C. Resigned employees' logon IDs are not deleted immediately. Which of the following should be a concern to an IS auditor ? Denies selected traffic and allows rest all traffic. D. Terminals are located within the facility in small clusters under the supervision of an administrator. C. data on the hard disk should be deleted. A. ensure that all assets are insured against losses. B. SSID (Service Set IDentifier) broadcasting has been enabled. Data owner. C. Is frequently used for granting access from un- trusted network to an external System. (5)Which among the below is the First step in implementation of access control list: (6)IS auditor is reviewing security of a payroll application. In this situation, the IS auditor is MOST likely to conclude that: (24)IS auditor observed that even though password policy requires passwords to be a combination of letters, numbers and special characters, users are not following the same rigorously. A. many users can claim to be a specific user. This policy: (3)To prevent unauthorized entry to database of critical application, an IS auditor should recommend: (4) IS auditor is reviewing general IT controls of an organisation. Which of the following should concern him? C. Proper sign in procedure for visitors. (29)Which of the following BEST logical control mechanism to ensure that access allowed to users to only those functions needed to perform their duties? A. D. user accountability may not be established. C. process for change authorization is in place. The CISA exam will test you on 5 domains covering a variety of different subject areas. Mock Test-Compliance & Substantive Testing (CISA-Domain-1) Mock Test-Compliance & Substantive Testing (CISA-Domain-1) Which of the following tests is an IS auditor performing when a sample of programs is selected to determine if the source and object versions are the same? C. Full access is provided for a limited period. This section talks about the audit charter and what it contains, and steps for audit planning. C. Is frequently used for granting access from a trusted network to an external Systems. (1)The Allow All Access Control Policy: 1 point. B. it improvises the productivity of employees. (26)IS auditor is reviewing an organization's logical access security. Which of the following is the MOST effective control? C. Stand-alone terminals with password protection are located in insecure locations. Mock Test-Biometrics (CISA-Domain-5) Mock Test-Biometrics (CISA-Domain-5) D. Online access to be blocked after a specified number of unsuccessful attempts. Mock Test-IDS & IPS (CISA-Domain 5) Mock Test-IDS & IPS (CISA-Domain 5) Two factor authentication is mandatory of access of critical applications. One of the free resources that we make available at AuditScripts.com is a database of free ISACA CISA exam questions. A. C. establish appropriate access control guidelines, D. ensure all information assets have access controls, A. help to avoid ambiguous resource names, B. reduce the number of rules required to adequately protect resources, D. ensure that internationally recognized names are used to protect resources. B. Outsider can gain access to the system. You must make sure you have adequate time to review all domains at least once; this involves not only studying but also completing mock exams, visiting online forums and spending extra time … A. LAN connections are easily in the facility to connect laptops to the network. B. Logging data communication access activities, C. Verifying user authorization at the field level. (17) Mechanism that checks each request by a subject to access and use an object is as per security policy is known as : (18)Most effective transmission media in terms of security against unauthorized access is: (19)An IS auditor reviewing system controls should be most concerned that: (20)IS auditor is evaluating general operating system access control functions. C. implementation of access control rules. To ensure compliance within security policy, the IS auditor should recommend that: (25)IS auditor is evaluating database-level access control functions. Containing CISA exam sample questions that are in line with the questions that you might come across in the certification examination, this CISA practice test lets you analyze your skills and better them if required. A. Complete Video Training Courses & Practice Test PDF Questions For Passing CISA Exam Quickly. Allows selected traffic and denies rest all traffic. These are the official ISACA job practice areas for 5 CISA domains. The first domain covers how IT auditors provide services in accordance with IT audit standards, in order to assist the organization in protecting and controlling information systems. (8) An IS auditor is evaluating access control policy of an organisation. B. D. Message compression (2) Digital signature will address which of the concerns about electronic message: 1 point. He should be most concerned if: (27) The FIRST step in data classification is to: (28)Which of the following is the MOST important objective of data protection? (1) An IS auditor is reviewing access control policy of an organisation. 1 point . (23) An IS auditor observes that default printing options are enabled for all users. IT Systems Auditors/Auditors; Compliance/Assurance related roles; Level of the Program and Pre-requisites . C. it ensures smooth flow of information among users. D. monthly security awareness training to be delivered. D. restricted access for system parameters is in place. Message integrity. Denies selected traffic and allows rest all traffic. C. Antivirus software has been installed in all wireless clients. B. there is no way to limit role based access. Which of the following should concern him? ISACA has stated that this domain represents 30 percent of the CISA examination which is approximately 60 questions. B. ensures access is granted as per the approved structure. (1) An IS auditor is reviewing access control policy of an organisation.
