CISA Exam Question 576
What is the GREATEST concern for an IS auditor reviewing contracts for licensed software that executes a critical business process?
Correct Answer: D
The greatest concern for an IS auditor reviewing contracts for licensed software that executes a critical business process is that software escrow was not negotiated. Software escrow is an arrangement where a third- party holds a copy of the source code and documentation of a licensed software in a secure location. The software escrow agreement specifies the conditions under which the licensee can access the escrowed materials, such as in case of bankruptcy, termination, or breach of contract by the licensor. Software escrow is important for ensuring the continuity and availability of a critical business process that depends on a licensed software. Without software escrow, the licensee may face significant risks and challenges in maintaining, modifying, or recovering the software in case of any disruption or dispute with the licensor. References:
CISA Review Manual (Digital Version)
CISA Questions, Answers and Explanations Database
CISA Review Manual (Digital Version)
CISA Questions, Answers and Explanations Database
CISA Exam Question 577
A source code repository should be designed to:
Correct Answer: C
A source code repository is a system that stores and manages the source code of a software project. A source code repository should be designed to provide secure versioning and backup capabilities for existing code, as these are essential features for concurrent development, code quality, and disaster recovery. Versioning allows developers to track, compare, and revert changes to the code over time. Backup ensures that the code is safely stored and can be restored in case of data loss or corruption.
References
Source Code Repositories: What is a Source Code Repository?
Git Source Code Repository Design Considerations
Best practices for repositories - GitHub Docs
References
Source Code Repositories: What is a Source Code Repository?
Git Source Code Repository Design Considerations
Best practices for repositories - GitHub Docs
CISA Exam Question 578
Which of the following is the BEST data integrity check?
Correct Answer: C
Data integrity is the property that ensures that data is accurate, complete, consistent, and reliable throughout its lifecycle. The best data integrity check is tracing data back to the point of origin, which is the source where the data was originally created or captured. This check can verify that data has not been altered or corrupted during transmission, processing, or storage. It can also identify any errors or discrepancies in data entry or conversion. Counting the transactions processed per day is a performance measure that does not directly assess data integrity. Performing a sequence check is a validity check that ensures that data follows a predefined order or pattern. It can detect missing or out-of-order data elements, but it cannot verify their accuracy or completeness. Preparing and running test data is a testing technique that simulates real data to evaluate how a system handles different scenarios. It can help identify errors or bugs in the system logic or functionality, but it cannot ensure data integrity in production environments. References: Information Systems Operations and Business Resilience, CISA Review Manual (Digital Version)
CISA Exam Question 579
An IS auditor is conducting an audit of a very large e-commerce platform. Which of the following techniques BEST enables the auditor to identify web application security flaws?
Correct Answer: B
The correct answer is B. Vulnerability scanning.
For a very large e-commerce platform, vulnerability scanning is the best technique among the options because it provides automated, broad coverage for identifying security weaknesses across web applications, servers, interfaces, and related components. ISACA defines vulnerability scanning as an automated process used to proactively identify security weaknesses in a network or individual system. ISACA's CISA Exam Content Outline also includes threat and vulnerability management and the use of technical security testing to identify potential vulnerabilities.
Option A, code review, can be very useful for identifying insecure coding practices and logic flaws, but it is usually more time-consuming and less practical as the primary technique for a very large e-commerce environment. It may also require access to source code and specialized development expertise.
Option C, logical security testing, focuses mainly on access rights, authentication, authorization, and logical access controls. It is important, but it is narrower than vulnerability scanning for identifying web application security flaws.
Option D, penetration testing, is valuable because it attempts to exploit vulnerabilities in a controlled manner.
ISACA defines penetration testing as a live test of security defenses by mimicking real-life attackers.
However, penetration testing is usually more targeted and is often used to validate exploitability of vulnerabilities. For broad identification of web application flaws in a very large platform, vulnerability scanning is the stronger answer.
This question maps mainly to Protection of Information Assets because the CISA Exam Content Outline includes security testing tools and techniques, security monitoring, threat and vulnerability management, and protection of information assets under Domain 5.
References: ISACA CISA Exam Content Outline, Domain 5; ISACA Interactive Glossary, "Vulnerability scanning," "Vulnerability management," and "Penetration testing."
For a very large e-commerce platform, vulnerability scanning is the best technique among the options because it provides automated, broad coverage for identifying security weaknesses across web applications, servers, interfaces, and related components. ISACA defines vulnerability scanning as an automated process used to proactively identify security weaknesses in a network or individual system. ISACA's CISA Exam Content Outline also includes threat and vulnerability management and the use of technical security testing to identify potential vulnerabilities.
Option A, code review, can be very useful for identifying insecure coding practices and logic flaws, but it is usually more time-consuming and less practical as the primary technique for a very large e-commerce environment. It may also require access to source code and specialized development expertise.
Option C, logical security testing, focuses mainly on access rights, authentication, authorization, and logical access controls. It is important, but it is narrower than vulnerability scanning for identifying web application security flaws.
Option D, penetration testing, is valuable because it attempts to exploit vulnerabilities in a controlled manner.
ISACA defines penetration testing as a live test of security defenses by mimicking real-life attackers.
However, penetration testing is usually more targeted and is often used to validate exploitability of vulnerabilities. For broad identification of web application flaws in a very large platform, vulnerability scanning is the stronger answer.
This question maps mainly to Protection of Information Assets because the CISA Exam Content Outline includes security testing tools and techniques, security monitoring, threat and vulnerability management, and protection of information assets under Domain 5.
References: ISACA CISA Exam Content Outline, Domain 5; ISACA Interactive Glossary, "Vulnerability scanning," "Vulnerability management," and "Penetration testing."
CISA Exam Question 580
Which of the following is a PRIMARY responsibility of a quality assurance (QA) team?
Correct Answer: D
A quality assurance (QA) team is a group of professionals who are responsible for ensuring that the products or services of an organization meet the quality standards and expectations of customers and stakeholders1. A QA team performs various activities, such as:
Planning, designing, and executing quality tests and audits to verify the quality of the products or services1 Identifying, analyzing, and reporting quality issues, defects, or non-conformities1 Recommending and implementing corrective and preventive actions to resolve quality problems and prevent recurrence1 Monitoring and measuring the effectiveness and efficiency of the quality processes and improvements1 Establishing and maintaining quality documentation, records, and reports1 Providing quality training, guidance, and support to the staff and management1 One of the primary responsibilities of a QA team is to implement procedures to facilitate adoption of quality management best practices. Quality management best practices are the methods, techniques, or tools that have been proven to be effective in achieving and maintaining high-quality standards in an organization2. Some examples of quality management best practices are:
Adopting a customer-focused approach that aims to meet or exceed customer requirements and satisfaction2 Implementing a process approach that manages the interrelated activities as a coherent system2 Applying continuous improvement methods that seek to enhance the performance and value of the products or services2 Using evidence-based decision making that relies on factual data and information2 Developing a culture of engagement and empowerment that involves and motivates the people in the organization2 By implementing procedures to facilitate adoption of quality management best practices, a QA team can help the organization achieve the following benefits:
Improve the quality and reliability of the products or services2
Reduce the costs and risks associated with poor quality or non-compliance2 Increase the customer loyalty and retention2 Enhance the reputation and competitiveness of the organization2 Foster a culture of excellence and innovation in the organization2 The other options are not primary responsibilities of a QA team. Creating test data to facilitate the user acceptance testing (UAT) process is a task that can be performed by a QA team, but it is not their main duty. UAT is a process in which the end users test the product or service to ensure that it meets their needs and expectations before it is released or deployed3. A QA team can create test data to simulate real-world scenarios and conditions for UAT, but they are not directly involved in conducting UAT. Managing employee onboarding processes and background checks is not a responsibility of a QA team. Employee onboarding is a process in which new hires are integrated into the organization, while background checks are screenings that verify the identity, credentials, and history of potential employees4. These processes are usually handled by the human resources department or an external agency, not by a QA team. Advising the steering committee on quality management issues and remediation efforts is not a primary responsibility of a QA team. A steering committee is a group of senior executives or managers who provide strategic direction, oversight, and support for a project or program5. A QA team can advise the steering committee on quality management issues and remediation efforts, but they are not accountable for making decisions or implementing actions. Therefore, option D is the correct answer.
References:
Quality Assurance Team: Roles and Responsibilities
What are the Best Practices in Quality Management?
User Acceptance Testing (UAT): A Complete Guide
Employee Onboarding Process: Definition and Best Practices
What Is A Steering Committee? - The Basics
Planning, designing, and executing quality tests and audits to verify the quality of the products or services1 Identifying, analyzing, and reporting quality issues, defects, or non-conformities1 Recommending and implementing corrective and preventive actions to resolve quality problems and prevent recurrence1 Monitoring and measuring the effectiveness and efficiency of the quality processes and improvements1 Establishing and maintaining quality documentation, records, and reports1 Providing quality training, guidance, and support to the staff and management1 One of the primary responsibilities of a QA team is to implement procedures to facilitate adoption of quality management best practices. Quality management best practices are the methods, techniques, or tools that have been proven to be effective in achieving and maintaining high-quality standards in an organization2. Some examples of quality management best practices are:
Adopting a customer-focused approach that aims to meet or exceed customer requirements and satisfaction2 Implementing a process approach that manages the interrelated activities as a coherent system2 Applying continuous improvement methods that seek to enhance the performance and value of the products or services2 Using evidence-based decision making that relies on factual data and information2 Developing a culture of engagement and empowerment that involves and motivates the people in the organization2 By implementing procedures to facilitate adoption of quality management best practices, a QA team can help the organization achieve the following benefits:
Improve the quality and reliability of the products or services2
Reduce the costs and risks associated with poor quality or non-compliance2 Increase the customer loyalty and retention2 Enhance the reputation and competitiveness of the organization2 Foster a culture of excellence and innovation in the organization2 The other options are not primary responsibilities of a QA team. Creating test data to facilitate the user acceptance testing (UAT) process is a task that can be performed by a QA team, but it is not their main duty. UAT is a process in which the end users test the product or service to ensure that it meets their needs and expectations before it is released or deployed3. A QA team can create test data to simulate real-world scenarios and conditions for UAT, but they are not directly involved in conducting UAT. Managing employee onboarding processes and background checks is not a responsibility of a QA team. Employee onboarding is a process in which new hires are integrated into the organization, while background checks are screenings that verify the identity, credentials, and history of potential employees4. These processes are usually handled by the human resources department or an external agency, not by a QA team. Advising the steering committee on quality management issues and remediation efforts is not a primary responsibility of a QA team. A steering committee is a group of senior executives or managers who provide strategic direction, oversight, and support for a project or program5. A QA team can advise the steering committee on quality management issues and remediation efforts, but they are not accountable for making decisions or implementing actions. Therefore, option D is the correct answer.
References:
Quality Assurance Team: Roles and Responsibilities
What are the Best Practices in Quality Management?
User Acceptance Testing (UAT): A Complete Guide
Employee Onboarding Process: Definition and Best Practices
What Is A Steering Committee? - The Basics
- Other Version
- 4495ISACA.CISA.v2025-12-09.q630
- 4703ISACA.CISA.v2025-12-02.q704
- 19283ISACA.CISA.v2025-06-20.q647
- 7703ISACA.CISA.v2025-06-11.q606
- 4829ISACA.CISA.v2023-03-04.q272
- 3727ISACA.CISA.v2022-10-31.q203
- 3575ISACA.CISA.v2022-03-29.q126
- 123ISACA.Examprepaway.CISA.v2022-02-10.by.barret.126q.pdf
- 11094ISACA.CISA.v2021-11-29.q567
- 36ISACA.Actualvce.CISA.v2021-08-31.by.ralap.101q.pdf
- Latest Upload
- 395ISACA.CISA.v2026-09-25.q633
- 168VMware.250-605.v2026-09-25.q75
- 184Microsoft.AZ-305.v2026-09-25.q198
- 293IIA.IIA-CIA-Part1.v2026-09-25.q362
- 169Huawei.H19-308_V4.0.v2026-09-24.q46
- 201Microsoft.AI-900.v2026-09-24.q146
- 200HP.HPE6-A85.v2026-09-23.q64
- 165Microsoft.SC-500.v2026-09-23.q32
- 180Cisco.300-110.v2026-09-22.q45
- 187InsuranceLicensing.NJ-Life-Producer.v2026-09-22.q44
[×]
Download PDF File
Enter your email address to download ISACA.CISA.v2026-09-25.q633 Practice Test
