Isaca CISA Practice Test Questions and Exam Dumps Part17 Q321-Q340

View Full Isaca CISA Exam Dumps and Practice Test Dumps

 

Question 321. What is the primary purpose of a configuration management database (CMDB)?

1) To identify and maintain information about configuration items and their relationships
2) To replace all network monitoring tools
3) To encrypt every organizational database
4) To approve employee access requests

Answer: 1) To identify and maintain information about configuration items and their relationships

Explanation:

A configuration management database maintains information about configuration items, such as servers, applications, network devices, and services, along with relevant relationships between them. This information can help organizations understand dependencies, assess the potential impact of changes, and support incident and problem management. Auditors may evaluate whether CMDB information is accurate, complete, authorized, and regularly updated. A CMDB does not itself replace network monitoring, provide universal encryption, or approve user access. Its effectiveness depends on maintaining reliable configuration information and integrating appropriate processes for changes, verification, and reconciliation.

Question 322. Which control provides the strongest assurance that an IT asset inventory remains accurate?

1) Maintaining the inventory only in a spreadsheet
2) Updating the inventory whenever someone remembers a change
3) Periodically reconciling inventory records with discovery or procurement information
4) Allowing asset owners to delete records without approval

Answer: 3) Periodically reconciling inventory records with discovery or procurement information

Explanation:

An IT asset inventory should provide an accurate view of hardware, software, and other relevant technology assets. Periodic reconciliation with independent sources, such as automated discovery tools, procurement records, or configuration repositories, can identify missing, duplicate, or unauthorized assets. Auditors should determine whether reconciliation is performed at an appropriate frequency and whether discrepancies are investigated and resolved. A manually maintained spreadsheet can become outdated, while relying on individuals to remember changes creates inconsistent results. Uncontrolled deletion of records can also undermine accountability. Reliable inventory information supports security, licensing, capacity, maintenance, and risk-management activities.

Question 323. What is the primary purpose of a service catalog?

1) To document approved IT services and relevant service information
2) To store employee passwords
3) To replace all incident records
4) To eliminate service-level agreements

Answer: 1) To document approved IT services and relevant service information

Explanation:

A service catalog provides structured information about the IT services an organization offers or supports. It may include service descriptions, availability information, ownership, users, support arrangements, and other relevant details. A well-maintained catalog helps users understand available services and assists management in aligning IT services with business requirements. Auditors can assess whether services are appropriately defined, owned, reviewed, and aligned with approved objectives. A service catalog is not a password repository and does not replace incident records or service-level agreements. Instead, it provides an organized view of services and their associated responsibilities.

Question 324. Which metric is most useful for evaluating the effectiveness of an incident management process?

1) Number of employees in the IT department
2) Average time to resolve incidents compared with the defined target
3) Number of pages in the incident policy
4) Total number of installed applications

Answer: 2) Average time to resolve incidents compared with the defined target

Explanation:

Incident management effectiveness can be evaluated using measurable indicators that reflect how well incidents are handled against established objectives. Mean or average time to resolution, when compared with an agreed target, can indicate whether incidents are being restored within expected timeframes. Other useful measures may include resolution rates, reopened incidents, escalation frequency, and user satisfaction. Auditors should ensure that metrics are clearly defined, consistently calculated, and meaningful for the services being measured. The number of IT employees, policy length, or installed applications does not directly demonstrate incident management effectiveness.

Question 325. What is the main purpose of problem management?

1) To approve every user access request
2) To create new employee accounts
3) To identify and address underlying causes of recurring or significant incidents
4) To replace backup procedures

Answer: 3) To identify and address underlying causes of recurring or significant incidents

Explanation:

Problem management focuses on identifying and addressing the underlying causes of incidents so that recurring issues can be reduced or eliminated. It may involve trend analysis, root cause investigation, known-error management, and preventive actions. This differs from incident management, which primarily focuses on restoring normal service as quickly as practical. Auditors can assess whether recurring incidents are analyzed, whether significant problems are formally tracked, and whether corrective actions are monitored through completion. Effective problem management can improve service reliability by addressing systemic weaknesses rather than repeatedly resolving the same symptoms.

Question 326. Which condition should trigger a review of a business application’s service-level agreement?

1) A change in service requirements or agreed performance expectations
2) An employee changing their office chair
3) A routine password reset
4) A completed printer toner replacement

Answer: 1) A change in service requirements or agreed performance expectations

Explanation:

A service-level agreement should remain aligned with the services and performance expectations agreed between the relevant parties. Significant changes in business requirements, service scope, availability expectations, security requirements, or performance targets can therefore justify an SLA review. Auditors should determine whether SLA review procedures are defined and whether changes are formally approved and documented. Routine activities unrelated to service commitments generally do not require an SLA review. Keeping agreements current helps ensure that performance is measured against relevant expectations and that responsibilities remain clearly understood by service providers and business stakeholders.

Question 327. What is the primary purpose of service-level monitoring?

1) To eliminate the need for service providers
2) To determine whether agreed service performance requirements are being achieved
3) To increase the number of system users
4) To prevent all system changes

Answer: 2) To determine whether agreed service performance requirements are being achieved

Explanation:

Service-level monitoring compares actual service performance with defined commitments and objectives. Measures can include availability, response time, resolution time, capacity, or other indicators specified in the relevant agreement. Auditors should assess whether measurements are based on clearly defined criteria, collected reliably, reported to responsible stakeholders, and followed by appropriate action when targets are missed. Monitoring should provide evidence about actual performance rather than simply confirming that an agreement exists. It also helps management identify trends and determine whether contractual or operational corrective actions are necessary.

Question 328. Which approach best supports effective IT capacity planning?

1) Increasing capacity only after systems fail
2) Ignoring historical utilization data
3) Monitoring trends and forecasting future resource requirements
4) Purchasing maximum possible capacity for every system

Answer: 3) Monitoring trends and forecasting future resource requirements

Explanation:

Effective capacity planning uses current utilization, historical trends, business growth expectations, and workload forecasts to determine future resource requirements. This allows management to identify potential constraints before they affect service performance and helps avoid unnecessary overinvestment. Auditors should examine whether capacity thresholds are defined, utilization is monitored, forecasts are documented, and planned increases are aligned with business requirements. Waiting until a system fails is reactive and can result in service disruption. Conversely, purchasing the maximum possible capacity for every system may create unnecessary costs. Capacity planning should balance performance, availability, scalability, and economic considerations.

Question 329. Which control is most important when an organization uses automated job scheduling for critical batch processing?

1) Ensuring job dependencies, schedules, failures, and completion status are monitored
2) Allowing every administrator to modify schedules without approval
3) Removing all job execution logs
4) Running every job manually

Answer: 1) Ensuring job dependencies, schedules, failures, and completion status are monitored

Explanation:

Automated batch processing often supports important business activities, so failures or incorrect sequencing can affect downstream systems and reports. Effective scheduling controls should address job dependencies, execution timing, failure handling, restart procedures, and completion monitoring. Access to modify schedules should also be restricted and changes should follow appropriate approval processes. Auditors can examine execution logs and exception reports to determine whether failed or delayed jobs are identified and investigated. Running every job manually would reduce automation benefits and could introduce additional human error. Strong monitoring helps ensure that scheduled processing occurs completely, accurately, and on time.

Question 330. What is the primary purpose of an interface control between two applications?

1) To increase employee privileges
2) To ensure data transferred between systems is complete, accurate, and authorized
3) To eliminate application testing
4) To replace database backups

Answer: 2) To ensure data transferred between systems is complete, accurate, and authorized

Explanation:

Interface controls help ensure that information exchanged between applications is transferred completely, accurately, and according to defined authorization requirements. Controls can include validation, record counts, control totals, error handling, reconciliation, duplicate detection, and exception reporting. Auditors should assess whether interfaces have clearly defined control requirements and whether failed or rejected transactions are appropriately investigated. Without effective interface controls, errors in one system can propagate into another system and affect reports or business processing. Interface controls complement, rather than replace, application testing and backup procedures.

Question 331. Which control best detects transactions that were accepted by a source system but not successfully received by a destination system?

1) Network password complexity
2) Physical access monitoring
3) Interface reconciliation using control totals or record counts
4) Software license tracking

Answer: 3) Interface reconciliation using control totals or record counts

Explanation:

Interface reconciliation compares information sent by a source system with information successfully received and processed by the destination system. Control totals, record counts, hash totals, or other reconciliation mechanisms can identify missing, duplicated, or rejected transactions. Auditors should verify that reconciliation is performed at an appropriate frequency and that differences are investigated and resolved. Other security controls, such as password policies and physical access monitoring, address different risks. Effective interface reconciliation is particularly important when automated transfers support financial, operational, or regulatory reporting because undetected transmission errors can lead to incomplete or inaccurate downstream information.

Question 332. What is the main purpose of an exception-handling procedure in an automated process?

1) To ensure unusual or failed conditions are identified, investigated, and appropriately resolved
2) To prevent all automated processing
3) To allow users to bypass authorization controls
4) To permanently delete failed transactions

Answer: 1) To ensure unusual or failed conditions are identified, investigated, and appropriately resolved

Explanation:

Exception handling provides a structured response when automated processing encounters conditions outside normal expectations. Examples include rejected transactions, missing data, failed jobs, duplicate records, or invalid input. Effective procedures should identify exceptions, assign responsibility, preserve relevant information, investigate causes, and document resolution. Auditors should determine whether exceptions are reviewed promptly and whether unresolved issues are escalated according to defined requirements. Automatically deleting failed transactions can remove evidence and make investigation difficult. Allowing users to bypass authorization controls also introduces additional risk. Well-designed exception handling ensures that unusual conditions do not silently remain unresolved.

Question 333. Which activity best demonstrates that an application control continues to operate effectively after implementation?

1) Reviewing only the original project proposal
2) Performing periodic testing of the control using current transactions
3) Assuming the control remains effective because it worked during development
4) Removing all control documentation

Answer: 2) Performing periodic testing of the control using current transactions

Explanation:

Application controls can become ineffective when requirements, configurations, interfaces, data structures, or business processes change. Periodic testing using current transactions provides evidence that controls continue to operate as intended. Depending on the control, testing may involve inspection, reperformance, data analysis, or other appropriate procedures. Auditors should consider the control’s risk and significance when determining the extent and frequency of testing. A successful test during initial implementation does not prove continued effectiveness. Ongoing assurance is especially important for automated controls because configuration changes or system upgrades can alter their behavior.

Question 334. Which factor should most influence the frequency of reviewing an automated control?

1) The color of the application’s user interface
2) The number of pages in the control documentation
3) The risk and significance of the process controlled
4) The age of the organization’s office building

Answer: 3) The risk and significance of the process controlled

Explanation:

Control review frequency should be determined by risk, business significance, likelihood of change, and the potential impact of control failure. Critical processes with significant financial, operational, security, or compliance consequences generally require more rigorous and appropriately frequent review than low-risk activities. Auditors should evaluate whether management has established a rational review methodology and whether the frequency is adjusted when risk changes. Factors such as interface appearance, documentation length, or office age do not meaningfully determine control-review requirements. A risk-based approach ensures that monitoring resources are focused where control failures could have the greatest consequences.

Question 335. What is the primary purpose of a software escrow arrangement?

1) To provide an independent party with source code for release under predefined conditions
2) To eliminate software licensing requirements
3) To guarantee that software contains no defects
4) To prevent all vendor access to an application

Answer: 1) To provide an independent party with source code for release under predefined conditions

Explanation:

Software escrow arrangements are designed to protect an organization’s access to critical source code when it depends on an external software provider. Source code and related materials may be deposited with an independent escrow agent and released to the customer when predefined conditions occur, such as a vendor’s failure to provide required support or other contractually specified events. Auditors should review whether the escrow agreement clearly defines release conditions, deposited materials, verification procedures, and responsibilities. Escrow does not guarantee software quality or eliminate licensing obligations. Its primary purpose is to reduce dependency risk when continued access to source code is important.

Question 336. Which control best reduces the risk of unauthorized software being installed on corporate endpoints?

1) Increasing the number of available applications
2) Allowlisting approved software and restricting installation privileges
3) Disabling all system logs
4) Giving standard users administrative rights

Answer: 2) Allowlisting approved software and restricting installation privileges

Explanation:

Application allowlisting permits only approved software to execute or be installed according to defined organizational rules. Combined with restricted installation privileges, it can reduce the likelihood of unauthorized or malicious software being introduced onto endpoints. Auditors should examine whether the approved software list is maintained, exceptions are authorized, and changes follow appropriate procedures. Giving standard users administrative privileges would increase their ability to install unauthorized software and potentially weaken endpoint security. Disabling logs would also reduce visibility into software installation activity. Controls should be balanced with legitimate business requirements so that authorized applications remain available.

Question 337. What is the primary purpose of a software patch management process?

1) To increase the number of unsupported applications
2) To ensure security and functional updates are evaluated, approved, deployed, and verified
3) To prevent all software changes
4) To replace vulnerability assessments

Answer: 2) To ensure security and functional updates are evaluated, approved, deployed, and verified

Explanation:

Patch management provides a structured process for identifying available updates, assessing their relevance and risk, testing where appropriate, deploying approved patches, and verifying successful installation. Timely patching can reduce exposure to known vulnerabilities and address software defects. Auditors should evaluate whether patching responsibilities are defined, critical patches are prioritized appropriately, exceptions are documented, and deployment results are verified. Patch management complements vulnerability management rather than replacing it. An organization may identify a vulnerability through scanning but still require patch-management processes to ensure the appropriate remediation is implemented consistently across affected systems.

Question 338. Which action should occur when a critical system cannot be patched within the required timeframe?

1) Ignore the vulnerability until the next annual audit
2) Remove all monitoring controls
3) Document the exception and implement appropriate compensating risk controls
4) Give unrestricted administrative access to users

Answer: 3) Document the exception and implement appropriate compensating risk controls

Explanation:

When a critical system cannot be patched promptly because of technical, operational, or compatibility constraints, management should formally document the exception and assess the associated risk. Appropriate compensating controls may include network isolation, enhanced monitoring, access restrictions, application controls, or other measures that reduce exposure until permanent remediation is possible. Auditors should verify that exceptions are authorized by the appropriate risk owner, have defined expiration or review requirements, and are periodically reassessed. Ignoring the vulnerability or removing monitoring would increase risk. Compensating controls should be proportionate to the exposure and should not become an indefinite substitute for remediation without management approval.

Question 339. What is the primary purpose of a technology refresh strategy?

1) To ensure technology remains supportable, secure, and aligned with business requirements
2) To replace every system regardless of condition
3) To eliminate asset inventories
4) To prevent all technology upgrades

Answer: 1) To ensure technology remains supportable, secure, and aligned with business requirements

Explanation:

A technology refresh strategy helps organizations plan the replacement or upgrade of hardware, software, and infrastructure before they become unsuitable or unsupported. Factors can include vendor support lifecycles, security risks, performance, compatibility, capacity, business requirements, and total cost of ownership. Auditors can assess whether refresh decisions are based on documented criteria and whether aging or unsupported assets are identified and managed appropriately. The goal is not to replace every system regardless of need. A risk-based refresh strategy helps maintain reliable operations while avoiding unnecessary expenditures and reducing exposure associated with obsolete technologies.

Question 340. Which control is most important when decommissioning an application that contains sensitive organizational data?

1) Leaving administrator accounts active indefinitely
2) Ensuring required data is retained or migrated and unnecessary data and access are securely removed
3) Removing all audit records immediately
4) Keeping the application accessible to all users after retirement

Answer: 2) Ensuring required data is retained or migrated and unnecessary data and access are securely removed

Explanation:

Application decommissioning should address both information retention and security. Before retirement, required data should be identified, preserved or migrated according to business and retention requirements, and validated for completeness. Unnecessary accounts, credentials, integrations, and access paths should then be removed. Relevant audit records may need to be retained rather than immediately deleted. Auditors should examine whether decommissioning is formally authorized, documented, tested, and supported by evidence that data and access were handled appropriately. Leaving retired systems or accounts accessible can create unnecessary security exposure, while premature deletion can result in loss of required information.