Sample Questions from Certified Information Systems Auditor (CISA) by ISACA

Preview a few questions below — answers are revealed when you take the exam.

  1. A team needs to implement a new security framework for a multinational organization. The organization has diverse IT infrastructures across different regions. What approach should they take to ensure the framework is effective and compliant across all regions?

    • Conduct a comprehensive risk assessment for each region, identify unique threats and vulnerabilities, and tailor the security framework to address specific regional compliance requirements while maintaining a consistent global security policy.
    • Implement the security framework uniformly across all regions without considering regional differences, relying on the global security policy to address all compliance and security needs.
    • Focus on the most critical assets and implement the security framework only for those, assuming that the remaining assets will be protected by the overall security posture of the organization.
    • Outsource the implementation of the security framework to a third-party vendor, ensuring that the vendor has experience in multinational organizations and can handle regional compliance requirements.
  2. Identify the command used in Unix-based systems to display the current user's environment variables.

    • printenv
    • env
    • echo $ENV
    • showenv
  3. Consider the situation where an organization is experiencing frequent data breaches due to weak password policies. Which method solves it best?

    • Implementing a multi-factor authentication system combined with regular security awareness training for employees and enforcing a strong password policy with complexity requirements and periodic password changes.
    • Relying solely on complex password policies without additional security measures or employee training.
    • Using a password management tool that generates and stores complex passwords for users without enforcing any additional security practices.
    • Implementing a single sign-on (SSO) solution that eliminates the need for users to remember multiple passwords, assuming this will reduce the risk of data breaches.
  4. Which option best evaluates the effectiveness of an organization's incident response plan?

    • Conducting regular tabletop exercises that simulate various incident scenarios, reviewing the response times and actions taken, and identifying areas for improvement based on the outcomes of these exercises.
    • Assuming the incident response plan is effective if no incidents have occurred in the past year.
    • Relying on external audits to evaluate the incident response plan without conducting any internal assessments or simulations.
    • Focusing solely on the technical aspects of the incident response plan, such as the tools and technologies used, without considering the human and procedural elements.
  5. How should a professional assess the security posture of a cloud-based application?

    • Performing a comprehensive security assessment that includes reviewing the application's architecture, conducting vulnerability scans, assessing the cloud provider's security controls, and evaluating the organization's cloud security policies and practices.
    • Assuming the cloud provider is responsible for all security aspects and focusing only on the application's code and configuration.
    • Relying solely on the cloud provider's security certifications and compliance reports without conducting any additional assessments.
    • Conducting a security assessment only on the application's code and configuration, assuming that the cloud infrastructure is secure by default.