View Full Isaca CISA Exam Dumps and Practice Test Dumps
Question 341. What is the primary purpose of establishing a maximum tolerable downtime (MTD) for a business process?
1) To determine the number of employees required for recovery
2) To establish the acceptable level of data loss
3) To define the maximum period a process can be unavailable before unacceptable business impact occurs
4) To identify the cost of replacing obsolete hardware
Answer: 3) To define the maximum period a process can be unavailable before unacceptable business impact occurs
Explanation:
Maximum tolerable downtime (MTD) identifies the longest period a business process can remain unavailable before the resulting impact becomes unacceptable to the organization. It supports continuity planning by helping management establish recovery priorities and determine appropriate recovery capabilities. MTD differs from the recovery point objective, which focuses on acceptable data loss, and from recovery time objectives, which define targeted restoration times. During business impact analysis, organizations evaluate operational, financial, regulatory, and reputational consequences to establish appropriate tolerance levels. Defining MTD helps ensure that continuity strategies are aligned with actual business requirements rather than being based solely on technical capabilities or infrastructure limitations.
Question 342. Which condition should primarily trigger invocation of a business continuity plan?
1) A disruption exceeds predefined criteria established for plan activation
2) Any minor system warning is generated
3) A routine maintenance activity is scheduled
4) A user reports a password problem
Answer: 1) A disruption exceeds predefined criteria established for plan activation
Explanation:
A business continuity plan should be invoked when a disruption meets predefined activation criteria established by management. These criteria may include the expected duration of an outage, impact on critical business processes, loss of facilities, significant personnel unavailability, or failure of normal recovery procedures. Clearly defined invocation criteria prevent unnecessary activation for minor incidents while ensuring that serious disruptions receive an organized response. The criteria should be documented, communicated to responsible personnel, and periodically reviewed. Management should also identify who has authority to invoke the plan because delays or uncertainty during a major disruption can increase operational and financial consequences.
Question 343. What is the primary benefit of mapping dependencies among business processes, applications, infrastructure and vendors during continuity planning?
1) It reduces the need for business impact analysis
2) It determines employee performance ratings
3) It eliminates all third-party risks
4) It helps identify the resources that must be recovered together to restore critical services**
Answer: 4) It helps identify the resources that must be recovered together to restore critical services
Explanation:
Dependency mapping shows the relationships between critical business processes and the resources required to support them. These resources can include applications, databases, infrastructure, telecommunications, facilities, employees, and external service providers. Understanding these dependencies helps the organization establish realistic recovery sequences. For example, restoring an application before its required database or network service may not restore the business process successfully. Dependency mapping can therefore reveal hidden recovery requirements and potential bottlenecks. It also supports recovery testing because test scenarios can include the appropriate components and their relationships. This makes continuity planning more complete and aligned with actual operational dependencies.
Question 344. During a prolonged system outage, which approach can best maintain essential business operations when automated processing is unavailable?
1) Disable all business processes until systems are restored
2) Activate documented manual workarounds for critical processes
3) Remove all authorization requirements
4) Allow employees to create undocumented procedures independently
Answer: 2) Activate documented manual workarounds for critical processes
Explanation:
Documented manual workarounds can allow essential business activities to continue when automated systems are unavailable. These procedures should identify which processes can be performed manually, who is authorized to perform them, what records must be maintained, and how transactions will be reconciled after normal operations resume. Manual procedures should be developed and tested before an actual disruption occurs. They should also preserve important controls such as authorization and segregation of duties wherever practical. Undocumented workarounds can introduce errors, fraud opportunities, and inconsistent processing. Properly designed manual procedures therefore provide a controlled temporary operating capability while the organization works toward full system recovery.
Question 345. Who should normally be accountable for ensuring that a business continuity plan remains appropriate for the business process it supports?
1) The external hardware supplier
2) The internal help desk
3) The business process owner
4) The network administrator alone
Answer: 3) The business process owner
Explanation:
The business process owner should generally be accountable for ensuring that continuity requirements remain aligned with the process’s current needs. The owner understands the process’s objectives, critical activities, dependencies, personnel requirements, and acceptable disruption levels. IT and other technical teams provide important support, but they may not have sufficient knowledge of changing business priorities. The process owner should participate in plan reviews, approve relevant recovery requirements, and ensure that changes to the process are reflected in continuity documentation. Clear ownership also improves accountability during exercises and actual disruptions. Responsibilities should be formally documented so that continuity plans do not become outdated or dependent on informal knowledge.
Question 346. Which evidence provides the strongest indication that a disaster recovery procedure has been successfully tested?
1) Documented test results showing expected recovery activities and outcomes
2) A statement from an administrator that the procedure should work
3) An outdated copy of the recovery plan
4) A vendor brochure describing recovery capabilities
Answer: 1) Documented test results showing expected recovery activities and outcomes
Explanation:
Documented recovery test results provide direct evidence that recovery procedures were actually exercised and produced measurable outcomes. Effective test documentation normally records the scenario, systems or processes included, participants, recovery steps performed, actual recovery times, issues encountered, and corrective actions. This evidence allows management and auditors to determine whether recovery objectives were achieved and whether identified weaknesses were addressed. A plan document only demonstrates that procedures have been written; it does not prove that they are effective. Likewise, administrator opinions and vendor statements provide less reliable evidence than direct testing. Regular testing and documented results help confirm that recovery capabilities remain practical as systems and business requirements change.
Question 347. What is the most important characteristic of a realistic business continuity exercise scenario?
1) It should avoid involving critical processes
2) It should test only documentation accuracy
3) It should always use the same scenario
4) It should reflect plausible disruptions and challenge actual recovery capabilities**
Answer: 4) It should reflect plausible disruptions and challenge actual recovery capabilities
Explanation:
A realistic continuity exercise should simulate conditions that the organization could reasonably experience and should challenge the procedures, dependencies, communications, and decisions required during an actual disruption. Scenarios may involve facility loss, system outages, supplier disruption, unavailable personnel, or combinations of these events. Exercises should be designed around identified business risks rather than simply confirming that participants have read the plan. A realistic scenario can expose unclear responsibilities, missing dependencies, inadequate resources, and communication problems. Results should be documented and converted into corrective actions. Repeating identical exercises may provide limited assurance because participants can become familiar with expected events and responses.
Question 348. Which contractual requirement would most directly support continuity of a critical outsourced service?
1) A requirement for the vendor to change its logo periodically
2) Defined recovery requirements, testing obligations and notification responsibilities
3) A restriction on the vendor’s office location
4) A requirement to use a particular programming language
Answer: 2) Defined recovery requirements, testing obligations and notification responsibilities
Explanation:
Contracts for critical outsourced services should include continuity requirements that are consistent with the organization’s business needs. These may include recovery objectives, backup requirements, disaster recovery capabilities, testing frequency, incident notification timelines, and responsibilities during a disruption. Such provisions establish measurable expectations rather than relying on general assurances from the provider. The organization should also obtain evidence that the provider can meet these requirements, such as test results or appropriate assurance reports. Without contractual requirements, a vendor may prioritize its own recovery objectives, which may not match those of the customer. Continuity provisions therefore help manage operational dependency on important external service providers.
Question 349. Why should an organization develop a cloud service exit and portability strategy before depending heavily on a cloud provider?
1) To guarantee that cloud services will never experience outages
2) To eliminate the need for access controls
3) To prepare for migration, termination or provider failure without unacceptable disruption
4) To prevent employees from using cloud applications
Answer: 3) To prepare for migration, termination or provider failure without unacceptable disruption
Explanation:
A cloud exit and portability strategy prepares the organization for situations such as contract termination, provider failure, unacceptable service changes, regulatory requirements, or the need to migrate to another environment. Planning should address data export formats, application dependencies, migration procedures, required resources, contractual termination provisions, and secure handling of data after migration. Organizations should understand whether their data and applications can realistically be transferred without excessive cost or operational disruption. Exit planning is particularly important when services use proprietary technologies or tightly integrated architectures. Establishing these requirements before implementation reduces dependence on assumptions and provides management with a structured approach for future transition.
Question 350. What is the primary purpose of a cryptographic key recovery procedure?
1) To restore access to encrypted information when an authorized key is lost or unavailable
2) To make passwords unnecessary
3) To replace all encryption algorithms automatically
4) To prevent authorized users from decrypting information
Answer: 1) To restore access to encrypted information when an authorized key is lost or unavailable
Explanation:
Cryptographic key recovery procedures provide a controlled method for restoring access to encrypted information when an authorized encryption key becomes unavailable, damaged, or inaccessible. Without appropriate recovery mechanisms, permanently encrypted information could become unusable even when the underlying data remains intact. Key recovery should be carefully controlled because unauthorized access to recovered keys could compromise confidential information. Procedures may include secure backup, recovery authorization, separation of responsibilities, and logging of key-recovery activities. Organizations should also test recovery procedures periodically to verify that keys can actually be retrieved when needed. Effective key recovery supports availability while preserving the confidentiality and integrity objectives of encryption.
Question 351. Which control is most effective for preventing unauthorized exposure of application secrets such as API keys and service credentials?
1) Storing secrets in application source-code comments
2) Including credentials in configuration files shared with all developers
3) Sending credentials through ordinary email
4) Using a centralized secrets-management mechanism with controlled access**
Answer: 4) Using a centralized secrets-management mechanism with controlled access
Explanation:
A centralized secrets-management mechanism provides a controlled location for storing sensitive credentials such as API keys, database passwords, tokens, and service credentials. Applications can retrieve required secrets through authenticated and authorized mechanisms without embedding them directly in source code. Good secrets management also supports access controls, auditing, rotation, and revocation. This reduces the likelihood that credentials will be exposed through source repositories, configuration files, logs, or developer communications. Access to the secrets repository should follow least-privilege principles and should be monitored. Organizations should also establish procedures for rotating compromised credentials and removing secrets that are no longer required.
Question 352. Why are hardcoded credentials in application source code considered a significant security concern?
1) They make applications execute faster than expected
2) They can expose reusable credentials to developers, repositories or unauthorized users
3) They automatically improve application availability
4) They eliminate the need for authentication testing
Answer: 2) They can expose reusable credentials to developers, repositories or unauthorized users
Explanation:
Hardcoded credentials create a significant security risk because sensitive values may become accessible to anyone who can view source code, build artifacts, backups, or source repositories. If the same credentials are reused across environments or systems, a single exposure can create broader compromise. Hardcoded secrets are also difficult to rotate because changing them may require modifying and redeploying application code. Secure development practices should instead retrieve secrets from an appropriately protected secrets-management system or equivalent secure mechanism. Automated code scanning can help identify accidentally committed credentials, while repository controls and secret rotation procedures can reduce exposure. Removing hardcoded credentials improves both security and operational manageability.
Question 353. What is the primary purpose of network access control (NAC)?
1) To increase the physical capacity of network cables
2) To replace all firewalls
3) To control network access based on device or user security requirements
4) To encrypt every database automatically
Answer: 3) To control network access based on device or user security requirements
Explanation:
Network access control helps organizations determine whether users or devices should be permitted to connect to network resources based on defined security requirements. NAC can evaluate characteristics such as identity, device type, security configuration, or compliance status before granting access. For example, an organization may restrict network access for devices that lack required security controls or place them into a limited network segment for remediation. NAC supports enforcement of access policies closer to the point where devices connect. It does not replace all other security mechanisms because firewalls, authentication, endpoint protection, and segmentation continue to serve different purposes within a layered security architecture.
Question 354. What is the main security purpose of switch port security?
1) To restrict unauthorized devices from connecting through designated switch ports
2) To increase Internet bandwidth
3) To encrypt database records
4) To automatically update application software
Answer: 1) To restrict unauthorized devices from connecting through designated switch ports
Explanation:
Switch port security can restrict which devices are permitted to use specific physical network ports. It commonly uses device identifiers or configured policies to limit unauthorized connections. This can reduce the risk of an unauthorized device being connected to an internal network through an available switch port. Depending on the configuration, a violation may cause the port to block traffic, generate an alert, or enter a protective state. Port security should be implemented according to network requirements and managed carefully to avoid disrupting legitimate devices. It is one layer of network protection and should be complemented by stronger identity, authentication, monitoring, and segmentation controls.
Question 355. Which principle is most closely associated with a zero trust security architecture?
1) Trust all internal users by default
2) Grant permanent access after the first successful login
3) Eliminate authentication for internal systems
4) Continuously evaluate access based on identity, context and risk rather than network location alone**
Answer: 4) Continuously evaluate access based on identity, context and risk rather than network location alone
Explanation:
A zero trust approach does not assume that users or devices should automatically be trusted simply because they are inside a traditional network boundary. Access decisions are based on factors such as identity, device condition, requested resource, context, and applicable security policies. Authentication and authorization are therefore treated as ongoing security requirements rather than one-time events. Least-privilege access helps limit what an authenticated subject can do. Monitoring and policy enforcement provide additional protection when circumstances change. Zero trust is not a single product or technology; it represents an architectural approach that reduces reliance on implicit trust and strengthens control over access to organizational resources.
Question 356. What is the primary purpose of threat modeling during application design?
1) To determine the application’s marketing strategy
2) To identify potential threats and weaknesses so appropriate controls can be designed early
3) To replace all application testing
4) To determine employee compensation levels
Answer: 2) To identify potential threats and weaknesses so appropriate controls can be designed early
Explanation:
Threat modeling identifies potential threats, attack paths, trust boundaries, and weaknesses during the design stage of an application. Addressing security concerns early is generally more effective than discovering them after deployment because architecture and design decisions may be easier to change before implementation is complete. The process can consider sensitive data, authentication, authorization, external interfaces, privilege boundaries, and possible misuse scenarios. Threat modeling does not replace security testing; rather, it helps determine where testing and controls should receive attention. The results should be documented and reviewed as the application evolves. Integrating threat modeling into development improves the likelihood that security requirements are incorporated into the architecture.
Question 357. When should a security architecture review ideally occur for a major new information system?
1) Only after the system has been retired
2) After every user has received access
3) Early enough in the design process to influence architecture and control decisions
4) Only after a security incident occurs
Answer: 3) Early enough in the design process to influence architecture and control decisions
Explanation:
A security architecture review is most useful when performed early enough to influence major design decisions. Reviewing architecture before implementation can identify weaknesses involving authentication, authorization, data protection, network boundaries, interfaces, logging, and other security requirements while changes are still practical. Waiting until deployment can make remediation more expensive and may require significant redesign. Reviews should consider business requirements, applicable policies, risks, and the system’s dependencies. Significant architectural changes should trigger additional review because previously approved assumptions may no longer apply. Early security involvement therefore helps integrate appropriate controls into the design rather than attempting to add them after the system is operational.
Question 358. What is the primary purpose of an internal audit quality assurance review?
1) To evaluate whether audit activities comply with applicable professional and organizational requirements
2) To approve every operational change in the organization
3) To replace the audit committee
4) To determine the organization’s annual sales target
Answer: 1) To evaluate whether audit activities comply with applicable professional and organizational requirements
Explanation:
An internal audit quality assurance review evaluates whether audit activities are performed consistently with applicable professional standards, the audit charter, organizational policies, and established methodology. It can assess areas such as planning, documentation, evidence, supervision, reporting, independence, and follow-up. Quality assurance helps identify opportunities to improve the reliability and consistency of audit work. Reviews may be performed internally or through qualified independent assessments, depending on organizational requirements. Findings should lead to appropriate corrective actions and improvements to audit processes. Quality assurance is distinct from management’s operational responsibilities because its focus is on the effectiveness and quality of the audit function itself.
Question 359. What should an internal auditor primarily consider before relying on an external assurance provider’s work?
1) Whether the provider has the largest market share
2) Whether management personally prefers the provider
3) Whether the report contains the most pages
4) Whether the provider’s competence, independence, scope and evidence are sufficient for the intended reliance**
Answer: 4) Whether the provider’s competence, independence, scope and evidence are sufficient for the intended reliance
Explanation:
Before relying on external assurance work, an internal auditor should evaluate whether the external provider is competent and independent and whether the engagement’s scope and evidence are relevant to the internal audit objective. The auditor should understand what was tested, the period covered, applicable criteria, identified exceptions, and limitations of the external work. A report should not automatically be considered sufficient merely because it was issued by an independent organization. Additional procedures may be necessary when the external engagement does not adequately address the internal audit objective. Proper evaluation helps ensure that reliance is based on relevant and reliable assurance rather than the provider’s reputation alone.
Question 360. Which statement best distinguishes a consulting engagement from an assurance engagement in internal audit?
1) Consulting engagements always provide an independent audit opinion
2) Consulting engagements are advisory in nature and generally focus on providing guidance rather than an assurance conclusion
3) Consulting engagements cannot involve risk management topics
4) Consulting engagements eliminate management’s responsibility for decisions
Answer: 2) Consulting engagements are advisory in nature and generally focus on providing guidance rather than an assurance conclusion
Explanation:
A consulting engagement is generally advisory in nature and is intended to provide management with guidance, recommendations, or insight on a particular process, risk, or control issue. An assurance engagement, by contrast, involves an independent evaluation that results in a conclusion about a subject against defined criteria. Internal auditors participating in consulting work must still maintain appropriate objectivity and avoid assuming management responsibilities. Management remains responsible for decisions and implementation of recommendations. Clearly defining the engagement’s objectives, scope, responsibilities, and expected deliverables helps prevent confusion between advisory activities and assurance work and supports appropriate governance of the internal audit function.