| Other CISA Certification Interview Questions |
| |
| Question | Asked @ | Answers |
| |
| Disaster recovery planning for a company's computer system
usually focuses on:
A. operations turnover procedures.
B. strategic long-range planning.
C. the probability that a disaster will occur.
D. alternative procedures to process transactions. | | 1 |
| A decision support system (DSS):
A. is aimed at solving highly structured problems.
B. combines the use of models with nontraditional data
access and retrieval functions.
C. emphasizes flexibility in the decision making approach of
users.
D. supports only structured decision-making tasks. | | 1 |
| The initial step in establishing an information security
program is the:
A. development and implementation of an information security
standards manual.
B. performance of a comprehensive security control review by
the IS auditor.
C. adoption of a corporate information security policy
statement.
D. purchase of security access control software. | | 2 |
| Which of the following message services provides the
strongest protection that a specific action has occurred?
A. Proof of delivery
B. Nonrepudiation
C. Proof of submission
D. Message origin authentication | | 1 |
| Creation of an electronic signature:
A. encrypts the message.
B. verifies where the message came from.
C. cannot be compromised when using a private key.
D. cannot be used with e-mail systems. | | 1 |
| Confidential data stored on a laptop is BEST protected by:
A. storage on optical disks.
B. logon ID and password.
C. data encryption.
D. physical locks. | | 1 |
| Which of the following tests performed by an IS auditor
would be the MOST effective in determining compliance with
an organization's change control procedures?
A. Review software migration records and verify approvals.
B. Identify changes that have occurred and verify approvals.
C. Review change control documentation and verify approvals.
D. Ensure that only appropriate staff can migrate changes
into production. | | 1 |
| Which of the following is a technique that could be used to
capture network user passwords?
A. Encryption
B. Sniffing
C. Spoofing
D. A signed document cannot be altered. | | 1 |
| The responsibilities of a disaster recovery relocation team
include:
A. obtaining, packaging and shipping media and records to
the recovery facilities, as well as establishing and
overseeing an offsite storage schedule.
B. locating a recovery site if one has not been
predetermined and coordinating the transport of company
employees to the recovery site.
C. managing the relocation project and conducting a more
detailed assessment of the damage to the facilities and
equipment.
D. coordinating the process of moving from the hot site to a
new location or to the restored original location. | | 1 |
| A decrease in amplitude as a signal propagates along a
transmission medium is known as:
A. noise.
B. crosstalk.
C. attenuation.
D. delay distortion. | | 1 |
| An IS auditor needs to link his/her microcomputer to a
mainframe system that uses binary synchronous data
communications with block data transmission. However, the IS
auditor's microcomputer, as presently configured, is capable
of only asynchronous ASCII character data communications.
Which of the following must be added to the IS auditor's
computer to enable it to communicate with the mainframe system?
A. Buffer capacity and parallel port
B. Network controller and buffer capacity
C. Parallel port and protocol conversion
D. Protocol conversion and buffer capability | | 1 |
| An IS auditor should be able to identify and evaluate
various types of risks and their potential effects. Which of
the following risks is associated with authorized program
exits (trap doors)?
A. Inherent
B. Detection
C. Audit
D. Error | | 2 |
| During which phase of a system development process should an
IS auditor first raise the issue of application controls?
A. Construction
B. System design
C. Acceptance testing
D. Functional specification | | 1 |
| Which of the following hardware devices relieves the central
computer from performing network control, format conversion
and message handling tasks?
A. Spool
B. Cluster controller
C. Protocol converter
D. Front end processor | | 1 |
| An offsite information processing facility having electrical
wiring, air conditioning and flooring, but no computer or
communications equipment is a:
A. cold site.
B. warm site.
C. dial-up site.
D. duplicate processing facility. | | 1 |
| The BEST method of proving the accuracy of a system tax
calculation is by:
A. detailed visual review and analysis of the source code of
the calculation programs.
B. recreating program logic using generalized audit software
to calculate monthly totals.
C. preparing simulated transactions for processing and
comparing the results to predetermined results.
D. automatic flowcharting and analysis of the source code of
the calculation programs. | | 2 |
| During a post-implementation review of an enterprise
resource management system, an IS auditor would MOST likely:
A. review access control configuration.
B. evaluate interface testing.
C. review detailed design documentation.
D. evaluate system testing. | | 2 |
| Many IT projects experience problems because the development
time and/or resource requirements are underestimated. Which
of the following techniques would provide the GREATEST
assistance in developing an estimate of project duration?
A. Function point analysis
B. PERT chart
C. Rapid application development
D. Object-oriented system development | | 1 |
| Which of the following functions should be performed by the
application owners to ensure an adequate segregation of
duties between IS and end users?
A. System analysis
B. Authorization of access to data
C. Application programming
D. Data administration | | 1 |
| Which of the following would an IS auditor place LEAST
reliance on when determining management's effectiveness in
communicating information systems policies to appropriate
personnel?
A. Interviews with user and IS personnel
B. Minutes of IS steering committee meetings
C. User department systems and procedures manuals
D.Information processing facilities operations and
procedures manuals | | 1 |
| |
| For more CISA Certification Interview Questions Click Here |