Which of the following is the PRIMARY reason for an organization to conduct a formal information security audit?
Correct Answer: B
The correct answer is B. To identify material information security vulnerabilities. The primary purpose of a formal information security audit is to independently evaluate whether security controls are adequate and effective, and to identify material vulnerabilities, weaknesses, or risks that could affect the confidentiality, integrity, and availability of information assets. ISACA states that audit objectives often center on substantiating the existence of internal controls to minimize business risk, and ISACA's cybersecurity audit guidance describes reviewing gathered data to identify potential security vulnerabilities or risk and documenting findings and recommendations. Option A is important, but it is more directly related to information security governance and strategy than the primary purpose of a formal audit. Option C is not correct because reducing software licensing cost is a cost- management activity, not the main objective of an information security audit. Option D is also incorrect because monitoring security team productivity is a management function, not the primary purpose of an independent audit. This question maps mainly to Information Systems Auditing Process because it concerns why an audit is conducted: to provide independent assurance, identify material issues, and support risk-based recommendations. References: ISACA CISA Exam Content Outline, Domain 1; ISACA Interactive Glossary, "Audit objective," "Audit evidence," and "Auditor's opinion"; ISACA article, Six Benefits of a Cybersecurity Audit.
CISA Exam Question 57
Which of the following tasks would cause the GREATEST segregation of duties (SoD) concern if performed by the person who reconciles the organization's device inventory?
Correct Answer: C
CISA Exam Question 58
When reviewing the functionality of an intrusion detection system (IDS), the IS auditor should be MOST concerned if:
Correct Answer: B
The main purpose of an IDS is to detect and report malicious or suspicious activity on a network or a host. If an IDS fails to identify actual attacks, it means that the IDS is not functioning properly or effectively, and it exposes the organization to serious security risks and potential damage. This is the most concerning scenario for an IS auditor, as it indicates a major deficiency in the IDS performance and configuration. ReferencesWhat is an intrusion detection system (IDS)?What is Intrusion Detection Systems (IDS)? How does it Work?When reviewing an intrusion detection system (IDS), an IS auditor ...Intrusion Detection Systems (IDS)-An Overview with a Generalized ...An overview of issues in testing intrusion detection systems - NISTA Review of Intrusion Detection Systems and Their ...
CISA Exam Question 59
Which of the following is the BEST control to help ensure the completeness of outbound transactions?
Correct Answer: D
To ensurecompleteness of outbound transactions, alog with periodic validationis thebest control. Option A (Incorrect):Edit checkshelp withdata accuracy, not completeness. Option B (Incorrect):Sequential numberingdetects missing transactions but does not verifyactual transmission. Option C (Incorrect):Recipient ID validationis important foraccuracy, not for ensuring all transactions are sent. Option D (Correct):Maintaining and validating transaction logsensures thatall outbound transactions are properly accounted for, making it the best completeness control. Reference:ISACA CISA Review Manual -Domain 3: Information Systems Acquisition, Development, and Implementation- Coversdata integrity, completeness controls, and transaction logging.
CISA Exam Question 60
Which of the following is the BEST way to ensure an organization's data classification policies are preserved during the process of data transformation?
Correct Answer: D
Data classification is the process of tagging data according to its type, sensitivity, and value to the organization. Data transformation is the process of changing the structure and format of data to make it usable for analysis and visualization. Both processes are important for data security and compliance, but they also pose some challenges. One of the challenges is to ensure that the organization's data classification policies are preserved during the process of data transformation. This means that the data should retain its original classification level and labels after it is transformed, and that the appropriate controls and protections are applied to the transformed data. The best way to ensure this is to implement classification labels in metadata during data creation (D). Metadata is data that describes other data, such as its source, format, content, and context. By adding classification labels to metadata, the data can be easily identified and tracked throughout its lifecycle, including during data transformation. The labels can also help enforce the proper access rights and encryption standards for the data, regardless of its state or location.