Inspirational journeys

Follow the stories of academics and their research expeditions

CISA—Certified Information Systems Auditor - Part 140

Mary Smith

Sat, 24 May 2025

CISA—Certified Information Systems Auditor - Part 140

1. Proper segregation of duties prohibits a system analyst from performing quality-assurance functions. True or false?

A) True
B) False
C)
D)



2. What should an IS auditor do if he or she observes that project-approval procedures do not exist?

A) Advise senior management to invest in project-management training for the staff
B) Create project-approval procedures for future project implementations
C) Assign project leaders
D) Recommend to management that formal approval procedures be adopted and documented



3. Who is ultimately accountable for the development of an IS security policy?

A) The board of directors
B) Middle management
C) Security administrators
D) Network administrators



4. Proper segregation of duties normally does not prohibit a LAN administrator from also having programming responsibilities. True or false?

A) True
B) False
C)
D)



5. A core tenant of an IS strategy is that it must:

A) Be inexpensive
B) Be protected as sensitive confidential information
C) Protect information confidentiality, integrity, and availability
D) Support the business objectives of the organization



1. Right Answer: A
Explanation: Proper segregation of duties prohibits a system analyst from performing quality-assurance functions.

2. Right Answer: D
Explanation: If an IS auditor observes that project-approval procedures do not exist, the IS auditor should recommend to management that formal approval procedures be adopted and documented.

3. Right Answer: A
Explanation: The board of directors is ultimately accountable for the development of an IS security policy.

4. Right Answer: B
Explanation: Proper segregation of duties normally prohibits a LAN administrator from also having programming responsibilities.

5. Right Answer: D
Explanation: Above all else, an IS strategy must support the business objectives of the organization.

0 Comments

Leave a comment