check

Quiz gratuit CISA

Ce quiz de 10 questions vous permet d'évaluer votre niveau de préparation au CISA

Cliquer sur le bouton ci-dessous pour commencer.

Démarrer

Question 1 sur 10

An audit charter should:

A

be dynamic and change to coincide with the changing nature of technology and the audit profession.

B

clearly state audit objectives for, and the delegation of, authority to the maintenance and review of internal controls.

C

document the audit procedures designed to achieve the planned audit objectives.

D

outline the overall authority, scope and responsibilities of the audit function.

Question 2 sur 10

An IS auditor finds a small number of user access requests that had not been authorized by managers through the normal predefined workflow steps and escalation rules. The IS auditor should:

A

perform an additional analysis.

B

report the problem to the audit committee.

C

conduct a security risk assessment.

D

recommend that the owner of the identity management (IDM) system fix the workflow issues.

Question 3 sur 10

An IS auditor observes that an enterprise has outsourced software development to a third party that is a startup company. To ensure that the enterprise's investment in software is protected, which of the following should be recommended by the IS auditor?

A

Due diligence should be performed on the software vendor.

B

A quarterly audit of the vendor facilities should be performed.

C

There should be a source code escrow agreement in place.

D

A high penalty clause should be included in the contract.

Question 4 sur 10

An enterprise's risk appetite is BEST established by:

A

the chief legal officer.

B

security management.

C

the audit committee.

D

the steering committee.

Question 5 sur 10

When identifying an earlier project completion time, which is to be obtained by paying a premium for early completion, the activities that should be selected are those:

A

whose sum of activity time is the shortest.

B

that have zero slack time.

C

that give the longest possible completion time.

D

whose sum of slack time is the shortest.

Question 6 sur 10

An IS auditor is assigned to audit a software development project, which is more than 80 percent complete, but has already overrun time by 10 percent and costs by 25 percent. Which of the following actions should the IS auditor take?

A

Report that the organization does not have effective project management.

B

Recommend the project manager be changed.

C

Review the IT governance structure.

D

Review the conduct of the project and the business case.

Question 7 sur 10

A programmer maliciously modified a production program to change data and then restored the original code. Which of the following would MOST effectively detect the malicious activity?

A

Comparing source code

B

Reviewing system log files

C

Comparing object code

D

Reviewing executable and source code integrity

Question 8 sur 10

Which of the following would BEST ensure continuity of a wide area network (WAN) across the organization?

A

Built-in alternative routing

B

Complete full system backup daily

C

A repair contract with a service provider

D

A duplicate machine alongside each server.

Question 9 sur 10

An IS auditor is reviewing the physical security controls of a data center and notices several areas for concern. Which of the following areas is the MOST important?

A

The emergency power off button cover is missing.

B

Scheduled maintenance of the fire suppression system was not performed.

C

There are no security cameras inside the data center.

D

The emergency exit door is blocked.

Question 10 sur 10

Which of the following choices BEST helps information owners to properly classify data?

A

Understanding of technical controls that protect data

B

Training on organizational policies and standards

C

Use of an automated data leak prevention (DLP) tool

D

Understanding which people need to access the data

Confirmez et soumettez