Browse all practice questions for the CISA Domain 2 Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

CISA Domain 2 Practice Exam course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • In relation to service provider selection, which should be considered imperative in agreements?
  • What should an IS auditor recommend when finance and marketing departments report differing product profitability results?
  • What is the most likely effect of a lack of senior management commitment to IT strategic planning?
  • What is the primary goal of an IT performance measurement process?
  • In a strategic IT plan, what assessment should an IS auditor expect to find?
  • Which method primarily achieves transparency of IT's cost, value, and risk in IT governance?
  • In addressing differing profitability reports, what practice should be implemented for better data interpretation?
  • Who is best suited to determine an enterprise's risk appetite?
  • When a business unit selects a new application without consulting IT, what is the PRIMARY risk?
  • When assessing the alignment of IT strategies with business objectives, what is key for an IS auditor to verify?
  • In short-term planning for an IT department, what does an IS auditor deem most relevant?
  • What is the PRIMARY objective of implementing corporate governance?
  • What does risk mitigation entail in the context of IT security?
  • What recommendation should be made concerning undefined responsibilities in IT management?
  • What should an IS auditor report when noticing that a separate project to develop a future-state representation is ongoing?
  • What is the primary benefit of implementing a security program within a governance framework?
  • What is the primary control purpose of required vacations for employees?
  • What is the primary responsibility of the board of directors regarding IT strategy?
  • What is a potential limitation of using a maturity model for strategic alignment?
  • When an organization outsources its help desk, what is the IS auditor's greatest concern in the contract review?
  • What recommendation is most appropriate when no risk management function exists in an IT department?
  • What is a significant risk if critical IT policies lack management approval?
  • What presents the greatest risk during a merger involving the replacement of legacy systems?
  • What is a suitable compensating control when segregation of duties concerns exist between IT support staff and end users?
  • What is a key aspect of an IT policy’s effectiveness?
  • What is the most critical success factor when developing a formal enterprise security program?
  • What is essential for the long-term support of a purchased product from a vendor?
  • Which condition is of greatest concern for an IS auditor when reviewing outsourced IT services?
  • What is essential for an IS auditor to check in an outsourced help desk service agreement?
  • What is necessary for ensuring the effectiveness of an information security policy?
  • What should be ensured when developing security policies according to industry standards?
  • Why is it essential to have a software escrow agreement with a vendor?
  • Which of the following is not a direct responsibility of an IT steering committee?
  • Which of the following reflects a priority in discussing IT governance issues?
  • An organization seeking to improve its risk management strategies should prioritize which governance aspect?
  • Overall quantitative business risk is best expressed as what?
  • What factor is considered most important for facilitating compliance with a newly developed IT policy?
  • Which of the following is the best practice for ensuring compliance in IT policies?
  • Inadequate ownership policy for data may lead to what critical risk?
  • Why is a RACI chart important in project management?
  • What should be the first objective of an IS auditor reviewing outsourced IT services?
  • Which benefit does a well-defined IT strategy provide to an organization?
  • IT governance is primarily the responsibility of which group?
  • During a risk management review, what is the most important consideration?
  • Which action should be prioritized to limit access to confidential data when an employee leaves?
  • Which situation is specifically addressed by a software escrow agreement?
  • In risk measurement, what is a relevant consideration regarding network risks?
  • What concern should an IS auditor prioritize when reviewing an organization's governance model?
  • To best align an IT project portfolio with organizational priorities, what should an IS auditor recommend?
  • Which factor is NOT a primary focus for an IS auditor in IT governance?
  • What is typically a responsibility of the chief information security officer?
  • What is the primary consideration for an IS auditor reviewing IT project prioritization?
  • What primary concern should an IS auditor have regarding compliance with IT governance?
  • What is a critical risk to monitor during business process reengineering?
  • Which activity should be prioritized to assess the operational performance of an IT process?
  • When assessing cross-training practices, an IS auditor should focus on the risk of what?
  • Upon an employee's resignation, what should be done first if they had access to confidential information?
  • What is the first step in creating a firewall policy?
  • Involvement of senior management is most critical in the development of which plans?
  • Which issue must a comprehensive email policy specifically address?
  • What is the output of the risk management process primarily used for?
  • In developing information security policies, what should be the primary focus of an IS auditor?
  • What aspect of an organization’s security should be evaluated when implementing new technology?
  • If an organization’s software vendor is unresponsive, what is a recommended action?
  • Which user profile is of MOST concern to an IS auditor auditing an electronic funds transfer system?
  • Which characteristic is NOT ideal for an IT steering committee?
  • What is one of the key aspects that must be included in an outsourcing contract?
  • What is the most critical consideration for an IS auditor when evaluating an organization's IT strategy?
  • What is a common purpose of assessing employee performance evaluations in the context of security?
  • What aspect does NOT contribute directly to optimizing IT performance?
  • What key aspect should be documented before evaluating the effectiveness of information security controls?
  • What should be considered FIRST when implementing a risk management program?
  • What is the first step in developing a security architecture?
  • What is the purpose of an IT balanced scorecard in aligning IT with business objectives?
  • In the context of IT strategic planning, what is essential for the plan to articulate?
  • Which practice should be minimized in an effective IT steering committee?
  • What is a crucial outcome from the IT steering committee maintaining accurate minutes?
  • Which benefit does open system architecture provide?
  • What is the most important IS audit consideration when outsourcing a customer credit review system?
  • What is the MOST important aspect for an auditor when obtaining cloud hosting services from a vendor?
  • When evaluating IT governance implementation effectiveness, what is the most critical factor?
  • What is the primary reason for separating responsibilities among IT personnel?
  • What is the MOST important consideration for an IS auditor when reviewing a service level agreement?
  • What is the MOST critical factor for maintaining a successful security policy?
  • What does an effective IT strategy ideally ensure according to best practices?
  • What crucial element must an outsourcing contract specify?
  • Which critical aspect should be assessed when an employee is given access to sensitive information?
  • What is the primary concern when employees are unaware of the organization's information security policy?
  • What signifies a vulnerability within an information system?
  • What should an IS auditor FIRST reference when conducting an IS audit?
  • In reviewing a business process reengineering effort, what is the primary concern?
  • Which of the following is critical for an IS auditor to review in regards to a vendor's service level agreement?
  • Effective IT governance ensures that the IT plan is consistent with what organizational aspect?
  • What is the ultimate purpose of IT governance?
  • What does a lack of adequate security controls define?
  • Which element should be included in an organization's information security policy?
  • During which phase of e-business security assessment should risks first be identified?
  • What does effective alignment of IT with business strategy ensure?
  • Why do many organizations require mandatory vacations for employees?
  • Which method best supports the prioritization of new IT projects?
  • When prioritizing areas for IT governance implementations, what should be the most important consideration?
  • What is the MOST important objective when implementing an IT governance framework?
  • The chief information security officer typically does NOT handle which of the following tasks?
  • What measure is best for prioritizing IT projects based on overall investment performance?
  • How can an organization best ensure its policies are effective in guiding legal compliance?
  • Which of the following best defines the responsibility of IT management regarding security policies?
  • What is a primary benefit of implementing a source code escrow agreement?
  • When considering a major technology upgrade, what is the MOST crucial factor to evaluate?
  • Which of the following is NOT a recommended reason to keep patient benefit data in-house?
  • Why is conducting periodic audits essential for vendor management?
  • What is the purpose of aligning IT risk with business objectives?
  • What is a significant implementation risk within decision support systems?
  • During an audit, which situation is MOST concerning for an organization that outsources IS processing to a private network?
  • How should segregation of duties be enforced in a scenario with only one DBA having root access?
  • After examining existing e-business applications for vulnerabilities, what should the IS auditor do next?
  • A decision support system primarily aids management in:
  • Which function is typically part of an IT steering committee?
  • Which factor most likely indicates that a customer data warehouse should remain in-house?
  • What positive outcome does strategic alignment in information security governance provide?
  • Which issue is the most concerning when reviewing human resources policies?
  • What is the greatest concern for an IS auditor if they discover several IT projects implemented without approval from the steering committee?
  • Which type of insurance provides coverage for losses arising from fraudulent acts by employees?
  • Which of the following focuses specifically on ensuring business and IT plans are linked?
  • What composition should an IT steering committee ideally have?
  • What should an organization ensure when customizing its approach to email retention?
  • What should be a top priority in the short-term planning for IT departments?
  • The primary benefit of an enterprise architecture initiative is to do what?
  • Which risk management practice is likely to expose an organization to the greatest compliance risk?
  • When unique user accounts are not assigned in a call center, what is the most appropriate recommendation?
  • When reviewing the classification levels of information assets, what is MOST important to consider?
  • Errors in audit procedures PRIMARILY impact which of the following risks?
  • How can the risk associated with electronic evidence gathering be mitigated?
  • What is a LAN administrator typically restricted from?
  • What benefit does using a decision support system provide for management?
  • Who is primarily responsible for establishing the level of acceptable risk within an organization?
  • What should be the IS auditor's approach to incidents not documented in the risk assessment plan?
  • What is an acceptable method for verifying messages within an electronic funds transfer system?
  • Which role is responsible for implementing, monitoring, and enforcing the security rules established by management?
  • What is the primary purpose of a mandatory vacation policy?
  • Which responsibility is NOT typically associated with the IT steering committee?
  • What is the main concern for an IS auditor when a service provider outsources work involving confidential information?
  • What is the main purpose of assessing the performance of an outsourcing provider?
  • Which option best describes the importance of goals and metrics in the context of strategic alignment?
  • When should an IS auditor be most concerned about the security policy?
  • If a team is struggling to project financial losses from a risk, what should they pursue to evaluate the potential impact?
  • Which is considered an effective control for managing risks associated with software products?
  • Which responsibility is most likely assigned to an IT steering committee?
  • What strategy should IT management employ when evaluating new technology implementations?
  • In a feasibility study, why is it important for an IS auditor to review a vendor's business continuity plan?
  • When reviewing the IT short-range plan, what is the primary focus an IS auditor should consider?
  • What role does the executive sponsor play in a security program?
  • What mechanism helps mitigate risks from using a third-party vendor for critical applications?
  • What is the primary purpose of job descriptions from a control perspective?
  • What is essential for an effective IT strategy within an organization?
  • What does a balanced scorecard help organizations measure?
  • Who is typically responsible for approving an information security policy?
  • What should an IS auditor primarily focus on when determining protection levels for an information asset?
  • When should vendors be invited to IT steering committee meetings?
  • What provides the most assurance of confidentiality when a service provider delegates work to a subcontractor?
  • What control best ensures that a service provider's employees adhere to security policies?
  • Which activity is essential for minimizing the risk associated with short-term employees in an IS audit department?
  • What is the first step an IS auditor should take when reviewing the software quality management process?
  • What is the most critical aspect for an IS auditor to consider when reviewing an enterprise's project portfolio?
  • Which method of managing risk involves sharing that risk with another party?
  • In a small IT department where individuals perform more than one role, which practice represents the greatest risk?
  • What is a characteristic of an effective information security compliance program?
  • Which of the following is considered the best enabler for strategic alignment between business and IT?
  • What is the most important element for the successful implementation of IT governance?
  • What is the first step in establishing an information security program?
  • Before evaluating management's risk assessment of information systems, an IS auditor should first review what?
  • To support organizational goals, what should the IT department focus on?
  • What is the primary purpose of an IS control objective?
  • Which role combination represents the biggest risk regarding system access?
  • As a result of profitability pressure, what is the BEST recommendation of an IS auditor to senior management?
  • Which of the following is typically included in an organization's strategic plan?
  • In a contract for a proprietary application solution, what should be included according to best practices?
  • Which method is essential for reviewing the effectiveness of IT investments?
  • Before implementing an IT balanced scorecard, what must an organization define?
  • What is a major role of documentation in the meetings of the IT steering committee?
  • What is of MOST interest to an IS auditor reviewing an organization's risk strategy?
  • Which scenario presents the highest potential risk related to an organization's information security policy?
  • What is the best reason for implementing conditions on secondary employment for IT staff?
  • What is the primary focus when auditing the coordination of IT projects?
  • What must effective IT governance ensure?
  • What is a potential risk when employees are cross-trained for job roles?
  • What is the MOST important element for the effective design of an information security policy?
  • A top-down approach to the development of operational policies primarily ensures what?
  • What is the best method for assessing IT risk?
  • What is the most effective way to achieve value delivery from IT to the business?
  • Why are control objectives important in IT governance?
  • When reviewing a quality management system, what should the IS auditor primarily focus on collecting evidence for?
  • What is the primary consideration when reviewing a vendor for a critical business application?
  • When an IS auditor finds unapproved IT policies that are being followed, what should they do first?
  • Which option is crucial for managing the integrity of a cloud-based application controlled by a department?
  • What is the primary goal of requiring employees to take a mandatory vacation each year?
  • Which measure of security risk should be considered within an IT security risk management program?
  • The increasing rate of technology change emphasizes the importance of which process?
  • What is the GREATEST concern when a department uses a cloud application without consulting IT?
  • Which security clause is MOST important to include in a master services agreement for software protection?
  • Which method is considered the most reliable for assuring the integrity of new staff?
  • Which responsibility should NOT be expected of a chief security officer?
  • What is the PRIMARY benefit of establishing a steering committee for IT investment oversight?
  • Why would an auditor be concerned about outsourcing core activities?
  • What aspect of IT strategy review is relevant for assessing its effectiveness?
  • What is the primary objective of value delivery in effective information security governance?
  • An IS auditor reviews an organizational chart primarily for what reason?
  • What is a key responsibility of senior management concerning risk?
  • What should be a primary concern for an IS auditor regarding the organization's information security policy?
  • Upon termination, what is the most critical action an organization must take?
  • When software development is outsourced to a startup company, what should an IS auditor recommend?
  • Which aspect should concern an IS auditor most when reviewing an information security policy?
  • What method is considered the best for ensuring organizational policies comply with legal requirements?
  • Which risk management strategy is exemplified when an organization requires job rotation?
  • What practice enhances strategic alignment in IT governance?
  • What is the GREATEST concern in evaluating an organization's IT governance framework?
  • What is the primary risk when performance indicators for an IT balanced scorecard are not objectively measurable?
  • What should be of primary concern to an IS auditor reviewing external IT service provider management?
  • Which is a likely consequence of poorly managed electronic evidence?
  • A poor choice of passwords is classified as what type of security issue?
  • When outsourcing IT services, what should IT management primarily focus on?
  • What is one of the primary benefits of using key performance indicators in a service level agreement?
  • After conducting a threat and vulnerability analysis, what is the BEST method to determine whether suggested controls should be implemented?
  • What is the primary goal of requiring system administrators to sign off on daily backups?
  • What is the most effective method for ensuring contract compliance with a vendor after signing?
  • Which factor provides the most value to strategic IT initiative decision-making?
  • What is the greatest risk posed by inadequate policy definition for ownership of data and systems?
  • In what scenario should the IT steering committee focus on strategic matters?
  • What does risk transfer address primarily?
  • When reviewing risk policies, what element should be evaluated last?
  • What is a primary responsibility of an IT steering committee?
  • Which combination of roles should raise the most concern for an IS auditor regarding separation of duties?
  • What critical element should be addressed in an organization's information security program to prevent breaches?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy