{"id":13847,"date":"2026-09-16T11:18:13","date_gmt":"2026-09-16T11:18:13","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=13847"},"modified":"2026-09-16T11:18:13","modified_gmt":"2026-09-16T11:18:13","slug":"isaca-cisa-practice-test-questions-and-exam-dumps-part17-q321-q340","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-cisa-practice-test-questions-and-exam-dumps-part17-q321-q340\/","title":{"rendered":"Isaca CISA Practice Test Questions and Exam Dumps Part17 Q321-Q340"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cisa-exam-dumps\"><b>Isaca CISA Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Question 321. What is the primary purpose of a configuration management database (CMDB)?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To identify and maintain information about configuration items and their relationships<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To replace all network monitoring tools<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To encrypt every organizational database<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To approve employee access requests<\/span><\/p>\n<p><b>Answer: 1) To identify and maintain information about configuration items and their relationships<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A configuration management database maintains information about configuration items, such as servers, applications, network devices, and services, along with relevant relationships between them. This information can help organizations understand dependencies, assess the potential impact of changes, and support incident and problem management. Auditors may evaluate whether CMDB information is accurate, complete, authorized, and regularly updated. A CMDB does not itself replace network monitoring, provide universal encryption, or approve user access. Its effectiveness depends on maintaining reliable configuration information and integrating appropriate processes for changes, verification, and reconciliation.<\/span><\/p>\n<h3><b>Question 322. Which control provides the strongest assurance that an IT asset inventory remains accurate?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Maintaining the inventory only in a spreadsheet<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Updating the inventory whenever someone remembers a change<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Periodically reconciling inventory records with discovery or procurement information<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Allowing asset owners to delete records without approval<\/span><\/p>\n<p><b>Answer: 3) Periodically reconciling inventory records with discovery or procurement information<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An IT asset inventory should provide an accurate view of hardware, software, and other relevant technology assets. Periodic reconciliation with independent sources, such as automated discovery tools, procurement records, or configuration repositories, can identify missing, duplicate, or unauthorized assets. Auditors should determine whether reconciliation is performed at an appropriate frequency and whether discrepancies are investigated and resolved. A manually maintained spreadsheet can become outdated, while relying on individuals to remember changes creates inconsistent results. Uncontrolled deletion of records can also undermine accountability. Reliable inventory information supports security, licensing, capacity, maintenance, and risk-management activities.<\/span><\/p>\n<h3><b>Question 323. What is the primary purpose of a service catalog?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To document approved IT services and relevant service information<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To store employee passwords<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To replace all incident records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To eliminate service-level agreements<\/span><\/p>\n<p><b>Answer: 1) To document approved IT services and relevant service information<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A service catalog provides structured information about the IT services an organization offers or supports. It may include service descriptions, availability information, ownership, users, support arrangements, and other relevant details. A well-maintained catalog helps users understand available services and assists management in aligning IT services with business requirements. Auditors can assess whether services are appropriately defined, owned, reviewed, and aligned with approved objectives. A service catalog is not a password repository and does not replace incident records or service-level agreements. Instead, it provides an organized view of services and their associated responsibilities.<\/span><\/p>\n<h3><b>Question 324. Which metric is most useful for evaluating the effectiveness of an incident management process?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Number of employees in the IT department<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Average time to resolve incidents compared with the defined target<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Number of pages in the incident policy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Total number of installed applications<\/span><\/p>\n<p><b>Answer: 2) Average time to resolve incidents compared with the defined target<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Incident management effectiveness can be evaluated using measurable indicators that reflect how well incidents are handled against established objectives. Mean or average time to resolution, when compared with an agreed target, can indicate whether incidents are being restored within expected timeframes. Other useful measures may include resolution rates, reopened incidents, escalation frequency, and user satisfaction. Auditors should ensure that metrics are clearly defined, consistently calculated, and meaningful for the services being measured. The number of IT employees, policy length, or installed applications does not directly demonstrate incident management effectiveness.<\/span><\/p>\n<h3><b>Question 325. What is the main purpose of problem management?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To approve every user access request<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To create new employee accounts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To identify and address underlying causes of recurring or significant incidents<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To replace backup procedures<\/span><\/p>\n<p><b>Answer: 3) To identify and address underlying causes of recurring or significant incidents<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Problem management focuses on identifying and addressing the underlying causes of incidents so that recurring issues can be reduced or eliminated. It may involve trend analysis, root cause investigation, known-error management, and preventive actions. This differs from incident management, which primarily focuses on restoring normal service as quickly as practical. Auditors can assess whether recurring incidents are analyzed, whether significant problems are formally tracked, and whether corrective actions are monitored through completion. Effective problem management can improve service reliability by addressing systemic weaknesses rather than repeatedly resolving the same symptoms.<\/span><\/p>\n<h3><b>Question 326. Which condition should trigger a review of a business application&#8217;s service-level agreement?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> A change in service requirements or agreed performance expectations<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> An employee changing their office chair<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> A routine password reset<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> A completed printer toner replacement<\/span><\/p>\n<p><b>Answer: 1) A change in service requirements or agreed performance expectations<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A service-level agreement should remain aligned with the services and performance expectations agreed between the relevant parties. Significant changes in business requirements, service scope, availability expectations, security requirements, or performance targets can therefore justify an SLA review. Auditors should determine whether SLA review procedures are defined and whether changes are formally approved and documented. Routine activities unrelated to service commitments generally do not require an SLA review. Keeping agreements current helps ensure that performance is measured against relevant expectations and that responsibilities remain clearly understood by service providers and business stakeholders.<\/span><\/p>\n<h3><b>Question 327. What is the primary purpose of service-level monitoring?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To eliminate the need for service providers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To determine whether agreed service performance requirements are being achieved<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To increase the number of system users<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To prevent all system changes<\/span><\/p>\n<p><b>Answer: 2) To determine whether agreed service performance requirements are being achieved<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Service-level monitoring compares actual service performance with defined commitments and objectives. Measures can include availability, response time, resolution time, capacity, or other indicators specified in the relevant agreement. Auditors should assess whether measurements are based on clearly defined criteria, collected reliably, reported to responsible stakeholders, and followed by appropriate action when targets are missed. Monitoring should provide evidence about actual performance rather than simply confirming that an agreement exists. It also helps management identify trends and determine whether contractual or operational corrective actions are necessary.<\/span><\/p>\n<h3><b>Question 328. Which approach best supports effective IT capacity planning?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Increasing capacity only after systems fail<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Ignoring historical utilization data<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Monitoring trends and forecasting future resource requirements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Purchasing maximum possible capacity for every system<\/span><\/p>\n<p><b>Answer: 3) Monitoring trends and forecasting future resource requirements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Effective capacity planning uses current utilization, historical trends, business growth expectations, and workload forecasts to determine future resource requirements. This allows management to identify potential constraints before they affect service performance and helps avoid unnecessary overinvestment. Auditors should examine whether capacity thresholds are defined, utilization is monitored, forecasts are documented, and planned increases are aligned with business requirements. Waiting until a system fails is reactive and can result in service disruption. Conversely, purchasing the maximum possible capacity for every system may create unnecessary costs. Capacity planning should balance performance, availability, scalability, and economic considerations.<\/span><\/p>\n<h3><b>Question 329. Which control is most important when an organization uses automated job scheduling for critical batch processing?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Ensuring job dependencies, schedules, failures, and completion status are monitored<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Allowing every administrator to modify schedules without approval<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Removing all job execution logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Running every job manually<\/span><\/p>\n<p><b>Answer: 1) Ensuring job dependencies, schedules, failures, and completion status are monitored<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Automated batch processing often supports important business activities, so failures or incorrect sequencing can affect downstream systems and reports. Effective scheduling controls should address job dependencies, execution timing, failure handling, restart procedures, and completion monitoring. Access to modify schedules should also be restricted and changes should follow appropriate approval processes. Auditors can examine execution logs and exception reports to determine whether failed or delayed jobs are identified and investigated. Running every job manually would reduce automation benefits and could introduce additional human error. Strong monitoring helps ensure that scheduled processing occurs completely, accurately, and on time.<\/span><\/p>\n<h3><b>Question 330. What is the primary purpose of an interface control between two applications?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To increase employee privileges<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To ensure data transferred between systems is complete, accurate, and authorized<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To eliminate application testing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To replace database backups<\/span><\/p>\n<p><b>Answer: 2) To ensure data transferred between systems is complete, accurate, and authorized<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Interface controls help ensure that information exchanged between applications is transferred completely, accurately, and according to defined authorization requirements. Controls can include validation, record counts, control totals, error handling, reconciliation, duplicate detection, and exception reporting. Auditors should assess whether interfaces have clearly defined control requirements and whether failed or rejected transactions are appropriately investigated. Without effective interface controls, errors in one system can propagate into another system and affect reports or business processing. Interface controls complement, rather than replace, application testing and backup procedures.<\/span><\/p>\n<h3><b>Question 331. Which control best detects transactions that were accepted by a source system but not successfully received by a destination system?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Network password complexity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Physical access monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Interface reconciliation using control totals or record counts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Software license tracking<\/span><\/p>\n<p><b>Answer: 3) Interface reconciliation using control totals or record counts<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Interface reconciliation compares information sent by a source system with information successfully received and processed by the destination system. Control totals, record counts, hash totals, or other reconciliation mechanisms can identify missing, duplicated, or rejected transactions. Auditors should verify that reconciliation is performed at an appropriate frequency and that differences are investigated and resolved. Other security controls, such as password policies and physical access monitoring, address different risks. Effective interface reconciliation is particularly important when automated transfers support financial, operational, or regulatory reporting because undetected transmission errors can lead to incomplete or inaccurate downstream information.<\/span><\/p>\n<h3><b>Question 332. What is the main purpose of an exception-handling procedure in an automated process?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To ensure unusual or failed conditions are identified, investigated, and appropriately resolved<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To prevent all automated processing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To allow users to bypass authorization controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To permanently delete failed transactions<\/span><\/p>\n<p><b>Answer: 1) To ensure unusual or failed conditions are identified, investigated, and appropriately resolved<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Exception handling provides a structured response when automated processing encounters conditions outside normal expectations. Examples include rejected transactions, missing data, failed jobs, duplicate records, or invalid input. Effective procedures should identify exceptions, assign responsibility, preserve relevant information, investigate causes, and document resolution. Auditors should determine whether exceptions are reviewed promptly and whether unresolved issues are escalated according to defined requirements. Automatically deleting failed transactions can remove evidence and make investigation difficult. Allowing users to bypass authorization controls also introduces additional risk. Well-designed exception handling ensures that unusual conditions do not silently remain unresolved.<\/span><\/p>\n<h3><b>Question 333. Which activity best demonstrates that an application control continues to operate effectively after implementation?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Reviewing only the original project proposal<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Performing periodic testing of the control using current transactions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Assuming the control remains effective because it worked during development<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Removing all control documentation<\/span><\/p>\n<p><b>Answer: 2) Performing periodic testing of the control using current transactions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application controls can become ineffective when requirements, configurations, interfaces, data structures, or business processes change. Periodic testing using current transactions provides evidence that controls continue to operate as intended. Depending on the control, testing may involve inspection, reperformance, data analysis, or other appropriate procedures. Auditors should consider the control&#8217;s risk and significance when determining the extent and frequency of testing. A successful test during initial implementation does not prove continued effectiveness. Ongoing assurance is especially important for automated controls because configuration changes or system upgrades can alter their behavior.<\/span><\/p>\n<h3><b>Question 334. Which factor should most influence the frequency of reviewing an automated control?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> The color of the application&#8217;s user interface<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> The number of pages in the control documentation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> The risk and significance of the process controlled<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> The age of the organization&#8217;s office building<\/span><\/p>\n<p><b>Answer: 3) The risk and significance of the process controlled<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Control review frequency should be determined by risk, business significance, likelihood of change, and the potential impact of control failure. Critical processes with significant financial, operational, security, or compliance consequences generally require more rigorous and appropriately frequent review than low-risk activities. Auditors should evaluate whether management has established a rational review methodology and whether the frequency is adjusted when risk changes. Factors such as interface appearance, documentation length, or office age do not meaningfully determine control-review requirements. A risk-based approach ensures that monitoring resources are focused where control failures could have the greatest consequences.<\/span><\/p>\n<h3><b>Question 335. What is the primary purpose of a software escrow arrangement?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To provide an independent party with source code for release under predefined conditions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To eliminate software licensing requirements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To guarantee that software contains no defects<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To prevent all vendor access to an application<\/span><\/p>\n<p><b>Answer: 1) To provide an independent party with source code for release under predefined conditions<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Software escrow arrangements are designed to protect an organization&#8217;s access to critical source code when it depends on an external software provider. Source code and related materials may be deposited with an independent escrow agent and released to the customer when predefined conditions occur, such as a vendor&#8217;s failure to provide required support or other contractually specified events. Auditors should review whether the escrow agreement clearly defines release conditions, deposited materials, verification procedures, and responsibilities. Escrow does not guarantee software quality or eliminate licensing obligations. Its primary purpose is to reduce dependency risk when continued access to source code is important.<\/span><\/p>\n<h3><b>Question 336. Which control best reduces the risk of unauthorized software being installed on corporate endpoints?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Increasing the number of available applications<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Allowlisting approved software and restricting installation privileges<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Disabling all system logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Giving standard users administrative rights<\/span><\/p>\n<p><b>Answer: 2) Allowlisting approved software and restricting installation privileges<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application allowlisting permits only approved software to execute or be installed according to defined organizational rules. Combined with restricted installation privileges, it can reduce the likelihood of unauthorized or malicious software being introduced onto endpoints. Auditors should examine whether the approved software list is maintained, exceptions are authorized, and changes follow appropriate procedures. Giving standard users administrative privileges would increase their ability to install unauthorized software and potentially weaken endpoint security. Disabling logs would also reduce visibility into software installation activity. Controls should be balanced with legitimate business requirements so that authorized applications remain available.<\/span><\/p>\n<h3><b>Question 337. What is the primary purpose of a software patch management process?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To increase the number of unsupported applications<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To ensure security and functional updates are evaluated, approved, deployed, and verified<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To prevent all software changes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To replace vulnerability assessments<\/span><\/p>\n<p><b>Answer: 2) To ensure security and functional updates are evaluated, approved, deployed, and verified<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Patch management provides a structured process for identifying available updates, assessing their relevance and risk, testing where appropriate, deploying approved patches, and verifying successful installation. Timely patching can reduce exposure to known vulnerabilities and address software defects. Auditors should evaluate whether patching responsibilities are defined, critical patches are prioritized appropriately, exceptions are documented, and deployment results are verified. Patch management complements vulnerability management rather than replacing it. An organization may identify a vulnerability through scanning but still require patch-management processes to ensure the appropriate remediation is implemented consistently across affected systems.<\/span><\/p>\n<h3><b>Question 338. Which action should occur when a critical system cannot be patched within the required timeframe?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Ignore the vulnerability until the next annual audit<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Remove all monitoring controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Document the exception and implement appropriate compensating risk controls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Give unrestricted administrative access to users<\/span><\/p>\n<p><b>Answer: 3) Document the exception and implement appropriate compensating risk controls<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">When a critical system cannot be patched promptly because of technical, operational, or compatibility constraints, management should formally document the exception and assess the associated risk. Appropriate compensating controls may include network isolation, enhanced monitoring, access restrictions, application controls, or other measures that reduce exposure until permanent remediation is possible. Auditors should verify that exceptions are authorized by the appropriate risk owner, have defined expiration or review requirements, and are periodically reassessed. Ignoring the vulnerability or removing monitoring would increase risk. Compensating controls should be proportionate to the exposure and should not become an indefinite substitute for remediation without management approval.<\/span><\/p>\n<h3><b>Question 339. What is the primary purpose of a technology refresh strategy?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To ensure technology remains supportable, secure, and aligned with business requirements<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To replace every system regardless of condition<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To eliminate asset inventories<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To prevent all technology upgrades<\/span><\/p>\n<p><b>Answer: 1) To ensure technology remains supportable, secure, and aligned with business requirements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A technology refresh strategy helps organizations plan the replacement or upgrade of hardware, software, and infrastructure before they become unsuitable or unsupported. Factors can include vendor support lifecycles, security risks, performance, compatibility, capacity, business requirements, and total cost of ownership. Auditors can assess whether refresh decisions are based on documented criteria and whether aging or unsupported assets are identified and managed appropriately. The goal is not to replace every system regardless of need. A risk-based refresh strategy helps maintain reliable operations while avoiding unnecessary expenditures and reducing exposure associated with obsolete technologies.<\/span><\/p>\n<h3><b>Question 340. Which control is most important when decommissioning an application that contains sensitive organizational data?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Leaving administrator accounts active indefinitely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Ensuring required data is retained or migrated and unnecessary data and access are securely removed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Removing all audit records immediately<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Keeping the application accessible to all users after retirement<\/span><\/p>\n<p><b>Answer: 2) Ensuring required data is retained or migrated and unnecessary data and access are securely removed<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application decommissioning should address both information retention and security. Before retirement, required data should be identified, preserved or migrated according to business and retention requirements, and validated for completeness. Unnecessary accounts, credentials, integrations, and access paths should then be removed. Relevant audit records may need to be retained rather than immediately deleted. Auditors should examine whether decommissioning is formally authorized, documented, tested, and supported by evidence that data and access were handled appropriately. Leaving retired systems or accounts accessible can create unnecessary security exposure, while premature deletion can result in loss of required information.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca CISA Exam Dumps and Practice Test Dumps &nbsp; Question 321. What is the primary purpose of a configuration management database (CMDB)? 1) To identify and maintain information about configuration items and their relationships 2) To replace all network monitoring tools 3) To encrypt every organizational database 4) To approve employee access requests [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/13847"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=13847"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/13847\/revisions"}],"predecessor-version":[{"id":13853,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/13847\/revisions\/13853"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=13847"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=13847"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=13847"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}