ISACA CISA Exam (page: 37)
ISACA Certified Information Systems Auditor
Updated on: 25-Dec-2025

Viewing Page 37 of 366

When evaluating the management practices at a third-party organization providing outsourced services, the IS auditor considers relying on an independent auditor's report. The IS auditor would FIRST:

  1. review the objectives of the audit.
  2. examine the independent auditor's workpapers.
  3. discuss the report with the independent auditor.
  4. determine if recommendations have been implemented.

Answer(s): A



What is the BEST control to address SQL injection vulnerabilities?

  1. Digital signatures
  2. Input validation
  3. Unicode translation
  4. Secure Sockets Layer (SSL) encryption

Answer(s): B



In a typical network architecture used for e-commerce, a load balancer is normally found between the:

  1. routers and the web servers.
  2. mail servers and the mail repositories.
  3. users and the external gateways.
  4. databases and internal firewalls.

Answer(s): A



During an audit of a financial application, it was determined that many terminated users' accounts were not disabled. Which of the following should be the IS auditor's NEXT step?

  1. Perform a review of terminated users' account activity.
  2. Conclude that IT general controls are ineffective.
  3. Communicate risks to the application owner.
  4. Perform substantive testing of terminated users' access rights.

Answer(s): C



When developing metrics to measure the contribution of IT to the achievement of business goals, the MOST important consideration is that the metrics:

  1. measure the effectiveness of IT controls in the achievement of IT strategy.
  2. provide quantitative measurement of IT initiatives in relation with business targets.
  3. are expressed in terms of how IT risk impacts the achievement of business goals.
  4. are used by similar industries to measure the effect of IT on business strategy.

Answer(s): B



Viewing Page 37 of 366



Share your comments for ISACA CISA exam with other users:

Mike 8/20/2023 5:12:00 PM

the exam dumps are helping me get a solid foundation on the practical techniques and practices needed to be successful in the auditing world.
UNITED STATES


Sam 8/31/2023 10:32:00 AM

not bad but you question database from isaca
MALAYSIA


Deno 10/25/2023 1:14:00 AM

i failed the cisa exam today. but i have found all the questions that were on the exam to be on this site.
Anonymous