Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

ISACA Exam Questions & Answers (Grade A+).docx

Rating
-
Sold
-
Pages
198
Grade
A+
Uploaded on
22-05-2026
Written in
2025/2026

ISACA Exam Questions & Answers (Grade A+).docx

Institution
CISM - Certified Information Security Manager
Course
CISM - Certified Information Security Manager

Content preview

ISACA Exam Questions & Answers
(Grade A+)
Which of the following is an appropriate test method to apply to a
business continuity plan?
Pilot
Paper
Unit
System - B is the correct answer.
Justification
A pilot test is used for implementing a new process or technology
and is not appropriate for a BCP.
A paper test (sometimes called a deskcheck) is appropriate for
testing a business continuity plan (BCP). It is a walk-through of the
entire BCP, or part of the BCP, involving major players in the BCP's
execution who reason out what may happen in a particular disaster.
A unit test is used to test new software components and is not
appropriate for a BCP.
A system test is an integrated test used to test a new IT system but
is not appropriate for a BCP.


A company has implemented a new client-server enterprise
resource planning (ERP) system. Local branches transmit customer
orders to a central manufacturing facility. Which of the following

,ISACA Exam Questions & Answers
(Grade A+)
would BEST ensure that the orders are processed accurately, and
the corresponding products are produced?
Verifying production of customer orders
Logging all customer orders in the ERP system
Using hash totals in the order transmitting process
Approving (production supervisor) orders prior to production - A is
the correct answer.
Justification
Verification of the products produced will ensure that the produced
products match the orders in the order system.
Logging can be used to detect inaccuracies but does not, in itself,
guarantee accurate processing.
Hash totals will ensure accurate order transmission, but not
accurate processing centrally.
Production supervisory approval is a time consuming, manual
process that does not guarantee proper control.


An IS auditor is reviewing system access and discovers an excessive
number of users with privileged access. The IS auditor discusses the
situation with the system administrator, who states that some
personnel in other departments need privileged access and

,ISACA Exam Questions & Answers
(Grade A+)
management has approved the access. Which of the following
would be the BEST course of action for the IS auditor?
Determine whether compensating controls are in place.
Document the issue in the audit report.
Recommend an update to the procedures.
Discuss the issue with senior management. - A is the correct
answer.
Justification
An excessive number of users with privileged access is not
necessarily an issue if compensating controls are in place.
An IS auditor should gather additional information before
presenting the situation in the report.
An update to procedures would not address a potential weakness
in logical security and may not be feasible if individuals are required
to have this access to perform their jobs.
The IS auditor should gather additional information before
reporting the item to senior management.


An organization has a business process with a recovery time
objective equal to zero and a recovery point objective close to one
minute. This implies that the process can tolerate:

, ISACA Exam Questions & Answers
(Grade A+)
a data loss of up to one minute, but the processing must be
continuous.
a one-minute processing interruption but cannot tolerate any data
loss.
a processing interruption of one minute or more.
both a data loss and a processing interruption longer than one
minute. - A is the correct answer.
Justification
Recovery time objective (RTO) measures an organization's tolerance
for downtime and recovery point objective (RPO) measures how
much data loss can be accepted.
A processing interruption of one minute would exceed the zero RTO
set by the organization.
This would exceed the continuous availability requirements of an
RTO of zero.
An RPO of one minute would only allow data loss of one minute.


A certificate authority (CA) can delegate the processes of:
revocation and suspension of a subscriber's certificate.
generation and distribution of the CA public key.
establishing a link between the requesting entity and its public key.

Written for

Institution
CISM - Certified Information Security Manager
Course
CISM - Certified Information Security Manager

Document information

Uploaded on
May 22, 2026
Number of pages
198
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

$15.99
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Chloelunar University Of Nevada-Las Vegas
Follow You need to be logged in order to follow users or courses
Sold
96
Member since
2 year
Number of followers
6
Documents
14296
Last sold
3 days ago

Get study materials, exam answer packs, step-by-step assignment solutions, and much more. Learn more effectively and quickly. After acquiring any document, please always provide a review to ensure that our consumers are completely satisfied.Best Wishes!!!!!!

3.5

17 reviews

5
7
4
4
3
1
2
0
1
5

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions