Which of the following is the PRIMARY role of the IT steering committee?
Correct Answer: B
CISA Exam Question 82
When reviewing a business case for a proposed implementation of a third-party system, which of the following should be an IS auditor's GREATEST concern?
Correct Answer: A
The IS auditor's greatest concern when reviewing a business case for a proposed implementation of a third- party system should be A. Lack of ongoing maintenance costs. This is because ongoing maintenance costs are an essential part of the total cost of ownership (TCO) of a third-party system, and they can have a significant impact on the return on investment (ROI) and the feasibility of the project. If the business case does not include ongoing maintenance costs, it may underestimate the true cost of the project and overestimate the benefits. This could lead to poor decision making and unrealistic expectations. Lack of training materials (B), lack of plan for pilot implementation , and lack of detailed work breakdown structure (D) are also potential issues that could affect the quality and success of the project, but they are not as critical as lack of ongoing maintenance costs. Training materials can be developed or acquired later, pilot implementation can be planned during the project initiation or planning phase, and work breakdown structure can be refined as the project progresses. However, ongoing maintenance costs are difficult to change or estimate once the project is approved and implemented, and they can have long-term implications for the organization. Therefore, they should be included and analyzed in the business case.
CISA Exam Question 83
A bank performed minor changes to the interest calculation computer program. Which of the following techniques would provide the STRONGEST evidence to determine whether the interest calculations are correct?
Correct Answer: B
Parallel simulation involves running the same data through two systems and comparing the results1. In this case, the bank's data would be processed using both the modified interest calculation program and an audit software. The results from both systems would then be compared to check for discrepancies1. This technique provides strong evidence of the correctness of interest calculations as it directly tests the program's output against a known and trusted output1. While source code review23, manual verification of a sample of results4567, and review of QA test results8910 can also provide valuable insights, they do not offer the same level of direct, comparative evidence as parallel simulation1. References: Parallel simulation in IT testing - Universal CPA Review 5 code review best practices - Work Life by Atlassian How to Make Good Code Reviews Better - Stack Overflow Guidelines for the validation and verification of quantitative and qualitative test methods - Mathematics LibreTexts Method Validation and Verification - University of Utah Sample Procedure for Method Validation - NIST Method validation and verification - CFS Good Practices for Quality Assurance Reviewers: Assessing Evidence of Supervisory Review - IGNET How do quality assurance engineers test calculations? - Software Quality Assurance and Testing Stack Exchange Quality Assurance/Quality Control (QA/QC) Plan and Procedures - UNFCCC
CISA Exam Question 84
Which of the following activities should be separated in an organization's incident management processes?
Correct Answer: D
The correct answer is D. Initiating and closing error logs. The key separation-of-duties concern is that the same person should not be able to both initiate and close an error log without independent review. If one individual can create and close error records, there is a risk that incidents, problems, or errors may be closed without proper resolution, root-cause analysis, approval, or accountability. Option A is not the best answer because recording and classifying incidents are closely related service desk activities and may reasonably be performed together. Option B is not the best answer because collecting and analyzing logs may be part of the same monitoring function, provided appropriate oversight exists. Option C is not the best answer because identifying root causes and recommending workarounds are related problem management activities. This maps to Information Systems Operations and Business Resilience, because incident management, problem management, operational monitoring, and service management are included in CISA Domain 4. ISACA's CISA Exam Content Outline includes incident/problem management and IT operations practices under this domain. References: ISACA CISA Exam Content Outline, Domain 4; ISACA Interactive Glossary, "Segregation /separation of duties."
CISA Exam Question 85
When auditing the feasibility study of a system development project, the IS auditor should:
Correct Answer: C
A feasibility study is an assessment that determines the likelihood of a proposed project being successful, such as a new system development1. A feasibility study typically covers various aspects of the project, such as technical, economic, operational and legal feasibility2. The IS auditor's role is to audit the feasibility study and ensure that it is objective, realistic and reliable3. One of the most important aspects of a feasibility study is the economic feasibility, which analyzes the costs and benefits of the proposed system and compares them with alternative solutions2. The economic feasibility study should include a detailed breakdown of the development, implementation and operational costs, as well as the expected revenues, savings and intangible benefits of the system3. The IS auditor should review the cost-benefit documentation for reasonableness and accuracy, and verify that the assumptions and calculations are valid and supported by evidence3. The other options are not directly related to auditing the feasibility study of a system development project. Reviewing qualifications of key members of the project team (option A) is more relevant to auditing the project management and human resources aspects of the project. Reviewing the request for proposal (RFP) to ensure that it covers the scope of work (option B) is more relevant to auditing the procurement and vendor selection process of the project. Ensuring that vendor contracts are reviewed by legal counsel (option D) is more relevant to auditing the legal and contractual aspects of the project. References: 3: Types of Feasibility Study in Software Project Development 2: Feasibility Analysis in System Development Process 1: What Is a Feasibility Study? Definition, Benefits and Types