| Other CISA Certification Interview Questions |
| |
| Question | Asked @ | Answers |
| |
| To share data in a multivendor network environment, it is
essential to implement program-to-program communication.
With respect to program-to-program communication features
that can be implemented in this environment, which of the
following makes implementation and maintenance difficult?
A. User isolation
B. Controlled remote access
C. Transparent remote access
D. The network environments | | 1 |
| Capacity monitoring software is used to ensure:
A. maximum use of available capacity.
B. that future acquisitions meet user needs.
C. concurrent use by a large number of users.
D. continuity of efficient operations. | | 2 |
| Which of the following business recovery strategies would
require the least expenditure of funds?
A. Warm site facility
B. Empty shell facility
C. Hot site subscription
D. Reciprocal agreement | | 1 |
| What is a risk associated with attempting to control
physical access to sensitive areas, such as computer rooms,
through card keys, locks, etc.?
A. Unauthorized individuals wait for controlled doors to
open and walk in behind those authorized.
B. The contingency plan for the organization cannot
effectively test controlled access practices.
C. Access cards, keys, and pads can be easily duplicated
allowing easy compromise of the control.
D. Removing access for people no longer authorized is complex. | | 1 |
| An IS auditor performing an application maintenance audit
would review the log of program changes for the:
A. authorization for program changes.
B. creation date of a current object module.
C. number of program changes actually made.
D. creation date of a current source program. | | 1 |
| Which of the following would be considered an essential
feature of a network management system?
A. A graphical interface to map the network topology
B. Capacity to interact with the Internet to solve the problems
C. Connectivity to a help desk for advice on difficult issues
D. An export facility for piping data to spreadsheets | | 1 |
| The most common reason for the failure of information
systems to meet the needs of users is that:
A. user needs are constantly changing.
B. the growth of user requirements was forecast inaccurately.
C. the hardware system limits the number of concurrent users.
D. user participation in defining the system's requirements
was inadequate. | | 1 |
| Which of the following pairs of functions should not be
combined to provide proper segregation of duties?
A. Tape librarian and computer operator
B. Application programming and data entry
C. Systems analyst and database administrator
D. Security administrator and quality assurance | | 3 |
| Applying a retention date on a file will ensure that:
A. data cannot be read until the date is set.
B. data will not be deleted before that date.
C. backup copies are not retained after that date.
D. datasets having the same name are differentiated. | | 1 |
| An IS auditor conducting a review of software usage and
licensing discovers that numerous PCs contain unauthorized
software. Which of the following actions should the IS
auditor take?
A. Personally delete all copies of the unauthorized software.
B. Inform auditee of the unauthorized software, and follow
up to confirm deletion.
C. Report the use of the unauthorized software to auditee
management and the need to prevent recurrence.
D. Take no action, as it is a commonly accepted practice and
operations management is responsible for monitoring such use. | | 1 |
| Accountability for the maintenance of appropriate security
measures over information assets resides with the:
A. security administrator.
B. systems administrator.
C. data and systems owners.
D. systems operations group. | | 2 |
| Which of the following types of risks assumes an absence of
compensating controls in the area being reviewed?
A. Control risk
B. Detection risk
C. Inherent risk
D. Sampling risk | | 1 |
| Which of the following is the primary purpose for conducting
parallel testing?
A. To determine if the system is cost-effective.
B. To enable comprehensive unit and system testing.
C. To highlight errors in the program interfaces with files.
D. To ensure the new system meets user requirements. | | 1 |
| To determine which users can gain access to the privileged
supervisory state, which of the following should an IS
auditor review?
A. System access log files
B. Enabled access control software parameters
C. Logs of access control violations
D. System configuration files for control options used | | 1 |
| Connection-oriented protocols in the TCP/IP suite are
implemented in the:
A. transport layer.
B. application layer.
C. physical layer.
D. network layer. | | 1 |
| Which of the following components is responsible for the
collection of data in an intrusion detection system (IDS)?
A. Analyzer
B. Administration console
C. User interface
D. Sensor | | 1 |
| Which of the following functions would be acceptable for the
security administrator to perform in addition to his/her
normal functions?
A. Systems analyst
B. Quality assurance
C. Computer operator
D. Systems programmer | | 1 |
| One of the purposes of library control software is to allow:
A. programmers access to production source and object libraries.
B. batch program updating.
C. operators to update the control library with the
production version before testing is completed.
D. read-only access to source code. | | 1 |
| A company has implemented a new client-server enterprise
resource planning (ERP) system. Local branches transmit
customer orders to a central manufacturing facility. Which
of the following would BEST ensure that the orders are
entered accurately and the corresponding products are produced?
A. Verifying production to customer orders
B. Logging all customer orders in the ERP system
C. Using hash totals in the order transmitting process
D. Approving (production supervisor) orders prior to production | | 1 |
| The primary goal of a web site certificate is:
A. authentication of the web site to be surfed through.
B. authentication of the user who surfs through that site.
C. preventing surfing of the web site by hackers.
D. the same purpose as that of a digital certificate. | | 1 |
| |
| For more CISA Certification Interview Questions Click Here |