ISACA CISA Exam (page: 41)
ISACA Certified Information Systems Auditor
Updated on: 25-Dec-2025

Viewing Page 41 of 366

During a project meeting for the implementation of an enterprise resource planning (ERP). a new requirement is requested by the finance department. Which of the following would BEST indicate to an IS auditor that the resulting risk to the project has been assessed?

  1. The project status as reported in the meeting minutes
  2. The analysis of the cost and time impact of the requirement
  3. The updated business requirements
  4. The approval of the change by the finance department

Answer(s): B



An organization has implemented a quarterly job schedule to update database tables so prices are adjusted in line with a price index. These changes do not go through the regular change management process. Which of the following is the MOST important control to have in place?

  1. An overarching approval is obtained from the change advisory board.
  2. User acceptance testing (UAT) is performed after the production run.
  3. Each production run is approved by an authorized individual.
  4. Exception reports are generated to identify anomalies.

Answer(s): C



Which of the following methods will BEST reduce the risk associated with the transition to a new system using technologies that are not compatible with the old system?

  1. Pilot operation
  2. Parallel changeover
  3. Modular changeover
  4. Phased operation

Answer(s): B



Following a merger, a review of an international organization determines the IT steering committee's decisions do not extend to regional offices as required in the consolidated IT operating model. Which of the following is the IS auditor's BEST recommendation?

  1. Create regional centers of excellence.
  2. Engage an IT governance consultant.
  3. Update the IT steering committee's formal charter.
  4. Create regional IT steering committees.

Answer(s): C



An organization recently decided to send the backup of its customer relationship management (CRM) system to its cloud provider for recovery. Which of the following should be of GREATEST concern to an IS auditor reviewing this process?

  1. Testing of restore data has not been performed.
  2. Validation of backup data has not been performed.
  3. Backups are sent and stored in unencrypted format.
  4. The cloud provider is located in a different country.

Answer(s): C



Viewing Page 41 of 366



Share your comments for ISACA CISA exam with other users:

Mike 8/20/2023 5:12:00 PM

the exam dumps are helping me get a solid foundation on the practical techniques and practices needed to be successful in the auditing world.
UNITED STATES


Sam 8/31/2023 10:32:00 AM

not bad but you question database from isaca
MALAYSIA


Deno 10/25/2023 1:14:00 AM

i failed the cisa exam today. but i have found all the questions that were on the exam to be on this site.
Anonymous