Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Systems Auditor

Domain 3Objective 4

Control Identification and Design CISA Practice Questions (Page 2)

Part of the Information Systems Acquisition, Development and Implementation domain, which accounts for 12% of the CISA exam.

28questions here
6free pages
5concepts
12%of the exam

Questions 6–10

  1. 6application · medium

    During the design of a new inventory management system, the project team identified the following risks: (1) unauthorized changes to inventory records, (2) loss of data due to system failure, and (3) inaccurate data entry by warehouse staff. Which control mapping provides the most comprehensive coverage for these risks?

    Select an answer first
  2. 7application · medium

    A project team is designing a new system for a hospital that will store patient health records. They have identified a risk that a nurse could accidentally view another patient's records. Which control design would best mitigate this risk?

    Select an answer first
  3. 8application · medium

    During the control identification phase for a new e-commerce platform, the project team has documented a control that requires two-factor authentication (2FA) for all administrator accounts. Which risk is this control primarily designed to mitigate?

    Select an answer first
  4. 9foundation · easy

    What is the primary purpose of mapping controls to risks in an information systems project?

    Select an answer first
  5. 10expert · hard

    A project team is using a DevOps approach to develop a new mobile application. The team wants to integrate security controls into the CI/CD pipeline. Which control integration strategy best aligns with DevOps principles while ensuring effective risk mitigation?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.