| Other CISA Certification Interview Questions |
| |
| Question | Asked @ | Answers |
| |
| Which of the following would an IS auditor expect to find in
a console log?
A. Names of system users
B. Shift supervisor identification
C. System errors
D. Data edit errors | | 1 |
| Which of the following groups should assume ownership of a
systems development project and the resulting system?
A. User management
B. Senior management
C. Project steering committee
D. Systems development management | | 1 |
| An enterprise has established a steering committee to
oversee its e-business program. The steering committee would
MOST likely be involved in the:
A. documentation of requirements.
B. escalation of project issues.
C. design of interface controls.
D. specification of reports. | | 1 |
| In large corporate networks having supply partners across
the globe, network traffic may continue to rise. The
infrastructure components in such environments should be
scalable. Which of the following firewall architectures
limits future scalability?
A. Appliances
B. Operating system based
C. Host based
D. Demilitarized | | 1 |
| Which of the following concerns associated with the World
Wide Web would be addressed by a firewall?
A. Unauthorized access from outside the organization
B. Unauthorized access from within the organization
C. A delay in Internet connectivity
D. A delay in downloading using file transfer protocol (FTP) | | 1 |
| Passwords should be:
A. assigned by the security administrator.
B. changed every 30 days at the discretion of the user.
C. reused often to ensure the user does not forget the password.
D. displayed on the screen so that the user can ensure that
it has been entered properly. | | 2 |
| An organization is proposing to install a single sign-on
facility giving access to all systems. The organization
should be aware that:
A. Maximum unauthorized access would be possible if a
password is disclosed.
B. User access rights would be restricted by the additional
security parameters.
C. The security administrator?s workload would increase.
D. User access rights would be increased. | | 1 |
| The PRIMARY reason for replacing checks (cheques) with EFT
systems in the accounts payable area is to:
A. make the payment process more efficient.
B. comply with international EFT banking standards.
C. decrease the number of paper-based payment forms.
D. reduce the risk of unauthorized changes to payment
transactions. | | 1 |
| An organization is introducing a single sign-on (SSO)
system. Under the SSO system, users will be required to
enter only one user ID and password for access to all
application systems. Under the SSO system, unauthorized access:
A. is less likely.
B. is more likely.
C. will have a greater impact.
D. will have a smaller impact. | | 1 |
| A distinction that can be made between compliance testing
and substantive testing is that compliance testing tests:
A. details, while substantive testing tests procedures.
B. controls, while substantive testing tests details.
C. plans, while substantive testing tests procedures.
D. for regulatory requirements, while substantive testing
tests validations. | | 1 |
| Which of the following IS functions may be performed by the
same individual, without compromising on control or
violating segregation of duties?
A. Job control analyst and applications programmer
B. Mainframe operator and system programmer
C. Change/problem and quality control administrator
D. Applications and system programmer | | 1 |
| Detection risk refers to:
A. concluding that material errors do not exist, when in
fact they do.
B. controls that fail to detect an error.
C. controls that detect high-risk errors.
D. detecting an error but failing to report it. | | 1 |
| Which of the following methods of providing
telecommunication continuity involves routing traffic
through split- or duplicate-cable facilities?
A. Diverse routing
B. Alternative routing
C. Redundancy
D. Long haul network diversity | | 1 |
| Which of the following functions would be acceptable for the
security administrator to perform in addition to his/her
normal functions?
A. Systems analyst
B. Quality assurance
C. Computer operator
D. Systems programmer | | 1 |
| Which of the following issues should be included in the
business continuity plan?
A. The staff required to maintain critical business
functions in the short, medium and long term
B. The potential for a natural disaster to occur, such as an
earthquake
C. Disastrous events impacting information systems
processing and end-user functions
D. A risk analysis that considers systems malfunctions,
accidental file deletions or other failures | | 1 |
| Which of the following findings would an IS auditor be MOST
concerned about when performing an audit of backup and
recovery and the offsite storage vault?
A. There are three individuals with a key to enter the area.
B. Paper documents also are stored in the offsite vault.
C. Data files, which are stored in the vault, are synchronized.
D. The offsite vault is located in a separate facility. | | 1 |
| Which of the following is a substantive audit test?
A. Verifying that a management check has been performed
regularly
B. Observing that user IDs and passwords are required to
sign on the computer
C. Reviewing reports listing short shipments of goods received
D. Reviewing an aged trial balance of accounts receivable | | 1 |
| Which of the following can identify attacks and penetration
attempts to a network?
A. Firewall
B. Packet filters
C. Stateful inspection
D. Intrusion detection system (IDs) | | 1 |
| Which of the following would an IS auditor consider to be
the MOST helpful when evaluating the effectiveness and
adequacy of a computer preventive maintenance program?
A. A system downtime log
B. Vendors' reliability figures
C. Regularly scheduled maintenance log
D. A written preventive maintenance schedule | | 1 |
| Which of the following is the primary purpose for conducting
parallel testing?
A. To determine if the system is cost-effective.
B. To enable comprehensive unit and system testing.
C. To highlight errors in the program interfaces with files.
D. To ensure the new system meets user requirements. | | 1 |
| |
| For more CISA Certification Interview Questions Click Here |