Inspirational journeys

Follow the stories of academics and their research expeditions

CISA—Certified Information Systems Auditor - Part 386

Mary Smith

Wed, 18 Jun 2025

CISA—Certified Information Systems Auditor - Part 386

1. As part of business continuity planning, which of the following is MOST important to include in a business impact analysis?

A) Define a risk appetite.
B) Assess risk of moving significant applications to the cloud.
C) Assess recovery scenarios.
D) Assess threats to the organization.



2. Which of the following is the MOST important reason for updating and retesting a business continuity plan?

A) Staff turnover
B) Emerging technology
C) Significant business change
D) Matching industry best practices



3. When developing a business continuity plan (BCP), which of the following should be performed FIRST?

A) Develop business continuity training
B) Classify operations
C) Conduct a business impact analysis (BIA)
D) Establish a disaster recovery plan (DRP)



4. An organization has outsourced its data leakage monitoring to an Internet service provider (ISP). Which of the following is the BEST way for an IS auditor to determine the effectiveness of this service?

A) Verify the ISP has staff to deal with data leakage
B) Review the ISP's external audit report
C) Review the data leakage clause in the SLA
D) Simulate a data leakage incident



5. Which of the following would be the GREATEST concern to an IS auditor reviewing a critical spreadsheet during a financial audit?

A) Periodic access reviews are manually performed.
B) Changes to the file are not always documented.
C) Access requests are manually processed.
D) A copy current validated file is not available.



1. Right Answer: D
Explanation:

2. Right Answer: C
Explanation:

3. Right Answer: C
Explanation:

4. Right Answer: C
Explanation:

5. Right Answer: B
Explanation:

0 Comments

Leave a comment