CISA Exam Question 376
The implementation of an IT governance framework requires that the board of directors of an organization:
Correct Answer: D
IT governance is a framework that defines the roles, responsibilities, and processes for aligning IT strategy with business strategy. The board of directors of an organization is ultimately accountable for IT governance and has the authority to approve the IT strategy. The board of directors does not need to address technical IT issues, be informed of all IT initiatives, or have an IT strategy committee, as these tasks can be delegated to other stakeholders or committees within the organization.
CISA Exam Question 377
An IS auditor is reviewing security controls related to collaboration tools for a business unit responsible for intellectual property and patents. Which of the following observations should be of MOST concern to the auditor?
Correct Answer: B
The observation that should be of most concern to the auditor when reviewing security controls related to collaboration tools for a business unit responsible for intellectual property and patents is that employees can share files with users outside the company through collaboration tools. Collaboration tools are software or hardware devices that enable users to communicate, cooperate, and coordinate with each other on a common task or project. Collaboration tools can facilitate information sharing and knowledge exchange among users, but they can also pose security risks if not properly controlled or managed. Employees can share files with users outside the company through collaboration tools, as this can compromise the security and confidentiality of intellectual property and patents, which are valuable and sensitive assets of the organization. Employees may share files with unauthorized or untrusted users who may misuse or disclose the intellectual property and patents, either intentionally or unintentionally. This can cause harm or damage to the organization, such as loss of competitive advantage, reputation, revenue, or legal rights. Training was not provided to the department that handles intellectual property and patents is a possible observation that could indicate a security issue related to collaboration tools for a business unit responsible for intellectual property and patents, but it is not the most concerning one. Training is anactivity that educates and instructs users on how to use collaboration tools effectively and securely, such as how to access, share, store, and protect information using collaboration tools. Training was not provided to the department that handles intellectual property and patents, as this can affect the awareness and competence of users on collaboration tools, and increase the likelihood of errors or mistakes that may compromise the security or quality of information. However, this observation may not be directly related to collaboration tools, as it may apply to any information system or resource used by the department. Logging and monitoring for content filtering is not enabled is a possible observation that could indicate a security issue related to collaboration tools for a business unit responsible for intellectual property and patents, but it is not the most concerning one. Logging and monitoring are processes that record and analyze the events or activities that occur on an information system or network, such as user actions, system operations, data changes, errors, alerts, etc. Content filtering is a technique that blocks or allows access to certain types of information based on predefined criteria or rules, such as keywords, categories, sources, etc. Logging and monitoring for content filtering is not enabled, as this can affect the auditability, accountability, and visibility of collaboration tools, and prevent detection or investigation of security incidents or violations related to information sharing using collaboration tools. However, this observation may not be specific to collaboration tools, as it may affect any information system or network that uses content filtering. The collaboration tool is hosted and can only be accessed via an Internet browser is a possible observation that could indicate a security issue related to collaboration tools for a business unit responsible for intellectual property and patents, but it is not the most concerning one. A hosted collaboration tool is a type of cloud-based service that provides collaboration functionality over the Internet without requiring installation or maintenance on local devices. An Internet browser is a software application that enables users to access and interact with web-based content or services. The collaboration tool is hosted and can only be accessed via an Internet browser, as this can affect the availability and reliability of collaboration tools, and introduce security or privacy risks for information sharing using collaboration tools. However, this observation may not be unique to collaboration tools, as it may apply to any cloud-based service that uses an Internet browser.
CISA Exam Question 378
The PRIMARY purpose of an incident response plan is to:
Correct Answer: A
The primary purpose of an incident response plan is to reduce the impact of an adverse event on information assets. An incident response plan is a set of instructions and procedures that guide the organization's actions in the event of a security breach, cyberattack, or other disruption that affects its information systems and data.
An incident response plan aims to:
Detect and identify the incident as soon as possible.
Contain and isolate the incident to prevent further damage or spread.
Analyze and investigate the incident to determine its cause, scope, and impact.
Eradicate and eliminate the incident and its root causes from the affected systems and data.
Recover and restore the normal operations and functionality of the systems and data.
Learn and improve from the incident by documenting the lessons learned, best practices, and recommendations for future prevention and mitigation.
By following an incident response plan, the organization can minimize the negative consequences of an adverse event on its information assets, such as:
Loss or corruption of data or information.
Disclosure or theft of confidential or sensitive data or information.
Interruption or degradation of system or service availability or performance.
Legal or regulatory noncompliance or liability.
Financial or reputational loss or damage.
An incident response plan also helps the organization to demonstrate its due diligence and accountability in protecting its information assets and complying with its legal and contractual obligations.
The other options are not the primary purpose of an incident response plan, although they may be secondary benefits or outcomes of having one.
Increasing the effectiveness of preventive controls is not the primary purpose of an incident response plan.
Preventive controls are controls that aim to prevent or deter incidents from occurring in the first place, such as firewalls, antivirus software, encryption, authentication, etc. An incident response plan is a reactive control that deals with incidents after they have occurred. However, an incident response plan may help to improve the effectiveness of preventive controls by identifying and addressing their weaknesses or gaps.
Reducing the maximum tolerable downtime (MTD) of impacted systems is not the primary purpose of an incident response plan. MTD is a measure of how long an organization can tolerate a system or service outage before it causes unacceptable harm or loss to its business operations or objectives. An incident response plan may help to reduce the MTD of impacted systems by facilitating a faster and smoother recovery process.
However, reducing the MTD is not the main goal of an incident response plan, but rather a desired outcome.
Increasing awareness of impacts from adverse events to IT systems is not the primary purpose of an incident response plan. Awareness is a state of being informed or conscious of something. An incident response plan may help to increase awareness of impacts from adverse events to IT systems by providing information and communication channels for stakeholders, such as management, employees, customers, regulators, etc.
However, increasing awareness is not the main objective of an incident response plan, but rather a means to achieve other objectives, such as reducing impact, ensuring compliance, or maintaining trust.
An incident response plan aims to:
Detect and identify the incident as soon as possible.
Contain and isolate the incident to prevent further damage or spread.
Analyze and investigate the incident to determine its cause, scope, and impact.
Eradicate and eliminate the incident and its root causes from the affected systems and data.
Recover and restore the normal operations and functionality of the systems and data.
Learn and improve from the incident by documenting the lessons learned, best practices, and recommendations for future prevention and mitigation.
By following an incident response plan, the organization can minimize the negative consequences of an adverse event on its information assets, such as:
Loss or corruption of data or information.
Disclosure or theft of confidential or sensitive data or information.
Interruption or degradation of system or service availability or performance.
Legal or regulatory noncompliance or liability.
Financial or reputational loss or damage.
An incident response plan also helps the organization to demonstrate its due diligence and accountability in protecting its information assets and complying with its legal and contractual obligations.
The other options are not the primary purpose of an incident response plan, although they may be secondary benefits or outcomes of having one.
Increasing the effectiveness of preventive controls is not the primary purpose of an incident response plan.
Preventive controls are controls that aim to prevent or deter incidents from occurring in the first place, such as firewalls, antivirus software, encryption, authentication, etc. An incident response plan is a reactive control that deals with incidents after they have occurred. However, an incident response plan may help to improve the effectiveness of preventive controls by identifying and addressing their weaknesses or gaps.
Reducing the maximum tolerable downtime (MTD) of impacted systems is not the primary purpose of an incident response plan. MTD is a measure of how long an organization can tolerate a system or service outage before it causes unacceptable harm or loss to its business operations or objectives. An incident response plan may help to reduce the MTD of impacted systems by facilitating a faster and smoother recovery process.
However, reducing the MTD is not the main goal of an incident response plan, but rather a desired outcome.
Increasing awareness of impacts from adverse events to IT systems is not the primary purpose of an incident response plan. Awareness is a state of being informed or conscious of something. An incident response plan may help to increase awareness of impacts from adverse events to IT systems by providing information and communication channels for stakeholders, such as management, employees, customers, regulators, etc.
However, increasing awareness is not the main objective of an incident response plan, but rather a means to achieve other objectives, such as reducing impact, ensuring compliance, or maintaining trust.
CISA Exam Question 379
An organization outsourced its IS functions to meet its responsibility for disaster recovery, the organization should:
Correct Answer: B
An organization outsourced its IS functions. To meet its responsibility for disaster recovery, the organization should coordinate disaster recovery administration with the outsourcing vendor. This is because the organization remains accountable for ensuring the continuity and availability of its IS functions, even if they are outsourced to a third party. The organization should establish clear roles and responsibilities, communication channels, testing procedures, and escalation processes with the outsourcing vendor for disaster recovery purposes. The organization should not discontinue maintenance of the disaster recovery plan (DRP), as it still needs to have a documented and updated plan for restoring its IS functions in case of a disaster. The organization should not delegate evaluation of disaster recovery to a third party or internal audit, as it still needs to monitor and review the performance and compliance of the outsourcing vendor with respect to disaster recovery objectives and standards. References: CISA Review Manual (Digital Version), [ISACA Auditing Standards]
CISA Exam Question 380
An IS auditor has identified deficiencies within the organization's software development life cycle policies.
Which of the following should be done NEXT?
Which of the following should be done NEXT?
Correct Answer: D
An IS auditor has identified deficiencies within the organization's software development life cycle (SDLC) policies. The SDLC is the process of planning, developing, testing, and deploying software applications1. SDLC policies are the guidelines and standards that govern the SDLC process and ensure its quality, security, and compliance2. Deficiencies in SDLC policies can lead to various risks, such as:
Software errors, bugs, or vulnerabilities that can affect the functionality, reliability, or security of the applications3 Software failures, delays, or overruns that can affect the delivery, performance, or customer satisfaction of the applications3 Software non-compliance that can result in legal, regulatory, or contractual violations or penalties3 The next step that the IS auditor should do after identifying deficiencies in SDLC policies is to communicate the observation to the auditee. The auditee is the person or entity that is subject to the audit and is responsible for the area being audited4. In this case, the auditee could be the software development manager, the project manager, or the senior management of the organization. Communicating the observation to the auditee is important for several reasons:
It allows the IS auditor to verify the accuracy and validity of the observation and gather additional evidence or information from the auditee4 It gives the auditee an opportunity to respond to the observation and provide their perspective, explanation, or justification for the deficiencies4 It enables the IS auditor to discuss with the auditee the potential impact, root cause, and remediation plan for the deficiencies4 It fosters a collaborative and constructive relationship between the IS auditor and the auditee and promotes transparency and accountability in the audit process4 The other options are not as appropriate as communicating the observation to the auditee. Documenting the findings in the audit report is a later stepthat should be done after communicating with the auditee and finalizing the observation. Identifying who approved the policies is not relevant for addressing the deficiencies and may imply blame or fault on a specific person or group. Escalating the situation to the lead auditor is not necessary unless there is a serious disagreement or conflict with the auditee that cannot be resolved by normal communication. Therefore, option D is the correct answer.
References:
What Is The Software Development Life Cycle? | PagerDuty
Software Development Life Cycle (SDLC) Policy | StrongDM
What Is SDLC? Best Phases, Methodologies, and Benefits Revealed - Kellton Communicating Audit Findings
Software errors, bugs, or vulnerabilities that can affect the functionality, reliability, or security of the applications3 Software failures, delays, or overruns that can affect the delivery, performance, or customer satisfaction of the applications3 Software non-compliance that can result in legal, regulatory, or contractual violations or penalties3 The next step that the IS auditor should do after identifying deficiencies in SDLC policies is to communicate the observation to the auditee. The auditee is the person or entity that is subject to the audit and is responsible for the area being audited4. In this case, the auditee could be the software development manager, the project manager, or the senior management of the organization. Communicating the observation to the auditee is important for several reasons:
It allows the IS auditor to verify the accuracy and validity of the observation and gather additional evidence or information from the auditee4 It gives the auditee an opportunity to respond to the observation and provide their perspective, explanation, or justification for the deficiencies4 It enables the IS auditor to discuss with the auditee the potential impact, root cause, and remediation plan for the deficiencies4 It fosters a collaborative and constructive relationship between the IS auditor and the auditee and promotes transparency and accountability in the audit process4 The other options are not as appropriate as communicating the observation to the auditee. Documenting the findings in the audit report is a later stepthat should be done after communicating with the auditee and finalizing the observation. Identifying who approved the policies is not relevant for addressing the deficiencies and may imply blame or fault on a specific person or group. Escalating the situation to the lead auditor is not necessary unless there is a serious disagreement or conflict with the auditee that cannot be resolved by normal communication. Therefore, option D is the correct answer.
References:
What Is The Software Development Life Cycle? | PagerDuty
Software Development Life Cycle (SDLC) Policy | StrongDM
What Is SDLC? Best Phases, Methodologies, and Benefits Revealed - Kellton Communicating Audit Findings
- Other Version
- 1319ISACA.CISA.v2026-09-25.q633
- 5269ISACA.CISA.v2025-12-02.q704
- 20200ISACA.CISA.v2025-06-20.q647
- 8075ISACA.CISA.v2025-06-11.q606
- 5197ISACA.CISA.v2023-03-04.q272
- 3930ISACA.CISA.v2022-10-31.q203
- 3686ISACA.CISA.v2022-03-29.q126
- 123ISACA.Examprepaway.CISA.v2022-02-10.by.barret.126q.pdf
- 11490ISACA.CISA.v2021-11-29.q567
- 36ISACA.Actualvce.CISA.v2021-08-31.by.ralap.101q.pdf
- Latest Upload
- 100Fortinet.NSE7_SSE_AR-26.v2026-10-05.q26
- 101IIA.IIA-CIA-Part1-CN.v2026-10-05.q321
- 101ISC.CISSP-CN.v2026-10-05.q802
- 101HP.HPE0-J81.v2026-10-05.q24
- 101Cisco.350-801.v2026-10-05.q313
- 147Oracle.1z0-3000.v2026-10-03.q21
- 210Microsoft.AZ-700.v2026-10-03.q164
- 166PaloAltoNetworks.NetSec-Analyst.v2026-10-03.q52
- 197ECCouncil.312-97.v2026-10-02.q65
- 223Salesforce.Plat-UX-102.v2026-10-02.q74
[×]
Download PDF File
Enter your email address to download ISACA.CISA.v2025-12-09.q630 Practice Test
