{"id":13849,"date":"2026-09-16T11:17:47","date_gmt":"2026-09-16T11:17:47","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=13849"},"modified":"2026-09-16T11:17:47","modified_gmt":"2026-09-16T11:17:47","slug":"isaca-cisa-practice-test-questions-and-exam-dumps-part19-q361-q380","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/isaca-cisa-practice-test-questions-and-exam-dumps-part19-q361-q380\/","title":{"rendered":"Isaca CISA Practice Test Questions and Exam Dumps Part19 Q361-Q380"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/cisa-exam-dumps\"><b>Isaca CISA Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Question 361. What is the primary purpose of conducting a business continuity plan review after a major organizational change?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To eliminate the need for continuity testing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To confirm that recovery requirements and procedures still reflect the current environment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To reduce the number of business processes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To replace all existing recovery personnel<\/span><\/p>\n<p><b>Answer: 2) To confirm that recovery requirements and procedures still reflect the current environment<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Major organizational changes can affect business continuity requirements, dependencies, personnel, facilities, applications, and recovery procedures. Examples include mergers, new applications, changes in suppliers, facility relocation, organizational restructuring, and changes to critical business processes. A continuity plan should therefore be reviewed when significant changes occur rather than relying only on a fixed annual review schedule. The review should determine whether recovery priorities, responsibilities, contact information, dependencies, and procedures remain accurate. Changes identified during the review should be incorporated through an appropriate change-management process. This helps ensure that continuity documentation remains useful and reflects the organization&#8217;s actual operating environment.<\/span><\/p>\n<h3><b>Question 362. Which activity provides the best assurance that emergency contact information in a continuity plan remains usable?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Reviewing the contact list only when an incident occurs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Asking employees whether they remember the numbers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Comparing the list with old organizational records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Periodically verifying contact information with responsible personnel**<\/span><\/p>\n<p><b>Answer: 4) Periodically verifying contact information with responsible personnel<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Emergency contact information can become outdated when employees change positions, leave the organization, or receive new telephone numbers. Periodic verification with responsible personnel provides direct confirmation that the information remains accurate. The verification process should cover key recovery team members, management contacts, vendors, service providers, emergency facilities, and other parties required during a disruption. Contact information should be protected because it may contain sensitive operational details. Organizations can also test notification mechanisms during continuity exercises to confirm that messages reach the intended personnel. Accurate contact information is essential because even well-designed recovery procedures may fail if responsible individuals cannot be reached when needed.<\/span><\/p>\n<h3><b>Question 363. Which factor should be considered when determining the sequence for restoring dependent systems after a major outage?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> The order in which systems were originally purchased<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> The number of users assigned to each system<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> The technical and business dependencies between systems and processes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> The age of the hardware supporting each system<\/span><\/p>\n<p><b>Answer: 3) The technical and business dependencies between systems and processes<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Recovery sequencing should consider both technical and business dependencies. A critical application may depend on a database, authentication service, network infrastructure, storage platform, or external service before it can operate successfully. Restoring the application without its dependencies may provide little business value and could create additional problems. Recovery priorities should therefore be established based on business impact analysis and documented dependency relationships. Technical teams should understand the order in which infrastructure components must become available, while business owners should confirm the importance of the associated processes. Proper sequencing helps ensure that recovery resources are used efficiently and that critical services can resume in a practical order.<\/span><\/p>\n<h3><b>Question 364. What is the primary purpose of a business continuity plan version-control process?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To ensure users can identify the current approved version of the plan<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To prevent management from reviewing the plan<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To allow employees to make uncontrolled changes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To eliminate the need for plan testing<\/span><\/p>\n<p><b>Answer: 1) To ensure users can identify the current approved version of the plan<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Version control helps ensure that personnel use the correct and approved continuity procedures during a disruption. Without version control, different departments may retain outdated copies containing incorrect contact information, recovery procedures, system dependencies, or responsibilities. A controlled process should identify the version, approval status, effective date, and significant changes. Obsolete copies should be appropriately withdrawn or clearly identified to prevent accidental use. Electronic plans should also have appropriate access controls and backup arrangements. Version control should be integrated with change management so that significant environmental or organizational changes result in controlled updates. This improves the reliability and consistency of continuity documentation.<\/span><\/p>\n<h3><b>Question 365. Which metric is most useful for evaluating whether a recovery exercise achieved its planned recovery objective?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Number of employees attending the exercise<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Number of pages in the recovery plan<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Actual recovery time compared with the defined recovery target<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Number of systems listed in the asset inventory<\/span><\/p>\n<p><b>Answer: 3) Actual recovery time compared with the defined recovery target<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Comparing actual recovery performance with a predefined recovery target provides measurable evidence of whether the exercise achieved its intended objective. The organization can evaluate how long it took to restore critical services and compare the result with established requirements. Other measures may also be useful, including data recovery success, communication effectiveness, unresolved issues, and successful completion of recovery procedures. Attendance and documentation size do not demonstrate recovery effectiveness by themselves. Exercise results should be documented and analyzed so that weaknesses can be corrected. Repeated testing can then determine whether corrective actions have improved recovery performance and whether recovery capabilities remain aligned with business requirements.<\/span><\/p>\n<h3><b>Question 366. What should an organization do when a continuity exercise identifies a significant gap in recovery capability?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Ignore the issue if normal operations are unaffected<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Document the gap, assign responsibility and track corrective action<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Delete the exercise results<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Immediately discontinue all continuity exercises<\/span><\/p>\n<p><b>Answer: 2) Document the gap, assign responsibility and track corrective action<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A continuity exercise is valuable because it identifies weaknesses before an actual disruption occurs. Significant gaps should therefore be documented and assigned to responsible individuals or teams for remediation. Corrective actions should include an appropriate priority, target completion date, and method for verifying that the issue has been resolved. Depending on the severity, management may need to implement temporary compensating measures while permanent improvements are developed. Merely recording an issue without follow-up does not improve recovery capability. Future exercises should verify whether corrective actions were effective. This creates a continuous improvement cycle in which testing results directly contribute to stronger continuity planning and operational resilience.<\/span><\/p>\n<h3><b>Question 367. Which situation most clearly indicates that a third-party continuity capability should be reassessed?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> The supplier changes its office furniture<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> The supplier publishes a new marketing brochure<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> The supplier hires additional administrative staff<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> The supplier experiences a major change affecting a critical outsourced service**<\/span><\/p>\n<p><b>Answer: 4) The supplier experiences a major change affecting a critical outsourced service<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A significant change affecting a critical outsourced service can alter the supplier&#8217;s ability to meet continuity requirements. Examples include a major technology migration, acquisition, change in hosting location, subcontractor change, financial difficulty, or modification of recovery architecture. The organization should assess whether the supplier continues to satisfy contractual recovery objectives and security requirements. Depending on the risk, the review may include updated assurance reports, continuity test evidence, revised recovery documentation, or discussions with the provider. Supplier monitoring should be risk-based rather than triggered by insignificant changes. For critical services, maintaining confidence in third-party recovery capabilities is important because the organization&#8217;s continuity may depend directly on them.<\/span><\/p>\n<h3><b>Question 368. Why should continuity plans identify critical external dependencies?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To ensure recovery planning accounts for services the organization does not directly control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To eliminate all vendor contracts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To transfer business ownership to suppliers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To avoid documenting internal dependencies<\/span><\/p>\n<p><b>Answer: 1) To ensure recovery planning accounts for services the organization does not directly control<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Organizations often depend on external providers for telecommunications, cloud hosting, payment processing, logistics, software services, utilities, and other essential activities. If these dependencies are omitted from continuity planning, an organization may restore its internal systems while remaining unable to perform critical business processes. External dependencies should therefore be identified and evaluated as part of continuity planning. Relevant contracts should define required service levels, recovery expectations, notification responsibilities, and other important obligations. The organization should also understand the provider&#8217;s own dependencies where appropriate. Including external dependencies produces a more realistic recovery strategy and helps management identify situations where additional alternatives or contingency arrangements may be necessary.<\/span><\/p>\n<h3><b>Question 369. Which control best reduces the risk that a compromised application programming interface (API) credential can be used indefinitely?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Disabling all API functionality<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Storing the credential in source code<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Using short-lived credentials with appropriate expiration and rotation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Sharing one credential among all applications<\/span><\/p>\n<p><b>Answer: 3) Using short-lived credentials with appropriate expiration and rotation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Short-lived credentials reduce the period during which a compromised credential can be misused. Where technically practical, API authentication mechanisms should use credentials or tokens with limited lifetimes and appropriate scopes. Rotation procedures should replace credentials regularly and provide a mechanism for rapid revocation when compromise is suspected. Credentials should also be protected through appropriate access controls and secrets-management practices. Disabling APIs entirely is generally not practical when applications require integration. Sharing credentials increases the impact of compromise because multiple systems may be affected. Combining limited credential lifetime, least privilege, monitoring, and secure storage provides stronger protection for application interfaces.<\/span><\/p>\n<h3><b>Question 370. What is the primary purpose of rate limiting on an Internet-facing API?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To increase the size of application databases<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To restrict excessive requests and reduce abuse or resource exhaustion<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To eliminate the need for authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To guarantee that every request is legitimate<\/span><\/p>\n<p><b>Answer: 2) To restrict excessive requests and reduce abuse or resource exhaustion<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">API rate limiting controls how many requests a user, application, or source can make within a defined period. It can help reduce abuse, automated attacks, excessive resource consumption, and certain denial-of-service conditions. Rate limits should be designed according to legitimate business requirements so that normal users are not unnecessarily prevented from accessing services. Rate limiting does not replace authentication, authorization, input validation, monitoring, or other security controls. Appropriate responses to excessive requests should also be defined and monitored. From an audit perspective, the effectiveness of rate limiting should be evaluated against documented requirements and expected traffic patterns, particularly for externally accessible and business-critical interfaces.<\/span><\/p>\n<h3><b>Question 371. Which web application control helps prevent session identifiers from being transmitted over an unencrypted connection?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Secure cookie attributes combined with encrypted transport<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Disabling application logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Increasing database storage capacity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Removing session expiration<\/span><\/p>\n<p><b>Answer: 1) Secure cookie attributes combined with encrypted transport<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Session identifiers should be protected because an attacker who obtains a valid session token may be able to impersonate the associated user. Using the Secure attribute on session cookies instructs compatible browsers to send those cookies only over encrypted HTTPS connections. Encrypted transport helps protect session information while it travels between the client and server. Other cookie protections, such as HttpOnly and appropriate SameSite settings, can provide additional safeguards against different attack scenarios. Session management should also include suitable expiration and invalidation procedures. These controls work together to reduce the likelihood that session identifiers will be intercepted, exposed, or misused.<\/span><\/p>\n<h3><b>Question 372. What should an auditor verify when assessing whether a web application properly validates session termination?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> That terminated sessions remain active indefinitely<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> That users can reuse expired sessions without authentication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> That session identifiers are deleted from the database only once per year<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> That logout, expiration or administrative termination invalidates the active session**<\/span><\/p>\n<p><b>Answer: 4) That logout, expiration or administrative termination invalidates the active session<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Effective session management should ensure that a session cannot continue to provide access after it has been intentionally terminated or has exceeded its permitted lifetime. An auditor can test whether logging out invalidates the session token and whether expired sessions are rejected when reused. Administrative termination may also be necessary when an account is disabled, compromised, or otherwise requires immediate revocation. Session invalidation should be tested from both normal and abnormal scenarios. Simply removing a session identifier from a client interface may not be sufficient if the server continues to accept it. Proper server-side session invalidation is therefore an important application security control.<\/span><\/p>\n<h3><b>Question 373. Which practice best reduces the risk associated with open-source software dependencies used in an application?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Allowing developers to download any version without review<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Maintaining an inventory of dependencies and monitoring them for known vulnerabilities<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Prohibiting all software updates<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Removing software documentation<\/span><\/p>\n<p><b>Answer: 2) Maintaining an inventory of dependencies and monitoring them for known vulnerabilities<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Open-source dependencies can introduce vulnerabilities or licensing concerns into applications, particularly when organizations do not know which components and versions are being used. Maintaining an inventory allows development and security teams to identify dependencies and determine whether vulnerabilities affect the application. Organizations can use automated scanning and software composition analysis to support this process. When vulnerabilities are identified, remediation should consider exploitability, application exposure, business criticality, and available updates. Dependencies should also be obtained from trusted sources and managed through appropriate development processes. Effective dependency management improves visibility and helps organizations respond more quickly when security issues are discovered in external components.<\/span><\/p>\n<h3><b>Question 374. What is the primary purpose of a software bill of materials (SBOM)?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To document the components and dependencies contained within software<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To replace application source code<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To provide employee performance evaluations<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To define an organization&#8217;s disaster recovery site<\/span><\/p>\n<p><b>Answer: 1) To document the components and dependencies contained within software<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A software bill of materials provides an inventory of software components and dependencies included in an application or software product. This visibility can help organizations determine whether a newly discovered vulnerability affects their environment. An SBOM can also support software supply-chain risk management, component tracking, and more efficient vulnerability response. It does not replace source code, security testing, or vulnerability management processes. For effective use, organizations should maintain sufficiently accurate and current component information. Auditors may assess whether appropriate processes exist to identify software components, maintain relevant inventories, and respond when security issues affect components used by business-critical applications.<\/span><\/p>\n<h3><b>Question 375. Which control is most effective for detecting unauthorized changes to critical system configurations?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Periodic employee satisfaction surveys<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Increasing system storage capacity<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Configuration monitoring with alerts for unauthorized changes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Removing all configuration documentation<\/span><\/p>\n<p><b>Answer: 3) Configuration monitoring with alerts for unauthorized changes<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Configuration monitoring can identify unauthorized changes to critical systems and provide evidence for investigation. Baseline configurations establish the expected state, while monitoring tools compare current settings against approved configurations and can generate alerts when deviations occur. Alerts should be investigated to determine whether changes were authorized, accidental, or malicious. Relevant changes should be traceable to approved requests or emergency procedures. Monitoring is especially important for systems supporting critical services because unauthorized configuration changes can weaken security or affect availability. An effective process combines configuration baselines, change authorization, monitoring, logging, and periodic review to maintain control over important system settings.<\/span><\/p>\n<h3><b>Question 376. Which security principle should guide the design of access between microservices?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Every service should have unrestricted access to every other service<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Access should be limited to the specific services and functions required<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Authentication should be disabled for internal service calls<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> All services should share one administrative account<\/span><\/p>\n<p><b>Answer: 2) Access should be limited to the specific services and functions required<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Microservices should communicate according to defined trust relationships and least-privilege requirements. A service should receive only the access needed to perform its intended function rather than unrestricted access to other services. Authentication and authorization should be applied appropriately to service-to-service communication, and sensitive operations should be monitored. Excessive privileges can increase the impact of a compromised service because an attacker may move laterally across the environment. Network segmentation and service-level authorization can further limit unnecessary communication paths. Auditors should evaluate whether service permissions are documented, approved, periodically reviewed, and technically enforced according to business and security requirements.<\/span><\/p>\n<h3><b>Question 377. What is the primary purpose of maintaining an audit trail for automated administrative actions?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> To make automated processing slower<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> To prevent all automation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> To provide accountability and evidence of actions performed by automated processes<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> To eliminate access reviews<\/span><\/p>\n<p><b>Answer: 3) To provide accountability and evidence of actions performed by automated processes<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Automated processes can perform significant administrative or business actions without direct human intervention. Maintaining an appropriate audit trail helps establish what action occurred, when it occurred, which process performed it, and, where applicable, which authorized individual initiated the activity. Logs should be protected against unauthorized modification and retained according to organizational requirements. Monitoring automated activity can also help identify unexpected behavior or misuse of service credentials. Accountability is particularly important when automation performs privileged operations because investigators need sufficient evidence to reconstruct events. Auditors should verify that logging requirements are defined and that important automated activities are actually recorded and reviewable.<\/span><\/p>\n<h3><b>Question 378. Which audit procedure best evaluates whether privileged access is being reviewed effectively?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Examine evidence that privileged accounts and their assigned permissions were periodically reviewed and exceptions resolved<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Ask administrators whether they believe reviews are effective<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Review only ordinary user accounts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Confirm that the organization owns a privileged access management product<\/span><\/p>\n<p><b>Answer: 1) Examine evidence that privileged accounts and their assigned permissions were periodically reviewed and exceptions resolved<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Effective auditing of privileged access requires evidence that privileged accounts and permissions are periodically reviewed by authorized personnel. The auditor should examine the population of privileged accounts, review frequency, reviewer authorization, identified exceptions, and evidence that inappropriate access was removed or corrected. Merely having a privileged access management product does not prove that access reviews are effective. Interviews can provide useful information but should be supported by reliable evidence. Testing should also consider dormant, shared, emergency, and service-related privileged accounts where applicable. The objective is to determine whether privileged access remains appropriate and whether management responds effectively when inappropriate permissions are identified.<\/span><\/p>\n<h3><b>Question 379. What should an auditor evaluate when determining whether an audit finding has been effectively remediated?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Whether management verbally states that the issue is closed<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Whether the original audit report is still available<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Whether the issue received a high priority initially<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Whether objective evidence demonstrates that the corrective action was implemented and the underlying condition addressed**<\/span><\/p>\n<p><b>Answer: 4) Whether objective evidence demonstrates that the corrective action was implemented and the underlying condition addressed<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Effective follow-up should determine whether management implemented the agreed corrective action and whether the underlying condition that caused the finding has actually been addressed. Auditors should obtain objective evidence appropriate to the control, such as system configurations, transaction records, access reports, procedures, or test results. A management statement alone may not provide sufficient assurance. The auditor should also consider whether the corrective action adequately addresses the original risk rather than merely treating a symptom. If the issue remains unresolved, its status and residual risk should be communicated according to established procedures. Proper follow-up provides assurance that audit recommendations produce meaningful improvements.<\/span><\/p>\n<h3><b>Question 380. Which factor should most influence the frequency of an internal audit&#8217;s review of a high-risk control?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> The personal preference of the auditor<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> The level of risk and the likelihood and impact of control failure<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> The number of pages in previous audit reports<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> The age of the organization&#8217;s audit software<\/span><\/p>\n<p><b>Answer: 2) The level of risk and the likelihood and impact of control failure<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Audit review frequency should be determined using a risk-based approach. Controls associated with higher likelihood or greater impact of failure generally require more frequent attention than controls associated with lower risks. Other factors can also influence frequency, including changes in the business environment, regulatory requirements, prior control deficiencies, system changes, and results from previous assessments. The auditor should document the rationale for the selected frequency and adjust it when risk conditions change. A risk-based schedule helps direct limited audit resources toward areas where assurance can provide the greatest value. It also supports a more dynamic audit program than simply reviewing every control at the same fixed interval.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Isaca CISA Exam Dumps and Practice Test Dumps &nbsp; Question 361. What is the primary purpose of conducting a business continuity plan review after a major organizational change? 1) To eliminate the need for continuity testing 2) To confirm that recovery requirements and procedures still reflect the current environment 3) To reduce the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/13849"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=13849"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/13849\/revisions"}],"predecessor-version":[{"id":13851,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/13849\/revisions\/13851"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=13849"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=13849"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=13849"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}