.
  • B. Conduct periodic review of change tickets to ensure all change documentation is attached.
  • C. Perform thorough testing of changes in the test environment.
  • D. Require approval of changes by the appropriate business process owners.

Answer: C

Explanation:
Section: Protection of Information Assets

 

NEW QUESTION 139
Which of the following is the BEST way for an IT forensics investigator to detect evidence of steganography?

  • A. Recover deleted files from a suspected hard drive utilizing forensics software.
  • B. Identify and analyze emergent properties within a file system's metadata.
  • C. Scan computer operating systems using administrative tools.
  • D. Compare file hashes between original and modified image files.

Answer: D

 

NEW QUESTION 140
Which of the following is the MOST important consideration when establishing vulnerability scanning on critical IT infrastructure?

  • A. The scanning will not degrade system performance.
  • B. The scanning will be followed by penetration testing.
  • C. The scanning will be performed during non-peak hours.
  • D. The scanning will be cost-effective.

Answer: A

 

NEW QUESTION 141
Which of the following presents an inherent risk with no distinct identifiable preventive controls?

  • A. Piggybacking
  • B. Data diddling
  • C. Viruses
  • D. Unauthorized application shutdown

Answer: B

Explanation:
Data diddling involves changing data before they are entered into the computer. It is one of the most common abuses, because it requires limited technical knowledge and occurs before computer security can protect the datA . There are only compensatingcontrols for data diddling. Piggybacking is the act of following an authorized person through a secured door and can be prevented by the use of deadman doors. Logical piggybacking is an attempt to gain access through someone who has the rights, e.g., electronically attaching to an authorized telecommunication link to possibly intercept transmissions. This could be prevented by encrypting the message. Viruses are malicious program code inserted into another executable code that can self-re plicate and spread from computer to computer via sharing of computer diskettes, transfer of logic over telecommunication lines or direct contact with an infected machine. Antiviral software can be used to protect the computer against viruses. The shutdownof an application can be initiated through terminals or microcomputers connected directly (online) or indirectly (dial-up line) to the computer. Only individuals knowing the high-level logon ID and password can initiate the shutdown process, which iseffective if there are proper access controls.

 

NEW QUESTION 142
Processing controls ensure that data is accurate and complete, and is processed only through which of the following?

  • A. Documented routines
  • B. Accepted routines
  • C. Approved routines
  • D. Authorized routines

Answer: D

Explanation:
Section: Protection of Information Assets
Explanation:
Processing controls ensure that data is accurate and complete, and is processed only through authorized routines.

 

NEW QUESTION 143
Which testing approach is MOST appropriate to ensure that internal application interface errors are identified as soon as possible?

  • A. System test
  • B. Top-down
  • C. Bottom up
  • D. Sociability testing

Answer: B

Explanation:
The top-down approach to testing ensures that interface errors are detected early and that testing of major functions is conducted early. A bottom-up approach to testing begins with atomic units, such as programs and modules, and works upward until acomplete system test has taken place. Sociability testing and system tests take place at a later stage in the development process.

 

NEW QUESTION 144
Which of the following encryption methods uses a matching pair of key-codes, securely distributed, which are used once-and-only-once to encode and decode a single message?

  • A. Tripwire
  • B. certificate
  • C. one-time pad
  • D. DES
  • E. None of the choices.
  • F. Blowfish

Answer: C

Explanation:
Explanation/Reference:
Explanation:
It's possible to protect messages in transit by means of cryptography.
One method of encryption --the one-time pad --has been proven to be unbreakable when correctly used.
This method uses a matching pair of key- codes, securely distributed, which are used once-and-only-once to encode and decode a single message. Note that this method is difficult to use securely, and is highly inconvenient as well.

 

NEW QUESTION 145
Which of the following network configuration options contains a direct link between any two host machines?

  • A. Ring
  • B. Completely connected (mesh)
  • C. Bus
  • D. Star

Answer: B

Explanation:
A completely connected mesh configuration creates a direct link between any two host machines.

 

NEW QUESTION 146
......


Exam Details

The exam for the ISACA CISA certification is available in English, French, Italian, Turkish, Korean, German, Japanese, Spanish, Simplified Chinese, and Traditional Chinese. The test is made up of 150 multiple-choice questions covering five domains of the exam content. The time allocated for the completion is 240 minutes. The passing score is 450/800 points. To register, the applicants are expected to pay the fee. For the ISACA members, it is $575, while the non members should pay $760.

The CISA exam is computer-based and administered at the authorized PSI testing centers across the world. You can schedule your appointment for 48 hours after the payment. You can find the complete details of the test-taking process on the certification webpage. You will also find links to different preparation resources, including virtual or in-person training and practice tests. There is no penalty for incorrect answers, and your grades are determined by the number of questions you answered correctly.

 

CISA Exam Dumps - PDF Questions and Testing Engine: https://pass4sure.examcost.com/CISA-practice-exam.html