
Certified Information Systems Auditor
Domain 2Objective 2
Risk and Compliance Management CISA Practice Questions (Page 3)
Part of the Governance and Management of IT domain, which accounts for 18% of the CISA exam.
31questions here
7free pages
8concepts
18%of the exam
Questions 11–15
- 11
What is the primary purpose of risk prioritization in the IT risk assessment process?
Select an answer first - 12
Which privacy principle, as outlined in the OECD guidelines, requires that personal data be collected only for specified, explicit, and legitimate purposes?
Select an answer first - 13
A large organization is implementing a data governance program. The program includes data stewardship, data quality, and data lifecycle management. The organization has a mix of structured and unstructured data across multiple systems. Which of the following is the MOST critical challenge for the data governance program to address?
Select an answer first - 14
What is the primary purpose of data governance?
Select an answer first - 15
A multinational corporation is implementing an ERM framework aligned with ISO 31000. The board has set a risk appetite that is 'moderate' for operational risks but 'low' for compliance risks. During a risk assessment, the IT department identifies a new cloud service that would reduce operational costs but introduces a compliance risk because the service provider stores data in a country without adequate data protection laws. The IT department proposes accepting the risk because the cost savings are significant. Which of the following is the MOST appropriate action for the risk manager?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.