CISA Exam Question 166
Control self-assessments (CSAs) can be used to:
Correct Answer: B
Control self-assessment (CSA) is a process that allows business units to evaluate the effectiveness of internal controls. It is primarily used toestablish baselines(Option B) for measuring control effectiveness and risk management.
ISACA CISA Reference:CSA is a recognized internal control mechanism that supports risk assessment and control improvement.
Risk Implication:If CSAs are not conducted properly, organizations may lack visibility into weak controls, increasing exposure to risks.
Alternative Choices:
Option A:CSA does not focus on asset valuation.
Option C:Strategic business goals are assessed separately through governance processes.
Option D:CSA complements, but does not replace, formal audits.
ISACA CISA Reference:CSA is a recognized internal control mechanism that supports risk assessment and control improvement.
Risk Implication:If CSAs are not conducted properly, organizations may lack visibility into weak controls, increasing exposure to risks.
Alternative Choices:
Option A:CSA does not focus on asset valuation.
Option C:Strategic business goals are assessed separately through governance processes.
Option D:CSA complements, but does not replace, formal audits.
CISA Exam Question 167
Which of the following is an organization's BEST defense against malware?
Correct Answer: A
CISA Exam Question 168
Which of the following is MOST important for an IS auditor to validate when auditing network device management?
Correct Answer: C
The most important thing for an IS auditor to validate when auditing network device management is that all devices have current security patches assessed. This is because security patches are essential for fixing known vulnerabilities and preventing unauthorized access, data breaches, or denial-of-service attacks on the network devices. If the network devices are not patched regularly, they may expose the network to various cyber threats and compromise the confidentiality, integrity, and availability of the network services and data12.
Devices cannot be accessed through service accounts is not the most important thing to validate because service accounts are typically used for automated tasks or processes that require privileged access to network devices. Service accounts can be secured by using strong passwords, limiting their permissions, and monitoring their activities. However, service accounts alone do not protect the network devices from external or internal attacks that exploit unpatched vulnerabilities3.
Backup policies include device configuration files is not the most important thing to validate because backup policies are mainly used for restoring the network devices in case of failure, disaster, or corruption. Backup policies can help with recovering the network functionality and data, but they do not prevent the network devices from being compromised or attacked in the first place. Backup policies should be complemented by security policies that ensure the network devices are patched and protected4.
All devices are located within a protected network segment is not the most important thing to validate because network segmentation is a technique that divides the network into smaller subnets or zones based on different criteria, such as function, security level, or access control. Network segmentation can help isolate and contain the impact of a potential attack on a network device, but it does not prevent the attack from happening.
Network segmentation should be combined with security patching and other security measures to ensure the network devices are secure.
Devices cannot be accessed through service accounts is not the most important thing to validate because service accounts are typically used for automated tasks or processes that require privileged access to network devices. Service accounts can be secured by using strong passwords, limiting their permissions, and monitoring their activities. However, service accounts alone do not protect the network devices from external or internal attacks that exploit unpatched vulnerabilities3.
Backup policies include device configuration files is not the most important thing to validate because backup policies are mainly used for restoring the network devices in case of failure, disaster, or corruption. Backup policies can help with recovering the network functionality and data, but they do not prevent the network devices from being compromised or attacked in the first place. Backup policies should be complemented by security policies that ensure the network devices are patched and protected4.
All devices are located within a protected network segment is not the most important thing to validate because network segmentation is a technique that divides the network into smaller subnets or zones based on different criteria, such as function, security level, or access control. Network segmentation can help isolate and contain the impact of a potential attack on a network device, but it does not prevent the attack from happening.
Network segmentation should be combined with security patching and other security measures to ensure the network devices are secure.
CISA Exam Question 169
An IS auditor reviewing the threat assessment tor a data center would be MOST concerned if:
Correct Answer: C
An IS auditor reviewing the threat assessment for a data center would be most concerned if the exercise was completed by local management, because this could introduce bias, conflict of interest, or lack of expertise in the assessment process. A threat assessment is a systematic method of identifying and evaluating the potential threats that could affect the availability, integrity, or confidentiality of the data center and its assets. A threat assessmentshould be conducted by an independent and qualified team that has the necessary skills, knowledge, and experience to perform a comprehensive and objective analysis of the data center's environment, vulnerabilities, and risks1.
The other options are not as concerning as option C for an IS auditor reviewing the threat assessment for a data center. Option A, some of the identified threats are unlikely to occur, is not a problem as long as the likelihood and impact of each threat are properly estimated and prioritized. A threat assessment should consider all possible scenarios, even if they have a low probability of occurrence, to ensure that the data center is prepared for any eventuality2. Option B, all identified threats relate to external entities, is not a flaw as long as the assessment also considers internal threats, such as human errors, malicious insiders, or equipment failures. External threats are often more visible and severe than internal threats, butthey are not the only source of risk for a data center3. Option D, neighboring organizations' operations have been included, is not a mistake as long as the assessment also focuses on the data center's own operations. Neighboring organizations' operations may have an impact on the data center's security and availability, especially if they share physical or network infrastructure or resources. A threat assessmentshould take into account the interdependencies and interactions between the data center and its external environment4.
References:
ISACA, CISA Review Manual, 27th Edition, 2019
ISACA, CISA Review Questions, Answers & Explanations Database - 12 Month Subscription Data Center Threats and Vulnerabilities1 Datacenter threat, vulnerability, and risk assessment2 Data Centre Risk Assessment3
The other options are not as concerning as option C for an IS auditor reviewing the threat assessment for a data center. Option A, some of the identified threats are unlikely to occur, is not a problem as long as the likelihood and impact of each threat are properly estimated and prioritized. A threat assessment should consider all possible scenarios, even if they have a low probability of occurrence, to ensure that the data center is prepared for any eventuality2. Option B, all identified threats relate to external entities, is not a flaw as long as the assessment also considers internal threats, such as human errors, malicious insiders, or equipment failures. External threats are often more visible and severe than internal threats, butthey are not the only source of risk for a data center3. Option D, neighboring organizations' operations have been included, is not a mistake as long as the assessment also focuses on the data center's own operations. Neighboring organizations' operations may have an impact on the data center's security and availability, especially if they share physical or network infrastructure or resources. A threat assessmentshould take into account the interdependencies and interactions between the data center and its external environment4.
References:
ISACA, CISA Review Manual, 27th Edition, 2019
ISACA, CISA Review Questions, Answers & Explanations Database - 12 Month Subscription Data Center Threats and Vulnerabilities1 Datacenter threat, vulnerability, and risk assessment2 Data Centre Risk Assessment3
CISA Exam Question 170
Which of the following BEST facilitates strategic program management?
Correct Answer: C
The best option that facilitates strategic program management is aligning projects with business portfolios (option C). This is because:
Strategic program management is the coordinated planning, management, and execution of multiple related projects that are directed toward the same strategic goals12.
Aligning projects with business portfolios means ensuring that the projects within a program are aligned with the organization's strategic objectives, vision, and mission .
Aligning projects with business portfolios helps to prioritize the most valuable and impactful projects, optimize the allocation of resources, monitor the progress and performance of the program, and deliver the expected benefits and outcomes .
Implementing stage gates (option A) is a process of reviewing and approving projects at predefined points in their lifecycle to ensure that they meet the quality, scope, time, and cost criteria. While this can help to control and improve the project management process, it does not necessarily facilitate strategic program management, as it does not address the alignment of projects with business portfolios.
Establishing a quality assurance (QA) process (option B) is a process of ensuring that the project deliverables meet the quality standards and requirements of the stakeholders. While this can help to enhance the quality and satisfaction of the project outcomes, it does not necessarily facilitate strategic program management, as it does not address the alignment of projects with business portfolios.
Tracking key project milestones (option D) is a process of monitoring and reporting the completion of significant events or deliverables in a project. While this can help to measure and communicate the progress and status of the project, it does not necessarily facilitate strategic program management, as it does not address the alignment of projects with business portfolios.
Therefore, the best option that facilitates strategic program management is aligning projects with business portfolios (option C), as this ensures that the projects within a program are consistent with the organization's strategic goals and objectives.
References: 1: Program Management: The Key to Strategic Execution 2: The Ultimate Guide to Program Management [2023] * Asana : Project Portfolio Management - PMI : Aligning Projects with Strategy - Harvard Business Review : What Is Stage-Gate Process? - ProjectManager.com : Quality Assurance in Project Management - PMI : What Is a Milestone in Project Management? - TeamGantt
Strategic program management is the coordinated planning, management, and execution of multiple related projects that are directed toward the same strategic goals12.
Aligning projects with business portfolios means ensuring that the projects within a program are aligned with the organization's strategic objectives, vision, and mission .
Aligning projects with business portfolios helps to prioritize the most valuable and impactful projects, optimize the allocation of resources, monitor the progress and performance of the program, and deliver the expected benefits and outcomes .
Implementing stage gates (option A) is a process of reviewing and approving projects at predefined points in their lifecycle to ensure that they meet the quality, scope, time, and cost criteria. While this can help to control and improve the project management process, it does not necessarily facilitate strategic program management, as it does not address the alignment of projects with business portfolios.
Establishing a quality assurance (QA) process (option B) is a process of ensuring that the project deliverables meet the quality standards and requirements of the stakeholders. While this can help to enhance the quality and satisfaction of the project outcomes, it does not necessarily facilitate strategic program management, as it does not address the alignment of projects with business portfolios.
Tracking key project milestones (option D) is a process of monitoring and reporting the completion of significant events or deliverables in a project. While this can help to measure and communicate the progress and status of the project, it does not necessarily facilitate strategic program management, as it does not address the alignment of projects with business portfolios.
Therefore, the best option that facilitates strategic program management is aligning projects with business portfolios (option C), as this ensures that the projects within a program are consistent with the organization's strategic goals and objectives.
References: 1: Program Management: The Key to Strategic Execution 2: The Ultimate Guide to Program Management [2023] * Asana : Project Portfolio Management - PMI : Aligning Projects with Strategy - Harvard Business Review : What Is Stage-Gate Process? - ProjectManager.com : Quality Assurance in Project Management - PMI : What Is a Milestone in Project Management? - TeamGantt
- Other Version
- 1066ISACA.CISA.v2026-09-25.q633
- 4920ISACA.CISA.v2025-12-09.q630
- 19670ISACA.CISA.v2025-06-20.q647
- 7934ISACA.CISA.v2025-06-11.q606
- 5115ISACA.CISA.v2023-03-04.q272
- 3891ISACA.CISA.v2022-10-31.q203
- 3659ISACA.CISA.v2022-03-29.q126
- 123ISACA.Examprepaway.CISA.v2022-02-10.by.barret.126q.pdf
- 11352ISACA.CISA.v2021-11-29.q567
- 36ISACA.Actualvce.CISA.v2021-08-31.by.ralap.101q.pdf
- Latest Upload
- 169PECB.ISO-9001-Lead-Auditor.v2026-09-29.q115
- 146Oracle.1Z0-1080-26.v2026-09-29.q59
- 154Microsoft.GH-500.v2026-09-29.q56
- 170Splunk.SPLK-1003.v2026-09-29.q96
- 277ISQI.CTFL_Syll_4.0.v2026-09-28.q175
- 205Cisco.300-445.v2026-09-28.q61
- 183Hitachi.HCE-5910.v2026-09-28.q53
- 136Peoplecert.DevOps-Leader.v2026-09-28.q19
- 245Microsoft.SC-401.v2026-09-28.q138
- 299Huawei.H12-821_V1.0.v2026-09-28.q183
[×]
Download PDF File
Enter your email address to download ISACA.CISA.v2025-12-02.q704 Practice Test
