Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA logo

Certified Information Systems Auditor

Domain 3Objective 4

Control Identification and Design CISA Practice Questions (Page 6)

Part of the Information Systems Acquisition, Development and Implementation domain, which accounts for 12% of the CISA exam.

28questions here
6free pages
5concepts
12%of the exam

Questions 26–28

  1. 26application · medium

    A project team is implementing a new system using a hybrid approach that combines elements of waterfall and agile. The project manager wants to ensure that controls are integrated into the project management processes. Which approach best supports control integration in a hybrid environment?

    Select an answer first
  2. 27application · medium

    A project team is using a traditional waterfall methodology to develop a new billing system. The project manager wants to ensure that security controls are integrated into the system development lifecycle (SDLC). Which approach best aligns with the waterfall model?

    Select an answer first
  3. 28expert · hard

    A healthcare organization is implementing a new patient portal that will allow patients to view their medical records and schedule appointments. The project team has identified the following risks: (1) unauthorized access to patient data, (2) data breaches due to insecure APIs, and (3) non-compliance with data protection regulations. The organization has a limited budget and must prioritize controls. Which control design provides the most balanced mitigation across all three risks?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CISA

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.