ISACA CISA Exam (page: 64)
ISACA Certified Information Systems Auditor
Updated on: 02-Jan-2026

Viewing Page 64 of 366

An employee transfers from an organization's risk management department to become the lead IS auditor. While in the risk management department, the employee helped develop the key performance indicators (KPIs) now used by the organization. Which of the following would pose the GREATEST threat to the independence of this auditor?

  1. Evaluating the effectiveness of IT risk management processes
  2. Recommending controls to address the IT risks identified by KPIs
  3. Developing KPIs to measure the internal audit team
  4. Training the IT audit team on IT risk management processes

Answer(s): B



As part of an audit response, an auditee has concerns with the recommendations and is hesitant to implement them. Which of the following would be the BEST course of action for the IS auditor?

  1. Suggest hiring a third-party consultant to perform a current state assessment.
  2. Issue a final report without including the opinion of the auditee.
  3. Conduct further discussions with the auditee to develop a mitigation plan.
  4. Accept the auditee's response and perform additional testing.

Answer(s): C



After discussing findings with an auditee, an IS auditor is required to obtain approval of the report from the CEO before issuing it to the audit committee. This requirement PRIMARILY affects the IS auditor's:

  1. judgment
  2. effectiveness
  3. independence
  4. integrity

Answer(s): C



During a review of IT service desk practices, an IS auditor notes that help desk personnel are spending more time fulfilling user requests for password resets than resolving critical incidents. Which of the following recommendations to IT management would BEST address this situation?

  1. Calculate the age of incident tickets and alert senior IT personnel when they exceed service level agreements (SLAs).
  2. Provide annual password management training to end users to reduce the number of instances requiring password resets.
  3. Incentivize service desk personnel to close incidents within agreed service levels.
  4. Implement a self-service solution and redirect users to access frequently requested services.

Answer(s): D



During which phase of a system development project should key performance indicators (KPIs) be established?

  1. Planning phase
  2. Initiation phase
  3. Execution phase
  4. Closure phase

Answer(s): A



Viewing Page 64 of 366



Share your comments for ISACA CISA exam with other users:

Mike 8/20/2023 5:12:00 PM

the exam dumps are helping me get a solid foundation on the practical techniques and practices needed to be successful in the auditing world.
UNITED STATES


Sam 8/31/2023 10:32:00 AM

not bad but you question database from isaca
MALAYSIA


Deno 10/25/2023 1:14:00 AM

i failed the cisa exam today. but i have found all the questions that were on the exam to be on this site.
Anonymous