Step2Study
IT & TechnologyCISA100% Free

ISACA Certified Information Systems Auditor (CISA) Exam

Practice bank
247 Qs
Real exam
150 Qs
Time limit
240 min
Passing
A scaled score of 450 or higher on a 200-800 point scale.

Exam blueprint

Domain 1: Information System Auditing Process
21%
Domain 2: Governance and Management of IT
17%
Domain 3: Information Systems Acquisition, Development and Implementation
12%
Domain 4: Information Systems Operations and Business Resilience
23%
Domain 5: Protection of Information Assets
27%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 150 questions each · 240 min · pass 75% · 247 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

ISACA Certified Information Systems Auditor (CISA) Exam practice test questions

Sample questions from the 247-question bank, with answers and explanations.

All questions
  1. 1. An organization's information security policy states, 'All employees shall protect company information assets.' However, the policy does not define what constitutes 'company information assets,' nor does it specify protection measures or consequences for non-compliance. What is the MOST significant implication of this policy's wording for information security governance?

    Domain 2: Governance and Management of IT

    • A. The organization may be viewed as having a weak security posture by external auditors.
    • B. Training programs for information security will be difficult to develop.
    • C. The policy is legally unenforceable in its current form.
    • D. Employees may inadvertently expose sensitive information due to a lack of clear guidance.
    Show answer

    D. Employees may inadvertently expose sensitive information due to a lack of clear guidance.

    An effective information security policy must be clear, specific, and actionable. Vague wording that fails to define key terms or specify expected behaviors and consequences makes it impossible for employees to understand or comply with their obligations, leading to inconsistent application and potential security breaches.

  2. 2. A CISA is auditing an organization's IT asset management process. The CISA discovers that while hardware assets are meticulously tracked from acquisition to disposal, software licenses are only tracked at the point of purchase, with no ongoing monitoring of usage or installation. What is the MOST significant risk introduced by this practice?

    Domain 2: Governance and Management of IT

    • A. Challenges in accurately forecasting future software budget requirements.
    • B. Higher likelihood of non-compliance with software vendor licensing agreements.
    • C. Reduced operational efficiency due to manual software inventory processes.
    • D. Increased difficulty in performing software upgrades and patches.
    Show answer

    B. Higher likelihood of non-compliance with software vendor licensing agreements.

    Without ongoing monitoring of software installations and usage, an organization runs a significant risk of being over-licensed (wasting money) or, more critically, under-licensed, leading to non-compliance with software vendor agreements. This can result in hefty fines, legal action, and reputational damage.

  3. 3. An IS auditor is reviewing the project management practices for a new data analytics platform. The project manager reports that the project is on schedule and within budget, but key stakeholders express concerns about the solution's ability to meet their evolving business intelligence needs. Which of the following is the MOST likely underlying issue?

    Domain 3: Information Systems Acquisition, Development and Implementation

    • A. Poor change control procedures.
    • B. Lack of continuous requirements validation.
    • C. Insufficient benefits realization management.
    • D. Inadequate risk management planning.
    Show answer

    B. Lack of continuous requirements validation.

    The scenario indicates that while the project is technically on track (on schedule, within budget), the delivered solution might not meet 'evolving business intelligence needs.' This points to a failure in continuously validating that the system being built still aligns with current and future business requirements, especially in dynamic environments like data analytics.

  4. 4. A CISA is evaluating the effectiveness of an organization's IT governance structure. The CISA observes that the IT department consistently implements new technologies without formal approval from a cross-functional steering committee, despite such a committee being documented in the governance framework. What is the MOST likely consequence of this situation?

    Domain 2: Governance and Management of IT

    • A. Reduced employee morale within the IT department.
    • B. Misalignment of IT investments with business strategy.
    • C. Difficulty in attracting and retaining skilled IT personnel.
    • D. Increased IT operational costs due to redundant systems.
    Show answer

    B. Misalignment of IT investments with business strategy.

    If IT implements new technologies without formal cross-functional approval, it indicates a lack of effective governance oversight. This bypasses the mechanism designed to ensure IT projects align with overall business objectives, leading to potential investments in technologies that do not support strategic goals or create unintended business risks.

  5. 5. An organization is considering replacing its existing IT governance framework with a new, industry-standard framework. During the evaluation, the CISA notes that the proposed framework requires significant cultural changes and new reporting structures that are fundamentally different from the current organizational culture and existing management hierarchy. What is the PRIMARY challenge the organization will face in implementing the new framework?

    Domain 2: Governance and Management of IT

    • A. Resistance from management and employees to adapt to new processes and responsibilities.
    • B. Increased complexity in integrating the new framework with existing IT operations.
    • C. Difficulty in obtaining budget approval for the new framework's tools and training.
    • D. Challenges in measuring the return on investment (ROI) of the framework implementation.
    Show answer

    A. Resistance from management and employees to adapt to new processes and responsibilities.

    Significant cultural changes and new reporting structures directly challenge established norms and power dynamics within an organization. Resistance from management and employees to adapt to these fundamental shifts is a common and often the most difficult barrier to successful implementation of new governance frameworks or any organizational change.

  6. 6. A CISA is evaluating an organization's human resources management practices related to IT. The CISA observes that new IT employees are granted broad system access immediately upon joining, with access reviews conducted only annually. What is the MOST significant risk associated with this practice?

    Domain 2: Governance and Management of IT

    • A. Elevated risk of unauthorized access and data breaches.
    • B. Difficulty in conducting effective IT audits.
    • C. Reduced employee productivity due to access complexity.
    • D. Increased cost due to unnecessary software licenses.
    Show answer

    A. Elevated risk of unauthorized access and data breaches.

    Granting broad access immediately and conducting infrequent reviews creates a significant window of opportunity for unauthorized actions, whether accidental or malicious. This practice directly increases the risk of data breaches and compromises system integrity, as access is not aligned with the principle of least privilege or need-to-know.

  7. 7. An IS auditor is evaluating the controls over a new financial reporting system still in the development phase. Which of the following would be the MOST effective control to ensure that only authorized and tested code changes are promoted to the production environment?

    Domain 3: Information Systems Acquisition, Development and Implementation

    • A. Automated regression testing after every code commit.
    • B. Segregation of duties between development, testing, and production environments.
    • C. Daily code reviews by peer developers.
    • D. Mandatory use of a version control system.
    Show answer

    B. Segregation of duties between development, testing, and production environments.

    Segregation of duties (SoD) between development, testing, and production environments is a fundamental control that prevents unauthorized or untested code from being promoted to production. It ensures that no single individual or team has control over all stages of the software development lifecycle, thereby reducing the risk of fraud or errors.

  8. 8. During an audit of an organization's human resources management, the CISA notes that security awareness training is conducted only for new hires and is not repeated annually for existing employees. What is the MOST significant risk associated with this practice?

    Domain 2: Governance and Management of IT

    • A. Difficulty in obtaining cyber insurance coverage.
    • B. Erosion of the organization's security posture over time.
    • C. Increased cost of onboarding new employees.
    • D. Decreased employee satisfaction due to lack of professional development.
    Show answer

    B. Erosion of the organization's security posture over time.

    Security awareness is not a one-time event; threats evolve, and human memory fades. Without regular, ongoing training, employees' understanding of security policies and best practices will diminish, leading to a weakened human firewall and an increased susceptibility to social engineering attacks, phishing, and other security incidents, thereby eroding the overall security posture.

  9. 9. An IS auditor is reviewing the go-live readiness assessment for a new critical online banking system. The assessment indicates that all functional and performance tests passed, and user acceptance testing (UAT) was signed off. However, the auditor notes that the disaster recovery plan (DRP) for the new system has not yet been fully integrated or tested with the new system's specific configurations. Which of the following is the MOST significant risk to address before go-live?

    Domain 3: Information Systems Acquisition, Development and Implementation

    • A. Inability to recover the system in the event of a major disruption after go-live.
    • B. Decreased user confidence if a disaster occurs shortly after launch.
    • C. Non-compliance with internal audit policies requiring tested DRPs.
    • D. Potential for increased operational costs due to lack of DRP testing.
    Show answer

    A. Inability to recover the system in the event of a major disruption after go-live.

    For a critical online banking system, the inability to recover from a major disruption (due to an untested DRP for the new system) poses the most significant and immediate threat to business continuity, customer trust, and regulatory obligations post-go-live.

  10. 10. A CISA is evaluating an organization's business continuity plan (BCP). The CISA notes that while the BCP identifies critical business processes and their recovery time objectives (RTOs), it lacks detailed procedures for data backup and restoration, particularly for complex, interconnected databases. What is the MOST likely consequence of this deficiency during a business disruption?

    Domain 2: Governance and Management of IT

    • A. Difficulty in communicating recovery status to stakeholders.
    • B. Increased risk of data corruption during the recovery process.
    • C. Extended downtime for critical applications due to inefficient data recovery.
    • D. Failure to meet regulatory compliance requirements for data retention.
    Show answer

    C. Extended downtime for critical applications due to inefficient data recovery.

    Without detailed data backup and restoration procedures, especially for complex systems, the actual recovery process will be inefficient, error-prone, and significantly prolonged. This directly translates to exceeding established RTOs and extended downtime for critical business applications.

  11. 11. A CISA is auditing an organization that uses a third-party cloud provider for its critical business applications. The organization's information security policy states that 'all data stored in the cloud must meet the same security standards as on-premise data.' However, the CISA finds no evidence of regular security audits or reviews of the cloud provider's environment by the organization. What is the MOST significant implication of this finding?

    Domain 2: Governance and Management of IT

    • A. The cloud provider might be operating inefficiently.
    • B. The organization's internal IT staff skills may degrade over time.
    • C. The organization's policy statement is effectively unenforceable and non-compliant.
    • D. The organization may be overpaying for cloud services.
    Show answer

    C. The organization's policy statement is effectively unenforceable and non-compliant.

    Without regular security audits or reviews of the cloud provider, the organization has no way to verify if its policy requirement ('same security standards as on-premise data') is actually being met. This renders the policy unenforceable in practice and exposes the organization to unknown security risks, making it non-compliant with its own stated policy.

  12. 12. An organization relies on a highly customized, mission-critical application developed in-house over 20 years ago. The original developers have long since left the company, and documentation is sparse. The organization's disaster recovery plan (DRP) lists this application as critical but provides only generic restoration steps. What is the MOST significant challenge this poses to the DRP's effectiveness?

    Domain 2: Governance and Management of IT

    • A. High probability of recovery failures due to lack of specialized knowledge.
    • B. Increased licensing costs for legacy operating systems and databases.
    • C. Inability to accurately estimate recovery time objectives (RTOs) for the application.
    • D. Difficulty in identifying and procuring compatible hardware for recovery.
    Show answer

    A. High probability of recovery failures due to lack of specialized knowledge.

    Given the application's age, customization, lack of original developers, and sparse documentation, the most significant challenge is the high likelihood that recovery efforts will fail due to the absence of the specific, specialized knowledge required to effectively restore and configure such a unique and complex legacy system. Generic steps are insufficient.

  13. 13. During an audit of an organization's IT governance structure, the CISA observes that the IT department frequently initiates projects without formal approval from business units, leading to scope creep and unmet business expectations. Which of the following is the MOST significant implication of this observation?

    Domain 2: Governance and Management of IT

    • A. Lack of alignment between IT initiatives and business objectives.
    • B. Difficulty in tracking project progress and reporting to stakeholders.
    • C. Potential for security vulnerabilities in hastily developed systems.
    • D. Increased operational costs due to inefficient resource allocation.
    Show answer

    A. Lack of alignment between IT initiatives and business objectives.

    When IT projects are initiated without formal business unit approval, it indicates a fundamental breakdown in the alignment between IT and the business. This directly leads to projects that may not support strategic organizational goals, making lack of alignment the most significant implication.

  14. 14. A CISA is auditing an organization's approach to information security. The CISA observes that the security policies are largely descriptive, outlining what 'should be done' but lacking specific instructions or measurable outcomes. Which of the following is the MOST significant concern for the CISA regarding these policies?

    Domain 2: Governance and Management of IT

    • A. They can be easily misinterpreted by employees due to their general nature.
    • B. They require frequent updates to remain relevant to technological changes.
    • C. They make it difficult to enforce compliance and measure effectiveness.
    • D. They may not adequately address emerging threats and vulnerabilities.
    Show answer

    C. They make it difficult to enforce compliance and measure effectiveness.

    Descriptive policies that lack specific instructions and measurable outcomes severely hinder the organization's ability to enforce compliance and objectively assess whether the policies are achieving their intended security goals. Without clear metrics and actionable directives, it is challenging to hold individuals accountable or to demonstrate policy effectiveness.

  15. 15. An organization is implementing a new enterprise resource planning (ERP) system. The CISA observes that the project team is highly technical, but business unit representatives are only minimally involved in requirements gathering and testing phases. From an IT governance perspective, what is the MOST significant concern?

    Domain 2: Governance and Management of IT

    • A. The project budget may be exceeded due to technical complexity.
    • B. Technical documentation for the ERP system may be inadequate.
    • C. The system may not effectively support critical business processes.
    • D. The project timeline may be extended due to a lack of technical resources.
    Show answer

    C. The system may not effectively support critical business processes.

    Effective IT governance requires strong alignment between IT projects and business needs. Minimal involvement of business representatives in requirements and testing significantly increases the risk that the new ERP system will not meet actual business process needs, leading to low user adoption and failure to achieve strategic objectives.

  16. 16. A CISA is auditing an organization that has recently outsourced its entire IT infrastructure management to a third-party service provider. The contract explicitly states the service level agreements (SLAs) for uptime and performance. However, there is no formal mechanism for the organization to monitor the provider's adherence to these SLAs. What is the MOST critical control weakness in this scenario?

    Domain 2: Governance and Management of IT

    • A. Potential for increased costs due to unmonitored service usage.
    • B. Lack of a clear exit strategy in the outsourcing contract.
    • C. Insufficient oversight to ensure vendor performance meets contractual obligations.
    • D. Absence of an independent audit clause for the service provider.
    Show answer

    C. Insufficient oversight to ensure vendor performance meets contractual obligations.

    While all options represent weaknesses, the most critical is the lack of a mechanism to monitor SLA adherence. Without this, the organization cannot verify if the service provider is meeting its contractual obligations, effectively nullifying the purpose of having SLAs and exposing the organization to operational and financial risks without recourse.

  17. 17. An IS auditor is reviewing controls over system acquisition for a new enterprise resource planning (ERP) system. The project team has developed a detailed Request for Proposal (RFP) and received multiple vendor responses. Which of the following criteria should the IS auditor recommend as the MOST important to evaluate vendor proposals against for a complex ERP system?

    Domain 3: Information Systems Acquisition, Development and Implementation

    • A. The proposed implementation timeline and project plan.
    • B. The vendor's reputation and market share.
    • C. The vendor's ability to meet critical business requirements.
    • D. The lowest total cost of ownership (TCO).
    Show answer

    C. The vendor's ability to meet critical business requirements.

    For a complex system like ERP, the vendor's ability to meet critical business requirements is paramount. Without this, even a low-cost, reputable vendor with a fast timeline will deliver a system that fails to support core business operations, leading to significant financial and operational losses.

  18. 18. An organization is updating its human resources management practices related to IT. The CISA reviews the onboarding process for new IT employees and notes that while background checks are conducted, there is no formal process for revoking access rights immediately upon an employee's termination. Which of the following is the MOST critical risk this omission poses?

    Domain 2: Governance and Management of IT

    • A. Difficulty in tracking software license usage.
    • B. Increased administrative burden on IT helpdesk staff.
    • C. Potential for unauthorized access to sensitive systems and data.
    • D. Delayed onboarding of new employees due to resource allocation.
    Show answer

    C. Potential for unauthorized access to sensitive systems and data.

    Failure to promptly revoke access rights for terminated employees creates a critical window of opportunity for unauthorized access, potentially leading to data breaches, system compromise, or malicious activity, which is a severe security risk.

  19. 19. An organization is updating its information security policy. The draft policy includes a statement: 'All sensitive data must be encrypted in transit.' However, it does not specify the encryption algorithms, key lengths, or protocols to be used. What is the MOST significant shortcoming of this policy statement from an audit perspective?

    Domain 2: Governance and Management of IT

    • A. It does not assign responsibility for implementing the encryption.
    • B. It lacks clarity regarding the types of sensitive data covered.
    • C. It is not sufficiently actionable or enforceable due to lack of specificity.
    • D. It fails to address encryption for data at rest, only data in transit.
    Show answer

    C. It is not sufficiently actionable or enforceable due to lack of specificity.

    From an audit perspective, a policy statement must be clear, measurable, and enforceable. Without specifying 'how' encryption should be achieved (algorithms, key lengths, protocols), the policy becomes difficult to implement consistently and impossible to audit for compliance effectively, making it not actionable or enforceable.

  20. 20. An IS auditor is reviewing the software maintenance process for an internally developed legacy system. The auditor observes that maintenance requests are often implemented directly into production without prior testing in a separate environment. What is the MOST likely consequence of this practice?

    Domain 3: Information Systems Acquisition, Development and Implementation

    • A. Non-compliance with software licensing agreements.
    • B. Difficulty in attracting and retaining skilled developers.
    • C. Increased software development costs over time.
    • D. Reduced system availability due to new defects introduced.
    Show answer

    D. Reduced system availability due to new defects introduced.

    Implementing changes directly into production without testing in a separate environment significantly increases the risk of introducing new defects, regressions, or incompatibilities. These untested changes can lead to system crashes, data corruption, or unexpected behavior, directly resulting in reduced system availability and service disruptions.

  21. 21. A CISA is reviewing an organization's IT organizational structure. The CISA notes that the Chief Information Security Officer (CISO) reports directly to the Chief Information Officer (CIO). Which of the following is the MOST significant risk associated with this reporting structure?

    Domain 2: Governance and Management of IT

    • A. Security priorities may be deprioritized in favor of IT operational efficiency.
    • B. The CISO may struggle to obtain adequate budget for security initiatives.
    • C. The CISO's technical recommendations may not be understood by the CIO.
    • D. The CISO's career progression within the organization may be limited.
    Show answer

    A. Security priorities may be deprioritized in favor of IT operational efficiency.

    When the CISO reports to the CIO, there's an inherent conflict of interest. The CIO's primary focus is often on IT service delivery, operational efficiency, and project completion, while the CISO's role is to ensure security, which can sometimes impose constraints on operations. This structure can lead to security concerns being overlooked or deprioritized to meet operational goals.

  22. 22. An IS auditor is reviewing the system development lifecycle (SDLC) for a critical customer-facing web application. The development team uses an Agile methodology. Which of the following practices BEST ensures that security requirements are adequately addressed throughout the development process?

    Domain 3: Information Systems Acquisition, Development and Implementation

    • A. Relying on penetration testing by an external vendor once per year.
    • B. Providing security awareness training to all developers at the beginning of the project.
    • C. Conducting a comprehensive security audit just before the final production release.
    • D. Integrating security activities, such as threat modeling and secure code reviews, into each sprint.
    Show answer

    D. Integrating security activities, such as threat modeling and secure code reviews, into each sprint.

    Integrating security activities into each sprint (often called 'shifting left') ensures that security is built into the application incrementally, addressing vulnerabilities early and reducing remediation costs.

  23. 23. An IS auditor is evaluating the project management practices for a new data analytics platform. The project manager reports a Budgeted Cost of Work Performed (BCWP) of $750,000, an Actual Cost of Work Performed (ACWP) of $800,000, and a Budgeted Cost of Work Scheduled (BCWS) of $700,000. What is the Cost Performance Index (CPI)?

    Domain 3: Information Systems Acquisition, Development and Implementation

    • A. 1.143
    • B. 1.071
    • C. 0.875
    • D. 0.938
    Show answer

    D. 0.938

    The Cost Performance Index (CPI) measures the cost efficiency of a project. It is calculated as BCWP / ACWP. In this case, $750,000 / $800,000 = 0.9375, which rounds to 0.938.

  24. 24. A CISA is evaluating an organization's IT organizational structure. The CISA discovers that a single individual is responsible for developing, testing, and deploying critical business application code, as well as managing the production database. What is the MOST significant risk associated with this arrangement?

    Domain 2: Governance and Management of IT

    • A. Opportunities for fraud, errors, or unauthorized changes are significantly increased.
    • B. The development lifecycle for new features will be excessively long.
    • C. The organization may struggle to attract and retain skilled IT personnel.
    • D. The individual may experience burnout due to an excessive workload.
    Show answer

    A. Opportunities for fraud, errors, or unauthorized changes are significantly increased.

    This scenario describes a severe lack of segregation of duties (SoD). Allowing one person to control development, testing, deployment, and production database management creates an environment where malicious acts, errors, or unauthorized changes could occur undetected and unprevented, leading to significant integrity and security risks.

  25. 25. An IS auditor is reviewing the controls over software maintenance for an internally developed application. User feedback indicates that system performance has degraded significantly after recent production updates. Which of the following controls is MOST likely to have failed?

    Domain 3: Information Systems Acquisition, Development and Implementation

    • A. Formal change request and approval process.
    • B. Version control for software code and configurations.
    • C. Segregation of duties between development and production environments.
    • D. Adequate testing of changes before deployment.
    Show answer

    D. Adequate testing of changes before deployment.

    Significant performance degradation after production updates strongly suggests that the changes were not adequately tested for their impact on system performance, stability, or resource utilization before being deployed to the live environment.

ISACA Certified Information Systems Auditor (CISA) Exam flashcards

Tap a card to flip it. 185 flashcards in the full deck.

  • Actionable Security Policy

    Flip card

    An actionable security policy is clearly written, defines key terms, specifies required behaviors, outlines responsibilities, and details consequences for non-compliance, enabling effective implementation and enforcement.

    • Provides clear guidance to employees.
    • Defines scope, responsibilities, and expectations.
    • Essential for consistent security practices.
    Study this card →
  • Software Asset Management (SAM)

    Flip card

    The practice of managing and optimizing the purchase, deployment, maintenance, utilization, and disposal of software applications within an organization to ensure compliance and cost-effectiveness.

    • Prevents over-licensing (waste) and under-licensing (non-compliance).
    • Requires continuous monitoring of installations and usage.
    • Reduces legal and financial risks.
    Study this card →
  • Continuous Requirements Validation

    Flip card

    An ongoing process throughout the system development lifecycle to ensure that the evolving system design and implementation consistently align with current and anticipated business needs and stakeholder expectations.

    • Crucial for dynamic projects.
    • Prevents scope creep and rework.
    • Ensures solution relevance to business goals.
    Study this card →
  • IT Governance Effectiveness

    Flip card

    The degree to which an organization's IT governance framework successfully ensures that IT delivers value, manages risks, and aligns with business objectives.

    • Requires active engagement from leadership.
    • Involves clear roles and responsibilities.
    • Measured by achievement of strategic goals.
    Study this card →
  • IT Governance Cultural Impact

    Flip card

    The successful implementation of an IT governance framework significantly depends on its alignment with the organization's culture and the willingness of management and employees to adapt to new processes, roles, and reporting structures.

    • Cultural resistance is a major barrier to change.
    • New frameworks often require changes in behavior and mindset.
    • Management buy-in and employee engagement are crucial.
    Study this card →
  • Least Privilege Principle

    Flip card

    A security principle requiring that users and processes are granted only the minimum necessary authorizations to perform their functions, and no more.

    • Minimizes potential damage from errors or malicious acts.
    • Reduces attack surface.
    • Requires regular access reviews.
    Study this card →
  • Segregation of Duties (SoD)

    Flip card

    A control principle that divides critical functions among different individuals or teams to prevent any single person from having complete control over a process, thereby reducing the risk of error, fraud, or misuse.

    • Prevents a single point of failure or compromise.
    • Enhances internal control effectiveness.
    • Commonly applied in financial, IT, and operational processes.
    Study this card →
  • Continuous Security Awareness

    Flip card

    An ongoing program designed to educate all employees regularly about current information security threats, policies, and best practices to maintain a strong security culture.

    • Addresses evolving threat landscape.
    • Reinforces security behaviors.
    • Crucial for human element of security.
    Study this card →
  • Go-Live DRP Readiness

    Flip card

    Go-Live DRP Readiness refers to the state where the disaster recovery plan for a new system has been fully developed, integrated, and validated to ensure the system can be recovered post-implementation.

    • DRP must be specific to the new system's architecture.
    • Testing is crucial before production deployment.
    • Ensures business continuity from day one.
    Study this card →
  • DRP Data Recovery Procedures

    Flip card

    Detailed, step-by-step instructions within a Disaster Recovery Plan (DRP) for backing up, restoring, and ensuring the integrity of critical data and systems following a disruptive event.

    • Crucial for meeting RTOs and RPOs.
    • Must account for complex interdependencies.
    • Requires regular testing and validation.
    Study this card →
  • Cloud Security Oversight

    Flip card

    Cloud security oversight involves the organization's responsibility to ensure that cloud service providers adhere to its security policies and regulatory requirements through regular audits, reviews, and contractual agreements.

    • Shared responsibility model applies.
    • Requires contractual security clauses.
    • Verification through audits is essential.
    Study this card →
  • Legacy System DRP Challenges

    Flip card

    Difficulties in developing and executing a Disaster Recovery Plan (DRP) for older, highly customized, or poorly documented systems, often due to lack of expertise, compatible hardware, or insufficient documentation.

    • Knowledge drain is a major risk.
    • Hardware/software compatibility issues.
    • Generic DRP steps are insufficient.
    Study this card →
  • IT-Business Alignment

    Flip card

    The process of ensuring that IT strategies, initiatives, and operations are integrated with and support the organization's overarching business goals and objectives.

    • Crucial for maximizing IT value.
    • Requires strong governance and communication.
    • Prevents IT projects from becoming 'solutions looking for a problem'.
    Study this card →
  • Business-IT Alignment

    Flip card

    Business-IT alignment ensures that IT strategies, projects, and operations are consistent with and support the organization's overall business objectives and priorities.

    • Critical for achieving business value from IT investments.
    • Requires active involvement of business stakeholders.
    • Ensures IT solutions meet actual business needs.
    Study this card →
  • Outsourcing Performance Monitoring

    Flip card

    The process of continually tracking and evaluating an outsourced service provider's performance against agreed-upon service level agreements (SLAs) and contractual obligations.

    • Ensures value for money and service quality.
    • Requires defined metrics and reporting mechanisms.
    • Critical for managing vendor risk and accountability.
    Study this card →
  • Vendor Proposal Evaluation Criteria

    Flip card

    Vendor proposal evaluation criteria are the standards used to assess and compare bids from potential suppliers for system acquisition, ensuring the chosen solution best meets organizational needs.

    • Should be defined before proposals are received.
    • Includes functional, technical, financial, and support aspects.
    • Critical business requirements are usually weighted highest.
    Study this card →
  • Access Revocation

    Flip card

    Access revocation is the immediate removal of all system and data access rights for an employee upon their termination or change in role, as a critical security control measure.

    • Prevents unauthorized access.
    • Reduces insider threat risk.
    • Must be a timely and documented process.
    Study this card →
  • Software Maintenance Controls

    Flip card

    Processes and procedures designed to ensure that changes to existing software systems are authorized, tested, and implemented in a controlled manner.

    • Includes change management, testing, and documentation.
    • Critical for system stability and security.
    • Applies to bug fixes, enhancements, and patches.
    Study this card →
  • CISO Reporting Structure

    Flip card

    The hierarchical placement of the Chief Information Security Officer (CISO) within an organization, which significantly impacts the CISO's authority, independence, and effectiveness in managing information security risks.

    • Ideal reporting lines include CEO, CRO, or Board.
    • Reporting to CIO can create conflicts of interest.
    • Independence is crucial for objective security oversight.
    Study this card →
  • Security in Agile SDLC

    Flip card

    Embedding security practices and considerations throughout all phases of an Agile development lifecycle, rather than as a separate, late-stage activity.

    • Known as 'shifting left' security.
    • Includes continuous threat modeling, secure coding, and testing.
    • Reduces cost and effort of fixing vulnerabilities later.
    Study this card →
  • Cost Performance Index (CPI)

    Flip card

    The Cost Performance Index (CPI) is an Earned Value Management (EVM) metric that measures the cost efficiency of budgeted resources for work performed.

    • CPI = Earned Value (EV) / Actual Cost (AC).
    • A CPI < 1 indicates a cost overrun.
    • A CPI > 1 indicates a cost underrun.
    Study this card →
  • Software Change Testing

    Flip card

    The process of verifying that modifications to software function as intended, do not introduce new defects, and do not negatively impact existing functionality or performance before deployment.

    • Prevents regressions and new defects.
    • Ensures system stability and performance.
    • Reduces risk of production incidents.
    Study this card →
  • Cloud Exit Strategy

    Flip card

    A documented plan outlining the procedures, responsibilities, and technical requirements for migrating data and applications out of a cloud provider's environment.

    • Ensures data ownership and access upon termination.
    • Prevents vendor lock-in.
    • Addresses data format, transfer methods, and timelines.
    Study this card →
  • Internal Control Objectives

    Flip card

    Internal control objectives for IT operations define the desired state for the security, integrity, availability, and efficiency of information systems and data within an organization.

    • Guides daily IT activities.
    • Protects organizational assets.
    • Forms the basis for internal audits.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.