How would an IS auditor BEST determine the effectiveness of a security awareness program?
Correct Answer: A
Comprehensive and Detailed Step-by-Step Explanation: Social engineering tests are the most effective way toassess real-world security awarenessby measuring employees' ability to recognize and resist security threats. Review the Results of Social Engineering Tests (Correct Answer - A) Simulated phishing attacks and pretexting exercises measure actual employee behavior. Provides actionable insights into weaknesses in security awareness. Example:If employees frequently click on phishing emails, the awareness program is ineffective. Evaluate Management Survey Results (Incorrect - B) Management perception is subjective and does not reflect actual employee behavior. Interview Employees (Incorrect - C) Employees may provide inaccurate or rehearsed responses. Review Security Training Quiz Results (Incorrect - D) Tests knowledge but does not measure practical application. References: ISACA CISA Review Manual NIST 800-53 (Security Awareness and Training) ISO 27001: Security Awareness Control
CISA Exam Question 267
What is the Most critical finding when reviewing an organization's information security management?
Correct Answer: C
The most critical finding when reviewing an organization's information security management is no periodic assessments to identify threats and vulnerabilities. Periodic assessments are essential for ensuring that the organization's information security policies, procedures, standards, and controls are aligned with the current and emerging risks and threats that may affect its information assets. Without periodic assessments, the organization may not be aware of its actual security posture, gaps, or weaknesses, and may not be able to take appropriate measures to mitigate or prevent potential security incidents. No dedicated security officer, no official charter for the information security management system, and no employee awareness training and education program are also findings that may indicate some deficiencies in the organization's information security management, but they are not as critical as no periodic assessments to identify threats and vulnerabilities. References: ISACA CISA Review Manual 27th Edition, page 343.
CISA Exam Question 268
During an operational audit on the procurement department, the audit team encounters a key system that uses an artificial intelligence (Al) algorithm. The audit team does not have the necessary knowledge to proceed with the audit. Which of the following is the BEST way to handle this situation?
Correct Answer: D
If the audit team lacks the necessary knowledge to audit a system that uses an AI algorithm, engaging external consultants who have audit experience and knowledge of AI would be the best approach12. These consultants can provide the expertise needed to effectively audit the AI system12. This approach ensures that the audit is conducted thoroughly and accurately, without requiring the audit team to acquire new skills or knowledge12. References: Auditing Guidelines for Artificial Intelligence - ISACA An In-Depth Guide To Audit AI Models - Censius
CISA Exam Question 269
Demonstrated support from which of the following roles in an organization has the MOST influence over information security governance?
Correct Answer: C
Information security governance is the subset of enterprise governance that provides strategic direction, ensures that objectives are achieved, manages risk appropriately, uses organizational resources responsibly, and monitors the success or failure of the enterprise security program. Information security governance is essential for ensuring that an organization's information assets are protected from internal and external threats, and that the organization complies with relevant laws and standards. Demonstrated support from which of the following roles in an organization has the most influence over information security governance? The answer is C, the board of directors. The board of directors is the highest governing body of an organization, responsible for overseeing its strategic direction, performance, and accountability. The board of directors sets the tone at the top for information security governance by: Establishing a clear vision, mission, and values for information security Approving and reviewing information security policies and standards Allocating sufficient resources and budget for information security Appointing and empowering a chief information security officer (CISO) or equivalent role Holding management accountable for information security performance and compliance Communicating and promoting information security awareness and culture The board of directors has the most influence over information security governance because it has the ultimate authority and responsibility for ensuring that information security is aligned with the organization's business objectives, risks, and stakeholder expectations. References: 10: What is Information Security Governance? - RiskOptics - Reciprocity 11: Information Security Governance and Risk Management | Moss Adams 12: ISO/IEC 27014:2020 - Information security, cybersecurity and privacy ...
CISA Exam Question 270
Which of the following is the PRIMARY role of the IS auditor m an organization's information classification process?
Correct Answer: B
Validating that assets are protected according to assigned classification is the primary role of the IS auditor in an organization's information classification process. An IS auditor should evaluate whether the information security controls are adequate and effective in safeguarding the information assets based on their classification levels. The other options are not the primary role of the IS auditor, but rather the responsibilities of the information owners, custodians, or security managers. References: * CISA Review Manual (Digital Version), Chapter 6, Section 6.2.31 * CISA Review Questions, Answers & Explanations Database, Question ID 206