FreeQAs
 Request Exam  Contact
  • Home
  • View All Exams
  • New QA's
  • Upload
PRACTICE EXAMS:
  • Oracle
  • Fortinet
  • Juniper
  • Microsoft
  • Cisco
  • Citrix
  • CompTIA
  • VMware
  • SAP
  • EMC
  • PMI
  • HP
  • Salesforce
  • Other
  • Oracle
    Oracle
  • Fortinet
    Fortinet
  • Juniper
    Juniper
  • Microsoft
    Microsoft
  • Cisco
    Cisco
  • Citrix
    Citrix
  • CompTIA
    CompTIA
  • VMware
    VMware
  • SAP
    SAP
  • EMC
    EMC
  • PMI
    PMI
  • HP
    HP
  • Salesforce
    Salesforce
  1. Home
  2. ISACA Certification
  3. CISA Exam
  4. ISACA.CISA.v2023-11-11.q163 Dumps
  • ««
  • «
  • …
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • …
  • »
  • »»
Download Now

Question 101

At the end of the testing phase of software development, an IS auditor observes that an intermittent software error has not been corrected. No action has been taken to resolve the error. The IS auditor should:

Correct Answer: C
Explanation/Reference:
Explanation:
When an IS auditor observes such conditions, it is best to fully apprise the auditee and suggest that further problem resolutions be attempted. Recording it as a minor error and leaving it to the auditee's discretion would be inappropriate, and neglecting the error would indicate that the auditor has not taken steps to further probe the issue to its logical end.
insert code

Question 102

Which of the following is the BEST type of program for an organization to implement to aggregate,
correlate and store different log and event files, and then produce weekly and monthly reports for IS
auditors?

Correct Answer: C
Section: Protection of Information Assets
Explanation:
A log management tool is a product designed to aggregate events from many log files (with distinct formats
and from different sources), store them and typically correlate them offline to produce many reports (e.g.,
exception reports showing different statistics including anomalies and suspicious activities), and to answer
time-based queries (e.g., how many users have entered the system between 2 a.m. and 4 a.m. over the
past three weeks?). A SIEM product has some similar features. It correlates events from log files, but does
it online and normally is not oriented to storing many weeks of historical information and producing audit
reports. A correlation engine is part of a SIEM product. It is oriented to making an online correlation of
events. An extract, transform, load (ETL) is part of a business intelligence system, dedicated to extracting
operational or production data, transforming that data and loading them to a central repository (data
warehouse or data mart); an ETL does not correlate data or produce reports, and normally it does not have
extractors to read log file formats.
insert code

Question 103

Processing controls ensure that data is accurate and complete, and is processed only through which of the following?

Correct Answer: B
Explanation/Reference:
Explanation:
Processing controls ensure that data is accurate and complete, and is processed only through authorized routines.
insert code

Question 104

What should an IS auditor do if he or she observes that project-approval procedures do not exist?

Correct Answer: D
Explanation/Reference:
If an IS auditor observes that project-approval procedures do not exist, the IS auditor should recommend to management that formal approval procedures be adopted and documented.
insert code

Question 105

Which of the following is a practice that should be incorporated into the plan for testing disaster recovery procedures?

Correct Answer: C
Recovery managers should be rotated to ensure the experience of the recovery plan is spread among the managers. Clients may be involved but not necessarily in every case. Not all technical staff should be involved in each test. Remote or offsite backup should always be used.
insert code
  • ««
  • «
  • …
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • …
  • »
  • »»
[×]

Download PDF File

Enter your email address to download ISACA.CISA.v2023-11-11.q163 Dumps

Email:

FreeQAs

Our website provides the Largest and the most Latest vendors Certification Exam materials around the world.

Using dumps we provide to Pass the Exam, we has the Valid Dumps with passing guranteed just which you need.

  • DMCA
  • About
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
©2026 FreeQAs

www.freeqas.com materials do not contain actual questions and answers from Cisco's certification exams.