Isaca CISA Practice Test Questions and Exam Dumps Part19 Q361-Q380

View Full Isaca CISA Exam Dumps and Practice Test Dumps

 

Question 361. What is the primary purpose of conducting a business continuity plan review after a major organizational change?

1) To eliminate the need for continuity testing
2) To confirm that recovery requirements and procedures still reflect the current environment
3) To reduce the number of business processes
4) To replace all existing recovery personnel

Answer: 2) To confirm that recovery requirements and procedures still reflect the current environment

Explanation:

Major organizational changes can affect business continuity requirements, dependencies, personnel, facilities, applications, and recovery procedures. Examples include mergers, new applications, changes in suppliers, facility relocation, organizational restructuring, and changes to critical business processes. A continuity plan should therefore be reviewed when significant changes occur rather than relying only on a fixed annual review schedule. The review should determine whether recovery priorities, responsibilities, contact information, dependencies, and procedures remain accurate. Changes identified during the review should be incorporated through an appropriate change-management process. This helps ensure that continuity documentation remains useful and reflects the organization’s actual operating environment.

Question 362. Which activity provides the best assurance that emergency contact information in a continuity plan remains usable?

1) Reviewing the contact list only when an incident occurs
2) Asking employees whether they remember the numbers
3) Comparing the list with old organizational records
4) Periodically verifying contact information with responsible personnel**

Answer: 4) Periodically verifying contact information with responsible personnel

Explanation:

Emergency contact information can become outdated when employees change positions, leave the organization, or receive new telephone numbers. Periodic verification with responsible personnel provides direct confirmation that the information remains accurate. The verification process should cover key recovery team members, management contacts, vendors, service providers, emergency facilities, and other parties required during a disruption. Contact information should be protected because it may contain sensitive operational details. Organizations can also test notification mechanisms during continuity exercises to confirm that messages reach the intended personnel. Accurate contact information is essential because even well-designed recovery procedures may fail if responsible individuals cannot be reached when needed.

Question 363. Which factor should be considered when determining the sequence for restoring dependent systems after a major outage?

1) The order in which systems were originally purchased
2) The number of users assigned to each system
3) The technical and business dependencies between systems and processes
4) The age of the hardware supporting each system

Answer: 3) The technical and business dependencies between systems and processes

Explanation:

Recovery sequencing should consider both technical and business dependencies. A critical application may depend on a database, authentication service, network infrastructure, storage platform, or external service before it can operate successfully. Restoring the application without its dependencies may provide little business value and could create additional problems. Recovery priorities should therefore be established based on business impact analysis and documented dependency relationships. Technical teams should understand the order in which infrastructure components must become available, while business owners should confirm the importance of the associated processes. Proper sequencing helps ensure that recovery resources are used efficiently and that critical services can resume in a practical order.

Question 364. What is the primary purpose of a business continuity plan version-control process?

1) To ensure users can identify the current approved version of the plan
2) To prevent management from reviewing the plan
3) To allow employees to make uncontrolled changes
4) To eliminate the need for plan testing

Answer: 1) To ensure users can identify the current approved version of the plan

Explanation:

Version control helps ensure that personnel use the correct and approved continuity procedures during a disruption. Without version control, different departments may retain outdated copies containing incorrect contact information, recovery procedures, system dependencies, or responsibilities. A controlled process should identify the version, approval status, effective date, and significant changes. Obsolete copies should be appropriately withdrawn or clearly identified to prevent accidental use. Electronic plans should also have appropriate access controls and backup arrangements. Version control should be integrated with change management so that significant environmental or organizational changes result in controlled updates. This improves the reliability and consistency of continuity documentation.

Question 365. Which metric is most useful for evaluating whether a recovery exercise achieved its planned recovery objective?

1) Number of employees attending the exercise
2) Number of pages in the recovery plan
3) Actual recovery time compared with the defined recovery target
4) Number of systems listed in the asset inventory

Answer: 3) Actual recovery time compared with the defined recovery target

Explanation:

Comparing actual recovery performance with a predefined recovery target provides measurable evidence of whether the exercise achieved its intended objective. The organization can evaluate how long it took to restore critical services and compare the result with established requirements. Other measures may also be useful, including data recovery success, communication effectiveness, unresolved issues, and successful completion of recovery procedures. Attendance and documentation size do not demonstrate recovery effectiveness by themselves. Exercise results should be documented and analyzed so that weaknesses can be corrected. Repeated testing can then determine whether corrective actions have improved recovery performance and whether recovery capabilities remain aligned with business requirements.

Question 366. What should an organization do when a continuity exercise identifies a significant gap in recovery capability?

1) Ignore the issue if normal operations are unaffected
2) Document the gap, assign responsibility and track corrective action
3) Delete the exercise results
4) Immediately discontinue all continuity exercises

Answer: 2) Document the gap, assign responsibility and track corrective action

Explanation:

A continuity exercise is valuable because it identifies weaknesses before an actual disruption occurs. Significant gaps should therefore be documented and assigned to responsible individuals or teams for remediation. Corrective actions should include an appropriate priority, target completion date, and method for verifying that the issue has been resolved. Depending on the severity, management may need to implement temporary compensating measures while permanent improvements are developed. Merely recording an issue without follow-up does not improve recovery capability. Future exercises should verify whether corrective actions were effective. This creates a continuous improvement cycle in which testing results directly contribute to stronger continuity planning and operational resilience.

Question 367. Which situation most clearly indicates that a third-party continuity capability should be reassessed?

1) The supplier changes its office furniture
2) The supplier publishes a new marketing brochure
3) The supplier hires additional administrative staff
4) The supplier experiences a major change affecting a critical outsourced service**

Answer: 4) The supplier experiences a major change affecting a critical outsourced service

Explanation:

A significant change affecting a critical outsourced service can alter the supplier’s ability to meet continuity requirements. Examples include a major technology migration, acquisition, change in hosting location, subcontractor change, financial difficulty, or modification of recovery architecture. The organization should assess whether the supplier continues to satisfy contractual recovery objectives and security requirements. Depending on the risk, the review may include updated assurance reports, continuity test evidence, revised recovery documentation, or discussions with the provider. Supplier monitoring should be risk-based rather than triggered by insignificant changes. For critical services, maintaining confidence in third-party recovery capabilities is important because the organization’s continuity may depend directly on them.

Question 368. Why should continuity plans identify critical external dependencies?

1) To ensure recovery planning accounts for services the organization does not directly control
2) To eliminate all vendor contracts
3) To transfer business ownership to suppliers
4) To avoid documenting internal dependencies

Answer: 1) To ensure recovery planning accounts for services the organization does not directly control

Explanation:

Organizations often depend on external providers for telecommunications, cloud hosting, payment processing, logistics, software services, utilities, and other essential activities. If these dependencies are omitted from continuity planning, an organization may restore its internal systems while remaining unable to perform critical business processes. External dependencies should therefore be identified and evaluated as part of continuity planning. Relevant contracts should define required service levels, recovery expectations, notification responsibilities, and other important obligations. The organization should also understand the provider’s own dependencies where appropriate. Including external dependencies produces a more realistic recovery strategy and helps management identify situations where additional alternatives or contingency arrangements may be necessary.

Question 369. Which control best reduces the risk that a compromised application programming interface (API) credential can be used indefinitely?

1) Disabling all API functionality
2) Storing the credential in source code
3) Using short-lived credentials with appropriate expiration and rotation
4) Sharing one credential among all applications

Answer: 3) Using short-lived credentials with appropriate expiration and rotation

Explanation:

Short-lived credentials reduce the period during which a compromised credential can be misused. Where technically practical, API authentication mechanisms should use credentials or tokens with limited lifetimes and appropriate scopes. Rotation procedures should replace credentials regularly and provide a mechanism for rapid revocation when compromise is suspected. Credentials should also be protected through appropriate access controls and secrets-management practices. Disabling APIs entirely is generally not practical when applications require integration. Sharing credentials increases the impact of compromise because multiple systems may be affected. Combining limited credential lifetime, least privilege, monitoring, and secure storage provides stronger protection for application interfaces.

Question 370. What is the primary purpose of rate limiting on an Internet-facing API?

1) To increase the size of application databases
2) To restrict excessive requests and reduce abuse or resource exhaustion
3) To eliminate the need for authentication
4) To guarantee that every request is legitimate

Answer: 2) To restrict excessive requests and reduce abuse or resource exhaustion

Explanation:

API rate limiting controls how many requests a user, application, or source can make within a defined period. It can help reduce abuse, automated attacks, excessive resource consumption, and certain denial-of-service conditions. Rate limits should be designed according to legitimate business requirements so that normal users are not unnecessarily prevented from accessing services. Rate limiting does not replace authentication, authorization, input validation, monitoring, or other security controls. Appropriate responses to excessive requests should also be defined and monitored. From an audit perspective, the effectiveness of rate limiting should be evaluated against documented requirements and expected traffic patterns, particularly for externally accessible and business-critical interfaces.

Question 371. Which web application control helps prevent session identifiers from being transmitted over an unencrypted connection?

1) Secure cookie attributes combined with encrypted transport
2) Disabling application logging
3) Increasing database storage capacity
4) Removing session expiration

Answer: 1) Secure cookie attributes combined with encrypted transport

Explanation:

Session identifiers should be protected because an attacker who obtains a valid session token may be able to impersonate the associated user. Using the Secure attribute on session cookies instructs compatible browsers to send those cookies only over encrypted HTTPS connections. Encrypted transport helps protect session information while it travels between the client and server. Other cookie protections, such as HttpOnly and appropriate SameSite settings, can provide additional safeguards against different attack scenarios. Session management should also include suitable expiration and invalidation procedures. These controls work together to reduce the likelihood that session identifiers will be intercepted, exposed, or misused.

Question 372. What should an auditor verify when assessing whether a web application properly validates session termination?

1) That terminated sessions remain active indefinitely
2) That users can reuse expired sessions without authentication
3) That session identifiers are deleted from the database only once per year
4) That logout, expiration or administrative termination invalidates the active session**

Answer: 4) That logout, expiration or administrative termination invalidates the active session

Explanation:

Effective session management should ensure that a session cannot continue to provide access after it has been intentionally terminated or has exceeded its permitted lifetime. An auditor can test whether logging out invalidates the session token and whether expired sessions are rejected when reused. Administrative termination may also be necessary when an account is disabled, compromised, or otherwise requires immediate revocation. Session invalidation should be tested from both normal and abnormal scenarios. Simply removing a session identifier from a client interface may not be sufficient if the server continues to accept it. Proper server-side session invalidation is therefore an important application security control.

Question 373. Which practice best reduces the risk associated with open-source software dependencies used in an application?

1) Allowing developers to download any version without review
2) Maintaining an inventory of dependencies and monitoring them for known vulnerabilities
3) Prohibiting all software updates
4) Removing software documentation

Answer: 2) Maintaining an inventory of dependencies and monitoring them for known vulnerabilities

Explanation:

Open-source dependencies can introduce vulnerabilities or licensing concerns into applications, particularly when organizations do not know which components and versions are being used. Maintaining an inventory allows development and security teams to identify dependencies and determine whether vulnerabilities affect the application. Organizations can use automated scanning and software composition analysis to support this process. When vulnerabilities are identified, remediation should consider exploitability, application exposure, business criticality, and available updates. Dependencies should also be obtained from trusted sources and managed through appropriate development processes. Effective dependency management improves visibility and helps organizations respond more quickly when security issues are discovered in external components.

Question 374. What is the primary purpose of a software bill of materials (SBOM)?

1) To document the components and dependencies contained within software
2) To replace application source code
3) To provide employee performance evaluations
4) To define an organization’s disaster recovery site

Answer: 1) To document the components and dependencies contained within software

Explanation:

A software bill of materials provides an inventory of software components and dependencies included in an application or software product. This visibility can help organizations determine whether a newly discovered vulnerability affects their environment. An SBOM can also support software supply-chain risk management, component tracking, and more efficient vulnerability response. It does not replace source code, security testing, or vulnerability management processes. For effective use, organizations should maintain sufficiently accurate and current component information. Auditors may assess whether appropriate processes exist to identify software components, maintain relevant inventories, and respond when security issues affect components used by business-critical applications.

Question 375. Which control is most effective for detecting unauthorized changes to critical system configurations?

1) Periodic employee satisfaction surveys
2) Increasing system storage capacity
3) Configuration monitoring with alerts for unauthorized changes
4) Removing all configuration documentation

Answer: 3) Configuration monitoring with alerts for unauthorized changes

Explanation:

Configuration monitoring can identify unauthorized changes to critical systems and provide evidence for investigation. Baseline configurations establish the expected state, while monitoring tools compare current settings against approved configurations and can generate alerts when deviations occur. Alerts should be investigated to determine whether changes were authorized, accidental, or malicious. Relevant changes should be traceable to approved requests or emergency procedures. Monitoring is especially important for systems supporting critical services because unauthorized configuration changes can weaken security or affect availability. An effective process combines configuration baselines, change authorization, monitoring, logging, and periodic review to maintain control over important system settings.

Question 376. Which security principle should guide the design of access between microservices?

1) Every service should have unrestricted access to every other service
2) Access should be limited to the specific services and functions required
3) Authentication should be disabled for internal service calls
4) All services should share one administrative account

Answer: 2) Access should be limited to the specific services and functions required

Explanation:

Microservices should communicate according to defined trust relationships and least-privilege requirements. A service should receive only the access needed to perform its intended function rather than unrestricted access to other services. Authentication and authorization should be applied appropriately to service-to-service communication, and sensitive operations should be monitored. Excessive privileges can increase the impact of a compromised service because an attacker may move laterally across the environment. Network segmentation and service-level authorization can further limit unnecessary communication paths. Auditors should evaluate whether service permissions are documented, approved, periodically reviewed, and technically enforced according to business and security requirements.

Question 377. What is the primary purpose of maintaining an audit trail for automated administrative actions?

1) To make automated processing slower
2) To prevent all automation
3) To provide accountability and evidence of actions performed by automated processes
4) To eliminate access reviews

Answer: 3) To provide accountability and evidence of actions performed by automated processes

Explanation:

Automated processes can perform significant administrative or business actions without direct human intervention. Maintaining an appropriate audit trail helps establish what action occurred, when it occurred, which process performed it, and, where applicable, which authorized individual initiated the activity. Logs should be protected against unauthorized modification and retained according to organizational requirements. Monitoring automated activity can also help identify unexpected behavior or misuse of service credentials. Accountability is particularly important when automation performs privileged operations because investigators need sufficient evidence to reconstruct events. Auditors should verify that logging requirements are defined and that important automated activities are actually recorded and reviewable.

Question 378. Which audit procedure best evaluates whether privileged access is being reviewed effectively?

1) Examine evidence that privileged accounts and their assigned permissions were periodically reviewed and exceptions resolved
2) Ask administrators whether they believe reviews are effective
3) Review only ordinary user accounts
4) Confirm that the organization owns a privileged access management product

Answer: 1) Examine evidence that privileged accounts and their assigned permissions were periodically reviewed and exceptions resolved

Explanation:

Effective auditing of privileged access requires evidence that privileged accounts and permissions are periodically reviewed by authorized personnel. The auditor should examine the population of privileged accounts, review frequency, reviewer authorization, identified exceptions, and evidence that inappropriate access was removed or corrected. Merely having a privileged access management product does not prove that access reviews are effective. Interviews can provide useful information but should be supported by reliable evidence. Testing should also consider dormant, shared, emergency, and service-related privileged accounts where applicable. The objective is to determine whether privileged access remains appropriate and whether management responds effectively when inappropriate permissions are identified.

Question 379. What should an auditor evaluate when determining whether an audit finding has been effectively remediated?

1) Whether management verbally states that the issue is closed
2) Whether the original audit report is still available
3) Whether the issue received a high priority initially
4) Whether objective evidence demonstrates that the corrective action was implemented and the underlying condition addressed**

Answer: 4) Whether objective evidence demonstrates that the corrective action was implemented and the underlying condition addressed

Explanation:

Effective follow-up should determine whether management implemented the agreed corrective action and whether the underlying condition that caused the finding has actually been addressed. Auditors should obtain objective evidence appropriate to the control, such as system configurations, transaction records, access reports, procedures, or test results. A management statement alone may not provide sufficient assurance. The auditor should also consider whether the corrective action adequately addresses the original risk rather than merely treating a symptom. If the issue remains unresolved, its status and residual risk should be communicated according to established procedures. Proper follow-up provides assurance that audit recommendations produce meaningful improvements.

Question 380. Which factor should most influence the frequency of an internal audit’s review of a high-risk control?

1) The personal preference of the auditor
2) The level of risk and the likelihood and impact of control failure
3) The number of pages in previous audit reports
4) The age of the organization’s audit software

Answer: 2) The level of risk and the likelihood and impact of control failure

Explanation:

Audit review frequency should be determined using a risk-based approach. Controls associated with higher likelihood or greater impact of failure generally require more frequent attention than controls associated with lower risks. Other factors can also influence frequency, including changes in the business environment, regulatory requirements, prior control deficiencies, system changes, and results from previous assessments. The auditor should document the rationale for the selected frequency and adjust it when risk conditions change. A risk-based schedule helps direct limited audit resources toward areas where assurance can provide the greatest value. It also supports a more dynamic audit program than simply reviewing every control at the same fixed interval.