
Certified Information Systems Auditor
Domain 2Objective 2
Risk and Compliance Management CISA Practice Questions (Page 1)
Part of the Governance and Management of IT domain, which accounts for 18% of the CISA exam.
31questions here
7free pages
8concepts
18%of the exam
Questions 1–5
- 1
Which of the following is a key component of establishing a privacy program?
Select an answer first - 2
Which of the following is an example of a key risk indicator (KRI) for IT security?
Select an answer first - 3
A financial services firm has identified a high-risk vulnerability in its customer-facing web application that could expose credit card data. The vulnerability is in a third-party component that is no longer supported by the vendor. The firm's risk appetite is low, and the application is critical to business operations. Which of the following risk response options is the MOST appropriate given the constraints?
Select an answer first - 4
A global e-commerce company processes personal data of customers in the European Union (EU) and the United States. The company is designing a new marketing analytics platform that will store customer purchase history and browsing behavior. The privacy team is tasked with ensuring compliance with GDPR. Which of the following is the MOST critical requirement for the platform design?
Select an answer first - 5
A financial institution has implemented a risk monitoring program. The board of directors receives a quarterly risk report that includes key risk indicators (KRIs). The CRO notices that one KRI, the number of unresolved high-risk audit findings, has been steadily increasing over the past three quarters. Which of the following is the MOST appropriate action for the CRO to take?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.