Inspirational journeys

Follow the stories of academics and their research expeditions

CISA—Certified Information Systems Auditor - Part 61

Mary Smith

Thu, 16 Apr 2026

CISA—Certified Information Systems Auditor - Part 61

1. When an organization and its IT-hosting service provider are establishing a contract with each other, it is MOST important that the contract includes:

A) each party's security responsibilities
B) details of expected security metrics
C) penalties for noncompliance with security policy
D) recovery time objectives (RTOs)



2. An organization is in the process of acquiring a competitor. The information security manager has been asked to report on the security posture of the targetacquisition. Which of the following should be the security manager's FIRST course of action?

A) Implement a security dashboard
B) Quantity the potential risk
C) Perform a gap analysis
D) Perform a vulnerability assessment



3. A review of an organization's IT portfolio revealed several applications that are not in use. The BEST way to prevent this situation from recurring would be to implement:

A) a formal request for proposal (RFP) process
B) an information asset acquisition policy
C) asset life cycle management
D) business development procedures



4. A manufacturing company is implementing application software for its sales and distribution system. Which of the following is the MOST important reason for the company choose a centralized online database?

A) Enhanced data redundancy
B) Elimination of multiple points of failure
C) Elimination of the need for data normalization
D) Enhanced integrity controls



5. An organization has replaced all of the storage devices at its primary data center with new, higher capacity units. The replaced devices have been installed at the disaster recovery site to replace older units. An IS auditor's PRIMARY concern would be whether:

A) the procurement was in accordance with corporate policies and procedures
B) the relocation plan has been communicated to all concerned parties
C) a hardware maintenance contract is in place for both old and new storage devices
D) the recovery site devices can handle the storage requirements



1. Right Answer: A
Explanation:

2. Right Answer: A
Explanation:

3. Right Answer: C
Explanation:

4. Right Answer: B
Explanation:

5. Right Answer: A
Explanation:

0 Comments

Leave a comment