
Certified Information Systems Auditor
Domain 3Objective 4
Control Identification and Design CISA Practice Questions (Page 4)
Part of the Information Systems Acquisition, Development and Implementation domain, which accounts for 12% of the CISA exam.
28questions here
6free pages
5concepts
12%of the exam
Questions 16–20
- 16
A financial services firm is implementing a new customer onboarding system. The project team has identified a risk that unauthorized users could access customer data through a misconfigured web application firewall (WAF). During the control identification phase, which control would be most appropriate to document as a preventive control for this specific risk?
Select an answer first - 17
During a control mapping exercise, the IS auditor discovers that a high-risk area has no corresponding control. What is the most appropriate action?
Select an answer first - 18
A project team is designing a new online banking system. They have identified a risk of fraudulent transactions. The team is considering two controls: (1) a real-time transaction monitoring system that flags suspicious transactions and (2) a rule that requires additional verification for transactions above a certain amount. The team has a limited budget and must choose one. Which control should they choose to best balance risk mitigation and user experience?
Select an answer first - 19
A project team is designing a new customer-facing web application. They have identified a risk of SQL injection attacks. The team is considering two controls: (1) parameterized queries and (2) a web application firewall (WAF). The team has a limited budget and must choose one. Which control should they choose to best mitigate the risk?
Select an answer first - 20
Which of the following best describes the integration of controls into the system development lifecycle (SDLC)?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.