Which of the following is the MAIN responsibility of the IT steering committee?
Correct Answer: A
This means that the IT steering committee is responsible for ensuring that the IT strategy aligns with and supports the business strategy, vision, and goals of the organization. The IT steering committee is also responsible for overseeing and approving major IT initiatives, projects, and investments, and allocating resources and priorities accordingly12. Developing and assessing the IT security strategy (B) is not the main responsibility of the IT steering committee, but rather a specific aspect of the IT strategy that may be delegated to a subcommittee or a dedicated security function. The IT steering committee may provide guidance and oversight for the IT security strategy, but it is not directly involved in developing and assessing it12. Implementing processes to integrate security with business objectives is not the main responsibility of the IT steering committee, but rather an operational task that may be performed by the IT management and staff. The IT steering committee may monitor and evaluate the effectiveness of the security processes, but it is not directly involved in implementing them12. Developing and implementing the secure system development framework (D) is not the main responsibility of the IT steering committee, but rather a technical task that may be performed by the IT developers and engineers. The IT steering committee may approve and endorse the secure system development framework, but it is not directly involved in developing and implementing it12.
CISA Exam Question 522
A characteristic of a digital signature is that it
Correct Answer: B
A digital signature is a specific type of e-signature that is backed by a digital certificate. A digital certificate is a document that contains the public key of a signer and is issued by a trusted third party called a certificate authority (CA). A digital signature provides proof of the identity of the signer and the integrity of the signed document. A characteristic of a digital signature is that it is unique to the message. This means that a digital signature cannot be copied from one document to another without being detected as invalid. A digital signature is created by applying a mathematical function called a hashing algorithm to the document. A hashing algorithm produces a fixed-length output called a hash or digest from any input data. The hash is unique to the input data; any change in the input data will result in a different hash. The signer then encrypts the hash with their private key (a secret key that only they know) to create the digital signature. The encrypted hash is attached to the document as the digital signature. The recipient of the document can verify the digital signature by decrypting it with the signer's public key (a key that is publicly available and matches the private key) to obtain the hash. The recipient then applies the same hashing algorithm to the document to generate another hash. The recipient then compares the two hashes; if they match, it means that the document has not been altered and that the signer is authentic. Therefore, a digital signature is unique to the message because it is derived from the hash of the message, which is unique to the message. References: * 7: Free Online Signature Generator (Type or Draw) | Signaturely * 8: What are digital signatures and certificates? | Acrobat Sign - Adobe * 9: eSign PDF with Electronic Signature Free Online - Smallpdf
CISA Exam Question 523
Which of the following is the PRIMARY purpose of a rollback plan for a system change?
Correct Answer: A
CISA Exam Question 524
Which of the following is MOST appropriate to review when determining if the work completed on an IT project is in alignment with budgeted costs?
Correct Answer: B
EVA is a project management technique that measures the performance of a project by comparing the actual work completed, the actual costs incurred, and the planned costs for the work scheduled. EVA can help determine if the project is on track, ahead of schedule, or behind schedule, and if the project is under budget, over budget, or on budget. EVA can also help forecast the final cost and schedule of the project based on the current performance. References ISACA CISA Review Manual, 27th Edition, page 255 18. Project Completion - Project Management - 2nd Edition How to Measure Project Success | Smartsheet
CISA Exam Question 525
Which of the following is the PRIMARY objective of enterprise architecture (EA)?