CISA Exam Question 296
Which of the following establishes the PRIMARY difference between a business continuity plan (BCP) and a disaster recovery plan (DRP)?
Correct Answer: C
The primary difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP) lies in their timeframe for activation and overall scope.
* BCP (Business Continuity Plan):
* Focuses on ensuring that critical business processes continue operating during and after a disruption.
* It includes strategies for maintaining operations (e.g., alternative work locations, manual procedures, supplier dependencies).
* Activated immediately when a disruption occurs to keep the business running.
* DRP (Disaster Recovery Plan):
* Primarily focuses on the recovery of IT systems and infrastructure after a disruption.
* It includes steps for restoring data, servers, and applications to bring IT operations back to normal.
* Activated after the disaster event to restore normal IT operations.
The timeframe for activation is the key difference because:
* BCP is implemented immediately to ensure business continuity.
* DRP is implemented after the disaster to restore IT operations.
* A. The annual testing requirements # Both BCP and DRP require regular testing, so this is not the key differentiator.
* B. The focus on system recovery # Only DRP focuses on system recovery, but the BCP covers more than just IT. The key difference is still the timeframe.
* D. The involvement of senior management # Senior management is involved in both plans, so this is not the primary distinction.
References:ISACA CISA Review Manual, 28th Edition, Chapter 4: Information Systems Operations and Business Resilience
* BCP (Business Continuity Plan):
* Focuses on ensuring that critical business processes continue operating during and after a disruption.
* It includes strategies for maintaining operations (e.g., alternative work locations, manual procedures, supplier dependencies).
* Activated immediately when a disruption occurs to keep the business running.
* DRP (Disaster Recovery Plan):
* Primarily focuses on the recovery of IT systems and infrastructure after a disruption.
* It includes steps for restoring data, servers, and applications to bring IT operations back to normal.
* Activated after the disaster event to restore normal IT operations.
The timeframe for activation is the key difference because:
* BCP is implemented immediately to ensure business continuity.
* DRP is implemented after the disaster to restore IT operations.
* A. The annual testing requirements # Both BCP and DRP require regular testing, so this is not the key differentiator.
* B. The focus on system recovery # Only DRP focuses on system recovery, but the BCP covers more than just IT. The key difference is still the timeframe.
* D. The involvement of senior management # Senior management is involved in both plans, so this is not the primary distinction.
References:ISACA CISA Review Manual, 28th Edition, Chapter 4: Information Systems Operations and Business Resilience
CISA Exam Question 297
Which of the following is the PRIMARY advantage of using visualization technology for corporate applications?
Correct Answer: B
Visualization technology is the use of software and hardware to create graphical representations of data, such as charts, graphs, maps, images, etc. Visualization technology can help users to understand, analyze, and communicate complex and large amounts of data in an intuitive and engaging way1.
One of the primary advantages of using visualization technology for corporate applications is that it can improve the utilization of resources, such as time, money, human capital, and physical assets. Some of the ways that visualization technology can achieve this are:
Visualization technology can help users to quickly and easily explore, filter, and interact with data, reducing the need for manual data processing and analysis1. This can save time and effort for both data producers and consumers, and allow them to focus on more value-added tasks.
Visualization technology can help users to discover patterns, trends, outliers, correlations, and causations in data that may otherwise be hidden or overlooked in traditional reports or tables1. This can enable users to make better and faster decisions based on data-driven insights, and optimize their strategies and actions accordingly.
Visualization technology can help users to communicate and share data more effectively and persuasively with different audiences, such as customers, partners,investors, regulators, etc1. This can enhance the reputation and credibility of the organization, and foster collaboration and innovation among stakeholders.
Visualization technology can help users to monitor and measure the performance and impact of their activities, products, services, or processes1. This can help users to identify problems or opportunities for improvement, and adjust their plans or actions accordingly.
Visualization technology can help users to create engaging and interactive experiences for their customers or end-users1. This can increase customer satisfaction and loyalty, and generate more revenue or value for the organization.
Therefore, using visualization technology for corporate applications can help organizations to better utilize their resources and achieve their goals.
References:
ISACA, CISA Review Manual, 27th Edition, 2019
ISACA, CISA Review Questions, Answers & Explanations Database - 12 Month Subscription TechRadar Blog, Best data visualization tools of 20232 IBM Blog, What is Data Visualization?3 TDWI Blog, Data Visualization Technology4 Tableau Blog, What are the advantages and disadvantagesof data visualization?
One of the primary advantages of using visualization technology for corporate applications is that it can improve the utilization of resources, such as time, money, human capital, and physical assets. Some of the ways that visualization technology can achieve this are:
Visualization technology can help users to quickly and easily explore, filter, and interact with data, reducing the need for manual data processing and analysis1. This can save time and effort for both data producers and consumers, and allow them to focus on more value-added tasks.
Visualization technology can help users to discover patterns, trends, outliers, correlations, and causations in data that may otherwise be hidden or overlooked in traditional reports or tables1. This can enable users to make better and faster decisions based on data-driven insights, and optimize their strategies and actions accordingly.
Visualization technology can help users to communicate and share data more effectively and persuasively with different audiences, such as customers, partners,investors, regulators, etc1. This can enhance the reputation and credibility of the organization, and foster collaboration and innovation among stakeholders.
Visualization technology can help users to monitor and measure the performance and impact of their activities, products, services, or processes1. This can help users to identify problems or opportunities for improvement, and adjust their plans or actions accordingly.
Visualization technology can help users to create engaging and interactive experiences for their customers or end-users1. This can increase customer satisfaction and loyalty, and generate more revenue or value for the organization.
Therefore, using visualization technology for corporate applications can help organizations to better utilize their resources and achieve their goals.
References:
ISACA, CISA Review Manual, 27th Edition, 2019
ISACA, CISA Review Questions, Answers & Explanations Database - 12 Month Subscription TechRadar Blog, Best data visualization tools of 20232 IBM Blog, What is Data Visualization?3 TDWI Blog, Data Visualization Technology4 Tableau Blog, What are the advantages and disadvantagesof data visualization?
CISA Exam Question 298
Which of the following provides an IS auditor assurance that the interface between a point-of-sale (POS) system and the general ledger is transferring sales data completely and accurately?
Correct Answer: A
The best option to provide an IS auditor assurance that the interface between a point-of-sale (POS) system and the general ledger is transferring sales data completely and accurately is A. Electronic copies of customer sales receipts are maintained. Electronic copies of customer sales receipts are records of the transactions that occurred at the POS system, which can be compared with the data transferred to the general ledger. This can help detect any errors, omissions, or discrepancies in the data transfer process and ensure that the sales data is complete and accurate.
The other options are not as effective as A in providing assurance that the interface between the POS system and the general ledger is transferring sales data completely and accurately. B. Monthly bank statements are reconciled without exception. Monthly bank statements are records of the cash inflows and outflows of the organization, which may not match with the sales data recorded by the POS system and the general ledger.
For example, there may be delays, discounts, returns, or refundsthat affect the cash flow but not the sales revenue. Therefore, reconciling monthly bank statements without exception does not necessarily mean that the sales data is complete and accurate. C. Nightly batch processing has been replaced with real-time processing. Nightly batch processing is a method of transferring data from the POS system to the general ledger in batches at a scheduled time, usually at night. Real-time processing is a method of transferring data from the POS system to the general ledger as soon as the transactions occur. Real-time processing may improve the timeliness and efficiency of the data transfer process, but it does not guarantee that the sales data is complete and accurate. There may still be errors, omissions, or discrepancies in the data transfer process that need to be detected and corrected. D. The data transferred over the POS interface is encrypted.
Encryption is a process of transforming data into an unreadable form using a secret key or algorithm, so that only authorized parties can access the original data. Encryption protects the confidentiality and security of the data transferred over the POS interface, but it does not ensure that the sales data is complete and accurate.
There may still be errors, omissions, or discrepancies in the data transfer process that need to be detected and corrected.
References:
ISACA, CISA Review Manual, 27th Edition, 2019, p. 2471
ISACA, CISA Review Questions, Answers & Explanations Database - 12 Month Subscription2 Sales Audit Overview - Oracle3 Notes on Audit of Ledgers - Guidelines to Auditors - Accountlearning
The other options are not as effective as A in providing assurance that the interface between the POS system and the general ledger is transferring sales data completely and accurately. B. Monthly bank statements are reconciled without exception. Monthly bank statements are records of the cash inflows and outflows of the organization, which may not match with the sales data recorded by the POS system and the general ledger.
For example, there may be delays, discounts, returns, or refundsthat affect the cash flow but not the sales revenue. Therefore, reconciling monthly bank statements without exception does not necessarily mean that the sales data is complete and accurate. C. Nightly batch processing has been replaced with real-time processing. Nightly batch processing is a method of transferring data from the POS system to the general ledger in batches at a scheduled time, usually at night. Real-time processing is a method of transferring data from the POS system to the general ledger as soon as the transactions occur. Real-time processing may improve the timeliness and efficiency of the data transfer process, but it does not guarantee that the sales data is complete and accurate. There may still be errors, omissions, or discrepancies in the data transfer process that need to be detected and corrected. D. The data transferred over the POS interface is encrypted.
Encryption is a process of transforming data into an unreadable form using a secret key or algorithm, so that only authorized parties can access the original data. Encryption protects the confidentiality and security of the data transferred over the POS interface, but it does not ensure that the sales data is complete and accurate.
There may still be errors, omissions, or discrepancies in the data transfer process that need to be detected and corrected.
References:
ISACA, CISA Review Manual, 27th Edition, 2019, p. 2471
ISACA, CISA Review Questions, Answers & Explanations Database - 12 Month Subscription2 Sales Audit Overview - Oracle3 Notes on Audit of Ledgers - Guidelines to Auditors - Accountlearning
CISA Exam Question 299
in a controlled application development environment, the MOST important segregation of duties should be between the person who implements changes into the production environment and the:
Correct Answer: A
In a controlled application development environment, the most important segregation of duties should be between the person who implements changes into the production environment and the application programmer. This segregation of duties ensures that no one person can create and deploy code without proper review, testing, and approval. This reduces the risk of errors, fraud, or malicious code being introduced into the production environment.
The other options are not as important as the segregation between the application programmer and the person who implements changes into production, but they are still relevant for achieving a secure and reliable application development environment. The segregation of duties between the person who implements changes into production and the systems programmer is important to prevent unauthorized or untested changes to system software or configuration. The segregation of duties between the person who implements changes into production and the computer operator is important to prevent unauthorized or uncontrolled access to production data or resources. The segregation of duties between the person who implements changes into production and the quality assurance (QA) personnel is important to ensure independent verification and validation of code quality and functionality.
References:
* ISACA CISA Review Manual 27th Edition (2019), page 247
* Segregation of Duties in an Agile Environment | AKF Partners3
* Separation of Duties: How to Conform in a DevOps World4
The other options are not as important as the segregation between the application programmer and the person who implements changes into production, but they are still relevant for achieving a secure and reliable application development environment. The segregation of duties between the person who implements changes into production and the systems programmer is important to prevent unauthorized or untested changes to system software or configuration. The segregation of duties between the person who implements changes into production and the computer operator is important to prevent unauthorized or uncontrolled access to production data or resources. The segregation of duties between the person who implements changes into production and the quality assurance (QA) personnel is important to ensure independent verification and validation of code quality and functionality.
References:
* ISACA CISA Review Manual 27th Edition (2019), page 247
* Segregation of Duties in an Agile Environment | AKF Partners3
* Separation of Duties: How to Conform in a DevOps World4
CISA Exam Question 300
Which of the following areas is MOST likely to be overlooked when implementing a new data classification process?
Correct Answer: A
The area that is most likely to be overlooked when implementing a new data classification process is end-user computing (EUC) systems. EUC systems are applications or tools that are developed or customized by end users, often without formal IT involvement or approval. EUC systems may contain sensitive or confidential data that need to be classified and protected according to the organization's policies and standards. However, EUC systems may not be subject to the same controls, oversight, or documentation as formal IT systems, and may not be included in the scope of the data classification process. Therefore, EUC systems pose a significant risk of data leakage, unauthorized access, or noncompliance. The other areas (B, C and D) are less likely to be overlooked, as they are more visible and manageable by the IT department or the data owners. References: IS Audit and Assurance Guideline 2202: Evidence Collection Techniques, CISA Review Manual (Digital Version), Chapter 5: Protection of Information Assets, Section 5.2: Data Classification
- Other Version
- 1189ISACA.CISA.v2026-09-25.q633
- 5210ISACA.CISA.v2025-12-02.q704
- 20081ISACA.CISA.v2025-06-20.q647
- 8036ISACA.CISA.v2025-06-11.q606
- 5158ISACA.CISA.v2023-03-04.q272
- 3921ISACA.CISA.v2022-10-31.q203
- 3678ISACA.CISA.v2022-03-29.q126
- 123ISACA.Examprepaway.CISA.v2022-02-10.by.barret.126q.pdf
- 11461ISACA.CISA.v2021-11-29.q567
- 36ISACA.Actualvce.CISA.v2021-08-31.by.ralap.101q.pdf
- Latest Upload
- 166ECCouncil.312-97.v2026-10-02.q65
- 184Salesforce.Plat-UX-102.v2026-10-02.q74
- 286Microsoft.AZ-802.v2026-10-02.q206
- 172InsuranceLicensing.PA-Title-Insurance-Agent.v2026-09-30.q30
- 206EMC.NCP-MCI.v2026-09-30.q46
- 241Microsoft.GH-200.v2026-09-29.q65
- 288PECB.ISO-9001-Lead-Auditor.v2026-09-29.q115
- 239Oracle.1Z0-1080-26.v2026-09-29.q59
- 233Microsoft.GH-500.v2026-09-29.q56
- 280Splunk.SPLK-1003.v2026-09-29.q96
[×]
Download PDF File
Enter your email address to download ISACA.CISA.v2025-12-09.q630 Practice Test
