
Certified Information Systems Auditor
Domain 2Objective 2
Risk and Compliance Management CISA Practice Questions (Page 2)
Part of the Governance and Management of IT domain, which accounts for 18% of the CISA exam.
31questions here
7free pages
8concepts
18%of the exam
Questions 6–10
- 6
What is the primary purpose of data classification?
Select an answer first - 7
An organization's IT risk committee meets quarterly to review risk status. The CISO wants to provide a concise, forward-looking view of emerging risks to the committee. Which of the following would be the MOST effective approach for the CISO to use?
Select an answer first - 8
A healthcare organization is implementing a data classification policy. The policy defines four classification levels: Public, Internal, Confidential, and Restricted. The organization stores patient records (Restricted), employee HR data (Confidential), and marketing materials (Public). The IT department is configuring a new file-sharing system. Which of the following is the MOST appropriate configuration for handling Restricted data?
Select an answer first - 9
What is the primary purpose of a key risk indicator (KRI) in risk monitoring?
Select an answer first - 10
Which of the following is an example of a data handling requirement that would apply to highly sensitive data?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.